Privacy notice
Open any app on a store and you get a data safety panel: a short stack of cards saying what the app takes and why. This page is that panel for YYY Software Ltd, with the length limit removed and the reasoning left in.
1. Who is answering
Controller
The company behind this site and behind the apps is YYY SOFTWARE LTD. It decides what data is taken and why, which under the UK General Data Protection Regulation and the Data Protection Act 2018 makes it the controller. Every answer on this page is that company's answer.
YYY SOFTWARE LTD
Company number 16938311, England and Wales
Email: [email protected]
Postal: the office filed under company number 16938311, published by Companies House
Article 37 sets out when an organisation must appoint a Data Protection Officer. Our processing sits outside those triggers, so questions go to the company itself rather than to a named officer, at the address above.
2. How to read a card
Sections 4 to 16 are cards. Each one takes a single kind of information and puts the same seven questions to it. The wording of the questions is borrowed from the store panels on purpose, so that what you read here can be laid straight over what you read before installing.
What each question means
Collected. Whether the information reaches us or a company working for us. Data that is created on your phone and stays on your phone is not collected, however personal it is.
Linked to you. Whether the information sits against something that identifies you, such as an email address or an account. Counted numbers with no name attached are not linked.
What it is for. The actual use. Not the widest use we could imagine one day.
Who else sees it. Any other organisation the information passes through, and what its role is.
Deletable. Whether you can make it go, and what happens when you ask.
Lawful basis. The Article 6 ground that makes the processing lawful. Nothing is processed without one.
Kept for. How long it survives before deletion, and what starts the clock.
A card marked not collected is still worth reading. Phones hold plenty that an app of this kind could ask for and does not, and a stated no is more use to you than silence.
3. The two roles we can be in
Both roles
Data protection law hangs everything on who chose the purpose. Choose it yourself and you are a controller, carrying the duties. Act on somebody else's instruction and you are a processor, carrying fewer.
For this website and for our own applications, the choice is ours, so the controller duties are ours: publishing this notice, answering your rights requests, reporting breaches, keeping records. Section 30 covers the narrower situation in which another organisation decides and we merely carry out the work.
The suppliers listed in section 23 are mostly our processors. They hold data because we asked them to, under a written contract that meets Article 28, and they are not free to use it for their own ends.
Your email address
- Collected
- Yes, if you send us mail. There is no other way for it to arrive.
- Linked to you
- Yes. An address is an identifier, and we treat it as one.
- What it is for
- Writing back. Keeping a thread findable if you write again.
- Who else sees it
- The company we buy mail hosting from, as our processor.
- Deletable
- Yes. Ask and the thread goes, sent copies included.
- Lawful basis
- Article 6(1)(f), legitimate interests: answering someone who wrote to us. Article 6(1)(a), consent, for the update list.
- Kept for
- 24 months after the last message in the thread.
This site has no forms. Every route on the contact page is a mail link, which means your address arrives because your own mail client put it there, and we never see it before you decide to press send.
Ask to join the update list and the consent is the whole basis for holding you on it. Withdrawing is a sentence in a reply, and it takes effect when we read it. We hold a note that you asked to stop, because forgetting that would mean adding you back by accident later.
Your address is never sold, rented, swapped or handed to anyone compiling a marketing list. The mail host is the only other party that touches it, and it does so because delivering mail is impossible otherwise.
What you write to us
- Collected
- Yes. The body of your message, plus anything you attach.
- Linked to you
- Yes, through the address it came from.
- What it is for
- Understanding the question well enough to answer it.
- Who else sees it
- The mail host. An adviser only if the message turns into a legal matter.
- Deletable
- Yes, on the same terms as card 01.
- Lawful basis
- Article 6(1)(f) for ordinary correspondence. Article 6(1)(c) where a message is a rights request we are obliged to handle.
- Kept for
- 24 months, except rights requests and security reports at 36 months.
You control the contents. If you would rather not put a detail in writing, leave it out and say so, and we will work with what you have given us.
