Privacy Policy
Last updated: 1 January 2025
1. Introduction
TechPayeX Ltd ("TechPayeX", "we", "us", "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use the TechPayeX software application and related services ("Service"). This policy complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. If you have any questions about this policy, please contact our Data Protection team at privacy@techpayex.com.
2. Data Controller
TechPayeX Ltd is the data controller responsible for your personal data. Our registered address is in London, United Kingdom. For data protection queries, contact: privacy@techpayex.com.
3. Information We Collect
We collect the following categories of personal data: Account Information: Name, email address, and password when you create an account. Payment Information: Billing address and payment card details (processed and stored by our PCI-DSS compliant payment processor — we do not store full card numbers on our servers). Device and Technical Data: Operating system version, hardware identifiers, software version, crash logs, and performance metrics collected to provide and improve the Service. Usage Data: Information about how you interact with the application, including features used, scan frequency, and session duration. Communication Data: Any information you provide when you contact our support team. We do not access, read, or transmit the personal files, documents, or private data stored on your computer.
4. How We Use Your Data
We use your personal data for the following purposes: Service Delivery: To provide, maintain, and improve the TechPayeX software and associated services. Account Management: To create and manage your account, process payments, and send subscription-related communications. Customer Support: To respond to your enquiries and resolve technical issues. Product Improvement: To analyse usage patterns and crash reports to identify bugs and improve software performance. Legal Compliance: To comply with applicable legal obligations and respond to lawful requests from authorities. Security: To detect, prevent, and respond to fraudulent activity, abuse, and security threats. We will not use your data for unsolicited marketing without your prior consent.
5. Legal Basis for Processing
Under UK GDPR, we process your personal data under the following legal bases: Contractual Necessity: Processing required to perform the contract for providing the Service to you (e.g., account management, payment processing). Legitimate Interests: Processing for our legitimate business interests, including fraud prevention, software improvement, and security, where these interests are not overridden by your data protection rights. Legal Obligation: Processing required to comply with applicable law. Consent: Where we process data based on your consent (e.g., optional communications), you may withdraw consent at any time without affecting the lawfulness of prior processing.
6. Data Sharing and Disclosure
We do not sell your personal data to third parties. We may share your data with: Service Providers: Third-party vendors who assist us in operating the Service (e.g., payment processors, cloud hosting providers, analytics platforms). These providers are contractually obligated to process data only as directed by us and to maintain appropriate security standards. Legal Authorities: Where required by law, court order, or governmental authority. Business Transfers: In connection with a merger, acquisition, or sale of all or substantially all of our assets, your data may be transferred to the acquiring entity, subject to equivalent data protection obligations. Any data shared with third parties is done under appropriate contractual safeguards.
7. International Data Transfers
Your personal data may be transferred to and processed in countries outside the UK or European Economic Area (EEA). Where such transfers occur, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the UK Information Commissioner's Office (ICO), to ensure your data receives equivalent protection.
8. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected and to comply with legal obligations. Specifically: Account data is retained for the duration of your subscription and for up to 3 years after account closure for legal and audit purposes. Technical and diagnostic data is retained for up to 12 months. Support communications are retained for up to 2 years. Once data is no longer needed, it is securely deleted or anonymised.
9. Your Rights
Under UK GDPR, you have the following rights regarding your personal data: Right of Access: To request a copy of the personal data we hold about you. Right to Rectification: To request correction of inaccurate or incomplete data. Right to Erasure: To request deletion of your data in certain circumstances (the "right to be forgotten"). Right to Restriction: To request that we restrict processing of your data in certain circumstances. Right to Data Portability: To receive your data in a structured, machine-readable format. Right to Object: To object to processing based on our legitimate interests. Rights Related to Automated Decision-Making: We do not make decisions based solely on automated processing that have legal or similarly significant effects on you. To exercise any of these rights, contact us at privacy@techpayex.com. We will respond within 30 days. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.
10. Security
We implement appropriate technical and organisational security measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These measures include 256-bit SSL/TLS encryption for data in transit, encrypted storage of sensitive data at rest, access controls and authentication mechanisms, regular security audits, and staff training on data protection. While we use commercially reasonable efforts to protect your data, no method of transmission over the Internet or electronic storage is 100% secure. We encourage you to maintain unique, strong passwords for your account.
11. Cookies
The TechPayeX website uses cookies and similar tracking technologies to improve your browsing experience, analyse site traffic, and remember your preferences. You can control cookie settings through your browser settings or our cookie preference centre. Disabling certain cookies may affect the functionality of our website. Our software application does not use browser cookies.
12. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without parental consent, we will take steps to delete that information promptly. If you believe we have inadvertently collected data from a child, please contact us at privacy@techpayex.com.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by updating the date at the top of this page and, where appropriate, by sending an email notification. Your continued use of the Service following any changes constitutes your acceptance of the updated policy.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or the way we handle your data, please contact our Data Protection team: Email: privacy@techpayex.com Address: TechPayeX Ltd, London, United Kingdom We aim to respond to all data protection enquiries within 30 days.