Skip to content

Legal

Privacy Policy

Last updated: 15 June 2026

1.Who We Are

Privacy Pathways Compliance Ltd (“Privacy Pathways”, “we”, “us”, “our”) operates the Privacy Pathways platform, a GDPR compliance management tool for organisations. We are the data controller for the personal information described in this policy.

Privacy Pathways Compliance Ltd is a company registered in Scotland (company no. SC850167) with its registered office at 5 Cairnfield Place, Bucksburn, Aberdeen, AB21 9LT. We are registered with the Information Commissioner’s Office (ICO) in the United Kingdom; our ICO registration number is available on request.

2.What Information We Collect

We collect information about you when you register for an account, use our platform, or contact us.

  • Account data: name, email address, and password (stored as a salted hash).
  • Organisational data: company name, country of registration, employee count, business description, and ICO registration status provided during onboarding.
  • Compliance records: ROPA entries, DPIA records, and other data you enter into the platform.
  • Usage data: log data, IP address, browser type, pages visited, and timestamps, collected automatically when you use our service.
  • Communications: the content of emails or support messages you send us.

We do not intentionally collect special category data (as defined under Article 9 UK GDPR) about our users. If you include such data in your compliance records, you remain the data controller for that content and we act as your processor.

3.Legal Basis for Processing

PurposeLegal basisDetail
Providing the serviceContractProcessing necessary to perform our agreement with you
Account securityLegitimate interestsPreventing fraud, abuse, and unauthorised access
Service improvementLegitimate interestsAnalysing usage patterns to improve features and reliability
Marketing communicationsConsentOnly where you have opted in; you may withdraw at any time
Legal complianceLegal obligationRetaining records as required by applicable law

4.How We Use Your Information

  • To create and manage your account and authenticate you.
  • To deliver the Privacy Pathways platform and its features.
  • To send transactional messages such as password resets and account notifications.
  • To respond to support requests and enquiries you send us.
  • To monitor for security incidents and prevent misuse of our platform.
  • To meet our legal and regulatory obligations as a data controller.
  • With your consent, to send product updates and relevant privacy compliance news.

We do not sell, rent, or trade your personal data to third parties for marketing purposes.

5.Who We Share Your Information With

We share personal data only as necessary and with appropriate safeguards in place:

  • Infrastructure providers: cloud hosting and database services that process data on our behalf under data processing agreements.
  • Analytics and monitoring: product analytics, error tracking and performance monitoring (PostHog, hosted in the EU), configured in cookieless mode to minimise personal data exposure.
  • Professional advisers: lawyers, auditors, and insurers where necessary and subject to confidentiality obligations.
  • Law enforcement: where we are required to do so by law or to protect the rights and safety of others.
  • Business transfers: in connection with a merger, acquisition, or sale of assets, where we will notify you in advance.

6.International Transfers

Our primary infrastructure is located within the EEA and United Kingdom. Where we use sub-processors in third countries, we ensure appropriate safeguards are in place, such as the UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses (SCCs). You may request a copy of the relevant safeguards by contacting us.

7.How Long We Keep Your Data

  • Account data: retained for the lifetime of your account and deleted within 30 days of account closure, unless retention is required by law.
  • Compliance records: retained as long as your account is active. Upon deletion we provide a 30-day grace period during which records can be exported.
  • Usage logs: retained for up to 12 months for security and operational purposes.
  • Financial records: retained for 7 years as required by UK tax law.

8.Your Rights

Under the UK GDPR and (where applicable) the EU GDPR, you have the following rights regarding your personal data:

  • Access (Art. 15): to receive a copy of the personal data we hold about you.
  • Rectification (Art. 16): to have inaccurate data corrected without undue delay.
  • Erasure (Art. 17): to request deletion of your personal data where there is no compelling reason for continued processing.
  • Restriction (Art. 18): to restrict processing while a dispute is resolved.
  • Portability (Art. 20): to receive your data in a structured, machine-readable format.
  • Object (Art. 21): to object to processing based on legitimate interests, including profiling.
  • Withdraw consent: where processing is based on consent, to withdraw it at any time without affecting prior processing.

To exercise any of these rights, please email dpo@privacypathways.co.uk. We will respond within one calendar month. We may ask you to verify your identity before processing your request.

9.Cookies

We use essential cookies to operate the platform (session management and authentication). We do not use tracking or advertising cookies without your consent.

  • Session cookies: necessary for you to remain logged in; expire when you close your browser.
  • Preference cookies: store your theme and display settings; persist for 12 months.

Our product analytics runs in cookieless mode: it stores no cookies or identifiers on your device, which is why you will not see a cookie consent banner on this site.

You can manage or disable cookies through your browser settings, though this may affect the functionality of the platform.

10.Security

We implement appropriate technical and organisational measures to protect your personal data, including encryption in transit (TLS), encryption at rest, access controls, and regular security reviews. However, no method of transmission over the internet is 100% secure and we cannot guarantee absolute security.

In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay as required by Article 34 UK GDPR.

11.Changes to This Policy

We may update this policy from time to time. When we make material changes, we will notify you by email or by a prominent notice on the platform at least 14 days before the changes take effect. Continued use of the platform after the effective date constitutes acceptance of the revised policy.

The “Last updated” date at the top of this page reflects when the policy was most recently revised.

12.Contact Us

If you have any questions about this privacy policy or how we handle your data, please contact our Data Protection Officer:

Data Protection Officer

Privacy Pathways Compliance Ltd

Email: dpo@privacypathways.co.uk

General enquiries: privacy@privacypathways.co.uk

You also have the right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner’s Office (ICO):

Information Commissioner’s Office

Website: ico.org.uk/make-a-complaint

Helpline: 0303 123 1113