Privacy Policy

Last updated: 18 June 2026

This Privacy Notice for FAT32 LTD (doing business as OneClickComply) ('we', 'us', or 'our'), describes how and why we might access, collect, store, use, and/or share ('process') your personal information when you use our services ('Services'), including when you:

  • Visit our website at https://oneclickcomply.com, or any website of ours that links to this Privacy Notice.

  • Use the OneClickComply platform and our Cyber Essentials and Cyber Essentials Plus services.

  • Engage with us in other related ways, including any sales, marketing, or events.

Who we are. FAT32 LTD, trading as OneClickComply, is a company registered in England. Our registered office is 69 Church Way, North Shields, Tyne and Wear, NE29 0AE, England. For most of the personal information described in this notice, we are the 'data controller'. Where we process personal information on behalf of our business customers as part of providing the Services, we act as a 'data processor' (see section 3).

Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at privacy@oneclickcomply.com.

SUMMARY OF KEY POINTS

This summary provides key points from our Privacy Notice, but you can find out more details by using our table of contents below to find the section you are looking for.

What personal information do we process? When you visit, use, or navigate our Services, we may process personal information depending on how you interact with us and the Services, the choices you make, and the products and features you use. Learn more in section 1.

Do we process any sensitive personal information? We do not process sensitive personal information (also known as special category data) in the ordinary course of providing the Services.

Do we collect any information from third parties? We may collect information from public databases, business-contact data providers, marketing partners, and other outside sources. Learn more in section 1.

How do we process your information? We process your information to provide, improve, and administer our Services, communicate with you, take payment, provide support, for security and fraud prevention, to recover sums due, and to comply with law. We process your information only when we have a valid legal reason to do so. Learn more in section 2.

In what situations and with which types of parties do we share personal information? We share information with our subprocessors and in specific situations described in section 4.

How do we keep your information safe? We have organisational and technical measures in place to protect your personal information, though no system can be guaranteed 100% secure. Learn more in section 9.

What are your rights? Depending on where you are located, applicable privacy law may give you certain rights over your personal information, including the right to make a data protection complaint directly to us. Learn more in section 11.

How do you exercise your rights? The easiest way is by visiting https://app.prighter.com/dsr/12516138869, or by contacting us.

How do you complain? You have the right to complain to us directly about how we handle your personal information. We will acknowledge your complaint within 30 days and keep you informed of the outcome. You can also complain to a data protection regulator. Learn more in section 11.

TABLE OF CONTENTS

  1. WHAT INFORMATION DO WE COLLECT?

  2. HOW DO WE PROCESS YOUR INFORMATION?

  3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR PERSONAL INFORMATION?

  4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?

  5. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?

  6. DO WE OFFER ARTIFICIAL INTELLIGENCE-BASED PRODUCTS?

  7. IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?

  8. HOW LONG DO WE KEEP YOUR INFORMATION?

  9. HOW DO WE KEEP YOUR INFORMATION SAFE?

  10. DO WE COLLECT INFORMATION FROM MINORS?

  11. WHAT ARE YOUR PRIVACY RIGHTS?

  12. CONTROLS FOR DO-NOT-TRACK FEATURES

  13. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?

  14. DO WE MAKE UPDATES TO THIS NOTICE?

  15. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?

  16. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

1. WHAT INFORMATION DO WE COLLECT?

Personal information you disclose to us

In Short: We collect personal information that you provide to us.

We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, when you communicate with us, or otherwise when you contact us.

Personal Information Provided by You. The personal information that we collect may include the following:

  • Names

  • Phone numbers

  • Email addresses

  • Mailing and billing addresses

  • Job titles

  • Company and role information

  • Usernames and passwords

  • Contact preferences

  • Contact or authentication data

  • Account and contract data

  • Payment and billing data, including debit/credit card information

  • Your communications with us and the related metadata

  • Your statements and views as recorded in meetings and calls, where these are recorded (see below)

Recorded meetings and calls. Where you attend an online meeting or telephone call with us, we may record and transcribe that meeting or call for the purposes of providing the Services, customer support, training, quality, and maintaining a record of our dealings with you. We will make you aware where a meeting or call is being recorded, including at the start of inbound telephone calls. Recording and transcription are carried out using a third-party provider (see section 4).

