D Fine Tech Ltd.

Version: 1.0
Effective Date: 14 May 2021
Company: D Fine Tech Ltd.
Company Number: 13396727
Jurisdiction: England & Wales

Table of Contents
1. Introduction
1.1 Purpose

D Fine Tech Ltd. ("D Fine Tech", "we", "our", or "us") recognises that the privacy and protection of personal information are fundamental rights.

This Privacy Policy explains in detail how we collect, use, store, disclose, transfer, secure and otherwise process personal information in connection with our business operations, including:

  • custom software development;
  • software engineering;
  • cloud application development;
  • mobile application development;
  • web application development;
  • systems integration;
  • application support;
  • managed technology services;
  • consulting services;
  • technical support;
  • cybersecurity services;
  • artificial intelligence development;
  • software maintenance;
  • project management;
  • business communications;
  • recruitment;
  • supplier management; and
  • operation of our websites and digital services.

This Privacy Policy has been drafted to comply with:

  • the UK General Data Protection Regulation ("UK GDPR");
  • the Data Protection Act 2018;
  • the Privacy and Electronic Communications Regulations 2003 (where applicable);
  • the Australian Privacy Act 1988;
  • the Australian Privacy Principles ("APPs"); and
  • recognised international privacy governance standards.

We are committed to ensuring that every item of personal information entrusted to us is processed lawfully, fairly, transparently and securely.

1.2 Commitment to Privacy

Privacy is integrated into our governance, software development lifecycle and organisational culture.

Accordingly, D Fine Tech implements:

  • privacy by design;
  • privacy by default;
  • secure software development practices;
  • encryption standards;
  • access control procedures;
  • security monitoring;
  • contractual confidentiality obligations;
  • employee privacy training;
  • incident response procedures;
  • vendor due diligence;
  • risk assessments;
  • data minimisation practices;
  • retention controls; and
  • governance measures designed to protect personal information throughout its lifecycle.

Where we process personal information on behalf of customers, we do so strictly in accordance with contractual instructions and applicable law.

1.3 Scope

This Privacy Policy applies to personal information collected through:

  • our corporate website;
  • customer portals;
  • software applications;
  • mobile applications;
  • cloud-hosted services;
  • technical support systems;
  • helpdesk platforms;
  • project management platforms;
  • customer relationship management systems;
  • recruitment systems;
  • email communications;
  • telephone communications;
  • video conferencing;
  • sales enquiries;
  • marketing activities;
  • supplier relationships;
  • contractual engagements;
  • social media interactions;
  • events;
  • webinars;
  • demonstrations;
  • training services;
  • cookies;
  • analytics technologies; and
  • any other interaction with D Fine Tech.
1.4 Processing Roles

Depending upon the circumstances, D Fine Tech may act as:

(a) Data Controller

We determine the purposes and means of processing personal information.

Examples include:

  • recruitment;
  • marketing;
  • customer management;
  • supplier administration;
  • website operation;
  • employee administration.

(b) Data Processor

Where we develop or host software for customers, we may process personal information solely on their documented instructions.

In these situations, the customer remains responsible for determining:

  • why personal information is processed;
  • what information is collected;
  • applicable retention periods;
  • legal basis;
  • responses to data subject requests.
1.5 Territorial Application

This Privacy Policy applies to processing activities relating to:

  • individuals located within the United Kingdom;
  • customers in Australia;
  • individuals whose personal information is processed in connection with services provided by D Fine Tech;
  • website visitors worldwide;
  • prospective customers;
  • suppliers;
  • contractors;
  • business representatives; and
  • job applicants.
2. Scope of this Privacy Policy

This Privacy Policy governs all processing activities undertaken by D Fine Tech unless an alternative privacy notice is specifically provided.

It applies regardless of whether information is collected:

  • electronically;
  • verbally;
  • in writing;
  • automatically;
  • directly from individuals;
  • from authorised representatives;
  • from customers;
  • from publicly available sources;
  • through third parties lawfully entitled to disclose such information.

This Policy covers both online and offline processing.

3. Definitions

For the purposes of this Privacy Policy, unless the context otherwise requires:

"Applicable Privacy Laws" means all legislation, regulations and binding guidance governing privacy, data protection and personal information, including the UK GDPR, Data Protection Act 2018 and Australian Privacy Act 1988.

"Artificial Intelligence" means machine learning, generative AI, large language models, predictive analytics, neural networks, automated reasoning, recommendation engines and similar computational technologies capable of producing outputs based upon supplied information.

"Consent" means any freely given, specific, informed and unambiguous indication of an individual's wishes by which they signify agreement to the processing of personal information.

"Customer" means any organisation or individual purchasing or receiving services from D Fine Tech.

"Data Controller" has the meaning given under the UK GDPR and refers to the entity determining the purposes and means of processing personal information.

"Data Processor" means a person or organisation processing personal information on behalf of a Data Controller.

"Personal Data" or "Personal Information" means any information relating to an identified or identifiable natural person, whether directly or indirectly identifiable.

Examples include:

  • names;
  • addresses;
  • email addresses;
  • IP addresses;
  • device identifiers;
  • employee IDs;
  • customer identifiers;
  • biometric identifiers;
  • online identifiers;
  • financial details;
  • employment information;
  • technical identifiers.

"Processing" means any operation performed on personal information including:

  • collection;
  • recording;
  • organisation;
  • storage;
  • adaptation;
  • retrieval;
  • consultation;
  • disclosure;
  • transmission;
  • restriction;
  • deletion;
  • destruction.

"Sensitive Personal Information" means special category data under UK GDPR and sensitive information under the Australian Privacy Act, including information concerning:

  • racial or ethnic origin;
  • political opinions;
  • religious beliefs;
  • philosophical beliefs;
  • trade union membership;
  • genetic data;
  • biometric data used for identification;
  • health information;
  • sexual orientation;
  • criminal offence information where applicable by law.
4. Our Regulatory Framework

D Fine Tech maintains privacy governance designed to satisfy applicable legal obligations across multiple jurisdictions.

