Back to Application
Data Protection & Privacy Manifest

Privacy Policy

Effective Date: 3 June 2026 | Certified Compliant (UK GDPR / DUAA 2025 / DMCCA 2024)

Data Privacy & Compliance Queries:

For any questions regarding your data rights, or to submit an inquiry, please contact our Data Privacy Lead directly at hello@itsmyapp.co.uk. We formally acknowledge all compliance submissions within 30 days.

1. Data Minimization & Cloud Architecture

We adhere strictly to the principle of Data Minimization. We collect and process only the minimal personal data necessary for service execution:

  • Identity Data: Full name and managerial role assignment.
  • Contact Data: Verified email address for authentication and statutory notifications.
  • Technical Data: IP address, browser user-agent tokens, and security event logs.
  • Usage Data: Operational banking figures, revenue breakdowns, terminal takings, and audit timestamps.

All database writes and reads are transmitted via end-to-end TLS/SSL encryption and stored on secure UK/EU Firebase Cloud infrastructure.

2. Recognized Legitimate Interests (UK GDPR / DUAA)

Pursuant to Article 6 of the UK GDPR (as amended by the Data (Use and Access) Act):

Processing of technical data for system security, fraud mitigation, malware reduction, multi-session abuse prevention, and emergency infrastructure response is recognized under Recognized Legitimate Interests, omitting the requirement for an ad-hoc balancing test while maintaining strict technical safeguards.

3. Automated Decision-Making & AI Protections

If automated algorithmic systems or AI calculation engines process significant records that carry legal or financially significant consequences:

Users maintain the explicit statutory right to receive a clear explanation of the calculation parameters, challenge automated outputs, and demand direct human review by our Data Privacy Lead.

4. Subject Access Requests (SARs) & Your Rights

Under the UK GDPR, you have the following enforceable rights:

  • Right of Access: Request a full copy of all personal records held in your name.
  • Right to Rectification: Request correction of inaccurate personal data.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your profile where retention is not required by statutory accounting laws.
  • Right to Data Portability: Export your company data in machine-readable JSON format directly from settings.

Subject searches are conducted under "reasonable and proportionate" criteria. The statutory 30-day timeline may be paused during identity verification or when clarifying overly broad requests.

5. Complaints Workflow & Regulatory Escalation

We commit to formal acknowledgment of all compliance inquiries and formal complaints within 30 days of receipt. To submit a request, contact our Data Privacy Lead at hello@itsmyapp.co.uk.

If you remain unsatisfied with our internal response, you retain the statutory right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.