Data Privacy ServicesPortal home

DATA PRIVACY SERVICES

Privacy Policy

Version 1.0 · Prepared 18 September 2026

1. Who this notice covers

This notice explains personal information use in the DPS Client Portal. Data Privacy Services is the trading name of Data Privacy and Data Security Services Limited, a company registered in Cyprus under company number HE 432380. Contact us at info@dataprivacyservices.co.uk. Our registered address is Griva Digeni 51, Athineon Court, Office 202, 8047 Paphos, Cyprus.

DPS determines how account administration, service communications and portal security information are used. For records and documents processed on a client organisation’s instructions, that organisation normally determines the purposes and is the controller; DPS’s responsibilities are governed by the agreed service and data processing terms. The organisation’s own privacy notice applies to that processing.

2. Information used by the portal

  • Account and business contact information: name, email, organisation, role, access permissions and profile details.
  • Service content entered by authorised users: tasks, support conversations, incidents, risk assessments, registers, questionnaires, meeting information and uploaded documents.
  • Operational information: sign-in/session information, activity and audit records, security events and technical information needed to operate the portal.
  • AI feature inputs and outputs, including chat messages, requested guidance and questionnaires submitted for ROPA development.

Information comes from you, your organisation, authorised DPS staff and the identity provider used for sign-in. Client records may contain information about other people. Upload only information necessary for the service and ensure your organisation has authority to provide it. Some services may involve sensitive information; the client organisation must identify the applicable legal basis and any additional condition for that processing.

3. Purposes and legal grounds

We use account and contact information to provide access, administer client relationships and answer requests. Our legitimate interests are delivering contracted business services and communicating with authorised users. Where the individual is themselves a contracting party, necessary processing may instead be based on that contract.

We use security and audit information to protect accounts, investigate misuse and maintain the service, relying on our legitimate interests in operating a secure portal. We may retain or disclose information where required by law. Optional activities that require consent must offer a separate choice; access to the portal is not consent to unrelated marketing. Client-controlled service data is handled on documented instructions under the applicable processing agreement.

4. Who can receive information

Portal access is linked to organisations and authorised roles. Client users can access their organisation’s permitted records; authorised DPS staff provide the contracted services. Relevant infrastructure providers support delivery: Hostinger for hosting and storage, Microsoft for identity and configured email/calendar functions, and OpenAI for enabled AI functions. Supplier use, subprocessors and processing terms must be documented in the service’s supplier records. Professional advisers or public authorities may receive information where necessary and lawful.

Emails and calendar invitations are sent to the recipients selected or configured for the relevant workflow. Check recipients before sharing guidance, attachments or meeting details. Links to external websites take you to services governed by their own notices.

5. AI-assisted features

Using an AI function sends the relevant prompt, conversation context or submitted questionnaire content to the configured AI service. Do not include unnecessary personal information. AI answers and generated ROPA entries are drafts for human checking and may contain errors. The portal does not itself make decisions producing legal or similarly significant effects about individuals. Provider-side retention and international processing arrangements must be confirmed in the applicable supplier terms; this notice does not promise zero retention or a particular processing location.

6. Cookies and browser storage

The portal uses essential session and security mechanisms for authentication and safe requests. The current account session is configured with a one-hour lifetime. Microsoft’s sign-in service uses its own authentication mechanisms. Browser storage may retain feature state. Signing out is recommended on shared devices. Blocking essential cookies may prevent sign-in. Any future optional analytics or advertising storage must be assessed and, where required, offered through a consent choice before activation.

7. Retention and deletion

Account information is needed while access and the client relationship are active. Service records and documents are retained according to the client’s instructions and agreed retention arrangements. Security, audit, correspondence and contractual records require periods proportionate to incident investigation, service administration and applicable legal obligations. Backup expiry and deletion arrangements depend on the hosting service. Contact DPS for the retention schedule and deletion procedures applicable to your service. Closing a log item or signing out does not itself delete the record.

8. Security and international processing

The portal uses HTTPS, authenticated access, organisation-based permissions and activity auditing. Access should be restricted to approved accounts, with identity-provider verification completed when requested. No online service can guarantee absolute security. Storage and backup encryption details remain subject to hosting verification and are not asserted here.

Supplier processing or support access may involve countries outside the UK or EEA. Any restricted transfer needs an applicable adequacy decision or appropriate safeguards and the required assessment. Ask DPS for the relevant destinations and safeguards for your service; the applicable arrangements are set out in supplier and processing documentation.

9. Your rights and complaints

Depending on the circumstances, you may request access, correction, erasure, restriction or portability, object to processing, or withdraw consent where processing relies on it. Contact info@dataprivacyservices.co.uk. We may need proportionate identity verification. Where your organisation controls the information, we will direct or assist your request through it.

You may complain to DPS and to a relevant supervisory authority, including the UK Information Commissioner’s Office or the Cyprus Commissioner for Personal Data Protection. You do not have to contact DPS before exercising that right.

10. Changes

The version and date above identify this notice. Material changes will be communicated through the portal or appropriate service communications. This notice supplements the relevant client agreement and processing terms.

Contact: info@dataprivacyservices.co.uk

© 2026 Data Privacy Services · ISMS Workspace
Privacy PolicyTerms and Conditions

If you like this portal, find out how we can help your organisation – contact smartflowai.uk