Our privacy management programme is built upon the following core legislative frameworks.

4.1 United Kingdom

Where UK law applies, we process personal information in accordance with:

  • UK GDPR;
  • Data Protection Act 2018;
  • Privacy and Electronic Communications Regulations;
  • guidance issued by the UK Information Commissioner's Office.
4.2 Australia

Where Australian law applies, we process personal information consistently with:

  • Privacy Act 1988;
  • Australian Privacy Principles;
  • guidance published by the Office of the Australian Information Commissioner (OAIC).
4.3 International Standards

Our internal governance also reflects recognised privacy principles including:

  • accountability;
  • lawfulness;
  • fairness;
  • transparency;
  • purpose limitation;
  • data minimisation;
  • storage limitation;
  • integrity;
  • confidentiality;
  • accuracy; and
  • organisational responsibility.
5. Our Privacy Principles

Every processing activity undertaken by D Fine Tech is guided by the following principles.

Principle 1 — Lawfulness

We only process personal information where an appropriate lawful basis exists.

Principle 2 — Fairness

We process information in ways individuals would reasonably expect and avoid unjustified adverse impacts.

Principle 3 — Transparency

We explain our processing activities through clear privacy notices and contractual documentation.

Principle 4 — Purpose Limitation

Information is collected only for specified, explicit and legitimate purposes and is not further processed incompatibly with those purposes.

Principle 5 — Data Minimisation

We seek to collect only information reasonably necessary for identified business purposes.

Principle 6 — Accuracy

Reasonable steps are taken to maintain accurate and current records.

Principle 7 — Storage Limitation

Personal information is retained only for as long as necessary to satisfy legal, contractual and operational obligations.

Principle 8 — Security

Appropriate technical and organisational safeguards are implemented to protect information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

Principle 9 — Accountability

D Fine Tech maintains governance structures demonstrating compliance with applicable privacy obligations.

6. Identity of the Data Controller
6.1 Data Controller

For the purposes of the UK General Data Protection Regulation, the Data Protection Act 2018, and, where applicable, the Australian Privacy Act 1988 (Cth), the data controller responsible for the processing of personal information described in this Privacy Policy is:

D Fine Tech Ltd.
Company Number: 13396727
Registered in England and Wales.

Unless otherwise stated, references to "D Fine Tech", "we", "our" or "us" throughout this Privacy Policy refer to D Fine Tech Ltd.

6.2 When We Act as a Data Processor

For many software development and technology services, D Fine Tech processes personal information solely on behalf of customers.

Examples include:

  • bespoke software development;
  • Software-as-a-Service platforms developed for customers;
  • cloud hosting environments;
  • managed application support;
  • software maintenance;
  • technical support services;
  • data migration projects;
  • API integrations;
  • application monitoring;
  • quality assurance environments.

In such circumstances:

  • our customer determines the purposes of processing;
  • our customer determines the categories of personal information processed;
  • our customer determines retention requirements;
  • our customer remains responsible for responding to data subject rights requests unless contractually delegated.

Where acting as a processor, D Fine Tech:

  • processes personal information only on documented instructions;
  • ensures personnel are subject to confidentiality obligations;
  • implements appropriate technical and organisational measures;
  • assists customers in complying with applicable privacy legislation where reasonably required;
  • maintains appropriate records of processing activities where legally required;
  • engages sub-processors only in accordance with contractual obligations.
6.3 Joint Controllers

In limited circumstances, D Fine Tech may jointly determine the purposes and means of processing together with another organisation.

Where joint controllership exists, responsibilities will be allocated contractually, and information regarding the essence of that arrangement will be made available where required by law.

7. Categories of Personal Data We Collect

The categories of personal information processed depend upon the nature of our relationship with you and the services provided.

We do not intentionally collect information unrelated to legitimate business purposes.

7.1 Identity Information

We may collect:

  • full name;
  • preferred name;
  • title;
  • gender where voluntarily supplied;
  • date of birth where legally required;
  • employee identification numbers;
  • customer reference numbers;
  • government-issued identification where legally necessary;
  • company registration information for sole traders.
7.2 Contact Information

This may include:

  • residential address;
  • business address;
  • postal address;
  • email address;
  • telephone number;
  • mobile number;
  • emergency contact information where applicable.
7.3 Business Information

For customers and suppliers we may process:

  • employer details;
  • business role;
  • department;
  • job title;
  • company name;
  • VAT or tax identifiers where applicable;
  • business correspondence;
  • contractual information;
  • purchase history.
7.4 Account Information

Where individuals access customer portals or online services we may process:

  • usernames;
  • authentication credentials;
  • encrypted passwords;
  • password reset history;
  • account preferences;
  • security questions where implemented;
  • multi-factor authentication records;
  • account activity logs.

Passwords are stored only in encrypted or cryptographically hashed form using recognised industry standards.

7.5 Technical Information

Our systems may automatically collect:

  • IP address;
  • browser type;
  • browser version;
  • operating system;
  • language settings;
  • screen resolution;
  • referring URLs;
  • time zone;
  • connection logs;
  • diagnostic information;
  • session identifiers;
  • API usage records;
  • application telemetry.
7.6 Device Information

Including:

  • device identifiers;
  • hardware model;
  • mobile operating system;
  • unique device identifiers;
  • crash reports;
  • software versions;
  • network information.
7.7 Usage Information

Including:

  • pages visited;
  • navigation history;
  • clickstream information;
  • session duration;
  • downloads;
  • interactions with our applications;
  • feature usage;
  • system events.
7.8 Communications

We may process:

  • emails;
  • enquiry forms;
  • live chat communications;
  • customer support requests;
  • meeting notes;
  • call recordings where notified;
  • project correspondence;
  • technical tickets.
7.9 Financial Information

Where required we may process:

  • invoicing information;
  • payment references;
  • transaction history;
  • bank account details for supplier payments;
  • tax information;
  • purchase orders.

