Skip to main content
Umzi Labs
Legal · charter of undertakings

Privacy notice

Set out as a charter. Each numbered article states an undertaking UMZI LABS LTD gives about personal data, names the lawful basis it rests on, and where the article asks something of you in return, says so in the same breath. The point of the form is that a reader can put a finger on one promise and measure a practice against it.

In force from 15 August 2026 Version 2.0 Twenty articles

1Who gives these undertakings

Every promise in this charter is given by UMZI LABS LTD, a private limited company on the register of England and Wales under the number 17061761. Throughout, we is that company and you is whichever living person the passage concerns. One address carries all of it: [email protected].

Formal service of a document belongs at the registered office, and the entry filed at Companies House is the copy of that address to work from. We deliberately do not restate it in these pages, because a web page can lag a filing by weeks and it is the filing that binds.

No statutory data protection officer has been appointed, and Article 37 does not call for one here: that duty attaches to public authorities, to controllers whose core business is watching people systematically at scale, and to those handling sensitive classes at scale. Our undertakings sit with the company's officers, whose particulars are published against the same company number. Please address requests to the mailbox rather than to a named individual, so that nothing waits on one person's calendar.

The company keeps no establishment inside the European Union and does not hold itself out to individuals there, so nobody has been appointed to act as a representative under Article 27.

How to read a charter article

Some articles govern work that only arises once an engagement is signed, and some govern software published under our own name. Each says at its head which situation it speaks to, and which of the two roles in Article 2 we occupy while it applies. Undertakings written before the commercial pressure arrives are harder to quietly relax afterwards, which is the reason for writing them this way round.

2Which of the two hats we are wearing

Data protection law hands out duties by role. Whoever settles the question of why personal data exists, and broadly by what means, carries the controller's duties. Whoever merely acts on that party's written directions carries the processor's, which are narrower and quite differently shaped. This company occupies both positions at different moments, so each article marks the role it speaks from.

2.1 Where the decisions are ours

We answer as controller for everything gathered for our own ends: correspondence arriving in the mailbox, the running record of dealings with clients and suppliers, contract and bookkeeping files, applications for work, and the technical traces a browser leaves when it asks this site for a page. In each case we picked the purpose, we chose the lawful basis, we fixed the period, and we answer to you and to the regulator for all three. Articles 4, 5 and 6 set that out.

2.2 Where the decisions belong to a client

Investigating, building or maintaining software for a client brings us within reach of personal data about that client's own users, customers and staff. None of it exists because we wanted it. The client is controller, we are processor, and we move only on written direction under a contract carrying the terms Article 28 demands. Article 7 sets that out.

One consequence deserves stating plainly rather than leaving to inference. Where your details sit inside a client's system we happen to work on, we are the wrong door to knock at, and courtesy is not the reason. Article 29 stops a processor acting on anything but the controller's instruction, so we may neither erase, amend nor disclose that record on our own judgement, however reasonable the asking.

2.3 The overlap

Working details of the people we deal with at a client organisation, meaning names, roles, work addresses and work numbers, are held by us as controller rather than processor. We keep them because we decided to keep them, in order to run the relationship and to keep our books straight, and that decision is what puts us in the controller's chair. Article 5 covers them.

2.4 Positions we do not occupy

We share the controller's chair with nobody, so no joint controller arrangement exists to be disclosed. Personal data is never sold, hired out, licensed or brokered by this company. There is no advertising arm, no enrichment service and no mailing list behind any of this, and we have never bought contact details from a supplier of them.

3The vocabulary this charter uses

Seven expressions recur through the articles below, and one of them carries a meaning wider than most readers expect.

UK GDPR
Regulation (EU) 2016/679 as retained in domestic law through the European Union (Withdrawal) Act 2018, together with the amendments made to it since.
DPA 2018
The Data Protection Act 2018, which fills in around the retained Regulation and supplies the exemptions mentioned at 11.12.
Personal data
Anything relating to a living person who can be picked out from it, on its own or once set beside something else. Article 4(1) draws the boundary, and it sits further out than everyday usage suggests: a device address or an internal reference number qualifies whenever it can be tied back to somebody.
Sensitive classes
The categories Article 9(1) walls off and forbids without a second, separate justification: health; sex life and sexual orientation; genetic material and biometric measurements used to identify somebody; ethnic background; political conviction; religious or philosophical belief; and membership of a trade union.
Lawful basis
The particular ground in Article 6(1) that makes a given holding lawful in the first place. Every row of every table below names the lawful basis relied on for that row, because a holding without one is unlawful however well meant it was.
Onward processor
A firm we bring in to handle personal data on our behalf, a mail host being the obvious example. Article 8 names ours.
Transfer instruments
The two contracts the Commissioner has issued under section 119A of the DPA 2018 to make a restricted transfer lawful. The first is the International Data Transfer Agreement, the IDTA, which stands on its own and is drafted for domestic law. The second is the International Data Transfer Addendum, which bends the European Commission's standard contractual clauses to fit. Article 9 explains when each is reached for.

