Privacy Policy
Effective date: 7 August 2026. Version 1.0. This is the first published version of this policy.
1. Who we are and what this policy covers
This policy is published by THE PATHFINDER LABS CORPORATION LIMITED, a company registered in England and Wales with company number 17061706 and a registered office at 30 Pettley Gardens, Romford, England, RM7 9AB. In this policy, “we”, “us” and “the company” mean that company. There is no group, no parent and no overseas branch. The company was incorporated on 1 March 2026 and is an applied research and prototyping studio.
This policy covers personal data handled in connection with:
- the website at pathfinderlabs.co.uk;
- email correspondence sent to or from hello@pathfinderlabs.co.uk;
- the administration of engagements, including proposals, contracts and invoices;
- material a client asks us to work with during an engagement; and
- any software application we publish, including on the Apple App Store and Google Play. As at the effective date of this policy we have published none. Section 20 sets out the rules that will apply to the first one.
“Personal data”, “controller”, “processor”, “processing” and “special category data” carry the meanings given to them in the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
We have not appointed a Data Protection Officer. A company of this size is not required to appoint one under Article 37 of the UK GDPR, and we would rather say that than imply a role exists. Responsibility for data protection sits with the director, and correspondence should go to hello@pathfinderlabs.co.uk.
Registration with the Information Commissioner’s Office: [TO CONFIRM: ICO data protection fee registration number, or confirmation that an exemption applies]
2. How to read this policy: our two roles
The law treats two situations very differently, and this policy keeps them apart from here on.
Where we are the controller, we decide what personal data is collected and why: this website, our email, proposals, contracts, invoices, suppliers, recruitment, and any application we publish under our own name. Part 1 deals with those.
Where we are the processor, a client decides and we act on that client’s written instructions, for example a database extract handed to us to test whether a technique works. Part 2 deals with those. There the client is the controller, and their privacy notice, not this one, tells you why the data was collected.
Every section below is labelled with the role it relates to, using a marker like the one at the start of section 4.
3. Which parts apply to you
Find yourself in the first column.
| If you are | Our role | Read |
|---|---|---|
| Someone reading this website | Controller | Sections 4, 14 to 19 |
| Someone who has emailed us | Controller | Sections 5, 10, 16, 17 |
| A named contact at a client organisation | Controller | Sections 6, 10, 16, 17 |
| A contact at one of our suppliers or advisers | Controller | Sections 7, 16, 17 |
| Someone who has applied to work with us | Controller | Sections 8, 16, 17 |
| A user of an application we publish | Controller | Sections 9, 20, 21 |
| A person whose data appears in material a client gave us | Processor | Sections 11 to 13, and your own controller’s notice |
Part 1. Where we are the controller
In this part we decide the purposes and means of processing, and we answer to you directly for it.
4. Visitors to this website
Role: controller
This is a static website with no accounts, no forms, no comment system, no advertising network, no analytics product and no social media embeds. We set no cookie of our own, and there is no consent banner because there is nothing to consent to. The Cookie Notice gives the full detail, including the security cookies our host may set.
The site is served by Cloudflare Pages, which records technical connection data at its edge. We do not receive individual records; we see aggregated request counts in the hosting dashboard.
The table below scrolls sideways.
| Category | Example fields | Source | Purpose | Lawful basis | Retention | Recipients |
|---|---|---|---|---|---|---|
| Connection and request data | IP address, timestamp, requested URL, HTTP status, user agent, approximate country | Collected automatically when your browser requests a page | Serving the page, blocking automated abuse, keeping the site available | Article 6(1)(f). Interest: keeping a public website online and defended against automated attack. | The host’s standard log period, measured in days | Cloudflare, Inc. as processor |
| Aggregate request counts | Requests, bandwidth, error rates, country totals | Derived by the host from the row above | Knowing whether the site works and roughly how much it is read | Article 6(1)(f). Interest: operating a website we can maintain sensibly. | While the hosting account exists | Cloudflare, Inc. as processor |
| Security cookies, if set | Cloudflare bot management and challenge identifiers | Set by the hosting edge, not by us | Telling a person apart from an automated client during an attack | Regulation 6(4) PECR, strictly necessary for security, with Article 6(1)(f) | 30 minutes to one year depending on the cookie, listed in the Cookie Notice | Cloudflare, Inc. as processor |
5. People who email us
Role: controller
Email is the only route into this company, so the mailbox holds most of the personal data we have about people outside the business: whatever you put in the message, plus the technical headers that come with it.
