Privacy Notice

Last updated: June 2026

We understand that your privacy is important, and we are committed to being transparent about how we handle your personal data. This privacy notice explains in clear terms how Privacy360 collects, uses, and protects your personal data when you interact with our website at privacy360.io or use our SaaS platform at app.privacy360.io.

1. Who we are

Privacy360 Limited ("Privacy360", "we", "us", "our") provides privacy compliance, AI governance and data protection software, together with related professional services.

Registered address
Grosvenor House, 11 St Pauls Square, Birmingham, B3 1RB, United Kingdom

General enquiries
sales@privacy360.io

Privacy enquiries / rights requests
dpo@privacy360.io

We have appointed Formiti Data International UK Ltd as our outsourced Data Protection Officer (DPO) and EU Representative under Article 27 GDPR. Formiti also acts as our local representative in jurisdictions where this is required by applicable law. As part of this role, Formiti may receive and handle personal data relating to enquiries, rights requests, complaints, incidents and regulatory correspondence strictly for the purpose of providing DPO, representative and privacy governance services to us.

Data Protection Officer (DPO)
Formiti Data International UK Ltd
Grosvenor House, 11 St Pauls Square, Birmingham, B3 1RB, United Kingdom
dpo@formiti.com

EU Representative
Formiti Data International
6 Fern Road, Sandyford, Dublin D18 FP98, Ireland
p360eurep@formiti.com

2. Scope of this notice

This privacy notice applies when you:

  • visit or use the privacy360.io website or any linked landing pages;
  • request a demo, download content, subscribe to communications, or contact us; or
  • access or use the Privacy360 SaaS platform at app.privacy360.io as an authorised user of a Privacy360 customer.

This notice does not cover how customers use personal data inside the Privacy360 platform in their role as controllers or data fiduciaries. Customers remain responsible for their own privacy notices to their employees, customers, vendors and other data subjects. Where Privacy360 acts as a processor on behalf of a customer, the processing is governed by the applicable customer contract and Data Processing Agreement.

3. The Privacy360 platform — what it does

The Privacy360 platform helps organisations operate their privacy and AI governance programme. Current modules include:

  • DPIA, LIA and FRIA assessments;
  • contract review and AI-assisted redlining;
  • consent management;
  • AI governance and AI system registry;
  • breach and incident management;
  • ROPA management; and
  • DSAR handling.

Personal data processed inside these modules by our customers is processed by Privacy360 as a processor under the customer's instructions, except where we separately act as a controller for limited operational data described in this notice.

4. What data we collect

Depending on how you interact with us, we may collect and process the following categories of personal data:

  • Identification and contact data — name, job title, organisation, business email, phone number, country, postal address and billing details.
  • Account and platform usage data — login credentials, user role, permissions, account status, preferences, support history and communication settings.
  • Device, network and security telemetry — IP address, browser type and version, device identifiers and characteristics, operating system, time zone, coarse geolocation derived from IP, session identifiers, authentication events and related security signals.
  • In-app audit logs — records of who accessed, created, changed or deleted data, with timestamps and related metadata.
  • AI interaction logs — prompts, inputs, outputs, model interaction metadata, safety events and related audit records generated through AI-assisted features.
  • Marketing and communications data — subscription status, preferences, event registrations, survey responses and engagement information.
  • Support and sales correspondence — emails, tickets, meeting notes, call summaries, attachments and related records.
  • Complaint and rights-handling records — identity verification information, correspondence, evidence submitted, internal case notes, decisions and response records.

We do not intentionally collect special category data through the website or standard product configuration. Customers are responsible for determining what personal data they choose to input into the platform in their role as controllers.

5. Website tracking and cookies

The privacy360.io marketing website is free from non-essential cookies and trackers. We do not use Google Analytics, Meta Pixel, LinkedIn Insight Tag, advertising cookies or third-party marketing trackers on the marketing website.

The only cookies set by the marketing website are strictly necessary for functionality:

Cookie nameTypePurposeDuration
sidebar:stateStrictly necessary / functionalRemembers whether the navigation sidebar is open or collapsed during your visit.7 days

You can configure your browser to block or delete cookies at any time, although doing so may affect the functionality described above.

6. Tracking inside the application

The Privacy360 application is a secured business tool. To protect customer data and meet our contractual, legal and security obligations, we process certain device and user information inside the application strictly for security, fraud prevention, audit, resilience and service integrity purposes.

This includes:

  • Device and network data — IP address, browser and device characteristics, operating system and coarse geolocation derived from IP.
  • Authentication events — logins, MFA challenges, session events, password resets and failed authentication attempts.
  • In-app audit logs — user actions, timestamps, records accessed and administrative changes.
  • AI interaction safety logs — prompts, outputs and safety metadata retained to detect abuse, support customer audit needs, investigate incidents and maintain model and platform integrity.

