Skip to content
YYY Software Ltd
Legal

Privacy notice

How YYY Software Ltd handles personal data under the UK General Data Protection Regulation and the Data Protection Act 2018, including the disclosures required by the Apple App Store and Google Play.

Effective date: 7 August 2026 Version 1.0 Controller: YYY SOFTWARE LTD, company number 16938311

1. Who we are and what this notice covers

This notice is published by YYY SOFTWARE LTD, registered in England and Wales, company number 16938311, registered office Flat 47 Bennets Courtyard, Watermill Way, London, SW19 2RW. "We" means that company.

It covers this website, email reaching studio@yyysoftware.co.uk, and any mobile application we publish to the Apple App Store or Google Play. We build our own consumer applications rather than taking client work, so we decide what is collected and why.

At the date this version takes effect we have not published an application. The sections on applications are written in advance, so the standard is public before anything ships, and each says where it is a commitment rather than a description of software that exists.

We do not sell personal data, share it with advertising networks, or buy data about you.

2. Our two roles: controller and processor

A controller decides the purposes and means of processing. A processor acts only on a controller’s documented instructions. Different obligations attach to each, and your rights are exercised against a different organisation, so every section from 4 onwards is marked with its role.

2.1 Where we are the controller

Controller

We are the controller for visits to this website, email correspondence, the "keep me posted" list, our applications and any accounts in them, supplier relationships, and statutory company records. That is nearly everything we do, so you deal directly with us.

2.2 Where we may be a processor

Processor

We would be a processor only where another organisation decided the purposes and means and engaged us under a written Article 28 contract. We do not expect this. Section 22 sets out how we would behave.

2.3 Joint controllership

We are not a joint controller with anyone under Article 26. The app stores are independent controllers for the account, payment and analytics data they hold about their own users (sections 6 and 14).

3. A plain summary before the detail

The rest is long because the law requires specific disclosures. Nothing below contradicts it.

  • No analytics, advertising, pixels, third party embeds or cookies of our own.
  • Email is held so we can reply, then deleted on the section 16 schedule.
  • In applications, data stays on the device unless leaving it is the point of the feature.
  • We do not track you across other companies’ apps and websites. Section 18 sets out your rights.

4. Data inventory: website visitors

Controller

This site is static, with no forms, login, comments or third party analytics. A visit generates the technical record any web server keeps, plus your browser’s request to Google’s font servers.

Website visitors, processing inventory (controller)
Category Example fields Source Purpose Lawful basis Retention Recipients
Connection and request data IP address, timestamp, URL, HTTP status, user agent, referrer, country from IP Automatic, on each page request Serving the page, keeping the site up, blocking abusive traffic Article 6(1)(f), legitimate interests: keeping our website available and defending it from attack and abuse Briefly, by the provider. We keep no copy Cloudflare, as processor (section 14)
Security event data Rate limit counters, blocked requests, bot scores The provider’s security layer Detecting and mitigating attacks Article 6(1)(f), legitimate interests: network and information security, recognised in Recital 49 Provider’s own schedule. Not exported by us Cloudflare, as processor
Font delivery request IP address and user agent sent to Google’s font hosts Your browser, downloading the two typefaces Rendering the site in the typefaces it is designed in Article 6(1)(f), legitimate interests: presenting a legible, consistent site We hold nothing Google, as an independent controller for that request

A content blocker will stop the request to Google’s font servers. The site stays legible in fallback typefaces and nothing else depends on it.

We have no analytics package, so we cannot tell you how many people visited a page, and we do not try to identify visitors.

5. Data inventory: people who email us

Controller

Email is the only contact route offered. You need not give your name, and we ask for no telephone number.

