Skip to content
Pathfinder Labs Corporation
Legal

Privacy Policy

Effective date: 7 August 2026. Version 1.0. This is the first published version of this policy.

1. Who we are and what this policy covers

This policy is published by THE PATHFINDER LABS CORPORATION LIMITED, a company registered in England and Wales with company number 17061706 and a registered office at 30 Pettley Gardens, Romford, England, RM7 9AB. In this policy, “we”, “us” and “the company” mean that company. There is no group, no parent and no overseas branch. The company was incorporated on 1 March 2026 and is an applied research and prototyping studio.

This policy covers personal data handled in connection with:

  • the website at pathfinderlabs.co.uk;
  • email correspondence sent to or from hello@pathfinderlabs.co.uk;
  • the administration of engagements, including proposals, contracts and invoices;
  • material a client asks us to work with during an engagement; and
  • any software application we publish, including on the Apple App Store and Google Play. As at the effective date of this policy we have published none. Section 20 sets out the rules that will apply to the first one.

“Personal data”, “controller”, “processor”, “processing” and “special category data” carry the meanings given to them in the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

We have not appointed a Data Protection Officer. A company of this size is not required to appoint one under Article 37 of the UK GDPR, and we would rather say that than imply a role exists. Responsibility for data protection sits with the director, and correspondence should go to hello@pathfinderlabs.co.uk.

Registration with the Information Commissioner’s Office: [TO CONFIRM: ICO data protection fee registration number, or confirmation that an exemption applies]

2. How to read this policy: our two roles

The law treats two situations very differently, and this policy keeps them apart from here on.

Where we are the controller, we decide what personal data is collected and why: this website, our email, proposals, contracts, invoices, suppliers, recruitment, and any application we publish under our own name. Part 1 deals with those.

Where we are the processor, a client decides and we act on that client’s written instructions, for example a database extract handed to us to test whether a technique works. Part 2 deals with those. There the client is the controller, and their privacy notice, not this one, tells you why the data was collected.

Every section below is labelled with the role it relates to, using a marker like the one at the start of section 4.

3. Which parts apply to you

Find yourself in the first column.

Which sections of this policy apply to each kind of reader
If you areOur roleRead
Someone reading this websiteControllerSections 4, 14 to 19
Someone who has emailed usControllerSections 5, 10, 16, 17
A named contact at a client organisationControllerSections 6, 10, 16, 17
A contact at one of our suppliers or advisersControllerSections 7, 16, 17
Someone who has applied to work with usControllerSections 8, 16, 17
A user of an application we publishControllerSections 9, 20, 21
A person whose data appears in material a client gave usProcessorSections 11 to 13, and your own controller’s notice

Part 1. Where we are the controller

In this part we decide the purposes and means of processing, and we answer to you directly for it.

4. Visitors to this website

Role: controller

This is a static website with no accounts, no forms, no comment system, no advertising network, no analytics product and no social media embeds. We set no cookie of our own, and there is no consent banner because there is nothing to consent to. The Cookie Notice gives the full detail, including the security cookies our host may set.

The site is served by Cloudflare Pages, which records technical connection data at its edge. We do not receive individual records; we see aggregated request counts in the hosting dashboard.

The table below scrolls sideways.

Data inventory for website visitors
CategoryExample fieldsSourcePurposeLawful basisRetentionRecipients
Connection and request data IP address, timestamp, requested URL, HTTP status, user agent, approximate country Collected automatically when your browser requests a page Serving the page, blocking automated abuse, keeping the site available Article 6(1)(f). Interest: keeping a public website online and defended against automated attack. The host’s standard log period, measured in days Cloudflare, Inc. as processor
Aggregate request counts Requests, bandwidth, error rates, country totals Derived by the host from the row above Knowing whether the site works and roughly how much it is read Article 6(1)(f). Interest: operating a website we can maintain sensibly. While the hosting account exists Cloudflare, Inc. as processor
Security cookies, if set Cloudflare bot management and challenge identifiers Set by the hosting edge, not by us Telling a person apart from an automated client during an attack Regulation 6(4) PECR, strictly necessary for security, with Article 6(1)(f) 30 minutes to one year depending on the cookie, listed in the Cookie Notice Cloudflare, Inc. as processor

5. People who email us

Role: controller

Email is the only route into this company, so the mailbox holds most of the personal data we have about people outside the business: whatever you put in the message, plus the technical headers that come with it.