We do not use this information for advertising, behavioural profiling for marketing, or sale to third parties.

7. Purposes and legal bases

The table below summarises the main purposes for which we process personal data as controller, the categories of personal data involved, and the lawful bases relied upon under UK GDPR / EU GDPR. Equivalent local legal bases or compliance grounds may apply in other jurisdictions.

Purpose / activityType of dataLawful basis for processing including basis of legitimate interest
Providing the website and platform, including account creation, authentication, core functionality and service administrationIdentification and contact data; account and platform usage data; device, network and security telemetry; in-app audit logsPerformance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) in operating, maintaining and improving a secure business platform
Security, fraud prevention, incident response and auditDevice, network and security telemetry; authentication events; in-app audit logs; AI interaction logs; complaint and rights-handling records where relevantLegal obligation (Art. 6(1)(c)) where security, accountability or regulatory obligations apply; legitimate interests (Art. 6(1)(f)) in protecting our systems, customers, staff and data, preventing misuse, investigating incidents and maintaining defensible audit trails
Sales, onboarding and customer relationship managementIdentification and contact data; marketing and communications data; support and sales correspondenceTaking steps prior to entering into a contract and performance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) in managing business development, customer onboarding and account relationships
Customer support and service communicationsIdentification and contact data; account and platform usage data; support correspondence; device and security data where relevantPerformance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) in providing effective support, diagnosing issues and maintaining service continuity
Service improvement, product development and internal analyticsAccount and platform usage data; device and telemetry data; AI interaction logs; support correspondenceLegitimate interests (Art. 6(1)(f)) in improving platform usability, resilience, feature quality and customer experience, using proportionate and privacy-conscious analysis
Direct B2B marketingIdentification and contact data; marketing and communications dataConsent (Art. 6(1)(a)) where required; legitimate interests (Art. 6(1)(f)) in promoting relevant business services to corporate contacts in accordance with applicable e-privacy rules
Compliance, complaints, rights handling and legal risk managementIdentification and contact data; complaint and rights-handling records; support and sales correspondence; audit and security recordsLegal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) in handling complaints, demonstrating compliance, responding to regulators, establishing, exercising or defending legal claims, and maintaining appropriate business records
AI governance, model assurance, abuse prevention and accountabilityAI interaction logs; account and usage data; audit logs; security telemetryLegal obligation (Art. 6(1)(c)) where applicable under data protection, product security or AI governance laws; legitimate interests (Art. 6(1)(f)) in ensuring safe, reliable, auditable and human-governed AI-assisted functionality

Where we rely on legitimate interests, we consider and balance the potential impact on individuals and apply safeguards such as access controls, minimisation, regional storage controls, role-based permissions, retention limits, contractual controls and human oversight.

Where we rely on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

8. Data residency and where your data is hosted

Privacy360 offers regional data residency for the application. Customer data inside app.privacy360.io is provisioned and stored in the region selected by the customer at onboarding, subject to product availability and customer configuration.

Current regions include:

  • UK / EU;
  • USA;
  • India; and
  • APAC.

Customer business data such as assessments, ROPA records, DSAR records, incident records, contracts, consent records and AI registry entries is intended to remain in the selected region. Certain limited operational data, such as authentication metadata, billing data, support correspondence, abuse-prevention telemetry and central governance records, may be processed outside that region where necessary to operate, secure and support the service. Where this occurs, we apply the safeguards described in section 10.

9. How we share your data

We share personal data only where necessary and proportionate for the purposes set out in this notice.

We may share personal data with:

  • Service providers / sub-processors providing hosting, infrastructure, authentication, storage, support, email delivery, CRM, billing, security and AI services;
  • Formiti Data International UK Ltd and affiliated Formiti entities acting as our outsourced DPO, EU representative, local representative and privacy governance support provider;
  • Implementation, consulting or reseller partners where involved in delivering or supporting your services;
  • Professional advisers such as lawyers, auditors, insurers and consultants;
  • Authorities, regulators, law enforcement bodies or courts where disclosure is legally required or necessary to establish, exercise or defend legal claims; and
  • Actual or prospective investors, purchasers or corporate transaction counterparties subject to appropriate confidentiality and security controls.