Sensitive Information. We do not intentionally collect special category (sensitive) personal information. Where such information is incidentally captured, for example in a recorded call, an uploaded document, or a free-text field, we do not use it for any separate purpose, and we delete or redact it where it is not needed.

Payment Data. We may collect data necessary to process your payment if you make purchases, such as your payment instrument number and the security code associated with your payment instrument. All card payment data is handled and stored by Stripe. You may find their privacy notice here: https://stripe.com/gb/privacy.

All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal information.

Information automatically collected

In Short: Some information — such as your Internet Protocol (IP) address and/or browser and device characteristics — is collected automatically when you visit our Services.

We automatically collect certain information when you visit, use, or navigate the Services. This information may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, information about how and when you use our Services, and other technical information. This information is primarily needed to maintain the security and operation of our Services, and for our internal analytics and reporting purposes.

Like many businesses, we also collect information through cookies, similar technologies, and product-analytics tools. This may include analytics events and, where enabled, session recordings of your interaction with the platform (see section 5).

The information we collect includes:

  • Log and Usage Data. Service-related, diagnostic, usage, and performance information our servers and logging tools automatically collect when you access or use our Services and which we record in log files. This may include your IP address, device information, browser type, settings, information about your activity in the Services, and device event information (such as system activity and error reports).

  • Device Data. Information about the computer, phone, tablet, or other device you use to access the Services, such as your IP address, device and application identification numbers, location, browser type, hardware model, Internet service provider and/or mobile carrier, operating system, and system configuration information.

  • Location Data. Information about your device's approximate location, derived from data such as your IP address. We do not collect precise (GPS-level) location data. You can opt out of allowing us to collect this information either by refusing access to the information or by disabling the relevant setting on your device. However, if you choose to opt out, you may not be able to use certain aspects of the Services.

Google API

Our use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Information collected from other sources

In Short: We may collect limited data from public databases, business-contact data providers, and other outside sources.

In order to enhance our ability to provide relevant marketing, offers, and services to you and to update our records, we may obtain information about you from other sources, such as public databases, business-contact data providers, joint marketing partners, affiliate programs, data providers, and other third parties. This information may include mailing addresses, job titles, email addresses, phone numbers, intent data (or user behaviour data), Internet Protocol (IP) addresses, social media profiles, social media URLs, and custom profiles.

Where we obtain your personal information from third-party sources rather than from you directly, we will provide you with the information required by Article 14 of the UK GDPR, including the categories of personal information concerned and the source it came from, within a reasonable period and no later than one month, or at the point we first contact you, whichever is earlier. We rely on our legitimate interests for this processing and carry out a balancing assessment beforehand.

2. HOW DO WE PROCESS YOUR INFORMATION?

In Short: We process your information to provide, improve, and administer our Services, communicate with you, take payment, provide support, recover sums due, for security and fraud prevention, and to comply with law.

We process your personal information for a variety of reasons, including:

  • To facilitate account creation and authentication and otherwise manage user accounts.

  • To deliver and facilitate delivery of services to the user, including the OneClickComply platform and the Cyber Essentials and Cyber Essentials Plus services.

  • To respond to user inquiries and offer support to users.

  • To take payment and issue invoices, and to manage renewals, non-payment, and the settlement of accounts.

  • To send administrative information to you, including service and outage notifications, and changes to our terms and policies.

  • To request feedback.

  • To send you marketing and promotional communications, in accordance with your marketing preferences. You can opt out at any time.

  • To deliver targeted advertising to you, where you have consented to the relevant cookies and technologies.

  • To maintain our business relationship with you.

  • To protect our Services, including fraud monitoring, security monitoring, and prevention.

  • To identify usage trends and improve our Services.

  • To determine the effectiveness of our marketing and promotional campaigns.

  • To establish, exercise, or defend legal claims, including the recovery of overdue accounts.

  • To save or protect an individual's vital interests, such as to prevent harm.

3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR INFORMATION?

In Short: We only process your personal information when we have a valid legal reason (i.e. legal basis) to do so.

If you are located in the EU or UK, this section applies to you.

The General Data Protection Regulation (GDPR) and UK GDPR require us to explain the valid legal bases we rely on. We may rely on the following:

  • Consent. Where you have given us permission to use your personal information for a specific purpose. You can withdraw your consent at any time.