Payment card details are ordinarily processed directly by authorised payment providers and are not retained by D Fine Tech except where necessary for lawful accounting purposes.

7.10 Recruitment Information

Applicants may provide:

  • curriculum vitae;
  • employment history;
  • qualifications;
  • references;
  • certifications;
  • interview notes;
  • right-to-work documentation;
  • professional memberships.
7.11 Marketing Preferences

Including:

  • communication preferences;
  • subscription status;
  • event registrations;
  • webinar attendance;
  • newsletter preferences;
  • consent records.
7.12 Sensitive Personal Information

We do not routinely collect special category or sensitive personal information.

However, limited sensitive information may be processed where:

  • required by employment law;
  • voluntarily disclosed by an applicant;
  • necessary for accessibility accommodations;
  • legally required;
  • necessary for establishment, exercise or defence of legal claims.

Such information receives enhanced protection.

8. Sources of Personal Data

Personal information may be collected directly from individuals or indirectly through lawful sources.

8.1 Information Provided Directly

Individuals may provide personal information when:

  • requesting quotations;
  • entering into contracts;
  • contacting support;
  • completing forms;
  • subscribing to newsletters;
  • attending webinars;
  • registering accounts;
  • applying for employment;
  • communicating by telephone;
  • corresponding by email.
8.2 Automatically Collected Information

Certain technical information is collected automatically through:

  • server logs;
  • cookies;
  • analytics tools;
  • security monitoring;
  • application telemetry;
  • authentication systems;
  • firewall logs;
  • network monitoring solutions.
8.3 Customer Systems

Where acting as a processor we receive information from customers using:

  • software platforms;
  • APIs;
  • secure uploads;
  • encrypted transfers;
  • database imports;
  • cloud storage;
  • integration services.
8.4 Third Parties

We may receive information from:

  • business partners;
  • recruitment agencies;
  • identity verification providers;
  • professional advisers;
  • publicly available registers;
  • regulatory authorities;
  • credit reference agencies where appropriate.
8.5 Public Sources

Information may also be obtained from publicly available sources including:

  • Companies House;
  • professional networking platforms;
  • business websites;
  • government registers;
  • regulatory publications.

Only information relevant to legitimate business activities is collected.

9. Lawful Bases for Processing

Where UK GDPR applies, every processing activity is supported by an appropriate lawful basis.

9.1 Contract

Processing is necessary to:

  • provide software development services;
  • fulfil contractual obligations;
  • deliver technical support;
  • provide managed services;
  • create customer accounts;
  • process payments;
  • fulfil procurement obligations.
9.2 Legitimate Interests

We may process personal information where necessary for our legitimate interests provided those interests are not overridden by individuals' rights.

Examples include:

  • business administration;
  • fraud prevention;
  • cybersecurity;
  • service improvement;
  • network security;
  • customer relationship management;
  • analytics;
  • internal reporting;
  • product development;
  • legal compliance;
  • enforcing contractual rights.

Prior to relying upon legitimate interests we consider:

  • necessity;
  • proportionality;
  • privacy impact;
  • reasonable expectations;
  • safeguards.
9.3 Legal Obligations

Processing may be necessary to comply with:

  • tax legislation;
  • accounting obligations;
  • employment law;
  • anti-money laundering requirements;
  • court orders;
  • regulatory investigations;
  • statutory reporting obligations.
9.4 Consent

Consent may be relied upon for:

  • certain marketing communications;
  • optional cookies;
  • optional AI functionality where appropriate;
  • photography at events;
  • promotional materials.

Where consent is relied upon it may be withdrawn at any time without affecting prior lawful processing.

9.5 Vital Interests

In exceptional circumstances processing may be necessary to protect the life or physical safety of an individual.

9.6 Public Task

Where relevant, information may be processed where necessary for tasks carried out in the public interest or under official authority.

10. How We Use Personal Information

We process personal information only where necessary for identified business purposes.

10.1 Delivering Services

Personal information may be used to:

  • develop bespoke software;
  • implement software projects;
  • configure cloud environments;
  • deliver managed services;
  • provide technical support;
  • diagnose technical issues;
  • monitor application performance;
  • maintain customer systems.
10.2 Customer Administration

Including:

  • creating customer records;
  • managing contracts;
  • invoicing;
  • billing;
  • payment reconciliation;
  • account management;
  • customer communications.
10.3 Website Administration

Including:

  • website operation;
  • performance monitoring;
  • troubleshooting;
  • security;
  • content optimisation;
  • analytics;
  • fraud detection.
10.4 Information Security

Personal information may be processed to:

  • detect unauthorised access;
  • investigate security incidents;
  • monitor networks;
  • prevent cyberattacks;
  • identify malware;
  • maintain audit logs;
  • preserve system integrity.
10.5 Service Improvement

We analyse usage information to improve:

  • software quality;
  • customer experience;
  • system reliability;
  • application performance;
  • accessibility;
  • documentation;
  • user interface design.

Analytics are designed wherever reasonably practicable to minimise the use of directly identifiable personal information.

10.6 Communications

We communicate with individuals regarding:

  • support tickets;
  • project updates;
  • contractual matters;
  • invoices;
  • product updates;
  • service notifications;
  • security advisories;
  • maintenance windows;
  • legal notices.

Operational communications may continue even where marketing communications have been declined where such communications are necessary for contractual or legal purposes.

10.7 Recruitment

Applicant information is processed for:

  • recruitment;
  • interview scheduling;
  • candidate assessment;
  • reference verification;
  • right-to-work verification;
  • onboarding;
  • equal opportunity monitoring where legally appropriate.
10.8 Compliance

We may process information to:

  • comply with legislation;
  • respond to regulators;
  • respond to law enforcement requests;
  • maintain statutory records;
  • resolve disputes;
  • establish, exercise or defend legal claims.
11. Automated Decision-Making
11.1 General Principle

D Fine Tech recognises that individuals have important rights in relation to decisions made solely by automated means. We are committed to ensuring that any use of automated processing is lawful, transparent, proportionate and subject to appropriate safeguards.

