Skip to content
TMLZEE

Legal document

Privacy notice

How TMLZEE GROUP LTD collects, uses, shares and retains personal data, the lawful basis for each activity, and how to exercise your rights under the UK General Data Protection Regulation and the Data Protection Act 2018.

Document: Privacy notice of TMLZEE GROUP LTD.

Effective: 7 August 2026. This is the first version of this notice.

Applies to: tmlzee.co.uk, correspondence with the company, engagements carried out by the company, and any mobile or web application published by the company under its own name.

Legal framework: the UK General Data Protection Regulation, the Data Protection Act 2018, and the Privacy and Electronic Communications (EC Directive) Regulations 2003.

1.Scope of this notice

1.1 What this document covers

This notice explains what TMLZEE GROUP LTD ("TMLZEE", "we", "us") does with personal data, as Articles 13 and 14 of the UK GDPR require. It covers tmlzee.co.uk, correspondence with the company, personal data handled during client engagements, and any application we publish under our own name.

1.2 What it does not cover

It does not govern personal data that a client controls and we handle only on that client's instructions: there the client is the controller and its own notice applies. Section 3 explains how to tell the two apart. It also does not cover other organisations' websites reached from ours.

TMLZEE GROUP LTD was incorporated on 1 March 2026 and the processing described here is small in volume. Where a section describes something provided for but not yet running, the text says so rather than implying an activity that already exists.

2.Who we are and how to contact us

Role: controller

2.1 Controller identity

The controller for the processing described in sections 4 to 7 and sections 15 to 21 of this notice is:

  • TMLZEE GROUP LTD, a private limited company registered in England and Wales.
  • Company number: 17061773.
  • Registered office: Unit 15 Swift Industrial Estate, Kingsteignton, Newton Abbot, England, TQ12 3SH.
  • Email: [email protected].

Officer and ownership details are held on the public register maintained by Companies House under the company number above. We do not reproduce individual names in this notice.

2.2 Data protection contact

We have not appointed a statutory Data Protection Officer: we are not a public authority, we do not carry out large scale regular and systematic monitoring, and we do not process special category or criminal offence data at scale, so Article 37(1) is not engaged. If that changes we will appoint one and publish the route here.

Send all data protection correspondence to [email protected], ideally with "Data protection request" in the subject line. You may also write to the registered office.

2.3 Representatives

We are established in the United Kingdom, so no Article 27 UK representative is required. We do not offer goods or services to individuals in the European Economic Area or monitor their behaviour there, so no EU representative has been appointed. This section will be updated before any such activity begins.

3.The two roles: controller and processor

Role: explains both

3.1 Why the distinction matters to you

A controller decides why and how personal data is processed. A processor processes it only on a controller's documented instructions. Which one applies decides who you should go to. TMLZEE occupies both positions in different parts of its business, and the two never overlap for the same set of data.

3.2 Where we are the controller

We are the controller when we decide the purpose ourselves: our website, our correspondence, our client and supplier relationships, our statutory accounting records, and any application we publish under our own name. There you can exercise every right in section 14 directly against us.

3.3 Where we are a processor

We are a processor when a client engages us to build, integrate or maintain a system and personal data belonging to that client's customers, staff or users passes through our hands. We do not choose why that data exists. We handle it under a written agreement satisfying Article 28 of the UK GDPR, forming part of the engagement contract.

If your data reached us that way, the organisation that engaged us is your controller and requests should go to them. If you contact us instead we are not permitted to act on the request ourselves; we will forward it without undue delay and confirm to you that we have done so.

3.4 Role of each section of this notice

Role marking by section
SectionsSubjectOur role
4 to 7Website visitors, enquirers, clients as organisations, suppliers and applicantsController
8Personal data inside systems we build or maintain for a clientProcessor
9Legitimate interests relied onController
10Sub-processors we use for our own operationsController, and processor where a client has approved the same providers
11International transfersController, and processor where transfers occur under a client engagement
12RetentionController, except the final row which is processor
13Security measuresBoth
14 to 17Rights, automated decisions, marketing, breachesController, with the processor position stated in each
18 to 21Applications, deletion, children, changesController

4.Website visitors

Role: controller

4.1 What the website itself collects

tmlzee.co.uk is a static website. It contains no contact form, no analytics script, no advertising pixel, no session tracking, no live chat widget and no embedded third party content other than web fonts served by Google Fonts. We do not build a profile of visitors and we cannot identify you from a visit.