  • Performance of a Contract. Where processing is necessary to fulfil our contractual obligations to you or to the contracting entity, including providing the Services, taking payment, and managing the account, or to take steps at your request before entering into a contract.

  • Legitimate Interests. Where processing is reasonably necessary to achieve our legitimate business interests and those interests are not overridden by your rights. The UK GDPR recognises that processing for direct marketing, transmitting personal data within our group of companies for internal administrative purposes, and ensuring the security of our network and information systems may be carried out on the basis of legitimate interests. Where we rely on legitimate interests, we carry out a balancing assessment. Examples include administering the relationship, recovering sums due, supporting our marketing, analysing and improving our Services, and preventing fraud.

  • Recognised Legitimate Interests. In limited circumstances, we may process your personal information on the basis of a 'recognised legitimate interest' under the UK GDPR, where doing so is necessary for purposes such as disclosing personal data to a public body that requires it to carry out its functions, preventing or detecting crime, safeguarding vulnerable individuals, or responding to an emergency. Where this basis applies, we are not required to carry out a separate balancing assessment, but the processing must still be necessary and proportionate.

  • Legal Obligations. Where processing is necessary for compliance with our legal obligations, including accounting and tax obligations, cooperating with a law enforcement body or regulatory agency, or exercising or defending our legal rights.

  • Vital Interests. Where processing is necessary to protect your vital interests or those of a third party.

Controller and processor. We are generally the 'data controller' of the personal information described in this Privacy Notice, since we determine the means and purposes of the processing. This Privacy Notice does not apply to the personal information we process as a 'data processor' on behalf of our business customers (for example, the data within a customer's connected cloud environment that we assess to deliver the Services). In those situations, the contracting customer with whom we have entered into a data processing agreement is the 'data controller', and we process the information on their behalf in accordance with their instructions. The contracting entity may be a company associated with your account rather than you personally. If you want to know more about our customers' privacy practices, you should read their privacy policies.

If you are located in Canada, this section applies to you.

We may process your information if you have given us express consent, or in situations where your consent can be inferred (implied consent). You can withdraw your consent at any time. In some exceptional cases we may be legally permitted to process your information without your consent, for example for fraud detection and prevention, for business transactions where certain conditions are met, where required to comply with a subpoena or court order, or where the information is publicly available and specified by the regulations.

4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?

In Short: We share information with our subprocessors and in the specific situations described below.

Subprocessors and third-party service providers. We share your data with third-party vendors, service providers, and contractors ('subprocessors') who perform services for us and require access to such information to do that work. We have written contracts in place with each subprocessor, in line with Article 28 of the UK GDPR, which require them to safeguard your personal information, to process it only on our instructions, and to retain it only for the period we instruct. They will not share your personal information with any organisation apart from us.

Several of these subprocessors are located outside the United Kingdom. Where that is the case, the transfer is protected by appropriate safeguards as described in section 7. We will provide the identities of the specific recipients of your personal data, and details of the safeguards applied, on request.

(a) Platform, infrastructure, and corporate subprocessors. These process the personal data of website visitors, prospects, and account users:

CategorySubprocessorPurpose

Hosting & infrastructure

Supabase

Managed PostgreSQL database hosting and secure storage of connection configuration

Hosting & infrastructure

Google Cloud (Cloud Storage; Document AI)

File and evidence storage; text and entity extraction from uploaded documents

Hosting & infrastructure

Bytescale

File upload handling and content delivery

Hosting & infrastructure

Cloudflare

Web application firewall, content delivery, and DDoS protection

Authentication & security

Auth0 (by Okta)

Authentication, multi-factor authentication, and account management

Payments, billing & finance

Stripe

Card payment processing and checkout

Payments, billing & finance

Xero

Invoicing and accounting

Sales & quoting

Qwilr

Quotes and proposals

Email & productivity

Resend

Sending of transactional and service emails

Email & productivity

Google Workspace (Gmail, Calendar, Drive)

Business email, calendar, and file storage used to correspond with you and administer the relationship

Email & productivity

Notion

Knowledge base content management

Scheduling

Reclaim

Scheduling of "Ask an Auditor" and similar sessions

Analytics, logging & monitoring

PostHog

Product analytics, feature flags, and (where enabled) session recording

Analytics, logging & monitoring

Better Stack

Application logging and performance monitoring

Product feedback

Featurebase

Product feedback, changelog, and identity verification for the feedback widget

AI & document processing

Anthropic (Claude)

