Privacy Policy
We build software that keeps data inside our clients' own boundaries. It would be odd if we were careless with yours. This policy explains what we do with personal data, in plain terms.
The short version. When you visit this website or talk to us about our services, Dtechtive is the data controller for the limited personal data involved, such as your name, work email and what you asked us about.
When we deploy our tool for an enterprise client, the position is different and deliberately so. Our software runs inside the client's own environment. Personal data in that environment stays there, under the client's control. We act as a processor on the client's instructions, and in most deployments we do not hold a copy of client data at all.
1. Who we are
Dtechtive Limited is a company registered in England and Wales, company number 12365322, with a registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ. In this policy, "Dtechtive", "we" and "us" mean Dtechtive Limited.
We provide privacy-first, AI-native metadata and data enrichment software to enterprises and public-sector organisations. We are registered with the Information Commissioner's Office (ICO) as a data controller.
2. Our two roles: controller and processor
Data protection law distinguishes between the organisation that decides why and how personal data is used (the controller) and the organisation that processes it on someone else's instructions (the processor). Dtechtive acts in both capacities, in clearly separated circumstances.
We are the controller when
You visit this website, contact us, book a demo, attend one of our webinars, subscribe to updates, apply for a role, or engage with us as a supplier or partner. This policy governs that processing.
We are the processor when
We deploy or operate our tool for a client. The client is the controller and determines what happens to the data in their environment. Our processing is governed by the data processing agreement we sign with them, not by this policy.
If you are an employee, customer or contact of one of our clients and want to know how your personal data is handled, the client is the right organisation to ask. We will always support them in responding.
3. Enterprise deployments and your data
This section matters most to enterprise buyers, so we have set it out plainly.
Our software is designed to be deployed inside the client's own boundary: inside your boundary, in the client's own cloud tenancy, or in an air-gapped environment. In those deployments:
- Client data is processed where it already lives. It is not transferred to Dtechtive's infrastructure.
- AI inference runs inside the same boundary, using a self-hosted open-source model or the client's own cloud AI service.
- We do not require a copy of client data in order to operate or support the deployment.
- Access by our personnel, where needed for support, is granted by the client, limited in scope and logged.
Where a client asks us to host a deployment on their behalf, that arrangement is agreed separately in writing, with the hosting location, security measures and sub-processors set out in the data processing agreement.
4. Personal data we collect
As a controller, we collect only what we need. In practice that means:
| Category | Examples | Where it comes from |
|---|---|---|
| Contact data | Name, work email, job title, organisation, phone number | You, when you contact us, book a demo or register for an event |
| Enquiry data | What you asked about, notes from discovery calls, requirements you shared | You, during our conversations |
| Contract data | Billing contacts, purchase order details, supplier records | You or your organisation |
| Account data | Name, email address, organisation and role | You, if you register for an account on our Web Data Search service |
| Technical data | IP address, browser type, pages viewed, referring site | Automatically, when you use this website |
| Recruitment data | CV, work history, right-to-work information | You, if you apply for a role with us |
We do not seek special category data (such as health, biometric or ethnicity information) through this website, and we ask that you do not send it to us unsolicited.
5. Why we use it, and our legal basis
| Purpose | Legal basis |
|---|---|
| Responding to your enquiry and arranging demos or meetings | Legitimate interests, or steps taken at your request before entering a contract |
| Providing our services and managing the client relationship | Performance of a contract |
| Sending relevant updates about our services to business contacts | Legitimate interests, with an unsubscribe option in every message |
| Responding to security questionnaires, tenders and procurement processes | Legitimate interests, or steps before entering a contract |
| Maintaining your Web Data Search account, improving the service based on how it is used, and notifying you of changes or service interruptions | Performance of a contract, and legitimate interests |
| Improving our website and understanding how it is used | Consent, where analytics cookies are used |
| Meeting our legal, tax and regulatory obligations | Legal obligation |
| Assessing job applications | Steps taken at your request before entering a contract |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and you can object at any time using the contact details below.