Serving any page inevitably involves your device sending a request that contains your IP address and technical details. Those requests reach our hosting and content delivery provider, Cloudflare, which processes them to deliver the page and to protect the site from attack. The cookies page explains exactly what is and is not set in your browser.

4.2 Inventory: website

Website visitor data
Category Example fields Source Purpose Lawful basis Recipients
Connection data IP address, timestamp, requested URL, HTTP status, bytes served, user agent string, TLS version Your browser, captured at the edge by our hosting provider Delivering the requested page and diagnosing delivery faults Article 6(1)(f), legitimate interests. The interest is operating a website that works and can be repaired. Cloudflare, Inc.
Security signals Request rate, request pattern, bot scoring signals, blocked request records Generated by our hosting provider from the request stream Preventing denial of service attacks, credential stuffing and automated abuse Article 6(1)(f), legitimate interests. The interest is network and information security, recognised in Recital 49. Cloudflare, Inc.
Font request data IP address, referring page, browser and operating system version, sent to Google when a font file is fetched Your browser, when it downloads the typefaces this site uses Displaying the site in the typefaces it is designed in Article 6(1)(f), legitimate interests. The interest is presenting a legible, consistently rendered site. Google Ireland Limited and Google LLC

We do not receive, store or have access to any of the font request data described in the third row. It passes from your browser directly to Google. If you prefer to avoid it, blocking fonts.googleapis.com and fonts.gstatic.com in your browser leaves the site fully readable in a substitute typeface.

5.Enquirers and prospective clients

Role: controller

5.1 How enquiries reach us

Because there is no form on this site, the only way an enquiry reaches us is that you write to us, or someone at your organisation gives us your details in the course of discussing a possible engagement. Everything we hold about a prospective client comes from one of those two places.

5.2 Inventory: enquiries

Enquiry and prospect data
Category Example fields Source Purpose Lawful basis Recipients
Contact details Name, email address, telephone number if you give one, employer, job title You, in your message Replying to your enquiry and identifying who we are speaking to Article 6(1)(b), steps at your request before entering a contract; or Article 6(1)(f) where you write on behalf of an organisation. The interest is answering people who ask us questions. Our email provider
Message content The text of your email, attachments, any project description you send You Understanding the requirement well enough to answer it, and preparing a proposal Article 6(1)(b), pre-contractual steps at your request Our email provider
Proposal records Scope documents, estimates, assumptions, the date sent and the outcome Created by us from your enquiry Quoting for work, and being able to show later what was quoted and on what terms Article 6(1)(f), legitimate interests. The interest is keeping an accurate record of our own commercial offers. Our email provider and our document storage
Correspondence history Meeting notes, call summaries, the thread of exchanged messages You and us Continuity across a conversation that may run for weeks Article 6(1)(f), legitimate interests. The interest is not asking you the same question twice. Our email provider and our document storage

5.3 What we will not do with an enquiry

We do not add enquirers to a marketing list, we do not enrich contact details from data brokers, and we do not pass details to any other organisation for its own purposes. If an enquiry does not lead to work, the record is deleted on the schedule in section 12.

6.Clients and their contacts

Role: controller

6.1 What this covers

Where an organisation engages us, we hold personal data about the individuals we deal with at that organisation. This is separate from any personal data inside the system we are building, which is dealt with in section 8.

6.2 Inventory: client relationship

Client contact and engagement data
Category Example fields Source Purpose Lawful basis Recipients
Client contacts Name, role, business email, business telephone, office location The client organisation, or the individual Performing the engagement, sending deliverables, arranging reviews Article 6(1)(b) where the individual is the contracting party; otherwise Article 6(1)(f), the interest being performing a contract with their employer. Our email provider and document storage
Engagement records Signed contract, scope document, change requests, decision log, review notes, handover documentation Created jointly during the work Delivering and evidencing the work, and defending or bringing a claim if one arises Article 6(1)(b) and Article 6(1)(f). The interest is having the record needed to establish, exercise or defend legal claims. Our document storage; professional advisers if a dispute arises
Billing records Invoices, purchase order references, payment dates, bank remittance references, billing contact name The client, and our own accounting process Charging for work, collecting payment, preparing statutory accounts and tax returns Article 6(1)(b) for taking payment, and Article 6(1)(c) for the retention required by the Companies Act 2006 and tax legislation. Our accountant, our bank, and HM Revenue and Customs
Access credentials Named accounts we are granted on client systems, repository access, key identifiers The client grants them Doing the technical work we were engaged to do Article 6(1)(b), performance of the contract Nobody outside the engagement

7.Suppliers and people who approach us for work

Role: controller

7.1 Suppliers and subcontractors

We hold the business contact details, contract terms and payment records of the organisations and individuals who supply services to us. The lawful basis is Article 6(1)(b) where the supplier is an individual contracting with us, Article 6(1)(f) where the contact works for a supplier organisation, and Article 6(1)(c) for the accounting retention that follows. The interest under Article 6(1)(f) is being able to run and pay for the services the business depends on.