Correspondence, processing inventory (controller)
Category Example fields Source Purpose Lawful basis Retention Recipients
General correspondence Name if given, address, message, attachments, headers You Answering your message and keeping a record of it Article 6(1)(f), legitimate interests: responding to a person who chose to write to us 24 months from the last message in the thread Our email provider, as processor
Keep me posted list Email address, the date you asked You, by emailing with that subject Writing to you when there is something to show Article 6(1)(a), consent. Withdraw by replying "stop" Until consent is withdrawn, or 36 months with no contact Our email provider, as processor
Data protection requests Address, the right exercised, verification, our response You, under section 18 Handling the request and showing we did so properly Article 6(1)(c), legal obligation, with Article 12 and the Article 5(2) accountability duty 36 months from closure Our email provider. The ICO, only if you complain
Security reports Reporter’s address, technical detail, steps You Investigating and fixing the issue Article 6(1)(f), legitimate interests: the security of our software and its users 36 months from closure Our email provider, as processor

6. Data inventory: applications we publish

Controller

We have not published an application. This section states the rules any we publish will follow, and is replaced on release with that application’s detail.

6.1 The default position: on device

Data created in an application stays on the device unless a feature cannot work without sending it somewhere. Content, files, settings and history sit in the app’s own storage, are covered by the operating system’s encryption when the device is locked, and go when you delete the app. We never receive it.

6.2 Where data would leave the device

  • A feature you switch on. Anything that syncs, shares or asks a server to compute is described where you enable it, and off until then.
  • Diagnostics. Optional, asked separately, default off. Declining changes no feature.
  • An account. Apps that do not need one will not have one. Where one exists its fields are listed here, and section 20 applies.

6.3 The app stores as independent controllers

Apple and Google process store account, payment, fraud prevention and analytics data as independent controllers under their own policies. We receive only aggregated reporting and the subscription record below, never card details.

6.4 The lawful bases that will apply

Applications, inventory that will apply on release (controller)
Category Example fields Source Purpose Lawful basis Retention Recipients
On device content and settings Whatever the app is for You Making the app work No processing by us, so no basis is engaged Until you delete it or the app Nobody
Account data, where an app has accounts Address, hashed password or token, creation date You, at sign up Providing the account and its features Article 6(1)(b), performance of a contract with you Life of the account, then 30 days from a request (section 20) Hosting processor named in section 14 at release
Optional diagnostics Crash trace, app and OS version, device model, an install identifier The app, if you switch diagnostics on Finding and fixing crashes Article 6(1)(a), consent, withdrawable by switching it off 12 months Diagnostics processor named in section 14 at release
In app support messages Email address, message, app version, device model You Answering your support message Article 6(1)(f), legitimate interests: answering a user who asked for help 24 months from the last message Our email provider, as processor
Subscription status, where an app is paid Transaction and product identifiers, renewal date, store country Apple or Google, on receipt validation Unlocking paid features, refunds, billing questions Article 6(1)(b), performance of a contract with you Six years from the end of the financial year, as an accounting record Apple, Google, our accountant

If an application needs data not described here, this notice is updated before release, and the change recorded in section 24.

7. Data inventory: suppliers, and statutory records

Controller

Suppliers, advisers and statutory records (controller)
Category Example fields Source Purpose Lawful basis Retention Recipients
Supplier and adviser contacts Name, work email, role, correspondence The individual or their employer Buying the services we need to operate Article 6(1)(b) if the individual is the supplier, else Article 6(1)(f): administering their employer’s contract Six years from the end of the relationship Our accountant, where it forms part of an invoice
Accounting records Invoices, receipts, payments and the names on them Suppliers, app stores, us Keeping accounting records and filing accounts and tax returns Article 6(1)(c), legal obligation, under section 386 Companies Act 2006 and HMRC requirements Six years from the end of the financial year Our accountant, HMRC, Companies House where a filing requires it
Statutory registers Director and person with significant control detail The individuals concerned Keeping the registers a company must keep, and required filings Article 6(1)(c), legal obligation, under the Companies Act 2006 Life of the company, and after dissolution Companies House, which publishes some of it

8. Special category data and criminal offence data

Controller

Special category data is that listed in Article 9(1): racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used to identify a person, health data, and data on sex life or sexual orientation. Criminal offence data falls under Article 10 and section 10 of the Data Protection Act 2018.