4What we undertake about messages you send

This article: we are controller

Writing to the mailbox is at present the only way personal data reaches this company at all, since nothing on the site can submit anything anywhere. So this article governs the ordinary case rather than an edge case.

Table 4.1 — what a message brings with it
What arrives Typically containing Reaching us how Held in order to Lawful basis Kept until Seen by
Who you are Your name, the address you wrote from, an employer and role, a number pasted into a signature block Typed by you, or carried in the headers your mail client attaches Work out who is writing, and write back to the right person Article 6(1)(f), legitimate interests. The interest: answering post addressed to the company, which cannot be done while ignorant of the sender Two years after the final exchange, unless the thread turns into an engagement The mail host named at Article 8
What you wrote Body text, subject line, anything attached, and the commercial background you choose to sketch Typed by you Grasp the request, judge whether we are any use on it, and compose a reply worth reading Article 6(1)(f) while we are weighing an approach. Once it turns into a contract, Article 6(1)(b) covers the steps taken at your request beforehand Two years, or the Table 10.1 period once it becomes engagement correspondence The mail host named at Article 8
What the transport adds Times, message identifiers, routing headers, spam scores and authentication verdicts Written automatically by the mail systems in between Deliver the message, thread the reply, and spot forged or hostile mail Article 6(1)(f). The interest: keeping our own mail trustworthy, which Article 32 independently requires of us Two years The mail host named at Article 8
A request under Article 11 What you asked for, how we satisfied ourselves who you were, what we decided, when we answered, any exemption leaned on Sent by you, plus the file we open on it Deal with the request, and afterwards show that it was dealt with properly Article 6(1)(c), a legal obligation, read alongside the accountability duty at Article 5(2) Three years from the day the file closes Nobody beyond the company, absent a demand from the regulator or a court
A security report The weakness, the steps that reproduce it, how to reach you, and any credit you would like Sent by you Reproduce it, repair it, and tell you what happened Article 6(1)(f). The interest: soundness of what we run, which serves our clients and you at the same time Three years from repair, so that a recurrence is recognised as one Nobody, unless the flaw turns out to belong to a third party's product, in which case you hear from us before they do

On a narrow screen the table scrolls sideways; every column is still there.

4.1 The sensitive classes

Nothing we do calls for them, so we never ask. Should something of that kind arrive unprompted it is put to no use whatever and leaves with the rest of the thread on the schedule above. We would ask you not to entrust the sensitive classes, or bank details, to an unsolicited email in the first place: ordinary mail is not a confidential channel and no undertaking of ours can make it one.

4.2 Marketing

Writing to us subscribes you to nothing, because there is nothing here to be subscribed to. Should a list ever be started, joining it will take a deliberate act of yours and will never be folded into agreeing to something else.

5What we undertake about client and supplier records

This article: we are controller

Individuals at the organisations we work with and buy from, together with the paperwork a limited company is obliged to keep. Table 5.1 gives the footing and the period for each kind.

Table 5.1 — engagements, prospects and suppliers
What we hold Typically containing Reaching us how Held in order to Lawful basis Kept until Seen by
Working contact details Name, role, work address, work number, employer, which office From you, or from your employer, in the course of an engagement Run the work: scheduling, questions, handing things over, escalating when it matters Article 6(1)(b) where you are the person contracting. Otherwise Article 6(1)(f), the interest being performance of a contract with your employer, which cannot happen without named people to talk to Seven years past the close of the engagement The mail and file storage firms named at Article 8
The engagement file Proposals, statements of work, notes of meetings, records of decisions, written findings Written by us, or handed over by you Deliver the work, and demonstrate afterwards what was agreed, discovered and advised Article 6(1)(b) while the contract runs. For the tail beyond it, Article 6(1)(f), the interest being the ability to answer a claim inside the limitation window Seven years past the close of the engagement Our file storage firm, our accountant, and solicitors if any are instructed
Billing and settlement Billing name and address, purchase order references, invoice numbers, sums, dates paid, bank references From you, plus what we raise and what the bank reports Invoice, collect, keep the books, and file VAT and corporation tax Article 6(1)(b) for the invoicing itself. Article 6(1)(c) for the record-keeping the Companies Act 2006 and the Taxes Management Act 1970 impose Six years past the close of the financial year in question HM Revenue and Customs, our bank, and our accountant
Supplier contacts Name, work address, work number, role, employer Given to us by the supplier Buy and administer the services this company runs on Article 6(1)(b), or Article 6(1)(f) with the interest being the orderly administration of our own purchasing Six years past the close of the relationship Our accountant, where the cost is an accounted one
Applications for work Name, contact details, the CV, employment history, confirmation of the right to work, notes taken at interview From you, or from a recruiter acting on your behalf Assess an application and, if it goes well, prepare an offer Article 6(1)(b), covering steps taken before a contract. The right to work check is Article 6(1)(c), under section 15 of the Immigration, Asylum and Nationality Act 2006 Twelve months past the decision, where the application did not succeed Nobody, unless a recruiter introduced you and keeps a file of their own as controller in their own right

5.1 How the balance is struck

Leaning on Article 6(1)(f) obliges a controller to do three things: name the interest, show the holding is genuinely needed to serve it, and satisfy itself that your rights and freedoms do not outweigh the whole exercise. Every row above names its interest. The features that recur across our assessments are these: what we hold describes you at work rather than at home; a supplier or would-be supplier behaving this way is what somebody in your position would reasonably expect; we neither blend it with outside sources nor assemble a picture of you from it; and 11.9 lets you object whenever you wish. Ask, and the written assessment behind any particular activity will be sent to you.

