Privacy Policy
Effective date: 31 July 2026 · Last updated: 31 July 2026
This policy explains how UR DATA LIMITED handles personal data on this website and in our mobile applications. We have tried to write it in plain English; if anything is unclear, email us at contact@ur-data.co.uk.
1. Who we are
The data controller for the personal data described in this policy is:
UR DATA LIMITED
Registered in Northern Ireland, Company No. NI737745
Registered office: 22 Killary Lane, Dungannon, County Tyrone, Northern Ireland, BT71 5QE
Email: contact@ur-data.co.uk
Given our size and the nature of our processing, we are not currently required to appoint a Data Protection Officer. Our privacy contact for all matters under this policy is the email address above.
2. Scope of this policy
This policy covers:
- this website, https://ur-data.co.uk; and
- the mobile applications published by UR DATA LIMITED on the Apple App Store and Google Play (together, "our apps"), including the planned UR Data companion app that lets clients view their dashboards and reports.
It does not cover third-party websites we link to, or the data-processing work we perform for business clients under contract (where we generally act as a processor on the client's instructions and the client's own privacy notice applies).
3. Information we collect on the website
3.1 Correspondence
The website contains no contact forms. If you email us at contact@ur-data.co.uk, we receive your email address, anything you choose to include in your message, and standard email metadata. We use this solely to respond to you and to manage any resulting business relationship.
3.2 Technical and server logs
The website is hosted and delivered by Cloudflare, Inc. In the course of serving the site and protecting it from abuse, Cloudflare processes technical data such as your IP address, user agent (browser and device type) and request data (URLs requested, timestamps, response codes). We may review aggregated or security-related log information to keep the site available and secure.
3.3 No analytics or advertising cookies
The website itself sets no analytics cookies, no advertising cookies and no tracking scripts. See our Cookie Policy for the strictly-necessary cookies Cloudflare's security layer may set.
4. Information we collect in our apps
The subsections below describe the categories of data our apps may process. Where a particular app does not offer a feature (for example accounts or sync), the corresponding data is simply not collected.
4.1 Account information
If an app offers accounts, we collect the email address you register with and, optionally, a display name. Accounts are used only to identify you within the app, secure your content and enable sync. Apps that work without an account collect no account information.
4.2 User content created in the app
Content you create in an app — for example saved views, notes, preferences or report configurations — is stored on your device. If the app offers sync or is a companion to a service we run for your organisation (such as viewing dashboards we host), that content and the associated report data are also stored on our servers so they can be delivered to your devices. Your content remains yours; see our Terms of Use.
4.3 Device and technical data
To make the app work reliably we may process: device model, operating-system version, app version, language/locale, crash state, and a non-advertising install identifier (a random identifier scoped to the app installation, used for diagnostics and support — not for advertising).
4.4 Usage analytics (if enabled)
If usage analytics are enabled in an app, we collect aggregated feature-usage events (for example "report opened" counts) to understand which features are useful. No advertising identifiers are used, and analytics are never used to profile individuals.
4.5 Crash and diagnostics reports
If the app crashes, a diagnostic report (stack trace, device model, OS version, app version, crash state) may be collected so we can fix the problem. Crash reports are not used for any other purpose.
4.6 App permissions
Our apps request only the permissions they need, each is optional, and each can be revoked at any time in your device's system settings:
| Permission | Purpose | Optional? |
|---|---|---|
| Notifications | Alerting you when a new report is available or a metric you follow changes (only if you turn alerts on) | Yes — revocable in system settings |
| Biometrics / device unlock (Face ID, Touch ID, or equivalent) | Optionally locking the app so your business data stays private; biometric data never leaves your device | Yes — revocable in system settings |
| Camera / photo library | Only if a specific app feature needs it (for example attaching an image to a note); requested at the moment of use | Yes — revocable in system settings |
4.7 What we do NOT do
- We do not sell personal data — to anyone, ever.
- We do not include advertising SDKs in our apps.
- We do not track you across other companies' apps or websites.
- We do not collect precise location data.
5. Purposes and lawful bases
Under UK GDPR we must have a lawful basis for each use of personal data:
| Purpose | Data categories | Lawful basis |
|---|---|---|
| Responding to your enquiries and correspondence | Email address, message content | Legitimate interests (running and promoting our business and answering the people who write to us) |
| Providing app features you sign up for (accounts, sync, report delivery) | Account information, user content, device data | Performance of a contract (our Terms of Use / our agreement with you or your organisation) |
| Keeping the website and apps secure and available | Server logs, technical data, crash state | Legitimate interests (security, fraud prevention and service reliability) |
| Fixing bugs and crashes | Crash and diagnostics reports | Legitimate interests (maintaining a working, safe product) |
| Understanding aggregate feature usage (only if analytics are enabled) | Aggregated usage events | Consent, where required; otherwise legitimate interests (improving the product), always without advertising identifiers |
| Sending optional notifications | Device push token, alert preferences | Consent (you enable notifications; you can withdraw at any time in system settings) |
| Keeping business and accounting records | Invoicing and correspondence records | Legal obligation (UK tax and company law) |
6. Who we share data with
We share personal data only with service providers who process it on our behalf under contract, and only as needed to run our services:
- Cloudflare, Inc. — website hosting, content delivery and security for ur-data.co.uk.
