We collect the minimum we need to run our website, our apps and our client work. We do not sell personal data. We do not use it to train third-party AI models. You can ask us to show you, correct or delete what we hold at any time by writing to privacy@techgptltd.com, and we will respond within 30 days.
1. Who we are
TechGPT Ltd ("TechGPT", "we", "us", "our") is a company registered in England and Wales under company number [Company Number], with its registered office at [Registered Office Address], United Kingdom.
For the purposes of the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018, and the EU General Data Protection Regulation ("EU GDPR") where it applies, TechGPT Ltd is the data controller for personal data processed through this website and through applications we publish under our own name.
Where we build or operate software on behalf of a client, that client is normally the data controller and we act as a data processor under a written data processing agreement. In those cases, the client's own privacy notice governs how your data is used, and this policy applies only to our own direct relationship with you.
You can reach our privacy contact at privacy@techgptltd.com or by post at the registered office address above, marked "Data Protection".
2. Scope of this policy
This policy applies to:
- This website and any subdomain we operate;
- Mobile applications published by TechGPT Ltd on the Apple App Store and Google Play;
- Enquiries, support requests and correspondence you send us;
- Our commercial relationships with clients, suppliers and applicants.
It does not apply to third-party websites or services we link to. Those have their own privacy policies, and we are not responsible for their content or practices.
3. Personal data we collect
3.1 Information you give us
- Contact details — name, email address, telephone number, company name and job title, when you complete a form, email us, or engage us commercially.
- Enquiry content — whatever you choose to write in a message, support ticket or project brief.
- Account details — where one of our applications offers an account, the identifiers used to create and secure it, such as an email address, display name and a hashed password or a third-party sign-in identifier.
- Content you submit — files, text, images or other material you upload into an application we operate.
- Recruitment data — CV, work history and anything else you send when applying for a role.
3.2 Information collected automatically
- Technical data — IP address, browser type and version, operating system, device model, language and screen size.
- Usage data — pages visited, features used, referring page, timestamps and approximate session duration.
- Diagnostic data — crash reports, error traces and performance measurements, used to find and fix defects.
Where our applications collect diagnostic or analytics data, this is disclosed in the App Store privacy label and Google Play Data Safety declaration for that app. See our Google Play policy page and App Store policy page for how those declarations are made.
3.3 Information from third parties
- Sign-in providers — if you sign in with Google or Apple, we receive the identifiers those services release to us, typically a user identifier, email address and display name. We do not receive your password.
- Payment processors — where you pay us, our processor confirms the transaction and gives us limited details such as the last four digits of a card, the amount and the outcome. We never receive or store full payment card numbers.
- App stores — aggregated download, subscription and crash statistics from Apple and Google.
3.4 Data we do not seek
We do not intentionally collect special category data — information about health, race, ethnicity, religion, political opinions, trade union membership, genetics, biometrics, sex life or sexual orientation — unless a specific service explicitly requires it and you have been told so and consented. Please do not send us this kind of information in a general enquiry.
4. Why we use personal data, and our legal basis
Under UK and EU GDPR we must have a lawful basis for each purpose. Ours are set out below.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Responding to enquiries and providing quotes | Contact details, enquiry content | Legitimate interests — responding to a request you made; or steps prior to entering a contract |
| Delivering contracted services to clients | Contact details, project data | Performance of a contract |
| Creating and securing user accounts | Account details, technical data | Performance of a contract |
| Diagnosing crashes and fixing defects | Diagnostic data, technical data | Legitimate interests — keeping our software working correctly |
| Measuring how our website and apps are used | Usage data, technical data | Consent, where analytics cookies or SDKs are used |
| Sending service messages (security, billing, outages) | Contact details | Performance of a contract; legal obligation |
| Sending marketing updates | Contact details | Consent, or legitimate interests for existing clients on comparable services |
| Preventing fraud, abuse and security incidents | Technical data, usage data | Legitimate interests — protecting our services and users |
| Accounting, tax and statutory records | Transaction and contact details | Legal obligation |
| Establishing or defending legal claims | Whatever is relevant | Legitimate interests — protecting our legal position |
| Recruitment | Application data | Steps prior to entering a contract; consent for talent pools |
Where we rely on legitimate interests, we have assessed that our interest does not override your rights and freedoms. You may object to that processing at any time — see section 10.
