This notice is published in advance so that it can be read before anyone installs anything. Sections that describe an application state the position that will apply from the first release. Sections that describe this website describe what happens today. Where the position is genuinely not yet settled, it is marked in the text rather than filled in with a guess.
1. Scope of this notice
This notice explains how WILDDECK LTD handles personal data. It covers two things, and it is written so that you can tell at every point which of the two is being described.
The first is this website, wilddeck.co.uk. The website is a set of static files. It has no accounts, no login, no comment facility, no newsletter, no shopping basket and no forms of any kind. The only way to send anything to the company from this site is to use one of the published email links, which open your own mail application. Nothing you type is captured by the site itself, because there is nothing in the site capable of capturing it.
The second is any mobile application published by WILDDECK LTD. As at the effective date there is no such application: nothing has been submitted to the Apple App Store or Google Play, there is no test build and no release date. The application sections below are therefore commitments about how a first release will be built. They bind the company when a release happens, and any change to them is published before that release rather than after it.
This notice covers no other company. A mobile application published under a similar name by an unrelated operator, and a British timber firm with a similar name, are not connected with WILDDECK LTD and are not governed by this notice.
2. Who the controller is
The controller of the personal data described in this notice is:
| Registered name | WILDDECK LTD |
|---|---|
| Company number | SC880737 |
| Jurisdiction of registration | Scotland |
| Registered office | |
| Contact for data protection | hello@wilddeck.co.uk, subject line: Data protection request |
| Data protection officer | None appointed. WILDDECK LTD is not a public authority, does not carry out large scale systematic monitoring, and does not process special category data at scale, so Article 37 of the UK GDPR does not require one. Data protection questions go to the address above and are handled by the company. |
| ICO registration | [TO CONFIRM: ICO data protection fee registration reference, once the fee is paid and the entry appears on the ICO register] |
| EU representative | None appointed. The company does not currently offer goods or services to individuals in the European Union or monitor their behaviour, so Article 27 of the EU GDPR does not apply. If that changes, a representative will be appointed and named here before any offering begins. |
3. Controller and processor: which role applies where
The two roles carry different duties, and a notice that blurs them is not much use to a reader trying to work out who to hold responsible. Every section of this notice that involves a downstream party is therefore marked with the role WILDDECK LTD holds for that activity.
3.1 Where WILDDECK LTD is the controller
Role: controller
WILDDECK LTD decides why and how personal data is processed, and is therefore the controller, for all of the following: correspondence sent to its published mailbox; the operation of this website including the technical logs kept by its hosting provider; any account a person creates in a future application; any purchase records the company receives from an app store; any support conversation; and any record it must keep to satisfy company law, tax law or its own accounting obligations. In every one of those cases the company answers for the processing, and a request under any of the rights in section 10 should be sent to it.
3.2 Where a third party is an independent controller
Role: not the controller
Two categories of processing are outside the company's control entirely, and it is important not to imply otherwise.
App store operators. Where a person downloads or pays for an application through the Apple App Store or Google Play, the store operator is an independent controller of that transaction and decides what it collects, holds and keeps. WILDDECK LTD never sees a full payment card number and receives only the limited transactional and aggregate reporting a store makes available to a developer. A data rights request about that processing must go to the store operator.
Your own email provider. Mail you send passes through your provider before it reaches the company. That provider is an independent controller of your mailbox. WILDDECK LTD is the controller of the copy that arrives in its own mailbox and of nothing before that point.
3.3 Where WILDDECK LTD acts through a processor
Role: controller, using processors
The company uses a small number of suppliers that process personal data on its instructions and for no purpose of their own. Those suppliers are processors within the meaning of Article 4(8) of the UK GDPR, and each is engaged under a written contract containing the terms required by Article 28(3). They are named individually in section 7. WILDDECK LTD remains the controller for all of that processing, and a request about it should be sent to the company rather than to the supplier.
3.4 Where WILDDECK LTD might in future be a processor
Role: processor, not applicable today
WILDDECK LTD does not currently process personal data on behalf of any other organisation. It has no clients, no enterprise customers and no data processing agreements in place under which it would act as somebody else's processor. If that ever changes, this section will be replaced with a description of the arrangement and the categories of processing involved, and the change will be published before the arrangement begins.
