Privacy policy
This privacy notice tells you what to expect us to do with your personal information. This Notice covers the personal information we collect and use as a controller in our own right, for example information about visitors to our website, prospective and existing customers and their contacts, and users of our platform. It does not cover the data our customers upload to the platform, which we process on their behalf as a processor, see “When we act as a processor” below. We are not a controller of clinical trial or patient health data.
Our staff are based in the United Kingdom and we do not outsource or offshore any of our operations. Our staff may occasionally access our systems while traveling for work, subject to the same access controls that apply in the UK, including individual accounts, multi-factor authentication, encryption and access logging. We do not accept card payments and do not hold card details.
We may update this Notice from time to time. Any update will be posted on this page with a revised “Last updated” date, and will apply to our processing of personal information from that date onwards. Where a change is material, we will take reasonable steps to bring it to your attention.
Presentient Technologies Ltd · Last updated September 2026
Contact details
Data Protection Officer: our Chief Operating Officer is responsible for data protection. You can contact them at dpo@presentient.com.
EU Representative: the contact details for our Representative for GDPR purposes are dpo_eu@presentient.com.
What information we collect, use, and why
We collect or use the following information to provide services:
- Names and contact details
- Website user information (including user journeys and cookie tracking)
We collect or use the following information for the operation of customer accounts:
- Names and contact details
- Account information, including registration details
- Login and authentication data, and data about your use of the platform, including audit logs
We collect or use the following information to comply with legal requirements:
- Name
- Contact information
We collect or use the following personal information for dealing with queries, complaints or claims:
- Names and contact details
Lawful bases and data protection rights
Under UK data protection law, we must have a “lawful basis” for collecting and using your personal information. There is a list of possible lawful bases in the UK GDPR. You can find out more about lawful bases on the ICO’s website.
Which lawful basis we rely on may affect your data protection rights which are set out in brief below. You can find out more about your data protection rights and the exemptions which may apply on the ICO’s website:
- Your right of access – You have the right to ask us for copies of your personal information. You can request other information such as details about where we get personal information from and who we share personal information with. There are some exemptions which means you may not receive all the information you ask for. Read more about the right of access.
- Your right to rectification – You have the right to ask us to correct or delete personal information you think is inaccurate or incomplete. Read more about the right to rectification.
- Your right to erasure – You have the right to ask us to delete your personal information. Read more about the right to erasure.
- Your right to restriction of processing – You have the right to ask us to limit how we can use your personal information. Read more about the right to restriction of processing.
- Your right to object to processing – You have the right to object to the processing of your personal data. Read more about the right to object to processing.
- Your right to data portability – You have the right to ask that we transfer the personal information you gave us to another organization, or to you. Read more about the right to data portability.
- Your right to withdraw consent – When we use consent as our lawful basis you have the right to withdraw your consent at any time. Read more about the right to withdraw consent.
Our lawful bases for the collection and use of your data
To provide services and goods
- Consent – we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.
- Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
- Legal obligation – we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object and the right to data portability.
For the operation of customer accounts and guarantees
- Consent – we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.
- Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
For service updates or marketing purposes
- Consent – we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time (see How to withdraw your consent).
- Legitimate interests – we’re collecting or using your information because it benefits you, our organization or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are to provide, improve, and customize our website and services, which furthers our legitimate interest in operating our business and communicating with the public regarding our website and services; supporting or provisioning users’ procurement, access to, and use of our website or services; analyzing, understanding, and obtaining insights into how our website and services are being used by users and how users are communicating with us; benchmarking, auditing, developing, and improving our website, services, and communications; monitoring the health, performance, and security of our website and services; and exploring and developing new methods of developing and growing our business.
For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.
For legal requirements
- Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
- Legal obligation – we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object and the right to data portability.
For dealing with queries, complaints or claims
- Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
Where we get personal information from
- Directly from you
- Third parties: our customers, who may provide contact details of their staff so that we can set up platform accounts and administer their agreement with us.
