Skip to main content
WILDDECK

Your privacy rights, and what we owe you

Who answers for your data
WILDDECK LTD, company number SC880737, on the Scottish register
Where to write
[email protected]
In force from
7 August 2026
Version
1.0
Law behind it
UK GDPR, read with the Data Protection Act 2018
What it covers
wilddeck.co.uk, and any application this company releases

This guide is arranged your way round. Each of the first fourteen parts opens with something you are entitled to, tells you the practical steps for claiming it, and only then sets out the duty it puts on us. Four shorter parts at the end cover work we have to do whether or not anybody asks. Nothing here is a favour, and none of it depends on you having bought anything.

1. Knowing who answers for you

Your right

You are entitled to be told, by name, which organisation makes the decisions about information relating to you. Data protection law calls that organisation the controller, and the controller is the party you get to hold responsible. A guide that never quite says who is speaking has failed at the first hurdle.

How to use it

Read the panel at the head of this page; you should not have to ask. If you want independent confirmation that the company exists and is trading, search the number SC880737 on the Companies House website, which costs nothing.

Our duty

WILDDECK LTD is the controller for every activity described below. We trade under no other name and share the decision with nobody, so there is no joint arrangement to disclose.

Two related points, because readers ask about both. We have appointed no data protection officer: Article 37 makes one compulsory for public authorities, for large scale monitoring and for special category data at scale, and none of those describes us. We have appointed no representative inside the European Union either, because we do not offer anything to people there or watch what they do. Should either position change, this part is rewritten and a name appears in it before the change takes effect.

Some firms handle data purely on our written instruction, deciding nothing for themselves. The law calls each of those a processor, and part 3 names them.

2. A plain list of what is held

Your right

Articles 13 and 14 entitle you to know what is gathered, where it came from, what it is being used for and which legal reason permits it. That reason is the lawful basis, and there are only six of them; nobody may process anything without picking one.

How to use it

Work down the two tables. They are exhaustive: an item absent from them is an item we do not gather. If you spot something happening to you that no row explains, tell us, because either the table is wrong or the software is.

Our duty

Wherever the reason given is legitimate interests, we name the interest instead of citing the article and stopping. Article 6(1)(f) on its own tells you nothing about what was weighed against your privacy.

Visiting this website
GatheredOriginUsed forLegal reason
Request records Sent by your browser automatically: network address, clock time, the page asked for, the response code, the browser signature, a rough country worked out from the address Handing you the page, spotting faults, absorbing floods of automated traffic Legitimate interests. The interest is keeping a public website up and defended. It is proportionate because the fields are few, nothing is joined to anything else, and no picture of you is built
Abuse-blocking records Produced at the network edge as traffic arrives: counters, blocked-request notes, robot scores Turning away automated abuse so the pages stay reachable Legitimate interests, specifically network security, which recital 49 names as legitimate in terms
Typeface fetches Your address and browser signature, sent by your own browser when it collects the lettering this site is set in Rendering the pages in the intended lettering Legitimate interests, the interest being a legible page. Disclosed because the request leaves our own equipment. Part 3 explains why the recipient is not a processor
Letters to us Whatever you put in an email: address, any name you sign, subject, body, attachments Reading it, replying, and being able to show later what was said Legitimate interests, namely dealing with post addressed to us. Where your message concerns a purchase or a step towards one, the basis is performance of a contract instead
Rights-request paperwork Your request, the evidence of identity you send with it, our answer and its date Doing what you asked, and proving to the regulator that we did Legal obligation, read with the accountability duty in Article 5(2). The identity check itself is required by Article 12(6)

The second table is the ceiling. It sets the outer limit of what any WILDDECK application may touch, and anything beyond it requires this page to be rewritten and republished, with its date changed, before the feature reaches anyone.

