UK GDPR & Data Protection Policy
This policy explains how Software and AI Services Ltd handles personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It sits alongside our Privacy Policy (which is written for the people whose data we handle) and our Information Security Policy (which describes the technical and organisational controls we apply).
1. Our roles
- We act as a data controller for personal data we collect and use ourselves — for example, enquiries and client contact details.
- We act as a data processor when we build, host or operate systems on behalf of clients that hold personal data belonging to the client’s users. In that role, the client remains the controller and we process data only on the client’s documented instructions, under a written Data Processing Agreement (DPA).
2. Principles
We follow the seven UK GDPR principles in Article 5:
- Lawfulness, fairness and transparency — we tell people what we do with their data and only process it where we have a lawful basis.
- Purpose limitation — data is only used for the purposes we have communicated.
- Data minimisation — we collect no more than we need.
- Accuracy — we keep records accurate and up to date, and correct them promptly on request.
- Storage limitation — data is retained no longer than needed.
- Integrity and confidentiality — data is protected by the technical and organisational controls in our Information Security Policy.
- Accountability — we can demonstrate compliance with these principles.
3. Lawful bases we rely on
- Consent — for optional cookies and any direct marketing.
- Contract — for personal data we need to enter into or perform a contract with you or your organisation.
- Legitimate interests — for responding to enquiries, running our business and keeping systems secure. We balance our interests against your rights.
- Legal obligation — where we must keep records for accounting, tax or regulatory reasons.
Where we act as a processor for a client, the client identifies the lawful basis.
4. Records of processing activities (Article 30)
We maintain a record of our processing activities describing the categories of data subjects and personal data, the purposes and lawful bases, the categories of recipients, retention periods and applicable security measures. This record is available to the Information Commissioner’s Office (ICO) on request.
5. Data subject rights
We support the full set of rights under Articles 15–22 UK GDPR: access, rectification, erasure, restriction, portability, objection, and rights in relation to automated decision-making (we do not make significant decisions about individuals by purely automated means).
Requests can be made by email to privacy@softwareandaiservices.co.uk. We respond within one month of receipt of a valid request and may extend this by up to two further months for complex requests, notifying the requester of the extension. Where we act as a processor for a client, we forward the request to the client without undue delay and support them in responding.
6. International transfers
Where personal data is transferred outside the UK, we rely on a UK-recognised transfer mechanism — such as UK Adequacy Regulations, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses — supplemented by contractual and technical safeguards as appropriate.
7. Personal-data breach response
Confirmed or suspected personal-data breaches are triaged under our incident response process. Where we act as controller, the ICO is notified within 72 hours of becoming aware if the breach is likely to result in a risk to individuals’ rights and freedoms, and individuals are informed where the risk is high. Where we act as processor, we notify the affected client without undue delay and support their assessment and communications.
8. Data Protection Impact Assessments (DPIAs)
We carry out DPIAs before starting processing that is likely to result in a high risk to individuals’ rights — for example, large-scale processing of special-category data or systematic monitoring at scale. Where we are the processor, we support the client in completing their own DPIA.
9. Sub-processors
Where we act as a processor on behalf of a client, we only use sub-processors under a written contract that imposes materially the same data-protection obligations that apply to us. Sub-processors are disclosed to the client and prior authorisation is obtained as required by the client’s DPA.
10. Data Protection Officer
Data-protection queries at Software and AI Services Ltd are handled by the Director, who is the point of contact for the ICO and for data subjects, via privacy@softwareandaiservices.co.uk. A statutory Data Protection Officer under UK GDPR Article 37 will be appointed if and when required by the nature or scale of the processing we carry out.
11. Complaints
Please raise data-protection concerns with us first at privacy@softwareandaiservices.co.uk — we take them seriously. If you are not satisfied with our response, you have the right to complain to the Information Commissioner’s Office:
- Website: ico.org.uk
- Helpline: 0303 123 1113
12. Review
This policy is reviewed at least annually and following any material change to the way we process personal data.
Software and AI Services Ltd is registered in Northern Ireland, company number NI732919. Registered office: 98 Larne Road, Ballyclare, Northern Ireland, BT39 9UD. Policy last updated: August 2026.