When we act as a processor
Our customers upload data to the platform. For that data our customer is the controller and we act only on its instructions under a data processing agreement. Our customer’s own privacy information governs that data, and our customer is responsible for informing individuals about it and for having a valid lawful basis and condition for the processing. If you believe an organization has uploaded your data to our platform and you wish to exercise your rights, please contact that organization, or contact us and we will pass your request on.
The only sub-processor with access to data our customers upload is Amazon Web Services, which provides the hosting infrastructure for the platform.
Your BRAKES platform account
If you use our BRAKES platform, we collect and use your account and contact details, your login and authentication data, and data about your use of the platform including audit logs. We use this to provide, administer and secure the platform, to communicate with you about it, to provide support, and to meet our legal and regulatory obligations. Our lawful bases are the performance of our contract with your organization and our legitimate interests in operating and securing the platform. This is separate from the data your organization uploads to the platform.
Automated decision-making
We do not make decisions about you by automated means that have legal effects or otherwise significantly affect you. Where our platform produces analysis for a customer, decisions about that analysis are taken by the customer, not by us.
How long we keep information
| Information type | Use of data | Retention period |
|---|---|---|
| Names and contact details | Provision of goods and services | 6 years |
| Website user information | Provision of goods and services | 1 year |
| Names and contact details | Operation of customer accounts | 6 years |
| Account information, including registration details | Operation of customer accounts | 6 years |
| Names and contact details | Legal requirements | 6 years |
| Names and contact details | Dealing with queries and complaints | 3 years |
For more information on how long we store your personal information or the criteria we use to determine this please contact us using the details provided above.
Who we share information with
Data processors
- Amazon Web Services. Infrastructure provider for hosting our web application and the BRAKES platform.
- Atlassian. Management of support tickets.
- Google. Google Workspace, for email, documents and data storage; and Google Analytics, for website analytics using aggregate statistics only (we do not enable Google Signals or advertising features).
- Hubspot. Customer relationship management, website forms and cookie consent records.
- Cloudflare and Sanity. Cloudflare hosts, delivers and protects our website. Sanity is our content management system and holds the content of the website.
Sharing information outside the UK
Some of our processors can access personal information from outside the UK. Where they do, appropriate safeguards are in place under the UK GDPR, as set out below. Our own staff access is from the UK, or occasionally from abroad while traveling for work, in each case under the same access controls. Where our contract is with a processor based in a country covered by UK adequacy regulations, no additional safeguard is needed for our transfer to that processor, and any onward transfer by that processor is its own responsibility.
For further information or to obtain a copy of the appropriate safeguard for any of the transfers below, please contact us using the contact information provided above.
Children’s privacy
Our Services are not directed to children under the age of 16, and we do not knowingly collect online personal data directly from children. If you are a parent or guardian of a minor child and believe that the child has disclosed online personal data to us, please contact us via email: dpo@presentient.com.
Changes to this policy
We may update this Notice from time to time. Any update will be posted on this page with a revised “Last updated” date and will apply from that date onwards. Where a change is material, we will take reasonable steps to bring it to your attention.
How to complain
You have the right to complain to us if you think we have not handled your personal information properly. You can complain by email to dpo@presentient.com, or by post to Presentient Technologies Ltd, 3 More London Riverside, London, SE1 2RE. You do not have to use either route and we will accept your complaint however it reaches us. We will acknowledge your complaint within 30 days of receiving it, make appropriate inquiries into it without undue delay, keep you informed of progress, and tell you the outcome and the reasons for it.
If you remain unhappy after complaining to us, you can also complain to the Information Commissioner’s Office, the UK data protection regulator. Where you are in the EEA, you may also complain to the supervisory authority in your country of residence.
The ICO’s address:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline number: 0303 123 1113
Website: ico.org.uk/make-a-complaint