We do not ordinarily make decisions that produce legal effects concerning individuals, or similarly significant effects, based solely on automated processing.

Examples of significant decisions include decisions relating to:

  • employment;
  • creditworthiness;
  • contractual eligibility;
  • insurance;
  • access to significant benefits;
  • financial profiling; or
  • other decisions with comparable legal or material consequences.

Where such processing is introduced in the future, it will only occur where permitted by applicable law and supported by appropriate safeguards.

11.2 Operational Automation

Our systems may use automated technologies for routine operational purposes, including:

  • spam detection;
  • cybersecurity monitoring;
  • malware identification;
  • authentication checks;
  • intrusion detection;
  • fraud prevention;
  • system performance monitoring;
  • application diagnostics;
  • network optimisation;
  • workload balancing;
  • service availability monitoring.

These activities are intended to protect the integrity, confidentiality and availability of our systems and do not ordinarily produce legal or similarly significant effects on individuals.

11.3 Human Oversight

Where automated tools are used to support business decisions, appropriate human oversight is maintained. Personnel responsible for reviewing automated outputs are expected to consider:

  • the context of the processing;
  • the reliability of the underlying data;
  • the appropriateness of the automated recommendation;
  • whether additional information is required;
  • whether intervention is necessary before action is taken.
11.4 Rights Relating to Automated Decisions

Where UK GDPR applies and an individual is subject to a qualifying automated decision, they may have the right to:

  • request human intervention;
  • express their point of view;
  • obtain an explanation of the decision;
  • contest the outcome.

Requests relating to automated decision-making should be submitted using the contact details provided in Section 29.

12. Artificial Intelligence Processing
12.1 Commitment to Responsible AI

As a technology company, D Fine Tech may design, develop, integrate or support artificial intelligence ("AI") systems as part of its services. We are committed to the responsible, lawful and ethical use of AI technologies and seek to ensure that their deployment aligns with applicable privacy legislation and recognised industry standards.

Our approach to AI is guided by the principles of:

  • lawfulness;
  • transparency;
  • accountability;
  • fairness;
  • human oversight;
  • privacy by design;
  • security by design;
  • proportionality;
  • data minimisation; and
  • continuous risk assessment.
12.2 AI in Service Delivery

Depending on the nature of the services provided, AI technologies may be used for purposes including:

  • software development assistance;
  • code generation;
  • code review;
  • debugging support;
  • documentation drafting;
  • software testing;
  • quality assurance;
  • predictive analytics;
  • natural language processing;
  • workflow automation;
  • customer support assistance;
  • technical knowledge retrieval;
  • anomaly detection;
  • application optimisation.

Where AI systems process customer data, D Fine Tech will do so in accordance with contractual obligations and applicable privacy legislation.

12.3 Customer Instructions

Where D Fine Tech processes customer information through AI-enabled systems while acting as a data processor, such processing will be undertaken only:

  • in accordance with documented customer instructions;
  • under applicable contractual terms;
  • subject to agreed technical and organisational safeguards.

Customers remain responsible for determining whether AI processing is appropriate for their own data processing activities.

12.4 Data Minimisation

Where AI systems are used, we seek to minimise the volume of personal information processed by:

  • removing unnecessary identifiers;
  • using pseudonymisation where appropriate;
  • restricting data inputs;
  • limiting retention;
  • restricting access;
  • implementing appropriate logging.
12.5 Model Training

Unless expressly agreed in writing with a customer, D Fine Tech does not use customer confidential information or customer personal information to train publicly available foundation models or publicly accessible generative AI systems.

Where AI models are developed internally for specific customer solutions, the applicable contractual documentation will govern ownership, usage rights and permitted processing.

12.6 AI Governance

Our AI governance programme may include:

  • documented governance procedures;
  • risk assessments;
  • security reviews;
  • privacy impact assessments;
  • supplier due diligence;
  • contractual controls;
  • access management;
  • change management;
  • human oversight;
  • periodic review.
12.7 Transparency

Where individuals interact directly with AI-enabled services operated by D Fine Tech, we seek, where reasonably practicable, to provide appropriate information regarding the nature of such interactions.

13. Cookies and Similar Technologies
13.1 Overview

Our websites, portals and online services use cookies and similar technologies to improve functionality, enhance user experience, protect security and analyse website performance.

Cookies are small text files stored on a user's device that enable websites to recognise browsers and retain certain information.

13.2 Categories of Cookies

We may use the following categories of cookies.

Strictly Necessary Cookies

These cookies are essential for the operation of our website and cannot ordinarily be disabled.

They may be used for:

  • authentication;
  • security;
  • session management;
  • load balancing;
  • fraud prevention;
  • website functionality.

Functional Cookies

These cookies enable enhanced functionality, including:

  • language preferences;
  • accessibility settings;
  • user preferences;
  • remembered selections;
  • customised experiences.

Analytics Cookies

Analytics technologies help us understand how visitors interact with our website.

Information collected may include:

  • pages viewed;
  • navigation paths;
  • session duration;
  • referral sources;
  • browser information;
  • operating system;
  • approximate geographic region;
  • device type.

Where reasonably practicable, analytics information is aggregated or pseudonymised.

Performance Cookies

Performance cookies assist in measuring and improving:

  • page loading;
  • website responsiveness;
  • server performance;
  • resource optimisation;
  • reliability.

Marketing Cookies

Where used, marketing cookies may support:

  • advertising effectiveness;
  • campaign measurement;
  • remarketing;
  • social media integration.

Marketing cookies will generally be deployed only where legally required consent has been obtained.

13.3 Cookie Consent

Where required by applicable law, users will be presented with an appropriate cookie consent mechanism enabling them to:

  • accept all cookies;
  • reject non-essential cookies;
  • customise cookie preferences;
  • withdraw consent.