6What we undertake about this website

This article: we are controller

umzilabs.co.uk is a stack of static files. No account exists to be opened, no form to be submitted, no comment thread, no search index and no application code running behind it. Nothing here is capable of sending us anything, which is precisely why the mailbox is the only route in. Nothing is counted, nothing is measured, and no script for measurement, advertising, live chat, heat mapping, session replay or social embedding is loaded.

Table 6.1 — what serving a page involves
What arises Typically containing Arising how Held in order to Lawful basis Kept until Seen by
The request itself The address your connection presents, the moment, the path asked for, the status returned, the bytes sent, the browser string, the referring page, the negotiated protocol version Produced between your browser and our host in the act of fetching a page Return the page, and recognise abuse such as flood traffic or bulk harvesting Article 6(1)(f). The interest: keeping the site up and sound, which Article 32 also expects of us The standard period our edge provider applies. Nothing is pulled down, aggregated or examined by us Cloudflare, Inc., as onward processor
A challenge marker A short-lived token our edge provider may write when its bot handling engages Placed by the edge network rather than by anything on the page Separate an ordinary reader from automated abuse Necessary for a service you asked for, and so outside consent under regulation 6(4) PECR. Article 6(1)(f) for the personal data alongside it A session, or the brief life the provider gives it Cloudflare, Inc.
A typeface fetch Connection address and browser string, disclosed to Google as your browser collects the lettering Your browser asks fonts.googleapis.com for the stylesheet, then fonts.gstatic.com for the files themselves Render these pages in the lettering they were set in Article 6(1)(f), the interest here being legible and consistent presentation. Google answers as controller in its own right for whatever it receives Whatever period Google applies. None of it comes back to us Google LLC and Google Ireland Limited

Nothing on these pages writes a marker of our own, and you will find no consent panel, because outside the necessary challenge token above there is nothing a panel could properly ask about. Were we to add something that PECR brings within consent, a panel would appear first, declining would cost exactly as few clicks as accepting, and the new component would stay dormant until you had chosen. The cookie notice works through the detail.

6.1 Where the lettering comes from

The typefaces these pages are set in are fetched from Google as the page loads, which means your browser opens a connection to Google's servers and Google learns your connection address and browser string in the ordinary course of answering it. Nothing returns to us from that exchange and no measurement of any kind is derived from it. Serving the font files from our own domain would close the connection altogether, and that is the direction this site is moving in; when it lands, this article will be replaced by a statement that no outside request is made at all.

7What we undertake when a client holds the pen

This article: we are processor

Engineering or investigative work inside a client's system puts personal data the client controls within our reach: records in a database being migrated, identifiers threaded through log files, a production sample borrowed to test whether an approach survives contact with real shapes, support tickets visible on the screen while a fault is chased. We gathered none of it and hold no purpose of our own for any of it.

7.1 The undertakings a client extracts from us in writing

Before an engagement touches personal data at all, a written processing agreement binds us to the following: to act only on directions the client has recorded; to warn the client where a direction looks to us like a breach of the legislation; to hold the material close and to bind everyone with access to the same silence; to apply the security measures Article 32 calls for; to obtain written permission before engaging anyone underneath us and to push identical terms down to them; to help the client with rights requests, with security, with notification and with impact assessments; to give the material back or destroy it when the work ends, whichever the client picks; and to open up whatever information and access the client needs to prove its own compliance.

7.2 How we prefer to work, absent instruction to the contrary

Our standing preference is to hold none of it. Where the work can be done inside the client's own environment, through accounts the client issues and can withdraw in a keystroke, that is where it is done and no copy travels to us. Where a local copy looks necessary, the first question asked is whether anonymised or invented data would settle the point just as well, which more often than not it does. Where a genuine extract cannot be avoided, we take the narrowest slice that answers the question, hold it for the shortest span that answers it, and destroy it with written confirmation the moment the task closes.

7.3 What this means when you want something done

Where your details live in a client's system we have worked on, the rights at Article 11 run against that client rather than against us. Write to us regardless and you will not be met with silence: the request goes on to the controller promptly, and where we are permitted to say who that is, we say. Acting on it ourselves is not something we may do, for the reason given at 2.2.

7.4 Anyone underneath us on client work

Nobody is brought in beneath us on a client's personal data without that client's written permission, recorded in the processing agreement itself. Article 8 lists the firms behind our own controller holdings; anyone engaged for a particular piece of work is named in that engagement's paperwork instead.

