Privacy Policy

eyeDP > Privacy Policy

Introduction

eyeDP (“we,” “us,” or “our”) is a trademark of SVC Labs Limited, and respects your privacy and is committed to protecting your personal data. This privacy policy informs you about how we handle your personal data when you visit our website or use our services and outlines your privacy rights and how the law protects you.

Who We Are

SCV Labs Limited is a company registered in England and Wales, with its registered office at 3 Assembly Square, Britannia Quay, Cardiff, CF10 4PL, United Kingdom. We act as the data controller for the personal data collected through our website and services.

Information We Collect

We collect, use, store, and transfer different kinds of personal data about you, which we have grouped as follows:

  • Identity Data: Includes first name, last name, username or similar identifier, title, date of birth, and gender.
  • Contact Data: Includes billing address, email address, and telephone numbers.
  • Technical Data: Includes internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this website.
  • Profile Data: Includes your username and password, feedback, and survey responses.
  • Usage Data: Includes information about how you use our website and services.
  • Special Category Data: We do not knowingly collect any special categories of personal data about you (such as details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data), nor do we collect any information about criminal convictions and offences. If such information is inadvertently provided to us, we will take steps to promptly delete it or, where deletion is not feasible, to restrict access and apply appropriate safeguards, including limiting processing to what is strictly necessary and ensuring it is handled by personnel subject to confidentiality obligations. Where we have a lawful basis and a relevant condition under applicable data protection laws to process such data, we will inform you and apply enhanced security and retention controls.

How We Collect Your Personal Data

We use different methods to collect data from and about you, including through:

  • Direct Interactions: You may provide us with your Identity and Contact Data by filling in forms or by corresponding with us by post, phone, email, or otherwise. This includes personal data you provide when you:
    • Apply for our services;
    • Subscribe to our newsletter;
    • Request marketing to be sent to you;
    • Give us feedback or contact us.
  • Automated Technologies or Interactions: As you interact with our website, we may automatically collect Technical Data about your equipment, browsing actions, and patterns. We collect this personal data by using cookies, server logs, and other similar technologies.
  • Third Party Suppliers: Occasionally we interact with third party suppliers in order to improve our services to you. From time to time these third-party suppliers may disclose personal data to us. The personal data will have been provided by you to the third party with your express agreement. The personal data we receive in this scenario is promptly removed from any documents via a portal, encrypted and replaced with synthetic data. Following this process the personal data could not at any time be accessed and the data subjects could not be re-identified.

How We Use Your Personal Data

We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:

  • Performance of Contract: Where we need to perform the contract we are about to enter into or have entered into with you.
  • Legitimate Interests: Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
  • Legal or Regulatory Obligations: Where we need to comply with a legal or regulatory obligation.

Purposes for Which We Will Use Your Personal Data

We have set out below a description of all the ways we plan to use your personal data, and which of the legal bases we rely on to do so:

  • To register you as a new customer: Performance of a contract with you.
  • To process and deliver your order: Performance of a contract with you; Necessary for our legitimate interests (to recover debts due to us).
  • To manage our relationship with you: Performance of a contract with you; Necessary to comply with a legal obligation; Necessary for our legitimate interests (to keep our records updated and to study how customers use our products/services).
  • To administer and protect our business and this website: Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud) and to comply with a legal obligation.
  • To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you: Necessary for our legitimate interests (to study how customers use our products/services, to develop them, to grow our business, and to inform our marketing strategy).
  • To use data analytics to improve our website, products/services, marketing, customer relationships, and experiences: Necessary for our legitimate interests (to define types of customers for our products and services, to keep our website updated and relevant, to develop our business, and to inform our marketing strategy).

Cookies

Our website uses cookies and similar technologies to distinguish you from other users, provide core functionality, and improve our site and services. We use:

  • Strictly necessary cookies: essential for site operation and security and cannot be switched off.
  • Performance/analytics cookies: help us understand how visitors use our site to improve performance.
  • Functional cookies: remember your settings and preferences.
  • Advertising/targeting cookies: may be set by us or our partners to deliver relevant advertising and measure its effectiveness.

You have the right to decide whether to accept or reject cookies:

  • Browser Settings: Most web browsers allow you to manage cookie preferences through their settings. Please note that disabling necessary cookies may impact website functionality.
  • Cookie Banner: Upon your first visit, our website presents a cookie banner where you can manage your cookie preferences.

You can also opt out of analytics and advertising cookies by using:

  • Google Analytics: https://tools.google.com/dlpage/gaoptout
  • Your Online Choices (EU): https://www.youronlinechoices.eu
  • Network Advertising Initiative: https://optout.networkadvertising.org

For detailed information on each cookie, its purpose, and duration, please see our Cookie Policy.

Data Security

We are committed to preserving the confidentiality, integrity, and availability of personal data. We implement a layered programme of technical and organisational measures designed to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, or damage.

