Privacy notice
How VAIR LTD processes personal data under the UK General Data Protection Regulation and the Data Protection Act 2018. Written to be read, not to be survived.
1About this notice
This notice explains what personal data VAIR LTD handles, why, on what lawful basis, who else sees it, how long it is kept and what you can do about it. It satisfies Articles 13 and 14 of the UK GDPR and is written to the standard the Apple App Store and Google Play require of a published app.
Two qualifications belong at the top. VAIR LTD was incorporated on 1 January 2026 and has released no software publicly, so sections describing app behaviour are forward-looking commitments and are marked as such. And the company holds no ISO 27001 certification, no SOC 2 report and no Cyber Essentials certification, so no claim here depends on one. Unsettled details are marked [TO CONFIRM: like this] rather than filled with plausible text.
Back to contents2Who we are and how to contact us
VAIR LTD is a private company limited by shares, registered in England and Wales under company number 16938467, with its registered office at Flat 6 Caledonian Court, Highwood Close, London, SE22 8NW. In this notice "we", "us" and "the company" mean VAIR LTD.
Contact points
- All privacy matters: hello@vairworks.co.uk, using the subject line "Data protection request".
- Post: Data Protection, VAIR LTD, Flat 6 Caledonian Court, Highwood Close, London, SE22 8NW.
Data protection officer
No data protection officer has been appointed. The company does not fall within Article 37(1) of the UK GDPR: its core activities involve neither large scale regular and systematic monitoring nor large scale processing of special category or criminal offence data. Privacy correspondence reaches the address above. If the position changes, a DPO will be appointed, published here and notified to the ICO.
UK representative
The company is established in the United Kingdom, so no Article 27 representative is required.
ICO registration
[TO CONFIRM: registration status for the ICO data protection fee under the Data Protection (Charges and Information) Regulations 2018. No registration number is claimed on this site and none will be published until one exists.]
Back to contents3Our two roles: controller and processor
The company handles personal data in two legally distinct capacities. Conflating them is the commonest defect in a small company privacy notice, so they are kept separate throughout.
3.1 Where we act as controller
We are the controller, under Article 4(7) of the UK GDPR, when we decide why and how data is processed: website visitors, people who write to us, contacts at organisations we contract with, our accounting and statutory records, and end users of software we publish. There, this notice is the notice and you exercise your rights against us.
3.2 Where we act as processor
We are a processor, under Article 4(8), when we handle data on a client's documented instructions during an engagement. A build system belongs to the client: its logs, commit metadata, user accounts and CI configuration are the client's data and the client decides the purposes and means. We set no lawful basis and decide no rights request on our own authority. See section 9.
3.3 Why the distinction matters to you
If your data appears in a client's build system, your rights run against that client. If you write to us anyway we forward the request without undue delay and tell you we have. We do not silently absorb a request we have no authority to answer.
Back to contents4Role markers used in this notice
Every section below carries a marker under its heading, so you never have to infer which capacity is in play.
- Role: controller VAIR LTD decides the purposes and means. The section applies to you directly.
- Role: processor A client decides the purposes and means. VAIR LTD acts only on their documented instructions.
5Website visitors
vairworks.co.uk is a set of static files: no database, no login, no comment system, no contact form, no analytics script, no tag manager, no advertising pixel, no embedded video and no third party widget. Nothing on the page contacts any host other than the site itself and Google Fonts, which serves the two typefaces. What processing occurs is the ordinary technical processing needed to deliver a page, performed by our hosting provider at the network edge.
| Category | Example fields | Source | Purpose | Lawful basis | Retention | Recipients |
|---|---|---|---|---|---|---|
| Connection data | IP address, timestamp, requested URL, HTTP status, bytes served, user agent string, TLS version | Observed automatically by the hosting provider when your browser requests a page | Delivering the page, terminating TLS, and defending the site against denial of service and abusive traffic | Article 6(1)(f), legitimate interests. The interest is keeping the company website available and resistant to attack. | Held by the hosting provider at the edge. We do not download, aggregate or retain these logs. See section 16. | Cloudflare, Inc. as processor |
| Font request data | IP address, user agent, referring page, sent to fonts.googleapis.com and fonts.gstatic.com | Sent by your browser when it fetches the two typefaces this site uses | Rendering the site in Newsreader and JetBrains Mono | Article 6(1)(f), legitimate interests. The interest is presenting the company's documents in the typefaces they were set in. | Not retained by us. We never see this data. | Google LLC, as an independent controller of that request |
| Cookies | None set by this site | Not applicable | Not applicable | No basis required because no processing occurs | Not applicable | None |
Table scrolls sideways on narrow screens.