Using a WILDDECK application: the outer limit
GatheredOriginUsed forLegal reason
Whatever you make Typed, saved or chosen by you, on hardware you own Running the feature you are using Performance of the contract. It stays on your hardware; we hold no copy, so there is nothing here for us to disclose to anyone
Your operating system's backup Copied by the phone or tablet itself, if you have that switched on Letting you restore your own device Not ours to justify. That arrangement runs between you and the platform, and we neither see it nor control it
Sign-in details Given by you, and only where an application needs accounts at all: an email address with a hashed password, or a platform sign-in token Letting you in, and letting you back in after a lost password Performance of the contract
What you bought Passed to us by Apple or Google after a purchase: transaction reference, product reference, date, subscription state, the country of the store account Unlocking what you paid for, handling renewals and refunds, and keeping the books Performance of the contract for the unlocking; legal obligation for the bookkeeping, under section 388 of the Companies Act 2006 and the record rules of HM Revenue and Customs
Fault reports Written by your device at the moment something crashes: the failure trace, our version number, the system version, the device model, memory free at the time Locating and mending defects Consent. It starts off, it works only once you switch it on, and switching it back off stops it that instant
Help you ask for Your email, your description of the trouble, the version number you quote Sorting out your problem Performance of the contract where the trouble concerns something you paid for; otherwise legitimate interests in answering post
Advertising identifiers Nothing, from nowhere Nothing No basis is needed, because none is read. We do not touch the iOS Identifier for Advertisers or the Android Advertising ID, and we build in no advertising kit that would want them

This website itself writes no cookie of ours, counts no visitors, embeds no social buttons and carries no advertising tag. The cookie statement goes through what does land on your device, which is almost nothing.

3. Knowing who else touches it

Your right

You may be told the categories of recipient, and in practice a category is a poor substitute for a name. Naming them is what lets you check a supplier's own reputation rather than taking ours on trust.

How to use it

The table names each firm. If you want the position on a supplier the table leaves open, write and ask; the answer is a name, a location and the safeguard relied on, and it is given without argument.

Our duty

Every firm below signs a contract carrying the clauses Article 28(3) requires: act only on our instruction, keep staff under confidentiality, engage nobody further without permission, help us answer you, and delete or return everything at the end. The list stays short deliberately, because each addition is another door.

Firms acting on our instruction
FirmWhat it doesWhat it can reachWhere, and on what safeguard
Cloudflare, Inc. Serves these pages and shields them at the network layer The request and abuse-blocking records in part 2. No page content, because this site holds none belonging to you An edge network spanning many countries; British visitors are normally served from a British or European site. The supplier is incorporated in the United States, so the addendum described in part 4 governs the arrangement
Our email host Receives and stores mail sent to the published address Everything in a message, including anything you decide to attach Named on request, together with its country and the safeguard covering it
Our accountant Prepares statutory accounts and tax returns Purchase and payment records, once there is trade to record. No correspondence, and nothing from inside an application United Kingdom. Nothing leaves the country, so no transfer safeguard arises
A fault-report service Would collect the optional reports described in part 2 Failure traces only, and only from people who switched the option on Nobody is engaged. Whoever is chosen appears in this row, with country and safeguard, before a single report is sent anywhere

Google is deliberately absent from that table. When your browser collects the lettering, it goes straight to Google's servers on nobody's instruction but its own, which makes Google an independent recipient for that one narrow purpose rather than a firm acting for us. We disclose it because the effect on you is the same either way: your network address reaches a third party. Blocking those two hostnames in a content blocker leaves every word of this site readable in a system typeface.

4. Knowing where it travels

Your right

If information about you crosses a border, you may be told which country and which protection travels with it. Chapter V of the UK GDPR exists so that leaving the country cannot be used to leave your rights behind.

How to use it

Ask, in one line, for the current list of destinations. You are entitled to a copy of the safeguard document too, and we will send it with commercial pricing redacted and nothing else taken out.

Our duty

Our preference is boring: keep the data in the United Kingdom, and where a supplier offers a British or European region, take it. Where that is not possible, one of three things has to be true before anything moves.

  • The destination has been ruled adequate by the Secretary of State, in which case no extra paperwork is needed and your rights travel intact.
  • An International Data Transfer Agreement is in force between us and the recipient.
  • The recipient is already on the EU standard contractual clauses, and the UK addendum is bolted onto them so that they bite here as well.

Paper alone is not the test. Before relying on any of the above we assess whether the destination's own surveillance law would hollow the promise out, and if it would, we look for a different supplier rather than filing the assessment and carrying on. Your entitlements do not shrink because a server sits abroad: a request under part 6 covers data wherever it physically rests, and a complaint under part 14 goes to the British regulator regardless.

5. Knowing how long it stays

Your right

Storage limitation is a principle in its own right under Article 5(1)(e). You are entitled to the period, or at least to the rule that fixes it, and a schedule that gives a number without a reason is a habit wearing a schedule's clothes.

How to use it

Find your row. If your situation is not covered, ask; you get a period and the reasoning, not a shrug.