7.2 People who approach us about work

We do not advertise vacancies on this website and we do not operate a recruitment process at present. If you send an unsolicited approach we will hold your message and any curriculum vitae attached to it in order to read and answer it. The lawful basis is Article 6(1)(f), the interest being responding to correspondence addressed to us. We do not build a talent pool, we do not pass approaches to recruiters, and we delete unsolicited approaches on the schedule in section 12 unless you ask us to keep them for longer, in which case the basis becomes your consent under Article 6(1)(a) and you may withdraw it at any time.

7.3 Special category data

We do not seek special category data as defined in Article 9 of the UK GDPR, meaning data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation. We also do not seek criminal offence data under Article 10. If such data reaches us unsolicited, for example inside a message you send, we delete it unless we have a lawful basis and an Article 9 condition to keep it, and we will tell you what we have done.

8.Personal data inside systems we build for clients

Role: processor

8.1 The standing position

When we build, integrate, migrate or maintain a system for a client, personal data belonging to that client's users may pass through our hands. We are a processor for that data. We process it only on the client's documented instructions, we do not use it for our own purposes, and we do not sell, share or mine it.

8.2 What the processing agreement fixes

Every engagement that involves personal data carries a written agreement satisfying Article 28(3) of the UK GDPR. It records the subject matter and duration of the processing, its nature and purpose, the types of personal data, the categories of individuals affected, and the client's rights and obligations. It also commits us to the following, each of which is a specific Article 28(3) requirement:

  • To process only on documented instructions, including on transfers out of the United Kingdom, unless required otherwise by law, in which case we tell the client first unless the law forbids it.
  • To ensure everyone authorised to process the data is under a duty of confidence.
  • To take the security measures required by Article 32.
  • Not to engage another processor without the client's prior specific or general written authorisation, and to impose the same obligations on any we do engage.
  • To assist the client, so far as possible, in responding to requests from individuals exercising their rights.
  • To assist the client with security, breach notification, breach communication and data protection impact assessments.
  • To delete or return all personal data at the client's choice at the end of the engagement, and delete existing copies unless law requires storage.
  • To make available the information needed to demonstrate compliance and to allow and contribute to audits.

8.3 Working practice on client data

Our working preference, which we recommend at the start of every engagement, is that development and testing are carried out against synthetic or effectively anonymised data rather than a copy of a live database. Where a client requires live data in a non-production environment, that instruction is recorded in writing along with the access controls applied to it and the date the copy will be destroyed.

8.4 If you are one of those individuals

Contact the organisation whose service you were using. They are your controller and they hold the record of what was collected and why. If you write to us we will pass the request on without undue delay and confirm to you that we have done so, but we cannot answer it ourselves.

9.Legitimate interests we rely on

Role: controller

Where the tables above cite Article 6(1)(f), the interest is named in the same cell. Article 6(1)(f) requires that the interest is real, that the processing is necessary for it, and that it is not overridden by your interests or fundamental rights. We have assessed each of the following and concluded that the balance favours the processing, principally because the data is limited, expected, and used for nothing beyond the stated purpose.

Legitimate interests assessment summary
ProcessingThe interestWhy it does not override you
Serving and repairing the websiteOperating a functioning websiteThe data is transient technical data, is not linked to a person by us, and no profile is built.
Blocking automated attacksNetwork and information securityRecital 49 recognises this interest expressly. Blocking abuse protects visitors as much as it protects us.
Answering enquiries from people at organisationsResponding to those who contact usYou initiated the contact and expect a reply. The data is business contact data.
Keeping a record of proposals and decisionsAccurate commercial and project recordsRecords are limited to what was agreed and by whom, and are needed to resolve any later disagreement fairly.
Holding client contact detailsPerforming a contract with the contact's employerBusiness contact data used only for the engagement the person is employed to work on.
Retaining engagement records after completionEstablishing, exercising or defending legal claimsLimited to the limitation period, then deleted. Records are not used for marketing.
Reading unsolicited approachesAnswering correspondence sent to usThe sender chose to send it, and it is deleted quickly if it leads nowhere.

You have an absolute right to object to processing based on legitimate interests for direct marketing purposes, and a qualified right to object to it for other purposes. Section 14.6 explains how.

