1.Entry — why the notebook is kept
Entered 7 August 2026. Rewritten only if the shape of the business changes.
A workshop keeps a notebook so that the person who comes after can see how a thing was made. This is the same idea applied to personal data. Rather than publish a page of reassurance, we have written down each place personal data actually reaches us, what happens to it there, and the reason we are allowed to touch it at all.
Read an entry for the situation you are in. If you wrote to us, entry five is yours. If your employer has hired us, five, six and twelve. If you are simply reading the site, entry four is the whole of it, and it is short.
Two things sit outside these pages. Websites we link out to keep their own notebooks, and we cannot vouch for them. Personal data held inside a system we built for a client belongs to that client's notebook, not ours; entry eight explains the difference and why it matters to you.
2.Entry — whose bench this is
Controller
Entered 7 August 2026. Changes if the registered office or the address changes.
TMLZEE GROUP LTD decides why and how the personal data described in most of these entries gets used, which under the UK GDPR makes the company its controller. The company is registered in England and Wales with the number 17061773, and its registered office is Unit 15 Swift Industrial Estate, Kingsteignton, Newton Abbot.
Everything about data reaches us at [email protected]. It is read by the people who run the company rather than by a ticket queue, and there is no other channel you need routing through. Put "Data protection" at the front of the subject line and it goes to the top of the pile the same morning.
Nothing in the law obliges a company this size to appoint a data protection officer, and appointing one would only put a title between you and whoever actually holds the file. Responsibility for what is written here sits with the directors, who answer to the address above and cannot pass the question along.
We work from the United Kingdom and are established here, so no representative under Article 27 is needed for a company in our position.
3.Entry — two hats, and how to tell which one is on
Controller and processor
Entered 7 August 2026. The most useful entry in the notebook, so it sits early.
Software firms hold personal data in two quite different capacities, and confusing them is how people end up asking the wrong company for their file.
The first is our own housekeeping: your enquiry, the invoice with your name on it, the note of what was agreed at a review. Nobody instructs us on any of that, so the decisions are ours and the responsibility is ours. Entries four through seven, and nine onwards, are written from that position.
The second is work done to order. Where a client hires us to build or look after a system, whatever personal data sits inside it was gathered by them, for their own purposes. We touch it only to do the job, only in the ways the signed agreement lets us, and we stop when we are told to stop. That makes us a processor for that data, and the client remains the controller of it. Entry eight is the whole of that position.
The practical test is simple. Ask who chose to collect the data in the first place. If it was us, write to us. If it was the organisation whose product you were using, write to them, and tell them we are their supplier if it helps them find the record.
4.Entry — what the website writes down
Controller
Entered 7 August 2026. This entry moves the day anything new is added to the page head.
tmlzee.co.uk is a set of flat files. Nothing here counts you, scores you, or remembers that you came back. There is no form to submit, no login, no measurement script, no advertising tag, no chat bubble and no embedded player. The cookie notice sets out what may be written to your device: one security cookie from our host, and not a thing from us.
What cannot be avoided is the request itself. To send you a page, your browser has to say where to send it, and that message carries an address and a few technical details with it. Those requests land at Cloudflare, which serves the site and shields it from attack, and they produce log lines there.
Two typefaces are fetched from Google's font service as a page renders, which is a request your browser makes directly. We never see it and hold nothing from it. Block those hosts and the pages stay perfectly readable in whatever face your system substitutes, because the layout was drawn on that assumption.
| What is recorded | Where it comes from | Why it exists | Ground | Who holds it |
|---|---|---|---|---|
| Address of the requesting device, time, path asked for, response code, size served, browser string | Your browser, caught at the edge as the page is served | Getting the page to you and working out why, on the days it fails | Legitimate interests, Article 6(1)(f): keeping a site that serves pages and can be mended | Cloudflare, Inc. |
| Rate and shape of requests, automated-client scoring, records of what was turned away | Derived by our host from the stream of requests | Keeping the site standing through flooding and automated abuse | Legitimate interests, Article 6(1)(f): keeping a public service available and secure | Cloudflare, Inc. |
| Address, referring page and browser version, disclosed at the moment a face is downloaded | Your browser, going straight to the font host | Rendering the site in the faces it was drawn in | Legitimate interests, Article 6(1)(f): a legible page that looks the same on every machine | Google Ireland Limited and Google LLC |
None of the third row reaches us. It is a conversation between your machine and Google's, and we mention it because you deserve to know it happens rather than because we can do anything with it.