Withdrawal of consent does not affect the lawfulness of prior processing.

13.4 Browser Controls

Most web browsers permit users to manage cookies through browser settings.

Users may generally:

  • block cookies;
  • delete cookies;
  • receive cookie notifications;
  • restrict third-party cookies.

Disabling cookies may reduce website functionality.

13.5 Similar Technologies

We may also use technologies including:

  • local storage;
  • session storage;
  • software development kits;
  • security tokens;
  • web beacons;
  • server logs;
  • pixel technologies,

where permitted by applicable law.

14. Marketing Communications
14.1 Business Communications

We may communicate with existing customers regarding:

  • service updates;
  • contractual matters;
  • security notices;
  • maintenance activities;
  • product improvements;
  • support information.

These communications are generally necessary for the performance of our contractual relationship or our legitimate interests.

14.2 Promotional Communications

Subject to applicable law, we may send:

  • newsletters;
  • product announcements;
  • webinar invitations;
  • event information;
  • service updates;
  • technology insights;
  • educational materials.

Marketing communications will only be sent where permitted by law.

14.3 Opt-Out

Recipients may unsubscribe from marketing communications at any time by:

  • using the unsubscribe link;
  • contacting D Fine Tech directly;
  • updating communication preferences.

Opting out of marketing does not prevent operational communications necessary for service delivery.

14.4 Consent Records

Where consent is required for marketing activities, we maintain records demonstrating:

  • when consent was obtained;
  • how consent was obtained;
  • the information presented at the time;
  • subsequent withdrawals where applicable.
15. International Transfers of Personal Data
15.1 International Nature of Our Business

As a technology company providing services to customers in multiple jurisdictions, personal information may be transferred internationally where necessary for legitimate business purposes.

Such transfers may occur:

  • between the United Kingdom and Australia;
  • between customers and approved service providers;
  • between cloud hosting environments;
  • during software development projects;
  • for technical support;
  • for disaster recovery;
  • for business continuity.
15.2 Protection of International Transfers

Where personal information is transferred outside the United Kingdom or Australia, we implement appropriate safeguards designed to ensure that transferred information continues to receive an appropriate level of protection.

Safeguards may include:

  • adequacy regulations;
  • International Data Transfer Agreements (IDTAs);
  • UK Addendum to the European Commission Standard Contractual Clauses;
  • Standard Contractual Clauses (where applicable);
  • contractual confidentiality obligations;
  • encryption;
  • access controls;
  • technical safeguards;
  • organisational controls.
15.3 Transfer Risk Assessments

Where appropriate, D Fine Tech may undertake transfer risk assessments considering:

  • destination country;
  • legal framework;
  • recipient safeguards;
  • technical protections;
  • contractual obligations;
  • likelihood of government access;
  • security controls.
15.4 Cloud Infrastructure

Where cloud infrastructure is utilised, customer information may be stored or processed within data centres operated by reputable cloud service providers.

Where customers require data residency within a specific jurisdiction, this will be addressed contractually where commercially and technically feasible.

15.5 Australian Information

Where Australian personal information is disclosed overseas, D Fine Tech seeks to ensure that overseas recipients handle such information consistently with applicable Australian Privacy Principles or equivalent contractual protections.

16. Disclosure of Personal Data
16.1 General Principle

We do not sell personal information.

Personal information is disclosed only where necessary for legitimate business purposes, legal compliance or with appropriate authority.

16.2 Service Providers

We may disclose information to carefully selected service providers supporting our operations, including providers of:

  • cloud hosting;
  • cybersecurity;
  • software development tools;
  • communications;
  • customer relationship management;
  • accounting;
  • payment processing;
  • recruitment;
  • professional advisory services;
  • document management;
  • project management;
  • analytics.

All service providers are expected to protect personal information through appropriate contractual and security obligations.

16.3 Professional Advisers

Information may be disclosed where necessary to:

  • solicitors;
  • barristers;
  • auditors;
  • insurers;
  • accountants;
  • tax advisers;
  • regulatory consultants.

Such disclosures occur only where reasonably necessary.

16.4 Corporate Group

Where operationally necessary, personal information may be disclosed within the D Fine Tech corporate group (including future subsidiaries or affiliated entities) for legitimate internal administrative purposes, including:

  • financial administration;
  • governance;
  • information security;
  • legal compliance;
  • risk management;
  • internal reporting;
  • business continuity planning; and
  • operational support.

Any such disclosures will be subject to appropriate confidentiality and security obligations.

16.5 Legal and Regulatory Authorities

We may disclose personal information where required or authorised by law, including to:

  • courts and tribunals;
  • law enforcement agencies;
  • regulatory authorities;
  • tax authorities;
  • government departments;
  • supervisory authorities;
  • statutory bodies.

We will take reasonable steps to verify the legitimacy and scope of any request before disclosing personal information, unless prohibited by law.

16.6 Protection of Rights

Personal information may be disclosed where reasonably necessary to:

  • establish, exercise or defend legal claims;
  • enforce contractual rights;
  • investigate suspected fraud;
  • protect the rights, property or safety of D Fine Tech, our customers or others;
  • respond to security incidents;
  • prevent unlawful activity.
16.7 Corporate Transactions

If D Fine Tech undergoes or proposes a:

  • merger;
  • acquisition;
  • investment transaction;
  • business restructuring;
  • sale of assets;
  • insolvency process; or
  • business transfer,

personal information may be disclosed to prospective purchasers, investors, advisers or counterparties, provided appropriate confidentiality obligations are in place.

Where required by applicable law, affected individuals will be notified of any material changes affecting the processing of their personal information.

16.8 Customer Instructions

Where D Fine Tech acts solely as a data processor, we disclose personal information only:

  • in accordance with documented customer instructions;
  • where required by law; or
  • as otherwise authorised under the applicable data processing agreement.
16.9 International Service Providers

Some approved service providers may operate internationally.

