Legal

Privacy Policy

Last updated 26 September 2026

1. Who we are

3RDi Limited ("we", "us", "our") is the data controller for the personal data described in this policy.

  • Registered address. Flat 8 Magistrates House, Market Place, Brentford, United Kingdom TW8 8FJ
  • Company number. 11080079 (registered in England and Wales)
  • Privacy contact. privacy@3rdi.ai

We have not appointed a Data Protection Officer. We have assessed the criteria in Article 37 of the UK GDPR and concluded that our processing does not meet the threshold requiring one. The Director is accountable for data protection.

2. Scope of this policy

This policy explains how we handle personal data for which we are the controller: data about visitors to our website, our customers' authorised users, our employees, and our vendor and partner contacts.

It does not cover personal data processed within a customer's own deployment of the Prophesee Platform. We do not receive or store that data.

The Prophesee Platform is installed on the customer's own premises or in the customer's own cloud tenancy. It is not a subscription service that we host. We do not operate user accounts or authentication for platform users: each customer administers its own users entirely within its own deployment, and no account, credential, telemetry or usage data is transmitted back to us. Where a customer processes personal data in its deployment, the customer is the controller of that data.

Where a customer requires support, troubleshooting or data validation, our personnel may be granted access to work within the customer's own environment, under the terms of the agreement signed with that customer. Any personal data seen in that context remains within the customer's systems and under the customer's control: it is not copied, exported, emailed or otherwise transferred to 3RDi Limited. In that work we act on the customer's instructions, and the customer remains the controller.

3. Personal data we process, and why

CategoryDataWho it is aboutPurposeLawful basisRetention
Customer contactsName, business email, job title, companyStaff of customers and prospective customersManaging the commercial relationshipLegitimate interests; Contract where they are our counterpartyRelationship + 2 years
Support correspondenceName, business email, content of correspondenceStaff of our customersResponding to support requestsContract3 years
Billing recordsCustomer contact and invoice detailsStaff of our customersInvoicing and statutory accountingContract; Legal obligation for retention7 years
Employee HR recordsName, address, date of birth, right-to-work documentation, absence recordsEmployeesAdministering employmentContract; Legal obligation for right-to-work checksEmployment + 7 years
Employee payroll dataSalary, tax code, national insurance number, and bank account details which we hold ourselves and do not share with our payroll providerEmployeesPaying salaries and meeting payroll tax obligationsContract; Legal obligationEmployment + 7 years
Employee contact dataEmail, phone, emergency contactsEmployeesBusiness communication and emergenciesContract; Vital interests for emergenciesDuration of employment
Performance dataReviews, objectives, feedbackEmployeesPerformance managementLegitimate interestsEmployment + 3 years
IT access dataUser accounts, access logs, device informationEmployeesInformation securityLegitimate interests1 year (logs); duration of employment (accounts)
Website visitor dataIP address and standard web server log data, generated automatically by our hosting platform. No analytics, tracking or cookies.Website visitorsKeeping the website available and secureLegitimate interestsNot retained. Our content delivery network is not configured to export or store access logs.
Vendor and partner contactsName, email, phoneVendor and partner staffManaging supplier relationshipsLegitimate interestsRelationship + 2 years
Enquiry correspondenceName, email, content of your messagePeople who contact usResponding to enquiriesLegitimate interests2 years from last contact

Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may object to that processing at any time.

We do not use your personal data to make solely automated decisions that produce legal or similarly significant effects. We do not sell personal data.

4. Cookies and similar technologies

www.3rdi.ai is an informational website. It sets no cookies at all, not even strictly necessary ones, and uses no local storage, session storage or other client-side storage.

We run no analytics, advertising, tracking or profiling on the site, and the site loads no third-party scripts, fonts, video embeds or chat widgets. Visiting our website therefore places nothing on your device and sends no data about you to any third party.

Our footer links to our LinkedIn page and to our Trust Centre. These are ordinary links: nothing is loaded from those services unless you choose to follow the link, at which point that service's own privacy policy applies.

