The short version. We collect what we need to run the site, answer
your enquiries, do the work you hired us for, hire people, and meet our legal
obligations. Nothing beyond that. We do not sell your personal data and we do not
hand it to other companies so they can market to you. Project data belongs to the
client who gave it to us, and only the people working on that project can open it.
Everything below is the long version: each category of data we hold, why we hold it,
who else ever sees it, where in the world it goes, how long it stays, and what you
can tell us to do about it.
01
Introduction & Scope
THESOFTKING Limited ("THESOFTKING", "we", "us" or "our") wrote this policy to set out
what happens to personal information once it reaches us. It covers what we collect,
our reasons for collecting it, who we pass it to, where it travels, how long we keep
it, and the rights you can exercise over it.
This policy applies to:
- Our website at thesoftking.com, together with any subdomains,
landing pages or microsites we run.
- The client portal, billing area, invoices, support desk and meeting booking tools.
- Enquiries, proposals, contracts and the delivery of work for clients and
prospective clients.
- Recruitment and anything else connected to applying for a job with us.
- Marketing you have asked to receive.
This policy does not apply to:
- Third-party websites and services we link to or write about. Each has its own
policy and its own habits.
- Personal data our clients control, which we only touch on their written
instructions. Section 07 covers that situation.
- Companies we neither own nor control, and people who are not our employees, agents
or authorised contractors.
Using the site or sending us information means you have read this and understood it.
Where the law asks for your consent, we will ask separately and in plain words rather
than bury it in a pre-ticked box. Our
Terms of Service and
Refund Policy sit alongside this document and are
worth reading too.
02
Who We Are & How to Reach Us
THESOFTKING Limited is a software engineering and digital product agency. We have been
building for clients since 2011: web platforms, mobile applications, SaaS products,
infrastructure and Artificial Intelligence solutions. The work is done by our own
in-house team rather than passed down a chain of subcontractors.
For most of the information described here we are the data controller,
which means the decisions about it are ours and so is the responsibility. There is a
second situation though. When we work inside a client's product or systems, the
personal data sitting in there belongs to that client. They decide, we follow. In that
case we are a data processor, and
Section 07 explains what it means for you.
Privacy questions, data requests and complaints are handled by our privacy team at
support@thesoftking.com. Postal addresses for all
our offices are at the end of this policy.
03
Information We Collect
Below is every category of information we hold. How much of it applies to you depends
entirely on how you have dealt with us. Someone who reads two pages and leaves appears
in one row of this list. A client of eight years appears in most of them.
Identity & contact data
Your name, job title, company, email address, phone number, postal or billing
address, website and time zone.
Account data
Username, hashed password, preferences, verification status and login history.
If you sign in through a social or third-party account, we also receive the
basic profile fields that provider chooses to share.
Billing & transaction data
Invoices, deposits, payment references, purchase history and billing address.
Card numbers go straight to our regulated payment providers. They never touch
our servers and we could not show you one if you asked.
Project & client content
Briefs, specifications, designs, source code, credentials you give us for
integrations, test data, and whatever else you send over so the work can
happen.
Communications data
Contact form submissions, support tickets, meeting bookings, emails, call notes
and whether you have asked to hear from us.
Technical & usage data
IP address, the rough location it suggests, browser and device, operating
system, the page that sent you here, what you looked at and for how long.
Cookie & consent data
Session identifiers, security tokens, the cookie choices you made and the date
you made them.
Recruitment data
If you apply for a role: your CV, cover letter, portfolio links, work history,
education, references and our interview notes.
Please keep sensitive data out of it
We do not ask for health information, biometrics, racial or ethnic origin,
religious belief, political opinion or trade union membership, and we would
rather you did not send it. If a particular project genuinely cannot proceed
without some of it, that gets agreed in writing first.
04
How We Collect Information
Directly from you
You fill in a contact form, ask for a quote, book a meeting, open an account,
subscribe to the newsletter, raise a ticket, sign a contract, pay an invoice or apply
for a job. All of that is you choosing to tell us something, and you are free not to.
Some of it we genuinely need before we can reply or start work, and we will say so
when that is the case.
Automatically, while you use the site
Cookies, server logs and analytics record technical and usage data as you browse. This
is how we keep the site standing, work out why something broke at 2am, and see which
pages earn their place. Anything past the essentials only runs if you have allowed it.
From other people
- Payment providers tell us whether a payment went through, plus a
reference so we can match it to an invoice.
- Authentication providers pass over basic profile details when you
choose to sign in with an existing account.