If you would rather not contact Google's font hosts, blocking those two domains leaves this site fully readable. The layout degrades to the system monospace and serif faces without breaking.
6Correspondence and enquiries
If you email hello@vairworks.co.uk or write to the registered office, we process what you send in order to answer you. There is no form on this site, so everything here originated in a message you chose to send.
| Category | Example fields | Source | Purpose | Lawful basis | Retention | Recipients |
|---|---|---|---|---|---|---|
| Enquiry content | Name, email address, employer, job title, message body, attachments, any technical detail you volunteer about your build system | You, directly | Reading, triaging and answering your message | Article 6(1)(f), legitimate interests. The interest is responding to unsolicited enquiries about the company's own services. Where the exchange is preparatory to a contract, Article 6(1)(b) applies instead. | 24 months from the last message in the thread | Email provider as processor |
| Email metadata | Sending address, routing headers, timestamps, spam scoring | Generated by mail transport | Delivering mail and filtering spam | Article 6(1)(f), legitimate interests. The interest is operating a working mailbox that is not flooded with abuse. | 24 months, alongside the message | Email provider as processor |
| Rights requests | Your identity, the right invoked, evidence you supply, our response and its date | You, directly | Handling the request and being able to show we handled it | Article 6(1)(c), legal obligation, read with Articles 12 to 22 | 12 months after the request closes | Email provider as processor |
| Security reports | Reporter's contact details, technical description, proof of concept material | You, directly | Investigating and fixing a reported issue, and replying to the reporter | Article 6(1)(f), legitimate interests. The interest is correcting security defects in material the company publishes. | 24 months after the issue is closed | Email provider as processor |
Table scrolls sideways on narrow screens.
We do not add anyone who writes to us to a marketing list. There is no marketing list. See section 26.
Back to contents7Clients, contracts and accounting
If the company contracts with an organisation, we process data about the individuals who act for it: the person who signs, the person who is invoiced, the engineers we correspond with. We are controller because we decide what is needed to run a contract and keep lawful books.
| Category | Example fields | Source | Purpose | Lawful basis | Retention | Recipients |
|---|---|---|---|---|---|---|
| Client contacts | Name, business email, telephone, role, organisation | The client organisation, or the individual directly | Negotiating, agreeing and performing an engagement | Article 6(1)(b) where the individual is the contracting party; Article 6(1)(f) where they act for a company. The interest is administering a business relationship with the organisation that engaged us. | Six years after the engagement ends | Email provider; accounting software provider |
| Contract records | Signed scope documents, statements of work, change notes, signatory name and date | Both parties | Evidencing what was agreed, and defending or bringing a claim if one arises | Article 6(1)(b) for performance; Article 6(1)(f) for retention beyond it. The interest is being able to prove the terms of a contract for as long as a claim on it is possible. | Six years after the engagement ends, matching the Limitation Act 1980 period for simple contract claims | Accountant; professional advisers if a dispute arises |
| Billing and payment | Invoice number, amount, dates, purchase order reference, bank details supplied for payment, VAT details where applicable | The client; our bank | Raising invoices, collecting payment, and keeping the accounting records a company must keep | Article 6(1)(c), legal obligation, under section 386 and section 388 of the Companies Act 2006 and HMRC record keeping requirements | Six years from the end of the financial year in which the transaction falls | Accountant; bank; HMRC and Companies House where required by law |
| Supplier contacts | Name, business email, role at a supplier or professional adviser | The supplier | Buying the services the company needs to operate | Article 6(1)(f), legitimate interests. The interest is procuring and administering the company's own supplies. | Six years after the supply relationship ends | Accountant |
Table scrolls sideways on narrow screens.
No client has been contracted as at the effective date. The inventory above describes the processing that will occur when one is, published in advance so a prospective client can read it before signing rather than after.