Because we set no non-essential cookies, no consent banner is required under the Privacy and Electronic Communications Regulations. If we introduce cookies or similar technologies in future, we will ask for your consent before doing so.

5. Who we share personal data with

Each of the following is bound by a written contract meeting the requirements of Article 28 of the UK GDPR.

ProcessorWhat they process for usPurpose
Microsoft AzureWebsite hosting and our operational systemsCloud infrastructure, compute and storage
Microsoft 365Employee and business correspondence, documentsEmail, collaboration and file storage
BreatheHREmployee HR recordsHR information system
VSM Payroll LimitedEmployee payroll data, including salary, tax and national insurance details. Bank account details are not shared with them.Payslip generation and Real Time Information filing to HMRC
XeroCustomer and supplier contact and invoice details; employee salary costsAccounting and bookkeeping
GitHubSource code (no personal data)Code repository and CI/CD
VantaSecurity and compliance posture dataCompliance monitoring

We may also disclose personal data where required by law, or to establish, exercise or defend legal claims. If our business or its assets are acquired, personal data may transfer to the acquirer, who would remain bound by this policy until they notify you otherwise.

6. Where your personal data is held

Our Azure infrastructure is hosted in the UK South, West Europe, North Europe and Sweden Central regions. Personal data for which we are the controller is stored within the United Kingdom and the European Economic Area.

No transfer risk assessment is required. Every processor we use holds personal data within the United Kingdom or within a country covered by United Kingdom adequacy regulations. Xero, BreatheHR, VSM Payroll Limited, Foxboro and CoutissonVA are United Kingdom based. Microsoft 365 and Azure hold our data in UK South, West Europe, North Europe and Sweden Central, all within the United Kingdom or the European Economic Area. BrightPay, engaged by our payroll provider, is in the United Kingdom or the Republic of Ireland. We will complete an assessment if a processor is engaged that transfers personal data beyond that area.

7. How we protect personal data

We apply technical and organisational measures appropriate to the risk, as required by Article 32 of the UK GDPR. These include:

  • Encryption of personal data in transit using TLS 1.2 or higher, and at rest using AES-256
  • Multi-factor authentication on all administrative accounts
  • Role-based access control, with access granted on a least-privilege basis
  • Quarterly reviews of user access rights
  • Logging and monitoring of access to systems holding personal data
  • Annual penetration testing and continuous vulnerability scanning
  • Documented incident response procedures, tested by exercise
  • An information security management system aligned to ISO/IEC 27001, and continuous control monitoring through a compliance platform

8. Your rights

Under the UK GDPR you have the following rights:

  • Access. To obtain a copy of the personal data we hold about you, and information about how we process it (Article 15)
  • Rectification. To have inaccurate personal data corrected, and incomplete data completed (Article 16)
  • Erasure. To have your personal data deleted where one of the grounds in Article 17 applies
  • Restriction. To limit how we process your personal data in the circumstances set out in Article 18
  • Portability. To receive personal data you gave us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller (Article 20)
  • Objection. To object to processing carried out on the basis of legitimate interests, and to object at any time to direct marketing (Article 21)
  • Withdraw consent. At any time where we rely on it, without affecting processing carried out before withdrawal

To exercise any of these rights, contact privacy@3rdi.ai. We will respond within one month. That period may be extended by a further two months for complex or numerous requests, in which case we will tell you within the first month and explain why.

Exercising these rights is free. We may charge a reasonable fee, or refuse to act, only where a request is manifestly unfounded or excessive, and we will explain our reasons if we do.

9. Complaints

If you are unhappy with how we have handled your personal data, please contact us first at privacy@3rdi.ai so we can try to put it right.

You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority for data protection:

Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
www.ico.org.uk

10. Changes to this policy

We review this policy at least annually. Where we make a material change we will update the date above and, where appropriate, notify you directly. This policy replaces the version dated 3 April 2019.