Trust and compliance
Every claim on this page can be checked. Please do.
Everything below is either a statutory registration you can verify on a public register, or a fact about how this system is actually built. Nothing here is a roadmap, and nothing is asserted that you cannot check for yourself.
ISO/IEC 27001
2022 revision
Implementation phase
We are building the information security management system with Sprinto. An independent audit and certification process follows, through a certification body accredited by the International Accreditation Forum. We are not certified until that audit is passed, and we will publish the certificate when it is.
UK GDPR
Data Protection Act 2018
Readiness assessment
Sprinto is running a readiness assessment against UK requirements, after which we implement the practices it identifies. Our supervisory authority is the Information Commissioner’s Office, we are registered with it, and our privacy notices are already published.
EU GDPR
Regulation 2016/679
Readiness assessment
The same engagement covers the EU position. Service data is already hosted in the European Union, and the outcome includes a Data Processing Agreement so customers can use Wastify AI as a processor. Transfers outside the EEA rely on standard contractual clauses, listed on the sub-processors page.
ICO registration
Reference ZB957060
Active
Wastify AI Ltd is registered with the Information Commissioner’s Office as a data controller. You can verify the entry yourself on the ICO’s public register, and we would rather you did. Registration is a statutory requirement for a data controller rather than a security certification, and we do not present it as one.
Check this on the ICO registerWhat is true today
Each of these describes the system as it is running now, not a roadmap. Several are checkable from outside without asking us.
This website
No cookies, and no consent banner because none is needed
This site sets no cookies on any public page. No analytics product is loaded, and every script served is our own. There is nothing to consent to, which is why you were not asked.
Served over TLS, on infrastructure in the EU
The site and its database run on Railway in the EU West region. Traffic is served over HTTPS only.
Documents behind the form are genuinely private
Gated documents are held in a private bucket with access control on, and a download is issued as a signed link that expires after ten minutes. The file cannot be fetched by guessing its address, which is what separates a real gate from a decorative one.
The personal data you give us
We ask for what the request needs, and say why
Requesting a document asks for your name, work email and company. The consent wording shown at the point of capture is stored alongside the record, so we can show what you were told at the moment you were told it.
An erasure request is one query, not an archaeology exercise
Leads are held in a typed collection carrying the source, the consent evidence and the lawful basis, rather than as untyped form submissions. That is a deliberate design decision, and it is what makes a subject access or erasure request answerable quickly and completely.
Access to the CMS is least privilege
There are two roles, administrator and editor. Only administrators can read lead records. Role assignment is locked at field level, so an editor cannot grant themselves administrator rights.
Questions a form will not answer
For a security questionnaire, a data processing agreement, a records of processing request or anything else a procurement team needs in writing, write to us and a person will answer.
hello@wastify-ai.co.ukWastify AI Ltd, Company No. 16641783. ICO Registration ZB957060. Registered in England and Wales.