Privacy Policy

We build software that keeps data inside our clients' own boundaries. It would be odd if we were careless with yours. This policy explains what we do with personal data, in plain terms.

Version 1.0.0 Last updated: 16 August 2026 Applies to: dtechtive.com and our business relationships

The short version. When you visit this website or talk to us about our services, Dtechtive is the data controller for the limited personal data involved, such as your name, work email and what you asked us about.

When we deploy our tool for an enterprise client, the position is different and deliberately so. Our software runs inside the client's own environment. Personal data in that environment stays there, under the client's control. We act as a processor on the client's instructions, and in most deployments we do not hold a copy of client data at all.

1. Who we are

Dtechtive Limited is a company registered in England and Wales, company number 12365322, with a registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ. In this policy, "Dtechtive", "we" and "us" mean Dtechtive Limited.

We provide privacy-first, AI-native metadata and data enrichment software to enterprises and public-sector organisations. We are registered with the Information Commissioner's Office (ICO) as a data controller.

2. Our two roles: controller and processor

Data protection law distinguishes between the organisation that decides why and how personal data is used (the controller) and the organisation that processes it on someone else's instructions (the processor). Dtechtive acts in both capacities, in clearly separated circumstances.

We are the controller when

You visit this website, contact us, book a demo, attend one of our webinars, subscribe to updates, apply for a role, or engage with us as a supplier or partner. This policy governs that processing.

We are the processor when

We deploy or operate our tool for a client. The client is the controller and determines what happens to the data in their environment. Our processing is governed by the data processing agreement we sign with them, not by this policy.

If you are an employee, customer or contact of one of our clients and want to know how your personal data is handled, the client is the right organisation to ask. We will always support them in responding.

3. Enterprise deployments and your data

This section matters most to enterprise buyers, so we have set it out plainly.

Our software is designed to be deployed inside the client's own boundary: inside your boundary, in the client's own cloud tenancy, or in an air-gapped environment. In those deployments:

  • Client data is processed where it already lives. It is not transferred to Dtechtive's infrastructure.
  • AI inference runs inside the same boundary, using a self-hosted open-source model or the client's own cloud AI service.
  • We do not require a copy of client data in order to operate or support the deployment.
  • Access by our personnel, where needed for support, is granted by the client, limited in scope and logged.

Where a client asks us to host a deployment on their behalf, that arrangement is agreed separately in writing, with the hosting location, security measures and sub-processors set out in the data processing agreement.

4. Personal data we collect

As a controller, we collect only what we need. In practice that means:

CategoryExamplesWhere it comes from
Contact dataName, work email, job title, organisation, phone numberYou, when you contact us, book a demo or register for an event
Enquiry dataWhat you asked about, notes from discovery calls, requirements you sharedYou, during our conversations
Contract dataBilling contacts, purchase order details, supplier recordsYou or your organisation
Account dataName, email address, organisation and roleYou, if you register for an account on our Web Data Search service
Technical dataIP address, browser type, pages viewed, referring siteAutomatically, when you use this website
Recruitment dataCV, work history, right-to-work informationYou, if you apply for a role with us

We do not seek special category data (such as health, biometric or ethnicity information) through this website, and we ask that you do not send it to us unsolicited.

5. Why we use it, and our legal basis

PurposeLegal basis
Responding to your enquiry and arranging demos or meetingsLegitimate interests, or steps taken at your request before entering a contract
Providing our services and managing the client relationshipPerformance of a contract
Sending relevant updates about our services to business contactsLegitimate interests, with an unsubscribe option in every message
Responding to security questionnaires, tenders and procurement processesLegitimate interests, or steps before entering a contract
Maintaining your Web Data Search account, improving the service based on how it is used, and notifying you of changes or service interruptionsPerformance of a contract, and legitimate interests
Improving our website and understanding how it is usedConsent, where analytics cookies are used
Meeting our legal, tax and regulatory obligationsLegal obligation
Assessing job applicationsSteps taken at your request before entering a contract

Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and you can object at any time using the contact details below.

6. AI models and your data

We are an AI company, so we think this deserves its own section rather than a clause buried elsewhere.