Where personal information is disclosed to overseas recipients, we implement appropriate safeguards as described in Section 15.

16.10 No Sale of Personal Information

D Fine Tech does not:

  • sell personal information;
  • trade personal information;
  • rent personal information to third parties for commercial gain.
17. Security Measures
17.1 Commitment to Security

Protecting personal information is fundamental to our business operations.

D Fine Tech maintains technical and organisational measures designed to safeguard personal information against:

  • accidental loss;
  • unlawful destruction;
  • unauthorised disclosure;
  • unauthorised access;
  • alteration;
  • misuse;
  • corruption;
  • cyberattack.

No security programme can guarantee absolute security. However, we continuously review and improve our controls to address evolving risks.

17.2 Information Security Framework

Our information security programme is based upon recognised security principles and includes governance measures relating to:

  • risk management;
  • asset management;
  • access management;
  • secure development;
  • incident response;
  • business continuity;
  • disaster recovery;
  • supplier security;
  • vulnerability management;
  • change management.
17.3 Technical Security Controls

Depending on the nature of the services provided, our technical controls may include:

  • encryption of data in transit using current industry-standard protocols (such as TLS);
  • encryption of data at rest where appropriate;
  • cryptographic hashing of passwords;
  • network segmentation;
  • firewalls;
  • intrusion detection and prevention systems;
  • endpoint protection;
  • anti-malware technologies;
  • security monitoring;
  • security logging;
  • vulnerability scanning;
  • patch management;
  • backup and recovery procedures;
  • secure configuration standards;
  • multi-factor authentication for privileged access where appropriate.
17.4 Organisational Controls

Organisational safeguards may include:

  • confidentiality agreements;
  • employee background checks where appropriate and lawful;
  • information security policies;
  • acceptable use policies;
  • role-based access controls;
  • regular security awareness training;
  • secure onboarding and offboarding procedures;
  • documented incident response procedures;
  • supplier due diligence;
  • internal audits.
17.5 Access Controls

Access to personal information is limited to personnel who require access for legitimate business purposes.

Access permissions are granted according to the principles of:

  • least privilege;
  • need-to-know;
  • role-based authorisation.

Access rights are periodically reviewed and updated.

17.6 Secure Software Development

As a software development company, D Fine Tech seeks to integrate security throughout the software development lifecycle, including:

  • secure architecture reviews;
  • code review procedures;
  • dependency management;
  • vulnerability assessment;
  • secure testing;
  • release management;
  • change control.
17.7 Incident Management

Security incidents are managed using documented procedures designed to:

  • identify incidents promptly;
  • contain threats;
  • investigate root causes;
  • mitigate risks;
  • restore normal operations;
  • notify customers and authorities where legally required;
  • implement corrective actions.
17.8 Customer Responsibilities

Customers also play an important role in protecting information.

Customers are responsible for maintaining appropriate security over:

  • account credentials;
  • passwords;
  • endpoint devices;
  • internal user permissions;
  • customer-managed environments;
  • information uploaded to our services.
18. Data Retention
18.1 General Principle

We retain personal information only for as long as reasonably necessary to fulfil:

  • contractual obligations;
  • legal obligations;
  • regulatory requirements;
  • legitimate business purposes;
  • dispute resolution;
  • enforcement of agreements.

Once information is no longer required, it will be securely deleted, anonymised or otherwise disposed of in accordance with our retention procedures.

18.2 Factors Considered

Retention periods are determined having regard to:

  • the purpose of collection;
  • contractual obligations;
  • statutory limitation periods;
  • accounting requirements;
  • taxation obligations;
  • legal claims;
  • regulatory expectations;
  • operational necessity.
18.3 Secure Disposal

Where information reaches the end of its retention period, D Fine Tech will, where appropriate:

  • securely erase electronic records;
  • permanently delete cloud-based information;
  • destroy physical documents using secure methods;
  • anonymise datasets where continued analytical use is appropriate.
18.4 Data Retention Schedule

The following retention periods are indicative and may be extended where required by law, regulatory obligation, litigation hold or legitimate business necessity.

Category Typical Retention Period
Customer contracts7 years after termination
Customer account records7 years after account closure
Project documentation7 years after project completion
Financial records7 years
Tax records7 years or longer where legally required
Supplier contracts7 years after termination
Marketing consent recordsDuration of consent plus 6 years
Recruitment records (unsuccessful applicants)Up to 12 months unless longer retention is authorised
Employee recordsIn accordance with employment law requirements
Security logsTypically 12–24 months depending on operational requirements
Website analyticsGenerally up to 26 months unless anonymised earlier
Technical support recordsUp to 7 years after closure where operationally necessary
Backup mediaManaged in accordance with documented backup retention schedules

Where D Fine Tech acts solely as a processor, retention periods are primarily determined by the customer.

19. Rights of Individuals under UK GDPR

Subject to applicable law and any relevant exemptions, individuals may exercise the following rights.

19.1 Right to be Informed

Individuals have the right to receive clear information regarding how their personal information is processed.

This Privacy Policy forms part of that commitment.

19.2 Right of Access

Individuals may request confirmation of whether we process their personal information and, where applicable, obtain:

  • a copy of the information;
  • processing purposes;
  • categories of information;
  • recipients;
  • retention periods;
  • applicable safeguards;
  • information regarding their rights.
19.3 Right to Rectification

Individuals may request correction of inaccurate or incomplete personal information.

We may request reasonable evidence before making changes.

19.4 Right to Erasure

Individuals may request deletion of personal information where:

  • the information is no longer necessary;
  • consent has been withdrawn;
  • processing is unlawful;
  • applicable law otherwise provides for erasure.

This right is not absolute and may be restricted where continued processing is required by law or for the establishment, exercise or defence of legal claims.