10.Sub-processors and other recipients

Role: controller for our own operations; processor where a client has approved the same providers

10.1 Named sub-processors

These are the organisations that process personal data on our behalf. The list is short because the business is small and deliberately dependency light. It is complete as at the effective date of this notice.

Sub-processors
Provider Function Data involved Location of processing Transfer mechanism
Cloudflare, Inc. Website hosting on Cloudflare Pages, content delivery, TLS termination and denial of service protection Connection data and security signals described in section 4.2 Global edge network, including servers in the United Kingdom, the European Economic Area and the United States UK International Data Transfer Addendum to the EU standard contractual clauses
Google Ireland Limited and Google LLC Google Fonts, serving typeface files directly to your browser The font request data in section 4.2. We neither receive nor store it. Ireland and the United States Not a transfer by us. Google states its own basis to you as the party making the request.
Email and document provider Business email and document storage for correspondence, proposals and engagement records Everything in sections 5, 6 and 7 [TO CONFIRM: the provider, its processing locations and its transfer mechanism, to be named here before any client engagement begins] To be recorded above once confirmed

We use no analytics provider, no advertising network, no customer relationship management platform, no marketing automation tool and no data enrichment service. If any of those are ever adopted, this table will be updated before they are switched on.

10.2 Other recipients

  • Our accountant and auditors, for preparing statutory accounts and tax returns. They act as independent controllers for their own professional obligations.
  • Our bank, for making and receiving payments, as an independent controller.
  • HM Revenue and Customs and Companies House, where the law requires a filing or a disclosure.
  • Professional advisers, including solicitors and insurers, where we need advice or where a claim is threatened or brought.
  • A buyer, if the business or part of it is sold or reorganised, in which case personal data would transfer with the part of the business it relates to and you would be told.
  • Law enforcement, courts and regulators, where there is a legal obligation or a court order. We check that any such request is valid before we act on it and we tell the individual affected unless we are prohibited from doing so.

We do not sell personal data. We have never sold personal data and there is no arrangement under which we would.

10.3 Changes to sub-processors under a client engagement

Where we act as processor for a client, the processing agreement fixes how sub-processors are approved and how changes are notified. Our standard term is written notice to the client in advance of any addition or replacement, with a period in which the client may object and, if the objection cannot be resolved, terminate the affected part of the engagement without penalty.

11.International transfers

Role: controller, and processor where transfers occur under a client engagement

11.1 The rule we apply

Chapter V of the UK GDPR restricts transfers of personal data to countries outside the United Kingdom. A restricted transfer needs either a determination of adequacy by the Secretary of State, an appropriate safeguard under Article 46, or one of the narrow derogations in Article 49. We rely on the first two and treat the derogations as genuinely exceptional.

11.2 Adequacy

Transfers to countries covered by UK adequacy regulations, which include the European Economic Area states and the other jurisdictions the United Kingdom has recognised, require no additional safeguard. Where a provider processes only within those countries, adequacy is the mechanism and nothing further is needed.

11.3 The IDTA and the UK Addendum

Where a transfer is to a country without UK adequacy, principally the United States, we rely on one of two instruments issued by the Information Commissioner under section 119A of the Data Protection Act 2018:

  • The International Data Transfer Agreement, known as the IDTA, which is a standalone UK contract used where there is no existing EU standard contractual clauses arrangement to build on.
  • The International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, known as the UK Addendum, which sits on top of the EU clauses and adapts them for UK law. This is the more common route in practice because most international providers already offer the EU clauses as part of their data processing terms.

Our transfer to Cloudflare, Inc. relies on the UK Addendum applied to the EU standard contractual clauses contained in Cloudflare's data processing addendum.

11.4 Transfer risk assessment

Signing the clauses is not by itself sufficient. Before relying on the IDTA or the UK Addendum we carry out a transfer risk assessment, considering the law and practice of the destination country, whether public authorities there could access the data in a way incompatible with UK standards, the nature and sensitivity of the data, and what supplementary measures reduce the risk. For website connection data the assessment is straightforward: the data is technical, transient and not linked by us to an identified person, and it is encrypted in transit throughout.

11.5 Client engagements

Where we act as processor, transfers happen only on the client's documented instruction. If a client instructs a transfer outside the United Kingdom we will identify the mechanism relied on and record it in the processing agreement before the transfer occurs. Absent such an instruction, we keep client personal data within the United Kingdom or an adequate country.