We process neither. Nothing here asks for it, no application will ask without this notice being amended first, and we do not infer it. Because we do not process it, no Article 9(2) condition and no Schedule 1 condition in the Data Protection Act 2018 is currently relied on.

Two clarifications. If you volunteer such information in an email, for example a health reason for a request, we rely on Article 9(2)(a), your explicit consent, solely to read and answer it, and delete it with the thread. Face or fingerprint unlock is done by your operating system: the template stays in your device’s secure hardware and we receive only a yes or no, which is not Article 9 processing by us.

If we ever intend to process either, we will amend this notice to name the Article 9(2) condition and, where required, the Schedule 1 condition and the appropriate policy document Schedule 1 Part 4 requires, before processing starts.

9. Children and age thresholds

Controller

This website is not directed at children and we do not knowingly collect data from a child.

Section 9 of the Data Protection Act 2018 sets the age at which a child can consent to information society services in the United Kingdom at 13. Where an application relies on consent it will be offered only to people aged 13 or over, and the store age rating will reflect what it does. Any application likely to be accessed by children will be assessed against the ICO’s Age Appropriate Design Code, with the outcome summarised here at release. If you believe a child has given us data, write to us and we will delete it.

10. Cookies and similar technologies

Controller

This website sets no cookies of its own, uses no local storage, sets no pixel and runs no third party script. There is no consent banner because there is nothing to consent to under regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003.

Our provider may set a strictly necessary security cookie to tell a human visitor from automated traffic, within the regulation 6(4) exemption. Names and durations are in the cookie notice. If an application stores identifiers beyond what the service needs, it will ask your consent in the app first.

11. Device permissions, and how to revoke them

Controller

No application we have published requests a permission, because we have not published one. The table sets the standard every request must meet before it ships, and is replaced by the per application list on release. Two rules apply to every row: a permission is asked for when the feature needs it, never as a block of prompts on first launch, and no permission is a condition of using an application.

Device permissions: the standard applied to every application
Permission Only purpose it would be requested for Required or optional If you decline Revoke on iOS Revoke on Android
Camera Capturing an image at the moment you ask for a capture Optional Capture is unavailable. You can still pick a file Settings, Privacy and Security, Camera, turn the app off Settings, Apps, the app, Permissions, Camera, Don’t allow
Photos and media Reading a file you pick, or saving one you asked us to Optional The picker still hands over the one file you choose Settings, Privacy and Security, Photos, Selected Photos or None Settings, Apps, the app, Permissions, Photos and videos, Don’t allow
Microphone Recording while you are recording, never in the background Optional Recording is unavailable. No other feature changes Settings, Privacy and Security, Microphone, turn the app off Settings, Apps, the app, Permissions, Microphone, Don’t allow
Location, while using the app Results depending on where you are, when you ask. Never background Optional Location results are unavailable. You can enter a place by hand Settings, Privacy and Security, Location Services, the app, Never Settings, Location, App location permissions, the app, Don’t allow
Notifications A reminder you set up yourself. Never marketing Optional Reminders stay in the app but do not appear as notifications Settings, Notifications, the app, Allow Notifications off Settings, Notifications, App settings, the app, off
Contacts Where a feature you started needs you to pick a person Optional You type the detail in by hand Settings, Privacy and Security, Contacts, turn the app off Settings, Apps, the app, Permissions, Contacts, Don’t allow
Local network Direct transfer between two of your own devices Optional Direct transfer is unavailable Settings, Privacy and Security, Local Network, turn the app off Settings, Apps, the app, Permissions, Nearby devices, Don’t allow
App Tracking Transparency Only if we tracked you across other companies’ apps Not requested Not applicable Settings, Privacy and Security, Tracking Not applicable, see section 12

Menu paths change between operating system versions. If one does not match, your settings search will find it.

12. Analytics, advertising and App Tracking Transparency

Controller

12.1 This website

No analytics of any kind. No advertising, tag manager, pixel, session recording, heat mapping, testing tool or chat widget. Two typefaces load from Google’s font servers and nothing else loads from anywhere, which is why our content security policy is so narrow.