| Category | Example fields | Source | Purpose | Lawful basis | Retention | Recipients |
|---|---|---|---|---|---|---|
| Enquiry correspondence | Name, email address, employer, job title if given, message content, attachments | You, directly | Reading your enquiry and replying to it in context | Article 6(1)(f). Interest: answering people who approach the business about its services. | 24 months from the last message, unless it becomes an engagement | Our email provider as processor |
| Message metadata | Addresses, timestamps, message identifiers, spam scores, routing headers | Generated automatically by mail systems | Delivering mail, filtering spam, tracing delivery failures | Article 6(1)(f). Interest: running a mailbox not overwhelmed by unsolicited mail. | 24 months, alongside the message | Our email provider as processor |
| Data protection requests | Identity details, the request, our response and reasoning | You, directly | Handling the request and showing we handled it correctly | Article 6(1)(c) to handle it; Article 6(1)(f) to retain the record, the interest being demonstrable compliance. | Six years from closure | Email provider as processor; the ICO on complaint |
Email provider: [TO CONFIRM: the name and country of the email hosting provider for hello@pathfinderlabs.co.uk, to be added to the sub-processor table in section 14]
Please do not send special category data, financial credentials or anything under a confidentiality obligation in a first email. If material of that kind is needed, we will agree a route for it before you send it.
6. Client contacts and contract administration
Role: controller
When an engagement is agreed we hold information about the individuals we deal with at the client organisation, plus the commercial records that go with the work. This is separate from anything inside the client’s own material, which Part 2 covers.
| Category | Example fields | Source | Purpose | Lawful basis | Retention | Recipients |
|---|---|---|---|---|---|---|
| Contact details of the people we work with | Name, job title, work email, work telephone, employer | You, your colleagues, or your organisation’s website | Running the engagement, arranging meetings, delivering findings | Article 6(1)(b) if you contract with us personally; otherwise Article 6(1)(f), the interest being administration of a contract with an organisation through its named staff. | Six years from the end of the engagement | Email provider, and a document storage provider where used |
| Proposals, scopes and signed agreements | The written question, stages, prices, dates, signatures | Us and the client jointly | Agreeing what will be done, and proving what was agreed | Article 6(1)(b), and Article 6(1)(f) for the evidential copy, the interest being defence of a legal claim. | Six years from the end of the engagement | Our professional advisers if a dispute arises |
| Invoices, payments and accounting entries | Billing name and address, invoice number, amount, dates, reference | The client and our bank | Billing, collecting payment, statutory accounts and tax returns | Article 6(1)(c), legal obligation under the Companies Act 2006 and tax legislation. | Six years from the end of the accounting period | Our accountant, our bank, HM Revenue and Customs |
| Engagement working notes | Meeting notes, decisions, questions and who asked them | Us, during the work | Doing the work and writing an accurate findings memo | Article 6(1)(f). Interest: a written record that is accurate about what was decided and by whom. | Six years from the end of the engagement | Nobody outside the company unless the client asks |
7. Suppliers, advisers and contractors
Role: controller
We hold names, business contact details, bank details where we pay them, contracts and invoices for the people and firms that supply the company, including any contractor engaged to help on a piece of work. The lawful basis is Article 6(1)(b) where the supplier is an individual contracting with us and Article 6(1)(f) otherwise, the legitimate interest being administration of the company’s own supply arrangements. Payment records are kept for six years from the end of the relevant accounting period under Article 6(1)(c); other supplier records for six years from the end of the relationship.
Where a contractor will touch client material, they are engaged under a written agreement containing confidentiality obligations and the sub-processor terms required by Article 28 of the UK GDPR, and the client is told before it happens.
8. Job applicants and speculative approaches
Role: controller
We are not recruiting and there is no application system on this website. If you write to us about work anyway, we hold your message, your curriculum vitae if attached, and any notes we make. The lawful basis is Article 6(1)(f), the interest being consideration of people who offer to work with a small company; where an application progresses towards an offer, Article 6(1)(b) also applies. Unsuccessful application material is kept for 12 months from our last message so that we can explain a decision, then deleted, and deleted sooner if you ask.
