Privacy Notice
Last updated: June 2026
We understand that your privacy is important, and we are committed to being transparent about how we handle your personal data. This privacy notice explains in clear terms how Privacy360 collects, uses, and protects your personal data when you interact with our website at privacy360.io or use our SaaS platform at app.privacy360.io.
1. Who we are
Privacy360 Limited ("Privacy360", "we", "us", "our") provides privacy compliance, AI governance and data protection software, together with related professional services.
Registered address
Grosvenor House, 11 St Pauls Square, Birmingham, B3 1RB, United Kingdom
General enquiries
sales@privacy360.io
Privacy enquiries / rights requests
dpo@privacy360.io
We have appointed Formiti Data International UK Ltd as our outsourced Data Protection Officer (DPO) and EU Representative under Article 27 GDPR. Formiti also acts as our local representative in jurisdictions where this is required by applicable law. As part of this role, Formiti may receive and handle personal data relating to enquiries, rights requests, complaints, incidents and regulatory correspondence strictly for the purpose of providing DPO, representative and privacy governance services to us.
Data Protection Officer (DPO)
Formiti Data International UK Ltd
Grosvenor House, 11 St Pauls Square, Birmingham, B3 1RB, United Kingdom
dpo@formiti.com
EU Representative
Formiti Data International
6 Fern Road, Sandyford, Dublin D18 FP98, Ireland
p360eurep@formiti.com
2. Scope of this notice
This privacy notice applies when you:
- visit or use the privacy360.io website or any linked landing pages;
- request a demo, download content, subscribe to communications, or contact us; or
- access or use the Privacy360 SaaS platform at app.privacy360.io as an authorised user of a Privacy360 customer.
This notice does not cover how customers use personal data inside the Privacy360 platform in their role as controllers or data fiduciaries. Customers remain responsible for their own privacy notices to their employees, customers, vendors and other data subjects. Where Privacy360 acts as a processor on behalf of a customer, the processing is governed by the applicable customer contract and Data Processing Agreement.
3. The Privacy360 platform — what it does
The Privacy360 platform helps organisations operate their privacy and AI governance programme. Current modules include:
- DPIA, LIA and FRIA assessments;
- contract review and AI-assisted redlining;
- consent management;
- AI governance and AI system registry;
- breach and incident management;
- ROPA management; and
- DSAR handling.
Personal data processed inside these modules by our customers is processed by Privacy360 as a processor under the customer's instructions, except where we separately act as a controller for limited operational data described in this notice.
4. What data we collect
Depending on how you interact with us, we may collect and process the following categories of personal data:
- Identification and contact data — name, job title, organisation, business email, phone number, country, postal address and billing details.
- Account and platform usage data — login credentials, user role, permissions, account status, preferences, support history and communication settings.
- Device, network and security telemetry — IP address, browser type and version, device identifiers and characteristics, operating system, time zone, coarse geolocation derived from IP, session identifiers, authentication events and related security signals.
- In-app audit logs — records of who accessed, created, changed or deleted data, with timestamps and related metadata.
- AI interaction logs — prompts, inputs, outputs, model interaction metadata, safety events and related audit records generated through AI-assisted features.
- Marketing and communications data — subscription status, preferences, event registrations, survey responses and engagement information.
- Support and sales correspondence — emails, tickets, meeting notes, call summaries, attachments and related records.
- Complaint and rights-handling records — identity verification information, correspondence, evidence submitted, internal case notes, decisions and response records.
We do not intentionally collect special category data through the website or standard product configuration. Customers are responsible for determining what personal data they choose to input into the platform in their role as controllers.
5. Website tracking and cookies
The privacy360.io marketing website is free from non-essential cookies and trackers. We do not use Google Analytics, Meta Pixel, LinkedIn Insight Tag, advertising cookies or third-party marketing trackers on the marketing website.
The only cookies set by the marketing website are strictly necessary for functionality:
| Cookie name | Type | Purpose | Duration |
|---|---|---|---|
| sidebar:state | Strictly necessary / functional | Remembers whether the navigation sidebar is open or collapsed during your visit. | 7 days |
You can configure your browser to block or delete cookies at any time, although doing so may affect the functionality described above.
6. Tracking inside the application
The Privacy360 application is a secured business tool. To protect customer data and meet our contractual, legal and security obligations, we process certain device and user information inside the application strictly for security, fraud prevention, audit, resilience and service integrity purposes.
This includes:
- Device and network data — IP address, browser and device characteristics, operating system and coarse geolocation derived from IP.
- Authentication events — logins, MFA challenges, session events, password resets and failed authentication attempts.
- In-app audit logs — user actions, timestamps, records accessed and administrative changes.