Data inventory for email correspondence
CategoryExample fieldsSourcePurposeLawful basisRetentionRecipients
Enquiry correspondence Name, email address, employer, job title if given, message content, attachments You, directly Reading your enquiry and replying to it in context Article 6(1)(f). Interest: answering people who approach the business about its services. 24 months from the last message, unless it becomes an engagement Our email provider as processor
Message metadata Addresses, timestamps, message identifiers, spam scores, routing headers Generated automatically by mail systems Delivering mail, filtering spam, tracing delivery failures Article 6(1)(f). Interest: running a mailbox not overwhelmed by unsolicited mail. 24 months, alongside the message Our email provider as processor
Data protection requests Identity details, the request, our response and reasoning You, directly Handling the request and showing we handled it correctly Article 6(1)(c) to handle it; Article 6(1)(f) to retain the record, the interest being demonstrable compliance. Six years from closure Email provider as processor; the ICO on complaint

Email provider: [TO CONFIRM: the name and country of the email hosting provider for hello@pathfinderlabs.co.uk, to be added to the sub-processor table in section 14]

Please do not send special category data, financial credentials or anything under a confidentiality obligation in a first email. If material of that kind is needed, we will agree a route for it before you send it.

6. Client contacts and contract administration

Role: controller

When an engagement is agreed we hold information about the individuals we deal with at the client organisation, plus the commercial records that go with the work. This is separate from anything inside the client’s own material, which Part 2 covers.

Data inventory for client contacts and contract administration
CategoryExample fieldsSourcePurposeLawful basisRetentionRecipients
Contact details of the people we work with Name, job title, work email, work telephone, employer You, your colleagues, or your organisation’s website Running the engagement, arranging meetings, delivering findings Article 6(1)(b) if you contract with us personally; otherwise Article 6(1)(f), the interest being administration of a contract with an organisation through its named staff. Six years from the end of the engagement Email provider, and a document storage provider where used
Proposals, scopes and signed agreements The written question, stages, prices, dates, signatures Us and the client jointly Agreeing what will be done, and proving what was agreed Article 6(1)(b), and Article 6(1)(f) for the evidential copy, the interest being defence of a legal claim. Six years from the end of the engagement Our professional advisers if a dispute arises
Invoices, payments and accounting entries Billing name and address, invoice number, amount, dates, reference The client and our bank Billing, collecting payment, statutory accounts and tax returns Article 6(1)(c), legal obligation under the Companies Act 2006 and tax legislation. Six years from the end of the accounting period Our accountant, our bank, HM Revenue and Customs
Engagement working notes Meeting notes, decisions, questions and who asked them Us, during the work Doing the work and writing an accurate findings memo Article 6(1)(f). Interest: a written record that is accurate about what was decided and by whom. Six years from the end of the engagement Nobody outside the company unless the client asks

7. Suppliers, advisers and contractors

Role: controller

We hold names, business contact details, bank details where we pay them, contracts and invoices for the people and firms that supply the company, including any contractor engaged to help on a piece of work. The lawful basis is Article 6(1)(b) where the supplier is an individual contracting with us and Article 6(1)(f) otherwise, the legitimate interest being administration of the company’s own supply arrangements. Payment records are kept for six years from the end of the relevant accounting period under Article 6(1)(c); other supplier records for six years from the end of the relationship.

Where a contractor will touch client material, they are engaged under a written agreement containing confidentiality obligations and the sub-processor terms required by Article 28 of the UK GDPR, and the client is told before it happens.

8. Job applicants and speculative approaches

Role: controller

We are not recruiting and there is no application system on this website. If you write to us about work anyway, we hold your message, your curriculum vitae if attached, and any notes we make. The lawful basis is Article 6(1)(f), the interest being consideration of people who offer to work with a small company; where an application progresses towards an offer, Article 6(1)(b) also applies. Unsuccessful application material is kept for 12 months from our last message so that we can explain a decision, then deleted, and deleted sooner if you ask.

