Privacy Policy
Last updated: January 1, 2024
Important: This Privacy Policy explains how Trick Earth Ltd collects, uses, and protects your personal information in accordance with UK GDPR and the Data Protection Act 2018.
Table of Contents
1. Who We Are
Trick Earth Ltd is a UK-based software and SaaS solutions provider. We are the data controller for the personal information we collect and process.
Company Name: Trick Earth Ltd
Company Number: 12345678
Registered Address: 25 Cavendish Square, London W1G 0PN, United Kingdom
ICO Registration: ZA123456
Data Protection Officer: [email protected]
2. Information We Collect
We collect different types of personal information depending on how you interact with our services:
Information You Provide Directly
- Contact Information: Name, email address, phone number, company name, job title
- Enquiry Information: Project details, budget range, service interests, messages
- Newsletter Subscription: Email address, subscription preferences
- Communication Records: Records of our interactions, including emails, calls, and meetings
Information We Collect Automatically
- Website Usage: Pages visited, time spent, click patterns, referral sources
- Technical Information: IP address, browser type, device information, operating system
- Cookies and Tracking: As detailed in our Cookie Policy
- Performance Data: Website performance metrics and error logs
3. How We Use Your Information
We use your personal information for the following purposes:
Service Delivery and Communication
- Responding to your enquiries and providing quotes
- Delivering our software and consulting services
- Managing project communications and documentation
- Providing customer support and technical assistance
Marketing and Business Development
- Sending newsletter content and industry insights (with consent)
- Sharing relevant service updates and case studies
- Inviting you to relevant events and webinars
- Conducting market research and gathering feedback
Legal and Administrative
- Fulfilling legal obligations and regulatory requirements
- Maintaining business records and documentation
- Protecting against fraud and security threats
- Resolving disputes and enforcing agreements
4. Legal Basis for Processing
Under UK GDPR, we process your personal data based on the following legal grounds:
Contract
Processing necessary for the performance of a contract or to take steps at your request before entering into a contract.
Consent
Where you have given clear consent for specific processing activities, such as marketing communications.
Legitimate Interests
Processing necessary for our legitimate business interests, such as improving our services and business operations.
Legal Obligation
Processing necessary to comply with legal obligations, such as tax and accounting requirements.
6. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes outlined in this policy:
- Enquiry Data: 3 years from last contact
- Client Data: 7 years after contract completion (legal requirement)
- Newsletter Subscriptions: Until you unsubscribe
- Website Analytics: 26 months
- Marketing Data: 3 years from last interaction
7. Your Rights
Under UK GDPR, you have the following rights regarding your personal data:
Access
Request copies of your personal data
Rectification
Correct inaccurate or incomplete data
Erasure
Request deletion of your personal data
Restriction
Limit how we process your data
Portability
Receive your data in a portable format
Objection
Object to processing for specific purposes
To exercise your rights: Contact us at [email protected]. We will respond within one month and may ask for proof of identity to protect your privacy.
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data:
Technical Measures
- Encryption of data in transit and at rest
- Regular security assessments and penetration testing
- Secure cloud infrastructure with ISO 27001 certified providers
- Multi-factor authentication for system access
Organizational Measures
- Regular staff training on data protection
- Data protection impact assessments for new processes
- Incident response procedures and breach notification protocols
- Access controls and the principle of least privilege
10. International Transfers
Some of our service providers are located outside the UK. When we transfer your personal data internationally, we ensure appropriate safeguards are in place:
- Adequacy decisions by the UK government
- Standard Contractual Clauses approved by the ICO
- Certification schemes and codes of conduct
- Binding corporate rules for multinational service providers
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will:
- Post the updated policy on our website with a new effective date
- Notify you of significant changes via email if you have subscribed to our communications
- Maintain previous versions for reference and transparency
12. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
Data Protection Officer
Email: [email protected]
Postal Address
Trick Earth Ltd
25 Cavendish Square
London W1G 0PN
United Kingdom
Right to Complain: You have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe we have not handled your personal data in accordance with data protection law. Visit ico.org.uk for more information.