AI processing used to analyse and summarise content within the Services

AI & document processing

Google (Gemini / Generative AI)

AI processing used for evaluation, extraction, and content generation within the Services

AI & document processing

Reducto

AI-assisted document parsing and extraction

Integration & automation

Pipedream

Managed authentication and API connectivity for the integrations you choose to connect

Integration & automation

Make.com

Workflow automation supporting integration setup

Video & content hosting

api.video

Hosting of short video content captured as compliance evidence

Legacy / migration

Airtable

Legacy data source used during platform migration (being decommissioned)

Audio & Video Recording and Transcription

Circleback

To record and transcribe meetings

Telephony

Dialpad

To make and receive calls, with call recording capability.

Telephony

Answerconnect

To provide 24/7 contact centre solutions with call recording capability

(b) Subprocessors engaged in delivering the Services. These are engaged when we provide the Cyber Essentials, Cyber Essentials Plus, and wider compliance and security Services. They may process personal data contained within a business customer's connected environment, in which case we generally act as the customer's processor and the engagement is governed by our data processing agreement with that customer:

SubprocessorPurpose

Huntress

Managed endpoint detection and response

Guardz (EU-hosted)

Email security, phishing protection, security-awareness, and breached-credential monitoring

Afi

Cloud backup posture assessment

Cybershelter Ltd

The assessment of Cyber Essentials and Cyber Essentials Plus

We may also share your personal information in the following situations:

  • Certification bodies. Where you undergo a Cyber Essentials or Cyber Essentials Plus assessment, we share the information necessary to issue your certification with the relevant certification body (for example, the IASME Consortium).

  • Business Transfers. In connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.

  • When we use Google Maps Platform APIs. We may share your information with certain Google Maps Platform APIs (e.g. Google Maps API, Places API) to estimate and use location. You may revoke your consent anytime by contacting us.

  • Affiliates. With our affiliates, in which case we will require them to honour this Privacy Notice. Affiliates include our parent company and any subsidiaries, joint venture partners, or other companies under common control with us.

  • Business Partners. With our business partners to offer you certain products, services, or promotions.

  • Professional advisers, legal and regulatory disclosures. With our professional advisers (such as lawyers, accountants, and auditors), and with courts, law enforcement, regulators, debt-collection agencies, or other authorities where required by law or to establish, exercise, or defend legal claims.

5. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?

In Short: We may use cookies and other tracking technologies to collect and store your information.

We use cookies and similar technologies for different purposes. Some are strictly necessary to operate the Services and keep them and your account secure. Others collect statistical information about how the platform is used, or support basic functionality and appearance, and for these you can opt out at any time through our cookie banner and preference centre. We will only use technologies that record sessions of your interaction with the platform, or that are used for advertising, where you have given your consent, which you can withdraw at any time. Where we record sessions, we apply masking so that sensitive fields, such as passwords and payment details, are not captured. Specific information about the cookies we use, their purpose, and how to control or refuse them is set out in our Cookie Notice.

We also permit third parties and service providers to use online tracking technologies on our Services for analytics and advertising. To the extent these technologies are deemed to be a 'sale' or 'sharing' under applicable US state laws, you can opt out as described in section 13.

Google Analytics

We may share your information with Google Analytics to track and analyse the use of the Services. To opt out of being tracked by Google Analytics across the Services, visit https://tools.google.com/dlpage/gaoptout. For more information on the privacy practices of Google, please visit the Google Privacy & Terms page.

6. DO WE OFFER ARTIFICIAL INTELLIGENCE-BASED PRODUCTS?

In Short: We offer products, features, or tools powered by artificial intelligence, machine learning, or similar technologies.

As part of our Services, we offer products, features, or tools powered by artificial intelligence, machine learning, or similar technologies (collectively, 'AI Products'). The terms in this Privacy Notice govern your use of the AI Products within our Services.

Use of AI Technologies

We provide the AI Products through third-party service providers ('AI Service Providers'), including Anthropic (Claude), Google (Gemini / Generative AI and Cloud Document AI), and Reducto. Where you use an AI Product, your input, output, and the relevant personal information are shared with and processed by these AI Service Providers to enable the feature. We do not permit our AI Service Providers to use your content to train their general-purpose models, and our agreements with them require them to process the data only to provide the service to us. Our agreements with these providers also require them to retain your content only as long as needed to provide the feature to us, and not to retain it for their own purposes. You must not use the AI Products in any way that violates the terms or policies of any AI Service Provider.

