Privacy Policy
Last updated:
1. Data we collect
We collect minimal personal data you provide (e.g., contact form), device information, and cookie identifiers for essential functionality.
- Identification and contact data you submit, such as name and email when you contact us.
- Service usage data, including pages viewed, approximate timestamps, and interactions with features.
- Technical data, such as IP address (short-lived in logs), browser type, operating system, and device settings.
- Cookie and local storage identifiers needed to remember preferences (e.g., theme, cookie consent).
- Communications metadata (time, sender address, recipient address) for delivering messages and support.
- Optional diagnostics or feedback you choose to provide to improve reliability.
We do not intentionally collect special category data (e.g., health, biometrics) and we do not knowingly collect data about children.
2. How we use data
- Responding to enquiries
- Improving content relevance and usability
- Security and fraud prevention
We also use data to operate the service, ensure availability, and measure aggregate performance.
- Consent: non-essential cookies and optional feedback.
- Contract: providing requested services and support.
- Legitimate interests: improving the service, preventing abuse, and keeping systems secure.
- Legal obligations: complying with tax, accounting, and regulatory requirements.
3. Cookies
We use essential cookies for session and preferences (e.g., theme). You can manage cookies in your browser settings.
- Strictly necessary: required to deliver pages, balance load, and remember cookie consent (lifetimes vary up to 12 months).
- Preferences: store UI choices like theme or language (up to 12 months).
- Analytics (privacy-friendly): aggregated metrics without cross-site tracking (up to 24 months in aggregate form).
- No marketing or third-party advertising cookies are used.
You can withdraw consent for non-essential cookies at any time via your browser controls or the cookie banner when available.
4. Data retention
We retain data only as long as needed for the stated purposes or as required by law.
- Enquiry records: up to 24 months from last contact.
- Operational logs: up to 12 months, unless needed for security investigations.
- Contractual and billing records: up to 7 years to meet legal obligations.
- Analytics in aggregate: up to 36 months, without direct identifiers.
- Cookies/local storage: as described in the Cookies section or until you clear them.
5. Your rights
Under UK GDPR, you have rights to access, rectify, erase, restrict processing, and data portability. Contact us to exercise these rights.
- Access: receive a copy of your personal data we process.
- Rectification: correct inaccurate or incomplete data.
- Erasure: request deletion where we have no overriding lawful basis to retain.
- Restriction: limit processing under certain circumstances.
- Portability: receive data you provided in a structured, commonly used format.
- Objection: object to processing based on legitimate interests.
- Withdraw consent: for any processing based on consent, at any time.
We may ask for information to verify your identity. We aim to respond within one month of receipt of a complete request.
6. Contact
Email: [email protected]. Postal: SignalSense, 71-75 Shelton Street, London WC2H 9JQ, UK.
Phone (UK): +44 20 3476 8123
You may also lodge a complaint with the Information Commissioner’s Office (ICO) if you believe your rights have been infringed.
7. Lawful basis
We process personal data under the UK GDPR and Data Protection Act 2018 on the following bases:
- Contract: to provide requested services and respond to enquiries you initiate.
- Legitimate interests: to secure and improve our services, prevent abuse, and measure performance.
- Consent: for non-essential cookies and voluntary feedback.
- Legal obligation: for record keeping and compliance requirements.
8. Data sharing and processors
We do not sell your personal data. We share limited data with trusted service providers who act as processors under written contracts.
- Hosting and infrastructure providers to deliver our website and store server logs.
- Email delivery providers to send transactional messages and support replies.
- Privacy-focused analytics to measure aggregate usage without cross-site tracking.
Processors are required to implement appropriate security measures and may only process data on our documented instructions.
9. International transfers
Where data is transferred outside the UK, we use appropriate safeguards such as UK Addendum to the EU Standard Contractual Clauses or transfers to jurisdictions with UK adequacy regulations.
You can request a summary of relevant transfer safeguards via the contact details above.
10. Security
We apply organisational and technical measures appropriate to the risk.
- Transport security using industry-standard encryption in transit.
- Access controls with role-based permissions and least privilege.
- Logging and monitoring for anomaly detection and incident response.
- Regular dependency updates and vulnerability patching.
- Data minimisation and retention controls.
11. Automated decision-making
We do not make decisions with legal or similarly significant effects based solely on automated processing. Any automated scoring for security is used only to assist human review.
12. Children’s privacy
Our services are directed to business and general audiences. We do not knowingly collect personal data from children. If you believe a child has provided data, contact us and we will delete it promptly.
13. Changes to this policy
We may update this policy to reflect changes in our practices, technologies, or legal requirements. The “Last updated” date indicates the latest revision. Material changes will be communicated in-service where feasible.
14. Controller identity
Controller: SignalSense (UK). Primary contact: [email protected]. Registered correspondence address: 71-75 Shelton Street, London WC2H 9JQ, UK.
UK contact phone: +44 20 3476 8123