We do not carry out criminal record checks, credit checks or automated screening of applicants.

9. Users of any application we publish

Role: controller

At the effective date of this policy THE PATHFINDER LABS CORPORATION LIMITED has published no application on the Apple App Store, on Google Play or anywhere else, and holds no user accounts, so no user data of this kind exists.

Section 20 sets out the commitments that will apply to the first application, including the permission table and the store declarations. This section will be replaced with a data inventory in the format of sections 4 to 6 before any application is submitted for review, and the effective date above will change on the same day.

10. The legitimate interests we rely on, named

Role: controller

Article 6(1)(f) requires an interest to be identified, to be necessary, and to be balanced against your rights. We rely on it in five places, with the balancing outcome stated.

  1. Keeping a public website online and defended. A site with no protection is taken offline by automated traffic. The data is technical, held briefly and not used to build a profile.
  2. Answering people who email us. A message cannot be answered without processing it. You chose to write, you know what you sent, and you can ask us to delete the thread.
  3. Administering a contract held with an organisation through its named staff. Contracts are performed by people. The data is limited to work contact details and business correspondence.
  4. Keeping evidential copies of agreements and correspondence for six years. The limitation period for a simple contract in England and Wales is six years and a defence needs documents. The records sit unused unless a claim arises.
  5. Considering people who ask about work. An application cannot be read without processing it. Retention is short and deletion on request is immediate.

We do not rely on legitimate interests for marketing. We send no marketing email, operate no mailing list and buy no contact lists. If you ask to be told when our first experiment is published, we send one message about that and nothing else, on your consent under Article 6(1)(a), which you withdraw by replying.

Part 2. Where we are the processor

In this part a client decides what happens and we follow written instructions. That client, not this company, is the controller.

11. Client material we process on instruction

Role: processor

An engagement sometimes requires material that contains personal data, most often an extract used to find out whether a technique produces a usable result on real records rather than invented ones. When that happens:

  • the client remains the controller and decides the purpose;
  • we process only on the client’s documented instructions, as Article 28(3)(a) requires;
  • a written data processing agreement containing the Article 28(3) terms is signed before any material is transferred;
  • we ask the client to minimise or pseudonymise the extract and send only the fields the question needs;
  • the material is deleted within 30 days of the end of the engagement unless the client instructs otherwise in writing; and
  • we name the sub-processors that will have access before the material arrives, and add none during an engagement without written approval.

If a client instruction appears to breach the UK GDPR or the Data Protection Act 2018, we say so in writing and do not act on it, as Article 28(3) requires.

12. What we will not do with client material

Role: processor

We do not use client material to improve our methods, train a model, build a product, seed a demonstration, or illustrate a published experiment. We do not sell it, share it with another client, or keep a copy after deletion is due. Nothing in an engagement gives us a licence to any of that, and we will not ask for one as a condition of doing the work.

13. If your data reached us through a client

Role: processor

If an organisation gave us records that include information about you, that organisation decided to do so and is answerable for it. We cannot lawfully act on your request about that data without their instruction, because we are not the controller.

What we will do, if you write to hello@pathfinderlabs.co.uk, is tell you within five working days whether we hold material from that organisation, pass your request to them without delay, and confirm that we have done so. If you tell us they have not responded, we will say so to them in writing. You can also complain to the ICO about the controller directly, using the details in section 18.

Part 3. Applies to both roles

Everything below applies whether we are acting as controller or as processor, unless a paragraph says otherwise.

14. Recipients and sub-processors

Role: controller and processor

We are a small company and we keep the list of third parties short on purpose. Every organisation named below is engaged under a written contract containing the obligations required by Article 28 of the UK GDPR.

The table below scrolls sideways.

