Skip to content
Pathfinder Labs Corporation
Legal

Privacy Policy

A field guide to the route personal data takes through this company. Three legs, twenty-five waypoints. At each one: what is carried, what the hazards are, and which exit is open to you.

Edition one, in force from 15 August 2026. A guide is only worth carrying if it matches the ground, so the edition line moves whenever the route does.

1. The trailhead

THE PATHFINDER LABS CORPORATION LIMITED wrote this guide and answers for what is in it. Companies House carries the company under number 17061706, formed under the law of England and Wales, with its registered office in Romford. That office is the address at which a formal document has to be served for the service to count.

Throughout the guide, “we” and “the company” mean that one entity. Nothing sits above it and nothing sits beside it: no group, no parent, no overseas arm.

The route mapped below runs through five places:

  • the pages published at pathfinderlabs.co.uk;
  • mail travelling to or from [email protected];
  • the paperwork wrapped around an engagement, from first proposal to final invoice;
  • material a client puts into our hands while a piece of work is running; and
  • any application released under the company name, whether through the Apple App Store, Google Play or a direct download.

Where this guide uses a plain word, the defined one still governs. “Personal data”, “controller”, “processor”, “processing” and “special category data” all carry the meanings set for them by the UK General Data Protection Regulation and by the Data Protection Act 2018.

Who to write to. Article 37 of the UK GDPR lists the conditions that make a Data Protection Officer compulsory, and a company built at this scale falls outside every one of them. Accountability therefore rests with the director, and every message described in this guide should be sent to [email protected].

2. Two ways we appear on the route

Data protection law splits the job in half, and the two halves carry very different duties. This guide keeps them on separate legs so that you never have to work out which one you are reading.

Where we set the route, the company picks what is gathered and decides what it is for. That covers this website, the mailbox, proposals, contracts, invoices, the firms that supply us, people who write asking about work, and anything released to a store under our own name. Leg one maps all of it.

Where a client sets the route, the choice was made before the material reached us and our job is to follow written instructions, in the way a guide walks a party along a line somebody else drew. A database extract handed over so that a technique can be tried against genuine records is the usual case. Leg two maps that, and on it the client answers for the purpose. Their own notice, not this guide, explains why the records were gathered in the first place.

Each waypoint carries a marker showing which leg it belongs to, so a section can be read on its own without losing the thread.

3. Pick your leg

Find the description that fits you, then read only the waypoints beside it. Everything on leg three applies whichever row you land on.

Which waypoints to read, by kind of reader
If this is youWho set the routeWaypoints
Reading these pagesWe did4, then 14 to 19
You have written to the mailboxWe did5, 10, 16, 17
A named contact at a client organisationWe did6, 10, 16, 17
Working for a firm that supplies usWe did7, 16, 17
You asked about working with usWe did8, 16, 17
Using an application released under our nameWe did9, 20, 21
Your details sit inside material a client gave usThe client did11 to 13, plus that client’s own notice

Leg one. We set the route

Everything on this leg is chosen by the company, which means the company is the one you hold to account for it.

4. The page in front of you

Waypoint 4 · we set the route

What you will find here. A set of static files and nothing behind them. There is no account to open, no form to submit, no comment thread, no advertising network, no measurement product and no embedded social widget. Nothing is written to your device under our name, and no consent bar appears because none of the conditions that would call for one are met on these pages.

Cloudflare Pages puts the files in front of you and keeps a short technical record at its edge while doing so. Individual rows never reach us. What we see is the total in a hosting dashboard: how many requests arrived, how many failed, roughly where they came from.

The table below scrolls sideways.