11.6 Copies of the safeguards

You may ask for a copy of the safeguards relied on for a transfer that affects you, as Article 46(1) entitles you to do. Write to [email protected] and we will provide it, redacting commercial terms that are not part of the data protection safeguard.

12.How long we keep things

Role: controller, except the final row which is processor

Article 5(1)(e) requires that personal data is kept no longer than necessary. Every period below has a reason attached, because a retention schedule without reasons is only a list of numbers.

Retention schedule
RecordPeriodRuns fromReason for that period
Accounting records, including invoices and payment records 6 years The end of the financial year to which they relate Section 388 of the Companies Act 2006 requires a private company to preserve its accounting records for three years, and tax legislation requires records supporting a return to be kept longer. We apply six years as the standard UK accounting retention period, which also matches the ordinary limitation period.
Signed contracts and engagement records 6 years Completion or termination of the engagement Section 5 of the Limitation Act 1980 gives six years to bring an action on a simple contract. Deleting sooner would leave us unable to answer a claim brought in year five.
Contracts executed as a deed 12 years Completion or termination Section 8 of the Limitation Act 1980 gives twelve years for an action on a specialty.
Enquiries that did not lead to work 12 months The last message in the thread Long enough for a conversation to restart naturally, short enough that a dormant prospect list does not accumulate.
Proposals not accepted 24 months The date the proposal was issued Prospective clients frequently return with the same requirement a year or more later, and it is fairer to both sides to be able to see what was quoted before.
General correspondence 24 months The last message in the thread Covers the practical life of a business conversation without keeping mail indefinitely.
Unsolicited approaches about work 6 months Receipt Enough to answer and to reconsider, and no basis for keeping a curriculum vitae we did not ask for beyond that.
Records of data protection requests and our responses 3 years Closure of the request Accountability under Article 5(2). We need to be able to show a regulator how a request was handled.
Breach records 6 years The date of the breach Article 33(5) requires documentation of all breaches so the regulator can verify compliance; six years matches our other records.
Hosting and security logs held by our provider As set by the provider, typically days to weeks The request These are operational logs needed only for immediate diagnosis and abuse prevention, and we do not ask for longer retention.
Client personal data we process as a processor The engagement, then deleted or returned The client's instruction at the end of the engagement Article 28(3)(g). The retention decision belongs to the client as controller, not to us.

When a period expires we delete the record or, where deletion from backup media is not immediately possible, we put the data beyond ordinary use and delete it when the backup cycle next overwrites it. Backup cycles do not exceed 90 days.

13.Security

Role: both

13.1 Measures in place

Article 32 requires measures appropriate to the risk. Ours are proportionate to a small company handling a modest volume of business data:

  • Transport encryption on the website using TLS, with HTTP Strict Transport Security set so browsers refuse an unencrypted connection.
  • Multi-factor authentication on email, document storage, source control and hosting accounts.
  • Full disk encryption on every device used for company work.
  • A password manager, with unique credentials per service and no shared logins.
  • Least privilege access, granted per engagement and revoked at the end of it.
  • Separation of client engagements from one another, so that access to one does not confer access to another.
  • A static website with no database, no server side execution and no administrative login, which removes whole classes of attack at the source.
  • Security response headers on every page, restricting framing, content type sniffing, referrer leakage and the origins from which scripts and styles may load.

13.2 What we do not claim

TMLZEE GROUP LTD holds no ISO 27001 certification, no SOC 2 Type I or Type II report, and no Cyber Essentials or Cyber Essentials Plus certificate. Nothing in this notice should be read as implying any of them. If we obtain any such certification we will publish the certificate number and the certifying body so that it can be verified independently rather than taken on trust.

14.Your rights under the UK GDPR

Role: controller. Where we act as processor, section 3.3 applies instead.

14.1 How to exercise any right

Write to [email protected] or to the registered office. Say which right you are exercising, or simply describe what you want; we will work out which right applies and tell you. There is no form to complete and no fee.

Identity verification. Before acting we must be satisfied you are who you say you are, because disclosing data to the wrong person is itself a breach. If you write from an address already in our records that is usually enough. If not, we will ask for information that lets us match you to the record, and we will ask for the minimum that does the job. We do not ask for photographic identification for a routine request. Under Article 12(3) the response clock does not start until we have what we reasonably need to identify you.

Timing. We respond within one month of receiving the request, as Article 12(3) requires. That may be extended by two further months where the request is complex or where you have made a number of requests; if we extend, we tell you within the first month and explain why.

