Third Party Index

Snapshot 60970

Document
Privacy policy
URL
https://provenworks.com/privacy-policy/
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
static
Size
159384 bytes
SHA-256 (raw)
f69c5d8a14e594aa2ca3a25f01f66d700d41d71fab7ab6089ae02ddc09148cc1
SHA-256 (normalized text)
d609af9862b781ca2c30a8eebb5b09f82336d152319e49f14db4066aab8485cc

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Privacy Policy
1. Who We Are and How to Contact Us
Proven Works Limited (“ProvenWorks”, “we”, “us”) is the controller of the personal data described in this notice.
Detail	Information
Legal entity	Proven Works Limited
Registered number	06488766
Registered office	John Adams House, 29 Castle Street, Reading, RG1 7SB, United Kingdom
Data Protection Officer	legal@provenworks.com
Postal address for data protection matters	The Data Protection Officer, Proven Works Limited, John Adams House, 29 Castle Street, Reading, RG1 7SB, United Kingdom
ICO registration	ZA428738
Sales enquiries	sales@provenworks.com
We have designated a Data Protection Officer. You can contact them, about anything in this notice or about how we handle your personal data, at legal@provenworks.com, or by post at the address above marked for their attention.
2. What This Notice Covers
This notice covers the personal data we collect:
when you visit one of our websites: provenworks.com and impowr.io, together with any subdomain of them or of our product domains addresstools.io, phonetools.io and industrycomplete.io, including our product documentation sites. The three product domains themselves take you straight to provenworks.com
when you enquire about, or buy, our products, and when we contact you about them
when we market our products to you, by email or by telephone
when you speak to us on a sales call
Data inside our software, put there by our customers, is not covered: the customer decides what personal data goes into our licensed software and why, the customer is the controller and ProvenWorks is the processor, and the customer’s own privacy notice governs that data. If you want to know how your data is handled inside a ProvenWorks product that your employer or supplier operates, ask them. Where your employer or another organisation licenses our software, the information the software sends us to operate the license, including details identifying individual users, is governed by our agreement with that organisation, not by this notice; ask them for details.
If you apply to work for us, section 3.5 explains what we do with your application.
Our sites contain links to websites we do not run. This notice does not apply to them, and their own privacy notices govern what they do.
3. The Personal Data We Collect and Why
This section describes the personal data we may collect in each relationship we have with you, what we use it for, and our lawful basis for using it. Where we rely on legitimate interests, we weigh our interest against your rights. Section 5 covers marketing and profiling, and section 6 covers what happens when you visit our websites.
3.1 Enquiries and Demonstrations
When you complete an enquiry form on one of our websites, we may collect:
What we ask for	Do you have to give it?
Your first name and last name	Yes
Your company name	Yes
Your email address	Yes
Your country	Yes
Which product you are asking about	Yes
Your message to us	Yes
Your telephone number	No
How you heard about us	No
If you leave out the items marked yes, the form cannot be sent and your enquiry will not reach us. Nothing obliges you to send us an enquiry in the first place. The form also carries a separate, unticked box asking whether you want to receive marketing email from us about ProvenWorks products. Ticking it is entirely optional, and leaving it unticked does not stop us answering your enquiry.
The box is not the only way we may contact you about our products. Where you do not tick it, we may still send you marketing email in reliance on our legitimate interests, in the circumstances section 5 describes, and you can tell us to stop at any time.
We use what you send us to deal with your enquiry and to keep a record of what you asked and what we answered, relying on our legitimate interests in dealing with enquiries about our products, so that you do not have to repeat yourself. Where you tell us your job title, or anything further about your organisation, in the course of dealing with us, we may record that as well.
If you book a demonstration or an introductory call through one of our booking pages, run for us by Calendly, you give us your name and email address, and on some pages your telephone number. We use them to arrange and run the meeting and to follow it up, relying on the same legitimate interests in dealing with enquiries about our products.
3.2 Customers and Contract Contacts
Where your organisation buys our products, we use your business contact details to administer our commercial relationship with it, including licensing, renewals and support, relying on our legitimate interests in administering that relationship, which needs a named point of contact. You are not personally required to be that contact. We also keep the invoices, accounting and tax records the law requires us to keep, under legal obligation.
3.3 Calls We Record and Transcribe
Where you consent on the call, we record sales calls and transcribe them. We ask you on the call whether you mind it being recorded, and if you do not consent, the call is not recorded or transcribed. The recording and the transcript contain what you said on that call, and our lawful basis for them is that consent. The meeting software also shows every participant an on-screen notification when recording or transcription starts. Where a call is recorded, we also use an AI assistant (Microsoft 365 Copilot) to produce a meeting summary and action items from it; those notes are derived from your call, are personal data, and are covered by the same consent. Section 9 says how long the recording, the transcript and the notes are kept.
3.4 Special Category Data
We do not ask for, and do not knowingly collect, the special categories of personal data described in UK GDPR Article 9, such as health data or data about your beliefs. Please do not send them to us.
3.5 If You Apply to Work for Us
We advertise our vacancies, and take applications, through Breathe HR. Breathe runs that system on our instructions, as our processor, and we are the controller of what you send.