What the website leg carries
What is carriedTypical valuesWhere it joinsWhy it travelsLawful basisHow far it goesWho else handles it
Request and connection detail IP address, time of the request, the path asked for, response code, browser string, country to a rough approximation Picked up the moment your browser asks for a page Getting the page to you, and keeping automated traffic from flattening the site Article 6(1)(f). The interest: a public site that stays reachable and defended. The edge provider’s own log window, counted in days Cloudflare, Inc., as our processor
Totals derived from those requests Request counts, bandwidth, error rates, country tallies Worked out by the edge from the row above Telling whether the site is up and roughly how much it is read Article 6(1)(f). The interest: running something we can maintain sensibly. As long as the hosting account is open Cloudflare, Inc., as our processor
Security tokens, where the edge issues one Cloudflare challenge and bot-management identifiers Issued by the edge, never by us Telling a reader apart from an automated client while an attack is under way Regulation 6(4) PECR treats a security token of this kind as strictly necessary; Article 6(1)(f) runs alongside it Half an hour to a year, by token; the Cookie Notice names each Cloudflare, Inc., as our processor

Hazards. An IP address is personal data, and the edge sees yours on every single request. That is simply what serving a page costs, and it is the reason the record is kept briefly rather than banked. Reading these pages is not anonymous, and this guide would rather say so than imply otherwise.

Exits. The Cookie Notice names each security token, gives its lifetime, and explains what blocking it changes. Waypoint 16 sets out the rights that attach to the record itself.

5. The mailbox

Waypoint 5 · we set the route

What you will find here. Mail is the only door into this company, so the mailbox holds most of what we know about anyone outside it. That means whatever you chose to write, any file you attached, and the headers every mail system bolts on in transit.

The table below scrolls sideways.

What the mailbox leg carries
What is carriedTypical valuesWhere it joinsWhy it travelsLawful basisHow far it goesWho else handles it
The enquiry itself Your name, the address you wrote from, employer and role if you mention them, the body of the message, attachments You, in your own words Reading what you asked and answering it in context Article 6(1)(f). The interest: replying to people who approach the business about its work. Two years after the last message in the thread, unless the thread turns into an engagement The mail host, as our processor
Envelope and routing detail Sending and receiving addresses, timestamps, message identifiers, spam scores, delivery headers Attached automatically as mail moves between systems Delivering mail, filtering junk, tracing a message that failed to arrive Article 6(1)(f). The interest: a working mailbox rather than one buried in unsolicited traffic. Two years, travelling with the message The mail host, as our processor
Requests made under this guide What you asked for, what we checked, what we sent back and the reasoning behind it You, when you take an exit at waypoint 16 Answering the request, and being able to show later that it was answered properly Article 6(1)(c) to deal with it, then Article 6(1)(f) to keep the record, the interest being provable accountability. Six years from the day the request closes The mail host as processor; the regulator, if a complaint follows

Hazards. An opening message is the one you have thought least about, and it is the one that lands in a mailbox you cannot reach into. Keep special category data, financial credentials and anything covered by a confidentiality obligation out of it. Where a question genuinely needs material of that kind, we will settle a route for it before you send anything.

Exits. Ask for a thread to be deleted and it goes, subject only to the periods at waypoint 17. Waypoint 16.9 explains how we confirm it is really you asking.

6. The engagement file

Waypoint 6 · we set the route

What you will find here. Once a piece of work is agreed, a file builds up around it: the people we deal with at the client organisation, and the commercial record of what was promised and what was paid. This is separate from whatever sits inside the client’s own material, which travels on leg two.

The table below scrolls sideways.

What the engagement file carries
What is carriedTypical valuesWhere it joinsWhy it travelsLawful basisHow far it goesWho else handles it
The people on the client side Name, role, work address, work telephone, employer You, a colleague of yours, or your organisation’s own site Running the work, fixing meetings, delivering the findings to somebody who can act on them Article 6(1)(b) where you contract with us personally, otherwise Article 6(1)(f), the interest being a contract with an organisation performed through its named staff. Six years from the day the work ends The mail host, and a document store where one is used
Scopes and signed agreements The written question, the stages, prices, dates, signatures Drawn up between us Fixing what will be done, and proving afterwards what was agreed Article 6(1)(b), with Article 6(1)(f) for the evidential copy, the interest being the defence of a claim. Six years from the day the work ends Our advisers, only if a dispute starts
Billing and accounting entries Billing name and address, invoice number, sums, dates, payment reference The client, and our bank Invoicing, collecting payment, filing statutory accounts and tax returns Article 6(1)(c), a legal obligation under the Companies Act 2006 and under tax legislation. Six years from the close of the accounting period HM Revenue and Customs, plus our bank and our accountant
Working notes made during the work Meeting notes, decisions taken, who raised which question Us, while the work runs Doing the work, and writing a findings memo that is accurate about it Article 6(1)(f). The interest: a record that is truthful about what was decided and by whom. Six years from the day the work ends Nobody beyond the company unless the client asks for it