8What we undertake about the firms we lean on

This article: we are controller

The firms handling personal data on our behalf for our own operations. The list is short because the company runs on very little machinery, and each entry sits under a written contract carrying the Article 28 terms.

Table 8.1 — onward processors, named
Firm What it does for us What it touches Where the handling happens What protects a transfer
Cloudflare, Inc.
101 Townsend Street, San Francisco, CA 94107, United States
Static hosting through Cloudflare Pages, delivery, name resolution, certificate termination, absorbing flood traffic Connection address, browser string, request metadata, the challenge marker An edge network spanning many countries. A request from the United Kingdom is ordinarily answered from a domestic or European facility, though it need not be The addendum bending the European Commission's clauses to domestic law, incorporated in that firm's own processing terms
Mail host Carrying and storing the [email protected] mailbox Everything in Table 4.1: who wrote, what they wrote, attachments, transport metadata A contracted email hosting firm acting as processor, named to you on request
Accountant Bookkeeping, statutory accounts, preparing tax returns The billing and settlement rows of Table 5.1 United Kingdom Nothing leaves the country. An accountant bound by professional duties is generally controller in their own right for those duties
Domain registrar Registering and administering the umzilabs.co.uk domain The company's own registrant details. Nothing about a reader of this site A contracted registrar acting as processor, named to you on request

8.1 Others who may see something, in their own right

Separately from the firms above, material may reach organisations answering for themselves rather than to us: the bank, over payments in and out; HM Revenue and Customs and Companies House, where a statutory filing requires it; insurers, should a claim be made; solicitors, for advice or the conduct of proceedings; and any authority, regulator or court able to compel it. Where disclosure is compelled we undertake to tell you it happened, unless telling you is itself forbidden.

8.2 Changing the list

Should another firm be engaged, this table is amended before that firm handles anything, not afterwards. Clients under a processing agreement receive written notice ahead of any change bearing on their engagement, with a window in which to object to it.

8.3 Why Google is absent from the table

Google appears nowhere above because it works for nobody here. Your browser reaches Google directly for the lettering, and Google answers as controller in its own right for the connection details it collects that way. No contract of ours governs that exchange and nothing flows back to us from it. Article 6.1 explains it, including where the site is headed.

9What we undertake about international transfers

This article: controller, and processor on client work

An international transfer of personal data to a recipient beyond the United Kingdom is what the legislation calls a restricted transfer. Chapter V permits one only where a listed condition holds. Three of them are open to us, and we reach for them in this order.

9.1 A finding of adequacy

Article 45 allows the Secretary of State to declare by regulations that a country, a territory or a defined sector protects data well enough that nothing further need be added. The declarations made under the DPA 2018 reach the European Economic Area states and the other destinations listed there. For the United States the position is narrower than it first appears: cover flows only through the domestic extension to the transatlantic framework, and only for an organisation that has certified itself to that extension and remains on the list today. We never take an American recipient's cover on trust. It is checked, and where certification is missing or has lapsed a transfer instrument is used instead.

9.2 The IDTA

Absent a finding of adequacy, our first choice is the IDTA, the transfer agreement the Commissioner issued under section 119A of the DPA 2018. It was drafted for domestic law and stands on its own feet, which makes it the cleanest instrument wherever we contract directly with the overseas recipient.

9.3 The Addendum to the standard contractual clauses

International suppliers frequently offer the European Commission's standard contractual clauses and nothing else, their paperwork having been drawn up for a European market. In that case we use the addendum issued under the same section, which swaps the European references and supervisory authorities for domestic ones so the clauses operate here. Our edge provider's processing terms carry that addendum, and it is the instrument relied on in Table 8.1.

9.4 Assessing the risk before relying on either

Neither instrument does the job unaided, because a contract is only worth what it can achieve in the country it lands in. Before leaning on one we examine what surveillance and government access powers the destination actually confers, whether the recipient has ever faced a demand under them, what technical measures cut the exposure down in practice, and what would befall a person if the material were reached. Where that exercise says the paper would not hold, the transfer does not happen. We find a domestic or European alternative, or we restructure the work so nothing needs to leave.

9.5 On client work the choice is not ours

Wearing the processor's hat, whether anything crosses a border at all, and to which countries, is the controller's decision and is written into the processing agreement. No client's personal data leaves the United Kingdom on our initiative.

9.6 Asking to see the paperwork

Write to [email protected] and we will send you the instrument relied on for any transfer touching you. Commercial terms such as pricing may be blacked out. The data protection provisions will not be.

10What we undertake about retention

This article: we are controller

Article 5(1)(e) forbids keeping data in a form that identifies somebody for longer than the purpose needs. Each period below therefore carries its justification alongside it, on the view that a schedule of periods without reasons is not a schedule at all but a set of habits written down.