Named sub-processors and other recipients
OrganisationWhat it does for usPersonal data it can accessWhere processing happensTransfer mechanism
Cloudflare, Inc. Serves this website through Cloudflare Pages and filters automated abuse at the edge Connection data in section 4. No account data, as the site has no accounts. United States, with edge processing in the UK and elsewhere UK Addendum to the EU Standard Contractual Clauses, in the provider’s data processing terms
[TO CONFIRM: email hosting provider] Hosts the mailbox for hello@pathfinderlabs.co.uk All correspondence described in section 5, and any attachment sent to us [TO CONFIRM: country of processing] [TO CONFIRM: adequacy, IDTA or Addendum, once the provider is settled]
[TO CONFIRM: accounting software and accountant] Bookkeeping, invoicing and statutory accounts Billing names and addresses, invoice contents [TO CONFIRM: country of processing] [TO CONFIRM]
Our bank Receives payments and holds the company account Payer name, reference and amount United Kingdom Not applicable, no transfer outside the UK
HM Revenue and Customs, Companies House Statutory filings and tax Whatever the relevant statute requires United Kingdom Not applicable, no transfer outside the UK
Professional advisers, if instructed Legal advice on a dispute, or an insurance claim Only the records relevant to the matter United Kingdom Not applicable, no transfer outside the UK

We use no advertising networks, analytics products, customer relationship management platforms, chat widgets, session recording tools or lead enrichment services. If that changes, this table changes first and the effective date moves with it. We may also disclose personal data where required by law, a court order, or a regulator acting within its powers, and where we are permitted to tell you that this has happened, we will.

15. International transfers

Role: controller and processor

Our own operations are in the United Kingdom. Personal data leaves the UK only where a provider in the table above processes it abroad.

UK adequacy. Where a provider processes in a country covered by adequacy regulations made under section 17A of the Data Protection Act 2018, including the European Economic Area, the transfer rests on those regulations and no further safeguard is required.

The IDTA. Without adequacy cover, the transfer is made under the International Data Transfer Agreement issued by the Information Commissioner under section 119A of that Act, entered into with the provider.

The UK Addendum. Where a provider already operates on the European Commission Standard Contractual Clauses, we rely on the International Data Transfer Addendum to those clauses, also issued under section 119A, which adapts them for UK law. That is the mechanism covering the Cloudflare transfer in section 14.

Transfer risk assessment. Before relying on the IDTA or the Addendum we consider whether the law and practice of the destination country undermine the protection the clauses are meant to give, and record the conclusion. Where a provider is certified under the UK Extension to the EU to US Data Privacy Framework we may rely on that instead, and will name it in the table rather than leaving you to guess.

As processor, we transfer client material outside the UK only where the client has instructed it in writing and a mechanism above is in place. You can ask for a copy of the safeguards used for any specific transfer, and we will send it with commercially confidential terms redacted.

16. Your rights under the UK GDPR

Role: controller

These rights apply against the controller. Where we are the processor, section 13 explains what to do instead. Each right has its own subsection below, because they do different things and are refused in different circumstances.

16.1 Right of access, Article 15

You can ask whether we hold personal data about you and, if we do, receive a copy with the purposes, categories, recipients, retention period, the source if we did not get it from you, and the existence of your other rights. The first copy is free; we can charge a reasonable fee based on administrative cost for further copies, or refuse a request that is manifestly unfounded or excessive. Email hello@pathfinderlabs.co.uk with “Subject access request” in the subject line.

16.2 Right to rectification, Article 16

You can have inaccurate personal data corrected and incomplete data completed, including by a supplementary statement. Tell us which field is wrong and what it should say. Where we have disclosed the data to a recipient, Article 19 requires us to tell that recipient unless it is impossible or involves disproportionate effort, and we will tell you who we told.

16.3 Right to erasure, Article 17

You can ask us to delete personal data where it is no longer needed for the purpose we collected it for, where you withdraw the consent we relied on and there is no other basis, where you object under Article 21 and there is no overriding ground, or where it was processed unlawfully. The right is not absolute: we keep what the law requires, in particular accounting records, and what is needed for the establishment, exercise or defence of legal claims. Section 21 gives the route and timing.

16.4 Right to restriction of processing, Article 18

You can require us to stop using personal data while something is resolved: while we check a challenge to its accuracy, where processing is unlawful but you prefer restriction to deletion, where we no longer need it but you need it for a legal claim, or while we consider an objection under Article 21. During a restriction we keep the data but do not otherwise use it, and we will tell you before the restriction is lifted.