Exits. A named contact can correct anything wrong in the file at any point, and can object to the entries resting on legitimate interests. The billing rows are the one part we cannot lift out on request, for the reason given at waypoint 21.

7. The supply line

Waypoint 7 · we set the route

What you will find here. Names, work contact details, bank details where we pay somebody, contracts and invoices for the firms and individuals who supply the company, including any contractor brought in to help on a piece of work.

Where a supplier is an individual contracting with us, Article 6(1)(b) covers it. Where the supplier is an organisation, Article 6(1)(f) applies instead, the interest being the plain administration of the company’s own arrangements. Payment records rest on Article 6(1)(c) and stay for six years from the close of the accounting period they belong to; the rest of a supplier record runs out six years after the working relationship closes.

Hazards. A contractor who touches client material widens the circle around it. So before that happens, the contractor signs an agreement carrying confidentiality obligations and the sub-processor terms Article 28 of the UK GDPR requires, and the client is told who it is beforehand rather than finding out later.

8. People who write asking about work

Waypoint 8 · we set the route

What you will find here. No application system runs on this website, so anything of this kind arrives as ordinary mail: your message, a curriculum vitae if you attached one, and any note we made while reading it. Article 6(1)(f) is the basis, the interest being the sensible consideration of people who offer to work with a small company. Should an approach move towards an offer, Article 6(1)(b) joins it.

Material from an approach that goes no further stays twelve months from our last message, which is long enough to explain a decision if you ask why, and goes sooner the moment you tell us to. Nobody is screened by automated tool, credit file or criminal record check.

9. Anything released to a store

Waypoint 9 · we set the route

Waypoint 20 sets out the rules binding any application released under the company name: the permission table, the position on tracking, and how the store declarations get filled in. Those rules are written and published ahead of a submission on purpose, so that a reviewer and a reader can both hold the company to them from the outset rather than from launch day.

When an application does go out, this waypoint gains an inventory table built like the ones at waypoints 4 to 6, listing exactly what the application carries, and the edition line at the top of this guide moves on the same day.

10. Every balancing test, written out

Waypoint 10 · we set the route

Article 6(1)(f) is not a free pass. It asks for an interest that can be named, processing that is genuinely necessary to serve it, and a balance struck against your rights that comes out in favour of going ahead. We lean on it in five places, and here is each one with the balance stated.

  1. Keeping a public site reachable. Anything published without protection is knocked over by automated traffic within days. What the edge sees is technical, held briefly, and never assembled into a profile of a reader.
  2. Answering people who write. A message cannot be read without being processed. You chose to send it, you know exactly what went into it, and you can have the thread removed.
  3. Administering a contract through named staff. Organisations sign agreements but people carry them out. What we hold is limited to work contact details and the correspondence the job generated.
  4. Holding evidential copies for six years. A simple contract in England and Wales can be sued on for six years, and a defence without documents is not a defence. These copies sit untouched unless a claim arrives.
  5. Reading approaches about work. An approach cannot be considered without processing it. The window is short and a request to remove it is acted on at once.

Marketing is not on that list and never will be. The company runs no mailing list, sends no promotional mail and buys no contact data. Where you ask us to send you something that is not a reply to your own enquiry, that single message rests on your consent under Article 6(1)(a), and replying to say stop is enough to take the consent back.

