This guide is arranged your way round. Each of the first fourteen parts opens with something you are entitled to, tells you the practical steps for claiming it, and only then sets out the duty it puts on us. Four shorter parts at the end cover work we have to do whether or not anybody asks. Nothing here is a favour, and none of it depends on you having bought anything.
1. Knowing who answers for you
Your right
You are entitled to be told, by name, which organisation makes the decisions about information relating to you. Data protection law calls that organisation the controller, and the controller is the party you get to hold responsible. A guide that never quite says who is speaking has failed at the first hurdle.
How to use it
Read the panel at the head of this page; you should not have to ask. If you want independent confirmation that the company exists and is trading, search the number SC880737 on the Companies House website, which costs nothing.
Our duty
WILDDECK LTD is the controller for every activity described below. We trade under no other name and share the decision with nobody, so there is no joint arrangement to disclose.
Two related points, because readers ask about both. We have appointed no data protection officer: Article 37 makes one compulsory for public authorities, for large scale monitoring and for special category data at scale, and none of those describes us. We have appointed no representative inside the European Union either, because we do not offer anything to people there or watch what they do. Should either position change, this part is rewritten and a name appears in it before the change takes effect.
Some firms handle data purely on our written instruction, deciding nothing for themselves. The law calls each of those a processor, and part 3 names them.
2. A plain list of what is held
Your right
Articles 13 and 14 entitle you to know what is gathered, where it came from, what it is being used for and which legal reason permits it. That reason is the lawful basis, and there are only six of them; nobody may process anything without picking one.
How to use it
Work down the two tables. They are exhaustive: an item absent from them is an item we do not gather. If you spot something happening to you that no row explains, tell us, because either the table is wrong or the software is.
Our duty
Wherever the reason given is legitimate interests, we name the interest instead of citing the article and stopping. Article 6(1)(f) on its own tells you nothing about what was weighed against your privacy.
| Gathered | Origin | Used for | Legal reason |
|---|---|---|---|
| Request records | Sent by your browser automatically: network address, clock time, the page asked for, the response code, the browser signature, a rough country worked out from the address | Handing you the page, spotting faults, absorbing floods of automated traffic | Legitimate interests. The interest is keeping a public website up and defended. It is proportionate because the fields are few, nothing is joined to anything else, and no picture of you is built |
| Abuse-blocking records | Produced at the network edge as traffic arrives: counters, blocked-request notes, robot scores | Turning away automated abuse so the pages stay reachable | Legitimate interests, specifically network security, which recital 49 names as legitimate in terms |
| Typeface fetches | Your address and browser signature, sent by your own browser when it collects the lettering this site is set in | Rendering the pages in the intended lettering | Legitimate interests, the interest being a legible page. Disclosed because the request leaves our own equipment. Part 3 explains why the recipient is not a processor |
| Letters to us | Whatever you put in an email: address, any name you sign, subject, body, attachments | Reading it, replying, and being able to show later what was said | Legitimate interests, namely dealing with post addressed to us. Where your message concerns a purchase or a step towards one, the basis is performance of a contract instead |
| Rights-request paperwork | Your request, the evidence of identity you send with it, our answer and its date | Doing what you asked, and proving to the regulator that we did | Legal obligation, read with the accountability duty in Article 5(2). The identity check itself is required by Article 12(6) |
The second table is the ceiling. It sets the outer limit of what any WILDDECK application may touch, and anything beyond it requires this page to be rewritten and republished, with its date changed, before the feature reaches anyone.
| Gathered | Origin | Used for | Legal reason |
|---|---|---|---|
| Whatever you make | Typed, saved or chosen by you, on hardware you own | Running the feature you are using | Performance of the contract. It stays on your hardware; we hold no copy, so there is nothing here for us to disclose to anyone |
| Your operating system's backup | Copied by the phone or tablet itself, if you have that switched on | Letting you restore your own device | Not ours to justify. That arrangement runs between you and the platform, and we neither see it nor control it |
| Sign-in details | Given by you, and only where an application needs accounts at all: an email address with a hashed password, or a platform sign-in token | Letting you in, and letting you back in after a lost password | Performance of the contract |
| What you bought | Passed to us by Apple or Google after a purchase: transaction reference, product reference, date, subscription state, the country of the store account | Unlocking what you paid for, handling renewals and refunds, and keeping the books | Performance of the contract for the unlocking; legal obligation for the bookkeeping, under section 388 of the Companies Act 2006 and the record rules of HM Revenue and Customs |
| Fault reports | Written by your device at the moment something crashes: the failure trace, our version number, the system version, the device model, memory free at the time | Locating and mending defects | Consent. It starts off, it works only once you switch it on, and switching it back off stops it that instant |
| Help you ask for | Your email, your description of the trouble, the version number you quote | Sorting out your problem | Performance of the contract where the trouble concerns something you paid for; otherwise legitimate interests in answering post |
| Advertising identifiers | Nothing, from nowhere | Nothing | No basis is needed, because none is read. We do not touch the iOS Identifier for Advertisers or the Android Advertising ID, and we build in no advertising kit that would want them |
This website itself writes no cookie of ours, counts no visitors, embeds no social buttons and carries no advertising tag. The cookie statement goes through what does land on your device, which is almost nothing.