Our AI Products

Our AI Products are designed for functions including document generation, automation, evidence summarisation, document parsing and extraction, predictive analytics, research, text analysis, and natural language processing in support of compliance and security workflows.

How We Process Your Data Using AI

All personal information processed using our AI Products is handled in line with this Privacy Notice and our agreements with the relevant AI Service Providers.

Automated decision-making and safeguards

Where we use AI Products to make a decision about you based solely on automated processing (that is, without meaningful human involvement) and that decision produces a legal effect for you or similarly significantly affects you (a 'significant decision'), we will comply with the requirements of the UK GDPR (Articles 22A to 22D) and, where applicable, the EU GDPR.

In those circumstances we will put appropriate safeguards in place, including:

  • providing you with information about decisions that have been, or will be, taken about you on this basis;

  • enabling you to make representations about such decisions;

  • enabling you to obtain meaningful human intervention from us; and

  • enabling you to contest such decisions.

We do not make significant decisions based solely on automated processing of special category (sensitive) personal data unless we have your explicit consent or another lawful condition applies. Routine, non-significant automated record-keeping (such as account lifecycle staging and a contact-frequency count) does not amount to this kind of decision-making.

How to Opt Out

To opt out, you can contact our support team at https://support.oneclickcomply.com.

7. IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?

In Short: We may transfer, store, and process your information in countries other than your own.

We are based in the United Kingdom, and a number of the subprocessors listed in section 4 process personal data outside the United Kingdom and the European Economic Area (EEA), including in the United States. If you are accessing our Services from outside these areas, please be aware that your information may be transferred to, stored by, and processed by us and our subprocessors in those countries.

Where we transfer personal data internationally, we do so under appropriate safeguards. For transfers from the UK, we rely on UK adequacy regulations where they apply, or on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the European Commission's Standard Contractual Clauses, and we have regard to the data protection test under the UK GDPR. Where a recipient in the United States is certified under the UK Extension to the EU-US Data Privacy Framework, we may rely on that framework (the UK-US 'data bridge') as the transfer mechanism for transfers to that recipient. For transfers from the EEA, we use the European Commission's Standard Contractual Clauses. These mechanisms require the recipient to protect the personal information they process in accordance with applicable data protection law. Details of the safeguards we apply can be provided on request.

8. HOW LONG DO WE KEEP YOUR INFORMATION?

In Short: We keep your information for as long as necessary to fulfil the purposes outlined in this Privacy Notice unless otherwise required by law.

We retain your personal information for the duration of your contract and for a period of up to seven (7) years afterwards, in line with our retention policy and our legal, accounting, tax, and limitation-period obligations. We may retain certain information for a longer period where required or permitted by law.

Different categories of personal information may be kept for different periods within this overall limit. For example, where you opt out of marketing we stop using your information for that purpose promptly, while we retain account, transaction, and tax records for the period our legal and accounting obligations require.

When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymise it, or, if this is not possible (for example because it has been stored in backup archives), then we will securely store it and isolate it from any further processing until deletion is possible.

9. HOW DO WE KEEP YOUR INFORMATION SAFE?

In Short: We aim to protect your personal information through a system of organisational and technical security measures.

We have implemented appropriate and reasonable technical and organisational security measures designed to protect the security of any personal information we process, including encryption of data in transit and at rest, access controls, application-layer security monitoring, and malware scanning of uploaded files. However, despite our safeguards, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorised third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. Although we will do our best to protect your personal information, transmission of personal information to and from our Services is at your own risk. You should only access the Services within a secure environment.

10. DO WE COLLECT INFORMATION FROM MINORS?

In Short: We do not knowingly collect data from or market to children under 18 years of age.

We do not knowingly collect, solicit data from, or market to children under 18 years of age, nor do we knowingly sell such personal information. By using the Services, you represent that you are at least 18 or that you are the parent or guardian of such a minor and consent to such minor dependent's use of the Services. Where any part of our Services is likely to be accessed by children, we have regard to children's higher protection matters under the UK GDPR and the ICO's Age Appropriate Design Code. If we learn that personal information from users under 18 years of age has been collected, we will deactivate the account and take reasonable measures to promptly delete such data. If you become aware of any data we may have collected from children under 18, please contact us at privacy@oneclickcomply.com.