- Referrals. An existing client, partner or colleague passes on your
business contact details because they think we should talk.
- Recruitment platforms forward what you submitted through a job
board or professional network.
- Public business sources such as company registries and official
company websites, which we use only to check that a business contact is real.
05
How We Use It & Our Legal Bases
Personal information gets used for the purposes in this table and nothing else. If the
UK GDPR, EU GDPR or a comparable law applies to you, the third column names the legal
basis we rely on in each case.
| Purpose |
Data used |
Legal basis |
| Answering enquiries and putting together proposals and quotes |
Identity, contact, communications |
Steps taken at your request before a contract; legitimate interests |
| Delivering the design, development, QA and support you contracted for |
Identity, contact, account, project content |
Performance of a contract |
| Running accounts and the client portal |
Identity, account, technical |
Performance of a contract |
| Invoicing, taking payment and spotting fraud |
Identity, billing, transaction |
Performance of a contract; legal obligation; legitimate interests |
| Keeping the website, our systems and client environments secure |
Technical, account, cookie |
Legitimate interests; legal obligation |
| Improving the site, our services and what we publish |
Technical, usage, communications |
Legitimate interests; consent where analytics are not essential |
| Sending newsletters and company updates |
Identity, contact, preferences |
Consent; legitimate interests for business contacts |
| Publishing case studies and client references |
Company name, project details, approved quotes |
Consent; terms agreed with the client |
| Assessing job applications and keeping a talent pool |
Recruitment, identity, contact |
Steps before an employment contract; consent; legitimate interests |
| Meeting tax, accounting, audit and regulatory duties |
Identity, billing, transaction |
Legal obligation |
| Bringing or defending a legal claim |
Any category that turns out to be relevant |
Legal obligation; legitimate interests |
Where the basis is legitimate interests, we have weighed our interest in running a
secure and sustainable business against your rights, and concluded ours does not
override yours. You can disagree and object at any time, which
Section 12 explains how to do. Where the basis is consent,
you can take it back whenever you like, and doing so does not make anything we did
beforehand unlawful.
06
Cookies & Similar Technologies
A cookie is a small file a website leaves on your device so it can recognise you next
time. We use them, along with local storage and pixels, in four ways:
- Strictly necessary. Sessions, staying logged in, CSRF protection,
load balancing, fraud prevention. These cannot be switched off because the site
stops working without them.
- Functional. Remembering your preferences, language and cookie
choices so you are not asked the same question on every visit.
- Analytics. Counting page views, traffic sources and general usage
in aggregate, which is how we decide what to improve.
- Marketing. Where enabled, measuring whether a campaign worked and
capping how often you see the same message.
Your browser controls all of this. You can block cookies, delete the ones already
stored, or set the browser to ask each time. Block the strictly necessary ones and
parts of the site will break, which may be a trade you are happy with. Where your
browser sends a recognised opt-out signal, we treat it as a refusal for the categories
it covers.
07
Client Data & Our Role as Processor
Much of our work involves building and running systems that hold our clients' own
customer records. When that is the case, the client is in charge of that data and we
are not. We act on their written instructions and stop there.
What clients can hold us to
- A contract comes first. Every engagement is covered by a written
agreement. A Data Processing Agreement and an NDA are available on request, and
signed as standard wherever the law expects one.
- Access is narrow. Only the named people assigned to your project
get in, and their access is pulled the moment the project ends or they move on.
- No side uses. Client and end-user data never trains our models,
never enriches a marketing list, and never gets used for anything outside the
agreed scope.
- Live data is a last resort. We build and test against anonymised,
pseudonymised or synthetic data, and ask for the real thing only when there is no
honest alternative.
- Confidentiality outlasts the contract. Every employee and
contractor is bound by obligations that continue after they stop working with us.
- A clean exit. When the work finishes we return or securely destroy
what we hold, as the agreement requires, keeping only what the law forces us to
keep.
If you are a customer of a business whose product we built, and you want your data
corrected or removed, go to that business rather than to us. The decision is theirs to
make. We will help them answer you quickly, but we cannot overrule them.
08
When & With Whom We Share
We have never sold personal data
Not to advertisers, not to data brokers, not to anyone. We do not trade it for
money or for anything else of value, and we do not pass it to other companies
so they can sell to you.
Information leaves us only in the situations below, and only as much of it as the
situation actually requires:
- Service providers and sub-processors. Hosting and cloud
infrastructure, email delivery, payment processing, the support desk, scheduling
tools, analytics and error monitoring. Each one is under a written agreement that
limits them to our instructions and holds them to proper security. Ask and we will
send you the current list.