We do not carry out criminal record checks, credit checks or automated screening of applicants.
9. Users of any application we publish
Role: controller
At the effective date of this policy THE PATHFINDER LABS CORPORATION LIMITED has published no application on the Apple App Store, on Google Play or anywhere else, and holds no user accounts, so no user data of this kind exists.
Section 20 sets out the commitments that will apply to the first application, including the permission table and the store declarations. This section will be replaced with a data inventory in the format of sections 4 to 6 before any application is submitted for review, and the effective date above will change on the same day.
10. The legitimate interests we rely on, named
Role: controller
Article 6(1)(f) requires an interest to be identified, to be necessary, and to be balanced against your rights. We rely on it in five places, with the balancing outcome stated.
- Keeping a public website online and defended. A site with no protection is taken offline by automated traffic. The data is technical, held briefly and not used to build a profile.
- Answering people who email us. A message cannot be answered without processing it. You chose to write, you know what you sent, and you can ask us to delete the thread.
- Administering a contract held with an organisation through its named staff. Contracts are performed by people. The data is limited to work contact details and business correspondence.
- Keeping evidential copies of agreements and correspondence for six years. The limitation period for a simple contract in England and Wales is six years and a defence needs documents. The records sit unused unless a claim arises.
- Considering people who ask about work. An application cannot be read without processing it. Retention is short and deletion on request is immediate.
We do not rely on legitimate interests for marketing. We send no marketing email, operate no mailing list and buy no contact lists. If you ask to be told when our first experiment is published, we send one message about that and nothing else, on your consent under Article 6(1)(a), which you withdraw by replying.
Part 2. Where we are the processor
In this part a client decides what happens and we follow written instructions. That client, not this company, is the controller.
11. Client material we process on instruction
Role: processor
An engagement sometimes requires material that contains personal data, most often an extract used to find out whether a technique produces a usable result on real records rather than invented ones. When that happens:
- the client remains the controller and decides the purpose;
- we process only on the client’s documented instructions, as Article 28(3)(a) requires;
- a written data processing agreement containing the Article 28(3) terms is signed before any material is transferred;
- we ask the client to minimise or pseudonymise the extract and send only the fields the question needs;
- the material is deleted within 30 days of the end of the engagement unless the client instructs otherwise in writing; and
- we name the sub-processors that will have access before the material arrives, and add none during an engagement without written approval.
If a client instruction appears to breach the UK GDPR or the Data Protection Act 2018, we say so in writing and do not act on it, as Article 28(3) requires.
12. What we will not do with client material
Role: processor
We do not use client material to improve our methods, train a model, build a product, seed a demonstration, or illustrate a published experiment. We do not sell it, share it with another client, or keep a copy after deletion is due. Nothing in an engagement gives us a licence to any of that, and we will not ask for one as a condition of doing the work.
13. If your data reached us through a client
Role: processor
If an organisation gave us records that include information about you, that organisation decided to do so and is answerable for it. We cannot lawfully act on your request about that data without their instruction, because we are not the controller.
What we will do, if you write to hello@pathfinderlabs.co.uk, is tell you within five working days whether we hold material from that organisation, pass your request to them without delay, and confirm that we have done so. If you tell us they have not responded, we will say so to them in writing. You can also complain to the ICO about the controller directly, using the details in section 18.
Part 3. Applies to both roles
Everything below applies whether we are acting as controller or as processor, unless a paragraph says otherwise.
14. Recipients and sub-processors
Role: controller and processor
We are a small company and we keep the list of third parties short on purpose. Every organisation named below is engaged under a written contract containing the obligations required by Article 28 of the UK GDPR.
