1. Who we are
3RDi Limited ("we", "us", "our") is the data controller for the personal data described in this policy.
- Registered address. Flat 8 Magistrates House, Market Place, Brentford, United Kingdom TW8 8FJ
- Company number. 11080079 (registered in England and Wales)
- Privacy contact. privacy@3rdi.ai
We have not appointed a Data Protection Officer. We have assessed the criteria in Article 37 of the UK GDPR and concluded that our processing does not meet the threshold requiring one. The Director is accountable for data protection.
2. Scope of this policy
This policy explains how we handle personal data for which we are the controller: data about visitors to our website, our customers' authorised users, our employees, and our vendor and partner contacts.
It does not cover personal data processed within a customer's own deployment of the Prophesee Platform. We do not receive or store that data.
The Prophesee Platform is installed on the customer's own premises or in the customer's own cloud tenancy. It is not a subscription service that we host. We do not operate user accounts or authentication for platform users: each customer administers its own users entirely within its own deployment, and no account, credential, telemetry or usage data is transmitted back to us. Where a customer processes personal data in its deployment, the customer is the controller of that data.
Where a customer requires support, troubleshooting or data validation, our personnel may be granted access to work within the customer's own environment, under the terms of the agreement signed with that customer. Any personal data seen in that context remains within the customer's systems and under the customer's control: it is not copied, exported, emailed or otherwise transferred to 3RDi Limited. In that work we act on the customer's instructions, and the customer remains the controller.
3. Personal data we process, and why
| Category | Data | Who it is about | Purpose | Lawful basis | Retention |
|---|---|---|---|---|---|
| Customer contacts | Name, business email, job title, company | Staff of customers and prospective customers | Managing the commercial relationship | Legitimate interests; Contract where they are our counterparty | Relationship + 2 years |
| Support correspondence | Name, business email, content of correspondence | Staff of our customers | Responding to support requests | Contract | 3 years |
| Billing records | Customer contact and invoice details | Staff of our customers | Invoicing and statutory accounting | Contract; Legal obligation for retention | 7 years |
| Employee HR records | Name, address, date of birth, right-to-work documentation, absence records | Employees | Administering employment | Contract; Legal obligation for right-to-work checks | Employment + 7 years |
| Employee payroll data | Salary, tax code, National Insurance number, bank account details | Employees | Paying salaries, payroll tax obligations | Contract; Legal obligation | Employment + 7 years |
| Employee contact data | Email, phone, emergency contacts | Employees | Business communication and emergencies | Contract; Vital interests for emergencies | Duration of employment |
| Performance data | Reviews, objectives, feedback | Employees | Performance management | Legitimate interests | Employment + 3 years |
| IT access data | User accounts, access logs, device information | Employees | Information security | Legitimate interests | 1 year (logs); duration of employment (accounts) |
| Vendor and partner contacts | Name, email, phone | Vendor and partner staff | Managing supplier relationships | Legitimate interests | Relationship + 2 years |
| Enquiry correspondence | Name, email, content of your message | People who contact us | Responding to enquiries | Legitimate interests | 2 years from last contact |
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may object to that processing at any time.
We do not use your personal data to make solely automated decisions that produce legal or similarly significant effects. We do not sell personal data.
4. Cookies and similar technologies
www.3rdi.ai is an informational website. It sets no cookies at all, not even strictly necessary ones, and uses no local storage, session storage or other client-side storage.
We run no analytics, advertising, tracking or profiling on the site, and the site loads no third-party scripts, fonts, video embeds or chat widgets. Visiting our website therefore places nothing on your device and sends no data about you to any third party.
Our footer links to our LinkedIn page and to our Trust Centre. These are ordinary links: nothing is loaded from those services unless you choose to follow the link, at which point that service's own privacy policy applies.
Because we set no non-essential cookies, no consent banner is required under the Privacy and Electronic Communications Regulations. If we introduce cookies or similar technologies in future, we will ask for your consent before doing so.
5. Who we share personal data with
Each of the following is bound by a written contract meeting the requirements of Article 28 of the UK GDPR.
| Processor | What they process for us | Purpose |
|---|---|---|
| Microsoft Azure | Website hosting and our operational systems | Cloud infrastructure, compute and storage |
| Microsoft 365 | Employee and business correspondence, documents | Email, collaboration and file storage |
| BreatheHR | Employee HR records | HR information system |
| VSM Payroll Limited | Employee payroll data, including salary, tax and National Insurance details and bank account details | Payroll processing and RTI filing to HMRC |
| Xero | Customer and supplier contact and invoice details; employee salary costs | Accounting and bookkeeping |
| GitHub | Source code (no personal data) | Code repository and CI/CD |
| Vanta | Security and compliance posture data | Compliance monitoring |
We may also disclose personal data where required by law, or to establish, exercise or defend legal claims. If our business or its assets are acquired, personal data may transfer to the acquirer, who would remain bound by this policy until they notify you otherwise.
6. Where your personal data is held
Our Azure infrastructure is hosted in the UK South and West Europe regions. Personal data for which we are the controller is stored within the United Kingdom and the European Economic Area.
Where a processor named above transfers personal data outside the UK or EEA, that transfer is made under an approved safeguard, being the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy regulation.
7. How we protect personal data
We apply technical and organisational measures appropriate to the risk, as required by Article 32 of the UK GDPR:
- Encryption of personal data in transit using TLS 1.3, and at rest using AES-256
- Multi-factor authentication on all administrative accounts, using hardware security keys
- Role-based access control, with access granted on a least-privilege basis
- Quarterly reviews of user access rights
- Logging and monitoring of access to systems holding personal data
- Annual penetration testing and continuous vulnerability scanning
- Data masking capabilities for sensitive data in reports and non-production environments
- Documented incident response procedures, tested by exercise
- An information security management system certified to ISO/IEC 27001
8. Your rights
Under the UK GDPR you have the following rights:
- Access. To obtain a copy of the personal data we hold about you, and information about how we process it (Article 15)
- Rectification. To have inaccurate personal data corrected, and incomplete data completed (Article 16)
- Erasure. To have your personal data deleted where one of the grounds in Article 17 applies
- Restriction. To limit how we process your personal data in the circumstances set out in Article 18
- Portability. To receive personal data you gave us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller (Article 20)
- Objection. To object to processing carried out on the basis of legitimate interests, and to object at any time to direct marketing (Article 21)
- Withdraw consent. At any time where we rely on it, without affecting processing carried out before withdrawal
To exercise any of these rights, contact privacy@3rdi.ai. We will respond within one month. That period may be extended by a further two months for complex or numerous requests, in which case we will tell you within the first month and explain why.
Exercising these rights is free. We may charge a reasonable fee, or refuse to act, only where a request is manifestly unfounded or excessive, and we will explain our reasons if we do.
9. Complaints
If you are unhappy with how we have handled your personal data, please contact us first at privacy@3rdi.ai so we can try to put it right.
You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority for data protection:
Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
www.ico.org.uk
10. Changes to this policy
We review this policy at least annually. Where we make a material change we will update the date above and, where appropriate, notify you directly. This policy replaces the version dated 3 April 2019.