Table 10.1 — periods, and what fixes them
What is held For how long Counted from Why that long and no longer
Books, tax records, invoices and settlement records Six years End of the financial year in question Section 388 of the Companies Act 2006 asks a private company for three years of accounting records, but the Revenue expects company tax records for six from the close of the accounting period, and the longer duty swallows the shorter. This is a floor set by statute and no request of yours can lower it
Client contracts and the engagement file Seven years Close of the engagement Section 5 of the Limitation Act 1980 allows six years to sue on a simple contract. The seventh year exists so that a claim issued in the last weeks of the sixth can still be answered from the underlying papers rather than from memory
Enquiries that never became engagements Two years Date of the final message Long enough that somebody returning to a conversation need not set the scene again, short enough that we are not sitting on a decade of dormant threads
Files on rights requests Three years The day the file closes Showing the regulator how a request was handled is what Article 5(2) demands of us, and a repeated pattern only becomes visible against earlier requests
Security incidents, whether or not reportable Six years The day the incident closes Article 33(5) requires a record of every security failure detailed enough for the regulator to check our judgement. Six years lines the record up with the window for a claim arising from it
Unsuccessful applications for work Twelve months The day the decision is made Most tribunal claims carry a three month limit that can be extended, and a discrimination claim may surface later still. A year permits a defence without keeping applications for ever
Supplier records Six years Close of the supply relationship Matched to the accounting period, since a supplier record is usually an accounting record wearing a different label
Client personal data held as processor The engagement, and not a day beyond Completion of the task, or close of the engagement Destroyed or handed back at the client's election under Article 28(3)(g). No copy is kept for any purpose of ours, and the destruction is confirmed in writing
Edge and server logs The provider's standard period The moment of the request Nothing is exported or duplicated by us, so the period is the one our provider operates rather than one we have chosen

10.1 What reaching the end of a period means

The record is destroyed, or where destruction is not technically achievable, stripped until no living person can be picked out of it either alone or against anything else in our hands. Backups are not quietly exempted from this. Where something has gone from the live systems but survives in a backup set, that copy is placed beyond ordinary use, meaning it is never restored for any purpose short of recovering from a disaster, and it disappears as the backup rotation reaches it.

10.2 When a period is suspended

Where a claim, a regulatory investigation or a criminal proceeding is under way or can reasonably be foreseen, and a record bears on it, that record is held past its ordinary period until the matter finishes. The suspension reaches the relevant records and stops there; it is never a reason to keep everything else as well.

11What we undertake about the rights you hold

This article: controller. For data held as processor, see 7.3

These rights are yours by operation of law rather than by our courtesy. Exercising one costs nothing, and having exercised one changes nothing about how you are treated afterwards.

11.1 Making a request

Write to [email protected] and put "Data protection request" in the subject line. No particular formula is needed, no article need be cited, and no reason need be offered. Something said aloud counts, and so does a message that never once uses the word request. Naming the right you want and the data you mean will speed things along, but neither is a condition of anything. Somebody may act for you provided we first hold your written authority for them to do so.

11.2 Satisfying ourselves who you are

Article 12(6) permits a controller with real doubt to ask for what it reasonably needs to resolve that doubt, and Article 5(1)(f) forbids handing your data to the wrong person. Writing from an address already on our records normally settles it and nothing further will be asked. Where doubt survives, we ask for the least intrusive thing that would dispel it, frequently a detail already sitting in the record itself. A passport or licence scan sent through unencrypted mail is not something we will demand as a matter of routine. The clock at 11.3 begins only once identification is settled, and if something is needed you will hear promptly rather than at the end of a silent month.

11.3 How long an answer takes

Article 12(3) requires an answer promptly and inside one calendar month of the request landing, and that is the undertaking. Where a request is genuinely intricate, or where several have arrived together, that window may stretch by two further months at most; should we need it, you hear so inside the first month together with the reason. Confirmation that your request arrived safely is sent within five working days, so the month is not spent wondering.

11.4 Seeing what we hold, Article 15

Article 15 lets you ask whether anything about you is held here and, where it is, receive a copy along with the surrounding information Article 15(1) specifies: what it is for, what categories it falls into, who sees it, how long it stays or how that is worked out, the other rights in this article, the route to the regulator, where it came from if not from you, and whether any machinery decides anything. The copy comes in an ordinary electronic format unless you would rather have another. Where a record also describes somebody else, their part is obscured, unless they agree or disclosing it without agreement is reasonable in the terms paragraph 16 of Schedule 2 to the DPA 2018 sets out.

11.5 Putting the record right, Article 16

Inaccurate data must be corrected and incomplete data completed, if necessary by adding a statement of your own. Where the record captures an opinion we formed or advice we gave, we will not rewrite history to make it say something else; what we will do, and what Article 16 actually requires in that situation, is record accurately that you dispute it and what your account is. Where the data has already gone to somebody, Article 19 obliges us to pass the correction on unless doing so proves impossible or out of all proportion, and we will tell you who received it if you ask.

11.6 Having data erased, Article 17

Erasure follows where one of the Article 17(1) grounds is made out: the purpose has run its course; consent was withdrawn and nothing else supports the holding; you objected under Article 21 and nothing overrides the objection; or the holding was unlawful from the start. The right has edges. Erasure must be refused where a legal obligation requires the holding, which is why accounting records survive inside the six years at Table 10.1, and where the material is needed to bring or defend a claim. A refusal will identify which exception applies to which specific records, and everything falling outside that exception is erased regardless.