3. Knowing who else touches it
Your right
You may be told the categories of recipient, and in practice a category is a poor substitute for a name. Naming them is what lets you check a supplier's own reputation rather than taking ours on trust.
How to use it
The table names each firm. If you want the position on a supplier the table leaves open, write and ask; the answer is a name, a location and the safeguard relied on, and it is given without argument.
Our duty
Every firm below signs a contract carrying the clauses Article 28(3) requires: act only on our instruction, keep staff under confidentiality, engage nobody further without permission, help us answer you, and delete or return everything at the end. The list stays short deliberately, because each addition is another door.
| Firm | What it does | What it can reach | Where, and on what safeguard |
|---|---|---|---|
| Cloudflare, Inc. | Serves these pages and shields them at the network layer | The request and abuse-blocking records in part 2. No page content, because this site holds none belonging to you | An edge network spanning many countries; British visitors are normally served from a British or European site. The supplier is incorporated in the United States, so the addendum described in part 4 governs the arrangement |
| Our email host | Receives and stores mail sent to the published address | Everything in a message, including anything you decide to attach | Named on request, together with its country and the safeguard covering it |
| Our accountant | Prepares statutory accounts and tax returns | Purchase and payment records, once there is trade to record. No correspondence, and nothing from inside an application | United Kingdom. Nothing leaves the country, so no transfer safeguard arises |
| A fault-report service | Would collect the optional reports described in part 2 | Failure traces only, and only from people who switched the option on | Nobody is engaged. Whoever is chosen appears in this row, with country and safeguard, before a single report is sent anywhere |
Google is deliberately absent from that table. When your browser collects the lettering, it goes straight to Google's servers on nobody's instruction but its own, which makes Google an independent recipient for that one narrow purpose rather than a firm acting for us. We disclose it because the effect on you is the same either way: your network address reaches a third party. Blocking those two hostnames in a content blocker leaves every word of this site readable in a system typeface.
4. Knowing where it travels
Your right
If information about you crosses a border, you may be told which country and which protection travels with it. Chapter V of the UK GDPR exists so that leaving the country cannot be used to leave your rights behind.
How to use it
Ask, in one line, for the current list of destinations. You are entitled to a copy of the safeguard document too, and we will send it with commercial pricing redacted and nothing else taken out.
Our duty
Our preference is boring: keep the data in the United Kingdom, and where a supplier offers a British or European region, take it. Where that is not possible, one of three things has to be true before anything moves.
- The destination has been ruled adequate by the Secretary of State, in which case no extra paperwork is needed and your rights travel intact.
- An International Data Transfer Agreement is in force between us and the recipient.
- The recipient is already on the EU standard contractual clauses, and the UK addendum is bolted onto them so that they bite here as well.
Paper alone is not the test. Before relying on any of the above we assess whether the destination's own surveillance law would hollow the promise out, and if it would, we look for a different supplier rather than filing the assessment and carrying on. Your entitlements do not shrink because a server sits abroad: a request under part 6 covers data wherever it physically rests, and a complaint under part 14 goes to the British regulator regardless.
5. Knowing how long it stays
Your right
Storage limitation is a principle in its own right under Article 5(1)(e). You are entitled to the period, or at least to the rule that fixes it, and a schedule that gives a number without a reason is a habit wearing a schedule's clothes.
How to use it
Find your row. If your situation is not covered, ask; you get a period and the reasoning, not a shrug.