4. What is collected through this website
Role: controller
The table below is the complete inventory for the website as it stands on the effective date. If a field is not in this table, it is not collected. Lawful bases are cited to the article of the UK GDPR, and where the basis is legitimate interests the interest itself is named, because a bare citation of Article 6(1)(f) tells a reader nothing about what is actually being balanced.
| Category | Example fields | Source | Purpose | Lawful basis | Retention | Recipients |
|---|---|---|---|---|---|---|
| Server request data | IP address, timestamp, requested path, HTTP status, user agent string, approximate country derived by the network from the IP address | Automatically generated by your browser when it requests a page | Serving the page, protecting the site against denial of service and automated abuse, and diagnosing errors | Article 6(1)(f), legitimate interests. The interest is keeping a public website available and defended against attack. Proportionate because the data is minimal, is not combined with anything else and builds no profile. | Held in the hosting provider's edge logs for up to 30 days. WILDDECK LTD keeps no separate copy. | Cloudflare, Inc. as processor |
| Security event data | Rate limiting counters, blocked request records, bot scores generated by the network layer | Generated at the network edge in response to traffic | Blocking automated abuse and keeping the site reachable | Article 6(1)(f), legitimate interests. The interest is network and information security, which recital 49 of the UK GDPR expressly recognises as a legitimate interest. | Retained by the hosting provider under its own security event schedule, generally not more than 30 days | Cloudflare, Inc. as processor |
| Font request data | IP address and user agent sent to Google's font servers when your browser fetches the two typefaces this site uses | Automatically generated by your browser | Delivering the web fonts the site is set in | Article 6(1)(f), legitimate interests. The interest is presenting the site legibly and consistently. Disclosed because the request leaves the company's own infrastructure. | Governed by Google's retention practice for its font service. WILDDECK LTD receives and keeps none of it. | Google LLC and Google Ireland Limited, as an independent recipient for this narrow purpose |
| Correspondence | Your email address, your name if you sign your message, the subject line, the message body and any attachment you choose to send | Supplied by you when you write to the published mailbox | Reading and answering your message, and keeping a record of what was said | Article 6(1)(f), legitimate interests. The interest is answering correspondence addressed to the company and evidencing what was answered. Where the message concerns a contract or a step before one, Article 6(1)(b) applies instead. | 24 months from the last message, unless the thread forms part of an accounting record or a legal claim, when section 9 applies | The company's email hosting provider as processor, named in section 7 |
| Data rights request records | The request itself, the identity evidence you supply, the company's response and the date it was sent | Supplied by you when you exercise a right under section 10 | Handling the request, and being able to demonstrate to the ICO that it was handled correctly | Article 6(1)(c), legal obligation, read with Article 5(2), accountability. Identity evidence is processed under Article 6(1)(c) for the check required by Article 12(6). | Request and response 3 years. Identity evidence deleted once the check is complete, within 30 days. | The company's email hosting provider as processor |
This website sets no cookies of its own, runs no analytics, embeds no social widgets and carries no advertising or tracking pixels. The cookie statement sets out the full position.
5. What is collected through an application
Role: controller, from first release
No application exists yet. The table below is a design constraint published in advance: the maximum set of personal data a first release would process. Anything outside it requires this notice to be updated and republished first.