Back to contents8Recipients and sub-processors
We do not sell personal data and do not share it for anyone else's marketing. The organisations below are the only recipients. Where a supplier has not been selected, the row says so rather than naming a plausible one.
| Recipient | Role | What they handle | Location of processing | Transfer mechanism |
|---|---|---|---|---|
| Cloudflare, Inc. | Processor. Website hosting, CDN and DNS for vairworks.co.uk via Cloudflare Pages. | Connection data at the network edge: IP address, request line, user agent, timestamps. | Global edge network, including the United States | UK International Data Transfer Addendum to the EU Standard Contractual Clauses, incorporated in Cloudflare's data processing terms |
| Google LLC (Google Fonts) | Independent controller of the font request your browser makes. | IP address and user agent of the request for the two font files. | Global, including the United States | Governed by Google's own terms. We are not a party to that processing and cannot vary it. |
| Email provider | Processor. Hosting the hello@vairworks.co.uk mailbox. | All correspondence and its metadata. | [TO CONFIRM: provider and processing location not yet fixed] | [TO CONFIRM: to be the UK IDTA or the UK Addendum, depending on the provider selected] |
| Accounting software and accountant | Processor (software) and independent controller (the accountant, for their own professional obligations). | Invoices, client contact details, payment records. | [TO CONFIRM: neither has been appointed as at 7 August 2026] | [TO CONFIRM: expected to be UK based, in which case no transfer mechanism is needed] |
| Domain registrar | Processor for registration data; some registration data is also published or disclosed under ICANN policy. | Registrant contact details for vairworks.co.uk. | [TO CONFIRM: registrar not disclosed on this site] | Registrar's own data processing terms |
| Professional advisers | Independent controllers. | Only what is necessary for legal, tax or insurance advice, and only if a matter arises. | United Kingdom | No transfer |
| Public authorities | Independent controllers. | Data we are legally required to disclose, for example to HMRC, Companies House, the ICO, a court or a regulator. | United Kingdom | No transfer |
| A buyer of the business | Independent controller. | Records transferring with the business, if the company is ever sold or reorganised. | Depends on the buyer | Assessed at the time. Data subjects would be told before their data moved. |
Table scrolls sideways on narrow screens.
When we act as processor for a client, we will not engage any sub-processor without the client's prior written authorisation, and we will pass down the same data protection obligations we owe them, as Article 28(4) requires.
Back to contents9Engagement data on client systems
During an engagement we may be given access to a client's repository, CI configuration, build logs and metrics. Those records contain personal data incidentally: commit author names and addresses, usernames in build logs, whoever triggered a pipeline. The client is the controller of all of it.
9.1 What we commit to
Before access begins, a written contract meeting Article 28(3) of the UK GDPR is in place. Under it we commit, as contractual obligations, to:
- process the data only on the client's documented instructions, including on transfers, and flag any instruction we believe breaks data protection law;
- put everyone we authorise under a duty of confidence;
- apply the Article 32 measures described in section 17;
- engage no sub-processor without prior written authorisation;
- assist with rights requests, security, breach notification and any impact assessment;
- delete or return the data at the end of the engagement, at the client's choice;
- provide what the client needs to demonstrate compliance, and submit to audits.
9.2 What we ask clients to do
We prefer reduced data. Where an investigation can run on a redacted log or an anonymised metrics export we ask for that rather than raw access. Minimisation at handover is cheaper than deletion afterwards.
9.3 Rights requests reaching us by mistake
A rights request about a client's system is passed to the client without undue delay and you are told. Article 28 gives a processor no authority to decide it.
Back to contents10Software we have not yet published
The company is building command line and service software for build systems. As at the effective date nothing has been released, in any channel, to anyone. This section is a set of design commitments governing the first release, and will be replaced by a factual description on the day that release happens.
- No telemetry by default. If usage telemetry is added it will be off unless switched on, and the exact fields sent will be listed here before it ships.
- No advertising identifiers. The software will not read the iOS Identifier for Advertisers, the Android Advertising ID or any equivalent.
- No third party analytics or advertising SDKs.
- Build content stays with the build. Source, logs and cache contents are the user's and are not transmitted to us. A self-hosted cache tier will let them stay on the user's own infrastructure entirely.
- Crash reporting, if added, will be opt in, will strip file paths and environment values before transmission, and will be named here with its provider.
If a commitment has to change, this notice changes first and section 28 records it. We will not ship a data practice and document it afterwards.
Back to contents11Special category and criminal offence data
Special category data means the categories in Article 9(1) of the UK GDPR: racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for identification, health data, and data concerning sex life or sexual orientation. Criminal offence data is governed by Article 10 and section 10(5) of the Data Protection Act 2018.