19.5 Right to Restrict Processing

Individuals may request restriction of processing under circumstances provided by applicable law, including where:

  • accuracy is contested;
  • processing is unlawful;
  • information is required for legal claims.
19.6 Right to Data Portability

Where applicable, individuals may request that personal information they have provided be supplied:

  • in a structured, commonly used and machine-readable format; or
  • transmitted directly to another controller where technically feasible.
19.7 Right to Object

Individuals may object to processing carried out on the basis of legitimate interests or public interest.

Where an objection is received, D Fine Tech will consider whether compelling legitimate grounds override the individual's interests, rights and freedoms.

Individuals may object to direct marketing at any time.

19.8 Rights Relating to Automated Decision-Making

Where applicable, individuals may request:

  • human intervention;
  • review of automated decisions;
  • explanation of decision-making processes.
19.9 Exercising Rights

Requests should include sufficient information to enable identification of the requester.

Reasonable identity verification measures may be required before information is disclosed.

We will respond within the applicable statutory timeframes unless an extension is permitted by law.

20. Australian Privacy Rights
20.1 Application

Where the Australian Privacy Act 1988 (Cth) applies to our processing activities, D Fine Tech manages personal information in accordance with the Australian Privacy Principles ("APPs").

Individuals located in Australia, or whose personal information is processed under Australian privacy law, may exercise the rights described in this section in addition to any rights available under other applicable legislation.

20.2 Access to Personal Information

Individuals may request access to personal information held by D Fine Tech.

Subject to applicable legal exceptions, we will provide access within a reasonable period after receiving the request and verifying the requester's identity.

Access may be refused where permitted by the Privacy Act 1988, including where disclosure would:

  • unreasonably affect the privacy of another person;
  • prejudice legal proceedings;
  • reveal commercially sensitive information;
  • compromise law enforcement activities;
  • endanger public safety;
  • otherwise fall within a recognised statutory exception.

Where access cannot be provided, we will generally explain the reasons unless prohibited by law.

20.3 Correction of Personal Information

If an individual believes that personal information is inaccurate, incomplete, misleading or out of date, they may request correction.

Where appropriate, D Fine Tech will:

  • correct the information;
  • update internal records;
  • notify relevant third parties where required by law or reasonably practicable.
20.4 Complaints

Individuals who believe that D Fine Tech has breached the Australian Privacy Principles may submit a complaint using the procedures described in Section 27.

Where a complaint cannot be resolved internally, individuals may contact the Office of the Australian Information Commissioner (OAIC).

20.5 Overseas Disclosure

Where Australian personal information is transferred overseas, D Fine Tech seeks to ensure that overseas recipients provide a level of protection consistent with applicable Australian privacy requirements through appropriate contractual, organisational and technical safeguards.

21. Children's Privacy
21.1 General Policy

D Fine Tech's services are designed primarily for businesses, organisations and professionals.

Our services are not intentionally directed towards children.

21.2 Collection of Children's Information

We do not knowingly collect personal information directly from children except where:

  • authorised by a parent or legal guardian;
  • required by law;
  • necessary for a customer solution that independently determines the purposes of processing.

Where we become aware that personal information has been collected from a child without appropriate legal authority, we will take reasonable steps to delete that information unless retention is required by law.

21.3 Customer Responsibilities

Customers using D Fine Tech software to process children's personal information remain responsible for ensuring that they have an appropriate lawful basis and all required notices, consents and safeguards under applicable legislation.

22. Third-Party Websites and Services
22.1 External Websites

Our websites, communications or applications may contain links to third-party websites, services or applications.

These external services operate independently from D Fine Tech and maintain their own privacy practices.

We encourage individuals to review the privacy policies of any third-party websites before providing personal information.

22.2 Third-Party Integrations

Depending on customer requirements, software solutions developed by D Fine Tech may integrate with third-party platforms including:

  • cloud service providers;
  • payment providers;
  • authentication providers;
  • messaging platforms;
  • customer relationship management systems;
  • enterprise software platforms;
  • analytics providers;
  • communication services.

The privacy practices of those third parties are governed by their own policies and contractual arrangements.

22.3 Social Media

Where individuals interact with D Fine Tech through social media platforms, personal information may also be processed by the relevant platform operator under its own privacy policy.

23. Recruitment Information
23.1 Recruitment Activities

Personal information submitted during recruitment may be processed for purposes including:

  • assessing applications;
  • arranging interviews;
  • verifying qualifications;
  • confirming employment history;
  • checking professional references;
  • conducting lawful pre-employment screening;
  • evaluating suitability for employment.
23.2 Lawful Basis

Recruitment information may be processed on the basis of:

  • steps taken at the request of the applicant prior to entering into employment;
  • legitimate interests;
  • compliance with legal obligations;
  • consent where appropriate.
23.3 Background Checks

Where lawful and appropriate, D Fine Tech may conduct background verification, including:

  • employment history;
  • educational qualifications;
  • professional certifications;
  • right-to-work verification;
  • identity verification.

Background checks will be proportionate to the relevant role and conducted in accordance with applicable law.

23.4 Retention of Recruitment Records

Recruitment information will generally be retained only for the period reasonably necessary for recruitment purposes and any subsequent legal obligations, after which it will be securely deleted unless longer retention is authorised by the applicant or required by law.

24. Supplier Information
24.1 Supplier Relationships

D Fine Tech processes personal information relating to suppliers, contractors and business partners for purposes including:

  • procurement;
  • contract administration;
  • payment processing;
  • due diligence;
  • compliance;
  • relationship management;
  • service delivery.
24.2 Supplier Due Diligence

We may conduct reasonable due diligence regarding suppliers to assess:

  • competence;
  • security standards;
  • financial stability;
  • regulatory compliance;
  • information security capabilities.
24.3 Contract Management

Supplier information may be retained for the duration of contractual relationships and applicable statutory retention periods.

25. Business Continuity and Corporate Transactions
25.1 Business Continuity

Personal information may be included within secure backup systems and disaster recovery environments to ensure continuity of services.

Such backup information is protected using appropriate security controls and is retained in accordance with documented retention procedures.