12.2 Applications

Our applications will not carry advertising, and we will not integrate an advertising, attribution or audience segmentation software development kit. We do not use the Android advertising identifier, and any application we publish will omit the AD_ID permission from its manifest.

12.3 App Tracking Transparency on iOS

Apple’s framework governs whether an app may link its data to data from other companies’ apps and websites for advertising or measurement, or share it with a data broker. We do none of those things, so no application we publish will present the App Tracking Transparency prompt. Our App Store answers will be "Data Not Linked to You" and "Data Not Used to Track You". If that changed, the prompt would appear, this notice would be updated first, and declining would reduce no feature.

12.4 Diagnostics are not analytics

Optional crash diagnostics exist to fix crashes. They do not profile you, are not linked to an account, and stay off unless you switch them on.

13. Consistency with the app store declarations

Controller

Google Play requires a Data Safety declaration and Apple requires privacy nutrition labels. Both summarise this notice, and a difference between them is a defect to fix, not a matter of interpretation. We have no listing yet. When one is created, the following will be true and checkable.

  • Every type marked collected appears in section 6, with the same purpose, and every type marked optional maps to a setting or permission you can decline under section 11.
  • The answers on encryption in transit and on requesting deletion will both be yes, the latter supported by section 20.
  • Apple’s labels will never claim a lighter position than this notice, and where its categories are coarser the label takes the more cautious reading.

Tell us of any difference and we will correct whichever is wrong, in both places.

14. Recipients, processors and sub-processors

Controller

Each processor is engaged under a written Article 28 contract requiring it to act only on our instructions, keep the data confidential, apply appropriate security, help us answer your rights requests, and delete or return the data at the end.

Processors, sub-processors and other recipients
Organisation Role What it handles Where Transfer mechanism
Cloudflare, Inc. and Cloudflare Limited Processor. Hosting, delivery, security Website connection and security event data Global edge network, including outside the UK UK Addendum to the EU Standard Contractual Clauses
Google Ireland Limited and Google LLC (Google Fonts) Independent controller for the font request IP address and user agent, on typeface download Ireland and the United States Not a transfer by us. Your browser requests it
Our email provider Processor. Receiving, storing and sending email Everything in section 5 To be confirmed on selection To be confirmed on selection
Apple Distribution International Ltd and Apple Inc. Independent controller, once we publish an app Store account, payment, subscription, store analytics Ireland, the United States and elsewhere Apple’s own arrangements as controller
Google Ireland Limited and Google LLC (Google Play) Independent controller, once we publish an app Store account, payment, subscription, store analytics Ireland, the United States and elsewhere Google’s own arrangements as controller
Our accountant Processor for bookkeeping, controller for their own duties Invoices, receipts and payment records United Kingdom Not applicable
Application hosting and diagnostics providers Processors, only if an app needs a server or diagnostics Account data and optional diagnostics under section 6 To be confirmed on selection To be confirmed on selection

Two rows are unresolved, and we would rather show the gap than fill it with a plausible name. [TO CONFIRM: email provider, processing locations and transfer mechanism] [TO CONFIRM: application hosting and diagnostics providers]

We may also disclose data to a court, regulator, law enforcement body or professional adviser where we are legally required to, or where it is necessary for a legal claim. We do not answer informal requests from anyone, including law enforcement, without a lawful basis and a record of it. If the company is sold, data may transfer to the acquirer, and we will tell you where the law requires it.

15. International transfers

Controller

Some organisations in section 14 process personal data outside the United Kingdom. Chapter V of the UK GDPR permits that only under specific mechanisms. These are ours.

15.1 Adequacy regulations

Where the destination is covered by UK adequacy regulations under Article 45 and section 17A of the Data Protection Act 2018, no further mechanism is needed. That covers the European Economic Area and other recognised countries. For United States organisations certified under the UK Extension to the EU and US Data Privacy Framework, we check the certification is current and covers the data before relying on it.