Two kinds of message are kept longer than the rest, and for one reason: they are evidence. A rights request has a statutory clock on it, and Article 5(2) makes us able to show we met it. A reported vulnerability leaves a record of what was found and what was done about it. Both are held for 36 months from the day the matter closes, then deleted.
Web request records
- Collected
- Yes, by the network in front of this site, not by us.
- Linked to you
- No. We never join a request record to a name or an address.
- What it is for
- Serving pages, blocking attacks, keeping the site up.
- Who else sees it
- Cloudflare, Inc. and Cloudflare Limited, as our processors.
- Deletable
- Not individually. The records expire on the provider's own short cycle.
- Lawful basis
- Article 6(1)(f), legitimate interests: keeping a public website available and defended.
- Kept for
- The provider's schedule, measured in days. We hold no copy.
Fetching a page means telling a server where to send it. The record that results contains an IP address, the browser string your software announces, the path requested, a timestamp and the response code. This is how the web works rather than something we chose to gather.
There is no analytics product on this site. No pageview is counted, no visitor is scored, no funnel is built, and nothing at all is passed to an advertising network. The request records exist so that pages arrive and attacks do not, and they are stale within days.
Because we take no copy and cannot pick you out of the traffic, a request to erase a specific record has nothing we could act on. The cookie notice covers the small number of security cookies the same layer may set.
What you tap inside an app
- Collected
- No. Screen views, taps and session lengths stay on the handset.
- Linked to you
- Not applicable, since nothing leaves.
- What it is for
- Running the app in front of you. That is the whole use.
- Who else sees it
- Nobody.
- Deletable
- Yes, by deleting the app.
- Lawful basis
- None needed for on-device use, because no personal data reaches us.
- Kept for
- As long as the app is installed.
Behaviour telemetry is the ordinary way a mobile product is measured, and it is the thing we have decided against. An app of ours does not carry a third-party analytics kit, does not build a usage profile, and does not send a stream of events anywhere for someone to plot.
What replaces it is slower and less flattering: we use the thing daily, we read what people write to us, and we watch which parts of a screen have to be explained. A product this small can afford to learn that way.
If an app of ours genuinely cannot work without measurement, the answer on this card changes before that app reaches anyone, its store listing says so, and the app asks first.
Crash and performance reports
- Collected
- Only if you turn it on. The switch starts off.
- Linked to you
- No. A report carries no account and no address.
- What it is for
- Finding the line of code that failed and fixing it.
- Who else sees it
- A contracted diagnostics provider, as processor, named on request.
- Deletable
- Yes. Switch it off and the sending stops; ask and the stored reports go.
- Lawful basis
- Article 6(1)(a), consent, given by the switch and withdrawable at it.
- Kept for
- 12 months, then deleted.
A crash report is a stack trace, the model of handset, the operating system version and the build number. It is the software describing its own failure. It does not contain the contents of what you were working on.
Apple and Google both run their own crash reporting through the store and the operating system, under settings you control on the device rather than in our app. Those channels belong to them, and turning them on or off is done in the phone's own privacy settings.
Consent given here is not a price of entry. An app of ours works the same with the switch left alone, and nothing is withheld from anyone who declines.
Things you make in an app
- Collected
- No, unless a feature is explicitly about sending it somewhere.
- Linked to you
- Only where an account exists to sync it.
- What it is for
- The feature you asked for, and nothing beside it.
- Who else sees it
- An application hosting provider, as processor, where sync is involved.
- Deletable
- Yes. In the app, and by asking us.
- Lawful basis
- Article 6(1)(b), performing the service you signed up for.
- Kept for
- As long as the account exists, plus 30 days once you ask for it to go.
Notes, lists, entries, drafts: whatever an app of ours lets you write, the default home for it is the storage area the operating system gives that app on your own handset. No copy is taken for us to look at.
Some things cannot work locally. Sending something to another person, or having the same list on a phone and a tablet, requires a server by definition. Where that is the point of a feature, the screen that does the sending says where it goes, and this notice is updated to match before the feature ships.
Your own device backups are a separate matter. If iCloud or Google's backup service is copying the app's storage area, that copy sits under the terms you have with Apple or Google, and it is deleted according to their rules rather than ours.