  • We do not use client data to train commercial AI models. Client data is not sent to third-party model providers for training, fine-tuning or evaluation.
  • Inference happens inside the client's boundary. Depending on the deployment, this uses a self-hosted open-source model or the client's own cloud AI service under the client's own agreement with that provider.
  • Human review is built in. AI-generated metadata is presented for review rather than published automatically, so a person remains accountable for what is recorded.
  • We do not make solely automated decisions that produce legal or similarly significant effects about individuals.

7. Who we share personal data with

We will not share your information with other organisations for commercial purposes, and we will not pass your details to other parties unless we are required to do so by law. We do not sell personal data.

We share personal data only where necessary, with:

  • Service providers who support our own operations, such as our website host, email and productivity tools, CRM, meeting scheduling and accounting software. Each is bound by contract to process personal data only on our instructions.
  • Professional advisers such as lawyers, auditors and insurers, where needed.
  • Partners, where we deliver work jointly and you have been told this at the time.
  • Authorities, where we are required to disclose information by law.

A current list of the sub-processors used in a given deployment is provided to enterprise clients as part of the data processing agreement, and updated when it changes.

8. International transfers

We are a UK company and prefer to keep personal data in the UK or the European Economic Area. Where a service provider processes personal data outside those areas, we rely on an adequacy decision or on approved safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.

For enterprise deployments, data residency is determined by the client's own environment, which means clients with data residency obligations can meet them without depending on our infrastructure.

9. How long we keep personal data

  • Enquiries that do not proceed: up to 24 months from our last contact, so we can pick up the conversation if you return.
  • Client and supplier records: for the duration of the relationship and for 6 years afterwards, to meet contractual and tax requirements.
  • Marketing contacts: until you unsubscribe or ask us to stop.
  • Unsuccessful job applications: up to 12 months, unless you ask us to keep your details for longer.
  • Website analytics: in line with the retention period set in the analytics tool.

In processor deployments, retention of client data is set by the client, not by us.

10. How we protect personal data

Our approach is privacy by design rather than controls added afterwards. Measures include access control on a least-privilege basis, encryption in transit, logging of administrative access, supplier due diligence, and staff training on data protection and security. Penetration testing and Cyber Essentials certification are in progress.

If a personal data breach occurs that is likely to result in a risk to individuals, we will notify the ICO within 72 hours of becoming aware of it, and affected individuals where the risk is high. Where we act as a processor, we notify the client without undue delay so they can meet their own obligations.

11. Your rights

Under UK data protection law you have the right to ask us to: give you access to the personal data we hold about you; correct it if it is wrong; delete it; restrict how we use it; provide it in a portable format; or stop using it where we rely on legitimate interests. Where we rely on consent, you can withdraw that consent at any time.

In short: you are entitled to view, amend or delete the personal information we hold about you. To exercise any of these rights, contact us using the details below. We will respond within one month. There is no charge, and you do not need to give a reason.

If you are unhappy with how we have handled your personal data, you can complain to the Information Commissioner's Office at ico.org.uk. We would appreciate the chance to address your concern first.

12. Cookies and analytics

This website uses a small number of cookies. Strictly necessary cookies keep the site working, including remembering whether you have chosen the light or dark theme. This preference is stored in your browser and is not sent to us.

Where we use analytics to understand how the site is used, we ask for your consent first, and you can withdraw it at any time. Declining analytics does not affect your ability to use the site.

You can manage your cookie preferences at dtechtive.com/cookies. Most modern browsers also let you control cookies through their own settings. To find out more about cookies generally, including how to see which have been set and how to delete them, see aboutcookies.org.

13. Changes to this policy

We update this policy when our practices change or when the law requires it. The version date is shown at the top of this page. Where a change materially affects how we use personal data, we will tell affected individuals directly.

14. How to contact us

For any question about this policy, or to exercise your rights, email [email protected] or write to: Dtechtive Limited, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.

Enterprise clients and prospective clients can request our standard data processing agreement, sub-processor list and security documentation from [email protected].

Enterprise buyers

Need our DPA or security documentation?

We can share our standard data processing agreement, sub-processor list and security documentation ahead of any procurement or security review.

Request the documents