eyeDP (“we,” “us,” or “our”) is a trademark of SVC Labs Limited, and respects your privacy and is committed to protecting your personal data. This privacy policy informs you about how we handle your personal data when you visit our website or use our services and outlines your privacy rights and how the law protects you.
SCV Labs Limited is a company registered in England and Wales, with its registered office at 3 Assembly Square, Britannia Quay, Cardiff, CF10 4PL, United Kingdom. We act as the data controller for the personal data collected through our website and services.
We collect, use, store, and transfer different kinds of personal data about you, which we have grouped as follows:
We use different methods to collect data from and about you, including through:
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
We have set out below a description of all the ways we plan to use your personal data, and which of the legal bases we rely on to do so:
Our website uses cookies and similar technologies to distinguish you from other users, provide core functionality, and improve our site and services. We use:
You have the right to decide whether to accept or reject cookies:
You can also opt out of analytics and advertising cookies by using:
For detailed information on each cookie, its purpose, and duration, please see our Cookie Policy.
We are committed to preserving the confidentiality, integrity, and availability of personal data. We implement a layered programme of technical and organisational measures designed to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, or damage.
Technical and organisational measures. We maintain appropriate safeguards tailored to the risk presented by our processing activities and the nature of the data we handle, including access controls, encryption, network and perimeter protections, secure configuration, vulnerability management, logging and monitoring, backup and recovery, and staff training and awareness. We limit access to personal data to personnel and third parties who have a legitimate business need to know and who are bound by confidentiality obligations, and such persons process personal data only on our documented instructions.
Encryption. We use encryption and related key management practices designed to protect personal data in transit and at rest. Where encryption is not feasible, we apply alternative, appropriate compensating controls.
Access controls. We enforce the principle of least privilege through role-based access and account provisioning processes, with authentication controls, periodic access reviews, and prompt revocation of access upon role change or termination.
Regular security assessments. We conduct periodic reviews and assessments of our security controls, including risk assessments, testing and evaluation of the effectiveness of technical and organisational measures, and supplier due diligence and oversight for relevant third-party service providers.
Incident response. We maintain an incident response plan that sets out defined roles, escalation paths, containment and remediation steps, evidence preservation, and post-incident review. Where required by applicable law, we will notify affected individuals and/or regulators of personal data breaches without undue delay.
Confidentiality, integrity, and availability. We safeguard confidentiality through access restriction, encryption, and contractual duties; we protect integrity through change control, input validation, segregation of environments, and audit logging; and we uphold availability through resilience measures such as data backup, restoration testing, and capacity management.
Data handling and retention. We collect, use, and store personal data in accordance with our privacy practices and retain it only for as long as necessary for the purposes for which it was collected or as required by law. We have put in place appropriate security measures to prevent personal data from being accidentally lost, used, or accessed in an unauthorised way, altered, or disclosed. We limit access to personal data to employees, agents, contractors, and other third parties who have a business need to know, require them to process personal data only on our instructions, and bind them to a duty of confidentiality. We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements.
Continuous improvement. We periodically review and update our security measures and this clause to reflect legal, technological, and organisational developments, and we enhance controls in response to identified risks, audit findings, and industry best practice.
We retain personal data only for the period necessary to meet the purposes set out in this policy, after which it will be securely deleted or anonymised. The following retention periods will apply, unless a longer period is required by law or is necessary for the establishment, exercise, or defence of legal claims:
Where specific statutory retention obligations apply, we will retain the relevant records for the period prescribed by law. At the end of the applicable retention period, we will either delete or irreversibly anonymise your data.
We primarily store and process your personal data in the United Kingdom and the European Economic Area (EEA). Where we transfer your personal data to countries outside the UK or EEA that do not provide an equivalent level of data protection, we will implement appropriate safeguards to protect your data, such as:
Details of the safeguards in place can be obtained by contacting us using the details in the “Your Legal Rights” section below.
Under certain circumstances, you have rights under data protection laws in relation to your personal data, including the right to:
If you wish to exercise any of the rights set out above contact: [email protected]
Data Protection Officer
SVC Labs Limited
3 Assembly Square, Britannia Quay, Cardiff, CF10 4PL, United Kingdom
You have the right to lodge a complaint with the UK regulator, the Information Commissioner’s Office (ICO), if you are concerned about the way we handle your personal data. You may wish to contact the ICO if, for example, you believe we are not meeting our data protection obligations, you are dissatisfied with our response to a request to exercise your data protection rights, you have suffered detriment as a result of our processing, or you remain unhappy after raising a concern with us directly.
The ICO can be contacted using the following details:
The ICO encourages individuals to raise concerns with the relevant organisation first. We therefore ask that you contact us in the first instance so we have the opportunity to address your concerns. However, you can contact the ICO at any time.
This Privacy Policy was last updated on 17/04/26