Photos, files and the camera
- Collected
- No. Nothing from your library or your storage is uploaded.
- Linked to you
- Not applicable.
- What it is for
- Where a feature needs a picture, it is used on the handset and left there.
- Who else sees it
- Nobody.
- Deletable
- Yours already. Delete it in Photos or Files.
- Lawful basis
- None needed, since nothing is transmitted to us.
- Kept for
- Not held by us at any point.
Modern phones let an app ask for one picture rather than the run of the library, and that is the form of the request we use where a picture is needed at all. The narrower ask is the correct one, and the operating system enforces it.
Metadata deserves its own sentence, because a photograph often carries the place and moment it was taken. Anything of that kind stays inside the file, on your handset, and is not read out and stored separately.
Where the phone is
- Collected
- No. Precise and approximate location alike.
- Linked to you
- Not applicable.
- What it is for
- Nothing. No feature of ours currently turns on where you are.
- Who else sees it
- Nobody.
- Deletable
- Not applicable.
- Lawful basis
- Not applicable.
- Kept for
- Not applicable.
Location is the permission most often taken for reasons that have little to do with the feature that asked for it. An app of ours does not request it in the background, and does not ask for it while in use either.
Where an app of ours is about a place, location becomes the point rather than a side effect: the permission is asked for on the screen where it is needed, the store listing declares it, this card is rewritten, and refusing leaves the rest of the app working.
An IP address seen by the hosting network under card 03 gives a rough idea of country. That is a property of internet routing, it is not read as location by us, and it is never combined with anything else.
Contacts, calendar and messages
- Collected
- No. Not the address book, not the diary, not your texts or call log.
- Linked to you
- Not applicable.
- What it is for
- Nothing.
- Who else sees it
- Nobody.
- Deletable
- Not applicable.
- Lawful basis
- Not applicable.
- Kept for
- Not applicable.
An address book belongs to more people than the one holding the phone. Uploading it hands over details that everyone in it gave to your handset and to nobody else, and no invite feature is worth that trade.
The same reasoning covers your diary and your messages. Where a feature ever needs to put something in a calendar, the right shape is a single event handed to the operating system for you to confirm, without our software reading what is already there.
Health, fitness and body readings
- Collected
- No. Nothing is read from Apple Health or Health Connect.
- Linked to you
- Not applicable.
- What it is for
- Nothing.
- Who else sees it
- Nobody.
- Deletable
- Not applicable.
- Lawful basis
- Not applicable. Section 17 explains the extra bar this data would have to clear.
- Kept for
- Not applicable.
Steps, heart rate, sleep, cycles, weight: the stores treat these as their own category, and the law treats most of them as health data with a higher bar again. Our apps stay outside that category.
Anything you record yourself in an app of ours, in a note or a list, is app content under card 06 and lives on the handset. It is not passed into a health store, and nothing is taken out of one.
Purchases and payment
- Collected
- Not by us. The store bills you and keeps the card details.
- Linked to you
- At the store, yes. At our end, only a receipt total.
- What it is for
- Unlocking what you paid for, and our own books.
- Who else sees it
- Apple, Google and our accountant.
- Deletable
- No, while tax law requires the record. Section 25 gives the period.
- Lawful basis
- Article 6(1)(b) for the purchase, Article 6(1)(c) for keeping accounts.
- Kept for
- Six years, counted from the close of the financial year.
Paid apps and subscriptions on iPhone and Android are billed by the store, not by us. Your card number, billing address and payment history sit with Apple or with Google, each acting as controller for that relationship, under privacy terms you accepted when you set the account up.
What reaches us is a settlement report: sales by product and by territory, with amounts. It is not a list of customers, and it does not carry card details.
Where a purchase generates a record we must keep, the obligation comes from company and tax law rather than from us, and it is the one thing on this page that survives a deletion request. Section 386 of the Companies Act 2006 and the corporation tax rules set six years as the working minimum.
Device and advertising identifiers
- Collected
- No. No advertising identifier is requested on either platform.
- Linked to you
- Not applicable.
- What it is for
- Nothing. Our apps carry no advertising and no attribution kit.
