Data Protection & Privacy Policy¶
| Distribution | Employees and Contractors; Clients upon request |
| Version | 1.0 |
| Approved | 2024-03-02 |
| Approved by | Leadership |
Purpose¶
This policy defines how FooEngine Ltd. complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 in the handling of personal data.
Scope¶
This policy applies to all employees, contractors, systems, and third-party service providers processing personal data on behalf of the company.
Data Controller and Processing Roles¶
FooEngine Ltd. acts as the Data Controller for personal data processed in the course of business operations.
The company is registered with the UK Information Commissioner's Office (ICO) under registration reference ZB177982.
Depending on the service provided and the nature of information received, FooEngine Ltd. may also act as a Data Processor on behalf of its clients, processing personal data only in accordance with client instructions and applicable contractual requirements.
Personal Data Processed¶
The company processes limited personal data necessary for business operations, including:
- Client and partner contact details
- User account information
- Supplier and contractor contact details
- Internal HR administration records
FooEngine Ltd. does not process consumer marketing data, behavioural profiling data, or sell personal data.
Lawful Basis for Processing¶
Personal data is processed under one or more of the following lawful bases:
- Contractual necessity
- Legitimate business interest
- Legal or regulatory obligation
Data Storage and Retention¶
Personal data is stored securely within company-approved systems and cloud environments. Data is retained only for as long as necessary for business or legal purposes in accordance with the company's data retention schedule.
Data Sharing¶
Personal data is shared only with approved third-party service providers where required for service delivery.
All such providers operate under contractual confidentiality and information-security obligations.
Data Subject Rights¶
Individuals may request access, correction, restriction, or deletion of their personal data in accordance with UK GDPR requirements.
Security of Personal Data¶
Personal data is protected through technical and organisational security measures defined in the company Information Security Policy.
Data Breach Management¶
Any personal data breach will be managed under the company Incident Response process.
Where required, breaches will be reported to the ICO within 72 hours.
International Operations¶
FooEngine Ltd. provides services to clients in multiple regions including Europe (including the Nordics), Canada, Latin America, Australia and the United States.
Personal data processed in support of these services is handled in accordance with UK GDPR standards and stored within approved UK/EU cloud environments.
Where local privacy requirements apply, the company ensures equivalent or higher levels of protection are maintained.
US Privacy Considerations¶
Where personal data relating to US-based individuals is processed, FooEngine Ltd. applies privacy protections equivalent to those required under applicable US privacy regulations.
The company does not sell personal data, does not engage in behavioural profiling or targeted advertising, and processes only business-related contact information necessary for service delivery.
Responsibility¶
The CEO holds overall responsibility for data protection compliance.
Day-to-day administration may be delegated to nominated personnel.