Leg two. A client sets the route

Here the decisions were taken before the material arrived. We walk the line somebody else drew, and that somebody, not this company, answers for the purpose.

11. Material handed over on instruction

Waypoint 11 · the client sets the route

What you will find here. Some questions can only be settled against genuine records, because invented ones behave too well. Where a client hands over an extract of that kind, these conditions travel with it:

  • the client stays the controller throughout and owns the decision about purpose;
  • we act on documented instructions only, as Article 28(3)(a) requires;
  • a written processing agreement carrying the Article 28(3) terms is signed before a single record moves;
  • we ask for the extract to be cut down or pseudonymised first, so that only fields the question actually needs make the trip;
  • the material is destroyed within thirty days of the work ending, unless the client instructs otherwise in writing; and
  • every sub-processor that could reach it is named before it arrives, and none is added mid-engagement without written approval.

Hazards. An instruction can be wrong. Where one looks to us like a breach of the UK GDPR or of the Data Protection Act 2018, we put that in writing to the client and stop rather than carry it out, which is exactly what Article 28(3) obliges a processor to do.

12. Ground we will not cross

Waypoint 12 · the client sets the route

Client material is not raw material for us. It is not used to sharpen our methods, train a model, seed a demonstration, build a product of our own or illustrate published writing of ours. It is not sold, not shown to another client, and not quietly retained past the destruction date at waypoint 11.

No engagement grants a licence to do any of that, and we will not ask for one as the price of taking the work on. Where a client offers such a licence unprompted, we decline it, because holding a permission we have no use for only creates a risk that has to be managed.

13. If you joined this route elsewhere

Waypoint 13 · the client sets the route

Suppose an organisation gave us records that mention you. That organisation made the decision and answers for it, which also means we cannot lawfully act on your request about those records without their instruction. A processor that starts editing a controller’s data on a stranger’s say-so is a worse problem than the one it set out to solve.

Exits. Write to [email protected] and, inside five working days, we will tell you whether we hold anything from that organisation, pass your request straight to them, and confirm to you that it has gone. Tell us they have ignored it and we will put that to them in writing. You are also free to take the matter to the regulator against the controller itself, using the details at waypoint 18.

Leg three. Conditions on both legs

What follows holds whichever leg you are on, unless a paragraph says otherwise.

14. Who else travels with it

Waypoint 14 · both legs

The party is kept small deliberately: every organisation added to a route is another place data can go wrong. Each one below works under a written contract carrying the obligations Article 28 of the UK GDPR sets for processors.

The table below scrolls sideways.

Who else is on the route, and what covers them
WhoWhat they do on the routeWhat they can reachWhere they process itWhat covers the crossing
Cloudflare, Inc. Serves these pages through Cloudflare Pages and filters automated abuse at the edge The request detail at waypoint 4. No account records, since the site keeps none. United States, with edge handling in the UK and elsewhere UK Addendum to the EU Standard Contractual Clauses, inside the provider’s processing terms
Our mail host, a processor, named on request Runs the mailbox behind [email protected] Every message described at waypoint 5, and anything attached to one Confirmed on request Confirmed on request
Our accountant and their bookkeeping software, processors, named on request Bookkeeping, invoicing and the statutory accounts Billing names and addresses, and what an invoice says Confirmed on request Confirmed on request
Our bank Holds the company account and receives payment Payer name, reference, amount United Kingdom Nothing to cover: the data does not leave the country
HM Revenue and Customs, Companies House Statutory filings and tax Whatever the relevant statute calls for United Kingdom Nothing to cover: the data does not leave the country
Professional advisers, where instructed Advice on a dispute, or handling an insurance claim Only the records bearing on that matter United Kingdom Nothing to cover: the data does not leave the country

Beyond that party there is nothing: no advertising network, no measurement product, no customer relationship platform, no chat widget, no session recorder and no service that turns a visit into a sales lead. Were any of that to change, this table would be rewritten before the change went live, not after it. Separately, we may have to hand data to a court, a regulator acting inside its powers, or another body where the law compels it, and wherever we are allowed to tell you that this has happened, we will.

