Version: 1.0
Effective Date: 14 May 2021
Company: D Fine Tech Ltd.
Company Number: 13396727
Jurisdiction: England & Wales
D Fine Tech Ltd. ("D Fine Tech", "we", "our", or "us") recognises that the privacy and protection of personal information are fundamental rights.
This Privacy Policy explains in detail how we collect, use, store, disclose, transfer, secure and otherwise process personal information in connection with our business operations, including:
This Privacy Policy has been drafted to comply with:
We are committed to ensuring that every item of personal information entrusted to us is processed lawfully, fairly, transparently and securely.
Privacy is integrated into our governance, software development lifecycle and organisational culture.
Accordingly, D Fine Tech implements:
Where we process personal information on behalf of customers, we do so strictly in accordance with contractual instructions and applicable law.
This Privacy Policy applies to personal information collected through:
Depending upon the circumstances, D Fine Tech may act as:
(a) Data Controller
We determine the purposes and means of processing personal information.
Examples include:
(b) Data Processor
Where we develop or host software for customers, we may process personal information solely on their documented instructions.
In these situations, the customer remains responsible for determining:
This Privacy Policy applies to processing activities relating to:
This Privacy Policy governs all processing activities undertaken by D Fine Tech unless an alternative privacy notice is specifically provided.
It applies regardless of whether information is collected:
This Policy covers both online and offline processing.
For the purposes of this Privacy Policy, unless the context otherwise requires:
"Applicable Privacy Laws" means all legislation, regulations and binding guidance governing privacy, data protection and personal information, including the UK GDPR, Data Protection Act 2018 and Australian Privacy Act 1988.
"Artificial Intelligence" means machine learning, generative AI, large language models, predictive analytics, neural networks, automated reasoning, recommendation engines and similar computational technologies capable of producing outputs based upon supplied information.
"Consent" means any freely given, specific, informed and unambiguous indication of an individual's wishes by which they signify agreement to the processing of personal information.
"Customer" means any organisation or individual purchasing or receiving services from D Fine Tech.
"Data Controller" has the meaning given under the UK GDPR and refers to the entity determining the purposes and means of processing personal information.
"Data Processor" means a person or organisation processing personal information on behalf of a Data Controller.
"Personal Data" or "Personal Information" means any information relating to an identified or identifiable natural person, whether directly or indirectly identifiable.
Examples include:
"Processing" means any operation performed on personal information including:
"Sensitive Personal Information" means special category data under UK GDPR and sensitive information under the Australian Privacy Act, including information concerning:
D Fine Tech maintains privacy governance designed to satisfy applicable legal obligations across multiple jurisdictions.
Our privacy management programme is built upon the following core legislative frameworks.
Where UK law applies, we process personal information in accordance with:
Where Australian law applies, we process personal information consistently with:
Our internal governance also reflects recognised privacy principles including:
Every processing activity undertaken by D Fine Tech is guided by the following principles.
We only process personal information where an appropriate lawful basis exists.
We process information in ways individuals would reasonably expect and avoid unjustified adverse impacts.
We explain our processing activities through clear privacy notices and contractual documentation.
Information is collected only for specified, explicit and legitimate purposes and is not further processed incompatibly with those purposes.
We seek to collect only information reasonably necessary for identified business purposes.
Reasonable steps are taken to maintain accurate and current records.
Personal information is retained only for as long as necessary to satisfy legal, contractual and operational obligations.
Appropriate technical and organisational safeguards are implemented to protect information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
D Fine Tech maintains governance structures demonstrating compliance with applicable privacy obligations.
For the purposes of the UK General Data Protection Regulation, the Data Protection Act 2018, and, where applicable, the Australian Privacy Act 1988 (Cth), the data controller responsible for the processing of personal information described in this Privacy Policy is:
D Fine Tech Ltd.
Company Number: 13396727
Registered in England and Wales.
Unless otherwise stated, references to "D Fine Tech", "we", "our" or "us" throughout this Privacy Policy refer to D Fine Tech Ltd.
For many software development and technology services, D Fine Tech processes personal information solely on behalf of customers.
Examples include:
In such circumstances:
Where acting as a processor, D Fine Tech:
In limited circumstances, D Fine Tech may jointly determine the purposes and means of processing together with another organisation.
Where joint controllership exists, responsibilities will be allocated contractually, and information regarding the essence of that arrangement will be made available where required by law.
The categories of personal information processed depend upon the nature of our relationship with you and the services provided.