Our duty
Every period in the retention schedule below is justified rather than merely stated. Where two statutes disagree we apply the longer one across the board, so that nobody is worse off for living in one part of the United Kingdom rather than another.
| Record | Kept for | Why that long |
|---|---|---|
| Request and abuse-blocking records | Up to 30 days | Enough to look into an incident, short enough that the pile never becomes a liability. It is the host's own default and we have not lengthened it |
| Ordinary correspondence | 24 months after the last message in the thread | Conversations resume after gaps, and someone may reasonably ask what was agreed. Beyond two years, almost none of it earns its keep |
| Support about something paid for | 24 months, or 6 years where it evidences a purchase or a complaint | A contract claim can be raised for five years in Scotland and six in England and Wales. We hold the longer figure everywhere |
| Accounts and purchase records | 6 financial years after the one they belong to | Company law sets three years for a private company's accounting records; the tax authority wants six. Six wins |
| Account details in an application | As long as the account is open, then gone within 30 days of closure | The account exists to deliver the contract. Once that ends, keeping credentials serves nobody, and 30 days is the deadline we have published |
| Fault reports | 90 days | A crash trace stops being useful once the release it came from has been replaced, and three months covers an unhurried reproduction |
| Rights requests and answers | 3 years after the reply | We may have to show the regulator that requests were handled properly, and to answer the same person consistently if they return |
| Identity evidence sent with a request | Until the check is done, never beyond 30 days | Identity documents are sensitive and have exactly one job. Holding them afterwards is pure risk with no matching benefit |
| Records of a security incident | 6 years from the incident | Article 33(5) obliges us to document every one so the regulator can verify how it was handled, and six years matches the outer edge of related claims |
6. Getting a copy
Your right
Article 15 lets you find out whether anything about you is held, and if it is, to receive a copy along with the surrounding explanation: purposes, recipients, periods, and where it came from if not from you. This is the entitlement people mean when they say subject access request, and it costs you nothing.
How to use it
- Email [email protected] and put Data protection request in the subject line.
- Say which entitlement you are using. Plain words are fine; you need no form, no template and no solicitor.
- Write from the address we already hold for you where you can, since that alone usually settles who you are.
- Narrow it if you can. "Everything from March" is answered faster than "everything", though "everything" is perfectly proper and will be answered.
Our duty
The clock runs for one calendar month from the day your message lands. Genuinely complicated or repetitive requests may take up to two months longer, but if we need that, you hear from us inside the original month with the reason. Where we cannot identify you from what we hold, we say so rather than fishing for documents; where a check is genuinely needed, we ask for the least revealing thing that would settle it and destroy it afterwards.
Refusal is possible only where the law allows, and the two grounds are narrow: a request that is plainly excessive or vexatious, or one that would hand over somebody else's information. We will tell you which ground applies, what we have redacted, and how to challenge it. Charging is not on the table for a first copy.
7. Putting mistakes right
Your right
Under Article 16 you may have inaccurate information corrected, and incomplete information filled in. Accuracy is also a duty on us regardless, so this is a right you should never need to fight for.
How to use it
Tell us what is wrong and what the correct version is. Evidence helps where the point is disputable, but for something like a misspelled name your word is plainly enough.
Our duty
We correct it inside the same month, and we pass the correction to anyone we sent the wrong version to, unless that turns out to be impossible or wildly disproportionate. If we think the existing version is right, we do not simply refuse: we explain the basis, record your disagreement alongside the entry, and tell you how to escalate.
8. Having it wiped
Your right
Article 17 lets you have information erased once it is no longer needed for the purpose that justified collecting it, once consent is withdrawn and nothing else supports it, or where it was never lawful to hold. Closing an account and erasing what sat behind it are separate acts, and you are entitled to both.
How to use it
Send a message headed Delete my data, naming the address any account is under. Where a release includes accounts, account deletion is also available from inside the application itself: a control that closes the account and starts the erasure without you having to compose a message at all. It will never be buried behind a support conversation.
Our duty
Once we are satisfied who you are, erasure completes within 30 days, and you get written confirmation naming what went and what stayed. There is no cooling-off limbo in which the account quietly persists in case you return.
Three things survive, and each has a reason you can check.
- Accounting entries for anything you bought. The law requires them and consent does not enter into it. They are pared to the transaction and its amount, and they expire on the schedule in part 5.
- A minimal note that you asked. Your address, the date, what was done. Without it we cannot show a regulator that your request was honoured, and we would be deleting the evidence that we deleted.