- AI interaction safety logs — prompts, outputs and safety metadata retained to detect abuse, support customer audit needs, investigate incidents and maintain model and platform integrity.
We do not use this information for advertising, behavioural profiling for marketing, or sale to third parties.
7. Purposes and legal bases
The table below summarises the main purposes for which we process personal data as controller, the categories of personal data involved, and the lawful bases relied upon under UK GDPR / EU GDPR. Equivalent local legal bases or compliance grounds may apply in other jurisdictions.
| Purpose / activity | Type of data | Lawful basis for processing including basis of legitimate interest |
|---|---|---|
| Providing the website and platform, including account creation, authentication, core functionality and service administration | Identification and contact data; account and platform usage data; device, network and security telemetry; in-app audit logs | Performance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) in operating, maintaining and improving a secure business platform |
| Security, fraud prevention, incident response and audit | Device, network and security telemetry; authentication events; in-app audit logs; AI interaction logs; complaint and rights-handling records where relevant | Legal obligation (Art. 6(1)(c)) where security, accountability or regulatory obligations apply; legitimate interests (Art. 6(1)(f)) in protecting our systems, customers, staff and data, preventing misuse, investigating incidents and maintaining defensible audit trails |
| Sales, onboarding and customer relationship management | Identification and contact data; marketing and communications data; support and sales correspondence | Taking steps prior to entering into a contract and performance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) in managing business development, customer onboarding and account relationships |
| Customer support and service communications | Identification and contact data; account and platform usage data; support correspondence; device and security data where relevant | Performance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) in providing effective support, diagnosing issues and maintaining service continuity |
| Service improvement, product development and internal analytics | Account and platform usage data; device and telemetry data; AI interaction logs; support correspondence | Legitimate interests (Art. 6(1)(f)) in improving platform usability, resilience, feature quality and customer experience, using proportionate and privacy-conscious analysis |
| Direct B2B marketing | Identification and contact data; marketing and communications data | Consent (Art. 6(1)(a)) where required; legitimate interests (Art. 6(1)(f)) in promoting relevant business services to corporate contacts in accordance with applicable e-privacy rules |
| Compliance, complaints, rights handling and legal risk management | Identification and contact data; complaint and rights-handling records; support and sales correspondence; audit and security records | Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) in handling complaints, demonstrating compliance, responding to regulators, establishing, exercising or defending legal claims, and maintaining appropriate business records |
| AI governance, model assurance, abuse prevention and accountability | AI interaction logs; account and usage data; audit logs; security telemetry | Legal obligation (Art. 6(1)(c)) where applicable under data protection, product security or AI governance laws; legitimate interests (Art. 6(1)(f)) in ensuring safe, reliable, auditable and human-governed AI-assisted functionality |
Where we rely on legitimate interests, we consider and balance the potential impact on individuals and apply safeguards such as access controls, minimisation, regional storage controls, role-based permissions, retention limits, contractual controls and human oversight.
Where we rely on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
8. Data residency and where your data is hosted
Privacy360 offers regional data residency for the application. Customer data inside app.privacy360.io is provisioned and stored in the region selected by the customer at onboarding, subject to product availability and customer configuration.
Current regions include:
- UK / EU;
- USA;
- India; and
- APAC.
Customer business data such as assessments, ROPA records, DSAR records, incident records, contracts, consent records and AI registry entries is intended to remain in the selected region. Certain limited operational data, such as authentication metadata, billing data, support correspondence, abuse-prevention telemetry and central governance records, may be processed outside that region where necessary to operate, secure and support the service. Where this occurs, we apply the safeguards described in section 10.
9. How we share your data
We share personal data only where necessary and proportionate for the purposes set out in this notice.
We may share personal data with:
- Service providers / sub-processors providing hosting, infrastructure, authentication, storage, support, email delivery, CRM, billing, security and AI services;
- Formiti Data International UK Ltd and affiliated Formiti entities acting as our outsourced DPO, EU representative, local representative and privacy governance support provider;
- Implementation, consulting or reseller partners where involved in delivering or supporting your services;
- Professional advisers such as lawyers, auditors, insurers and consultants;
- Authorities, regulators, law enforcement bodies or courts where disclosure is legally required or necessary to establish, exercise or defend legal claims; and
- Actual or prospective investors, purchasers or corporate transaction counterparties subject to appropriate confidentiality and security controls.