5.Entry — correspondence, kept and destroyed
Controller
Entered 7 August 2026. Reviewed whenever the retention shelf in entry twelve is cleared.
With no form on the site, an enquiry only arrives one of two ways: you write to us, or a colleague of yours passes on your details while a piece of work is being discussed. There is no third route, and no list we bought.
What we then hold is what you sent plus what we wrote back. A name, an address to reply to, a phone number if you volunteered one, the organisation you work for, and the substance of the problem you described. If the conversation turns into a quote, the quote and its assumptions are filed with the thread, because a year later both of us may need to see what was actually offered and on what basis.
| What we hold | Why we hold it | Ground | Where it sits |
|---|---|---|---|
| Your name, reply address, telephone if given, employer and role | Replying, and knowing who is at the other end of it | Article 6(1)(b) if you are personally heading for a contract with us; otherwise Article 6(1)(f), our interest being that questions put to this company get answered | Our email provider |
| The text of the message, anything attached, the description of the problem | Understanding the job well enough to say something useful about it | Article 6(1)(b), work done at your request ahead of any contract | Our email provider |
| Scope notes, estimates, the assumptions under an estimate, dates and outcome | Quoting, and being able to show later exactly what was quoted | Article 6(1)(f): keeping a straight record of our own commercial offers | Email and document storage |
| Notes of calls and meetings, the running thread of messages | Continuity, in a conversation that may run for months | Article 6(1)(f): not making you explain the same thing twice | Email and document storage |
Three things never happen to an enquiry. It does not become a marketing list. It is not topped up with details bought from a data broker. It is not handed to another business for that business's own use. Where a conversation stops, the thread comes off the shelf on the schedule in entry twelve.
6.Entry — clients on the books
Controller
Entered 7 August 2026. Read alongside entry eight, which covers a different pile entirely.
When an organisation engages us, we deal with named people inside it: whoever signs, whoever answers technical questions, whoever will run the system afterwards. Their working details are held for the length of the engagement and then for as long as a dispute could still be raised about it.
This pile is small and dull, which is the intention. Names, roles, work addresses and numbers, the office someone sits in. Alongside it sits the engagement record itself: the signed agreement, the scope, every change request, the log of decisions taken with the reason attached, review notes, and the handover pack.
The ground for the individual who signs in their own name is Article 6(1)(b), because the contract is with them. For everybody else the ground is Article 6(1)(f): a contract with a company cannot be performed without talking to the people employed by it. Keeping the record after the work ends rests on the same provision, this time so that either side can prove what was agreed if it ever comes to that.
Financial records sit apart from all of this, because company and tax law says how long they must be preserved and our preferences do not come into it. Entry twelve gives the periods and the provisions behind them.
7.Entry — suppliers, and letters asking for work
Controller
Entered 7 August 2026. Short, because both piles are small.
Suppliers and subcontractors are companies, but the contact details we hold for them belong to people. We keep the name, work address and telephone of whoever we deal with, the contract itself, and the invoices. The ground is Article 6(1)(b) or (f) depending on whether the person contracts personally, and the invoices are held under Article 6(1)(c) because the law requires accounts to be preserved.
People also write asking whether we need anyone. If you send a curriculum vitae we will read it and reply, and the ground is our interest in answering correspondence someone chose to send us. An application nobody asked for is not filed away against some future vacancy unless you ask for that and we agree to it; ask for it gone sooner and it goes the day your message lands.
Nothing in either pile is meant to include health data, trade union membership, beliefs, sexual orientation, biometric or genetic data, or any of the other categories the law treats as special. If such a detail arrives anyway, in the body of a covering letter or an attachment, we take it out of the record rather than build a lawful basis around a detail we never asked for.
8.Entry — the data inside what we build
Processor
Entered 7 August 2026. The entry to read if you were a user of something we built for somebody else.