Refusals. We may refuse a request that is manifestly unfounded or excessive, in particular where it is repetitive, and Article 12(5) also allows a reasonable fee in that case. Some rights have their own exceptions, set out in each subsection below, and Schedule 2 to the Data Protection Act 2018 contains further restrictions, for example where complying would prejudice legal professional privilege or the prevention of crime. If we refuse, we tell you why, we tell you that you may complain to the Information Commissioner, and we tell you that you may seek a remedy through the courts.

14.2 The right to be informed

Articles 13 and 14 give you the right to be told what is being done with your data. This notice is how we meet it. If you want a fuller explanation of any part of it, ask and we will explain it in plain terms rather than repeating the paragraph back to you.

14.3 The right of access

Article 15 gives you the right to confirmation of whether we process your data, a copy of it, and the supplementary information in Article 15(1), including purposes, categories, recipients, retention, the source and your other rights. The first copy is free. We provide it in a commonly used electronic form unless you ask otherwise. Where a record contains another person's data we may redact that part, because Article 15(4) provides that the right must not adversely affect the rights of others.

14.4 The right to rectification

Article 16 gives you the right to have inaccurate data corrected without undue delay, and to have incomplete data completed. If we have shared the data with anyone, Article 19 requires us to tell them about the correction unless that proves impossible or involves disproportionate effort, and we will tell you who they were if you ask. A disagreement about opinion rather than fact is recorded alongside the record rather than overwritten.

14.5 The right to erasure

Article 17 gives you the right to erasure where the data is no longer necessary, where you withdraw consent that was the only basis, where you object successfully under Article 21, where processing was unlawful, or where erasure is required by law. It is not absolute. We will refuse, and tell you why, where continued processing is necessary for compliance with a legal obligation, in particular the statutory accounting retention in section 12, or for the establishment, exercise or defence of legal claims. In practice this means we can usually delete correspondence but not an invoice.

14.6 The right to restrict processing

Article 18 lets you require us to pause processing while something is being resolved: while we check the accuracy of data you dispute, where the processing is unlawful but you would rather restrict than erase, where we no longer need the data but you need it for a legal claim, or while an objection under Article 21 is being considered. While restricted we store the data and do nothing else with it without your consent, except to establish or defend legal claims. We tell you before lifting a restriction.

14.7 The right to object

Article 21(1) lets you object, on grounds relating to your particular situation, to processing based on legitimate interests. We must then stop unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is for legal claims. Article 21(2) gives you an unqualified right to object to direct marketing at any time, and we stop immediately with no balancing exercise. Section 16 explains our marketing position.

14.8 The right to data portability

Article 20 lets you receive data you provided to us, in a structured, commonly used and machine readable format, and to have it transmitted to another controller where technically feasible. It applies only where processing is based on consent or contract and is carried out by automated means, so it covers less of our processing than the right of access does. Where it applies we supply the data as a standard export file.

14.9 The right to withdraw consent

Where processing is based on consent under Article 6(1)(a), Article 7(3) lets you withdraw it at any time, and withdrawing must be as easy as giving it was. Withdrawal does not affect the lawfulness of what was done before. We rely on consent only in the narrow cases identified in this notice, principally keeping an unsolicited approach on file at your request.

14.10 Rights relating to automated decisions

Article 22 gives you the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you. Section 15 sets out our position, which is that we make no such decisions.

14.11 The right to complain

Article 77 gives you the right to lodge a complaint with a supervisory authority. In the United Kingdom that is the Information Commissioner. Full details are in section 14.12. You may complain to the Commissioner without coming to us first, although we would rather have the chance to put something right.

14.12 The Information Commissioner's Office

The supervisory authority for the United Kingdom is:

  • Information Commissioner's Office
  • Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
  • Telephone: 0303 123 1113
  • Website: ico.org.uk

You also have the right under Article 79 to an effective judicial remedy, and under Article 82 to compensation for material or non-material damage caused by an infringement.

15.Automated decision making and profiling

Role: controller

We do not carry out automated decision making producing legal or similarly significant effects, and we do not profile individuals. There is no algorithmic scoring of enquiries, no automated credit decision and no automated rejection of applicants. Judgements about whether to take on a piece of work are made by people, and if you want to know why we said no you can ask and we will tell you.

The bot scoring applied by our hosting provider to inbound web requests is a security control operating on request patterns rather than on identified individuals, and it does not produce a decision about a person within the meaning of Article 22. If a legitimate visitor is blocked in error, write to us and we will have it investigated.

16.Marketing and electronic communications

Role: controller

We operate no marketing mailing list, send no newsletter and run no advertising campaigns. There is no subscription box on this site because there is nothing to subscribe to.