The application form asks for your title, your first name and last name, the name you are known as, your telephone number, your email address, your full postal address, how you heard about the vacancy, and anything you want to tell us in a free-text note. You can also upload a CV or a covering letter.
We use all of it to assess your application and to run the recruitment process, including getting in touch with you about it. Our lawful bases are that the processing is necessary to take steps at your request before entering into a contract, and our legitimate interests in recruiting for our own vacancies. If we offer you a job, we then have to check that you are entitled to work in the United Kingdom, which is a legal obligation on us.
Nothing obliges you to apply, or to tell us anything you would rather not. If you leave out what we ask for, we may not be able to assess your application or come back to you about it.
If you are not successful, we keep your application for up to six months and then delete it. The form carries a separate box asking whether we may hold your details for other vacancies you might suit. If you tick it, we may keep them for up to a further twelve months so that we can consider you for other vacancies, relying on that consent. You can change your mind at any time by emailing recruitment@provenworks.com, and doing so does not affect the application you have already made.
4. Where We Get It From
Most of the personal data we hold about you comes from you, either because you gave it to us or because it was collected from your device when you used our websites (section 6). Our marketing contacts come from you: an enquiry form on one of our websites, meeting us at an event, or asking us about our products.
We may also look up a work telephone number for you from publicly available sources, for example your organisation’s website or its Google Maps listing, so that we can reach you at work. This notice is how we tell you that, and where the number came from: it is linked from the forms you use to contact us and from every marketing email we send you. If you have not seen this notice before we first call you, we will point you to it on the call.
5. Marketing, Profiling and Your Right to Object
What we send, and on what basis. We send sales and marketing email about our products. Where you ticked the box on an enquiry form, we rely on your consent. Otherwise we rely on our legitimate interests in promoting our products to the named business contacts of organisations that have asked about them, bought them, or met us at an industry event. Where we send you such email, we may record whether you opened it, relying on your consent, and whether you selected a link in it, relying on our legitimate interests in making any follow-up timely and relevant to what you actually looked at.
Telephone. We may telephone you about our products, relying on our legitimate interests in contacting named business contacts, about products relevant to their work, such as at organisations that have asked about our products, bought them, or met us at an industry event. Before we call, we check your number against the preference registers the law requires us to check, which is a legal obligation on us, and we do not call numbers registered on them.
You can tell us to stop at any time, and we have to. Section 10 explains your absolute right to object to marketing, which also stops the scoring described below.
A score and a grade. From your interactions with our emails and the forms you send us, we work out a score and a grade, held on your contact record. These are personal data about you, and your rights, including your right to object, apply to them (section 10). We rely on our legitimate interests in prioritising our sales effort on the contacts who have shown interest in our products, using activity we already hold lawfully.
We use the score and grade to decide whether and how our sales team gets in touch, including automatically starting or stopping email sequences, changing your membership of our mailing lists, and assigning a salesperson once a score passes a threshold. This is profiling, and parts of it run without individual review. It never affects what you pay, and anything you send us always reaches a person. You can object at any time and the scoring stops.
6. Cookies, Trackers and Online Identifiers
Cookies and similar technologies are governed by the Privacy and Electronic Communications Regulations 2003 (PECR) as amended.
The rule we must meet. Except where a technology is strictly necessary to deliver a page you asked for, or to remember the cookie choice you made, your consent is required before it is used, and you must be able to withdraw that consent afterwards.
Every analytics, session replay, advertising and cross-site tracking technology below runs only with your consent.
Our lawful basis under the UK GDPR. Where a technology needs your consent under the rule above, that consent is also our lawful basis for the personal data it collects, and you can withdraw it at any time (section 6.2). One part of your visit is not a matter of choice. Whoever serves you the page receives your IP address and information about your device, browser and operating system, because a page cannot be delivered to you without them, and the same information is used to keep our sites available and free of automated abuse. Which of our providers that is depends on which of our sites you visit: our website host serves provenworks.com and impowr.io, and our content delivery and DNS provider handles our other domains and our product documentation sites. Both are named in section 7. On provenworks.com and impowr.io, when our cookie consent banner loads, its provider, also named in section 7, receives the address of the page, your browser language, information about your browser and your IP address, which it uses to work out where you are so that it shows you the right banner, and it keeps none of them once the banner has been shown. For all of this we rely on our legitimate interests, and you can object under section 11.5. The record of the choice you then make is different: we keep it because the law requires us to be able to show that you consented, which is a legal obligation on us, and section 9 says how long it is kept.
Where one of our product documentation sites uses analytics, it asks for your consent through a control built into the site itself. That control keeps your choice only in your own browser: neither we nor any provider receives a record of it.