We do not intentionally collect information unrelated to legitimate business purposes.
We may collect:
This may include:
For customers and suppliers we may process:
Where individuals access customer portals or online services we may process:
Passwords are stored only in encrypted or cryptographically hashed form using recognised industry standards.
Our systems may automatically collect:
Including:
Including:
We may process:
Where required we may process:
Payment card details are ordinarily processed directly by authorised payment providers and are not retained by D Fine Tech except where necessary for lawful accounting purposes.
Applicants may provide:
Including:
We do not routinely collect special category or sensitive personal information.
However, limited sensitive information may be processed where:
Such information receives enhanced protection.
Personal information may be collected directly from individuals or indirectly through lawful sources.
Individuals may provide personal information when:
Certain technical information is collected automatically through:
Where acting as a processor we receive information from customers using:
We may receive information from:
Information may also be obtained from publicly available sources including:
Only information relevant to legitimate business activities is collected.
Where UK GDPR applies, every processing activity is supported by an appropriate lawful basis.
Processing is necessary to:
We may process personal information where necessary for our legitimate interests provided those interests are not overridden by individuals' rights.
Examples include:
Prior to relying upon legitimate interests we consider:
Processing may be necessary to comply with:
Consent may be relied upon for:
Where consent is relied upon it may be withdrawn at any time without affecting prior lawful processing.
In exceptional circumstances processing may be necessary to protect the life or physical safety of an individual.
Where relevant, information may be processed where necessary for tasks carried out in the public interest or under official authority.
We process personal information only where necessary for identified business purposes.
Personal information may be used to:
Including:
Including:
Personal information may be processed to:
We analyse usage information to improve:
Analytics are designed wherever reasonably practicable to minimise the use of directly identifiable personal information.
We communicate with individuals regarding:
Operational communications may continue even where marketing communications have been declined where such communications are necessary for contractual or legal purposes.
Applicant information is processed for:
We may process information to:
D Fine Tech recognises that individuals have important rights in relation to decisions made solely by automated means. We are committed to ensuring that any use of automated processing is lawful, transparent, proportionate and subject to appropriate safeguards.
We do not ordinarily make decisions that produce legal effects concerning individuals, or similarly significant effects, based solely on automated processing.
Examples of significant decisions include decisions relating to:
Where such processing is introduced in the future, it will only occur where permitted by applicable law and supported by appropriate safeguards.
Our systems may use automated technologies for routine operational purposes, including:
These activities are intended to protect the integrity, confidentiality and availability of our systems and do not ordinarily produce legal or similarly significant effects on individuals.
Where automated tools are used to support business decisions, appropriate human oversight is maintained. Personnel responsible for reviewing automated outputs are expected to consider:
Where UK GDPR applies and an individual is subject to a qualifying automated decision, they may have the right to:
Requests relating to automated decision-making should be submitted using the contact details provided in Section 29.
As a technology company, D Fine Tech may design, develop, integrate or support artificial intelligence ("AI") systems as part of its services. We are committed to the responsible, lawful and ethical use of AI technologies and seek to ensure that their deployment aligns with applicable privacy legislation and recognised industry standards.
Our approach to AI is guided by the principles of:
Depending on the nature of the services provided, AI technologies may be used for purposes including:
Where AI systems process customer data, D Fine Tech will do so in accordance with contractual obligations and applicable privacy legislation.
Where D Fine Tech processes customer information through AI-enabled systems while acting as a data processor, such processing will be undertaken only:
Customers remain responsible for determining whether AI processing is appropriate for their own data processing activities.
Where AI systems are used, we seek to minimise the volume of personal information processed by:
Unless expressly agreed in writing with a customer, D Fine Tech does not use customer confidential information or customer personal information to train publicly available foundation models or publicly accessible generative AI systems.
Where AI models are developed internally for specific customer solutions, the applicable contractual documentation will govern ownership, usage rights and permitted processing.
Our AI governance programme may include:
Where individuals interact directly with AI-enabled services operated by D Fine Tech, we seek, where reasonably practicable, to provide appropriate information regarding the nature of such interactions.
Our websites, portals and online services use cookies and similar technologies to improve functionality, enhance user experience, protect security and analyse website performance.
Cookies are small text files stored on a user's device that enable websites to recognise browsers and retain certain information.
We may use the following categories of cookies.
Strictly Necessary Cookies
These cookies are essential for the operation of our website and cannot ordinarily be disabled.