The table below scrolls sideways.
| Organisation | What it does for us | Personal data it can access | Where processing happens | Transfer mechanism |
|---|---|---|---|---|
| Cloudflare, Inc. | Serves this website through Cloudflare Pages and filters automated abuse at the edge | Connection data in section 4. No account data, as the site has no accounts. | United States, with edge processing in the UK and elsewhere | UK Addendum to the EU Standard Contractual Clauses, in the provider’s data processing terms |
| [TO CONFIRM: email hosting provider] | Hosts the mailbox for hello@pathfinderlabs.co.uk | All correspondence described in section 5, and any attachment sent to us | [TO CONFIRM: country of processing] | [TO CONFIRM: adequacy, IDTA or Addendum, once the provider is settled] |
| [TO CONFIRM: accounting software and accountant] | Bookkeeping, invoicing and statutory accounts | Billing names and addresses, invoice contents | [TO CONFIRM: country of processing] | [TO CONFIRM] |
| Our bank | Receives payments and holds the company account | Payer name, reference and amount | United Kingdom | Not applicable, no transfer outside the UK |
| HM Revenue and Customs, Companies House | Statutory filings and tax | Whatever the relevant statute requires | United Kingdom | Not applicable, no transfer outside the UK |
| Professional advisers, if instructed | Legal advice on a dispute, or an insurance claim | Only the records relevant to the matter | United Kingdom | Not applicable, no transfer outside the UK |
We use no advertising networks, analytics products, customer relationship management platforms, chat widgets, session recording tools or lead enrichment services. If that changes, this table changes first and the effective date moves with it. We may also disclose personal data where required by law, a court order, or a regulator acting within its powers, and where we are permitted to tell you that this has happened, we will.
15. International transfers
Role: controller and processor
Our own operations are in the United Kingdom. Personal data leaves the UK only where a provider in the table above processes it abroad.
UK adequacy. Where a provider processes in a country covered by adequacy regulations made under section 17A of the Data Protection Act 2018, including the European Economic Area, the transfer rests on those regulations and no further safeguard is required.
The IDTA. Without adequacy cover, the transfer is made under the International Data Transfer Agreement issued by the Information Commissioner under section 119A of that Act, entered into with the provider.
The UK Addendum. Where a provider already operates on the European Commission Standard Contractual Clauses, we rely on the International Data Transfer Addendum to those clauses, also issued under section 119A, which adapts them for UK law. That is the mechanism covering the Cloudflare transfer in section 14.
Transfer risk assessment. Before relying on the IDTA or the Addendum we consider whether the law and practice of the destination country undermine the protection the clauses are meant to give, and record the conclusion. Where a provider is certified under the UK Extension to the EU to US Data Privacy Framework we may rely on that instead, and will name it in the table rather than leaving you to guess.
As processor, we transfer client material outside the UK only where the client has instructed it in writing and a mechanism above is in place. You can ask for a copy of the safeguards used for any specific transfer, and we will send it with commercially confidential terms redacted.
16. Your rights under the UK GDPR
Role: controller
These rights apply against the controller. Where we are the processor, section 13 explains what to do instead. Each right has its own subsection below, because they do different things and are refused in different circumstances.
16.1 Right of access, Article 15
You can ask whether we hold personal data about you and, if we do, receive a copy with the purposes, categories, recipients, retention period, the source if we did not get it from you, and the existence of your other rights. The first copy is free; we can charge a reasonable fee based on administrative cost for further copies, or refuse a request that is manifestly unfounded or excessive. Email hello@pathfinderlabs.co.uk with “Subject access request” in the subject line.
16.2 Right to rectification, Article 16
You can have inaccurate personal data corrected and incomplete data completed, including by a supplementary statement. Tell us which field is wrong and what it should say. Where we have disclosed the data to a recipient, Article 19 requires us to tell that recipient unless it is impossible or involves disproportionate effort, and we will tell you who we told.
16.3 Right to erasure, Article 17
You can ask us to delete personal data where it is no longer needed for the purpose we collected it for, where you withdraw the consent we relied on and there is no other basis, where you object under Article 21 and there is no overriding ground, or where it was processed unlawfully. The right is not absolute: we keep what the law requires, in particular accounting records, and what is needed for the establishment, exercise or defence of legal claims. Section 21 gives the route and timing.
16.4 Right to restriction of processing, Article 18
You can require us to stop using personal data while something is resolved: while we check a challenge to its accuracy, where processing is unlawful but you prefer restriction to deletion, where we no longer need it but you need it for a legal claim, or while we consider an objection under Article 21. During a restriction we keep the data but do not otherwise use it, and we will tell you before the restriction is lifted.