| Category | Example fields | Source | Purpose | Lawful basis | Retention | Recipients |
|---|---|---|---|---|---|---|
| Content you create in the app | Whatever the application is for: text you enter, items you save, settings you choose | Created by you on your own device | Making the application work | Article 6(1)(b), performance of the contract formed by accepting the terms of use | On your device until you delete it or remove the application. The company holds no copy. | None. This data does not leave your device. |
| Device backup copies | The same content, if your device is set to back up application data | Copied by your operating system, at your device setting | Restoring your own device | Not processed by WILDDECK LTD at all. Your backup is between you and your device platform. | Controlled entirely by your own backup settings | Apple or Google as your platform backup provider, acting for you |
| Account identifiers | Email address and a hashed password, or a platform sign in identifier, only if a release includes accounts | Supplied by you at sign up | Letting you sign in and recover access | Article 6(1)(b), performance of the contract | For as long as the account exists, then deleted within 30 days of a closure request. See section 11. | Hosting and email processors named in section 7 |
| Purchase and subscription records | Transaction identifier, product identifier, purchase date, subscription state, country of the store account | Received from Apple or Google after a purchase | Granting the entitlement you paid for, handling refunds and renewals, and keeping the accounting record | Article 6(1)(b) for the entitlement. Article 6(1)(c) for the accounting record, read with section 388 of the Companies Act 2006 and HMRC business record requirements. | 6 years from the end of the financial year concerned, the statutory period for UK accounting records | Apple and Google as independent controllers of the transaction; the company's accountant as processor |
| Crash and diagnostic reports | Stack trace, application version, operating system version, device model, free memory at the time of the crash | Generated on your device when the application fails | Finding and fixing defects | Article 6(1)(a), consent. Off unless you turn it on, and turning it off stops it. Platform level crash reporting you have enabled in the operating system is a separate matter between you and the platform. | 90 days from receipt, then deleted | The crash reporting processor named in section 7, if one is used |
| Support correspondence | Your email address, your message, the application version you tell us about | Supplied by you | Answering your support request | Article 6(1)(b) where the request concerns the product you have paid for, otherwise Article 6(1)(f), the legitimate interest being answering correspondence sent to the company | 24 months from the last message in the thread | The company's email hosting provider as processor |
| Advertising identifiers | None | Not applicable | Not applicable | No basis, because none is collected. WILDDECK LTD does not read the Identifier for Advertisers on iOS or the Advertising ID on Android, and does not embed any advertising software development kit. | Not applicable | None |
6. Device permissions
Role: controller, from first release
A person deciding whether to grant a permission deserves to know what happens either way before the system prompt appears. No permission is requested routinely at first launch. Each is requested when the feature that needs it is used, with an on screen explanation immediately before the prompt.
| Permission | Why it would be asked for | Required or optional | If you decline | How to revoke it later |
|---|---|---|---|---|
| Notifications | Sending a reminder or an alert that you have asked for inside the application | Optional | The application works normally and sends no notifications. No feature is withheld. | iOS: Settings, Notifications, the application, Allow Notifications off. Android: Settings, Apps, the application, Notifications, off. |
| Photo library | Letting you choose an image to bring into the application, only when you tap a control that asks for one | Optional | You cannot import from your library. Everything else works. On iOS, selected photos only is treated as a full grant for this purpose. | iOS: Settings, Privacy and Security, Photos, the application. Android: Settings, Apps, the application, Permissions, Photos and videos. |
| Camera | Capturing an image directly rather than picking one from your library | Optional | You can still import from your library if that is granted. No other feature is affected. | iOS: Settings, Privacy and Security, Camera, the application. Android: Settings, Apps, the application, Permissions, Camera. |
| Microphone | Recording audio, only if a release includes a feature that records audio | Optional | Audio recording is unavailable. Nothing else changes. | iOS: Settings, Privacy and Security, Microphone, the application. Android: Settings, Apps, the application, Permissions, Microphone. |
| Precise or approximate location | Not requested. A consumer application of the kind intended has no need for location, and no release will ask for it without this notice being updated first. | Not requested | Not applicable | Not applicable |
| Contacts | Not requested. There is no feature planned that reads your address book. | Not requested | Not applicable | Not applicable |
| App Tracking Transparency, iOS | Not requested. The prompt is required only where an application tracks across other companies' apps and websites. See section 14. | Not requested | Not applicable | Not applicable. iOS shows the position under Settings, Privacy and Security, Tracking. |
A declined permission is never used as a reason to degrade an unrelated part of the application, and a refusal is not re-prompted. If you change your mind, use the operating system settings above.