25.2 Corporate Restructuring

In the event of:

  • merger;
  • acquisition;
  • restructuring;
  • investment;
  • refinancing;
  • sale of business assets;
  • insolvency proceedings;

personal information may be transferred to successor organisations where permitted by applicable law and subject to appropriate confidentiality and privacy protections.

26. Personal Data Breaches
26.1 Incident Response

D Fine Tech maintains documented procedures for responding to actual or suspected personal data breaches.

These procedures are designed to:

  • identify incidents promptly;
  • contain the incident;
  • assess the scope and impact;
  • investigate root causes;
  • mitigate ongoing risks;
  • restore affected services;
  • implement corrective actions.
26.2 Notification

Where required by applicable law, D Fine Tech will notify:

  • relevant supervisory authorities;
  • affected customers;
  • affected individuals;

within applicable legal timeframes where a personal data breach is likely to result in a risk to the rights and freedoms of individuals.

26.3 Record Keeping

We maintain records of security incidents and personal data breaches in accordance with our legal and governance obligations, including:

  • incident description;
  • categories of information affected;
  • remediation actions;
  • lessons learned;
  • preventive measures.
27. Complaints
27.1 Internal Complaints

Individuals who have questions, concerns or complaints regarding this Privacy Policy or our handling of personal information are encouraged to contact D Fine Tech first so that we may investigate and seek to resolve the matter promptly.

Complaints should include:

  • contact details;
  • description of the issue;
  • relevant dates;
  • supporting information where available.
27.2 Investigation

We will acknowledge receipt of complaints and investigate them fairly, impartially and within a reasonable timeframe.

Where additional information is required, we may contact the complainant during the investigation.

27.3 UK Supervisory Authority

Individuals located within the United Kingdom who remain dissatisfied may have the right to lodge a complaint with the Information Commissioner's Office (ICO).

Nothing in this Privacy Policy limits any statutory rights available under applicable law.

27.4 Australian Supervisory Authority

Individuals located in Australia may also refer unresolved complaints to the Office of the Australian Information Commissioner (OAIC) where appropriate.

28. Changes to this Privacy Policy

D Fine Tech may amend this Privacy Policy from time to time to reflect:

  • changes in legislation;
  • regulatory guidance;
  • technological developments;
  • business operations;
  • security practices;
  • service offerings.

Where material changes are made, we will take reasonable steps to notify affected individuals where required by applicable law.

The revised Privacy Policy will supersede previous versions from its stated effective date.

29. Contact Information

Questions regarding this Privacy Policy or requests relating to personal information may be directed to D Fine Tech Ltd.

D Fine Tech Ltd.
Company Number: 13396727
England and Wales

Requests relating to:

  • access to personal information;
  • correction;
  • deletion;
  • restriction;
  • portability;
  • objections;
  • marketing preferences;
  • privacy complaints;

should be submitted in writing using the contact details published on D Fine Tech's official website or otherwise provided through contractual communications. Our published contact details are available on our Contact Us page.

D Fine Tech will respond in accordance with applicable legal requirements.

Appendix A – Categories of Personal Information

The following table summarises the principal categories of personal information processed by D Fine Tech.

Category Examples
Identity InformationName, title, employee ID, customer ID
Contact InformationAddress, email, telephone number
Business InformationEmployer, role, department
Account InformationUsername, authentication records
Financial InformationInvoices, payment references, supplier banking details
Technical InformationIP address, browser, operating system
Device InformationDevice ID, hardware model, diagnostics
Usage InformationWebsite interactions, application logs
CommunicationsEmails, support tickets, meeting records
Recruitment InformationCVs, references, qualifications
Marketing PreferencesSubscription status, consent records
Security InformationAudit logs, authentication logs, access records
Appendix B – Detailed Data Retention Schedule
Record Category Standard Retention
Customer contracts7 years after expiry or termination
Project documentation7 years
Software development records7 years
Customer correspondence7 years
Technical support records7 years
Financial records7 years or longer if legally required
Tax recordsIn accordance with applicable tax legislation
Recruitment records (unsuccessful)Up to 12 months
Employee recordsIn accordance with employment legislation
Security logs12–24 months
Website analyticsUp to 26 months unless anonymised
Marketing consent recordsDuration of consent plus 6 years
Supplier records7 years after contract termination
Disaster recovery backupsIn accordance with documented backup schedules

Retention periods may be extended where required by litigation holds, regulatory investigations or other legal obligations.

Appendix C – Cookie Categories
Cookie Category Purpose
Strictly NecessaryAuthentication, security, website functionality
FunctionalPreferences, accessibility, language settings
AnalyticsWebsite usage analysis and performance measurement
PerformanceOptimisation and reliability
MarketingAdvertising and campaign measurement where consented
Appendix D – International Transfer Safeguards

Where international transfers occur, D Fine Tech may rely on one or more of the following safeguards:

  • UK adequacy regulations;
  • International Data Transfer Agreements (IDTAs);
  • UK Addendum to the European Commission Standard Contractual Clauses;
  • Standard Contractual Clauses where applicable;
  • contractual confidentiality obligations;
  • encryption of personal information;
  • pseudonymisation where appropriate;
  • access controls;
  • supplier due diligence;
  • transfer risk assessments.
Appendix E – Data Subject Request Procedure

Upon receipt of a valid privacy request, D Fine Tech will generally:

  1. Acknowledge receipt of the request.
  2. Verify the requester's identity where appropriate.
  3. Assess the applicable legal basis and any relevant exemptions.
  4. Locate relevant personal information.
  5. Review information for third-party rights or legal restrictions.
  6. Prepare the response.
  7. Respond within the applicable statutory timeframe.
  8. Record the request for compliance and audit purposes.

Where D Fine Tech acts solely as a data processor, requests relating to customer data may be referred to the relevant customer (the data controller), unless otherwise agreed contractually.

END OF PRIVACY POLICY