Your privacy at Polyphasic Developers.
This notice explains what personal data Polyphasic Developers Ltd collects, why we use it, who we may share it with, how long we keep it and the rights available to you.
Plain-English summary: We collect the information needed to run our website, respond to enquiries and deliver software services. We do not sell personal data. Optional Google Analytics stays off unless you allow it. You can contact us at any time about your information.
1. Who we are and what this notice covers
Polyphasic Developers Ltd (“Polyphasic Developers”, “PD”, “we”, “us” or “our”) is a software development company based in Lincoln, United Kingdom. For the personal data described in this notice, Polyphasic Developers Ltd is normally the data controller, which means we decide why and how that information is used.
This notice covers:
- visitors to polyphasicdevs.com and its public pages;
- people who contact us about projects, products, support or business matters;
- clients, prospective clients, suppliers and professional contacts; and
- personal data used to administer and deliver our own business services.
Some PD applications have a separate product-specific privacy policy. Where a separate notice is provided, it applies to that product and should be read alongside this notice where relevant.
When we build, host or support software for a client, we may process personal data on that client's instructions as a data processor. In that situation, the client is normally the controller, its privacy notice explains the processing, and our responsibilities are set out in the relevant contract or data-processing agreement.
2. The information we collect and why
We collect only the information reasonably needed for the purposes below. The exact information depends on how you interact with us.
| Information | How and why we use it | UK GDPR lawful basis |
|---|---|---|
| Name, role, organisation, email address, phone number and message content | To respond to enquiries, understand a proposed project, provide estimates and take steps towards a contract. | Steps at your request before entering a contract; legitimate interests in responding to business enquiries. |
| Client contacts, contracts, project correspondence, meeting notes, requirements, support requests and delivery records | To deliver and support agreed work, manage the relationship, document decisions and protect both parties if a dispute arises. | Contract; legitimate interests in project administration, service quality and legal protection. |
| Billing contacts, invoices, transaction references and accounting records | To invoice, receive payment, maintain accounts and meet tax and company-law obligations. We do not collect payment-card details through this website. | Contract; legal obligation; legitimate interests in financial administration. |
| Support information such as device, browser, app version, screenshots and steps to reproduce a problem | To investigate faults, provide support, maintain security and improve our products and services. | Contract where support is agreed; legitimate interests in resolving issues and improving services. |
| Website technical data such as IP address, requested URL, time, browser information and server/security logs | To deliver the website, maintain availability, diagnose faults, detect abuse and protect the site. | Legitimate interests in operating a secure and reliable website. |
| Optional analytics data such as pages viewed, approximate location, device category, referral source and interactions | To understand aggregate website use and improve content, navigation and performance. Analytics is activated only after you allow it. | Consent. |
| Supplier and professional contact details | To obtain services, manage suppliers, collaborate with delivery partners and maintain business records. | Contract; legitimate interests in running the business. |
Please do not include sensitive personal information in an initial enquiry unless it is genuinely necessary. If a project requires special-category or other sensitive data, we will assess the need, establish an appropriate legal basis and agree suitable safeguards before processing it.
3. Where information comes from
Most personal data comes directly from you when you email, call, meet with us, request support, enter a contract or work with us on a project. We may also receive business contact information:
- from a colleague, client or mutual contact who introduces you;
- from your organisation where you are its representative;
- from public professional sources such as a company website or professional profile; or
- automatically from website hosting, security and analytics systems as described in this notice.
6. International transfers
We are based in the UK, work with clients and team members internationally, and use technology providers that may process information outside the UK. When UK data-protection transfer rules apply, we use an available lawful mechanism such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another permitted safeguard. Where required, we also assess the destination and supplementary protections.
You may contact us for more information about the safeguard relevant to your personal data.
7. How we protect information
We use proportionate technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse or alteration. Depending on the system and risk, these measures may include access controls, multi-factor authentication, encryption in transit, managed backups, software updates, logging, supplier review, confidentiality obligations and limiting access to people who need the information.
No internet or storage system can be guaranteed completely secure. If we become aware of a personal-data breach, we assess it promptly and notify affected people and the Information Commissioner's Office where the law requires us to do so.
8. How long we keep information
We keep personal data only for as long as necessary for the purpose collected, including legal, accounting, security and dispute-management requirements. Our normal starting points are:
| Record | Normal retention |
|---|---|
| Unsuccessful or inactive project enquiries | Up to 24 months after the last meaningful contact, unless a longer period is justified or you ask us to delete it sooner. |
| Client contracts, project and support records | Normally for the relationship and up to six years afterwards, depending on contractual, limitation, insurance and legal requirements. |
| Invoices, transaction and tax records | Normally six years after the relevant financial period, or longer where law requires. |
| Supplier and professional contact records | For the relationship and normally up to six years afterwards where relevant to contracts or accounts. |
| Security and server logs | For a limited operational period set by us or the relevant infrastructure provider, unless needed longer to investigate an incident. |
| Google Analytics user and event-level data | Up to 14 months, subject to Google Analytics property settings and earlier deletion where appropriate. |
| Analytics consent choice | Up to six months. |
We may retain a minimal record of an objection, opt-out or rights request where needed to respect that choice and demonstrate compliance. Information may be deleted earlier when it is no longer needed.
9. Business communications and direct marketing
We use contact details to respond to requests and manage existing business relationships. If we send a direct-marketing message, we do so only where permitted by data-protection and electronic-marketing law. We do not share contact details with third parties for their own marketing.
You have an absolute right to object to direct marketing. You can opt out at any time by replying to the message or emailing [email protected]. Service messages about an active contract, security issue or support request are not marketing.
10. Your data-protection rights
Depending on the circumstances and lawful basis, UK data-protection law may give you the right to:
- be informed about how your personal data is used;
- request access to personal data we hold about you;
- request correction of inaccurate or incomplete information;
- request erasure in circumstances where the right applies;
- restrict processing in certain circumstances;
- receive or transfer data in a portable format where the right applies;
- object to processing based on legitimate interests and to direct marketing;
- withdraw consent at any time, without affecting processing that was lawful before withdrawal; and
- not be subject to certain decisions based solely on automated processing where they produce legal or similarly significant effects.
We do not use website or enquiry data to make decisions about you based solely on automated processing that produce legal or similarly significant effects.
To exercise a right, email [email protected]. Please describe your request clearly. We may ask for reasonable information to verify your identity and locate the relevant data. We normally respond within one month, subject to lawful extensions or exemptions. Rights are not absolute, and we will explain if a request cannot be fulfilled in full.
11. Questions and complaints
Please contact us first if you have a concern so we can investigate it. You also have the right to complain to the UK supervisory authority:
Information Commissioner's Office
Website: ico.org.uk/make-a-complaint
Telephone: 0303 123 1113
If you live outside the UK, you may also have the right to contact the data-protection authority where you live or work.
12. Children
This business website and our software-development services are not directed at children. We do not knowingly collect personal data from children through this website. If you believe a child has provided personal data to us, please contact us so we can assess and, where appropriate, delete it.
13. Third-party websites
The site links to client websites, app stores, social networks and other external services. We do not control those services or their privacy practices. Their own privacy notices apply when you follow an external link or use their service.
14. Changes to this notice
We review this notice when our services, suppliers or legal obligations change. The latest version is published on this page and the “last updated” date identifies the current version. We will use an appropriate additional notice if a material change requires your attention.
15. Contact Polyphasic Developers
For privacy questions, rights requests or complaints, contact:
Polyphasic Developers Ltd
Lincoln, United Kingdom
Email: [email protected]
Telephone: +44 330 111 0089