11.7 Freezing rather than erasing, Article 18

You may require us to keep data while ceasing to use it, in four situations: while accuracy you have challenged is being checked; where the holding is unlawful but you would rather freeze than erase; where we have finished with it but you need it kept for a claim; and while an objection under Article 21 is being weighed. Frozen data is stored and left alone, save with your agreement, for a legal claim, to protect somebody else's rights, or for a substantial public interest. You will hear from us before any freeze is lifted.

11.8 Taking data elsewhere, Article 20

Where a holding rests on your consent or on a contract with you and runs by automated means, you may receive what you gave us as a machine-readable file in an everyday format, and have it passed to another controller where that is technically achievable. Candidly, this right reaches less of our material than it might elsewhere, because most of what we hold rests on legitimate interests or consists of correspondence we composed rather than structured entries you supplied. Rather than refuse a request wholesale on that basis, we will tell you which parts qualify and hand those over.

11.9 Objecting, Article 21

Where a holding rests on legitimate interests you may object on grounds particular to your circumstances. We must then stop, unless we can show grounds that are both legitimate and weighty enough to override your interests, rights and freedoms, or unless the holding serves a legal claim. Where an override is claimed, the reasoning is set out for you to examine rather than merely asserted. For direct marketing the right admits of no balancing whatever and we stop on being asked; since no marketing happens here, the occasion should not arise.

11.10 Withdrawing consent, Article 7(3)

Where consent is what we rely on, you may take it back whenever you like, and taking it back must cost you no more effort than giving it did. Withdrawal works forwards and does not render what came before unlawful. As this charter stands, nothing in Articles 4 to 6 rests on consent, so there is nothing presently to withdraw; the undertaking is recorded because that could change.

11.11 Decisions made by machinery, Article 22

Where a decision is reached by automated means alone, profiling included, and carries legal consequences for you or bites on you nearly as hard, the law shields you from being subjected to it. No decision of that kind is made here. Article 17 of this charter goes further into it.

11.12 The narrow grounds for saying no

Article 12(5) permits a controller to refuse, or to charge reasonably, where a request is plainly baseless or plainly out of all proportion. That threshold sits high and we undertake not to use it as a way past an inconvenient question: breadth alone does not make a request excessive, and your being unhappy with us does not make one baseless. The exemptions across Schedules 2 to 4 of the DPA 2018 may also be relied on, for instance where answering would expose somebody else's data, where the material attracts legal professional privilege, or where answering would prejudice the detection of crime. Any refusal, whole or partial, comes inside the month, names the exemption, states what it covers, and points you to the regulator and to the courts.

12What we undertake if you go over our heads

Where our handling of your data, or of a request about it, has left you dissatisfied, we would ask to hear it first, for the practical reason that we can usually put a thing right faster than anybody else can order us to. That preference gives us no veto. Article 77 gives you the right to take a complaint to the Information Commissioner's Office, which supervises this legislation in the United Kingdom, and coming to us first is neither a precondition nor something that weakens the complaint.

Supervisory authority
Information Commissioner's Office
Postal address
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom
Telephone
0303 123 1113
Online
ico.org.uk

Two further routes sit alongside that one. Article 79 entitles you to an effective remedy from a court, and Article 82 entitles you to compensation for damage suffered through an infringement, whether the damage is material or not.

13What we undertake about security, and about failure

This article: both roles

13.1 The measures themselves

Article 32 asks for technical and organisational measures matched to the risk. Ours are matched to a very small company that has arranged its working practices around holding as little as possible: traffic encrypted end to end, with this site pinned to HTTPS through a strict transport policy; storage and devices encrypted where they sit; a second factor on every account that will accept one; access granted for a named task and withdrawn as the task closes; the standing preference at 7.2 for working inside a client's environment rather than taking copies away; anonymised or invented data wherever development can be done on it; and engagements walled off from one another, so that reaching one has never once implied reaching another.

13.2 What counts as a failure

The legislation means something broader by it than an intruder at the perimeter. A security failure covers any breach of security that wrecks, mislays, alters or exposes personal data, or opens it to somebody with no business seeing it, whether through mishap or through design. A misplaced laptop qualifies. So does a message sent to the wrong recipient, and so does ransomware that leaves data intact but unreachable.

13.3 Telling the regulator, Article 33

Wearing the controller's hat we judge whether a failure is likely to put rights and freedoms at risk. Where it is, the Commissioner is told promptly, and inside the seventy-two hour window Article 33 sets, timed from the moment we know. Where the full picture is not assembled in that window we report anyway and complete it in stages, which Article 33(4) expressly contemplates. A late report will carry our explanation for its lateness. Where we judge a failure to fall short of the threshold, the judgement and its reasoning go on the record regardless, because Article 33(5) wants every failure recorded whether reportable or not.