Our duty

Every period in the retention schedule below is justified rather than merely stated. Where two statutes disagree we apply the longer one across the board, so that nobody is worse off for living in one part of the United Kingdom rather than another.

Retention schedule: how long each kind of record lasts
RecordKept forWhy that long
Request and abuse-blocking recordsUp to 30 daysEnough to look into an incident, short enough that the pile never becomes a liability. It is the host's own default and we have not lengthened it
Ordinary correspondence24 months after the last message in the threadConversations resume after gaps, and someone may reasonably ask what was agreed. Beyond two years, almost none of it earns its keep
Support about something paid for24 months, or 6 years where it evidences a purchase or a complaintA contract claim can be raised for five years in Scotland and six in England and Wales. We hold the longer figure everywhere
Accounts and purchase records6 financial years after the one they belong toCompany law sets three years for a private company's accounting records; the tax authority wants six. Six wins
Account details in an applicationAs long as the account is open, then gone within 30 days of closureThe account exists to deliver the contract. Once that ends, keeping credentials serves nobody, and 30 days is the deadline we have published
Fault reports90 daysA crash trace stops being useful once the release it came from has been replaced, and three months covers an unhurried reproduction
Rights requests and answers3 years after the replyWe may have to show the regulator that requests were handled properly, and to answer the same person consistently if they return
Identity evidence sent with a requestUntil the check is done, never beyond 30 daysIdentity documents are sensitive and have exactly one job. Holding them afterwards is pure risk with no matching benefit
Records of a security incident6 years from the incidentArticle 33(5) obliges us to document every one so the regulator can verify how it was handled, and six years matches the outer edge of related claims

6. Getting a copy

Your right

Article 15 lets you find out whether anything about you is held, and if it is, to receive a copy along with the surrounding explanation: purposes, recipients, periods, and where it came from if not from you. This is the entitlement people mean when they say subject access request, and it costs you nothing.

How to use it

  1. Email [email protected] and put Data protection request in the subject line.
  2. Say which entitlement you are using. Plain words are fine; you need no form, no template and no solicitor.
  3. Write from the address we already hold for you where you can, since that alone usually settles who you are.
  4. Narrow it if you can. "Everything from March" is answered faster than "everything", though "everything" is perfectly proper and will be answered.

Our duty

The clock runs for one calendar month from the day your message lands. Genuinely complicated or repetitive requests may take up to two months longer, but if we need that, you hear from us inside the original month with the reason. Where we cannot identify you from what we hold, we say so rather than fishing for documents; where a check is genuinely needed, we ask for the least revealing thing that would settle it and destroy it afterwards.

Refusal is possible only where the law allows, and the two grounds are narrow: a request that is plainly excessive or vexatious, or one that would hand over somebody else's information. We will tell you which ground applies, what we have redacted, and how to challenge it. Charging is not on the table for a first copy.

7. Putting mistakes right

Your right

Under Article 16 you may have inaccurate information corrected, and incomplete information filled in. Accuracy is also a duty on us regardless, so this is a right you should never need to fight for.

How to use it

Tell us what is wrong and what the correct version is. Evidence helps where the point is disputable, but for something like a misspelled name your word is plainly enough.

Our duty

We correct it inside the same month, and we pass the correction to anyone we sent the wrong version to, unless that turns out to be impossible or wildly disproportionate. If we think the existing version is right, we do not simply refuse: we explain the basis, record your disagreement alongside the entry, and tell you how to escalate.

8. Having it wiped

Your right

Article 17 lets you have information erased once it is no longer needed for the purpose that justified collecting it, once consent is withdrawn and nothing else supports it, or where it was never lawful to hold. Closing an account and erasing what sat behind it are separate acts, and you are entitled to both.

How to use it

Send a message headed Delete my data, naming the address any account is under. Where a release includes accounts, account deletion is also available from inside the application itself: a control that closes the account and starts the erasure without you having to compose a message at all. It will never be buried behind a support conversation.

Our duty

Once we are satisfied who you are, erasure completes within 30 days, and you get written confirmation naming what went and what stayed. There is no cooling-off limbo in which the account quietly persists in case you return.

Three things survive, and each has a reason you can check.