- Who else sees it
- Nobody.
- Deletable
- Not applicable.
- Lawful basis
- Not applicable.
- Kept for
- Not applicable.
The identifier for advertisers on iPhone and the advertising ID on Android are the hooks that let one company recognise a handset inside another company's software. Neither is asked for here, which is why section 21 explains that no tracking prompt appears.
Where an app of ours needs to tell one installation from another, the correct tool is a value generated on the handset for that app alone, which the operating system throws away when the app is removed and which cannot be read by anyone else's software.
What you search for
- Collected
- No. Search terms typed in an app of ours stay in it.
- Linked to you
- Not applicable.
- What it is for
- Finding the thing you are looking for, on the handset.
- Who else sees it
- Nobody.
- Deletable
- Yes, by clearing it in the app or removing the app.
- Lawful basis
- None needed, since nothing reaches us.
- Kept for
- Until you clear it.
What a person types into a search box is often more revealing than anything else they do in an app, which is exactly why it is the sort of data that gets harvested. Searching in an app of ours is a local operation against local content.
This website carries no search box at all, so there is nothing on the site side to record.
17. Sensitive categories and offence records
Controller
Article 9 fences off a set of especially revealing categories: what your body is doing, who you sleep with, what you believe, where your ancestors came from, whether you belong to a union, and biometric or genetic readings that identify you. Article 10 does something similar for criminal convictions and offences.
None of this is sought by the website or by an app of ours. The cards above say so one category at a time, because a general reassurance is easier to write and worth less.
You can still put such a thing in an email to us, and people occasionally do while explaining a problem. Where that happens it is held as part of the correspondence and deleted on the schedule in section 25, and it is not indexed, tagged or used to sort you into anything. If you would rather not have it sitting in a mailbox at all, say so in the message and it will be taken out.
Should a future feature ever need a category from Article 9, an Article 6 basis would not be enough on its own. A second condition from Article 9(2) and from Schedule 1 to the Data Protection Act 2018 would have to apply, and this notice would carry it before the feature shipped.
18. Age, and who these apps are for
Controller
This website is written for adults, and nothing on it is aimed at children. We do not knowingly hold data about a child through it.
Section 9 of the Data Protection Act 2018 sets 13 as the age at which a child can consent for themselves to an online service. Below that, consent has to come from whoever holds parental responsibility. Where an app of ours ever relies on consent, it will be built to that line rather than around it.
The Information Commissioner's Age Appropriate Design Code applies to services likely to be accessed by children, and it asks for a standard of care rather than an age gate: privacy settings that start at the protective end, no nudges towards giving up more, no design pattern built to keep a child in the app. Those are the terms our apps are drawn to. Every card above answers the same for a fourteen-year-old as for anyone else, because the answers do not depend on knowing who you are.
Store listings carry a content rating and an age band, set through Apple's and Google's own questionnaires. Where a rating and this notice ever appear to disagree, write to us and we will fix whichever is wrong.
A parent or guardian who believes a child's data has reached us can write to the address in section 34. We will look, we will say what we found, and where there is something to delete it will be deleted rather than justified.
19. Every lawful basis, in one place
Controller
Each card names its own basis. This table gathers them so the pattern is visible in one view, with the interest being pursued spelled out wherever legitimate interests is the basis, as Article 13(1)(d) requires.
| Purpose | Basis | The reasoning behind it |
|---|---|---|
| Replying to mail you send | Article 6(1)(f) | Someone who writes to a company expects an answer; the interest is mutual and the data is what you chose to send |
| Holding you on the update list | Article 6(1)(a) | You asked to be on it, and the asking is the basis; leaving is a sentence in a reply |
| Serving the website and repelling attacks | Article 6(1)(f) | A site that is down or defaced serves nobody; the processing is connection data only |
| Running an app account, and syncing what it holds | Article 6(1)(b) | Without it the service you signed up for cannot be delivered |
| Optional crash diagnostics | Article 6(1)(a) | A switch that starts off, and consent that ends when you move it back |
| Answering a rights request | Article 6(1)(c) | Chapter III of the UK GDPR makes it an obligation, not a courtesy |
| Keeping books and tax records | Article 6(1)(c) | Companies Act 2006 and HMRC rules; the period is not ours to choose |
| Investigating a reported vulnerability | Article 6(1)(f) | Security of the software and of the people using it |
| Defending or bringing a legal claim | Article 6(1)(f) | A party to a dispute needs its own records; used only if a dispute arises |
Legitimate interests is the basis most easily stretched, so it is the one we test hardest. Each row above was weighed against what you would reasonably expect, and each is limited to data you either sent us or generated by connecting. Where the balance came out the other way, the row is not there. Section 31 explains how to object to any of them.