7. Sub-processors
Role: controller, using processors
These are the third parties that process personal data on the company's instructions. Each is engaged under a written contract that includes the obligations required by Article 28(3) of the UK GDPR. The list is short because the company is small and intends to keep it that way.
| Processor | Service provided | Data it can access | Processing location | Transfer mechanism |
|---|---|---|---|---|
| Cloudflare, Inc. | Static hosting and content delivery for wilddeck.co.uk, plus network layer protection against automated abuse | Server request data and security event data as described in section 4. No content, because the site collects none. | Global edge network. UK requests are normally served from a UK or European point of presence. The provider is a United States corporation. | UK International Data Transfer Addendum to the EU standard contractual clauses, incorporated into the provider's data processing terms |
| Email hosting provider | Receiving and storing mail sent to hello@wilddeck.co.uk | The full content of correspondence, including anything you choose to put in it | [TO CONFIRM: processing location of the email hosting provider for hello@wilddeck.co.uk] | [TO CONFIRM: provider name, and whether the UK IDTA or the UK Addendum to the EU SCCs applies to it] |
| Accountant | Preparation of statutory accounts and tax returns | Purchase and payment records once trading begins. No application content and no correspondence. | United Kingdom | Not applicable, no transfer outside the United Kingdom |
| Crash reporting provider | Receiving optional crash reports from a future application | Crash and diagnostic data as described in section 5, and only where you have switched the option on | Not engaged. No provider selected, because there is no application. | Will be named here, with location and mechanism, before any release that sends a crash report anywhere |
Google LLC and Google Ireland Limited are not listed as processors, because the font request in section 4 goes directly from your browser to Google's servers on no instruction from the company. It is disclosed anyway, since the practical effect is that your IP address reaches a third party when you load a page here. Most browsers and content blockers can block fonts.googleapis.com and fonts.gstatic.com, and this site remains fully readable in a system typeface if you do.
A new processor is added to this table before it begins handling personal data, not afterwards.
8. International transfers
Role: controller
8.1 The default position
WILDDECK LTD is a United Kingdom company and its default is to keep personal data in the United Kingdom. Where that is not possible, a transfer only happens on one of the bases set out below, and the basis for each supplier is recorded in the sub-processor table in section 7.
8.2 Adequacy
The United Kingdom recognises certain countries and territories as providing an adequate level of protection, under regulations made pursuant to Article 45 of the UK GDPR and section 17A of the Data Protection Act 2018. That list includes the European Economic Area. A transfer covered by UK adequacy regulations needs no additional safeguard, and the company relies on adequacy where a supplier processes within the European Economic Area.
The United Kingdom has also adopted a partial adequacy finding for United States organisations certified under the UK Extension to the EU-US Data Privacy Framework. Where a supplier holds a valid certification, transfers are covered while it remains valid. The company does not treat that as a substitute for a contractual safeguard and prefers to have both.
8.3 The International Data Transfer Agreement
Where a transfer goes to a country not covered by adequacy regulations, the company relies on the International Data Transfer Agreement issued by the Information Commissioner under section 119A of the Data Protection Act 2018, known as the IDTA. It is a standalone contract between exporter and importer providing appropriate safeguards for the purposes of Article 46(2) of the UK GDPR, and is used where the company contracts directly with no existing European clauses to build on.
8.4 The UK Addendum to the EU standard contractual clauses
Many suppliers already operate on the European Commission's standard contractual clauses adopted in June 2021. For those suppliers, the company relies on the International Data Transfer Addendum to the EU standard contractual clauses, commonly called the UK Addendum. The Addendum applies the EU clauses to a UK transfer with the modifications the Information Commissioner has specified, so that a single set of clauses can serve both. This is the mechanism relied on for Cloudflare, Inc., whose data processing terms incorporate the EU clauses with the UK Addendum.
8.5 Transfer risk assessment
Neither instrument is treated as a formality. Before relying on either, the company considers whether the law and practice of the destination country would in fact prevent the importer honouring the clauses, and whether a supplementary measure is needed. For a company of this size the measures that matter are encryption in transit and at rest, minimising what is sent at all, and choosing suppliers that publish transparency reporting on government access requests. Where a transfer cannot be made safe, it is not made.
8.6 Your rights are unaffected by location
The rights in section 10 apply wherever data is processed. A supplier being outside the United Kingdom is never a reason the company will give for failing to answer a request.