Key providers currently include:
| Recipient / provider | Role | Typical processing location |
|---|---|---|
| Supabase | Database, authentication and storage backend for the application | Region selected by customer |
| Cloudflare | Edge network, DNS, WAF, DDoS protection and front-end/website delivery | Global network with regional controls where supported |
| Stripe | Payments and billing | UK / EU / USA |
| HubSpot | CRM and B2B marketing communications | UK / EU / USA |
| Google Workspace | Internal email, collaboration and document handling | UK / EU / USA |
| Postmark | Transactional email delivery for service, account, security and workflow emails | UK / EU / USA or other service locations used by provider |
| AI model providers, such as OpenAI and Anthropic | AI model inference supporting AI-assisted platform features, subject to contractual restrictions and training controls | Regionally routed where available; otherwise UK / EU / USA depending on service configuration |
| Formiti Data International UK Ltd / Formiti Data International | Outsourced DPO, EU representative, local representative and privacy governance support | UK / EU and other relevant jurisdictions |
Where necessary for these services, we may share limited personal data such as contact details, account identifiers, correspondence, incident information, rights request data, complaint records, audit evidence and relevant case documentation. Recipients act under confidentiality obligations and appropriate contractual safeguards, including data processing agreements where required.
10. International transfers
Privacy360 operates internationally and uses service providers that may process personal data outside the UK, EEA, Switzerland, India or the customer's selected hosting region. When we transfer personal data internationally, we assess the transfer, apply an appropriate transfer mechanism, and implement supplementary technical, contractual and organisational safeguards where needed.
Depending on the circumstances, safeguards may include:
- Adequacy regulations or decisions where the destination jurisdiction has been recognised as providing an adequate level of protection.
- EU Standard Contractual Clauses (SCCs) for restricted transfers from the EEA.
- UK International Data Transfer Addendum or IDTA for restricted transfers from the UK.
- Transfer risk / impact assessments documenting the transfer context, local law assessment, recipient role, technical architecture and supplementary controls.
- Technical supplementary measures such as encryption in transit and at rest, pseudonymisation where appropriate, tokenisation, regional segregation, environment separation, key-management controls and strict access logging.
- Contractual and governance controls such as confidentiality obligations, onward-transfer restrictions, security commitments, incident notification clauses, audit rights and deletion/return obligations.
- Jurisdiction-specific controls required under laws such as the India DPDP Act or APAC transfer rules, where applicable.
Where regional routing is available for AI or infrastructure services, we seek to use the most privacy-protective option that is operationally appropriate. However, some support, abuse monitoring, governance, billing or resilience functions may still involve limited cross-border access or processing.
Individuals may contact us using the details in section 17 for more information about the safeguards we rely on for international transfers. Copies or summaries of relevant transfer mechanisms may be provided subject to legal, security and commercial confidentiality limitations.
11. Data retention
We retain personal data only for as long as necessary for the purposes described in this notice, including to provide services, maintain security, comply with legal and regulatory obligations, resolve disputes, handle complaints and enforce our agreements. Retention periods may vary depending on the customer contract, applicable law, litigation holds, regulatory expectations, active investigations or documented business need.
Indicative retention periods are as follows:
| Data category | Typical retention period | Notes |
|---|---|---|
| Website enquiries, demo requests and sales correspondence | Up to 3 years from last meaningful contact | May be retained longer where needed for contract history, suppression records or legal claims |
| Customer account records, commercial records and billing data | Contract term plus up to 6 years | Reflects tax, accounting, audit and legal limitation considerations |
| Platform audit logs and security telemetry | Up to 24 months by default | May be retained longer where required for customer-specific settings, security investigations, litigation holds or regulatory obligations |
| Authentication logs and fraud-prevention records | Up to 24 months by default | Used for account security, incident response and abuse investigations |
| AI interaction logs and AI safety records | Up to 12 months by default | May be shorter or longer depending on configuration, customer agreement, incident handling or documented governance need |
| Support tickets and support correspondence | Up to 6 years from closure | May be retained longer where linked to incidents, disputes or regulatory matters |
| Rights request and complaint records | Up to 6 years after closure | Maintained to evidence compliance, complaint handling and regulatory accountability |
| Backup data | Rolling backup cycles and secure overwrite / deletion schedules | Residual copies may persist temporarily in encrypted backups before deletion in line with backup lifecycle controls |
At the end of the relevant retention period, data is deleted, anonymised or securely put beyond use unless continued retention is required by law or justified by an active dispute, investigation, legal hold or equivalent documented need.
12. Your data protection rights
Subject to applicable law, you may have the right to:
- access personal data we hold about you;
- rectify inaccurate or incomplete personal data;
- erase personal data in certain circumstances;
- restrict processing in certain circumstances;
- object to processing based on legitimate interests, including direct marketing;
- receive portability of personal data you provided to us where this right applies;
- withdraw consent where processing is based on consent;
- request human review or contest outcomes where you believe automated processing affects you in a legally relevant way, where applicable; and
- exercise local statutory rights, such as nomination or grievance rights under applicable non-UK laws where relevant.