15.2 The IDTA and the UK Addendum

Without adequacy cover we rely on the Information Commissioner’s International Data Transfer Agreement, or on the International Data Transfer Addendum to the European Commission’s Standard Contractual Clauses, both issued under section 119A of the Data Protection Act 2018. In practice a provider issues a data processing addendum incorporating the EU clauses with the UK Addendum on top, and that is the form we accept.

15.3 Transfer risk assessment

Before relying on either we assess the law and practice of the destination country, the sensitivity of the data, and the measures protecting it. Our processing is limited and holds no special category data, which keeps the risk low, but the assessment is done rather than assumed.

15.4 Seeing the safeguards

You may ask for a copy of the mechanism relied on for a transfer affecting you, and we will provide it, redacted only for commercial terms irrelevant to your data.

16. How long we keep personal data

Controller

Article 5(1)(e) requires that data is kept no longer than necessary. A period with no reason behind it is not a policy, so each row carries its reason.

Retention schedule
Record Period Reason for that period At the end
Website connection and security logs The provider’s short schedule. We keep no copy Useful only for immediate availability and security, stale within days Deleted or aggregated by the provider
General email correspondence 24 months from the last message Long enough to resume a conversation, short enough that old mail does not pile up Deleted, including sent items
Keep me posted list Until consent is withdrawn, or 36 months with no contact Consent never acted on goes stale Deleted, except a suppression record if you asked us to stop
Data protection requests 36 months from closure Evidence of Article 12 compliance, demonstrable under Article 5(2) Deleted
Security vulnerability reports 36 months from closure A record of what was reported and fixed is part of security Deleted or anonymised
Application account data Life of the account, then 30 days from a deletion request The data exists only to provide the account. Thirty days is our commitment Live systems first, then backups within 90 days
Optional crash diagnostics 12 months A crash older than a release cycle or two is useless Deleted
Accounting records, including subscription transactions Six years from the end of the financial year Section 386 Companies Act 2006 and HMRC corporation tax rules make six years the practical minimum Deleted or securely destroyed
Supplier and adviser records Six years from the end of the relationship The Limitation Act 1980 allows a contract claim within six years Deleted
Statutory registers and filings Life of the company, and after dissolution Companies Act 2006 obligation, not our choice As the law requires
Backups Rotating, overwritten within 90 days Backups exist to recover from failure, and editing one selectively would undermine it Overwritten

17. Security measures

Controller

Article 32 requires measures appropriate to the risk. Ours suit a company that deliberately holds very little.

  • The site is served only over HTTPS with Strict Transport Security, under a content security policy permitting scripts and styles only from this domain and typefaces only from Google’s font hosts.
  • The site is static: no database, no admin login on the internet, no server side code to subvert.
  • Provider accounts use unique credentials in a password manager, with multi factor authentication wherever supported.
  • Access is limited to those who need it for the task in hand.
  • Application data stays on the device where possible, removing the risk of a central store being breached. Where it leaves, it is encrypted in transit and at rest.
  • Dependencies and provider configurations are patched as updates appear.

We do not hold ISO 27001 certification, a SOC 2 report or Cyber Essentials certification, and we will not represent otherwise. If we obtain any, the certificate reference and certifying body will be published on our about page and here. No security measure is perfect and we do not claim ours is.

18. Your rights under the UK GDPR

Controller

Where we are the controller these rights are yours. Where we act as a processor they are exercised against the controller (sections 2.2 and 22).

18.1 How to exercise any of them

Email studio@yyysoftware.co.uk with the right you are exercising in the subject line. You need no form, article number or reason, except where a right requires one below. You may also ask verbally or through a representative, whose authority we will ask to see.

18.2 Verifying who you are

We must be satisfied of your identity first, because disclosing your data to the wrong person would itself be a breach. Usually a request from the address we already hold is enough. Where the data is not tied to an address, or we have a genuine doubt, we may ask for one further detail matching you to the record. We will not ask for a passport for a routine request, and will not keep anything sent for verification.