9. How long data is kept
Role: controller
Storage limitation is a principle under Article 5(1)(e) of the UK GDPR, and a retention schedule with no stated reason is not a schedule, it is a habit. Every row below carries the reason the period is what it is.
| Record | Period | Reason for that period | What happens at the end |
|---|---|---|---|
| Web server request logs | Up to 30 days | Long enough to investigate an incident or a traffic anomaly, short enough that the data is not a standing liability. Set by the hosting provider's default, which the company has not extended. | Deleted by the hosting provider |
| Security event records | Up to 30 days | Matches the log period, because a security event is only useful alongside the request log it relates to. | Deleted by the hosting provider |
| General correspondence | 24 months from the last message in the thread | Long enough to pick up a conversation that resumes after a gap and to answer a follow up question about what was said. Not indefinite, because most correspondence stops being useful within two years. | Thread deleted from the mailbox |
| Support correspondence about a paid product | 24 months from the last message, or 6 years where it evidences a purchase or a complaint | The shorter period covers ordinary support. The longer one aligns with the limitation period for a contractual claim, which in Scotland is 5 years under the Prescription and Limitation (Scotland) Act 1973 and in England and Wales is 6 years under the Limitation Act 1980. The company uses the longer of the two so that a customer anywhere in the United Kingdom is not disadvantaged. | Deleted or, where still needed for a live claim, retained until the claim ends |
| Accounting records, including purchase and subscription records | 6 years from the end of the financial year to which they relate | Section 388 of the Companies Act 2006 requires a private company to preserve its accounting records for 3 years, and HM Revenue and Customs requires business records supporting a tax return to be kept for 6 years from the end of the relevant accounting period. The company applies the longer period to everything, so 6 years is the operative figure. | Deleted after the statutory period expires |
| Account records in a future application | Life of the account, then deleted within 30 days of closure | The account exists to perform the contract. Once the contract ends there is no basis to keep the credentials, and 30 days is the company's published completion commitment. | Deleted, except for the accounting record described above |
| Optional crash reports | 90 days from receipt | A crash report loses diagnostic value once the release it relates to has been superseded. Ninety days covers a normal release cycle with room for a slow reproduction. | Deleted |
| Data rights request records | 3 years from the response | Needed to demonstrate compliance under Article 5(2) if the ICO asks, and to show a consistent position if the same person asks again. Three years is a reasonable window for a regulator to look back over. | Deleted |
| Identity evidence supplied with a rights request | Until the check is complete, and no more than 30 days | Identity documents are sensitive and their only purpose is the single check required by Article 12(6). Keeping them afterwards creates risk with no corresponding benefit. | Deleted, with a note on the request record that a check was completed |
| Records relating to a personal data breach | 6 years from the incident | Article 33(5) requires the company to document every breach so that the ICO can verify compliance. Six years matches the outer limit for related claims. | Deleted |
10. Your rights under the UK GDPR
Role: controller
Each right has its own subsection below, because bundling them into one paragraph makes it harder to work out which one you want. All of them are exercised the same way, and the mechanics common to every request are set out first.
10.1 How to make a request, and what happens next
Write to hello@wilddeck.co.uk with the subject line Data protection request Say which right you are exercising and give the email address the company would hold for you. There is no form to complete and no particular wording is required.
Identity verification. Article 12(6) allows a controller to ask for the information it needs to confirm who you are, and it must do so where it has reasonable doubts. The company's approach is proportionate rather than obstructive. If you write from the address it already holds for you, that is normally enough on its own. If you write from a different address, it will ask you to reply from the address on record, or to confirm two details it would already hold, such as the approximate date of first contact. Identity documents are only requested where the request concerns a large volume of data or where the risk of disclosing to the wrong person is material, and where one is supplied it is deleted as soon as the check is complete and within 30 days at the outside. The one month clock in the next paragraph starts when the identity check is satisfied, not before.
Timing. Article 12(3) requires a response without undue delay and in any event within one month of receipt. The company treats one month as an outer limit rather than a target. For complex requests, or where a person has made several requests, that period may be extended by up to two further months. If it is extended you will be told within the first month and given the reason for the extension.
Cost. Requests are free. Article 12(5) permits a reasonable fee, or a refusal, where a request is manifestly unfounded or excessive, in particular because it is repetitive. If the company ever relied on that, it would tell you which limb it relied on and why, in writing.
Grounds for refusal. A request may be refused in whole or in part where an exemption in the Data Protection Act 2018 applies, for example where complying would disclose personal data about another identifiable person who has not consented, or where the data is processed for the purpose of establishing, exercising or defending legal claims. Where a request is refused, the company will tell you which ground applies, that you may complain to the ICO, and that you may seek a judicial remedy. It will not refuse a request silently or by not replying.