Key providers currently include:

Recipient / providerRoleTypical processing location
SupabaseDatabase, authentication and storage backend for the applicationRegion selected by customer
CloudflareEdge network, DNS, WAF, DDoS protection and front-end/website deliveryGlobal network with regional controls where supported
StripePayments and billingUK / EU / USA
HubSpotCRM and B2B marketing communicationsUK / EU / USA
Google WorkspaceInternal email, collaboration and document handlingUK / EU / USA
PostmarkTransactional email delivery for service, account, security and workflow emailsUK / EU / USA or other service locations used by provider
AI model providers, such as OpenAI and AnthropicAI model inference supporting AI-assisted platform features, subject to contractual restrictions and training controlsRegionally routed where available; otherwise UK / EU / USA depending on service configuration
Formiti Data International UK Ltd / Formiti Data InternationalOutsourced DPO, EU representative, local representative and privacy governance supportUK / EU and other relevant jurisdictions

Where necessary for these services, we may share limited personal data such as contact details, account identifiers, correspondence, incident information, rights request data, complaint records, audit evidence and relevant case documentation. Recipients act under confidentiality obligations and appropriate contractual safeguards, including data processing agreements where required.

10. International transfers

Privacy360 operates internationally and uses service providers that may process personal data outside the UK, EEA, Switzerland, India or the customer's selected hosting region. When we transfer personal data internationally, we assess the transfer, apply an appropriate transfer mechanism, and implement supplementary technical, contractual and organisational safeguards where needed.

Depending on the circumstances, safeguards may include:

  • Adequacy regulations or decisions where the destination jurisdiction has been recognised as providing an adequate level of protection.
  • EU Standard Contractual Clauses (SCCs) for restricted transfers from the EEA.
  • UK International Data Transfer Addendum or IDTA for restricted transfers from the UK.
  • Transfer risk / impact assessments documenting the transfer context, local law assessment, recipient role, technical architecture and supplementary controls.
  • Technical supplementary measures such as encryption in transit and at rest, pseudonymisation where appropriate, tokenisation, regional segregation, environment separation, key-management controls and strict access logging.
  • Contractual and governance controls such as confidentiality obligations, onward-transfer restrictions, security commitments, incident notification clauses, audit rights and deletion/return obligations.
  • Jurisdiction-specific controls required under laws such as the India DPDP Act or APAC transfer rules, where applicable.

Where regional routing is available for AI or infrastructure services, we seek to use the most privacy-protective option that is operationally appropriate. However, some support, abuse monitoring, governance, billing or resilience functions may still involve limited cross-border access or processing.

Individuals may contact us using the details in section 17 for more information about the safeguards we rely on for international transfers. Copies or summaries of relevant transfer mechanisms may be provided subject to legal, security and commercial confidentiality limitations.

11. Data retention

We retain personal data only for as long as necessary for the purposes described in this notice, including to provide services, maintain security, comply with legal and regulatory obligations, resolve disputes, handle complaints and enforce our agreements. Retention periods may vary depending on the customer contract, applicable law, litigation holds, regulatory expectations, active investigations or documented business need.

Indicative retention periods are as follows:

Data categoryTypical retention periodNotes
Website enquiries, demo requests and sales correspondenceUp to 3 years from last meaningful contactMay be retained longer where needed for contract history, suppression records or legal claims
Customer account records, commercial records and billing dataContract term plus up to 6 yearsReflects tax, accounting, audit and legal limitation considerations
Platform audit logs and security telemetryUp to 24 months by defaultMay be retained longer where required for customer-specific settings, security investigations, litigation holds or regulatory obligations
Authentication logs and fraud-prevention recordsUp to 24 months by defaultUsed for account security, incident response and abuse investigations
AI interaction logs and AI safety recordsUp to 12 months by defaultMay be shorter or longer depending on configuration, customer agreement, incident handling or documented governance need
Support tickets and support correspondenceUp to 6 years from closureMay be retained longer where linked to incidents, disputes or regulatory matters
Rights request and complaint recordsUp to 6 years after closureMaintained to evidence compliance, complaint handling and regulatory accountability
Backup dataRolling backup cycles and secure overwrite / deletion schedulesResidual copies may persist temporarily in encrypted backups before deletion in line with backup lifecycle controls

At the end of the relevant retention period, data is deleted, anonymised or securely put beyond use unless continued retention is required by law or justified by an active dispute, investigation, legal hold or equivalent documented need.

12. Your data protection rights

Subject to applicable law, you may have the right to:

  • access personal data we hold about you;
  • rectify inaccurate or incomplete personal data;
  • erase personal data in certain circumstances;
  • restrict processing in certain circumstances;
  • object to processing based on legitimate interests, including direct marketing;
  • receive portability of personal data you provided to us where this right applies;
  • withdraw consent where processing is based on consent;
  • request human review or contest outcomes where you believe automated processing affects you in a legally relevant way, where applicable; and
  • exercise local statutory rights, such as nomination or grievance rights under applicable non-UK laws where relevant.

To exercise your rights, please click here or email dpo@privacy360.io.