5. Artificial intelligence and automated processing
Some products we build use large language models and other machine learning services. Where that applies:
- We tell you within the product when you are interacting with an AI feature.
- Content you submit to an AI feature may be transmitted to a model provider (for example Anthropic, OpenAI or Google) purely to generate a response for you.
- We use enterprise or API tiers configured so that your content is not used to train the provider's models, and we require the same commitment contractually.
- We do not make decisions producing legal or similarly significant effects about you based solely on automated processing, within the meaning of Article 22 of the UK GDPR. Where an automated output informs a significant decision, a human reviews it.
- AI outputs can be wrong. They are provided for assistance only and should not be relied on as professional advice — see our Disclaimer.
6. Cookies and similar technologies
This website uses only the cookies and local storage strictly necessary for it to function. We do not run advertising trackers or cross-site profiling on it. Where a specific product does use analytics or other non-essential cookies, we ask for consent first and you can withdraw it at any time.
Full details, including categories, purposes and how to control them in your browser, are in our Cookie Policy.
7. Who we share personal data with
We do not sell personal data, and we do not share it for cross-context behavioural advertising. We share it only in the circumstances below.
- Service providers (processors) acting on our documented instructions — cloud hosting, email delivery, error monitoring, analytics, payment processing, customer support tooling and, where relevant, AI model providers. Each is bound by a written contract meeting Article 28 UK GDPR.
- Clients, where we process data on their behalf as their processor.
- Professional advisers — lawyers, accountants, auditors and insurers, where they need it and are under a duty of confidentiality.
- Authorities, where we are legally required to disclose, or where disclosure is necessary to establish, exercise or defend legal claims, or to protect the vital interests of any person.
- A successor entity, if our business or its assets are sold, merged or reorganised — in which case we will tell affected individuals and the acquirer remains bound by this policy until it lawfully changes it.
Our principal categories of processor are: cloud infrastructure and hosting (including Google Firebase and Amazon Web Services); email and communication tools; crash and performance monitoring; payment processing; and, where a product uses them, AI model providers.
8. International transfers
Some of our providers operate outside the United Kingdom and the European Economic Area, including in the United States. Where personal data is transferred outside the UK or EEA, we rely on one or more of:
- UK adequacy regulations or an EU adequacy decision covering the destination country;
- the International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK International Data Transfer Addendum;
- certification under the UK Extension to the EU–US Data Privacy Framework, where the recipient participates.
We carry out a transfer risk assessment where required and apply supplementary technical measures such as encryption in transit and at rest. You may request a copy of the safeguards in place by emailing privacy@techgptltd.com.
9. How long we keep personal data
We keep personal data only as long as we need it for the purpose it was collected for, or as long as the law requires.
| Category | Retention period |
|---|---|
| Enquiries that do not become projects | 24 months from last contact |
| Client project records and correspondence | 7 years after the engagement ends |
| Accounting and tax records | 6 years after the end of the relevant financial year (statutory) |
| Active user accounts | For as long as the account is active |
| Deleted user accounts | Removed from live systems within 30 days; purged from encrypted backups within 90 days |
| Website server and security logs | 90 days |
| Crash and diagnostic reports | 12 months |
| Analytics data | 14 months, in aggregated form thereafter |
| Marketing contacts | Until consent is withdrawn, then suppression-list only |
| Unsuccessful job applications | 12 months, or longer with your consent |
When a period ends we delete the data or irreversibly anonymise it so it can no longer identify anyone.
