Privacy Policy.
United Kingdom
Datanest Software Limited (NZBN 9429049893533) and its Related Bodies Corporate (“Datanest”, “we”, “us”, and “our”) respects your privacy and is committed to protecting it. We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, which govern how organisations process personal data.
Under the UK GDPR, “Personal Data” means any information relating to an identified or identifiable natural person ('data subject').
If you have any concerns or complaints about the manner in which your Personal Data has been collected, used, or disclosed by us, please contact us via the information set out in Section 10. We recommend that you keep this document for future reference.
Our website and services are not intended for children under 18, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us.
The kinds of Personal Information collected, used and disclosed by Datanest
We will only collect, use, or disclose your Personal Data where we have a valid lawful basis under the UK GDPR. We set out common collection, use, disclosure, and lawful basis instances in the table below:
Contact information: Name, company name, address, billing address, email address, phone numbers, login credentials.
Customer Service: Data collected in connection with enquiries or support.
Services: Facilitating access to products/services, handling customer support, enquiries, and billing.
Marketing: Uses outlined in the "Marketing Services" section.
Administration & Security:
System protection, business administration, quality assurance, and potential business sales.
Third parties connected with sales/e-commerce, payment gateway providers, financial institutions, IT service providers/consultants, related bodies corporate, and law enforcement (if legally required).
Performance of a Contract (Art. 6(1)(b)) & Legitimate Interests (Art. 6(1)(f))
Contact information: Name, email, postal address, phone numbers, country of residence.
Website Enquiries & Forums: Message content, account details, community posts.
Social Media Activity: Likes, comments, feedback, photos.
Analytics: Aggregated usage data.
Direct Marketing: Sending newsletters, updates, product awareness, and promotional alerts.
Consumer Analytics: Aggregating data to analyze market trends.
Social Media: Responding to social media messages and fulfilling platform rules.
Marketing software providers, promotional partners, IT service providers, related bodies corporate, and sales-related disclosures listed above.
Consent (Art. 6(1)(a)) for electronic marketing, or Legitimate Interests (Art. 6(1)(f)) for existing customers
Contact & ID: Name, email, address, phone, photo, passport/visa details, date of birth, next of kin.
CV & Qualifications: Work eligibility, education, professional memberships.
Financial: Payroll, tax, national insurance, bank details.
Screening & Health: Pre-employment medicals, drug/alcohol testing, referee feedback, background checks, CCTV footage.
Background Checks: Identity verification, criminal history checks, right-to-work confirmation, reference validation.
Employee Administration: Managing employment/contractor relationships, monitoring system and internet usage, performance tracking, workplace safety, payroll, and tax reporting.
HMRC, government agencies, pension providers, worker's compensation bodies, recruitment agents, payroll service providers, background screening partners, and financial institutions.
Performance of a Contract (Art. 6(1)(b)), Legal Obligation (Art. 6(1)(c)), and Legitimate Interests (Art. 6(1)(f))
How Datanest collects and holds Personal Information
Collection generally
As much as possible, we collect your Personal Data directly from you. When you fill out forms, submit support tickets, or engage with our platform, providing certain details may be mandatory to receive services. Failure to provide mandatory data may prevent us from providing services effectively.
Other collection types
We may also collect Personal Data about you from third parties or publicly available sources, including:
- Publicly accessible registers, Companies House, court judgments, and directorship searches;
- Online business directories and social media platforms (e.g., LinkedIn, Facebook, X, Google).
Notification of collection
If we collect details about you from someone else, we will notify you where required by law, except where:
- Information is obtained from referees listed on your application;
- Data is collected from publicly available sources; or
- Notification is prohibited or exempted by law.
Subprocessor & Third Party vendors
We use trusted third-party service providers to support the operation of our website, platform, customer support, billing, analytics, security, and communications. Where those providers process personal data on our behalf, we require them to process it only under our instructions and subject to appropriate confidentiality, security, and data protection obligations.
Unsolicited Personal Data
If we receive unsolicited Personal Data that is not required for our business purposes, we will securely destroy or permanently de-identify it as soon as practicable. If unsolicited data relates to potential future employment (e.g., an unsolicited CV), we may retain it within our HR records with your consent.
Storage and Security
Once collected, your Personal Data is stored on secure infrastructure controlled by us or hosted by third-party cloud service providers bound by appropriate data protection safeguards.
Cookies and Technical Data
We utilize cookies, IP tracking, and similar technologies to monitor website traffic, maintain operational security, analyze user performance, and enhance user experience. You can set your browser to reject cookies, though some features of our platform may become unavailable as a result.
Uses and disclosures of Personal Data
Permitted Disclosures
We use and disclose Personal Data strictly for the primary purposes detailed in Section 1, or for secondary purposes directly related to our operations where you would reasonably expect such use.
Exceptional Disclosures
We may disclose Personal Data without seeking further consent if:
- Required or authorized by law, court order, or regulatory authority;
- Necessary to prevent or lessen a serious and imminent threat to life, health, or safety; or
- Necessary to investigate or respond to suspected unlawful activity or security threats.
