This Privacy Policy explains how YTR INNOVATION LTD collects, uses, stores and protects personal information. It applies to this website and to the services we provide as a computer integrated systems design consultancy. The policy was prepared by the developer YTR Innovation and is maintained by the same team that operates the Walthamstow studio. We have written it in plain language so that any reader can understand what happens to personal data and what choices are available.
Contents
- Who We Are
- Scope of This Policy
- Information We Collect
- How We Collect Information
- Lawful Basis for Processing
- How We Use Information
- Cookies and Similar Technologies
- Sharing Information
- International Transfers
- How Long We Keep Information
- How We Protect Information
- Your Rights
- Privacy for Children
- Marketing Communications
- Third Party Services
- Changes to This Policy
- Complaints and Contact
- Detailed Retention Schedule
Who We Are
YTR INNOVATION LTD is a company registered in the United Kingdom and operating as a computer integrated systems design consultancy. The registered and trading address is 110 Grove Road, Walthamstow, London - E17 9BY, United Kingdom (GB). For the purposes of data protection law, YTR INNOVATION LTD is the controller of the personal information described in this policy.
The developer YTR Innovation is responsible for the design and maintenance of this website and of the systems that support our client work. Questions about this policy, about your personal information, or about how our systems handle data may be sent to technology@ytrinnovation.surf or raised by telephone on +17197168182. We aim to answer every privacy question within a reasonable time and to explain our reasoning clearly.
This policy is written for a general audience. It covers visitors to our website, prospective clients who contact us, existing clients under a services agreement, suppliers and professional contacts. Where we act as a processor on behalf of a client, the terms of the relevant services agreement take priority and the client remains the controller of the data concerned.
Scope of This Policy
This policy applies to personal information collected through this website, through email and telephone contact, through proposals and contracts, and through the delivery and support of our services. It does not apply to any third party website that may be reached from a link on our pages, because those sites operate their own privacy practices and their own notices apply.
Where we process personal information on behalf of a client as part of an integration, cloud, support or data engagement, our handling of that information is governed by a written data processing agreement. Such agreements set out the instructions we follow, the security measures we apply, the sub-processors we may use and the way information is returned or deleted when the engagement ends. The general commitments in this policy continue to describe the standards we hold ourselves to.
We may update this policy from time to time to reflect changes in our practices or in the law. When we make a material change we will update the date shown at the foot of this page and, where appropriate, provide a more prominent notice. Continued use of our website or services after an update indicates that you accept the revised policy.
Information We Collect
We collect only the information we need to respond to enquiries, provide our services and run our business. The categories of personal information we may collect include the following.
Contact details
When you contact us we may collect your name, email address, telephone number, employer or organisation name, job title and postal address. This information is used to reply to you, to prepare proposals and to maintain our records of professional relationships.
Project information
When we discuss a potential or active engagement we may collect information about your organisation, its systems, its requirements and the outcomes you seek. Some of this information may relate to identifiable individuals, for example where it describes named users of a system or the owners of a business process.
Website usage information
When you visit our website, our hosting infrastructure may record technical information such as the pages you request, the date and time of your visit, the referring address and a coarse indication of region. This information is used to keep the site available, secure and reasonably fast.
Billing and contract information
If you become a client we may collect the information needed to raise invoices and manage the relationship, including billing contact details, purchase order references and correspondence relating to the engagement.
We do not seek to collect special category information, such as information about health, beliefs or ethnicity, through this website, and we ask that you do not send such information to us unless it is genuinely necessary for a matter you have raised with us.
How We Collect Information
Most of the personal information we hold is provided directly by the people it concerns. You may provide information when you complete the contact form on our website, when you send us email, when you telephone the studio, when you meet us at an event or when you enter into a contract with us.
We may also generate information in the course of our work. For example, we may keep notes of meetings, records of correspondence, summaries of design decisions and logs of support activity. Where a client provides information about its own users so that we can complete an engagement, we receive that information from the client rather than from the individuals concerned, and we process it on the client instructions.