11.1 Our position
We do not seek, request or intentionally process either, in either role. Nothing in the website, the correspondence process, the contracting process or the planned software asks for it, so no Article 9(2) condition and no Schedule 1 condition is currently relied on.
11.2 If it arrives anyway
Someone might volunteer it in an email, for instance a health reason for a delay. That data is incidental and unsought. We use it only to read the message it appears in, copy it into no other record, and delete it when the retention period in section 16 expires. Where it is retained at all it is because the message is, and the condition would be Article 9(2)(f), legal claims, read with paragraph 33 of Schedule 1 to the Data Protection Act 2018.
11.3 Please do not send it
The company never needs it from you. If a message would otherwise contain it, leave it out.
Back to contents12Your rights under UK GDPR
These rights apply where VAIR LTD is the controller. Where we are a processor the same rights exist but you exercise them against our client (section 3). Exercising any is free. Section 13 covers the mechanics.
12.1 The right to be informed
Articles 13 and 14 entitle you to know what we do with your data. This notice discharges that, and is specific about fields, bases and periods rather than gesturing at categories.
12.2 The right of access
Article 15 lets you ask whether we process data about you and receive a copy, with the purposes, categories, recipients, retention periods, the source if it did not come from you, and your other rights. We supply it electronically unless you ask otherwise. We may redact where disclosure would adversely affect another person's rights, and we say when we have redacted.
12.3 The right to rectification
Article 16 lets you have inaccurate data corrected and incomplete data completed. Send the correct version and we amend the record. Where the data went to a recipient in section 8 we tell them, unless that is impossible or disproportionate, and we tell you who was told.
12.4 The right to erasure
Article 17(1) lets you ask for deletion where the data is no longer necessary, you withdraw the consent it relied on, you object successfully, it was processed unlawfully, or the law requires erasure. The right is not absolute. We refuse, naming the exemption, where a legal obligation requires retention, most often the six year accounting period in section 16, or where the data is needed for a legal claim. We then restrict it instead, so it sits unused until its period expires.
12.5 The right to restrict processing
Article 18 lets you require us to stop using data while something is resolved: an accuracy check, an objection, or in place of deletion where you need it preserved for a claim. Restricted data is retained but not otherwise processed, and we tell you before any restriction is lifted.
12.6 The right to data portability
Article 20 applies where processing rests on consent or a contract with you and is automated. You may then receive the data you provided in a structured, commonly used, machine readable format and ask us to transmit it to another controller where technically feasible. Most of what we hold rests on legitimate interests, so this right is often not engaged. We say which parts qualify rather than refusing outright.
12.7 The right to object
Article 21(1) lets you object to legitimate interests processing on grounds relating to your particular situation. We must stop unless we can demonstrate compelling legitimate grounds overriding your interests, rights and freedoms, or the processing is for legal claims. Article 21(2) gives an absolute right to object to direct marketing. We do none, so only the first limb arises.
12.8 The right to withdraw consent
Article 7(3) lets you withdraw consent at any time, as easily as it was given, without affecting the lawfulness of what was done beforehand. The company relies on consent for nothing, which is why no consent banner appears on this site.
12.9 Rights relating to automated decisions
Article 22 gives you the right not to be subject to a decision based solely on automated processing producing legal or similarly significant effects. We take none. See section 19.
12.10 The right to complain
Article 77 lets you complain to the Information Commissioner's Office. Details in section 27. You need not come to us first, though direct complaints are usually faster to fix.
Back to contents13How to exercise a right, and what we ask for
13.1 How to ask
Email hello@vairworks.co.uk with the subject "Data protection request", or write to Data Protection, VAIR LTD, Flat 6 Caledonian Court, Highwood Close, London, SE22 8NW. No particular wording is needed. It helps if you say which right you are invoking and, for access, whether you want everything or a defined slice.
13.2 Verifying who you are
Article 12(6) allows us to ask what is necessary to confirm your identity where we have reasonable doubts. Our approach is proportionate rather than reflexive.
- Writing from the address the data is attached to is normally enough.
- From a different address, we ask you to reply from the original one or supply another fact only you would know, such as the date and subject of the correspondence.