To exercise your rights, please click here or email dpo@privacy360.io.
If we process your personal data on behalf of a customer as processor, you should normally direct your request to the relevant customer as controller or data fiduciary. Where appropriate, we will assist the customer in responding in line with our contractual and legal obligations.
Data protection complaints
If you are dissatisfied with how we have handled your personal data or your information rights, you may submit a complaint directly to us by clicking here.
We will facilitate complaints in accessible ways, including electronically, acknowledge receipt within the applicable statutory timeframe, and respond without undue delay. We may need to verify your identity or authority where a complaint or request is submitted by a representative.
13. Automated decision-making and AI
Privacy360 includes AI-assisted functionality such as contract redlining, drafting support, summarisation, recommendations, risk support and governance tooling. In the standard product configuration, these features are designed as decision-support tools and are subject to human review.
We do not use solely automated decision-making with legal or similarly significant effects within the meaning of Article 22 GDPR in the standard product configuration. Customers remain responsible for assessing any workflow automations, scoring logic or downstream business decisions they configure using the platform.
14. AI governance and safeguards
We are committed to deploying AI-assisted functionality responsibly and in a manner aligned with applicable privacy, security and emerging AI governance requirements, including relevant transparency, accountability, record-keeping, risk-management and human-oversight expectations.
Our AI governance and safeguards include:
- Human oversight by design — AI outputs are intended to support, not replace, human judgment in standard workflows.
- Transparency — users are informed when they are interacting with or relying on AI-assisted functionality within relevant product flows.
- Logging and traceability — prompts, outputs and relevant safety or workflow metadata may be logged to support security, auditability, quality review, misuse investigations and customer assurance.
- Access controls and segregation — AI-related logs and tools are subject to role-based access restrictions and environment controls.
- Data minimisation — we aim to send only the personal data and contextual content necessary for the relevant AI task.
- Provider controls — where supported by contract and configuration, AI providers are configured not to use customer content to train their general models.
- Safety and abuse controls — measures may include prompt injection detection, data leakage controls, rate limiting, content filtering, anomaly monitoring and review procedures.
- Model and workflow governance — we assess use cases, maintain documentation, and review higher-risk use cases or features through internal governance processes.
- Testing and assurance — AI-assisted features are subject to quality, security and risk review appropriate to the nature of the feature.
- Customer responsibility controls — customers remain responsible for setting appropriate internal governance, user permissions, review thresholds and legal assessments for their own deployment and downstream use of outputs.
Where a particular feature may fall within a higher-risk regulatory classification in a customer's environment, the customer remains responsible for its own deployment obligations, impact assessments, workforce consultation, records and legal basis analysis.
15. Children's data
The website and services are intended for business users and are not directed at children. We do not knowingly collect children's personal data through the website or in standard B2B use of the platform. If you believe children's data has been provided to us inadvertently, please contact us so that appropriate action can be taken.
16. Security
We implement technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
These measures include, where appropriate:
- role-based access controls and least-privilege permissions;
- encryption in transit and at rest;
- multi-factor authentication and access monitoring;
- environment separation and regional data isolation controls;
- secure software development and change management practices;
- vulnerability management, patching and security testing;
- comprehensive logging, alerting and incident response processes;
- backup, resilience and recovery measures;
- supplier due diligence and contractual security controls;
- staff confidentiality, training and security awareness measures; and
- AI-specific safety, access and monitoring controls.
No system can be guaranteed to be completely secure, but we continuously review and improve our security posture in light of risk, technology and legal requirements.
17. How to contact us and complain to a regulator
For privacy enquiries, rights requests or DPO contact:
Email
dpo@privacy360.io
Post
Privacy360 Limited (FAO: Data Protection Officer)
Grosvenor House, 11 St Pauls Square, Birmingham, B3 1RB, United Kingdom
You also have the right to lodge a complaint with your local data protection or privacy regulator where applicable, including:
- United Kingdom — Information Commissioner's Office (ICO), ico.org.uk
- EEA — your national data protection authority, see edpb.europa.eu
- Switzerland — FDPIC, edoeb.admin.ch
- Singapore — PDPC, pdpc.gov.sg
- Australia — OAIC, oaic.gov.au
- Thailand — PDPC Thailand, pdpc.or.th
- India — the Data Protection Board of India when operational; until then, grievances may be raised with our DPO.
18. Changes to this notice
We may update this privacy notice from time to time to reflect changes in law, technology, our services or our processing practices. The updated version will be indicated by the revised "Last updated" date and will take effect once published, unless a later date is stated.
Where required or appropriate, we will notify users of material changes through the website, by email or through in-product notifications.