A limited amount of technical information is collected automatically by our hosting and security infrastructure when you interact with the website. We do not use intrusive tracking, and we do not attempt to identify individual visitors from technical logs except where this is necessary to investigate an incident or to protect the service.
Lawful Basis for Processing
Where data protection law requires us to identify a lawful basis, we rely on one or more of the following grounds. We rely on your consent when you voluntarily submit information through the website or when you subscribe to a communication and confirm that you wish to receive it.
We rely on the performance of a contract, or on steps taken at your request before entering a contract, when we correspond with you about a proposed or active engagement. We rely on our legitimate interests when we manage our professional relationships, improve our services, keep our systems secure and protect our business against fraud or misuse, provided that our interests are not overridden by your rights.
We rely on legal obligation where we must keep records for tax, accounting or other regulatory purposes. Where we process information on behalf of a client, the lawful basis is determined by the client as controller, and we follow the client written instructions.
How We Use Information
We use personal information to respond to enquiries, prepare proposals, deliver and support the services you have commissioned, and administer our contracts. We use it to communicate with you about the work in hand, to raise invoices, to keep accurate business records and to meet our legal and regulatory duties.
We also use information to improve our services. This may include reviewing how enquiries are handled, understanding which parts of our website are useful, and learning from completed projects so that future work is better designed. When we use information for this purpose we seek to minimise the amount of personal data involved and we prefer aggregated or anonymised forms where they are sufficient.
We may use contact details to send you information about our services where you have asked to receive it or where we have a relevant existing relationship and the law permits it. Every such communication includes a straightforward way to opt out, and we honour opt out requests promptly.
We do not use personal information for automated decision making that produces legal effects, and we do not build profiles of individuals for advertising purposes.
International Transfers
Some of our suppliers operate infrastructure in more than one country. Where personal information is transferred outside the United Kingdom or the European Economic Area, we take steps to ensure that it continues to receive an equivalent standard of protection. These steps may include relying on an adequacy decision, using approved contractual clauses, or applying additional safeguards where the circumstances require them.
We keep a record of the transfers we rely on and review them when our suppliers or their infrastructure change. If you would like to know more about the safeguards that apply to a particular transfer, you may contact us using the details at the end of this policy.
Where a client engagement involves data that the client has chosen to host in a particular region, we follow the client instructions and the terms of the relevant processing agreement, which may contain additional requirements.
How Long We Keep Information
We keep personal information only for as long as it is needed for the purpose for which it was collected, for as long as the law requires, or for as long as is necessary to protect our legitimate interests. The appropriate period depends on the nature of the information and the reason it is held.
Enquiries that do not lead to an engagement are generally retained for a reasonable period so that we can follow up and maintain a record of the conversation, after which they are reviewed and deleted or anonymised. Records relating to active and completed engagements are kept for the period required by contract and by law, including tax and accounting rules.
When a retention period ends we delete or anonymise the information in a controlled manner. Where information has been provided to us by a client, we return or delete it in line with the processing agreement when the engagement ends.
How We Protect Information
The security of personal information is central to our work. As a systems design consultancy we apply the same discipline to our own environment that we apply to our clients. Access to systems is granted on the principle of least privilege, authentication is required for administrative access, and activity is logged so that unusual behaviour can be detected.
We protect information in transit using encryption, and we protect stored information using encryption where the platform supports it. We keep software up to date, we review our suppliers periodically, and we maintain recovery arrangements so that services can be restored if something fails. Staff receive training on data protection and security, and they are bound by confidentiality obligations.
No method of transmission or storage is completely secure. We take reasonable steps to protect personal information, and we maintain procedures to respond to any incident that affects it. If a breach occurs that is likely to result in a risk to your rights, we will notify you and the relevant authority as the law requires.
Your Rights
Subject to the conditions in data protection law, you have a number of rights in relation to your personal information. You have the right to be informed about how your information is used, which is the purpose of this policy. You have the right of access to the information we hold about you, and the right to receive a copy of it.