  • Accounting entries for anything you bought. The law requires them and consent does not enter into it. They are pared to the transaction and its amount, and they expire on the schedule in part 5.
  • A minimal note that you asked. Your address, the date, what was done. Without it we cannot show a regulator that your request was honoured, and we would be deleting the evidence that we deleted.
  • Anything caught by a live legal claim. Only for as long as the claim runs, and we tell you if this applies to you rather than leaving you to guess.

What we will not do is treat erasure as a background job that gets to it eventually. Deletion instructions reach every firm in part 3 within the same window.

9. Freezing our use of it

Your right

Article 18 gives you a middle setting between leaving things alone and wiping them. We keep the information but stop doing anything with it, which is useful while accuracy is being argued about, or where you want something preserved for a claim of your own that erasure would destroy.

How to use it

Ask for it in terms, and say what you want frozen and why. It pairs naturally with part 7: dispute the accuracy and ask for a freeze in the same message, and nothing moves while the point is resolved.

Our duty

We apply the freeze inside the month and confirm it. While it is on, the data is stored and otherwise left untouched except with your agreement or for a legal claim. Before we lift it, you get told, so a freeze can never end quietly without your knowing.

10. Taking it away with you

Your right

Article 20 covers information you supplied where the handling rests on consent or on a contract and is done by machine. You may receive it in a structured, commonly used, machine-readable form, and you may ask for it to be sent straight to another provider where that is technically workable.

How to use it

Ask for an export and name the format if you have a preference. If you want it delivered to a competitor rather than to you, say so; we regard that as an ordinary request and not as a defection to be slowed down.

Our duty

The export arrives inside the month as JSON or CSV, whichever suits the data better, with a short note explaining the fields. Where an application keeps your work on your own device, the export is a function of that application rather than something you have to request from us, and we regard shipping it as part of doing the job properly rather than as a concession.

11. Saying no, and changing your mind

Your right

Two entitlements sit together here. Article 21 lets you object to handling that rests on legitimate interests, and where the purpose is direct marketing the objection is absolute: no balancing, no argument, it simply stops. Article 7(3) lets you withdraw any consent you gave, as easily as you gave it, and withdrawing it never makes the past handling unlawful.

How to use it

  • To object, write and say what you are objecting to. You may explain your particular situation, which strengthens the case, but for marketing you need give no reason whatsoever.
  • To pull consent for fault reports, switch the setting off inside the application. Nothing further leaves the device from that moment, and no message to us is needed.
  • To take back a device permission, use your phone's own settings screen. We never treat that as a fault, and the application must keep working with the feature that needed it politely disabled.

Our duty

An objection stops the activity unless we can show compelling grounds that override your interests, and if we ever claim that, you get the reasoning in writing and a route to challenge it. Permission prompts are asked for at the moment the feature needs them, never in a queue at first launch, and always after a plain-English screen explaining what happens if you decline. Nothing about this is buried: consent that is hard to withdraw was never freely given in the first place.

12. A decision made by a person

Your right

Article 22 protects you from being subjected to a decision based only on automated processing where it produces a legal effect on you, or something similarly significant. Where such a decision is made, you may demand human intervention, state your side and contest the outcome.

How to use it

Use it the moment a machine, rather than a person, makes a decision that materially affects you. No WILDDECK system works that way, so the right sits unused rather than unavailable, and if that ever changes the mechanics for challenging a decision appear in this part before the first decision is taken.

Our duty

We run no scoring, no ranking, no eligibility test, no per-person pricing and no automated moderation that could cut off your access. Nothing this company operates reaches a conclusion about anybody by machine. Introducing anything of the kind would mean first describing the logic, the significance and the likely consequences here, and putting in place the human review, the right to put your case and the right to object that Article 22(3) requires.

13. Being warned when it goes wrong

Your right

A security incident means information being destroyed, lost, altered, or exposed to somebody who should not have it, whether through accident or attack. Where the consequences for you are likely to be serious, Article 34 entitles you to hear about it directly, in plain terms, without undue delay.

How to use it

Mostly this one comes to you. If you have reason to think something has gone wrong before we have said anything, write and ask; a question about a suspected incident jumps the queue and is answered without waiting for the general timescale.

Our duty

Where an incident is likely to put people's rights at risk, we notify the regulator within 72 hours of becoming aware of it, and if we are ever late, the notification carries the reason for the delay rather than glossing over it. Where the risk to you personally is high, you hear from us as well, and that message tells you what happened, what it means in practice, what we have done and what you should do at your end. We write it in the language of the rest of this guide, not in the language of an apology drafted by somebody with one eye on liability.