They may be used for:
Functional Cookies
These cookies enable enhanced functionality, including:
Analytics Cookies
Analytics technologies help us understand how visitors interact with our website.
Information collected may include:
Where reasonably practicable, analytics information is aggregated or pseudonymised.
Performance Cookies
Performance cookies assist in measuring and improving:
Marketing Cookies
Where used, marketing cookies may support:
Marketing cookies will generally be deployed only where legally required consent has been obtained.
Where required by applicable law, users will be presented with an appropriate cookie consent mechanism enabling them to:
Withdrawal of consent does not affect the lawfulness of prior processing.
Most web browsers permit users to manage cookies through browser settings.
Users may generally:
Disabling cookies may reduce website functionality.
We may also use technologies including:
where permitted by applicable law.
We may communicate with existing customers regarding:
These communications are generally necessary for the performance of our contractual relationship or our legitimate interests.
Subject to applicable law, we may send:
Marketing communications will only be sent where permitted by law.
Recipients may unsubscribe from marketing communications at any time by:
Opting out of marketing does not prevent operational communications necessary for service delivery.
Where consent is required for marketing activities, we maintain records demonstrating:
As a technology company providing services to customers in multiple jurisdictions, personal information may be transferred internationally where necessary for legitimate business purposes.
Such transfers may occur:
Where personal information is transferred outside the United Kingdom or Australia, we implement appropriate safeguards designed to ensure that transferred information continues to receive an appropriate level of protection.
Safeguards may include:
Where appropriate, D Fine Tech may undertake transfer risk assessments considering:
Where cloud infrastructure is utilised, customer information may be stored or processed within data centres operated by reputable cloud service providers.
Where customers require data residency within a specific jurisdiction, this will be addressed contractually where commercially and technically feasible.
Where Australian personal information is disclosed overseas, D Fine Tech seeks to ensure that overseas recipients handle such information consistently with applicable Australian Privacy Principles or equivalent contractual protections.
We do not sell personal information.
Personal information is disclosed only where necessary for legitimate business purposes, legal compliance or with appropriate authority.
We may disclose information to carefully selected service providers supporting our operations, including providers of:
All service providers are expected to protect personal information through appropriate contractual and security obligations.
Information may be disclosed where necessary to:
Such disclosures occur only where reasonably necessary.
Where operationally necessary, personal information may be disclosed within the D Fine Tech corporate group (including future subsidiaries or affiliated entities) for legitimate internal administrative purposes, including:
Any such disclosures will be subject to appropriate confidentiality and security obligations.
We may disclose personal information where required or authorised by law, including to:
We will take reasonable steps to verify the legitimacy and scope of any request before disclosing personal information, unless prohibited by law.
Personal information may be disclosed where reasonably necessary to:
If D Fine Tech undergoes or proposes a:
personal information may be disclosed to prospective purchasers, investors, advisers or counterparties, provided appropriate confidentiality obligations are in place.
Where required by applicable law, affected individuals will be notified of any material changes affecting the processing of their personal information.
Where D Fine Tech acts solely as a data processor, we disclose personal information only:
Some approved service providers may operate internationally.
Where personal information is disclosed to overseas recipients, we implement appropriate safeguards as described in Section 15.
D Fine Tech does not:
Protecting personal information is fundamental to our business operations.
D Fine Tech maintains technical and organisational measures designed to safeguard personal information against:
No security programme can guarantee absolute security. However, we continuously review and improve our controls to address evolving risks.
Our information security programme is based upon recognised security principles and includes governance measures relating to:
Depending on the nature of the services provided, our technical controls may include:
Organisational safeguards may include:
Access to personal information is limited to personnel who require access for legitimate business purposes.
Access permissions are granted according to the principles of:
Access rights are periodically reviewed and updated.
As a software development company, D Fine Tech seeks to integrate security throughout the software development lifecycle, including:
Security incidents are managed using documented procedures designed to:
Customers also play an important role in protecting information.
Customers are responsible for maintaining appropriate security over:
We retain personal information only for as long as reasonably necessary to fulfil:
Once information is no longer required, it will be securely deleted, anonymised or otherwise disposed of in accordance with our retention procedures.