6. AI models and your data
We are an AI company, so we think this deserves its own section rather than a clause buried elsewhere.
- We do not use client data to train commercial AI models. Client data is not sent to third-party model providers for training, fine-tuning or evaluation.
- Inference happens inside the client's boundary. Depending on the deployment, this uses a self-hosted open-source model or the client's own cloud AI service under the client's own agreement with that provider.
- Human review is built in. AI-generated metadata is presented for review rather than published automatically, so a person remains accountable for what is recorded.
- We do not make solely automated decisions that produce legal or similarly significant effects about individuals.
7. Who we share personal data with
We will not share your information with other organisations for commercial purposes, and we will not pass your details to other parties unless we are required to do so by law. We do not sell personal data.
We share personal data only where necessary, with:
- Service providers who support our own operations, such as our website host, email and productivity tools, CRM, meeting scheduling and accounting software. Each is bound by contract to process personal data only on our instructions.
- Professional advisers such as lawyers, auditors and insurers, where needed.
- Partners, where we deliver work jointly and you have been told this at the time.
- Authorities, where we are required to disclose information by law.
A current list of the sub-processors used in a given deployment is provided to enterprise clients as part of the data processing agreement, and updated when it changes.
8. International transfers
We are a UK company and prefer to keep personal data in the UK or the European Economic Area. Where a service provider processes personal data outside those areas, we rely on an adequacy decision or on approved safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
For enterprise deployments, data residency is determined by the client's own environment, which means clients with data residency obligations can meet them without depending on our infrastructure.
9. How long we keep personal data
- Enquiries that do not proceed: up to 24 months from our last contact, so we can pick up the conversation if you return.
- Client and supplier records: for the duration of the relationship and for 6 years afterwards, to meet contractual and tax requirements.
- Marketing contacts: until you unsubscribe or ask us to stop.
- Unsuccessful job applications: up to 12 months, unless you ask us to keep your details for longer.
- Website analytics: in line with the retention period set in the analytics tool.
In processor deployments, retention of client data is set by the client, not by us.
10. How we protect personal data
Our approach is privacy by design rather than controls added afterwards. Measures include access control on a least-privilege basis, encryption in transit, logging of administrative access, supplier due diligence, and staff training on data protection and security. Penetration testing and Cyber Essentials certification are in progress.
If a personal data breach occurs that is likely to result in a risk to individuals, we will notify the ICO within 72 hours of becoming aware of it, and affected individuals where the risk is high. Where we act as a processor, we notify the client without undue delay so they can meet their own obligations.
11. Your rights
Under UK data protection law you have the right to ask us to: give you access to the personal data we hold about you; correct it if it is wrong; delete it; restrict how we use it; provide it in a portable format; or stop using it where we rely on legitimate interests. Where we rely on consent, you can withdraw that consent at any time.
In short: you are entitled to view, amend or delete the personal information we hold about you. To exercise any of these rights, contact us using the details below. We will respond within one month. There is no charge, and you do not need to give a reason.
If you are unhappy with how we have handled your personal data, you can complain to the Information Commissioner's Office at ico.org.uk. We would appreciate the chance to address your concern first.
12. Cookies and analytics
This website uses a small number of cookies. Strictly necessary cookies keep the site working, including remembering whether you have chosen the light or dark theme. This preference is stored in your browser and is not sent to us.
Where we use analytics to understand how the site is used, we ask for your consent first, and you can withdraw it at any time. Declining analytics does not affect your ability to use the site.
You can manage your cookie preferences at dtechtive.com/cookies. Most modern browsers also let you control cookies through their own settings. To find out more about cookies generally, including how to see which have been set and how to delete them, see aboutcookies.org.
13. Changes to this policy
We update this policy when our practices change or when the law requires it. The version date is shown at the top of this page. Where a change materially affects how we use personal data, we will tell affected individuals directly.
14. How to contact us
For any question about this policy, or to exercise your rights, email [email protected] or write to: Dtechtive Limited, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.
Enterprise clients and prospective clients can request our standard data processing agreement, sub-processor list and security documentation from [email protected].