15. Where the route leaves the country

Waypoint 15 · both legs

Our own work happens in the United Kingdom. Data crosses a border only where a provider in the table above handles it abroad, and each crossing needs something to stand on.

An adequacy finding. Where the destination is covered by regulations made under section 17A of the Data Protection Act 2018, the European Economic Area among them, those regulations carry the crossing and nothing further is needed.

The IDTA. With no adequacy finding available, the crossing is made under the International Data Transfer Agreement issued by the Commissioner under section 119A of that Act, signed with the provider concerned.

The Addendum. Where a provider already runs on the European Commission Standard Contractual Clauses, we rely instead on the International Data Transfer Addendum to those clauses, issued under the same section, which reshapes them for UK law. That is what carries the Cloudflare crossing named at waypoint 14.

Checking the ground first. Before leaning on either instrument we look at whether the destination’s law and practice would hollow out the protection the clauses promise, and we write the conclusion down. Where a provider holds certification under the UK Extension to the EU to US Data Privacy Framework we may rest on that instead, and the table above will name it rather than leaving you to work it out.

On leg two, client material crosses a border only where the client has instructed it in writing and one of the instruments above is already in place. Ask for the safeguards covering a particular crossing and we will send them, with commercially confidential terms blacked out.

16. Your exits, one at a time

Waypoint 16 · we set the route

These exits open against a controller. Where we are on leg two instead, waypoint 13 is the one to read. Each exit gets its own subsection below, because they do different jobs and close for different reasons.

16.1 Seeing a copy, Article 15

You can ask whether the company holds anything about you and, if it does, receive a copy of it. The copy comes with the purposes, the categories held, who else has seen it, how long it stays, where it came from if not from you, and a note of the other exits. The first copy costs nothing. Further copies may carry a fee reflecting the administrative cost, and a request that is manifestly unfounded or excessive can be turned down. Put “Subject access request” in the subject line and send it to [email protected].

16.2 Correcting it, Article 16

Anything inaccurate gets corrected, and anything incomplete gets completed, if necessary by adding a statement from you that sits alongside the record. Tell us which detail is wrong and what belongs there instead. Where the wrong version has already gone to somebody else, Article 19 obliges us to tell them unless that proves impossible or takes disproportionate effort, and we will tell you who was contacted.

16.3 Having it erased, Article 17

Erasure is open where the data is no longer needed for the purpose it was gathered for, where you take back a consent we were relying on and nothing else supports the processing, where you object under Article 21 and no stronger ground survives, or where the processing was unlawful. It is not an unconditional exit: records the law obliges us to keep, accounting entries above all, stay put, as does anything needed to bring or defend a legal claim. Waypoint 21 gives the route and the timings.

16.4 Freezing it, Article 18

Rather than deleting data you can have it frozen while something is worked out: while we test a challenge you have made to its accuracy, where processing was unlawful but you would rather it were held than destroyed, where we have finished with it but you need it kept for a claim, or while an objection under Article 21 is being weighed. Frozen data is stored and otherwise left alone, and we will tell you before the freeze comes off.

16.5 Taking it elsewhere, Article 20

Where processing runs on your consent or on a contract with you, and is carried out by automated means, you can receive what you gave us in a portable file another provider can read, and ask us to send it directly to that provider where the technology allows. In practice this exit is narrow here, since most of what we hold as controller rests on legitimate interests or on a legal obligation instead. Ask, and we will tell you precisely which parts qualify.

16.6 Objecting, Article 21

Where we process under legitimate interests you can object on grounds particular to your situation. We then have to stop unless we can show compelling grounds that outweigh your interests, rights and freedoms, or unless the processing exists to establish or defend a legal claim. Waypoint 10 names all five interests we rely on, so an objection can be aimed at one rather than fired at everything. Against direct marketing the exit is absolute, with nothing to weigh; the company does no direct marketing.