16.5 Right to data portability, Article 20
Where processing is based on your consent or a contract with you and is carried out by automated means, you can receive the personal data you gave us in a structured, commonly used, machine readable format and ask us to transmit it to another controller where technically feasible. In practice this affects very little of what we hold, because most of our controller processing rests on legitimate interests or a legal obligation. We will say which parts qualify when you ask.
16.6 Right to object, Article 21
Where we process under legitimate interests, you can object on grounds relating to your particular situation. We must stop unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is for legal claims. Section 10 names every legitimate interest we rely on, so you can object to a specific one. For direct marketing the right is absolute, with no balancing. We do no direct marketing.
16.7 Rights in relation to automated decisions, Article 22
You have the right not to be subject to a decision based solely on automated processing which produces legal effects concerning you or similarly significantly affects you. We make no decisions of that kind. Section 23 explains further.
16.8 Right to withdraw consent, Article 7(3)
Where we rely on consent you can withdraw it at any time, and it must be as easy to withdraw as it was to give. The only consent we ask for is the one at the end of section 10, and you withdraw it by replying and saying so. Withdrawal does not affect the lawfulness of what was done beforehand.
16.9 How to exercise a right, identity checks and timing
All requests go to hello@pathfinderlabs.co.uk. No form, no particular wording, and you do not have to mention the UK GDPR for a request to count.
Identity verification. We will not hand personal data to the wrong person. Where a request comes from an email address already in our records in connection with you, that is normally enough. Where it is not, we ask for the minimum extra information needed to link you to the records, for example the approximate date and subject of the correspondence. If that is insufficient we may ask to see one identity document, which we view and then delete rather than file. Nothing supplied for identification is used for any other purpose.
Timing. We respond without undue delay and within one month of receiving the request, as Article 12(3) requires. That runs from the day after receipt, or from the day we receive the information needed to verify your identity. Where a request is complex, or where you have made several, we may extend by up to two further months, and if we do we will tell you within the first month and explain why.
Cost. Free, except as described in section 16.1. Acting for someone else: we need written authority from that person, or evidence of your legal authority to act, before we can respond.
16.10 When we can refuse, and what we must tell you
We can refuse or partly refuse a request in these situations:
- the request is manifestly unfounded or excessive, in particular because of its repetitive character, under Article 12(5);
- an exemption in Schedule 2 to the Data Protection Act 2018 applies, for example where complying would disclose information about another identifiable person who has not consented and it is not reasonable to comply without that consent, or where the material is subject to legal professional privilege;
- the right does not apply to the processing in question, for example a portability request about data we hold under a legal obligation; or
- we cannot identify you from the data we hold and cannot verify who you are.
If we refuse, we will tell you within the same one month period, explain which ground we are relying on and why, tell you that you can complain to the ICO, and tell you that you can seek a remedy through the courts. We will not simply not reply.
17. Retention
Role: controller and processor
Every period below has a reason attached. We keep nothing on the basis that it might be useful one day.
The table below scrolls sideways.
| Record | Our role | Kept for | Reason for that period |
|---|---|---|---|
| Website connection logs at the hosting edge | Controller | The host’s standard period, measured in days | Long enough to investigate an attack, short enough that we hold no browsing record |
| Security cookies set by the hosting edge | Controller | 30 minutes to one year, per the Cookie Notice | The window over which repeat automated abuse is worth recognising |
| Enquiry email that does not become an engagement | Controller | 24 months from the last message | People return to a conversation a year later and the thread makes the reply useful. Beyond that it is stale. |
| Proposals, scopes and signed agreements | Controller | Six years from the end of the engagement | The limitation period for a simple contract, section 5 of the Limitation Act 1980 |
| Engagement working notes and findings memos | Controller | Six years from the end of the engagement | Aligned with the agreement, so a claim can be answered with a complete file |
| Accounting records, invoices and payment entries | Controller | Six years from the end of the accounting period | The statutory period for a private company’s accounting records, section 388 of the Companies Act 2006, and the tax requirement |
| Client material processed on instruction | Processor | Deleted within 30 days of the end of the engagement | The client is the controller. Holding it longer requires a written instruction. |
| Unsuccessful job application material | Controller | 12 months from our last message | Long enough to explain a decision, short enough not to build a file |
| Records of data protection requests | Controller | Six years from closure | Accountability under Article 5(2), and answering an ICO enquiry later |
| Personal data breach records | Controller and processor | Six years from the breach | Article 33(5) requires a record of every breach |
| Supplier and contractor records | Controller | Six years from the end of the relationship | Matches the contract limitation period and the accounting requirement |
When a period ends we delete the record or, where deletion from a backup is not immediately possible, put it beyond use and delete it when the backup cycles. Backups are overwritten on a rolling basis and are searched for nothing except restoring a system.