18.3 Timing

We respond without undue delay and in any event within one month of receipt, as Article 12(3) requires. Where a request is complex, or you have made several, we may extend by up to two further months and will tell you within the first month. The clock starts on receipt, or on the verification we reasonably asked for.

18.4 Cost, and when a request can be refused

Responding is free. Article 12(5) allows a reasonable fee, or a refusal, where a request is manifestly unfounded or excessive, in particular repetitive. If we rely on that we will explain why in writing, and tell you that you may complain to the Information Commissioner and seek a judicial remedy. Limits on individual rights are noted below.

18.5 Right of access, Article 15

You may ask whether we hold personal data about you and, if so, for a copy with the purposes, categories, recipients, retention period, source and transfer safeguards, sent electronically unless you ask otherwise. It does not reach other people’s data, so a document may be redacted, nor material subject to legal professional privilege.

18.6 Right to rectification, Article 16

If data we hold is inaccurate you may have it corrected, and if incomplete you may complete it, including by a supplementary statement. Where a fact is disputed rather than plainly wrong, we record your position beside ours. Where we have disclosed the data we tell the recipient, unless that is impossible or disproportionate.

18.7 Right to erasure, Article 17

You may ask us to delete data no longer necessary, where you withdraw the consent we relied on and no other basis applies, where you object successfully under Article 21, or where processing was unlawful. Erasure can be refused where we still need the data for a legal obligation. In practice that means accounting records: a transaction record cannot go before its six year statutory period has run, and we will say so.

18.8 Right to restriction, Article 18

You may ask us to hold data without using it: while we check accuracy you have contested, while we consider an objection, where processing is unlawful but you want it kept, or where we no longer need it but you do for a claim. While restricted we store it and do nothing else, except with your consent or for a claim, and we tell you before lifting it.

18.9 Right to data portability, Article 20

Where we process data you provided, by automated means, on consent or contract, you may have it in a structured, commonly used, machine readable format, and ask us to send it to another controller where feasible. It does not cover data processed on legitimate interests or a legal obligation, so it misses our correspondence and accounting records.

18.10 Right to object, Article 21

Where we rely on legitimate interests you may object on grounds relating to your particular situation, and we must stop unless we can show compelling legitimate grounds overriding your interests, or that we need the data for a claim. For direct marketing the right is absolute, needs no reason, and we stop at once. Replying "stop" to any message is enough.

18.11 Right to withdraw consent, Article 7(3)

Where processing is based on consent you may withdraw it at any time, as easily as you gave it. Withdrawal does not affect the lawfulness of processing before it, and is never a condition of anything else.

18.12 Rights on automated decisions, Article 22

See section 19. We take no decisions of the kind Article 22 covers.

18.13 Right to complain, Article 77

See section 23. You may complain to the Information Commissioner at any time.

19. Automated decision making and profiling

Controller

We take no decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you, within Article 22. We do not profile you for marketing, score you, or decide eligibility by algorithm.

Automated security filtering, deciding whether a suspicious request is served or challenged, is not an Article 22 decision. If you are wrongly blocked, email us and we will look by hand.

20. Account closure and data deletion

Controller

Both app stores require a developer offering accounts to provide a deletion route, including one startable from outside the app. This is that route. It applies to any application with accounts, and to personal data we hold about you generally.

20.1 The in app path

Any application with an account carries a deletion control at Settings, then Account, then Delete account. It asks you to confirm once, explains what is removed and what must be kept, then starts. You need not contact us or give a reason.

20.2 The email route

You may also email studio@yyysoftware.co.uk with "Delete my data" in the subject line, from the address on the account. This works whether or not you still have the application installed.

20.3 What happens, and how quickly

We acknowledge the request, verify your identity under section 18.2, and complete the deletion within 30 days of the verified request. Data goes from live systems first and from backups as they rotate, within 90 days. Backups are used only for disaster recovery, and a restore reinstating deleted data would be re-deleted at once.