16.5 Right to data portability, Article 20

Where processing is based on your consent or a contract with you and is carried out by automated means, you can receive the personal data you gave us in a structured, commonly used, machine readable format and ask us to transmit it to another controller where technically feasible. In practice this affects very little of what we hold, because most of our controller processing rests on legitimate interests or a legal obligation. We will say which parts qualify when you ask.

16.6 Right to object, Article 21

Where we process under legitimate interests, you can object on grounds relating to your particular situation. We must stop unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is for legal claims. Section 10 names every legitimate interest we rely on, so you can object to a specific one. For direct marketing the right is absolute, with no balancing. We do no direct marketing.

16.7 Rights in relation to automated decisions, Article 22

You have the right not to be subject to a decision based solely on automated processing which produces legal effects concerning you or similarly significantly affects you. We make no decisions of that kind. Section 23 explains further.

16.8 Right to withdraw consent, Article 7(3)

Where we rely on consent you can withdraw it at any time, and it must be as easy to withdraw as it was to give. The only consent we ask for is the one at the end of section 10, and you withdraw it by replying and saying so. Withdrawal does not affect the lawfulness of what was done beforehand.

16.9 How to exercise a right, identity checks and timing

All requests go to hello@pathfinderlabs.co.uk. No form, no particular wording, and you do not have to mention the UK GDPR for a request to count.

Identity verification. We will not hand personal data to the wrong person. Where a request comes from an email address already in our records in connection with you, that is normally enough. Where it is not, we ask for the minimum extra information needed to link you to the records, for example the approximate date and subject of the correspondence. If that is insufficient we may ask to see one identity document, which we view and then delete rather than file. Nothing supplied for identification is used for any other purpose.

Timing. We respond without undue delay and within one month of receiving the request, as Article 12(3) requires. That runs from the day after receipt, or from the day we receive the information needed to verify your identity. Where a request is complex, or where you have made several, we may extend by up to two further months, and if we do we will tell you within the first month and explain why.

Cost. Free, except as described in section 16.1. Acting for someone else: we need written authority from that person, or evidence of your legal authority to act, before we can respond.

16.10 When we can refuse, and what we must tell you

We can refuse or partly refuse a request in these situations:

  • the request is manifestly unfounded or excessive, in particular because of its repetitive character, under Article 12(5);
  • an exemption in Schedule 2 to the Data Protection Act 2018 applies, for example where complying would disclose information about another identifiable person who has not consented and it is not reasonable to comply without that consent, or where the material is subject to legal professional privilege;
  • the right does not apply to the processing in question, for example a portability request about data we hold under a legal obligation; or
  • we cannot identify you from the data we hold and cannot verify who you are.

If we refuse, we will tell you within the same one month period, explain which ground we are relying on and why, tell you that you can complain to the ICO, and tell you that you can seek a remedy through the courts. We will not simply not reply.

17. Retention

Role: controller and processor

Every period below has a reason attached. We keep nothing on the basis that it might be useful one day.

The table below scrolls sideways.

Retention periods and the reason for each
RecordOur roleKept forReason for that period
Website connection logs at the hosting edgeControllerThe host’s standard period, measured in daysLong enough to investigate an attack, short enough that we hold no browsing record
Security cookies set by the hosting edgeController30 minutes to one year, per the Cookie NoticeThe window over which repeat automated abuse is worth recognising
Enquiry email that does not become an engagementController24 months from the last messagePeople return to a conversation a year later and the thread makes the reply useful. Beyond that it is stale.
Proposals, scopes and signed agreementsControllerSix years from the end of the engagementThe limitation period for a simple contract, section 5 of the Limitation Act 1980
Engagement working notes and findings memosControllerSix years from the end of the engagementAligned with the agreement, so a claim can be answered with a complete file
Accounting records, invoices and payment entriesControllerSix years from the end of the accounting periodThe statutory period for a private company’s accounting records, section 388 of the Companies Act 2006, and the tax requirement
Client material processed on instructionProcessorDeleted within 30 days of the end of the engagementThe client is the controller. Holding it longer requires a written instruction.
Unsuccessful job application materialController12 months from our last messageLong enough to explain a decision, short enough not to build a file
Records of data protection requestsControllerSix years from closureAccountability under Article 5(2), and answering an ICO enquiry later
Personal data breach recordsController and processorSix years from the breachArticle 33(5) requires a record of every breach
Supplier and contractor recordsControllerSix years from the end of the relationshipMatches the contract limitation period and the accounting requirement

When a period ends we delete the record or, where deletion from a backup is not immediately possible, put it beyond use and delete it when the backup cycles. Backups are overwritten on a rolling basis and are searched for nothing except restoring a system.