10.2 The right to be informed
Articles 13 and 14 give you the right to be told what is collected, why, on what basis, who receives it and how long it is kept, at the point the data is obtained. This notice is how the company discharges that duty. If anything in it is unclear or appears incomplete, say so and it will be clarified in the text rather than only in a reply to you.
10.3 The right of access
Article 15 gives you the right to confirmation of whether your personal data is being processed, a copy of that data, and the supplementary information listed in the article. The company will provide the copy in a common electronic format unless you ask for something else. Where providing a copy would adversely affect the rights and freedoms of another person, it will supply what it can and explain what it has withheld and why.
10.4 The right to rectification
Article 16 gives you the right to have inaccurate personal data corrected without undue delay, and to have incomplete data completed. Tell the company what is wrong and what it should say. Where the data has been shared with a processor, the correction is passed on to it as well, and the company will tell you who it was passed to if you ask.
10.5 The right to erasure
Article 17 gives you the right to have your personal data deleted where one of the listed grounds applies, including where it is no longer necessary for the purpose it was collected for, where you withdraw the consent the processing relied on, or where you object under Article 21 and there is no overriding legitimate ground. Section 11 explains the practical route and the 30 day completion commitment. The right is not absolute: data the company must keep to comply with a legal obligation, in particular the six year accounting record described in section 9, cannot be deleted on request, and the company will tell you exactly what it has kept on that basis and when it will go.
10.6 The right to restrict processing
Article 18 gives you the right to have processing restricted, which means the data continues to be stored but is not otherwise used, in four situations: while the accuracy of the data is being checked, where the processing is unlawful but you prefer restriction to erasure, where the company no longer needs the data but you need it for a legal claim, and while an objection under Article 21 is being considered. The company will tell you before any restriction is lifted.
10.7 The right to data portability
Article 20 gives you the right to receive personal data you provided, where the processing is based on consent or on a contract and is carried out by automated means, in a structured, commonly used and machine readable format, and to have it transmitted to another controller where technically feasible. The company will provide JSON or CSV. Note that content created inside an application and stored only on your device is already in your possession and is exportable through the application itself, so a portability request is not usually necessary for it.
10.8 The right to object
Article 21 gives you the right to object at any time to processing based on legitimate interests, on grounds relating to your particular situation. Where you do, the company must stop unless it can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is for legal claims. You also have an unconditional right to object to processing for direct marketing, which the company must honour immediately and with no balancing exercise. WILDDECK LTD does not carry out direct marketing and operates no marketing list, so in practice this limb has nothing to bite on today.
10.9 Rights relating to automated decision making
Article 22 gives you the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you. As set out in section 17, the company makes no such decisions, so there is nothing to object to. If that ever changes, this notice will describe the logic involved and the significance and consequences of the processing before the practice begins.
10.10 The right to withdraw consent
Article 7(3) gives you the right to withdraw consent at any time where processing relies on it, and withdrawal must be as easy as giving it. The only processing in this notice that relies on consent is optional crash reporting in a future application, which is turned off and on by a single switch in the application settings. Withdrawal does not affect the lawfulness of processing carried out before it.
10.11 The right to complain
Article 77 gives you the right to lodge a complaint with a supervisory authority. Section 12 sets out the full contact details for the Information Commissioner's Office. You do not have to complain to the company first, although the company would prefer the chance to fix the problem.
11. Account closure and data deletion
Role: controller
Both platform stores require a published deletion route, and it should be a real one rather than a paragraph that ends in a support queue.
11.1 The in-application route
Any WILDDECK application that includes accounts will carry a deletion control inside the application itself, at Settings, then Account, then Delete account and data. That control is not buried behind a support link, it does not require you to state a reason, and it does not offer a downgrade instead. It asks once for confirmation, because deletion is irreversible, and then it proceeds. Where an application has no accounts, deleting the application from your device removes the data, because the data was only ever on the device.
11.2 The email route
You do not need a working installation to delete your data. Write to hello@wilddeck.co.uk with the subject line Delete my data, from the address associated with the account if you can. Identity verification follows section 10.1.