11. WHAT ARE YOUR PRIVACY RIGHTS?

In Short: Depending on your location, you have rights that allow you greater access to and control over your personal information.

In some regions (like the EEA, UK, Switzerland, and Canada), you have certain rights under applicable data protection laws. These may include the right (i) to request access and obtain a copy of your personal information; (ii) to request rectification or erasure; (iii) to restrict the processing of your personal information; (iv) where applicable, to data portability; (v) to object to processing carried out on the basis of our legitimate interests; and (vi) to make a data protection complaint. You can make such a request by contacting us using the details in section 15.

We will consider and act upon any request in accordance with applicable data protection laws. Where we need to verify your identity or clarify the scope of your request, we may pause the time limit for responding until we have received the information we need from you. Our response will be based on a reasonable and proportionate search for the personal information covered by your request.

Rights relating to automated decision-making. If you are located in the UK, where we make a significant decision about you based solely on automated processing, you have the right to be given information about the decision, to make representations about it, to obtain meaningful human intervention, and to contest the decision (see 'Automated decision-making and safeguards' in section 6). If you are located in the EEA or Switzerland, you have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you, except where permitted by law.

Making a data protection complaint to us. You have the right to complain to us directly if you are unhappy with how we have handled your personal information. You can make a complaint by:

  • emailing us at privacy@oneclickcomply.com;

  • writing to our privacy team at the postal address in section 15; or

  • submitting a request at https://app.prighter.com/dsr/12516138869.

We will accept your complaint however you choose to send it. We will acknowledge your complaint within 30 days of receiving it, investigate it and respond without undue delay, and keep you informed of progress and the outcome. We may ask you for further information, such as a reference number or proof of identity, where this is needed to investigate your complaint.

Complaining to a regulator. Making a complaint to us does not affect your right to complain to a data protection regulator, but we would encourage you to contact us first so we can try to resolve the matter.

  • If you are located in the UK, you can complain to the Information Commissioner's Office (ICO) via https://ico.org.uk or its helpline on 0303 123 1113.

  • If you are located in the EEA, you can complain to your Member State data protection authority.

  • If you are located in Switzerland, you may contact the Federal Data Protection and Information Commissioner.

Withdrawing your consent. If we are relying on your consent to process your personal information, you have the right to withdraw your consent at any time by contacting us using the details in section 15. This will not affect the lawfulness of processing before its withdrawal, nor processing conducted in reliance on lawful grounds other than consent.

Opting out of marketing. You can unsubscribe from our marketing communications at any time by clicking the unsubscribe link in our emails, or by contacting us. We may still send you service-related messages necessary for the administration and use of your account.

Account Information

If you would like to review or change the information in your account or terminate your account, you can contact us via https://support.oneclickcomply.com. Upon your request to terminate your account, we will deactivate or delete your account and information from our active databases. However, we may retain some information to prevent fraud, troubleshoot problems, assist with investigations, enforce our legal terms, and/or comply with applicable legal requirements.

Cookies. Most web browsers accept cookies by default. You can usually set your browser to remove or reject cookies, though this could affect certain features of our Services.

If you have questions or comments about your privacy rights, you may email us at privacy@oneclickcomply.com.

12. CONTROLS FOR DO-NOT-TRACK FEATURES

Most web browsers and some mobile operating systems and applications include a Do-Not-Track ('DNT') feature you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. As no uniform technology standard for recognising and implementing DNT signals has been finalised, we do not currently respond to DNT browser signals. If a standard is adopted that we must follow in the future, we will inform you in a revised version of this Privacy Notice.

Opt-out preference signals. Although we do not currently respond to Do-Not-Track signals as described above, where required by applicable US state law we honour recognised opt-out preference signals, such as the Global Privacy Control (GPC), as a valid request to opt out of the sale or sharing of personal information and of targeted advertising for the browser or device on which the signal is received. You can also make these choices using the 'Do Not Sell or Share My Personal Information' link on our website, or by contacting us.

13. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?

In Short: If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah, or Virginia, you may have specific rights regarding your personal information.