Building a system means being able to see what is in it. A customer record, an order history, an address book, a set of user accounts: whatever the client's product holds, we can reach some of it while we are working on it, and pretending otherwise would be untrue.
Our position on that data is fixed. It is the client's. We move on written instruction, we touch it for the job we were hired for and for nothing else, and it is never material for ends of our own. If a client ever instructed us to do something with it that we thought broke the law, we would say so in writing and decline that instruction.
Before any such work starts, a written agreement under Article 28 of the UK GDPR sets out the subject matter, the length, the kinds of data and people involved, and what we must do at the end. Ours also nails down these points, in writing, every time:
- confidentiality binding every individual who is given access, by contract rather than by assurance;
- security measures agreed before access is granted, not described afterwards;
- no further supplier brought in unless the client agrees to it in writing, with notice ahead of any change;
- help with a request from an individual, given at the client's direction and within a period that leaves the client able to meet its own deadline;
- reporting an incident to the client without delay, so that the client can decide about notifying the regulator;
- deletion or return of everything at the end, on the client's choice, with a written confirmation of what was destroyed;
- the client's right to inspect what we do, on reasonable notice.
In practice we take a further step that keeps most of the question from arising. Development and testing run on manufactured or masked data wherever the work allows it, so live records are touched only where a fault genuinely cannot be reproduced without them, and then briefly, with the client's knowledge.
If you were a user of a product we helped build and you want your data seen, corrected or removed, the organisation you dealt with holds that decision, not us. Ask them. If they route the request to us, we will do the work they instruct and confirm it back to them.
9.Entry — the grounds, set out where they can be checked
Controller
Entered 7 August 2026. Written to be argued with.
Every use of personal data described above stands on one of four grounds, and it is worth saying plainly which does what. Article 6(1)(b) covers a contract with you or steps you asked for before one. Article 6(1)(c) covers what a statute forces us to do, mostly around accounts and tax. Article 6(1)(f) covers an interest of ours that does not run over the top of you. Consent, Article 6(1)(a), we barely use, because for the handful of things we do it would be a fiction dressed up as a choice.
Where the ground is our own interest, the law wants the reasoning shown rather than asserted. Here it is, one line per job.
| The job | The interest | Why it does not run over you |
|---|---|---|
| Serving pages and diagnosing failures | A website that stays up and can be fixed | Technical, brief, never linked by us to a named person, and nothing is built from it |
| Turning away floods and automated abuse | Availability and security of a service people asked for | The measure protects readers as much as it protects us, and the records are held by our host for days, not years |
| Replying to a business enquiry | Answering the person who wrote to us | You started the conversation and expect a reply; the details are the ones on your own signature block |
| Filing quotes, decisions and reviews | An accurate account of what was offered and agreed | Confined to the commercial substance, and it protects the client's version of events as much as ours |
| Holding client contact details for the length of a job | Performing the contract we signed with the employer | Work details, used only for the work that person is employed to do |
| Keeping engagement papers after completion | Being able to bring or answer a claim | Held to the limitation period and no longer, and never repurposed for selling |
| Reading an approach nobody asked for | Courtesy to someone who took the trouble to write | They chose to write to us, and it is destroyed quickly once it leads nowhere |
Two of those you can challenge outright. Any use of your data to market at you must stop the moment you say so, with no balancing exercise and no argument from us. For the rest, you can object and put your reasons, and we then either stop or show you why the grounds we have outweigh yours. Entry fourteen explains how to make that objection.
10.Entry — other hands on the work
Controller and processor
Entered 7 August 2026. Amended before a new supplier is switched on, never after.