Retention periods are determined having regard to:
Where information reaches the end of its retention period, D Fine Tech will, where appropriate:
The following retention periods are indicative and may be extended where required by law, regulatory obligation, litigation hold or legitimate business necessity.
| Category | Typical Retention Period |
|---|---|
| Customer contracts | 7 years after termination |
| Customer account records | 7 years after account closure |
| Project documentation | 7 years after project completion |
| Financial records | 7 years |
| Tax records | 7 years or longer where legally required |
| Supplier contracts | 7 years after termination |
| Marketing consent records | Duration of consent plus 6 years |
| Recruitment records (unsuccessful applicants) | Up to 12 months unless longer retention is authorised |
| Employee records | In accordance with employment law requirements |
| Security logs | Typically 12–24 months depending on operational requirements |
| Website analytics | Generally up to 26 months unless anonymised earlier |
| Technical support records | Up to 7 years after closure where operationally necessary |
| Backup media | Managed in accordance with documented backup retention schedules |
Where D Fine Tech acts solely as a processor, retention periods are primarily determined by the customer.
Subject to applicable law and any relevant exemptions, individuals may exercise the following rights.
Individuals have the right to receive clear information regarding how their personal information is processed.
This Privacy Policy forms part of that commitment.
Individuals may request confirmation of whether we process their personal information and, where applicable, obtain:
Individuals may request correction of inaccurate or incomplete personal information.
We may request reasonable evidence before making changes.
Individuals may request deletion of personal information where:
This right is not absolute and may be restricted where continued processing is required by law or for the establishment, exercise or defence of legal claims.
Individuals may request restriction of processing under circumstances provided by applicable law, including where:
Where applicable, individuals may request that personal information they have provided be supplied:
Individuals may object to processing carried out on the basis of legitimate interests or public interest.
Where an objection is received, D Fine Tech will consider whether compelling legitimate grounds override the individual's interests, rights and freedoms.
Individuals may object to direct marketing at any time.
Where applicable, individuals may request:
Requests should include sufficient information to enable identification of the requester.
Reasonable identity verification measures may be required before information is disclosed.
We will respond within the applicable statutory timeframes unless an extension is permitted by law.
Where the Australian Privacy Act 1988 (Cth) applies to our processing activities, D Fine Tech manages personal information in accordance with the Australian Privacy Principles ("APPs").
Individuals located in Australia, or whose personal information is processed under Australian privacy law, may exercise the rights described in this section in addition to any rights available under other applicable legislation.
Individuals may request access to personal information held by D Fine Tech.
Subject to applicable legal exceptions, we will provide access within a reasonable period after receiving the request and verifying the requester's identity.
Access may be refused where permitted by the Privacy Act 1988, including where disclosure would:
Where access cannot be provided, we will generally explain the reasons unless prohibited by law.
If an individual believes that personal information is inaccurate, incomplete, misleading or out of date, they may request correction.
Where appropriate, D Fine Tech will:
Individuals who believe that D Fine Tech has breached the Australian Privacy Principles may submit a complaint using the procedures described in Section 27.
Where a complaint cannot be resolved internally, individuals may contact the Office of the Australian Information Commissioner (OAIC).
Where Australian personal information is transferred overseas, D Fine Tech seeks to ensure that overseas recipients provide a level of protection consistent with applicable Australian privacy requirements through appropriate contractual, organisational and technical safeguards.
D Fine Tech's services are designed primarily for businesses, organisations and professionals.
Our services are not intentionally directed towards children.
We do not knowingly collect personal information directly from children except where:
Where we become aware that personal information has been collected from a child without appropriate legal authority, we will take reasonable steps to delete that information unless retention is required by law.
Customers using D Fine Tech software to process children's personal information remain responsible for ensuring that they have an appropriate lawful basis and all required notices, consents and safeguards under applicable legislation.
Our websites, communications or applications may contain links to third-party websites, services or applications.
These external services operate independently from D Fine Tech and maintain their own privacy practices.
We encourage individuals to review the privacy policies of any third-party websites before providing personal information.
Depending on customer requirements, software solutions developed by D Fine Tech may integrate with third-party platforms including:
The privacy practices of those third parties are governed by their own policies and contractual arrangements.
Where individuals interact with D Fine Tech through social media platforms, personal information may also be processed by the relevant platform operator under its own privacy policy.
Personal information submitted during recruitment may be processed for purposes including:
Recruitment information may be processed on the basis of:
Where lawful and appropriate, D Fine Tech may conduct background verification, including:
Background checks will be proportionate to the relevant role and conducted in accordance with applicable law.
Recruitment information will generally be retained only for the period reasonably necessary for recruitment purposes and any subsequent legal obligations, after which it will be securely deleted unless longer retention is authorised by the applicant or required by law.
