Legal
GDPR Policy
Version 1.6
Document owner: Oliver Theakston, Director (DPO)
1. Introduction
Dashworx Ltd (“we”, “our”, “us”) is committed to protecting the privacy and personal data of our clients, users and partners in accordance with the UK General Data Protection Regulation (“UK GDPR”), the EU GDPR (where applicable) and the Data Protection Act 2018.
This policy explains how we collect, use, store and protect personal data, and the rights of individuals regarding their data.
2. Scope
This policy applies to all personal data processed by Dashworx Ltd in connection with:
Provision of related services, including onboarding, consultancy and support.
Business operations, including marketing and communications.
Any interface-centric products provided to clients.
3. Data Controller
Dashworx Ltd acts as the Data Controller for personal data it collects directly from clients and users. In some cases, where we process personal data on behalf of a client, we may act as a Data Processor under their instructions.
Dashworx Ltd
167-169 Great Portland Street, Fifth Floor, London, W1W 5PF
Company number: 14999312
4. Data Collection & Classification
We implement procedures to ensure personal data collection is limited to what is strictly necessary for the performance of our interface-centric platform and associated services (data minimisation).
Where the retention of personal data is required for authentication and service delivery, such data is strictly limited to:
User names;
Email addresses; and
Encrypted passwords.
4.1 Data categories and classification
We classify data into the following tiers to ensure appropriate governance and alignment with our Information Security Programme:
Public — information approved for general distribution, such as marketing materials and public website content.
Internal — non-sensitive operational data accessible via single sign-on (SSO), including internal communications and business documents.
Confidential (personal data) — strictly limited to authentication metadata, specifically user names, email addresses and encrypted passwords. Dashworx does not ingest, replicate or store external client business data.
Restricted (sensitive) — we do not intentionally collect special category data. If provided, it is subject to immediate encryption and strict access silos.
5. Lawful Basis & Usage
We process personal data only where lawful under Article 6 GDPR, including:
Contractual necessity — to deliver our services.
Legitimate interests — to improve our interface-centric platform and protect systems.
Consent — for marketing.
Legal obligation — to comply with applicable laws.
6. Access Control Policy
Dashworx maintains a documented Access Control Policy to prevent unauthorised internal and external access to our systems.
Account setup and authorisation — formal administrative procedures govern the creation, modification and removal of user accounts. Access is granted based on the Principle of Least Privilege.
Internal access limits — role-based access control (RBAC) ensures employees only access data necessary for their specific job function within the platform environment.
Sharing restrictions — internal sharing of personal data is restricted to authorised personnel via secure, encrypted channels. Sharing with third parties is governed by Data Processing Agreements (DPAs).
7. Data Sharing and Transfers
We share data only with service providers bound by GDPR-compliant contracts. Transfers outside the UK and EU are protected by standard contractual clauses (SCCs).
8. Data Retention, Deletion & Disposal
We retain personal data only as long as necessary for the provision of our services.
Retention schedule — client account data is retained for the duration of the contractual agreement plus 12 months.
Deletion procedures — upon the expiry of the retention period, or on a valid request, data is permanently deleted from primary databases and backup cycles.
Media restrictions and asset decommissioning — Dashworx operates as a paperless organisation and the physical printing of any data is prohibited. Consequently, no physical personal data is stored or maintained. Any hardware scheduled for decommissioning undergoes a verified factory reset to ensure all system-level tokens and cached credentials are removed.
9. Data Subject Access Request (DSAR) Policy
Individuals may exercise their rights, including access, rectification and erasure, by contacting dpo@dashworx.co.uk.
Process — we verify identity before processing requests.
Timeline — we respond to all valid DSARs within one month, as required by law.
10. Data Security & Technical Measures
We implement high-level security measures, including:
Secure two-factor authentication (2FA) for all administrative access.
AES-256 encryption for data at rest and TLS 1.2 or higher for data in transit.
Change management — all updates to the interface-centric platform undergo a documented change management process, including security impact assessments.
11. Incident Response & Breach Notification
Dashworx maintains a documented Security Incident Response Plan (SIRP).
Detection and reporting — incidents are logged and investigated immediately by the DPO.
Notification — in the event of a breach, we notify the Information Commissioner’s Office (ICO) within 72 hours.
Controller and processor communication — if acting as a processor, we notify the relevant Data Protection Officer immediately upon discovery of a breach to ensure legal and regulatory compliance.
12. Contact Us
For questions, requests or complaints, please contact:
Data Protection Officer
Dashworx Ltd
Email: dpo@dashworx.co.uk
Complaints may also be raised with the ICO at ico.org.uk.