If that changes, the Privacy and Electronic Communications Regulations 2003 will govern it. Marketing email to an individual subscriber requires prior consent or the narrow soft opt in at regulation 22(3), which applies only to our own similar products offered to someone whose details we obtained during a sale or negotiations for a sale, and which must carry a simple refusal route in every message. Every marketing message would identify us and provide a working unsubscribe address. We will not buy marketing lists.

Operational messages about an engagement that is under way, for example a deployment notice or an invoice, are not direct marketing and continue regardless of any marketing preference, because they are part of performing the contract.

17.Personal data breaches

Role: controller for our own data; processor where the breach affects client data

17.1 What counts as a breach

A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. It includes losing a device, sending an attachment to the wrong recipient, and a successful intrusion. It is not limited to hostile acts.

17.2 Our process

  1. Contain and record. On becoming aware, we stop the ongoing exposure where we can, and open a record. Article 33(5) requires that every breach is documented with its facts, effects and the remedial action, whether or not it is reported.
  2. Assess. We assess the likelihood and severity of risk to the individuals affected, considering the type of data, how easily someone could be identified, the seriousness of the possible consequences, and how many people are involved.
  3. Notify the Commissioner. Under Article 33(1) we notify the Information Commissioner without undue delay and, where feasible, not later than 72 hours after becoming aware, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. If we notify late we explain the delay, as Article 33(1) requires. Where the full picture is not available in 72 hours we notify in phases under Article 33(4) rather than waiting.
  4. Notify the individuals. Under Article 34(1), where the breach is likely to result in a high risk, we tell the affected individuals without undue delay, in clear and plain language, describing the nature of the breach, the likely consequences, the measures taken, and a contact point. Article 34(3) permits us not to notify individually where the data was encrypted to an appropriate standard, where we have taken measures that mean the high risk will no longer materialise, or where individual notice would involve disproportionate effort, in which case we make a public communication instead.
  5. Learn. Every breach record ends with what changed as a result.

17.3 Where we are the processor

Article 33(2) requires a processor to notify its controller without undue delay after becoming aware of a breach. Our standard commitment to clients is notice without undue delay and in any event within 24 hours of becoming aware, so that the client has time to make its own 72 hour assessment. We do not notify the Commissioner on a client's behalf unless the client instructs us to.

18.Mobile and web applications

Role: controller for applications we publish under our own name

18.1 Current position, stated plainly

As at the effective date of this notice, TMLZEE GROUP LTD has not published any mobile application under its own name on the Apple App Store, on Google Play, or on any other distribution platform. Nothing in this section should be read as describing an application that exists today. This section states the policy that applies automatically from the moment any such application is published, so that the standard is fixed in advance and published where it can be checked rather than written afterwards to fit whatever was built.

Where we build an application that is published under a client's name and account, the client is the controller for it, we are a processor, and section 8 applies rather than this section.

18.2 Device permissions

Our standing rule is that a permission is requested at the moment it is needed and never at first launch, that the reason is explained on screen before the system dialogue appears, and that declining never terminates the application. The table below sets out how each permission would be treated.

Device permission policy
Permission Purpose Required or optional If you decline How to revoke
Camera Capturing a photograph or scanning a code inside a feature that needs one Optional The capture feature is unavailable; you can attach an existing file instead and the rest of the application is unaffected iOS: Settings, Privacy and Security, Camera. Android: Settings, Apps, the app, Permissions, Camera
Photo library Selecting an existing image to attach Optional No image can be attached from the library. On iOS you may grant access to selected photos only, which we support iOS: Settings, Privacy and Security, Photos. Android: Settings, Apps, the app, Permissions, Photos and videos
Location Only where a feature is inherently locational, and only while the app is in use Optional Locational features are unavailable or fall back to a manually entered place name iOS: Settings, Privacy and Security, Location Services. Android: Settings, Location, App location permissions
Background location Not requested. We do not build background location tracking into applications published under our own name Never requested Not applicable Not applicable
Notifications Service messages such as the completion of a task you started Optional Nothing is lost; the same information appears in the app when you next open it iOS: Settings, Notifications, the app. Android: Settings, Notifications, App notifications
Microphone Only where a feature records or transmits audio at your instruction Optional Audio features are unavailable; text alternatives remain iOS: Settings, Privacy and Security, Microphone. Android: Settings, Apps, the app, Permissions, Microphone
Contacts Not requested. We do not upload address books Never requested Not applicable Not applicable
Files and storage Saving an export you asked for to your device Optional Exports can be shared through the system share sheet instead of written to storage iOS: managed per action through the system dialogue. Android: Settings, Apps, the app, Permissions, Files
Advertising identifier Not requested. We do not use IDFA, the Android Advertising ID, or any equivalent Never requested Not applicable Not applicable

Revoking a permission after granting it takes effect immediately and never deletes your account or your data. The lawful basis for processing that follows a permission grant is Article 6(1)(b) where the feature is part of the service you asked for, and Article 6(1)(a) consent where the permission is not necessary to deliver it. Note that the operating system permission dialogue is a device level control; it is not by itself UK GDPR consent, and where consent is the basis we ask for it separately in terms that meet Article 4(11).