18. Complaints and the ICO

Role: controller and processor

Please raise a complaint with us first if you are willing to: email hello@pathfinderlabs.co.uk with “Data protection complaint” in the subject line. We acknowledge within two working days and respond in full within 20 working days. You do not have to come to us first, and can complain to the supervisory authority at any time. For the United Kingdom that is the Information Commissioner’s Office:

Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk

You also have the right to an effective judicial remedy under Articles 78 and 79 of the UK GDPR, which means you can take a complaint about the ICO’s handling of your case, or a claim against us, to the courts.

19. Security and personal data breaches

Role: controller and processor

Our measures are proportionate to a company of this size that does not operate a platform holding other people’s live data: encryption in transit for the website and for email where the receiving server supports it; full disk encryption on development machines; multi-factor authentication on every account that can reach client material or company records; access limited to the people working on the engagement; a written data processing agreement before any client material is transferred; and deletion at the end of the engagement rather than indefinite storage.

We do not claim more than that. As stated on the About page, we do not hold ISO 27001 certification, a SOC 2 report or Cyber Essentials certification, and will not represent otherwise.

Notification to the ICO, Article 33

Where we are the controller and a personal data breach occurs, we assess whether it is likely to result in a risk to the rights and freedoms of the people affected. If it is, we notify the ICO without undue delay and, where feasible, not later than 72 hours after becoming aware of it; a notification made later than 72 hours will state the reasons for the delay, as Article 33(1) requires. If we conclude a breach is unlikely to result in a risk and so need not be reported, we record that assessment and the reasoning. Every breach is recorded whether or not it is reported, including the facts, effects and remedial action, as Article 33(5) requires, and those records are kept for six years.

Notification to you, Article 34

Where a breach is likely to result in a high risk to your rights and freedoms, we will tell you without undue delay and in plain language: the nature of the breach, the likely consequences, the measures taken or proposed, and a point of contact. Individual notice may not be needed if the data was unintelligible to anyone unauthorised, for example through strong encryption, if we have taken measures meaning the high risk is no longer likely, or if individual notice would involve disproportionate effort, in which case we make a public communication instead.

Where we are the processor

If a breach affects client material we notify the client without undue delay, as Article 33(2) requires, with the information they need for their own notification inside their own 72 hour window. We do not notify the ICO on a client’s behalf unless instructed in writing.

20. Mobile applications, permissions and store declarations

Role: controller

We have published no application at the effective date of this policy. This section is written now, before there is anything to defend, so the position is on record rather than assembled after the fact. It applies to any application THE PATHFINDER LABS CORPORATION LIMITED publishes.

Permissions

An application will request the smallest set of permissions that lets it do its job, will ask at the point of use rather than on first launch, and will stay usable in a reduced form if a permission is declined. The table below will be replaced with the actual manifest of the first application before it is submitted for review.

The table below scrolls sideways.

Application permissions, purpose, and how to revoke each one
PermissionWhy it would be asked forRequired or optionalIf you declineRevoke on iOSRevoke on Android
Camera Capturing a photograph or scanning a code in a feature you chose to use Optional That feature is unavailable. Everything else works, and you can type the same information. Settings, Privacy and Security, Camera, then turn the app off Settings, Apps, the app, Permissions, Camera, then Don’t allow
Photo library Attaching an image you select Optional You cannot attach an existing image. On iOS, selected photos only is the normal case here, not the exception. Settings, Privacy and Security, Photos, then the app Settings, Apps, the app, Permissions, Photos and videos
Notifications Telling you a long running task has finished Optional Nothing is lost, you check the screen instead. We would not market to you by notification. Settings, Notifications, then the app Settings, Notifications, App settings, then the app
Precise location Only where a feature is inherently about where you are Optional The feature is unavailable or falls back to a place you type. No background collection. Settings, Privacy and Security, Location Services, then the app Settings, Location, App permissions, then the app
Local file access Importing or exporting a file you choose Optional Import and export are unavailable. We use the system picker, which grants access to one file. Per file through the system picker, no standing permission Settings, Apps, the app, Permissions, Files
Tracking, the App Tracking Transparency prompt Not requested. See below. Not applicable Not applicable Not applicable Not applicable