Nobody runs a company alone, and a supplier who handles data on our behalf is part of how your data is handled. The list is short because we have kept the business deliberately light on dependencies, and it is accurate as at the date on this entry.
| Who | What they do for us | What reaches them | Where the work happens | Cover for leaving the UK |
|---|---|---|---|---|
| Cloudflare, Inc. | Holds and serves this site, terminates the encrypted connection, absorbs attacks | The request records and security signals in entry four | An edge network spanning the United Kingdom, Europe and the United States | The UK Addendum, applied to the EU clauses inside their processing terms |
| Google Ireland Limited and Google LLC | Serve two typeface files straight to your browser | Only what your own browser discloses in asking for the file; nothing passes through us | Ireland and the United States | Not our transfer to make. Google answers for it to the browser that asked |
| Our contracted email and document host | Business mail, and storage of proposals and engagement papers | Everything described in entries five, six and seven | Named in writing to anyone who asks | Named in writing to anyone who asks |
There is no measurement platform behind this site, no advertising network, no sales database, no automated marketing tool and no service that fills in details about you from elsewhere. Should any of that ever be adopted, this table gets rewritten first and the change goes live second.
Separately from suppliers, a few organisations receive data because the relationship or the law requires it, and they answer for it themselves rather than acting on our instruction. Our accountant, for statutory accounts and returns. Our bank, to move money. Companies House and HM Revenue and Customs, when a filing falls due. Solicitors and insurers, if advice is needed or a claim is made. A buyer, if the business or a part of it is ever sold, in which case the records move with the part of the business they belong to and you would be told. Courts, regulators and the police, where an order or a statutory duty applies; we check that any such demand is properly made before acting on it, and we tell the person concerned unless we are forbidden to.
Your data has never been sold, is not for sale, and there is no arrangement anywhere in this company under which it could be.
11.Entry — work that crosses a border
Controller and processor
Entered 7 August 2026. Reviewed if a supplier moves where it processes.
Chapter V of the UK GDPR treats sending personal data out of the country as something that needs justifying rather than something that just happens. Three justifications exist, and we use the first two.
The simplest is that the destination has been recognised by the United Kingdom as offering equivalent protection. Where a supplier keeps everything inside those countries, that recognition is the whole answer and nothing more is needed.
Where it has not been recognised, which in practice means the United States, we lean on the contractual instruments the Information Commissioner has issued using the power in section 119A of the Data Protection Act 2018. One is the International Data Transfer Agreement, the IDTA, a standalone United Kingdom contract for use where there is nothing European to build on. The other is the UK Addendum, a few pages that sit on top of the EU standard contractual clauses and bend them to United Kingdom law; it is the route taken more often, since most international suppliers already publish those clauses in their own processing terms. Our arrangement with Cloudflare runs on the addendum.
Signing a document is not the end of the exercise. Before either instrument is leaned on, we work through what the destination's law and practice mean for this particular data: whether authorities there could reach it in ways nobody here would accept, how sensitive it is, and which technical measures narrow the exposure. For the request records this site produces, that assessment is short: the data is technical, it lives briefly, we never attach a name to it, and it is encrypted the whole way.
On client work we move nothing across a border on our own initiative. A crossing happens on the client's instruction and on nothing else, and the instrument covering it is named in the processing agreement before anything travels. Absent that instruction, client data stays in this country or in a recognised one.
If a transfer touches you, you are entitled to see the safeguard it runs on. Ask at [email protected] and it comes back to you, with commercial terms that form no part of the protection struck out.
12.Entry — time on the shelf
Controller, except the last row
Entered 7 August 2026. These numbers move only if the law under them moves.
Data is not to be kept for longer than the job needs, and a schedule of periods with no reasons beside them is just a list of numbers somebody invented. Each row below says what holds it up.