Technical and organisational measures. We maintain appropriate safeguards tailored to the risk presented by our processing activities and the nature of the data we handle, including access controls, encryption, network and perimeter protections, secure configuration, vulnerability management, logging and monitoring, backup and recovery, and staff training and awareness. We limit access to personal data to personnel and third parties who have a legitimate business need to know and who are bound by confidentiality obligations, and such persons process personal data only on our documented instructions.

Encryption. We use encryption and related key management practices designed to protect personal data in transit and at rest. Where encryption is not feasible, we apply alternative, appropriate compensating controls.

Access controls. We enforce the principle of least privilege through role-based access and account provisioning processes, with authentication controls, periodic access reviews, and prompt revocation of access upon role change or termination.

Regular security assessments. We conduct periodic reviews and assessments of our security controls, including risk assessments, testing and evaluation of the effectiveness of technical and organisational measures, and supplier due diligence and oversight for relevant third-party service providers.

Incident response. We maintain an incident response plan that sets out defined roles, escalation paths, containment and remediation steps, evidence preservation, and post-incident review. Where required by applicable law, we will notify affected individuals and/or regulators of personal data breaches without undue delay.

Confidentiality, integrity, and availability. We safeguard confidentiality through access restriction, encryption, and contractual duties; we protect integrity through change control, input validation, segregation of environments, and audit logging; and we uphold availability through resilience measures such as data backup, restoration testing, and capacity management.

Data handling and retention. We collect, use, and store personal data in accordance with our privacy practices and retain it only for as long as necessary for the purposes for which it was collected or as required by law. We have put in place appropriate security measures to prevent personal data from being accidentally lost, used, or accessed in an unauthorised way, altered, or disclosed. We limit access to personal data to employees, agents, contractors, and other third parties who have a business need to know, require them to process personal data only on our instructions, and bind them to a duty of confidentiality. We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements.

Continuous improvement. We periodically review and update our security measures and this clause to reflect legal, technological, and organisational developments, and we enhance controls in response to identified risks, audit findings, and industry best practice.

Data Retention

We retain personal data only for the period necessary to meet the purposes set out in this policy, after which it will be securely deleted or anonymised. The following retention periods will apply, unless a longer period is required by law or is necessary for the establishment, exercise, or defence of legal claims:

  • Identity and Contact Data relating to customers: 6 years from the end of the contract or last transaction, to align with limitation periods and accounting requirements.
  • Profile and Usage Data: 24 months from last interaction with our website or services, to support service improvement and analytics, after which it will be aggregated or anonymised.
  • Technical Data (including IP addresses, device and log data): 12 months from collection, for security, fraud prevention, and service integrity purposes.
  • Marketing contact details and preferences: until you opt out, and in any event no longer than 24 months from your last interaction with our marketing communications, after which we will retain a minimal suppression record to respect your opt-out.
  • Customer service correspondence and complaints: 3 years from closure of the matter.
 

Where specific statutory retention obligations apply, we will retain the relevant records for the period prescribed by law. At the end of the applicable retention period, we will either delete or irreversibly anonymise your data.

International Data Transfers

We primarily store and process your personal data in the United Kingdom and the European Economic Area (EEA). Where we transfer your personal data to countries outside the UK or EEA that do not provide an equivalent level of data protection, we will implement appropriate safeguards to protect your data, such as:

  • UK International Data Transfer Agreements (IDTAs) or UK Addendum to EU Standard Contractual Clauses;
  • EU Standard Contractual Clauses where relevant; and
  • Additional technical and organisational measures, including encryption and access controls.
 

Details of the safeguards in place can be obtained by contacting us using the details in the “Your Legal Rights” section below.

Your Legal Rights

Under certain circumstances, you have rights under data protection laws in relation to your personal data, including the right to:

  • Request access to your personal data.
  • Request correction of your personal data.
  • Request erasure of your personal data.
  • Object to processing of your personal data.
  • Request restriction of processing your personal data.
  • Request transfer of your personal data.
  • Right to withdraw consent.
 

If you wish to exercise any of the rights set out above contact: [email protected]

Data Protection Officer
SVC Labs Limited
3 Assembly Square, Britannia Quay, Cardiff, CF10 4PL, United Kingdom

Complaints to the Information Commissioner’s Office (ICO)

You have the right to lodge a complaint with the UK regulator, the Information Commissioner’s Office (ICO), if you are concerned about the way we handle your personal data. You may wish to contact the ICO if, for example, you believe we are not meeting our data protection obligations, you are dissatisfied with our response to a request to exercise your data protection rights, you have suffered detriment as a result of our processing, or you remain unhappy after raising a concern with us directly.

The ICO can be contacted using the following details:

  • Website: https://www.ico.org.uk
  • Telephone: 0303 123 1113
  • Textphone: 01625 545860
  • Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
 

The ICO encourages individuals to raise concerns with the relevant organisation first. We therefore ask that you contact us in the first instance so we have the opportunity to address your concerns. However, you can contact the ICO at any time.

This Privacy Policy was last updated on 17/04/26

Simple. Fast. Reliable.
The Digital Eye for Your Documents