- We ask for photographic identity documents only where the request is broad, the data sensitive, or the risk of disclosure to the wrong person real. If we ask, we explain why, accept a redacted copy, and delete it within 30 days.
The one month clock starts when we have what we need to identify you, and we ask promptly rather than sitting on a request.
13.3 Timing
We respond without undue delay and within one month, as Article 12(3) requires. Where a request is complex, or you have made several, we may extend by up to two further months, telling you within the first month and explaining why. We aim to acknowledge within five working days.
13.4 When we can refuse, and what happens then
Article 12(5) lets us refuse, or charge a reasonable fee, where a request is manifestly unfounded or excessive, in particular because it is repetitive. Rights are also subject to the exemptions in Schedule 2 to the Data Protection Act 2018, including legal professional privilege and confidential references. Beyond that: erasure can be refused where a legal obligation or claim requires retention; access can be partly refused where disclosure would adversely affect another person, in which case we redact rather than withhold everything; and portability does not apply where the basis is legitimate interests or legal obligation.
Any refusal is given within one month with the reason, and with your right to complain to the ICO and to seek a judicial remedy. We do not refuse silently, and we do not treat an awkward request as an excessive one.
13.5 Cost
Exercising a right is free. A fee arises only in the narrow case above, and we would state the amount and its basis in writing before doing any work.
Back to contents14Lawful bases and our named legitimate interests
Each activity above carries its basis in the inventory table. This section collects the legitimate interests in one place, because "legitimate interests" alone is a category, not a disclosure. Each has been assessed against the three part test: is the interest legitimate, is the processing necessary for it, and does it override the individual's interests, rights and freedoms.
| Activity | The interest, named | Why the processing is necessary | Balancing outcome |
|---|---|---|---|
| Serving the website | Keeping the company website available and resistant to attack | A web server cannot answer a request without the requester's IP address, and cannot resist abusive traffic without observing patterns in it | Low impact. Data stays at the provider's edge, is not enriched, is not linked to any identity we hold, and is not read by us. |
| Web fonts | Presenting the company's documents in the typefaces they were set in | The browser must fetch the files from the host that serves them | Low impact and avoidable by the reader: blocking the two font hosts leaves the site fully usable. |
| Answering enquiries | Responding to unsolicited enquiries about the company's own services | We cannot answer a message without processing it | Expected by the sender, who initiated it. No secondary use, no profiling, no marketing. |
| Running a mailbox | Operating a working mailbox that is not flooded with abuse | Spam filtering requires inspection of headers and content | Low impact and universally expected of any email service. |
| Administering business relationships | Administering a business relationship with the organisation that engaged us | A contract with a company is performed through named individuals at that company | Business contact data, processed in a professional context, with no surprise to the individual. |
| Keeping contract evidence | Being able to prove the terms of a contract for as long as a claim on it is possible | A claim can be brought for six years under the Limitation Act 1980 | Data is archived, not used. Restriction is applied on request where the record must be kept. |
| Security reports | Correcting security defects in material the company publishes | A report cannot be investigated or answered without processing it | Reporter initiated. We keep only what the fix and the reply require. |
| Procurement | Procuring and administering the company's own supplies | Suppliers are contacted through named people | Business contact data in a professional context. |
Table scrolls sideways on narrow screens.
You can object to any of these under Article 21(1). A successful objection stops the processing. An unsuccessful one gets the compelling grounds explained, not asserted.
Back to contents15International transfers
Some services we depend on process data outside the United Kingdom. Chapter V of the UK GDPR permits that only under a defined mechanism. The mechanism for each recipient is named in section 8.
15.1 Adequacy regulations
Where the destination is covered by UK adequacy regulations under section 17A of the Data Protection Act 2018, no further mechanism is needed. That covers the EEA states, the other countries the UK has recognised, and United States organisations certified under the UK Extension to the EU-US Data Privacy Framework, the UK-US data bridge.
15.2 The IDTA
Where adequacy does not apply we use the International Data Transfer Agreement issued by the Information Commissioner under section 119A of the Data Protection Act 2018, a standalone contract for a restricted transfer, used where a supplier allows a UK specific agreement.
15.3 The UK Addendum to the EU SCCs
Most global suppliers contract on the EU Standard Contractual Clauses. Where they do we rely on the International Data Transfer Addendum to those clauses, also issued under section 119A, which modifies them to work as a UK transfer tool. This is the mechanism in Cloudflare's data processing terms and the one we expect for the email provider.
