Privacy Policy
Effective Date: 3 June 2026 | Certified Compliant (UK GDPR / DUAA 2025 / DMCCA 2024)
Data Privacy & Compliance Queries:
For any questions regarding your data rights, or to submit an inquiry, please contact our Data Privacy Lead directly at hello@itsmyapp.co.uk. We formally acknowledge all compliance submissions within 30 days.
1. Data Minimization & Cloud Architecture
We adhere strictly to the principle of Data Minimization. We collect and process only the minimal personal data necessary for service execution:
- Identity Data: Full name and managerial role assignment.
- Contact Data: Verified email address for authentication and statutory notifications.
- Technical Data: IP address, browser user-agent tokens, and security event logs.
- Usage Data: Operational banking figures, revenue breakdowns, terminal takings, and audit timestamps.
All database writes and reads are transmitted via end-to-end TLS/SSL encryption and stored on secure UK/EU Firebase Cloud infrastructure.
2. Recognized Legitimate Interests (UK GDPR / DUAA)
Pursuant to Article 6 of the UK GDPR (as amended by the Data (Use and Access) Act):
Processing of technical data for system security, fraud mitigation, malware reduction, multi-session abuse prevention, and emergency infrastructure response is recognized under Recognized Legitimate Interests, omitting the requirement for an ad-hoc balancing test while maintaining strict technical safeguards.
3. Automated Decision-Making & AI Protections
If automated algorithmic systems or AI calculation engines process significant records that carry legal or financially significant consequences:
Users maintain the explicit statutory right to receive a clear explanation of the calculation parameters, challenge automated outputs, and demand direct human review by our Data Privacy Lead.
4. Subject Access Requests (SARs) & Your Rights
Under the UK GDPR, you have the following enforceable rights:
- Right of Access: Request a full copy of all personal records held in your name.
- Right to Rectification: Request correction of inaccurate personal data.
- Right to Erasure ("Right to be Forgotten"): Request deletion of your profile where retention is not required by statutory accounting laws.
- Right to Data Portability: Export your company data in machine-readable JSON format directly from settings.
Subject searches are conducted under "reasonable and proportionate" criteria. The statutory 30-day timeline may be paused during identity verification or when clarifying overly broad requests.
5. Complaints Workflow & Regulatory Escalation
We commit to formal acknowledgment of all compliance inquiries and formal complaints within 30 days of receipt. To submit a request, contact our Data Privacy Lead at hello@itsmyapp.co.uk.
If you remain unsatisfied with our internal response, you retain the statutory right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.