11.3 The 30 day commitment
A verified deletion request is completed within 30 days of verification. Completion means the data is removed from live systems and from any processor's live systems. Where a processor keeps encrypted backups on a rolling schedule, residual copies may persist in those backups for a short further period, and they are overwritten as the backup cycle turns. Backup copies are not restored into use, and if a restore were ever necessary the deletion would be reapplied to the restored set.
11.4 What is retained after deletion, and why
| What is kept | Why it cannot be deleted on request | For how long |
|---|---|---|
| The transaction record of any purchase: date, amount, product, and the store transaction identifier | Legal obligation under Article 6(1)(c). Company law and tax law require the company to preserve the accounting record, and Article 17(3)(b) expressly excludes such data from the right to erasure. | 6 years from the end of the relevant financial year |
| A minimal record that a deletion request was made and completed, with the date | Accountability under Article 5(2). Without it the company could not demonstrate that it honoured the request. | 3 years |
| Data that is the subject of a live legal claim or a regulatory enquiry | Article 17(3)(e), establishment, exercise or defence of legal claims | Until the claim or enquiry concludes, then deleted |
Nothing else is kept. In particular, no shadow profile, no suppression list built from deleted accounts and no aggregate record that could be linked back to you is retained.
12. Complaints and the Information Commissioner
Role: controller
If you are unhappy with how WILDDECK LTD has handled your personal data or your request, write to hello@wilddeck.co.uk. A complaint will be acknowledged within three working days and answered within one month.
You may also complain to the United Kingdom supervisory authority at any time, whether or not you have raised the matter with the company first. Doing so does not affect any other remedy available to you.
| Authority | Information Commissioner's Office |
|---|---|
| Address | Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF |
| Helpline | 0303 123 1113 |
| Online | ico.org.uk/make-a-complaint |
| Website | ico.org.uk |
13. Personal data breaches
Role: controller
13.1 What counts as a breach
Article 4(12) defines a personal data breach as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. That covers loss of availability as well as confidentiality, so an incident that destroys data without anyone seeing it is still a breach.
13.2 Notifying the Information Commissioner, the 72 hour threshold
Article 33(1) requires the controller to notify the supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of a breach, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. The company's practice is as follows. The 72 hour clock starts at the point of reasonable certainty that a breach has occurred, not at the end of the investigation. Where the full picture is not available in time, an initial notification is made within 72 hours with what is known, and the remainder follows in phases, which Article 33(4) expressly permits. If a notification is made late, the reasons for the delay are given with it, as the same article requires.
13.3 Notifying you
Article 34(1) requires the controller to communicate a breach to the affected individuals without undue delay where it is likely to result in a high risk to their rights and freedoms. Where that threshold is met, the company will contact affected people directly using the contact details it holds, in plain language, describing the nature of the breach, its likely consequences, the measures taken or proposed, and a contact point for further information. Where direct contact would involve disproportionate effort, Article 34(3)(c) permits a public communication instead, and the company would publish it on this website and keep it up.
13.4 The internal record
Article 33(5) requires every breach to be documented, including the facts, the effects and the remedial action, whether or not it was notifiable. The company keeps that record for 6 years, as set out in section 9, so that the ICO can verify compliance.
13.5 If a processor has the breach
Article 33(2) requires a processor to notify its controller without undue delay after becoming aware of a breach. That obligation is written into each processor contract. A processor's breach is treated as the company's breach for the purposes of this section, and the company does not treat a supplier failure as a reason to delay its own notification.
14. Tracking, advertising and App Tracking Transparency
Role: controller
Apple's App Tracking Transparency framework requires an application to obtain permission through the system prompt before tracking a user across apps and websites owned by other companies, or before accessing the device advertising identifier for that purpose.
WILDDECK LTD's position is that no application it publishes will do either. It will not read the Identifier for Advertisers, it will not embed an advertising or attribution software development kit, it will not participate in any data broker arrangement, and it will not combine data from its own application with data received from another company for advertising or measurement. Because it does not track, the App Tracking Transparency prompt is not shown, and its absence should be read as the absence of tracking rather than as a decision to skip a required prompt.
The same applies to the website. There is no advertising, no retargeting pixel, no conversion tag, no fingerprinting script and no analytics product of any kind. The cookie statement sets out what is actually set when you load a page here, which is very little.