16.7 Automated decisions, Article 22

You are entitled not to be on the receiving end of a decision made purely by machine where it carries legal consequences for you or affects you in a comparably serious way. Nothing here works like that. Waypoint 23 goes further into it.

16.8 Pulling consent back, Article 7(3)

Consent, where it is what we rely on, can be withdrawn whenever you like, and withdrawing it has to be as easy as giving it was. The single consent this guide asks for sits at the end of waypoint 10, and a reply saying stop withdraws it. What was done while the consent stood remains lawful.

16.9 Taking an exit: proof and timing

Everything goes to [email protected]. No form, no set wording, and no need to cite the legislation for a request to count.

Proving it is you. Handing personal data to the wrong person is the one failure an access request can cause, so we check. Where a request arrives from an address already tied to you in our records, that is normally the end of it. Where it does not, we ask for the least we need to connect you to the file, such as roughly when you wrote and what the exchange was about. If that still leaves a gap we may ask to see a single identity document, which is looked at and then destroyed rather than filed. Nothing supplied for this purpose is used for any other.

Timing. A reply comes inside one month of the request landing, as Article 12(3) requires, and sooner where the answer is straightforward. The month runs from the day after arrival, or from the day the information needed to identify you arrives. A complex request, or several from the same person, can extend that by up to two further months; if it does, we will say so and explain why before the first month is out.

Cost. Nothing, apart from the further-copies fee at waypoint 16.1. Acting for somebody else: send written authority from that person, or evidence of your legal authority, before we can answer.

16.10 When an exit is closed

A request can be refused, in whole or in part, in these situations:

  • it is manifestly unfounded or excessive, repetition being the usual reason, under Article 12(5);
  • an exemption in Schedule 2 to the Data Protection Act 2018 covers it, for instance where answering would expose information about another identifiable person who has not agreed and it is not reasonable to answer without that agreement, or where the material is covered by legal professional privilege;
  • the exit does not apply to that processing at all, such as a portability request aimed at records held under a legal obligation; or
  • we cannot pick you out of what we hold and cannot establish who you are.

A refusal still gets a reply inside the same month. It will name the ground relied on, explain why that ground fits, and tell you that the regulator and the courts are both open to you. Silence is not one of the options.

17. How long anything stays

Waypoint 17 · both legs

Retention is the waypoint most guides skip. Every period below carries a reason alongside it, and nothing is held on the theory that it might come in useful one day.

The table below scrolls sideways.

How long each record is held, and why that long
What is heldWhich legHeld untilWhy that long
Request logs at the hosting edgeWe set itThe edge provider’s window, counted in daysLong enough to unpick an attack, short enough that no reading history builds up
Security tokens issued by the edgeWe set itHalf an hour to a year, as the Cookie Notice sets outThe span over which repeat automated abuse is worth recognising
An enquiry that never became workWe set itTwo years after the last messagePeople come back to a conversation a year later and the thread makes the answer worth having. After that it has gone stale.
Scopes and signed agreementsWe set itSix years from the end of the workSection 5 of the Limitation Act 1980 gives a simple contract a six year window in which to be sued on
Working notes and findings memosWe set itSix years from the end of the workMatched to the agreement, so a claim can be met with a complete file rather than half of one
Invoices, payments, accounting entriesWe set itSix years from the close of the accounting periodThe statutory span for a private company’s accounting records, section 388 of the Companies Act 2006, plus the tax requirement
Client material carried on instructionThe client set itDestroyed within thirty days of the work endingThe client is the controller; keeping it longer takes a written instruction from them
Material from an approach about workWe set itTwelve months after our last messageLong enough to explain a decision, short enough that no file quietly accumulates
Records of requests made under this guideWe set itSix years from closureAccountability under Article 5(2), and answering a regulator’s question about it later
Records of a personal data breachEither legSix years from the breachArticle 33(5) requires that every breach be written down
Supplier and contractor recordsWe set itSix years after the relationship closesLines up with both the contract limitation period and the accounting requirement

When a period runs out the record is destroyed. Where a copy sits inside a backup that cannot be reached into individually, it is put beyond use immediately and disappears as that backup rotates. Backups exist to restore a system after a failure and are searched for nothing else.