Every incident is written up internally whether or not it crosses the reporting threshold, because Article 33(5) requires the record and because a threshold judgment nobody wrote down is not a judgment. A supplier from part 3 that suffers one must tell us without delay, and that obligation is in their contract rather than left to goodwill.

14. Complaining, over our head

Your right

Article 77 gives you a direct line to the supervisory authority, which in the United Kingdom is the Information Commissioner's Office. You may use it whenever you think your data has been mishandled. You do not need our permission, our agreement, or our knowledge, and you certainly do not need to have exhausted anything with us first.

How to use it

We would rather hear first, because most problems are our error and can be mended in days, and because you keep every option open by trying. But that is a preference, not a hurdle, and nothing is lost by going straight to the regulator.

The regulator
BodyInformation Commissioner's Office
PostWycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom
Telephone0303 123 1113
Onlineico.org.uk/make-a-complaint

Our duty

Complaints to us go to the same published address and are handled by the company rather than routed into a ticketing product that hides the reply behind a login. Beyond the regulator you also keep a route to the courts, including compensation under Article 82 for damage caused by a breach of the rules, and using one route never closes the other.

15. Duty: keeping it safe

The four parts that follow are ours to perform whether or not anybody asks.

Article 32 asks for measures appropriate to the risk rather than a fixed shopping list, which means the honest thing to publish is what is actually running. Pages are served only over HTTPS, with strict transport security so a browser refuses to fall back to an unencrypted connection. A content security policy limits what a page is permitted to load, which is what stops an injected script from being useful. Traffic to and from every firm in part 3 is encrypted. The mailbox and the hosting account both sit behind multi-factor authentication. The supplier list is kept deliberately short. Personal data is not copied onto laptops beyond what answering a message actually requires.

Because appropriateness is a moving target rather than a certificate, these measures get revisited whenever the handling described in this guide changes, and this part is rewritten to match.

16. Duty: young people

This website is not aimed at children and we do not knowingly gather anything from one through it. Section 9 of the Data Protection Act 2018 puts the age at which a child can consent to an online service in the United Kingdom at 13.

Any application carries an age rating on each store. Where a release is meant for a general audience it is built to the Information Commissioner's Age Appropriate Design Code, which in practice means the private setting is the default rather than the option, that no interface nudges a young person towards giving up more than they need to, that nothing profiles anybody by default, and that a feature collects only what it actually requires to work.

If we discover we are holding something gathered from a child when it should not have been, it goes promptly. If you believe that has happened, write to the address above and it is dealt with ahead of the queue.

17. Duty: what the stores are told

Both app stores make a developer declare, on the listing itself, what an application collects before anyone installs it. Those declarations and this guide have to say the same thing, and where a reader finds them disagreeing we treat it as a defect to be corrected rather than a difference of interpretation.

App Tracking Transparency. Apple's framework requires an application to obtain permission through the system prompt before following a person across other companies' apps and websites, or before reaching for the advertising identifier to do it. Our position is that no application we publish does either. We do not read that identifier, we embed no advertising or attribution kit, we take part in no data broker arrangement, and we join our own data to nothing received from another company for advertising or measurement. Because there is no tracking, the prompt does not appear, and its absence means exactly that rather than a required prompt having been skipped.

Google Play Data Safety. Measured against the application table in part 2, the declaration reads: nothing shared with third parties; collection limited to the rows in that table; fault reporting optional and switchable; everything encrypted in transit; a deletion route available both inside the application and by email. The Apple privacy labels are completed to the same effect.

At every submission, this page and the store declarations are read against each other line by line, and against the software as it actually behaves. A discrepancy found afterwards gets corrected in both places, with the date of the correction stated.

18. Duty: telling you this changed

This is version 1.0, in force from 7 August 2026. When it changes, the version and the date in the panel at the top change with it.

A material change is one that alters what is gathered, what for, on what legal reason, who receives it or how long it lasts. Those are published before they take effect rather than afterwards, and where we hold contact details for the people affected, we write to them instead of hoping they revisit the page. Where a change needs consent, it is asked for rather than assumed.

One commitment about the manner of change, because it is the part that usually goes wrong. If this company ever decides to start doing something this version rules out, advertising identifiers being the obvious example, it will say so in those words. It will not arrive as a softened phrase in a longer document nobody was told had moved.

This guide sits alongside the terms of use and the cookie statement, and forms part of the agreement between us.