If we process your personal data on behalf of a customer as processor, you should normally direct your request to the relevant customer as controller or data fiduciary. Where appropriate, we will assist the customer in responding in line with our contractual and legal obligations.

Data protection complaints

If you are dissatisfied with how we have handled your personal data or your information rights, you may submit a complaint directly to us by clicking here.

We will facilitate complaints in accessible ways, including electronically, acknowledge receipt within the applicable statutory timeframe, and respond without undue delay. We may need to verify your identity or authority where a complaint or request is submitted by a representative.

13. Automated decision-making and AI

Privacy360 includes AI-assisted functionality such as contract redlining, drafting support, summarisation, recommendations, risk support and governance tooling. In the standard product configuration, these features are designed as decision-support tools and are subject to human review.

We do not use solely automated decision-making with legal or similarly significant effects within the meaning of Article 22 GDPR in the standard product configuration. Customers remain responsible for assessing any workflow automations, scoring logic or downstream business decisions they configure using the platform.

14. AI governance and safeguards

We are committed to deploying AI-assisted functionality responsibly and in a manner aligned with applicable privacy, security and emerging AI governance requirements, including relevant transparency, accountability, record-keeping, risk-management and human-oversight expectations.

Our AI governance and safeguards include:

  • Human oversight by design — AI outputs are intended to support, not replace, human judgment in standard workflows.
  • Transparency — users are informed when they are interacting with or relying on AI-assisted functionality within relevant product flows.
  • Logging and traceability — prompts, outputs and relevant safety or workflow metadata may be logged to support security, auditability, quality review, misuse investigations and customer assurance.
  • Access controls and segregation — AI-related logs and tools are subject to role-based access restrictions and environment controls.
  • Data minimisation — we aim to send only the personal data and contextual content necessary for the relevant AI task.
  • Provider controls — where supported by contract and configuration, AI providers are configured not to use customer content to train their general models.
  • Safety and abuse controls — measures may include prompt injection detection, data leakage controls, rate limiting, content filtering, anomaly monitoring and review procedures.
  • Model and workflow governance — we assess use cases, maintain documentation, and review higher-risk use cases or features through internal governance processes.
  • Testing and assurance — AI-assisted features are subject to quality, security and risk review appropriate to the nature of the feature.
  • Customer responsibility controls — customers remain responsible for setting appropriate internal governance, user permissions, review thresholds and legal assessments for their own deployment and downstream use of outputs.

Where a particular feature may fall within a higher-risk regulatory classification in a customer's environment, the customer remains responsible for its own deployment obligations, impact assessments, workforce consultation, records and legal basis analysis.

15. Children's data

The website and services are intended for business users and are not directed at children. We do not knowingly collect children's personal data through the website or in standard B2B use of the platform. If you believe children's data has been provided to us inadvertently, please contact us so that appropriate action can be taken.

16. Security

We implement technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

These measures include, where appropriate:

  • role-based access controls and least-privilege permissions;
  • encryption in transit and at rest;
  • multi-factor authentication and access monitoring;
  • environment separation and regional data isolation controls;
  • secure software development and change management practices;
  • vulnerability management, patching and security testing;
  • comprehensive logging, alerting and incident response processes;
  • backup, resilience and recovery measures;
  • supplier due diligence and contractual security controls;
  • staff confidentiality, training and security awareness measures; and
  • AI-specific safety, access and monitoring controls.

No system can be guaranteed to be completely secure, but we continuously review and improve our security posture in light of risk, technology and legal requirements.

17. How to contact us and complain to a regulator

For privacy enquiries, rights requests or DPO contact:

Email
dpo@privacy360.io

Post
Privacy360 Limited (FAO: Data Protection Officer)
Grosvenor House, 11 St Pauls Square, Birmingham, B3 1RB, United Kingdom

You also have the right to lodge a complaint with your local data protection or privacy regulator where applicable, including:

  • United Kingdom — Information Commissioner's Office (ICO), ico.org.uk
  • EEA — your national data protection authority, see edpb.europa.eu
  • Switzerland — FDPIC, edoeb.admin.ch
  • Singapore — PDPC, pdpc.gov.sg
  • Australia — OAIC, oaic.gov.au
  • Thailand — PDPC Thailand, pdpc.or.th
  • India — the Data Protection Board of India when operational; until then, grievances may be raised with our DPO.

18. Changes to this notice

We may update this privacy notice from time to time to reflect changes in law, technology, our services or our processing practices. The updated version will be indicated by the revised "Last updated" date and will take effect once published, unless a later date is stated.

Where required or appropriate, we will notify users of material changes through the website, by email or through in-product notifications.

Privacy-first website: We do not use tracking cookies, advertising pixels, or third-party analytics on this site. Read our Privacy Notice.