10. Your rights
Under the UK GDPR and EU GDPR you have the following rights, free of charge in almost all cases:
- Access — a copy of the personal data we hold about you and information about how we use it.
- Rectification — correction of data that is inaccurate or incomplete.
- Erasure — deletion of your data where there is no overriding reason for us to keep it. See Delete your account.
- Restriction — to have us pause processing while a dispute about accuracy or lawfulness is resolved.
- Portability — to receive data you gave us in a structured, commonly used, machine-readable format, and to have it sent to another controller where technically feasible.
- Objection — to object to processing based on legitimate interests, and an absolute right to object to direct marketing.
- Withdraw consent — at any time, where processing is based on consent. This does not affect processing already carried out.
- Automated decisions — not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
To exercise any right, email privacy@techgptltd.com. We will acknowledge within 72 hours and respond substantively within one month. That period can be extended by two further months for complex or numerous requests, in which case we will tell you within the first month and explain why. We may ask for proof of identity before disclosing personal data.
11. Additional rights for United States residents
If you are a resident of California, or of another US state with comparable legislation, you may have the right to know what personal information is collected, disclosed or sold; to request deletion or correction; to opt out of sale or sharing; and not to be discriminated against for exercising those rights.
TechGPT Ltd does not sell personal information and does not share it for cross-context behavioural advertising as those terms are defined under the California Consumer Privacy Act, as amended. To exercise a US state privacy right, write to privacy@techgptltd.com with the subject line "US Privacy Request". You may use an authorised agent, provided we can verify their authority.
12. Children
Our website and our business services are directed at organisations and adults, and are not intended for children under 13. We do not knowingly collect personal data from children under 13 in the UK, or under the age set by local law where that is higher.
Some consumer applications we publish may be rated for a broader audience. Where that is the case, the specific protections that apply are described in our Children's Privacy Policy. If you believe a child has given us personal data, contact privacy@techgptltd.com and we will delete it promptly.
13. How we protect personal data
We apply technical and organisational measures appropriate to the risk, including encryption in transit (TLS 1.2 or above) and at rest, role-based access control, multi-factor authentication on administrative accounts, least-privilege permissions, code review, dependency scanning, logging and regular backups.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of it, and notify affected individuals without undue delay where the risk is high. Further detail is on our Security page.
14. Marketing communications
We send marketing email only where you have opted in, or where you are an existing client and the message concerns similar services — the "soft opt-in" permitted by the Privacy and Electronic Communications Regulations. Every marketing message contains an unsubscribe link that works immediately. Unsubscribing does not stop essential service messages such as security notices, billing or outage notifications.
15. Third-party links and services
Our website and applications may link to third-party sites and integrate third-party services. We do not control them and are not responsible for their privacy practices. We encourage you to read the privacy policy of any third-party service before providing it with personal data.
16. Changes to this policy
We may update this policy to reflect changes to our services, technology or the law. The "Last updated" date at the top always reflects the current version. Where a change materially affects your rights we will give reasonable advance notice — by email to registered users, by an in-product notice, or by a prominent banner on this website. Continued use after a change takes effect means you accept the updated policy.
17. Complaints
If you are unhappy with how we have handled your personal data, please tell us first at privacy@techgptltd.com so we have the chance to put it right.
You also have the right to complain to a supervisory authority. In the United Kingdom that is the Information Commissioner's Office:
- Website: ico.org.uk/make-a-complaint
- Helpline: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
If you are in the European Economic Area, you may instead complain to the supervisory authority in your country of residence, place of work, or where the alleged infringement occurred.
18. Contact us
TechGPT Ltd
[Registered Office Address]
United Kingdom
Company number: [Company Number]
Privacy enquiries: privacy@techgptltd.com
General enquiries: hello@techgptltd.com
Security reports: security@techgptltd.com
Terms of Service · Cookie Policy · Account Deletion · Children's Privacy · Google Play policies · App Store policies