20. Phone permissions, and taking them back
Controller
A permission prompt is a promise with a button on it. The rule our apps follow is that a prompt appears at the moment the feature is used, never on first launch as a sweep, and that saying no leaves everything else working.
Whatever you grant, you can take back, and you do not need us to do it:
On iPhone and iPad
Open Settings, scroll to the app, and every permission it holds is listed with a switch. Settings, then Privacy & Security, gives the same information organised by permission instead of by app, which is the better view when you want to see everyone holding a particular one.
On Android
Open Settings, then Apps, choose the app, then Permissions. Settings, then Privacy, then Permission manager gives the by-permission view. Recent Android versions also revoke permissions automatically for apps you have not opened in a while, and that behaviour is fine by us.
Removing a permission takes effect at once. An app of ours is written to carry on without one rather than to nag, and no screen will hold a feature hostage until you go back and grant it.
21. App Tracking Transparency on iPhone
Controller
App Tracking Transparency is Apple's rule that an app must ask before linking what it knows about you to data held by other companies for advertising or measurement. The prompt is the familiar one asking whether an app may track you across apps and websites owned by other companies.
You will not see that prompt from an app of ours, and the reason is plain: there is nothing behind it. No advertising identifier is requested, as card 12 records, and nothing about you is joined to a data set belonging to anyone else. An app that does not track has no honest reason to display a prompt asking to.
The permission itself remains yours to inspect. Settings, then Privacy & Security, then Tracking lists every app that has asked, and lets you switch off the ability to ask at all.
Apple's own privacy labels sit on each store listing under App Privacy, and are generated from declarations the developer files. Ours are filed to match the cards on this page. If a label and a card ever diverge, treat it as a mistake worth reporting, and write to us.
22. The Data Safety form on Google Play
Controller
Google Play requires a Data Safety declaration for every listing: which of Google's data types the app collects, which it shares, whether each is required or optional, whether data travels encrypted, and whether a user can request deletion. Google publishes the answers on the store page and holds the developer to them.
The card format on this page follows that form deliberately. The store panel gives you a line per data type; this page gives you the same line with the reasoning attached, so the two can be read against each other in a minute.
| Declaration on the listing | Our position | Card |
|---|---|---|
| Data collected | Diagnostics, if you switch it on. Account and content data, only where a feature syncs | Cards 05, 06 |
| Data shared with third parties | None. Processors acting on our instructions are not third parties for this purpose | Section 23 |
| Data encrypted in transit | Yes, on every connection | Section 26 |
| Deletion route offered | Yes, in the app and by email | Section 28 |
| Required or optional | Diagnostics optional; account data required only for the account feature itself | Cards 05, 06 |
| Independent security review | Not claimed on the listing | Section 26 |
Both stores also let a developer publish a link to a privacy policy. That link points here. Where a store panel and this page cannot both be right, this page is the one we will correct the other against, and the correction goes in at the next release rather than waiting.