- Anything caught by a live legal claim. Only for as long as the claim runs, and we tell you if this applies to you rather than leaving you to guess.
What we will not do is treat erasure as a background job that gets to it eventually. Deletion instructions reach every firm in part 3 within the same window.
9. Freezing our use of it
Your right
Article 18 gives you a middle setting between leaving things alone and wiping them. We keep the information but stop doing anything with it, which is useful while accuracy is being argued about, or where you want something preserved for a claim of your own that erasure would destroy.
How to use it
Ask for it in terms, and say what you want frozen and why. It pairs naturally with part 7: dispute the accuracy and ask for a freeze in the same message, and nothing moves while the point is resolved.
Our duty
We apply the freeze inside the month and confirm it. While it is on, the data is stored and otherwise left untouched except with your agreement or for a legal claim. Before we lift it, you get told, so a freeze can never end quietly without your knowing.
10. Taking it away with you
Your right
Article 20 covers information you supplied where the handling rests on consent or on a contract and is done by machine. You may receive it in a structured, commonly used, machine-readable form, and you may ask for it to be sent straight to another provider where that is technically workable.
How to use it
Ask for an export and name the format if you have a preference. If you want it delivered to a competitor rather than to you, say so; we regard that as an ordinary request and not as a defection to be slowed down.
Our duty
The export arrives inside the month as JSON or CSV, whichever suits the data better, with a short note explaining the fields. Where an application keeps your work on your own device, the export is a function of that application rather than something you have to request from us, and we regard shipping it as part of doing the job properly rather than as a concession.
11. Saying no, and changing your mind
Your right
Two entitlements sit together here. Article 21 lets you object to handling that rests on legitimate interests, and where the purpose is direct marketing the objection is absolute: no balancing, no argument, it simply stops. Article 7(3) lets you withdraw any consent you gave, as easily as you gave it, and withdrawing it never makes the past handling unlawful.
How to use it
- To object, write and say what you are objecting to. You may explain your particular situation, which strengthens the case, but for marketing you need give no reason whatsoever.
- To pull consent for fault reports, switch the setting off inside the application. Nothing further leaves the device from that moment, and no message to us is needed.
- To take back a device permission, use your phone's own settings screen. We never treat that as a fault, and the application must keep working with the feature that needed it politely disabled.
Our duty
An objection stops the activity unless we can show compelling grounds that override your interests, and if we ever claim that, you get the reasoning in writing and a route to challenge it. Permission prompts are asked for at the moment the feature needs them, never in a queue at first launch, and always after a plain-English screen explaining what happens if you decline. Nothing about this is buried: consent that is hard to withdraw was never freely given in the first place.
12. A decision made by a person
Your right
Article 22 protects you from being subjected to a decision based only on automated processing where it produces a legal effect on you, or something similarly significant. Where such a decision is made, you may demand human intervention, state your side and contest the outcome.
How to use it
Use it the moment a machine, rather than a person, makes a decision that materially affects you. No WILDDECK system works that way, so the right sits unused rather than unavailable, and if that ever changes the mechanics for challenging a decision appear in this part before the first decision is taken.
Our duty
We run no scoring, no ranking, no eligibility test, no per-person pricing and no automated moderation that could cut off your access. Nothing this company operates reaches a conclusion about anybody by machine. Introducing anything of the kind would mean first describing the logic, the significance and the likely consequences here, and putting in place the human review, the right to put your case and the right to object that Article 22(3) requires.
13. Being warned when it goes wrong
Your right
A security incident means information being destroyed, lost, altered, or exposed to somebody who should not have it, whether through accident or attack. Where the consequences for you are likely to be serious, Article 34 entitles you to hear about it directly, in plain terms, without undue delay.
How to use it
Mostly this one comes to you. If you have reason to think something has gone wrong before we have said anything, write and ask; a question about a suspected incident jumps the queue and is answered without waiting for the general timescale.
Our duty
Where an incident is likely to put people's rights at risk, we notify the regulator within 72 hours of becoming aware of it, and if we are ever late, the notification carries the reason for the delay rather than glossing over it. Where the risk to you personally is high, you hear from us as well, and that message tells you what happened, what it means in practice, what we have done and what you should do at your end. We write it in the language of the rest of this guide, not in the language of an apology drafted by somebody with one eye on liability.
