Legal

Privacy Policy

Last updated 18 September 2026

1. Who we are

3RDi Limited ("we", "us", "our") is the data controller for the personal data described in this policy.

  • Registered address. Flat 8 Magistrates House, Market Place, Brentford, United Kingdom TW8 8FJ
  • Company number. 11080079 (registered in England and Wales)
  • Privacy contact. privacy@3rdi.ai

We have not appointed a Data Protection Officer. We have assessed the criteria in Article 37 of the UK GDPR and concluded that our processing does not meet the threshold requiring one. The Director is accountable for data protection.

2. Scope of this policy

This policy explains how we handle personal data for which we are the controller: data about visitors to our website, our customers' authorised users, our employees, and our vendor and partner contacts.

It does not cover personal data processed within a customer's own deployment of the Prophesee Platform. We do not receive or store that data.

The Prophesee Platform is installed on the customer's own premises or in the customer's own cloud tenancy. It is not a subscription service that we host. We do not operate user accounts or authentication for platform users: each customer administers its own users entirely within its own deployment, and no account, credential, telemetry or usage data is transmitted back to us. Where a customer processes personal data in its deployment, the customer is the controller of that data.

Where a customer requires support, troubleshooting or data validation, our personnel may be granted access to work within the customer's own environment, under the terms of the agreement signed with that customer. Any personal data seen in that context remains within the customer's systems and under the customer's control: it is not copied, exported, emailed or otherwise transferred to 3RDi Limited. In that work we act on the customer's instructions, and the customer remains the controller.

3. Personal data we process, and why

CategoryDataWho it is aboutPurposeLawful basisRetention
Customer contactsName, business email, job title, companyStaff of customers and prospective customersManaging the commercial relationshipLegitimate interests; Contract where they are our counterpartyRelationship + 2 years
Support correspondenceName, business email, content of correspondenceStaff of our customersResponding to support requestsContract3 years
Billing recordsCustomer contact and invoice detailsStaff of our customersInvoicing and statutory accountingContract; Legal obligation for retention7 years
Employee HR recordsName, address, date of birth, right-to-work documentation, absence recordsEmployeesAdministering employmentContract; Legal obligation for right-to-work checksEmployment + 7 years
Employee payroll dataSalary, tax code, National Insurance number, bank account detailsEmployeesPaying salaries, payroll tax obligationsContract; Legal obligationEmployment + 7 years
Employee contact dataEmail, phone, emergency contactsEmployeesBusiness communication and emergenciesContract; Vital interests for emergenciesDuration of employment
Performance dataReviews, objectives, feedbackEmployeesPerformance managementLegitimate interestsEmployment + 3 years
IT access dataUser accounts, access logs, device informationEmployeesInformation securityLegitimate interests1 year (logs); duration of employment (accounts)
Vendor and partner contactsName, email, phoneVendor and partner staffManaging supplier relationshipsLegitimate interestsRelationship + 2 years
Enquiry correspondenceName, email, content of your messagePeople who contact usResponding to enquiriesLegitimate interests2 years from last contact

Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may object to that processing at any time.

We do not use your personal data to make solely automated decisions that produce legal or similarly significant effects. We do not sell personal data.

4. Cookies and similar technologies

www.3rdi.ai is an informational website. It sets no cookies at all, not even strictly necessary ones, and uses no local storage, session storage or other client-side storage.

We run no analytics, advertising, tracking or profiling on the site, and the site loads no third-party scripts, fonts, video embeds or chat widgets. Visiting our website therefore places nothing on your device and sends no data about you to any third party.

Our footer links to our LinkedIn page and to our Trust Centre. These are ordinary links: nothing is loaded from those services unless you choose to follow the link, at which point that service's own privacy policy applies.

Because we set no non-essential cookies, no consent banner is required under the Privacy and Electronic Communications Regulations. If we introduce cookies or similar technologies in future, we will ask for your consent before doing so.

5. Who we share personal data with

Each of the following is bound by a written contract meeting the requirements of Article 28 of the UK GDPR.

ProcessorWhat they process for usPurpose
Microsoft AzureWebsite hosting and our operational systemsCloud infrastructure, compute and storage
Microsoft 365Employee and business correspondence, documentsEmail, collaboration and file storage
BreatheHREmployee HR recordsHR information system
VSM Payroll LimitedEmployee payroll data, including salary, tax and National Insurance details and bank account detailsPayroll processing and RTI filing to HMRC
XeroCustomer and supplier contact and invoice details; employee salary costsAccounting and bookkeeping
GitHubSource code (no personal data)Code repository and CI/CD
VantaSecurity and compliance posture dataCompliance monitoring

We may also disclose personal data where required by law, or to establish, exercise or defend legal claims. If our business or its assets are acquired, personal data may transfer to the acquirer, who would remain bound by this policy until they notify you otherwise.

6. Where your personal data is held

Our Azure infrastructure is hosted in the UK South and West Europe regions. Personal data for which we are the controller is stored within the United Kingdom and the European Economic Area.

Where a processor named above transfers personal data outside the UK or EEA, that transfer is made under an approved safeguard, being the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy regulation.

7. How we protect personal data

We apply technical and organisational measures appropriate to the risk, as required by Article 32 of the UK GDPR:

  • Encryption of personal data in transit using TLS 1.3, and at rest using AES-256
  • Multi-factor authentication on all administrative accounts, using hardware security keys
  • Role-based access control, with access granted on a least-privilege basis
  • Quarterly reviews of user access rights
  • Logging and monitoring of access to systems holding personal data
  • Annual penetration testing and continuous vulnerability scanning
  • Data masking capabilities for sensitive data in reports and non-production environments
  • Documented incident response procedures, tested by exercise
  • An information security management system certified to ISO/IEC 27001

8. Your rights

Under the UK GDPR you have the following rights:

  • Access. To obtain a copy of the personal data we hold about you, and information about how we process it (Article 15)
  • Rectification. To have inaccurate personal data corrected, and incomplete data completed (Article 16)
  • Erasure. To have your personal data deleted where one of the grounds in Article 17 applies
  • Restriction. To limit how we process your personal data in the circumstances set out in Article 18
  • Portability. To receive personal data you gave us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller (Article 20)
  • Objection. To object to processing carried out on the basis of legitimate interests, and to object at any time to direct marketing (Article 21)
  • Withdraw consent. At any time where we rely on it, without affecting processing carried out before withdrawal

To exercise any of these rights, contact privacy@3rdi.ai. We will respond within one month. That period may be extended by a further two months for complex or numerous requests, in which case we will tell you within the first month and explain why.

Exercising these rights is free. We may charge a reasonable fee, or refuse to act, only where a request is manifestly unfounded or excessive, and we will explain our reasons if we do.

9. Complaints

If you are unhappy with how we have handled your personal data, please contact us first at privacy@3rdi.ai so we can try to put it right.

You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority for data protection:

Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
www.ico.org.uk

10. Changes to this policy

We review this policy at least annually. Where we make a material change we will update the date above and, where appropriate, notify you directly. This policy replaces the version dated 3 April 2019.