13.4 Telling you, Article 34

Where a failure is likely to put your rights and freedoms at high risk, you hear from us directly and promptly, in language that does not need decoding: what happened, who to speak to here, what is likely to follow, what we have already done, and what we would suggest you do. Telling you individually is not required where the material was unintelligible to whoever reached it, strong encryption being the usual reason, or where subsequent measures mean the high risk is no longer likely to come about. Where reaching everyone individually would take effort out of all proportion, a public statement takes its place.

13.5 Wearing the processor's hat instead

Article 33(2) obliges us to tell the client promptly once we know. In that position we notify neither the Commissioner nor the individuals affected, since the assessment and the duty both belong to the controller. What we promise clients contractually is tighter than the legislation requires: notice inside twenty-four hours of our becoming aware, carrying what they need to run their own seventy-two hour assessment.

13.6 Telling us

Where you believe data of ours has been exposed, write to [email protected] with "Security report" in the subject line. Confirmation that it reached a person comes inside two working days.

14What we undertake about permissions in an application

This article: controller, for anything published under our own name

Which software this article binds

The undertakings here govern a mobile application published by this company under its own name, in whichever marketplace it is distributed. Where we build an application for a client and it goes out under the client's name, the client's own privacy notice governs it and this charter does not reach it.

14.1 The governing undertaking

No device permission will ever be a condition of using the core of an application published by us. Each one is optional, each is asked for at the moment it is first genuinely needed rather than queued up at first launch, and each request arrives behind a plain sentence explaining what it is for. Declining will not close the application, will not hide something unrelated, and will not summon the same prompt again next week. We ask once. A refusal stands until you change it yourself in the device settings.

Table 14.1 — permissions, and what refusing costs you
Permission What it would be asked for Required? Refusing means Withdrawing it on iOS Withdrawing it on Android
Notifications Letting you know a long task you started has finished Optional Nothing is lost. You look in the application instead Settings, Notifications, pick the app, switch Allow Notifications off Settings, Apps, pick the app, Notifications, switch off
Camera Taking a picture at a point where you chose to attach one Optional Attach a picture you already have, or attach nothing Settings, Privacy and Security, Camera, switch the app off Settings, Apps, pick the app, Permissions, Camera, Don't allow
Photo library Attaching a picture you pick out Optional No attachment. On iOS you may share selected pictures only, which we treat as the ordinary answer rather than a grudging one Settings, Privacy and Security, Photos, pick the app, choose None or Limited Access Settings, Apps, pick the app, Permissions, Photos and videos, Don't allow
Microphone Recording audio that you started recording Optional Audio capture is unavailable and nothing else changes Settings, Privacy and Security, Microphone, switch the app off Settings, Apps, pick the app, Permissions, Microphone, Don't allow
Location Only where a feature you opened is inherently about where you are. Location in the background is never asked for Optional Type a place in by hand. The feature itself is not withheld from you Settings, Privacy and Security, Location Services, pick the app, choose Never Settings, Location, App location permissions, pick the app, Don't allow
Contacts Not anticipated. Were a feature ever to need it, it would be so you could pick a recipient, and your address book would stay on the device Optional Type the recipient in by hand Settings, Privacy and Security, Contacts, switch the app off Settings, Apps, pick the app, Permissions, Contacts, Don't allow
Files and storage Opening a file you picked, or writing out an export you asked for Optional Import and export are unavailable and the rest works Granted one file at a time through the document picker, so there is no standing permission to withdraw Settings, Apps, pick the app, Permissions, Files and media, Don't allow
Biometric lock Putting the application behind Face ID, Touch ID or the Android biometric prompt, should you switch it on Optional, and off unless you turn it on The application is not locked separately from the device. Either way no biometric measurement travels to us Settings, Face ID and Passcode, Other Apps, switch the app off Settings, Apps, pick the app, Permissions, or switch it off inside the application
Cross-app tracking on iOS Never asked for. Article 16 explains why the prompt will not appear Never requested Nothing to refuse, since nothing is asked Settings, Privacy and Security, Tracking. Nothing of ours appears in the list Not applicable. The advertising identifier goes untouched

On a narrow screen the table scrolls sideways; every column is still there.

14.2 Changing your mind afterwards

Every permission above can be given or taken back at any moment from the device settings, without removing anything and without asking us first. Withdrawal takes effect at once, and whatever was gathered while it was granted falls under the erasure route at Article 15.

15What we undertake about erasure

This article: we are controller

These undertakings bind any account system this company operates, and they also reach the correspondence records at Article 4.

15.1 Erasure from inside the product

Any product of ours holding user accounts will carry its own erasure control, reachable without writing to anybody. The path runs Settings, then Account, then Delete account, and it will never sit more than three steps from the main screen. Before you confirm, it will show what goes and what must stay, and it will ask once. There will be no offer of a discount to stay, and no corridor of discouraging screens to walk down first.

15.2 Erasure by mail

Asking by mail always works, whether or not a control exists inside the product. Write to [email protected] with "Deletion request" in the subject line. Confirmation that it arrived comes within five working days.