- Apple Inc. and Google LLC — distribution of our apps through the Apple App Store and Google Play and, where used, in-app purchase billing. For the purchase transaction itself, Apple and Google act under their own privacy policies; we never see your full payment details.
- Crash-reporting or analytics tooling — only if enabled in a given app, limited to the diagnostics and aggregated usage data described in section 4, and configured without advertising identifiers. We commit to keeping this section up to date with the specific providers in use at any time.
We do not sell or rent personal data. We may disclose personal data where required by law, court order, or to protect our legal rights, and in the unlikely event of a business sale or reorganisation, in which case this policy would continue to apply to the transferred data.
7. International transfers
Some of our service providers process data outside the United Kingdom — for example, Cloudflare operates a global network. Where personal data leaves the UK, we rely on one or more of the following safeguards: UK adequacy regulations for the destination country; the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses; or standard contractual clauses with supplementary measures where appropriate.
8. How long we keep data
| Data | Retention period |
|---|---|
| Email correspondence | Up to 24 months after our last contact with you, unless a longer period is needed for an active contract or legal claim |
| Website server and security logs | Held by Cloudflare on its short rolling retention schedule; we do not maintain a separate long-term copy |
| App account data and synced content | For as long as your account exists; deleted within 30 days of account deletion |
| Crash and diagnostics reports | 90 days |
| Backups | Purged on a rolling 30-day cycle, so deleted data leaves backups within 30 days of deletion |
| Invoicing and statutory business records | As required by UK tax and company law (typically 6 years) |
9. Your rights
Under UK GDPR you have the following rights over your personal data:
- Access — ask for a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — ask us to delete your data ("right to be forgotten"), subject to any legal retention duties.
- Restriction — ask us to limit how we use your data while a concern is resolved.
- Portability — receive data you provided to us in a structured, commonly used, machine-readable format.
- Objection — object to processing based on legitimate interests; we will stop unless we have compelling grounds.
- Withdrawal of consent — where processing is based on consent (for example notifications), withdraw it at any time without affecting earlier processing.
- Automated decision-making — rights in relation to solely automated decisions with legal or similarly significant effects. We do not make any such decisions about you.
To exercise any right, email contact@ur-data.co.uk. We will respond within one month. We may need to verify your identity before acting on a request — for example by asking you to write from the email address associated with your account — to make sure we do not disclose or delete data at the wrong person's request.
10. Complaints
You have the right to complain to the UK supervisory authority, the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Telephone: 0303 123 1113
Website: https://ico.org.uk/
We would welcome the chance to resolve any concern first — please contact us at contact@ur-data.co.uk before going to the ICO, though you are not required to.
11. Children
Our website and apps are business tools and are not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, contact contact@ur-data.co.uk and we will delete it. The age ratings shown for our apps on the Apple App Store and Google Play also apply.
12. Account and data deletion
You can delete your account and associated data at any time, in either of two ways:
- In the app: once our apps ship, go to Settings → Account → Delete account. This deletes your account and synced content from our servers.
- By email: send a request to contact@ur-data.co.uk with the subject line "Account deletion request", from the email address associated with your account.
Deletion is completed within 30 days of the request, including removal from rolling backups. A minimal set of records may be retained beyond that where the law requires it — for example invoices and payment records kept for UK tax purposes, or records needed to establish or defend legal claims — and such records are kept only as long as those obligations require.
13. iOS App Tracking Transparency
Our apps do not track users across other companies' apps or websites, and do not share user data with data brokers. Because no tracking (as defined by Apple's App Tracking Transparency framework) takes place, our apps do not show the ATT permission prompt. If this ever changed, we would request your consent first through the ATT framework before any tracking occurred, and update this policy.
14. Google Play Data Safety
The Data Safety declarations for our apps on Google Play are prepared from this policy and are kept consistent with it. If you ever spot a discrepancy between a Play Store listing and this policy, please tell us at contact@ur-data.co.uk and we will correct it.
15. Security
We protect personal data with measures appropriate to our size and the sensitivity of the data, including: TLS encryption for data in transit; encryption at rest where applicable on our hosting providers' infrastructure; least-privilege access controls, so data is accessible only to those who need it; and separation of client environments. In the event of a personal-data breach likely to result in a risk to your rights and freedoms, we will notify the ICO and, where required, affected individuals in accordance with Articles 33 and 34 of UK GDPR.
16. Changes to this policy
When we change this policy we will update the "last updated" date at the top of this page, and for material changes affecting app users we will additionally announce the change in the app or by email before it takes effect. Earlier versions are available on request. We review this policy at least annually.
17. Contact
Questions, requests and complaints about this policy or your personal data:
Email: contact@ur-data.co.uk
Post: UR DATA LIMITED, 22 Killary Lane, Dungannon, County Tyrone, Northern Ireland, BT71 5QE