15.4 Transfer risk assessment
A transfer tool alone is not enough. Before relying on either we assess the destination's law and practice on government access, the nature and volume of the data, and whether measures such as encryption in transit and at rest reduce the risk acceptably. Given the small volume and the absence of special category data the assessment is short, but it is done rather than assumed.
15.5 Getting a copy
Article 15(2) lets you ask for a copy of the safeguards, at hello@vairworks.co.uk. For published supplier terms we point you to them; for a negotiated agreement we supply the relevant parts, redacted for commercial terms.
Back to contents16Retention
Article 5(1)(e) requires that data be kept only as long as the purpose needs. Every period below has a stated reason. A period with no reason behind it is a habit, and habits are how data accumulates.
| Record | Period | Clock starts | Reason for that period | At the end |
|---|---|---|---|---|
| Edge connection logs | Held by Cloudflare under its own retention policy. We hold no copy. | On request | We have no operational need for them, so the shortest retention is the one where we never take delivery in the first place | Deleted by the provider |
| General correspondence | 24 months | Last message in the thread | Long enough for a conversation to resume naturally after a pause, short enough that stale enquiry data does not sit in a mailbox for years | Deleted |
| Rights request records | 12 months | Date the request is closed | Article 5(2) accountability: we must be able to show a request was handled properly, but not indefinitely | Deleted |
| Security reports | 24 months | Date the issue is closed | Time to detect a regression of the same defect and to credit the reporter if they ask | Deleted, or anonymised if kept as a technical note |
| Contract and engagement records | 6 years | End of the engagement | The Limitation Act 1980 allows a claim on a simple contract to be brought for six years, so evidence of what was agreed must survive that long | Deleted |
| Accounting records | 6 years | End of the financial year the transaction falls in | Statutory. Sections 386 and 388 of the Companies Act 2006 require adequate accounting records to be kept for six years for a private company, and HMRC requires the same for company tax records | Deleted |
| Statutory company registers | As required by the Companies Act 2006 | Entry made | Statutory obligation on the company, not a discretionary period | Retained as required |
| Identity evidence supplied for a rights request | Up to 30 days | Date identity is confirmed | It exists only to answer one question, so it is destroyed as soon as that question is answered | Deleted |
| Breach records | 6 years | Date the incident is closed | Article 33(5) requires a record of every breach sufficient for the ICO to verify compliance; six years aligns it with the other statutory periods | Reviewed and deleted |
| Client data held as processor | Duration of the engagement | Contract end | Article 28(3)(g): a processor deletes or returns the data at the end of the service, at the controller's choice | Deleted or returned as the client directs |
Table scrolls sideways on narrow screens.
Deletion means removal from live systems immediately and from routine backups as they age out of their cycle. A record restricted rather than deleted under section 12.5 is retained but not used.
Back to contents17Security
Article 32 requires measures appropriate to the risk. What follows is what the company does. It contains no certification claim, because the company holds none.
- The site is served over HTTPS only, with HSTS set and the response headers in the site's
_headersfile restricting framing, content type sniffing and referrer leakage. - There is no server-side application, no database and no admin interface, which removes a class of risk rather than mitigating it.
- Accounts administering the domain, the hosting and the mailbox have multi-factor authentication enabled.
- Devices used for company work have full disk encryption and automatic screen locking.
- Access to a client system uses credentials the client issues, scoped to the work and revoked by them at the end.
- Client material is not copied to personal accounts or personal devices.
- Suppliers are chosen partly on their published security posture and bound by written processing terms.
Plainly: VAIR LTD does not hold ISO 27001 certification, a SOC 2 report or Cyber Essentials certification, and will not represent otherwise. If any is obtained it will be named here with its scope and certificate number, not shown as a badge.
18Personal data breaches
A personal data breach is a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. It is not only a hack. Sending an attachment to the wrong recipient counts.
18.1 The process
- Contain. Revoke the credential, invalidate the disclosure, isolate the account.
- Record. Open a breach record: what happened, when discovered, the categories and approximate number of individuals and records, the likely consequences and the measures taken. Article 33(5) requires this whether or not the breach is reportable.
- Assess. Decide whether the breach is likely to result in a risk to individuals' rights and freedoms.