15.3 The thirty day undertaking

Once a request is verified, erasure across the live systems and every firm holding a copy completes inside thirty days. That is deliberately shorter than the month plus extension Article 12(3) would allow us. Backup copies are put beyond ordinary use immediately and fall away as the rotation reaches them, which is why this undertaking is expressed as erasure from live systems inside thirty days rather than as the disappearance of every last byte everywhere. Written confirmation follows when it is done.

15.4 What survives an erasure, and on whose authority

  • Invoices and settlement records, for six years from the close of the relevant financial year, because the Revenue and the Companies Act 2006 require it. That is an obligation no request of yours can lift from us.
  • The bare fact that an erasure was asked for, by whom and when it completed, for three years, both to evidence that we complied and to stop a backup restore quietly reinstating what was removed.
  • A suppression entry where one is genuinely needed to keep something from being reintroduced, held to the minimum that achieves that and put to no other use.
  • Anything under a suspension per 10.2, for as long as that matter runs.
  • Aggregated and stripped information from which you cannot be picked out, which has ceased to be personal data and therefore falls outside an erasure request altogether.

Beyond that list, nothing survives. No shadow copy of a closed account is retained for measurement, for winning you back, or for any other reason.

15.5 Erasure from a client's system

Where the data sits in a client's system we cannot erase it on your instruction, for the reason set out at 2.2 and 7.3. The request goes on to the controller promptly and you are told that it has.

16What we undertake about marketplace declarations

16.1 App Tracking Transparency on iOS

Apple obliges an application to obtain permission through a system prompt before it follows a person around software and websites belonging to other companies, or reads the device advertising identifier. Neither is something any product of ours does or is intended to do. The consequence is that the App Tracking Transparency prompt will simply not be presented: there is nothing to accept, nothing to decline, and no feature waiting behind an answer. We do not read the Identifier for Advertisers, do not embed advertising or attribution kits, do not fingerprint a device as a way round the identifier, and pass nothing to data brokers. Were that ever to change, the prompt would appear, this article would be rewritten in advance of it, and refusing would still cost you no functionality.

16.2 Google Play and the Data Safety form

Google Play obliges every application to publish a Data Safety declaration covering four things: what it gathers, what it passes on and why, whether transit is encrypted, and whether erasure can be asked for. Our undertaking is that the declaration filed for any application of ours will say exactly what this charter says. Where the form offers only a category coarser than the truth, we will take the category and use the free text to state the narrower reality, rather than let a label stand that claims more collection than actually happens.

Should you ever find daylight between a declaration of ours and this charter, treat it as our mistake and write to [email protected]. Whichever document is wrong gets corrected, and we will tell you which one it was. The same undertaking covers the privacy labels shown on the Apple App Store.

17What we undertake about judgement by machinery

Nothing about you is decided here by automated means alone in a way that carries legal weight or lands nearly as heavily, so the restriction at Article 22 is not engaged by anything this company does. We assemble no behavioural picture of anyone, we neither score nor rank individuals, and personal data is not used to train machine learning models, ours or anybody else's.

Where an engagement involves building an automated decision system for a client, that client is its controller and carries the Article 22 duties, the lawful footing and the impact assessment along with them. Our undertaking in that position is narrower but not empty: to raise the issue the moment we see it, to build the safeguards the controller specifies, and to put it in writing where we believe a system we have been asked for would be unlawful.

18What we undertake about children

This site and the work behind it address businesses, and adults acting in a professional capacity. Nothing here is aimed at a child, and personal data is not knowingly gathered from anyone under eighteen. No service of ours engages the information society services rules at Article 8, under which the age of consent in the United Kingdom is thirteen.

Where you believe a child has given us something, write to [email protected] and it will be erased promptly. Should this company later publish a consumer product a child might plausibly reach, we undertake to assess it against the Commissioner's Age Appropriate Design Code before release, and to amend this charter to say so.

19What we undertake when this charter is amended

This is version 2.0, in force from 15 August 2026. The whole of it is reviewed at least once a year, and whenever something it describes actually changes: another firm engaged, a new activity started, an application published.

The date and version at the head always describe the text underneath them. Where an amendment bears materially on your rights, or substantially alters what becomes of your data, a silent update is not something we will rely on: those affected are contacted directly wherever we hold the means to do it, and told what changed rather than merely that something did. Small corrections, a broken link being the usual case, are made without announcement and the review date moves. Nothing is ever backdated. A version governs from its own commencement date onwards, and handling that has already happened is judged against whichever version was in force at the time.

20Where anything arising should be sent

Anything at all under this charter, the rights at Article 11 included, goes to [email protected]. Putting "Data protection request" in the subject line routes it faster where that is what it is, though a request is perfectly valid however it happens to be worded.

Controller
UMZI LABS LTD
Company number
17061761, on the register of England and Wales
Mailbox
[email protected]
Confirmation of arrival
Inside 5 working days
The answer itself
Inside 1 calendar month, stretchable by up to 2 further months where a request is intricate, with notice given inside the first month

Alongside this charter sit the terms of use and the cookie notice.

Back to the top