- Professional advisers. Accountants, auditors, insurers and
lawyers, when they need it to advise us, and always under professional
confidentiality.
- Authorities. Regulators, courts and law enforcement, where we are
legally compelled. We read every request properly, hand over only what is
demanded, and tell you first whenever the law lets us.
- A corporate transaction. A prospective buyer or partner in a
merger, acquisition or restructuring, under confidentiality, with this policy
continuing to govern whatever moves across.
- Anyone you point us at. If you ask us to share something with a
third party, we will.
09
International Data Transfers
We work from offices in the United States, the United Kingdom, Canada and Bangladesh,
and the cloud services we depend on run in other countries again. Your information
will therefore cross borders, and some of those countries have not been formally
recognised as offering protection equivalent to your own.
We do not treat that casually. Every international transfer rests on at least one of these:
- Standard Contractual Clauses approved by the European Commission, or the UK
International Data Transfer Agreement and Addendum.
- An adequacy decision covering the destination country.
- Encryption in transit and at rest, tight access control and, where it fits,
pseudonymisation, as supplementary technical measures.
- Your explicit consent, or the plain necessity of the transfer to perform a contract
with you, when nothing else applies.
Want to know which one covers a particular transfer? Email
support@thesoftking.com and we will tell you.
10
How Long We Keep Information
We keep information for as long as the purpose lasts, or as long as the law insists,
whichever runs longer. These are our standard periods. An individual contract can set
a shorter or longer one, and where it does, the contract wins.
| Information |
Retention period |
| Enquiries and proposals that never became projects |
Up to 24 months from the last time we spoke |
| Account and portal data |
While the account is open, then deleted or anonymised within 90 days of
closure |
| Client project files and correspondence |
The length of the engagement plus whatever the contract says, usually
up to 3 years |
| Invoices, payments and accounting records |
6 to 7 years, because tax and company law require it |
| Support tickets |
Up to 3 years after the ticket closes |
| Marketing subscriptions |
Until you unsubscribe. We then keep a suppression record so the opt-out
actually sticks |
| Unsuccessful job applications |
12 months, unless you ask us to hold on for future roles |
| Server, security and access logs |
Usually 12 months |
| Aggregated or anonymised analytics |
Kept indefinitely, since it no longer points to anyone |
When the clock runs out we delete the information, or strip it back far enough that it
can never be traced to a person again. We do not hoard data simply because storage
happens to be cheap.
11
Security & Breach Response
We sell security work, so running our own house badly would be a poor look. What
follows is what we actually have in place, sized to the risk rather than to the
brochure:
- TLS for data in transit, and encryption at rest for stored data and backups.
- Role-based access on a least-privilege footing, revoked the day someone changes
role or leaves.
- Strong password rules, hashed credentials, and multi-factor authentication on every
administrative and infrastructure account.
- Firewalling, network protection, logging and active monitoring of production.
- Regular patching, dependency updates, code review and testing before anything
ships.
- Separate environments, with live data kept out of the ones that do not need it.
- Backups that run on schedule, are monitored, and get restored as a test rather than
assumed to work.
- Confidentiality obligations, appropriate vetting, and privacy and security training
for the team.
- Due diligence and contractual security obligations on every vendor and
sub-processor before they touch anything.
If something goes wrong
No system is perfectly secure, and anyone claiming otherwise is selling you something.
We keep a written incident response plan. If a breach happens we contain it, work out
who is affected and how badly, fix the cause, and notify the relevant supervisory
authority within 72 hours where the law requires it. Affected people and clients hear
from us without undue delay. Where we were acting for a client, that client hears
first, so they can meet their own obligations on time.
Your side of it matters too. Use a password you have not reused anywhere else, turn on
multi-factor authentication where it is offered, and email
support@thesoftking.com the moment you suspect
someone else has been in your account.
12
Your Privacy Rights
Depending on where you live, some or all of the following are yours to exercise:
- Access. Find out whether we hold anything about you, and get a
copy of it.
- Rectification. Have anything wrong or incomplete put right.
- Erasure. Have it deleted, where we have no overriding reason to
keep it.
- Restriction. Tell us to pause while an accuracy question or a
dispute is sorted out.
- Portability. Receive what you gave us in a structured,
machine-readable format, or have it sent on to another provider where that is
technically possible.
- Objection. Object to processing based on legitimate interests, and
object to direct marketing at any time. Marketing objections we always honour, no
questions asked.
- Withdrawing consent. Take back a consent you gave earlier,
whenever you like.
- No penalty. Use any of these rights and your service and pricing
stay exactly as they were.