23. Everyone who touches any of it
Controller
A processor holds data because we asked, does only what the contract permits, and cannot use it for itself. Article 28 sets out what that contract must contain: instructions in writing, confidentiality, security, help with your rights requests, no sub-processor without permission, and deletion or return at the end. Every processor below is engaged on those terms.
| Organisation | Capacity | What it handles | Where | Transfer route |
|---|---|---|---|---|
| Cloudflare, Inc. and Cloudflare Limited | Processor: hosting, delivery, protection | Web request and security records, card 03 | Edge network, partly outside the UK | EU Standard Contractual Clauses carrying the UK Addendum |
| Our contracted mail host | Processor: receiving, storing and sending mail | Cards 01 and 02 in full | Named on request | As section 24, where relevant |
| Google Ireland Limited and Google LLC, for the lettering | Separate controller for the font request itself | IP address and browser string, at the moment a typeface is fetched | Ireland and the United States | Requested by your browser, not sent by us |
| Apple Distribution International Ltd and Apple Inc. | Separate controller for anything bought through the store | Store account, billing, subscription state, store metrics | Ireland, the United States and elsewhere | Apple's own arrangements |
| Google Ireland Limited and Google LLC, for Google Play | Separate controller for anything bought through the store | Store account, billing, subscription state, store metrics | Ireland, the United States and elsewhere | Google's own arrangements |
| Our contracted app hosting and diagnostics providers | Processors, engaged only where a feature needs a server | Cards 05 and 06 | Named on request | As section 24, where relevant |
| Our accountant | Processor for bookkeeping, controller for their own professional duties | Invoices, receipts, settlement reports | United Kingdom | Not applicable |
Two entries are named on request rather than on the page, because a supplier can change and a stale name in a policy is worse than none. Ask at the address in section 34 and you will be told who they are, which country each processes in, and the safeguard in place. That reply is not conditional on you being a customer.
Beyond this table, data goes out only where a court, a regulator or a law enforcement body is entitled to it, or where a professional adviser needs it for a live matter. Each such request is checked against the power claimed rather than waved through. Were the business ever sold or reorganised, records would pass with it, and a notice of that would go on this page.
24. Data that leaves the United Kingdom
Controller
Some of the organisations above operate outside the UK. Chapter V of the UK GDPR allows that only through defined routes, and these are the ones relied on here.
Adequacy
Where the destination is covered by UK adequacy regulations made under Article 45 and section 17A of the Data Protection Act 2018, nothing further is needed. The European Economic Area is covered, along with the other countries the Secretary of State has recognised. For a United States organisation certified under the UK Extension to the EU–US Data Privacy Framework, we check the certification is live and covers the kind of data in question before leaning on it.
Contractual safeguards
Without adequacy, the route is the International Data Transfer Agreement, or the International Data Transfer Addendum bolted onto the European Commission's Standard Contractual Clauses, both issued under section 119A of the Data Protection Act 2018. In practice a supplier offers a data processing addendum built on the EU clauses with the UK Addendum on top, and that is the form we accept.
Checking the destination
Signing clauses is not the end of it. Before relying on them we look at the law and the practice of the country involved, at how sensitive the data is, and at what protects it in transit and at rest. Our processing is narrow and holds nothing from Article 9, which keeps the risk low, but the assessment is carried out rather than presumed.
Seeing the paperwork
Ask for the safeguard covering a transfer that affects you and you will get it. Commercial terms with no bearing on your data may be blanked; the parts describing what protects the data will not be.
25. How long each thing survives
Controller
Article 5(1)(e) says data must not be kept longer than the purpose needs. A period picked because it sounded reasonable is not a policy, so every row here carries the reason that produced the number.
