Skip to content

Data Protection & Privacy Policy

Distribution Employees and Contractors; Clients upon request
Version 1.0
Approved 2024-03-02
Approved by Leadership

Purpose

This policy defines how FooEngine Ltd. complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 in the handling of personal data.

Scope

This policy applies to all employees, contractors, systems, and third-party service providers processing personal data on behalf of the company.

Data Controller and Processing Roles

FooEngine Ltd. acts as the Data Controller for personal data processed in the course of business operations.

The company is registered with the UK Information Commissioner's Office (ICO) under registration reference ZB177982.

Depending on the service provided and the nature of information received, FooEngine Ltd. may also act as a Data Processor on behalf of its clients, processing personal data only in accordance with client instructions and applicable contractual requirements.

Personal Data Processed

The company processes limited personal data necessary for business operations, including:

  • Client and partner contact details
  • User account information
  • Supplier and contractor contact details
  • Internal HR administration records

FooEngine Ltd. does not process consumer marketing data, behavioural profiling data, or sell personal data.

Lawful Basis for Processing

Personal data is processed under one or more of the following lawful bases:

  • Contractual necessity
  • Legitimate business interest
  • Legal or regulatory obligation

Data Storage and Retention

Personal data is stored securely within company-approved systems and cloud environments. Data is retained only for as long as necessary for business or legal purposes in accordance with the company's data retention schedule.

Data Sharing

Personal data is shared only with approved third-party service providers where required for service delivery.

All such providers operate under contractual confidentiality and information-security obligations.

Data Subject Rights

Individuals may request access, correction, restriction, or deletion of their personal data in accordance with UK GDPR requirements.

Security of Personal Data

Personal data is protected through technical and organisational security measures defined in the company Information Security Policy.

Data Breach Management

Any personal data breach will be managed under the company Incident Response process.

Where required, breaches will be reported to the ICO within 72 hours.

International Operations

FooEngine Ltd. provides services to clients in multiple regions including Europe (including the Nordics), Canada, Latin America, Australia and the United States.

Personal data processed in support of these services is handled in accordance with UK GDPR standards and stored within approved UK/EU cloud environments.

Where local privacy requirements apply, the company ensures equivalent or higher levels of protection are maintained.

US Privacy Considerations

Where personal data relating to US-based individuals is processed, FooEngine Ltd. applies privacy protections equivalent to those required under applicable US privacy regulations.

The company does not sell personal data, does not engage in behavioural profiling or targeted advertising, and processes only business-related contact information necessary for service delivery.

Responsibility

The CEO holds overall responsibility for data protection compliance.

Day-to-day administration may be delegated to nominated personnel.