- Report where required. If there is such a risk, notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware, as Article 33(1) requires, giving reasons for any delay. Where no notification is needed the reasoning goes in the record.
- Tell the individuals where required. Where the breach is likely to result in a high risk, Article 34 requires us to tell them without undue delay, in clear and plain language, describing the breach, our contact point, the likely consequences and the measures taken.
- Fix and review. Remove the cause and record what changed.
18.2 Exceptions to telling individuals
Article 34(3) removes that duty where the data was rendered unintelligible, for example by strong encryption; where later measures mean the high risk is no longer likely; or where individual notification would take disproportionate effort, in which case a public communication is made instead. We record which exception applied and why.
18.3 When we are the processor
Article 33(2) requires a processor to notify the controller without undue delay. The client is told first, promptly, with everything we know. Whether to notify the ICO and affected individuals is their decision. We do not notify on a client's behalf unless the contract asks us to.
Back to contents19Automated decision-making and profiling
We take no decisions about you based solely on automated processing that produce legal or similarly significant effects, within the meaning of Article 22, and we do no profiling. There is no scoring, ranking, automated eligibility assessment or algorithmic content selection anywhere in the company's operations.
Mailbox spam filtering is automated, but it decides which folder a message lands in, which is not a decision with legal or similarly significant effect. If it catches a legitimate message, telling us by another route is the fastest fix.
Back to contents20Children
This website and the software being built are aimed at professional engineering teams. They are not directed at children, carry no content designed to appeal to children, and we do not knowingly collect data from anyone under 13. Any published app will be age rated accordingly and will not appear in a children's category.
If you believe a child's data has reached us, tell us at hello@vairworks.co.uk and we will delete it. Because the services are not information society services offered directly to a child, the Article 8 consent age does not arise and the ICO's Age Appropriate Design Code is not engaged. If that changes, this section is rewritten before the change ships.
Back to contents21Device permissions in published apps
The company has published no mobile application as at 7 August 2026. The table below is the permission policy that will govern the first one, published in advance so it can be checked against the app when it appears. "Not requested" means the permission will not be declared in the manifest or the Info.plist at all, which is stronger than declaring it and promising not to use it.
| Permission | Purpose | Required or optional | If you decline | How to revoke, iOS | How to revoke, Android |
|---|---|---|---|---|---|
| Notifications | Telling you a long-running build or cache warm has finished | Optional | The app works normally. You check build status in the app instead of being told. | Settings, then the app's entry, then Notifications, then Allow Notifications off | Settings, then Apps, then the app, then Notifications, then off |
| Local network | Reaching a self-hosted cache or build agent on the same network as your device | Optional | Only remote endpoints reachable over the internet can be used. Self-hosted local endpoints will not be found. | Settings, then the app's entry, then Local Network off | Not a separate Android permission. Network access is governed by the app's normal internet permission. |
| Camera | Not requested | Not requested | Not applicable | Not applicable | Not applicable |
| Microphone | Not requested | Not requested | Not applicable | Not applicable | Not applicable |
| Location, precise or approximate | Not requested | Not requested | Not applicable | Not applicable | Not applicable |
| Contacts | Not requested | Not requested | Not applicable | Not applicable | Not applicable |
| Photos and media library | Not requested | Not requested | Not applicable | Not applicable | Not applicable |
| Calendar and reminders | Not requested | Not requested | Not applicable | Not applicable | Not applicable |
| Tracking, App Tracking Transparency | Not requested. See section 23. | Not requested | Not applicable | Settings, then Privacy and Security, then Tracking, controls this globally | Settings, then Privacy, then Ads, where you can delete or opt out of the advertising ID |
Table scrolls sideways on narrow screens.
Both platforms let you revoke a granted permission at any time without uninstalling. If a release genuinely needs a permission not listed here, this table is updated before that release is submitted, and the app explains the reason at the point it asks.
Back to contents22Account and data deletion
No account system exists yet, because no product has been released. Both app stores require an in-app deletion path and an external one for any app supporting account creation. The commitment below is written now so it constrains the first release.
22.1 In-app route
Any account-bearing app will carry a deletion control at Settings, then Account, then Delete account, with no requirement to contact support first, no dark pattern in the way, and a single confirmation stating what will be removed.
22.2 Email route
You may also email hello@vairworks.co.uk with the subject "Account deletion request", from the address on the account. This works whether or not the app is installed, and stays on this page for as long as any account data exists.
