All legal documents

Data Protection & GDPR

Our UK GDPR compliance programme: governance, records of processing, DPIAs, sub-processors, international transfers, breach handling and how automated screening stays human-supervised.

Effective and last updated October 2026 · Aquifert Ltd · London · enquiry@aquifert.com

1.Our commitment

Aquifert processes personal data principally of business contacts, but we apply the UK GDPR and the Data Protection Act 2018 in full. The controller is Aquifert Ltd (company number [●]), whose registered office is at [●], United Kingdom (“Aquifert”, “we”, “us”, “our”).

Data protection is designed into the Platform rather than added on: data minimisation, purpose limitation, role-based access and audit logging are built into how the product works.

2.Governance

  • Data protection lead: reachable at privacy@aquifert.com (DPO function).
  • Records of processing activities (ROPA) maintained under Article 30 UK GDPR and reviewed at least annually.
  • Staff confidentiality obligations and data protection training on induction and annually.
  • Data protection impact assessments (DPIAs) conducted for higher-risk processing, including AI-assisted features and compliance screening, before launch and on material change.
  • A standing privacy-by-design checkpoint in our engineering review process.

3.Human oversight of automated screening

Our compliance and matching systems use automated screening (sanctions lists, document checks, risk scoring). No decision with legal or similarly significant effect is made solely by automated means: the engine flags; a human clears. Every flagged transaction or account is reviewed by a trained member of our compliance or operations team, and you may request human review of any decision affecting you by emailing privacy@aquifert.com.

4.Counterparty anonymity and data minimisation

A core data-minimisation control is structural: the Platform is architected so that nothing that could reveal a Supplier reaches a buyer — ever. Quotations, shipping documents and certificates are re-issued or redacted before a buyer can see them. This limits the personal and commercial data any counterparty ever receives to the minimum needed to perform the contract.

5.Sub-processors

Categories of sub-processors we engage (each under a written data processing agreement with Article 28 terms):

  • Cloud hosting and managed database (EU/UK regions where available);
  • Payment processing and billing;
  • Transactional email and customer communications;
  • Customer support and ticketing;
  • Product analytics (subject to cookie consent);
  • KYC/AML and sanctions screening providers.

6.International transfers

Where personal data is transferred outside the UK, we rely on UK adequacy regulations, the UK IDTA, or the UK addendum to EU Standard Contractual Clauses, and assess transfer risk with supplementary measures (encryption, access controls) where required.

7.Data subject requests

We handle access, rectification, erasure, restriction, objection and portability requests free of charge and within one month of receipt (extendable by two further months for complex requests, with notice). Requests: privacy@aquifert.com. We may need to verify your identity first.

8.Personal data breaches

We maintain a breach response procedure. Breaches likely to risk individuals’ rights and freedoms are reported to the ICO within 72 hours of becoming aware, and affected individuals are notified without undue delay where there is a high risk.

9.Retention

Retention periods are set out in our Privacy Policy (section 6). Data is deleted or irreversibly anonymised at the end of its retention period, subject to legal holds.

10.Contact

Data protection lead, Aquifert Ltd — privacy@aquifert.com. Supervisory authority: UK Information Commissioner’s Office (ico.org.uk).

Last updated: October 2026. Questions about this document? Email enquiry@aquifert.com.