You have the right to have inaccurate information corrected and, in some circumstances, to have information erased. You have the right to restrict the way we use your information while a concern is investigated, and the right to object to processing that we carry out on the basis of legitimate interests or for direct marketing.
Where we process information on the basis of consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal. Where processing is carried out by automated means on the basis of consent or contract, you may have the right to receive your information in a portable format.
To exercise any of these rights, contact us using the details at the end of this policy. We will respond within the time allowed by law and will explain our decision if we are unable to comply with a request in full.
Privacy for Children
Our website and services are intended for organisations and for adults acting in a professional capacity. They are not directed at children, and we do not knowingly collect personal information from children. If you believe that a child has provided personal information to us, please contact us so that we can investigate and, where appropriate, delete the information.
Where an engagement with a client involves data relating to children, we handle that data strictly in accordance with the client written instructions and with the additional protections that the law provides for younger people.
We encourage parents and guardians to discuss online privacy with the young people in their care, and to help them understand how information may be collected and used.
Marketing Communications
We send marketing or informational communications only where we are permitted to do so. This may be because you have asked to receive them, or because you are an existing contact and the law allows us to send you relevant information about similar services.
Every marketing message includes a simple way to stop receiving further messages. You may also contact us at any time and ask to be removed from our contact list. We record and respect opt out requests, and we do not pass your details to other organisations for their own marketing.
Transactional and service messages, such as a reply to an enquiry or an update about work in hand, are not marketing and continue while the relevant matter is active or while we are required to keep the record.
Third Party Services
Our website may link to third party services that we do not control, including professional networks and external resources. When you follow such a link you leave our site, and the privacy notice of the destination applies. We encourage you to read the privacy notice of any service you use.
We may embed a small number of tools to help us operate, such as forms processing or email delivery. These tools act on our instructions and are bound by terms that protect the information they handle. We review them as part of our supplier management process, and we change them when a better or safer option is available.
We are not responsible for the content or the practices of third party sites, but we do take reasonable care when choosing the services we use and when deciding what to link to.
Changes to This Policy
We may update this policy to reflect changes in our practices, in our services or in the law. When we update it we will revise the date shown at the foot of the page. Where a change is significant we will provide a clearer notice, and where the law requires it we will ask for your consent before applying the change to information we already hold.
We encourage you to review this policy from time to time so that you remain aware of how your information is protected. The current version is always the one published on this page.
Complaints and Contact
If you have a question or a concern about how we handle personal information, please contact us first. We would like the opportunity to understand the issue and to put it right. You can write to YTR INNOVATION LTD at 110 Grove Road, Walthamstow, London - E17 9BY, United Kingdom (GB), send email to technology@ytrinnovation.surf, or telephone +17197168182.
If you are not satisfied with our response, you have the right to raise the matter with the data protection authority in the country where you live or work, or in the country where the issue occurred. In the United Kingdom the competent authority is the Information Commissioner Office.
We keep a record of privacy questions and complaints so that we can learn from them and improve. We always aim to resolve concerns quickly and fairly, and to explain clearly what we have done and why.
Detailed Retention Schedule
The following schedule describes in outline how long we keep common categories of information. It is provided for transparency and does not override any longer period that the law or a contract may require.
Website enquiries
Enquiries made through the contact form or by email are retained while the conversation is active and for a period afterwards so that we can follow up and keep a record of our professional relationships. When that period ends, the information is reviewed and deleted or anonymised.
Client engagement records
Records relating to a contract, including correspondence, design documents, delivery evidence and support logs, are kept for the duration of the engagement and for a period afterwards in line with contractual, tax and accounting requirements.
Financial records
Invoices, payment records and related accounting information are retained for the period required by tax and accounting law in the relevant jurisdiction.
Security and access logs
Technical logs generated by our infrastructure are retained for a limited period sufficient to detect and investigate incidents, after which they are deleted or aggregated.
When a retention period expires, we make sure that the information is removed from active systems and from backups as those backups are cycled, in line with our data management procedures.