Our role as controller and processor
For personal data we collect directly from you, such as account registration data, billing details, support requests, website usage data, marketing preferences, and job application information, Datanest acts as the controller.
Where our customers upload, submit, or otherwise make personal data available through the Datanest platform, we usually process that data as a processor on behalf of the customer. In those circumstances, the customer is the controller and is responsible for determining the purposes and lawful basis for processing. Our processing of customer-controlled data is governed by our Terms and Conditions.
Special Category (Sensitive) Personal Data
Definition
Special Category Data includes information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or sexual orientation.
Handling & Explicit Consent
We process special category data only where an Article 9 UK GDPR condition applies, such as explicit consent, employment law obligations, occupational health requirements, legal claims, or another condition permitted by UK data protection law. Where required, we also rely on an appropriate condition under the Data Protection Act 2018 and maintain appropriate safeguards.
Direct Marketing & Opt-Out
Marketing Communications
Where required by law, we will obtain your consent before sending electronic marketing communications. In some cases, we may rely on the soft opt-in under PECR or our legitimate interests under UK GDPR, such as where we market similar products or services to existing business contacts and provide a clear opportunity to opt out.
Opt-out
If at any time you do not wish to receive any further Direct Marketing Communications from us or others under this Section 6, you may ask us not to send you any further information about products and services and not to disclose your information to other organisations for that purpose. You may do this at any time by using the “unsubscribe” facility included in the Direct Marketing Communication or by contacting us via the details set out in this document.
International Data Transfers (Cross-Border Disclosures)
Transfer Mechanisms
Personal Data collected by Datanest may be stored or processed outside the UK, including in New Zealand, where Datanest Software Limited is incorporated and/or operates, or in other jurisdictions via global cloud service infrastructure.
When transferring Personal Data outside the UK, we ensure appropriate safeguards are established in compliance with UK GDPR Article 46, using:
- Countries recognized by the UK government as offering an adequate level of data protection (e.g., New Zealand);
- The UK International Data Transfer Agreement (IDTA) or the UK Addendum to EU Standard Contractual Clauses (SCCs) with international vendors.
Where personal data is transferred from the UK to New Zealand, we rely on the UK’s adequacy regulations recognising New Zealand as providing an adequate level of protection.
Data Security, Accuracy, and Retention
Security Safeguards
We take technical and organizational measures to safeguard Personal Data against unauthorized access, loss, misuse, alteration, or destruction. While no internet transmission is completely immune to threats, we continuously maintain safeguards to minimize operational risk.
Security Breach Procedures
In the event of a confirmed or suspected personal data breach that poses a risk to your rights and freedoms, we maintain incident procedures to notify affected individuals and the UK Information Commissioner’s Office (ICO) without undue delay, as required by law.
Data Retention
We retain Personal Data only for as long as necessary to fulfill the primary purposes set out in this Policy or as required by statutory, tax, accounting, or legal obligations. Once data is no longer needed, we securely delete or permanently anonymize it.
Your Data Subject Rights under the UK GDPR
Subject to statutory conditions and exemptions, where the UK GDPR applies to our processing of your personal data, you may have the following rights the following rights regarding their Personal Data:
- Right of Access: Request a copy of the Personal Data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete Personal Data.
- Right to Erasure (“Right to be Forgotten”): Request deletion of your Personal Data where processing is no longer necessary or lawful.
- Right to Restrict Processing: Request that we temporarily suspend processing your data under certain circumstances.
- Right to Data Portability: Request a copy of your data in a structured, commonly used, machine-readable format for transfer to another provider.
- Right to Object: Object to our processing of your data based on legitimate interests or for direct marketing.
- Withdraw Consent: Withdraw consent at any time where processing was based on prior consent.
To exercise any of these rights, please contact us using the details in Section 10. We respond to verified statutory requests within one calendar month.
Resolving Privacy Complaints
Complaints Procedure
We maintain a process to resolve privacy complaints promptly and fairly. If you have concerns about how we collect, handle, or store your Personal Data, please contact our Privacy Team.
Contact Details
Datanest Software Limited is incorporated in New Zealand with NZBN 9429049893533 and has its registered office at Unit 15, 14 Broad Street, Christchurch 8023. You can contact us about privacy matters at hello@datanest.earth.
Escalation to Supervisory Authority (ICO)
If you are dissatisfied with our response or believe your data rights have been infringed, you have the right to lodge a complaint with the UK supervisory authority:
- Information Commissioner’s Office (ICO)
- Website: www.ico.org.uk
- Helpline: 0303 123 1113
Consent, Modifications, and Updates
Interaction with Contracts
This Privacy Policy outlines legal data practices rather than serving as a commercial contract. However, terms of this policy may be incorporated by reference into our customer agreements (such as our SaaS Cloud Computing Terms).
Policy Updates
We review and update this Privacy Policy periodically to reflect legal, regulatory, or operational changes. Updated versions will be published on our website with a revised revision date.