- A human decision. Not be subject to a decision with legal or
similarly significant effects that was made by software alone.
How to ask
Most details you can change yourself by logging in. For anything else, email
support@thesoftking.com and say what you want. We
will confirm we have your request, check you are who you say you are using information
we already hold, and reply within 30 days. A genuinely complicated
request can take up to 60 days longer, and if yours is one of those we will tell you so
and explain why. None of this costs anything, unless a request is plainly excessive or
repeated to make a point.
Someone can act for you where the law allows it, provided we get proof they are
authorised. One honest caveat on deletion: certain records we are legally required to
keep, such as accounting history, or material we need to defend a legal claim. If part
of your request runs into that, we will tell you which part and why, rather than
quietly do less than you asked.
13
Regional Privacy Notices
European Economic Area & United Kingdom
We handle personal data under the EU GDPR and UK GDPR, relying on the legal bases set
out in Section 05. You can complain to your local
supervisory authority, which in the UK is the Information Commissioner's Office. We
would rather you came to us first and gave us a chance to put it right, but that is
your call, not ours.
California, United States
Under the CCPA as amended by the CPRA, California residents can ask what categories and
specific pieces of personal information we collected, where it came from, why we
wanted it and who received it. You can also ask us to delete or correct it, opt out of
any sale or sharing, and limit how sensitive information is used. We do not
sell or share personal information as the CCPA defines those terms, and we have not
done so in the previous twelve months. We do not knowingly collect or sell
information about anyone under 16. Exercising a right will never cost you service or
money here.
Other United States states
If you live in Virginia, Colorado, Connecticut, Utah, Texas or another state with a
comprehensive privacy law, you have equivalent rights of access, correction, deletion,
portability and opt-out, plus the right to appeal if we turn a request down.
Canada
We follow PIPEDA and the applicable provincial privacy legislation, including their
principles on accountability, consent, limiting collection and safeguarding what we
hold.
Bangladesh and everywhere else
Where your local law gives you stronger rights than anything described above, the
stronger standard is the one we apply. If you are not sure which rules cover you, ask
us and we will work it out.
14
Artificial Intelligence & Automated Processing
Artificial Intelligence is a large part of what we build, so it is worth being blunt
about where it does and does not touch personal data.
- Your data does not train public or general-purpose models. Neither does our
clients'. This is not a preference, it is a rule.
- Internally we do use Artificial Intelligence tools for drafting and engineering
assistance. There are rules about what may be typed into them, and confidential
client material is not permitted in any tool we have not approved in writing.
- When we build Artificial Intelligence features for a client, that client's
instructions and our contract with them govern the data, not this policy.
- Nothing with a legal or similarly significant effect on you is decided by software
alone. Automated fraud and spam checks exist, and a person will look again if you
ask them to.
15
Job Applicants & Recruitment
Apply for a role and your application is used to assess whether you are right for it,
to keep you posted, and if it goes well, to get your paperwork ready. That is the whole
list.
- Only the hiring team and the relevant department lead can see an application.
- Unsuccessful applications stay with us for 12 months in case something better
suited comes up. Ask and we will delete yours sooner.
- References and background checks happen with your knowledge, never behind your
back, and only where the law permits them.
- Please do not put sensitive personal information in your CV or portfolio beyond
what the role actually calls for.
16
Children's Privacy
Our website and services are built for businesses and adults. We do not knowingly
collect information from children under 16 without a parent or guardian agreeing
first, and we do not market to children at all.
If you are a parent or guardian and think a child has given us something, email
support@thesoftking.com and we will delete it
promptly. Where we build a product aimed at younger users for a client, extra
protections get agreed in that engagement, and the client stays in control of the data.
17
Third-Party Sites & Integrations
Our website, blog, portal and proposals sometimes point at third-party products and
platforms: payment gateways, scheduling tools, review sites, social networks. Those
services run on their own policies and their own terms, which may be nothing like
ours.
The moment you leave our site, or interact with something embedded from elsewhere,
this policy stops applying. We have no control over how those companies behave and no
responsibility for it. Read their policies before you hand them anything.
18
Changes to This Policy
We reread this policy when our practices change, when we launch something new, or when
the law moves under us. Whatever is published on this page is the version that counts.
If a change actually affects you, we will give reasonable notice before it takes
effect, by email, a notice inside the product, or a banner here. We cannot promise
every message reaches every person, so it is worth glancing at this page now and then.
Carrying on using the site or our services after a change takes effect means you
accept it. If you want to see an earlier version, ask and we will send it.