18.3 App Tracking Transparency on iOS

Apple's App Tracking Transparency framework requires an application to obtain permission before tracking a user across applications and websites owned by other companies, or before accessing the device advertising identifier.

Our position is that we do not track. Applications published under our own name will not link user or device data with data from third party sources for advertising or measurement purposes, will not share it with data brokers, and will not access the IDFA. Because no tracking occurs, no App Tracking Transparency prompt will be shown. The absence of the prompt means there is nothing to consent to, not that consent has been assumed. Should any future application require tracking, the prompt would be shown, a plain explanation would precede it, declining would remain fully supported, and this notice would be updated before release.

18.4 Google Play Data Safety consistency

Google Play requires a Data Safety declaration in the store listing describing what data an application collects and shares, whether it is encrypted in transit, and whether the user can request deletion. That declaration and this notice must agree, and where they ever appear to diverge the difference is an error we want to know about.

The declaration for any application we publish will be prepared from this notice and will be reviewed at every release. Our baseline declaration would state: no data shared with third parties for advertising or analytics; data collected limited to what the application's own function requires; data encrypted in transit; a deletion route available both inside the application and by email; and no advertising identifier collected. The equivalent Apple privacy nutrition labels are prepared from the same source. If you find an inconsistency between a store listing and this page, write to [email protected] and we will correct whichever is wrong.

19.Account closure and data deletion

Role: controller

19.1 Two routes, both of which work

Both platforms now require an application that supports account creation to also support account deletion, initiated from within the application and not only through a support channel. Our standing commitment is that both of the following exist for any account based application we publish:

  • In application: Settings, then Account, then Delete account. The path is reachable in no more than three steps from the main screen, requires confirmation, and states clearly what will be deleted and what will be kept before you confirm.
  • By email: write to [email protected] from the address on the account, with "Delete my account" in the subject line. This route exists so that deletion does not depend on still having the application installed or on still owning the device.

19.2 What happens and how quickly

Access is revoked immediately on confirmation. Complete deletion from live systems and from backup media is finished within 30 days of the request, and we confirm in writing when it is done. Deletion is not reversible, so we say so clearly before you confirm rather than afterwards.

19.3 What is retained after deletion, and why

Retained after account deletion
RetainedPeriodReason
Records of payments made to us6 yearsStatutory accounting retention, section 12. We cannot delete an invoice on request.
The fact and date of the deletion request3 yearsSo we can evidence that the request was honoured, and so a later account is not confused with the deleted one.
Aggregate counts containing no identifiersIndefiniteNot personal data once aggregated, and cannot be traced back to an individual.
Content you posted somewhere sharedRemoved or attributed to a deleted accountWhere content forms part of another person's record, we sever the link to you rather than deleting their record.

Deleting an account is not the only option. If you would rather stop processing without losing the record, section 14.6 covers restriction and section 14.7 covers objection.

20.Children

Role: controller

This website and our services are directed at businesses and are not intended for children. We do not knowingly collect personal data from anyone under 18 in the course of our own business. Section 9 of the Data Protection Act 2018 sets the age at which a child can consent to information society services in the United Kingdom at 13, and if we ever publish a consumer application capable of being used by children we will apply the Information Commissioner's Age Appropriate Design Code, including data protection by default, and this notice will be updated to describe how.

If you believe a child's personal data has reached us, write to [email protected] and we will delete it promptly.

21.Changes to this notice

Role: controller

This is version 1.0, effective 7 August 2026. Every future version will carry its own effective date at the top of this page so you can tell whether anything has moved since you last read it.

Where a change is substantive, meaning it introduces a new purpose, a new category of recipient, a new international transfer or a materially longer retention period, we will not rely on a silent update. We will describe the change on this page and, where we hold a contact address for the people affected and the change materially affects them, we will tell them directly before it takes effect.

If you disagree with a change you retain every right in section 14, including objection and erasure, and you may complain to the Information Commissioner at any time.

Back to the home page