22.3 Timing
Deletion is acknowledged within five working days and completed within 30 days of a verified request. Live systems are cleared immediately; backups age out of their normal cycle, during which they are not accessible for any operational purpose.
22.4 What is deleted, and what is not
Deleted: your account record, profile fields, authentication credentials, settings and preferences, and any content you stored in the service.
Retained, minimally and only where the law requires: transaction and invoice records for the six year accounting retention in section 16; a record that a deletion request was made and completed, kept 12 months to evidence compliance; and anything needed for a legal claim. Retained records are restricted, held but not used, and deleted when their period ends.
22.5 Store subscriptions
Deleting an account does not cancel a subscription billed by Apple or Google. Those are cancelled in the store account: see section 6 of the terms of use. We cannot cancel or refund a store-billed subscription, because we never hold that billing relationship.
Back to contents23App Tracking Transparency on iOS
Apple's App Tracking Transparency framework requires permission before an app tracks a user across apps and websites owned by other companies, or accesses the device advertising identifier.
No app the company publishes will track you in that sense. It will not read the Identifier for Advertisers, will not link user or device data with third party data for advertising or measurement, and will not share user or device data with a data broker. It will therefore not present the ATT prompt, because there is nothing for you to permit. An app that shows the prompt without needing to is asking for something it should not have.
If a future version needed tracking as Apple defines it, this section would be rewritten first, the prompt presented properly, and the app would work for anyone who declined.
Back to contents24Google Play Data Safety consistency
Google Play requires a Data Safety declaration describing what data an app collects and shares, and it must match the app's actual behaviour and its privacy policy. Apple's Privacy Nutrition Labels impose an equivalent discipline. The following is a commitment about process, not a claim about a product that does not exist yet.
- The Data Safety form and the App Store privacy labels will be completed from this notice, so the three documents describe one set of facts.
- If a release changes what is collected or shared, this notice is updated first, then the store declarations, then the release goes out.
- Any data type declared as collected will appear in an inventory table here, with its purpose, lawful basis and retention period.
- If a declaration and this notice disagree, treat this notice as what actually happens and tell us, so the declaration can be corrected.
On the effective date, the accurate declaration would be that no app is published and therefore no data is collected by one.
Back to contents25Cookies and similar technologies
This website sets no cookies of its own and uses no local storage, session storage, IndexedDB or device fingerprinting. There is no consent banner because there is nothing to consent to, and a banner asking for permission it does not need trains people to click through the ones that matter.
Regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 governs storage of and access to information on your device. Our position under it, and the one narrow case in which the hosting provider may set a strictly necessary cookie, are in the cookie notice.
Back to contents26Marketing and PECR
The company operates no mailing list, sends no newsletter, runs no advertising and makes no marketing calls. Nobody is added to anything by writing to us. If that changes, a subscription will be opt in under regulation 22 of PECR, every message will carry a working unsubscribe link, and consent records will show who agreed, when and to what.
We do not buy contact lists and do not use them. If you received an unsolicited message claiming to be from VAIR LTD, it did not come from us, and we would like to see it.
Back to contents27Complaints and the ICO
27.1 Complain to us
Email hello@vairworks.co.uk with the subject "Data protection complaint". We acknowledge within five working days and respond substantively within one month. Say what happened and what you want done, and if we got something wrong we will say so.
27.2 Complain to the regulator
You have the right under Article 77 of the UK GDPR to complain to the Information Commissioner's Office at any time. You do not need our permission and you do not need to have complained to us first.
| Regulator | Information Commissioner's Office |
|---|---|
| Address | Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF |
| Telephone | 0303 123 1113 |
| Website | ico.org.uk/make-a-complaint |
Table scrolls sideways on narrow screens.
You also have the right to an effective judicial remedy under Articles 78 and 79, and the right to compensation for damage caused by an infringement under Article 82.
Back to contents28Changes to this notice
This notice will change, because the company is at the start of its life and several sections describe things that have not happened yet. When it does, the effective date and the revision letter at the top both change, and the table below records what moved. We do not silently edit a live document.
Where a change materially affects how we use data about you, and we hold a way of contacting you, we will tell you directly rather than relying on you noticing.
| Revision | Effective | Change |
|---|---|---|
| A | 7 August 2026 | First publication. |
Table scrolls sideways on narrow screens.
Back to contents