18. Escalating past us

Waypoint 18 · both legs

Come to us first if you are willing to: mail [email protected] with “Data protection complaint” in the subject line, and we will confirm receipt inside two working days and answer in full inside twenty. You are under no obligation to start with us, and you can go to the supervisory authority whenever you choose. In the United Kingdom that authority is the Information Commissioner’s Office.

Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk

Articles 78 and 79 of the UK GDPR also give you a judicial route: you can challenge how the regulator handled your case, or bring a claim against this company, in the courts.

19. When something goes wrong

Waypoint 19 · both legs

The protections here are sized for a company that does not run a platform holding other people’s live data. Traffic to the site and to the mailbox is encrypted where the receiving server supports it; development machines are encrypted whole; every account that can reach client material or company records needs a second factor; access is confined to whoever is working on the engagement; a written processing agreement is signed before client material moves; and material is destroyed when the work ends rather than lingering.

Telling the regulator, Article 33

Where the company is the controller and a personal data breach happens, we work out whether it is likely to put anyone’s rights and freedoms at risk. Where it is, the Information Commissioner is told without undue delay and, where it can be done, inside seventy-two hours of us becoming aware; anything reported later carries the reason for the delay, as Article 33(1) demands. Where the assessment is that no risk is likely and no report is due, that assessment and its reasoning are written down too. Every breach is recorded either way, with the facts, the effects and what was done about it, which is what Article 33(5) requires, and those records stay six years.

Telling you, Article 34

Where a breach is likely to put your rights and freedoms at high risk, you hear from us without undue delay and in ordinary language: what happened, what it is likely to mean for you, what has been done and what happens next, and who to speak to. Individual notice can fall away in three cases: the data was unreadable to anyone unauthorised, strong encryption being the usual reason; steps taken since mean the high risk is no longer likely; or reaching everyone individually would take disproportionate effort, in which case a public announcement replaces it.

On leg two

Where a breach touches client material, the client hears from us without undue delay, as Article 33(2) requires, carrying what they need for their own report inside their own seventy-two hour window. We do not report to the regulator on a client’s behalf unless they instruct us to in writing.

20. Store listings and permissions

Waypoint 20 · we set the route

This waypoint binds any application THE PATHFINDER LABS CORPORATION LIMITED releases. It is stocked ahead of the journey rather than after it, so that the commitments are already on the record when the first submission goes in.

Permissions

An application will ask for the smallest set of permissions that lets it do its job, will ask at the moment the feature is used rather than on first launch, and will keep working in a reduced form when a permission is declined. The table below is replaced by the real manifest before any application goes to review.

The table below scrolls sideways.

Permissions, why each would be asked for, and how to switch it off
PermissionWhy it would be asked forNeeded or optionalDecline it andTurn it off in iOS SettingsTurn it off in Android Settings
Camera Taking a photograph, or reading a code, inside a feature you opened Optional That one feature is unavailable. The rest works, and the same detail can be typed in. Privacy and Security → Camera → switch this app off Apps → this app → Permissions → Camera → Don’t allow
Photo library Attaching an image you pick Optional An existing image cannot be attached. On iOS the selected-photos option is the expected choice here, not a grudging one. Privacy and Security → Photos → this app Apps → this app → Permissions → Photos and videos
Notifications Saying that a long-running task has finished Optional Nothing is lost; you look at the screen instead. Notifications would never be used to sell you anything. Notifications → this app Notifications → App settings → this app
Precise location Only where a feature is inherently about where you are standing Optional The feature is unavailable, or falls back to a place you type. Nothing is collected in the background. Privacy and Security → Location Services → this app Location → App permissions → this app
Files on the device Importing or exporting a file you choose Optional Import and export are unavailable. The system picker is used, which opens one file at a time. Granted file by file through the system picker; nothing standing to revoke Apps → this app → Permissions → Files
Tracking, the App Tracking Transparency prompt Not asked for. See below. Not applicable Not applicable Not applicable Not applicable

App Tracking Transparency on iOS

The App Tracking Transparency prompt will stay unseen, for the straightforward reason that there is nothing for it to authorise. We will not reach for the Identifier for Advertisers, will not tie what an application of ours gathers to outside data for advertising or measurement, and will not pass an identifier to a data broker. Were any of that ever to change, the prompt would appear, this waypoint would be rewritten first, and declining would never cost you a feature.