Every incident is written up internally whether or not it crosses the reporting threshold, because Article 33(5) requires the record and because a threshold judgment nobody wrote down is not a judgment. A supplier from part 3 that suffers one must tell us without delay, and that obligation is in their contract rather than left to goodwill.
14. Complaining, over our head
Your right
Article 77 gives you a direct line to the supervisory authority, which in the United Kingdom is the Information Commissioner's Office. You may use it whenever you think your data has been mishandled. You do not need our permission, our agreement, or our knowledge, and you certainly do not need to have exhausted anything with us first.
How to use it
We would rather hear first, because most problems are our error and can be mended in days, and because you keep every option open by trying. But that is a preference, not a hurdle, and nothing is lost by going straight to the regulator.
| Body | Information Commissioner's Office |
|---|---|
| Post | Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom |
| Telephone | 0303 123 1113 |
| Online | ico.org.uk/make-a-complaint |
Our duty
Complaints to us go to the same published address and are handled by the company rather than routed into a ticketing product that hides the reply behind a login. Beyond the regulator you also keep a route to the courts, including compensation under Article 82 for damage caused by a breach of the rules, and using one route never closes the other.
15. Duty: keeping it safe
The four parts that follow are ours to perform whether or not anybody asks.
Article 32 asks for measures appropriate to the risk rather than a fixed shopping list, which means the honest thing to publish is what is actually running. Pages are served only over HTTPS, with strict transport security so a browser refuses to fall back to an unencrypted connection. A content security policy limits what a page is permitted to load, which is what stops an injected script from being useful. Traffic to and from every firm in part 3 is encrypted. The mailbox and the hosting account both sit behind multi-factor authentication. The supplier list is kept deliberately short. Personal data is not copied onto laptops beyond what answering a message actually requires.
Because appropriateness is a moving target rather than a certificate, these measures get revisited whenever the handling described in this guide changes, and this part is rewritten to match.
16. Duty: young people
This website is not aimed at children and we do not knowingly gather anything from one through it. Section 9 of the Data Protection Act 2018 puts the age at which a child can consent to an online service in the United Kingdom at 13.
Any application carries an age rating on each store. Where a release is meant for a general audience it is built to the Information Commissioner's Age Appropriate Design Code, which in practice means the private setting is the default rather than the option, that no interface nudges a young person towards giving up more than they need to, that nothing profiles anybody by default, and that a feature collects only what it actually requires to work.
If we discover we are holding something gathered from a child when it should not have been, it goes promptly. If you believe that has happened, write to the address above and it is dealt with ahead of the queue.
17. Duty: what the stores are told
Both app stores make a developer declare, on the listing itself, what an application collects before anyone installs it. Those declarations and this guide have to say the same thing, and where a reader finds them disagreeing we treat it as a defect to be corrected rather than a difference of interpretation.
App Tracking Transparency. Apple's framework requires an application to obtain permission through the system prompt before following a person across other companies' apps and websites, or before reaching for the advertising identifier to do it. Our position is that no application we publish does either. We do not read that identifier, we embed no advertising or attribution kit, we take part in no data broker arrangement, and we join our own data to nothing received from another company for advertising or measurement. Because there is no tracking, the prompt does not appear, and its absence means exactly that rather than a required prompt having been skipped.
Google Play Data Safety. Measured against the application table in part 2, the declaration reads: nothing shared with third parties; collection limited to the rows in that table; fault reporting optional and switchable; everything encrypted in transit; a deletion route available both inside the application and by email. The Apple privacy labels are completed to the same effect.
At every submission, this page and the store declarations are read against each other line by line, and against the software as it actually behaves. A discrepancy found afterwards gets corrected in both places, with the date of the correction stated.
18. Duty: telling you this changed
This is version 1.0, in force from 7 August 2026. When it changes, the version and the date in the panel at the top change with it.
A material change is one that alters what is gathered, what for, on what legal reason, who receives it or how long it lasts. Those are published before they take effect rather than afterwards, and where we hold contact details for the people affected, we write to them instead of hoping they revisit the page. Where a change needs consent, it is asked for rather than assumed.
One commitment about the manner of change, because it is the part that usually goes wrong. If this company ever decides to start doing something this version rules out, advertising identifiers being the obvious example, it will say so in those words. It will not arrive as a softened phrase in a longer document nobody was told had moved.
This guide sits alongside the terms of use and the cookie statement, and forms part of the agreement between us.