App Tracking Transparency on iOS

We will not display the App Tracking Transparency prompt, because we will not track you. We will not access the Identifier for Advertisers, link data collected in our application to third party data for advertising or measurement, or share any identifier with a data broker. If that changed, the prompt would appear, this section would be rewritten first, and declining would never reduce what the application does.

Consistency with the store declarations

The Google Play Data Safety declaration and the Apple App Privacy labels for any application we publish will be filled in from this section, not written separately. If you find a difference between a store listing and this policy, treat it as an error and tell us at hello@pathfinderlabs.co.uk: we will correct whichever is wrong within five working days and say which it was. Where an application collects nothing, the declaration will say so rather than listing categories defensively.

21. Account closure and data deletion

Role: controller

There are no accounts on this website, so there is nothing here to close. The commitments below apply to any application or service we publish that does have accounts. The email route applies today to anything we hold about you.

In the application

Any application we publish will contain a deletion path inside the application itself, reachable without contacting us, at Settings, then Account, then Delete account. It will delete the account and the personal data associated with it rather than deactivating it, and will state on screen what is retained and why before you confirm.

By email

You can also email hello@pathfinderlabs.co.uk with “Delete my data” in the subject line. This route works whether or not you have used an application, and covers correspondence, enquiry records and anything else we hold about you as controller. We verify identity as described in section 16.9 first.

Timing

We complete deletion across live systems within 30 days of a verified request and confirm in writing when it is done. Copies inside routine backups are put beyond use immediately and removed as those backups cycle, which takes no longer than a further 30 days.

What is retained after deletion, and why

  • Accounting records that mention you, for six years from the end of the relevant accounting period, because section 388 of the Companies Act 2006 and tax legislation require it. We cannot delete an invoice on request.
  • The record of the deletion request itself, for six years, at the minimum needed to show it was handled properly: who asked, when, what was deleted and when it completed.
  • A suppression entry if you asked never to be contacted again, because honouring that means remembering the address to avoid.
  • Material needed for a live legal claim, restricted so it is used for nothing else and deleted when the matter ends.

Nothing else survives deletion: no shadow copy, no anonymised profile derived from your record, no export in a spreadsheet somewhere.

22. Children

Role: controller

This website and our services are directed at businesses and are not intended for children. We do not knowingly collect personal data from anyone under 13, and we would not build a general audience application without applying the ICO Age Appropriate Design Code to it first. If you believe a child has sent us personal data, tell us and we will delete it.

23. Automated decision making and profiling

Role: controller

We make no decisions about people by automated means and we profile nobody. Enquiries and job applications are read by a person. Nothing on this website scores, ranks or segments you, and no part of our process produces a legal or similarly significant effect on you without a human deciding it. Spam filtering on the mailbox is automated, but it decides where a message is filed rather than anything about you, and a message wrongly filtered is retrieved by a person on request.

24. Changes to this policy

Role: controller and processor

When this policy changes we change the effective date and version at the top. Where a change is significant, for example a new sub-processor, category of data, purpose or international transfer, we describe it in a short note at the top for at least 90 days rather than expecting you to compare versions. Where a change requires your consent, we ask before it takes effect rather than after.

25. How to contact us

Role: controller and processor

Email: hello@pathfinderlabs.co.uk, with a clear subject line such as “Subject access request”, “Delete my data” or “Data protection complaint”. Post: THE PATHFINDER LABS CORPORATION LIMITED, 30 Pettley Gardens, Romford, England, RM7 9AB, which is accepted but not monitored daily, so a time critical request should go by email.

We reply to email within two working days. Statutory deadlines run as described in section 16.9 and are unaffected by that shorter service commitment.