Legal
Data Protection Policy
In effect from 1 May 2025
Effective Date: 01-05-2025
This Data Protection & GDPR Policy sets out how Wastify AI Ltd (“Wastify”, “we”, “our”, “us”) processes, protects, and manages personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Wastify AI Ltd is formally registered with the Information Commissioner’s Office (ICO) as a Data Controller. Our ICO registration number is: ZB957060.
We are committed to safeguarding personal data, ensuring transparency, and respecting the rights of individuals whose data we process.
Scope
This Policy applies to:
- Visitors to our website.
- Clients and users of Wastify products and services.
- Partners, suppliers, and contractors who interact with us.
- Employees, job applicants, and other stakeholders.
Data We Collect
We may collect the following categories of personal data:
- Identity data: Name, job title, company, department.
- Contact data: Email address, phone number, business address.
- Usage data: Platform usage, waste logging activities, audit logs, tenant-linked reporting data.
- Technical data: IP address, device identifiers, browser information, and session activity.
- Communication data: Support tickets, call logs, and correspondence.
Lawful Basis for Processing
We process personal data under the following lawful bases:
- Contractual necessity – to deliver services you have subscribed to.
- Legal obligation – to comply with UK law, ESG reporting requirements, or financial regulations.
- Legitimate interests – to improve services, ensure security, and support client relationships.
- Consent – for optional marketing communications.
How We Use Personal Data
We use personal data to:
- Deliver and maintain our services.
- Provide tenant-level reporting and ESG compliance outputs.
- Manage client accounts, invoicing, and billing.
- Monitor service usage and performance.
- Carry out security monitoring and fraud prevention.
- Communicate with clients about updates, features, or support.
- Meet regulatory and legal compliance obligations.
Data Security
Wastify employs robust security measures to protect data:
- Encryption: TLS encryption in transit and AES-256 encryption at rest.
- Access control: Role-based permissions with multi-factor authentication.
- Hosting: Services hosted in UK/EU data centres.
- Monitoring: Continuous monitoring, regular penetration testing, and vulnerability management.
- Backups: Daily backups with geo-redundancy and tested disaster recovery.
Data Retention
We retain data only for as long as necessary for the purposes collected, or as required by law.
- Account data: retained for the duration of a client’s contract plus 7 years for compliance.
- Usage and audit logs: retained for 3 years unless longer retention is required by ESG reporting obligations.
- Marketing data: retained until consent is withdrawn or unsubscribed.
International Transfers
We primarily process and store data in the UK/EU. If data is transferred outside the UK/EU, we ensure that:
- Transfers are made only to countries with adequacy decisions, or
- Appropriate safeguards (e.g., Standard Contractual Clauses) are in place.
Data Subject Rights
Under the UK GDPR, individuals have the following rights:
- Right of access to their personal data.
- Right to rectification of inaccurate data.
- Right to erasure (“right to be forgotten”).
- Right to restrict processing.
- Right to object to processing (including direct marketing).
- Right to data portability.
Requests to exercise these rights should be made via: 📧 hello@wastify-ai.co.uk
We aim to respond to all data subject requests within 30 days in line with regulatory requirements.
Breach Notification
In the event of a personal data breach:
- Wastify will assess the scope and impact immediately.
- The ICO will be notified within 72 hours where legally required.
- Affected individuals will be informed without undue delay if the breach poses a high risk to their rights and freedoms.
Roles and Responsibilities
- Data Protection Officer (DPO): Wastify appoints a DPO responsible for overseeing compliance with data protection obligations.
- Employees: All staff must comply with this Policy and undergo data protection training.
- Suppliers & Partners: Must demonstrate compliance with data protection laws through contracts and due diligence.
Policy Updates
This Policy may be updated from time to time to reflect changes in law, regulation, or business practices. Any updates will be published on this page with a revised effective date.
Contact
For questions about this Policy, to exercise your rights, or to raise a concern, please contact us:
📧 hello@wastify-ai.co.uk