| Record | Held for | Counted from | What fixes the period |
|---|---|---|---|
| Invoices, payments and the rest of the accounting record | 6 years | Close of the financial year concerned | Company law sets a floor for preserving accounting records and tax law wants the papers behind a return kept longer; six years is the settled United Kingdom practice and lines up with the ordinary limitation period |
| Signed agreements and the engagement file behind them | 6 years | The day the engagement finished or was ended | Six years is how long an ordinary contract claim stays alive under the Limitation Act 1980, and a file destroyed in year three leaves us defenceless against a claim brought in year five |
| Anything signed as a deed | 12 years | The day it completed or was ended | The same Act allows twice as long for a claim on a specialty |
| Enquiries that went nowhere | 12 months | The last message either side sent | Long enough for a stalled conversation to pick up naturally, short enough that no dormant prospect list quietly accumulates |
| Quotes that were not taken up | 24 months | The day the quote went out | Buyers often come back with the same requirement eighteen months on, and both sides are better off able to see what was said the first time |
| General business correspondence | 24 months | Whichever message came last | About as long as a business conversation stays alive, without hoarding mail out of habit |
| Letters from people asking about work | 6 months | Arrival | Time to reply and to think again, with no case for holding a curriculum vitae nobody requested beyond that |
| Requests about data, and what we did about them | 3 years | The day the request was closed | A regulator may ask how a request was dealt with, and answering that means keeping the dealing with |
| Incident records | 6 years | The date of the incident | Every incident has to be documented well enough for the regulator to check the judgement made, and six years keeps it with everything else |
| Request and security logs at our host | Days to weeks, set by the provider | The request | Operational records, useful for immediate diagnosis and abuse prevention only; we have never asked for them to be kept longer |
| Personal data we hold for a client | As long as the engagement, then destroyed or handed back | The client's instruction at the close | The choice is the client's to make as controller, and the agreement records which way they went |
When a period runs out the record is deleted. Where a copy survives inside a backup that cannot be opened and edited selectively, the data is put beyond ordinary use and goes when that backup is overwritten in the normal cycle, which never exceeds ninety days.
13.Entry — locks, keys and the state of the workshop
Controller and processor
Entered 7 August 2026. Tightened whenever a tool or a supplier changes.
Security has to be proportionate to what is being protected, and what we hold is a modest volume of business correspondence plus whatever access a live engagement requires. These are the measures actually in force, described so that you could check them rather than admire them.
- Every page here travels encrypted, and browsers are instructed to refuse an unencrypted connection to this domain at all.
- A second factor is required on mail, document storage, source control and the hosting account, without exception for convenience.
- Every machine used for company work has its disk encrypted, so a stolen laptop is a lost laptop rather than an incident.
- Credentials are generated and stored in a password manager, one per service, never shared between people or between services.
- Access to a client system is granted for a named engagement and withdrawn when that engagement closes, rather than accumulating.
- Engagements are kept apart from one another, so reaching one client's material never puts another client's within reach.
- This website has no database, no code running on the server and no administrative login, which removes several whole categories of attack instead of defending against them.
- Response headers on every page restrict framing, content-type guessing, referrer leakage and the origins a page may load anything from.
14.Entry — your rights, and the shortest way to use them
Controller. Where entry eight applies, ask the client instead
Entered 7 August 2026. The entry we would most like people to actually use.
Write to [email protected], or send paper to the registered office if you would rather. Tell us what you want done. You do not have to name the right you are exercising or quote an article at us; describing the outcome you want is enough, and working out which provision applies is our job. Nothing about this costs you anything.
Proving who you are. Handing your file to somebody else would itself be a breach, so we have to be reasonably sure. An email from an address already in the thread usually settles the question. Otherwise we ask for the smallest thing that ties you to the record, and a photograph of your passport is not it for a routine request. The clock does not start until we can tell who you are.
How long we take. One month from a request we can act on. Where a request is genuinely complicated, or several arrive together, that can run on by a further two months; if the extra time is needed we say so inside the first month and give the reason.
When we can say no. A request that is plainly excessive or repetitive can be refused or charged for, and several rights have their own limits, which are set out below. Schedule 2 of the Data Protection Act 2018 also restricts some rights, for instance where legal advice is privileged. A refusal always comes with the reason, a note that you can take it to the regulator, and a note that a court can be asked to intervene.
The rights themselves
- To be told what happens to your data. This notebook is how we do it. If any entry is unclear, ask, and you will get an explanation rather than the same paragraph quoted back.
- To get a copy. You may have confirmation of whether we hold anything, a copy of it, and the surrounding detail: purposes, categories, who else saw it, how long it stays, where it came from. The first copy is free and normally arrives as a file. Where a document also contains somebody else's data, their part may be covered up, since your right cannot be exercised at their expense.
- To have it corrected. Wrong details get fixed promptly, and incomplete ones completed. If the wrong version went to anyone else, we tell them, and we tell you who they were. Where the disagreement is about an opinion rather than a fact, your account is filed next to ours rather than replacing it.