Categories of Personal Information We Collect

We have collected the following categories of personal information in the past twelve (12) months:

CategoryExamplesCollected

A. Identifiers

Contact details, such as real name, alias, postal address, telephone or mobile contact number, unique personal identifier, online identifier, Internet Protocol address, email address, and account name

YES

B. Personal information as defined in the California Customer Records statute

Name, contact information, education, employment, employment history, and financial information

YES

C. Protected classification characteristics under state or federal law

Gender, age, date of birth, race and ethnicity, national origin, marital status, and other demographic data

NO

D. Commercial information

Transaction information, purchase history, financial details, and payment information

YES

E. Biometric information

Fingerprints and voiceprints

NO

F. Internet or other similar network activity

Browsing history, search history, online behaviour, interest data, and interactions with our and other websites, applications, systems, and advertisements

YES

G. Geolocation data

Approximate device location (derived from IP address)

YES

H. Audio, electronic, sensory, or similar information

Images and audio, video or call recordings created in connection with our business activities

YES

I. Professional or employment-related information

Business contact details, job title, work history, and professional qualifications

YES

J. Education Information

Student records and directory information

NO

K. Inferences drawn from collected personal information

Inferences drawn from any of the collected personal information listed above to create a profile or summary

YES

L. Sensitive personal Information

NO

We may also collect other personal information outside of these categories where you interact with us in person, online, or by phone or mail.

Your Rights

You have rights under certain US state data protection laws, which are not absolute and may be limited by law. These include the right to know whether we are processing your personal data; to access it; to correct inaccuracies; to request deletion; to obtain a copy; to non-discrimination for exercising your rights; and to opt out of processing for targeted advertising, the sale of personal data, or profiling that produces legal or similarly significant effects.

Depending on your state, you may also have the right to access the categories of personal data being processed; to obtain a list of the categories or specific third parties to which we have disclosed personal data; to review, understand, question, and correct how personal data has been profiled; and to limit the use and disclosure of sensitive personal data.

How to Exercise Your Rights

To exercise these rights, you can contact us by visiting https://app.prighter.com/dsr/12516138869, or by referring to the contact details in section 15. You can designate an authorised agent to make a request on your behalf, subject to proof of valid authorisation.

Request Verification

Upon receiving your request, we will need to verify your identity. We will only use personal information provided in your request to verify your identity or authority to make the request. If we cannot verify your identity from the information already maintained by us, we may request additional information for verification and security purposes.

Appeals

If we decline to take action regarding your request, you may appeal our decision by emailing us at privacy@oneclickcomply.com. If your appeal is denied, you may submit a complaint to your state attorney general.

California 'Shine The Light' Law

California Civil Code Section 1798.83 permits our users who are California residents to request, once a year and free of charge, information about categories of personal information we disclosed to third parties for direct marketing purposes and the names and addresses of those third parties. To make such a request, please contact us using the details in section 15.

14. DO WE MAKE UPDATES TO THIS NOTICE?

In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws.

We may update this Privacy Notice from time to time. The updated version will be indicated by an updated 'Last updated' date at the top of this Privacy Notice. If we make material changes to this Privacy Notice, we will notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this Privacy Notice frequently.

15. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?

If you have questions or comments about this notice, or you wish to exercise your rights, you may contact our privacy team by email at privacy@oneclickcomply.com, or by post at:

Privacy Team
OneClickComply
The Commissioner's Building
Sunderland, SR1 1NW
England

Our registered office is:

FAT32 LTD
69 Church Way
North Shields, Tyne and Wear, NE29 0AE
England

If you are a resident in the European Economic Area or Switzerland, we are the 'data controller' of your personal information. We have appointed Maetzler Rechtsanwalts GmbH & Co KG to be our representative in the EEA and Switzerland. You can contact them directly regarding our processing of your information by visiting https://app.prighter.com/dsr/12516138869, or by post to:

c/o FAT32 Limited
Kriegerstraße 44
Hannover 30161
Germany

16. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

Based on the applicable laws of your country or state of residence, you may have the right to request access to the personal information we collect from you, details about how we have processed it, correct inaccuracies, or delete your personal information. You may also have the right to withdraw your consent to our processing of your personal information. These rights may be limited in some circumstances by applicable law. To request to review, update, or delete your personal information, please visit: https://app.prighter.com/dsr/12516138869.