| Record | Period | Why that long | What then |
|---|---|---|---|
| Web request and security records | The provider's own short cycle, in days | Useful for availability and defence while fresh, useless once stale | Expired or aggregated by the provider; we hold no copy |
| Ordinary correspondence | 24 months from the last message | Long enough to pick a thread back up, short enough that old mail does not accumulate | Deleted, sent copies included |
| Update list membership | Until you withdraw, or 36 months of silence | Consent that has sat unused for three years no longer means much | Deleted, apart from a note that you asked to stop |
| Rights requests and our replies | 36 months from closure | Article 5(2) requires us to be able to show the request was handled properly | Deleted |
| Vulnerability reports | 36 months from closure | Knowing what was reported and what was fixed is part of security | Deleted or stripped of identifying detail |
| App account data | As long as the account exists, plus 30 days once deletion is asked for | It exists to run the account; thirty days is the commitment we hold ourselves to | Live systems first, backups within 90 days |
| Optional crash diagnostics | 12 months | A crash from two release cycles back tells you nothing about today's build | Deleted |
| Accounting and transaction records | Six years, counted from the close of the financial year | Companies Act 2006 section 386 and the tax rules make six years the floor | Deleted or destroyed securely |
| Supplier and adviser records | Six years, counted from the day the relationship ends | The Limitation Act 1980 leaves a contract claim possible for six years | Deleted |
| Statutory registers and filings | The life of the company, and beyond dissolution | Required by the Companies Act 2006; not a choice we make | Handled as the legislation directs |
| Backups | Rotating, overwritten within 90 days | A backup exists to restore from disaster, and editing one selectively defeats it | Overwritten |
Deleting from live systems happens when you ask. Backups are the honest exception: they are sealed copies, and reaching into one to remove a single record would compromise the thing they exist for. Restored data is re-deleted immediately, and the cycle above puts an outside limit of 90 days on the wait.
26. What guards it
Controller
Article 32 requires security proportionate to the risk. Here is what that means in practice on a small estate.
Every connection to this site and to any app of ours runs over TLS, with the strict transport header set so a browser will not fall back to plain HTTP. Content security rules on the site restrict what may execute and where anything may be fetched from, which shuts the door on injected scripts. The site is static: no database sits behind it, no form posts anywhere, and no interpreter runs on a page request, which removes whole classes of attack rather than defending against them.
Accounts holding company data carry a second factor. Access follows need rather than seniority, and there is not much of either to spread around. Suppliers are chosen partly on what they publish about their own security, and each contract contains the Article 28 terms above.
No system is beyond compromise, and a page claiming otherwise would be telling you something untrue. What we can say is what is in place, which is above, and what happens if it fails, which is next.
27. If it goes wrong
Controller
A personal data breach means a security failure that destroys, loses, alters or exposes personal data, whether by accident or by attack. It is wider than a hack: mail sent to the wrong recipient counts, and so does a lost laptop.
The procedure, in order. The failure is contained first and the scope established: what data, how many people, how bad the consequences could be. Article 33 then gives us 72 hours from becoming aware to report it to the Information Commissioner, unless the risk to people is unlikely; where the 72 hours cannot be met in full, we report what we have and follow with the rest. Article 34 adds a duty to tell the people affected directly where the risk to them is high, in plain language, saying what happened, what it means for them and what to do about it. An internal record is kept whether or not either report is required, because Article 33(5) says so and because the pattern of near misses is where the next fix comes from.
What we will not do is wait for certainty before telling you something that affects you, or describe an incident in language designed to make it sound smaller than it was.
If you think something has gone wrong with data of yours, write to [email protected]. A message of that kind goes to the front of the queue.
28. Account deletion, and deleting everything else
Controller
Both stores require an app with accounts to offer a route to delete your account and the data behind it, reachable from inside the app and from outside it. That is the standard here.
From inside an app
Where an app of ours has an account, the settings screen carries the account deletion control, and it does not hide behind a support conversation. Confirming it removes the account and everything held against it from live systems, then from backups on the 90-day cycle in section 25.
By writing
Send a message to [email protected] asking us to delete your data, and say how much of it you mean. That covers an app account, the whole of your correspondence with us, your place on the update list, or all of it together. Where the mailbox alone does not establish who you are, we may need one more thing to check it, asked for narrowly rather than as a document round.
What deletion cannot reach
Two things survive, and both are outside our discretion. Accounting records tied to a purchase are held for the statutory period in section 25. A suppression note that you asked for no further mail is itself the mechanism that keeps the promise. Everything else goes.
The store account is separate
Deleting an app account of ours does not touch your Apple or Google account, your purchase history there, or your subscription. Those live with the store, and are managed in the store's own settings. Removing an app from a handset is likewise not a deletion request to us, because a request has to reach us before it can be acted on.
29. Decisions made by machine
Controller
Article 22 covers decisions taken about you by automated means alone, where the effect is legal or similarly significant: refusing credit, filtering an application, pricing by profile. Nothing on this site or in an app of ours makes a decision of that kind, so the Article 22 safeguards are not engaged.