18. Complaints and the ICO
Role: controller and processor
Please raise a complaint with us first if you are willing to: email hello@pathfinderlabs.co.uk with “Data protection complaint” in the subject line. We acknowledge within two working days and respond in full within 20 working days. You do not have to come to us first, and can complain to the supervisory authority at any time. For the United Kingdom that is the Information Commissioner’s Office:
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk
You also have the right to an effective judicial remedy under Articles 78 and 79 of the UK GDPR, which means you can take a complaint about the ICO’s handling of your case, or a claim against us, to the courts.
19. Security and personal data breaches
Role: controller and processor
Our measures are proportionate to a company of this size that does not operate a platform holding other people’s live data: encryption in transit for the website and for email where the receiving server supports it; full disk encryption on development machines; multi-factor authentication on every account that can reach client material or company records; access limited to the people working on the engagement; a written data processing agreement before any client material is transferred; and deletion at the end of the engagement rather than indefinite storage.
We do not claim more than that. As stated on the About page, we do not hold ISO 27001 certification, a SOC 2 report or Cyber Essentials certification, and will not represent otherwise.
Notification to the ICO, Article 33
Where we are the controller and a personal data breach occurs, we assess whether it is likely to result in a risk to the rights and freedoms of the people affected. If it is, we notify the ICO without undue delay and, where feasible, not later than 72 hours after becoming aware of it; a notification made later than 72 hours will state the reasons for the delay, as Article 33(1) requires. If we conclude a breach is unlikely to result in a risk and so need not be reported, we record that assessment and the reasoning. Every breach is recorded whether or not it is reported, including the facts, effects and remedial action, as Article 33(5) requires, and those records are kept for six years.
Notification to you, Article 34
Where a breach is likely to result in a high risk to your rights and freedoms, we will tell you without undue delay and in plain language: the nature of the breach, the likely consequences, the measures taken or proposed, and a point of contact. Individual notice may not be needed if the data was unintelligible to anyone unauthorised, for example through strong encryption, if we have taken measures meaning the high risk is no longer likely, or if individual notice would involve disproportionate effort, in which case we make a public communication instead.
Where we are the processor
If a breach affects client material we notify the client without undue delay, as Article 33(2) requires, with the information they need for their own notification inside their own 72 hour window. We do not notify the ICO on a client’s behalf unless instructed in writing.
20. Mobile applications, permissions and store declarations
Role: controller
We have published no application at the effective date of this policy. This section is written now, before there is anything to defend, so the position is on record rather than assembled after the fact. It applies to any application THE PATHFINDER LABS CORPORATION LIMITED publishes.
Permissions
An application will request the smallest set of permissions that lets it do its job, will ask at the point of use rather than on first launch, and will stay usable in a reduced form if a permission is declined. The table below will be replaced with the actual manifest of the first application before it is submitted for review.
The table below scrolls sideways.