- To have it erased. Where data is no longer needed, or was processed unlawfully, or an objection has succeeded, it goes. The right has edges. We refuse, with the reason attached, where a statute obliges us to keep something, usually an accounting entry, or where the papers might be needed for a claim on either side. In plain terms, we can usually delete the correspondence but not the invoice.
- To have it frozen. If you dispute the accuracy of something, or object and are waiting on our answer, you can require us to keep the record but stop using it while the question is open.
- To object. Any processing resting on our own interests can be objected to, with your reasons. We then stop, or we set out the grounds that we say outweigh yours. Against marketing, an objection is absolute and takes effect immediately.
- To take it elsewhere. Where you gave us data yourself and we hold it under a contract or your consent, and it sits in a system rather than in prose, you can have it in a machine-readable file or have it sent directly to another provider where that is technically workable.
- To withdraw consent. Wherever consent is asked for, withdrawing it is as easy as giving it was, and whatever happened before the withdrawal stays lawful.
- Not to be judged by a machine. Entry fifteen covers this, and the short version is that we do not do it.
- To complain about us to the regulator. Set out below.
Taking it further
We would rather you told us first, because most complaints are quicker to fix than to escalate, but you are not obliged to and nothing is lost by going straight to the regulator. The supervisory authority here is the Information Commissioner's Office, reachable at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, on 0303 123 1113, and through the complaint form published at ico.org.uk.
The courts are a separate route and stay open whichever way you go: a person who suffers damage from a breach of the legislation may bring a claim for compensation.
15.Entry — machines that decide things
Controller
Entered 7 August 2026. Would need rewriting before any such tool was ever adopted.
No decision about you is taken by software running on its own here. Quotes are priced by people, work is accepted or declined by people, and nothing scores or ranks the individuals who write to us. There is no profiling of visitors, prospects or clients, and the site has no mechanism that could perform any.
Where the law gives you rights against being subjected to a decision made purely by automated means with a serious effect on you, those rights have nothing to bite on in this company. If that position ever changed we would describe the logic involved, what it means for you, and how to demand a human being, in this entry, before switching anything on.
16.Entry — what we send you, and what we never will
Controller
Entered 7 August 2026. Unchanged as long as there is no mailing list.
There is no newsletter, no campaign, no drip sequence and no list. Mail from us is either an answer to something you sent or traffic about work already running: the proposal you asked for, an invoice, a warning that Thursday's release is going out.
PECR governs marketing by electronic means, and its rules matter even where, as here, there is nothing much to regulate. Should we ever write to past clients about a related service, that would rest on the narrow allowance the rules make for an existing customer relationship, every message would carry a one-click way out, and the choice would be honoured on the day it is made rather than at the end of a cycle. Individual subscribers would be asked first.
The registered office address, the company number and the trading name appear on business correspondence because company law requires them, which is a disclosure obligation rather than marketing.
17.Entry — when something goes wrong
Controller and processor
Entered 7 August 2026. Written in advance, because nobody thinks clearly on the day.
An incident is any security failure that leads to personal data being destroyed, lost, altered, disclosed or reached by somebody who should not have reached it, whether by accident or by attack. A laptop left on a train counts. A message sent to the wrong client counts. A supplier being compromised counts.
What happens then is set down in advance so that it does not have to be invented under pressure:
- Contain it. Revoke the credential, pull the access, isolate the machine, stop the process that is leaking.
- Write down what is known and when it became known, and keep writing as the picture changes. The log is started in the first hour.
- Judge the risk to the people affected, on what could actually happen to them, not on how embarrassing it is for us.
- Where there is a real risk to people, tell the Information Commissioner within seventy-two hours of becoming aware, including where the picture is still incomplete, and follow up as it fills in.
- Where the risk to individuals is high, tell them directly and in ordinary words: what happened, what it means for them, what has been done about it, what they should do next.
- Afterwards, work out what let it happen and change that, then record the change against the incident.
Every incident is documented whether or not it is reportable, including the ones we decide not to report and the reasoning for that decision, because that reasoning is exactly what a regulator would want to test.