Keeping the store declarations honest

The Google Play Data Safety form and the Apple App Privacy labels get filled in from this waypoint rather than drafted separately, which is how the two end up agreeing. Spot a difference between a store listing and this guide and you have found a mistake: tell us at [email protected] and within five working days we will correct whichever is wrong and say plainly which one it was. Where an application gathers nothing in a category, the declaration will say nothing rather than list categories defensively.

21. Leaving the route altogether

Waypoint 21 · we set the route

These pages hold no accounts, so there is no account here to shut. What follows binds any application or service we publish that does carry accounts, while the mail route below already covers everything held about you today.

From inside the application

Any application we release carries a deletion path within the application itself, reachable without writing to anybody, under Settings, then Account, then Delete account. It removes the account and the personal data attached to it rather than parking it in a deactivated state, and it says on screen what survives and why before you confirm.

By mail

Send “Delete my data” to [email protected]. This route works whether or not you have ever opened an application of ours, and it reaches correspondence, enquiry records and anything else held about you while we are the controller. Identity is checked first, in the way waypoint 16.9 describes.

Timing

Deletion across live systems finishes within thirty days of a verified request, and you get written confirmation once it is done. Copies inside routine backups are put beyond use straight away and vanish as those backups rotate, which adds no more than a further thirty days.

What survives, and why

  • Accounting entries that name you, for six years from the close of the accounting period, because section 388 of the Companies Act 2006 and tax legislation both demand it. An invoice cannot be deleted on request.
  • The record of the deletion itself, for six years, cut back to what proves it was handled properly: who asked, when, what went, and when it finished.
  • A suppression entry, where you asked never to be contacted again, since honouring that means remembering the address to leave alone.
  • Anything needed for a live legal claim, frozen so it serves no other purpose and destroyed once the matter closes.

Past that, deletion is deletion. No shadow copy, no anonymised residue derived from your record, no forgotten export sitting in a spreadsheet.

22. Children

Waypoint 22 · we set the route

This route is laid out for businesses, and it is not built for children to walk. We do not knowingly gather personal data from anyone under thirteen, and a general audience application would not be built here without the ICO Age Appropriate Design Code applied to it from the design stage rather than bolted on at the end. If you think a child has sent us something, tell us and it will be deleted.

23. Machines that decide things

Waypoint 23 · we set the route

Nothing about you is decided here by machine, and nobody is profiled. Enquiries and approaches about work are read by a person. Nothing on this website scores you, ranks you or sorts you into a segment, and no part of how we work produces a legal or similarly serious effect on anyone without a human being making the call. The mailbox does filter junk automatically, but that decides where a message is filed rather than anything about the person who sent it, and a message caught wrongly is fished back out by hand when you tell us.

24. Revisions to this edition

Waypoint 24 · both legs

When the route changes, the edition line at the top changes with it. Where a change matters, a new organisation on the route, a new category carried, a new purpose or a new border crossing, a short note sits at the top of this guide for at least ninety days describing it, rather than leaving you to compare two versions line by line. Where a change needs your agreement, we ask before it takes effect instead of afterwards.

25. Reaching the keeper of this guide

Waypoint 25 · both legs

Everything goes to [email protected]. A clear subject line helps it move: “Subject access request”, “Delete my data” or “Data protection complaint” all route themselves.

Ordinary mail gets an answer inside two working days. The statutory clocks described at waypoint 16.9 run on their own terms and are not shortened or lengthened by that service commitment.