D Fine Tech processes personal information relating to suppliers, contractors and business partners for purposes including:
We may conduct reasonable due diligence regarding suppliers to assess:
Supplier information may be retained for the duration of contractual relationships and applicable statutory retention periods.
Personal information may be included within secure backup systems and disaster recovery environments to ensure continuity of services.
Such backup information is protected using appropriate security controls and is retained in accordance with documented retention procedures.
In the event of:
personal information may be transferred to successor organisations where permitted by applicable law and subject to appropriate confidentiality and privacy protections.
D Fine Tech maintains documented procedures for responding to actual or suspected personal data breaches.
These procedures are designed to:
Where required by applicable law, D Fine Tech will notify:
within applicable legal timeframes where a personal data breach is likely to result in a risk to the rights and freedoms of individuals.
We maintain records of security incidents and personal data breaches in accordance with our legal and governance obligations, including:
Individuals who have questions, concerns or complaints regarding this Privacy Policy or our handling of personal information are encouraged to contact D Fine Tech first so that we may investigate and seek to resolve the matter promptly.
Complaints should include:
We will acknowledge receipt of complaints and investigate them fairly, impartially and within a reasonable timeframe.
Where additional information is required, we may contact the complainant during the investigation.
Individuals located within the United Kingdom who remain dissatisfied may have the right to lodge a complaint with the Information Commissioner's Office (ICO).
Nothing in this Privacy Policy limits any statutory rights available under applicable law.
Individuals located in Australia may also refer unresolved complaints to the Office of the Australian Information Commissioner (OAIC) where appropriate.
D Fine Tech may amend this Privacy Policy from time to time to reflect:
Where material changes are made, we will take reasonable steps to notify affected individuals where required by applicable law.
The revised Privacy Policy will supersede previous versions from its stated effective date.
Questions regarding this Privacy Policy or requests relating to personal information may be directed to D Fine Tech Ltd.
D Fine Tech Ltd.
Company Number: 13396727
England and Wales
Requests relating to:
should be submitted in writing using the contact details published on D Fine Tech's official website or otherwise provided through contractual communications. Our published contact details are available on our Contact Us page.
D Fine Tech will respond in accordance with applicable legal requirements.
The following table summarises the principal categories of personal information processed by D Fine Tech.
| Category | Examples |
|---|---|
| Identity Information | Name, title, employee ID, customer ID |
| Contact Information | Address, email, telephone number |
| Business Information | Employer, role, department |
| Account Information | Username, authentication records |
| Financial Information | Invoices, payment references, supplier banking details |
| Technical Information | IP address, browser, operating system |
| Device Information | Device ID, hardware model, diagnostics |
| Usage Information | Website interactions, application logs |
| Communications | Emails, support tickets, meeting records |
| Recruitment Information | CVs, references, qualifications |
| Marketing Preferences | Subscription status, consent records |
| Security Information | Audit logs, authentication logs, access records |
| Record Category | Standard Retention |
|---|---|
| Customer contracts | 7 years after expiry or termination |
| Project documentation | 7 years |
| Software development records | 7 years |
| Customer correspondence | 7 years |
| Technical support records | 7 years |
| Financial records | 7 years or longer if legally required |
| Tax records | In accordance with applicable tax legislation |
| Recruitment records (unsuccessful) | Up to 12 months |
| Employee records | In accordance with employment legislation |
| Security logs | 12–24 months |
| Website analytics | Up to 26 months unless anonymised |
| Marketing consent records | Duration of consent plus 6 years |
| Supplier records | 7 years after contract termination |
| Disaster recovery backups | In accordance with documented backup schedules |
Retention periods may be extended where required by litigation holds, regulatory investigations or other legal obligations.
| Cookie Category | Purpose |
|---|---|
| Strictly Necessary | Authentication, security, website functionality |
| Functional | Preferences, accessibility, language settings |
| Analytics | Website usage analysis and performance measurement |
| Performance | Optimisation and reliability |
| Marketing | Advertising and campaign measurement where consented |
Where international transfers occur, D Fine Tech may rely on one or more of the following safeguards:
Upon receipt of a valid privacy request, D Fine Tech will generally:
Where D Fine Tech acts solely as a data processor, requests relating to customer data may be referred to the relevant customer (the data controller), unless otherwise agreed contractually.
END OF PRIVACY POLICY
© 2020 Copyright