If the company ever concludes it needs a measurement tool, this section will be rewritten first, the tool will be named in section 7, and any tracking that requires consent will ask for it through the proper prompt.
15. Google Play Data Safety
Role: controller
Google Play requires a developer to complete a Data Safety declaration, which appears on the store listing and tells a person what an application collects and shares before they install it. That declaration and this notice must agree, and where a reader finds a discrepancy the company treats it as a defect to be fixed rather than a matter of interpretation.
Against the inventory in section 5, the declaration for a first release would state: no data shared with third parties; data collected limited to what appears in that table; crash and diagnostic data optional and switchable; data encrypted in transit; a deletion route available both inside the application and by email as described in section 11. The Apple App Store privacy labels will be completed to the same effect.
Before any submission to either store, this notice and the store declarations are checked against each other line by line, and against the code as built. If a discrepancy is found after publication, the company will correct the declaration and this notice, and say when it did so.
16. Children
Role: controller
This website is not directed at children and the company does not knowingly collect personal data from children through it. Section 9 of the Data Protection Act 2018 sets the age at which a child can consent to information society services in the United Kingdom at 13.
Any application published by the company will carry an age rating on each store, and where a release is intended for a general audience it will be designed to comply with the Information Commissioner's Age Appropriate Design Code. That means, at a minimum, high privacy settings by default, no nudge techniques that push a young person towards weaker privacy choices, no profiling that is on by default, and no collection of more data than the feature actually needs.
If the company learns it holds personal data collected from a child in circumstances where it should not have, it will delete that data promptly. If you believe that has happened, write to the mailbox above and it will be treated with priority.
17. Automated decision making and profiling
Role: controller
WILDDECK LTD makes no decisions about any person by solely automated means, and carries out no profiling. There is no scoring, no ranking, no eligibility assessment, no automated pricing that varies by individual and no automated moderation that could restrict access to a service. Nothing on this website or in a planned release produces a legal effect or a similarly significant effect on anyone through an automated process.
If the company ever introduced such processing, it would first update this notice to describe the logic involved and the significance and envisaged consequences, and would provide the safeguards Article 22(3) requires, including a route to human intervention, the ability to express your point of view and the ability to contest the decision.
18. Security
Role: controller
Article 32 requires technical and organisational measures appropriate to the risk. The measures a company of this size can honestly claim are these: the site is served over HTTPS with HTTP Strict Transport Security; a content security policy restricts what a page may load; data in transit to and from any processor is encrypted; access to the mailbox and to the hosting account is protected by multi-factor authentication; the number of processors is deliberately small; and personal data is not copied onto local machines beyond what is needed to answer a message.
What cannot honestly be claimed is set out in section 20. In particular, WILDDECK LTD holds no security certification of any kind, and nothing in this section should be read as implying an audited control environment.
19. Changes to this notice
Role: controller
This is version 1.0, effective 7 August 2026, and it is the first published version. When it changes, the version number and effective date at the top of the page change with it. A material change, meaning one that alters what is collected, why, on what basis, who receives it or how long it is kept, is published before it takes effect rather than after, and where the company holds contact details for affected people it will tell them directly. Where a change requires consent, it will be sought rather than assumed.
The company will not use a change of notice to bring in a practice this version rules out, such as advertising identifiers or data sharing, without saying plainly that is what it is doing.
20. Things this notice does not claim
Role: controller
A privacy notice is a natural place for implied credibility to creep in, so the position is stated directly.
- WILDDECK LTD does not hold ISO 27001 certification, has not been assessed against it, and has no assessment in progress.
- WILDDECK LTD has no SOC 2 report of any type, and no audit has been commissioned.
- WILDDECK LTD does not hold Cyber Essentials or Cyber Essentials Plus.
- No penetration test has been carried out on a product, because there is no product to test.
- No security or privacy claim in this notice has been verified by an external auditor.
- No data protection officer has been appointed, and none is required. Officer details for the company are on the public Companies House register against company number SC880737; no individual is named on this site.
If any of that changes, the certificate holder, the scope of the certification and the date of issue will be named here so the claim can be checked, and not before.
This notice forms part of the terms of use and should be read with the cookie statement. Version 1.0, effective 7 August 2026.