Nor is anyone profiled. No score is calculated about you, no segment is assigned, and no model is trained on your data to predict what you will do next. Were that to change, this section would carry the logic involved, what it means for you, and the route to a human being, before rather than after.
30. When we are the processor
Processor
Occasionally another organisation decides the purpose and we carry out the work: an application built to a specification, or a system supported on someone else's behalf. In that arrangement they are the controller and we are the processor, and the duties change shape.
What that means in practice: we act on their written instructions and nowhere beyond them; we keep the data confidential and secure; we take no sub-processor without their agreement; we help them meet their own obligations, including answering the rights requests that reach them; and at the end of the work we delete or return the data as they direct.
The person whose data it is deals with the controller rather than with us, because they hold the relationship and the duty to answer. If a request of that sort arrives here by mistake, we pass it to them promptly and tell you that we have, rather than answering something that is not ours to answer.
31. Your rights, and how to fire one
Controller
Chapter III of the UK GDPR gives you a set of rights over data about you. They are exercised by asking, in whatever words you like, to [email protected].
| Right | Article | What it gets you from us |
|---|---|---|
| Being told | 13 and 14 | This page, which is the notice itself |
| Access | 15 | A copy of what we hold about you, with the purposes, recipients and periods |
| Correction | 16 | Anything wrong put right, and anything incomplete completed |
| Erasure | 17 | We delete your data, subject only to the two exceptions in section 28 |
| Restriction | 18 | Processing paused while a dispute about accuracy or basis is settled |
| Portability | 20 | Data you gave us, in a machine-readable file, where consent or contract is the basis |
| Objection | 21 | A stop, unless we can show grounds that override yours; absolute for direct marketing |
| Withdrawing consent | 7(3) | An end to anything resting on consent, from the moment you say so |
| Not being profiled by machine | 22 | Nothing to apply here, as section 29 explains |
How a request is handled
Article 12(3) sets the deadline at one month from receipt, extendable by two further months for a request that is genuinely complex, in which case we tell you inside the first month and say why. Nothing is charged. Where we cannot tell from the message that the request is really from you, we ask for one thing that would settle it, and the clock waits for that answer rather than running down.
If we decline any part of a request, you get the reason in writing along with the route to challenge it, which is section 32. A refusal without an explanation is not an answer.
32. Taking it to the ICO
Controller
The Information Commissioner's Office regulates data protection in the United Kingdom, and you may complain to it about how we have handled your data. Article 77 gives you that right directly, and nothing on this page limits it.
Coming to us first is often quicker and sometimes fixes the thing outright, but it is a suggestion and not a condition. You are free to go straight to the regulator, and doing so will not change how we treat you afterwards.
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
Online: ico.org.uk/make-a-complaint
The ICO charges nothing to consider a complaint, and there is no requirement to be represented by anyone.
Section 168 of the Data Protection Act 2018 also lets a court award compensation for damage caused by a contravention, and Article 79 preserves the route to a judicial remedy. Those sit alongside a complaint rather than instead of it.
33. When this page changes
Controller
This notice changes when the facts change: a new feature that touches data, a supplier swapped out, a period revised, a card that needs a different answer. The date and version at the top move with it.
A wording tidy goes in quietly. A change to what is collected, why, who sees it or how long it lives is different, and it will be described here rather than folded in silently. Where a change needs your consent, you will be asked before it takes effect and not told about it afterwards. Where it materially affects someone on the update list, a message goes out.
The store listings carry declarations that have to match this page. A change here that affects a card triggers an update to the App Privacy labels and to the Play Data Safety form at the next release.
34. Where to write
Both roles
Rights requests, questions about a card, complaints about how any of this has gone: one address takes all of them, and the company answers rather than a ticketing system.
YYY SOFTWARE LTD
Email: [email protected]
Company number 16938311, England and Wales
Post: the office filed under that number, published by Companies House
Post reaches us, but writing electronically is what the company can answer properly. Naming the right you are using at the top of the message is the fastest way to get it dealt with under section 31.