| Permission | Why it would be asked for | Required or optional | If you decline | Revoke on iOS | Revoke on Android |
|---|---|---|---|---|---|
| Camera | Capturing a photograph or scanning a code in a feature you chose to use | Optional | That feature is unavailable. Everything else works, and you can type the same information. | Settings, Privacy and Security, Camera, then turn the app off | Settings, Apps, the app, Permissions, Camera, then Don’t allow |
| Photo library | Attaching an image you select | Optional | You cannot attach an existing image. On iOS, selected photos only is the normal case here, not the exception. | Settings, Privacy and Security, Photos, then the app | Settings, Apps, the app, Permissions, Photos and videos |
| Notifications | Telling you a long running task has finished | Optional | Nothing is lost, you check the screen instead. We would not market to you by notification. | Settings, Notifications, then the app | Settings, Notifications, App settings, then the app |
| Precise location | Only where a feature is inherently about where you are | Optional | The feature is unavailable or falls back to a place you type. No background collection. | Settings, Privacy and Security, Location Services, then the app | Settings, Location, App permissions, then the app |
| Local file access | Importing or exporting a file you choose | Optional | Import and export are unavailable. We use the system picker, which grants access to one file. | Per file through the system picker, no standing permission | Settings, Apps, the app, Permissions, Files |
| Tracking, the App Tracking Transparency prompt | Not requested. See below. | Not applicable | Not applicable | Not applicable | Not applicable |
App Tracking Transparency on iOS
We will not display the App Tracking Transparency prompt, because we will not track you. We will not access the Identifier for Advertisers, link data collected in our application to third party data for advertising or measurement, or share any identifier with a data broker. If that changed, the prompt would appear, this section would be rewritten first, and declining would never reduce what the application does.
Consistency with the store declarations
The Google Play Data Safety declaration and the Apple App Privacy labels for any application we publish will be filled in from this section, not written separately. If you find a difference between a store listing and this policy, treat it as an error and tell us at hello@pathfinderlabs.co.uk: we will correct whichever is wrong within five working days and say which it was. Where an application collects nothing, the declaration will say so rather than listing categories defensively.
21. Account closure and data deletion
Role: controller
There are no accounts on this website, so there is nothing here to close. The commitments below apply to any application or service we publish that does have accounts. The email route applies today to anything we hold about you.
In the application
Any application we publish will contain a deletion path inside the application itself, reachable without contacting us, at Settings, then Account, then Delete account. It will delete the account and the personal data associated with it rather than deactivating it, and will state on screen what is retained and why before you confirm.
By email
You can also email hello@pathfinderlabs.co.uk with “Delete my data” in the subject line. This route works whether or not you have used an application, and covers correspondence, enquiry records and anything else we hold about you as controller. We verify identity as described in section 16.9 first.
Timing
We complete deletion across live systems within 30 days of a verified request and confirm in writing when it is done. Copies inside routine backups are put beyond use immediately and removed as those backups cycle, which takes no longer than a further 30 days.
What is retained after deletion, and why
- Accounting records that mention you, for six years from the end of the relevant accounting period, because section 388 of the Companies Act 2006 and tax legislation require it. We cannot delete an invoice on request.
- The record of the deletion request itself, for six years, at the minimum needed to show it was handled properly: who asked, when, what was deleted and when it completed.
- A suppression entry if you asked never to be contacted again, because honouring that means remembering the address to avoid.
- Material needed for a live legal claim, restricted so it is used for nothing else and deleted when the matter ends.
Nothing else survives deletion: no shadow copy, no anonymised profile derived from your record, no export in a spreadsheet somewhere.
22. Children
Role: controller
This website and our services are directed at businesses and are not intended for children. We do not knowingly collect personal data from anyone under 13, and we would not build a general audience application without applying the ICO Age Appropriate Design Code to it first. If you believe a child has sent us personal data, tell us and we will delete it.
23. Automated decision making and profiling
Role: controller
We make no decisions about people by automated means and we profile nobody. Enquiries and job applications are read by a person. Nothing on this website scores, ranks or segments you, and no part of our process produces a legal or similarly significant effect on you without a human deciding it. Spam filtering on the mailbox is automated, but it decides where a message is filed rather than anything about you, and a message wrongly filtered is retrieved by a person on request.
24. Changes to this policy
Role: controller and processor
When this policy changes we change the effective date and version at the top. Where a change is significant, for example a new sub-processor, category of data, purpose or international transfer, we describe it in a short note at the top for at least 90 days rather than expecting you to compare versions. Where a change requires your consent, we ask before it takes effect rather than after.
25. How to contact us
Role: controller and processor
Email: hello@pathfinderlabs.co.uk, with a clear subject line such as “Subject access request”, “Delete my data” or “Data protection complaint”. Post: THE PATHFINDER LABS CORPORATION LIMITED, 30 Pettley Gardens, Romford, England, RM7 9AB, which is accepted but not monitored daily, so a time critical request should go by email.
We reply to email within two working days. Statutory deadlines run as described in section 16.9 and are unaffected by that shorter service commitment.