20.4 What we keep afterwards, and why

  • Transaction records. Where you paid, the amount, date, transaction identifier and product form part of our accounting records and must be kept for six years from the end of the financial year, under section 386 of the Companies Act 2006 and HMRC requirements, on the basis in Article 6(1)(c).
  • A suppression record. Where you asked us to stop contacting you, normally a one way hash of your address, because deleting it would defeat its purpose.
  • A record of the request. The fact, date and our response, kept 36 months as evidence under Article 5(2).
  • Anything needed for a live legal claim, only while one is actually on foot.

Data held only on your device goes when you delete the application. We cannot do that for you, having never held it.

21. Personal data breaches

Controller

A personal data breach is a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. Losing data is a breach, not only leaking it.

21.1 What we do first

We contain it, establish what data and how many people are affected, log it whether or not it is reportable, and assess the risk to those involved. The log records the facts, the effects and the remedial action, as Article 33(5) requires.

21.2 Reporting to the ICO, Article 33

Where a breach is likely to result in a risk to rights and freedoms, we notify the Information Commissioner without undue delay and, where feasible, not later than 72 hours after becoming aware of it. A late report says why. Without the full picture at 72 hours we still report, in phases.

21.3 Telling you, Article 34

Where a breach is likely to result in a high risk to your rights and freedoms, we tell you without undue delay, in plain language, describing the likely consequences, what we have done or propose to do, and a contact point. Individual notice may not be required if the data was unintelligible to anyone unauthorised, for example through strong encryption, if we have removed the high risk, or if it would involve disproportionate effort, in which case we communicate publicly instead.

21.4 If a processor has the breach

Article 33(2) requires a processor to notify us without undue delay. That is in every processor contract we sign, and our 72 hour clock starts when they do.

22. Where we act as a processor

Processor

We do not process personal data on behalf of any other organisation. If that changed, we would:

  • process only on the controller’s documented instructions, and tell them if an instruction appeared to breach the law;
  • place everyone with access under a duty of confidentiality;
  • apply the measures in section 17 plus anything else the contract required;
  • engage no sub-processor without prior written authorisation, give notice of a change, and impose the same obligations by contract;
  • assist with rights requests, and forward any that reached us rather than answer it, telling you who the controller is;
  • notify the controller of a breach without undue delay, so they can meet their own 72 hour obligation;
  • delete or return the data at the end, at the controller’s choice; and
  • make available what is needed to demonstrate Article 28 compliance, and allow for audits.

Your rights are no weaker there, only exercised against a different organisation.

23. Complaints and the Information Commissioner

Controller

If you are unhappy with how we handled your data or your request, tell us at studio@yyysoftware.co.uk and we will look again and reply in writing. Under Article 77 you may complain to the Information Commissioner’s Office, the United Kingdom’s supervisory authority, whether or not you come to us first.

Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk/make-a-complaint

You also have a right to an effective judicial remedy under Articles 78 and 79, and to compensation under Article 82 for damage caused by an infringement.

24. Changes to this notice

Both roles

We update this notice when what we do changes, not to make what we already do sound better. Every version carries an effective date and version number. Where a change materially affects you, for example a new category of data, purpose or recipient, we make it before processing starts and, where we hold an address, tell you directly.

Version history: version 1.0, effective 7 August 2026, the first version of this notice.

25. How to contact us

Both roles

Data protection enquiries, rights requests and complaints go to the same place, and are handled by the company. We have not appointed a statutory Data Protection Officer, because we do not meet the Article 37 conditions that would require one.

YYY SOFTWARE LTD
Email: studio@yyysoftware.co.uk
Registered office: Flat 47 Bennets Courtyard, Watermill Way, London, SW19 2RW
Registered in England and Wales, company number 16938311

Post to the registered office reaches us, but email is the route we answer reliably. We aim to acknowledge a data protection request within three working days and answer it within one month.

Whether we must pay the ICO data protection fee depends on the processing we carry out. Our position is being confirmed, and any registration reference will be published here. [TO CONFIRM: ICO data protection fee registration status and reference number]