Where the failure is on a client's system that we look after, the client makes the notification decisions as controller, and our obligation is to tell them without delay and give them everything they need to make those decisions properly.
18.Entry — applications published on the stores
Controller for our own; processor for a client's
Entered 7 August 2026. Rewritten before any listing of ours is ever submitted.
Mobile work usually ships from the client's own store account and under the client's name, so the notice governing it is theirs rather than this one. This entry applies where a mobile or web application is published under the name TMLZEE GROUP LTD, and it states the standing rules for how one of ours is built.
Permissions are requested at the moment the feature needs them, never in a batch at first launch, and each request explains what it is for in the same sentence that asks for it. Declining a permission never blocks the rest of an application; the feature that needed it is simply unavailable and says so. Camera, microphone, location, contacts, photo library and notification access are each treated that way, and any of them can be withdrawn afterwards in the operating system settings without uninstalling anything.
App Tracking Transparency on iOS decides whether an app may follow somebody out into other companies' apps and sites. We do not build applications that do that, so an application of ours has no reason to raise the tracking prompt, and if one ever did, a refusal would be respected in full rather than routed around by other means.
The Data Safety declaration on Google Play tells somebody, before they install anything, what an app gathers and what it hands on. Ours is written from the same source of truth as this notebook, so the store card, the in-app text and this page say the same thing. Where they ever disagreed, that would be a defect to fix rather than a gap to argue over, and the stricter statement would apply until it was fixed.
An application of ours collects only what its features actually need, keeps as much on the device as the design allows, and identifies an installation by a value that means nothing outside that application. No advertising identifier is read, no software development kit is embedded for advertising or analytics, and nothing is passed to a data broker.
19.Entry — deletion of data, and closing an account
Controller and processor
Entered 7 August 2026. Deliberately the least procedural entry here.
Two routes exist and both work. Ask us in writing, at [email protected], and say what you want removed; a sentence is enough. Or, where you hold an account in an application published under our name, use the deletion control inside the account section of that application, which does the same thing without anyone having to read your message first.
Once we are satisfied who you are, deletion of data happens within thirty days and normally inside a week. You get written confirmation of what went, and of anything that had to stay behind with the reason attached.
What stays behind is short and specific. Invoices and the accounting entries around them, because company and tax law require them for six years and no request can shorten that. A bare note that a deletion was asked for and carried out, because without it we could not show that it was. Anything genuinely needed for a live claim or dispute, held only while that lasts. Copies inside backup media, which are not opened to remove a single record but are excluded from use and disappear when the backup cycle overwrites them, within ninety days.
Where the account belongs to a system we run for a client, the deletion decision is the client's. Send it to them; if they instruct us, we carry it out and confirm it back to them the same way.
20.Entry — children
Controller
Entered 7 August 2026. Would be rewritten before any work aimed at young people began.
This is a business-to-business company. The website is written for people buying software for an organisation, we do not offer anything to children, and nothing here is designed to appeal to them.
We therefore do not knowingly hold data about anyone under 18 in our own records. If a child's details reach us anyway, in an attachment or a stray message, they are removed rather than filed. If you believe we hold something about a child, write and it will be dealt with as a priority.
Where a client's product is meant for children or is likely to be used by them, the standards that apply to services for young people are a design question for that product, and we raise them at the start of the work rather than at the end. A system built for that audience should collect less, default to the private setting, and avoid nudging a young user into giving up more. Those calls belong to the client as controller, and our advice goes in writing so the record shows what was urged.
21.Entry — later entries
Controller
Entered 7 August 2026. The entry that governs all the others.
A notebook that gets quietly rewritten is worth nothing. When practice at the bench changes, its entry is rewritten and the date at the head of the page moves, so that a change is visible rather than silent.
Where a change is substantial, a new supplier touching your data, a new purpose, a new country involved, this page says so outright rather than leaving you to notice. Where the change would need your permission, we will ask for it before the change takes effect, not afterwards.
An older version of any entry can be sent to you on request, so that you can see what the position was on a date that matters to you. Questions about anything above go to [email protected] and are answered by the people who wrote it.