6.1 What Is Running on Our Websites
Purpose	Provider and technology
Tag management (a container that loads other items, not a purpose in itself)	Google Tag Manager
Cookie consent banner and recording your choice on provenworks.com and impowr.io (strictly necessary)	Cookiebot
Cookie consent control on our product documentation sites, remembering your choice in your browser only (strictly necessary)	The consent feature built into the documentation site software (Material for MkDocs)
DNS, and content delivery and security in front of our other domains and documentation sites (partly strictly necessary)	Cloudflare
Website analytics	Google Analytics 4
Session replay, recording mouse movement, scrolling, clicks and page content. What you type into form fields is masked	Microsoft Clarity
Advertising and ad serving	Google Ads, Google AdSense
Advertising conversion tracking	LinkedIn Insight Tag
Advertising conversion tracking	Reddit pixel
Advertising measurement and conversion tracking on impowr.io, recording your visit and whether you go on to our demonstration booking page	OpenAI measurement pixel
Email preference centre, reached from the footer of our marketing email	Pardot (Salesforce Account Engagement)
Embedded video, loaded only when you choose to play it	YouTube
6.2 Changing Your Mind
You can change or withdraw your consent at any time. On provenworks.com and impowr.io, use the cookie settings control, or the cookie declaration, on the site. On a product documentation site that asks for your consent, use the Cookie settings link at the foot of the page. Withdrawing consent will not make our earlier use of the data unlawful, and it will not stop us using data we hold on a different basis.
7. Who We Share Your Data With
7.1 Service Providers Acting on Our Instructions
These organisations process personal data for us, on our instructions.
What they do for us	Who they are
Hosting and serving provenworks.com and impowr.io, content management, and the fonts served with them	Automattic (WordPress.com)
DNS, and content delivery and security for our other domains and our documentation sites	Cloudflare
Showing the cookie consent banner on provenworks.com and impowr.io and keeping a record of the choice you make (section 6)	Usercentrics (Cookiebot)
Customer relationship management	Salesforce
Marketing automation and prospect email	Pardot (Salesforce Account Engagement)
Website analytics	Google (Analytics, Tag Manager)
Accounting, invoicing and payment handling	Xero
Advertising our vacancies, receiving applications, and our HR records (section 3.5)	Breathe HR
Booking a demonstration call with us, where you use the booking page rather than emailing us	Calendly
Legal and accounting advice, where we need it	Our lawyers and accountants
Our business email and calendars, the platform we use for video meetings and sales calls, and the storage that holds a call recording, its transcript and the notes made from it (sections 3.3 and 9)	Microsoft (Microsoft 365)
7.2 Organisations That Decide for Themselves What They Do with the Data
These providers are not acting only on our instructions. They decide for themselves what to do with data collected through our sites, and their own privacy notices govern that use:
Service	Provider	Position
Session replay	Microsoft (Clarity)	Microsoft’s terms for Clarity make Microsoft and ProvenWorks independent controllers, and expressly state that neither is the other’s processor. Microsoft’s terms permit it to use what it collects for its own purposes, including building user profiles for advertising. That is Microsoft’s use, decided by Microsoft, and it is not something we direct or can limit
Insight Tag and advertising	LinkedIn	LinkedIn acts as a separate and independent controller of the data the tag collects
Advertising pixel	Reddit	Reddit receives the data as a recipient in its own right
Advertising measurement and conversion tracking on impowr.io	OpenAI	OpenAI’s Ad Tools terms make each party an independent controller of what the pixel collects, and state that neither party is the other’s processor for it. The exception is a narrow category the terms call Restricted Processing, which covers matching a contact list we supply against OpenAI’s own records, and any data we send marked with an opt-out. For that, OpenAI acts as our processor
Advertising and ad serving	Google (Ads, AdSense)	Google’s advertising terms treat Google as a controller in its own right for these services, with some features running under separate processor terms
Embedded video	YouTube (Google)	The player is not loaded until you select it and accept marketing cookies. Once you do, it sets its own identifiers and reports to Google, which acts as an independent controller of what it collects rather than as our processor
7.3 Payments
We do not store, process or transmit card numbers ourselves. Card details do not reach us.
Card payment is not taken through our websites. Where your organisation pays us by card, arranged as part of our dealings with it, the payment is taken through the payment facility attached to our accounting system and processed by Stripe, which presents its own terms at the point you pay. Your card details go to Stripe.
7.4 Other Disclosures
Where we are legally required to disclose data, or need to in connection with legal proceedings.
If our business, or substantially all of its assets, is acquired, in which case customer records would be among the assets transferred. We would tell you.
We do not pass your contact details to anyone else for their own marketing. The advertising and analytics services in sections 6 and 7.2 are a different matter, set out there: they receive information about your visit and use it for their own purposes.
8. Sending Data Outside the UK
Most of the personal data this notice covers is stored in the United Kingdom. Our business email, calendars, meeting recordings and files are held in Microsoft 365 in Microsoft’s United Kingdom datacentres, and our customer relationship management system is a Salesforce instance hosted in the United Kingdom. Some of the organisations in section 7 are outside the United Kingdom, mainly in the United States, and Microsoft and Salesforce may access data from outside the United Kingdom to support and operate their services.
Where we transfer your personal data out of the UK, we rely on one of the following:
UK adequacy regulations, where the receiving country has been recognised as providing adequate protection. This covers transfers to a provider’s Irish or other European entity.
The UK Extension to the EU-US Data Privacy Framework, where the receiving organisation is certified under it and has opted into the UK Extension.
The UK Addendum to the EU Standard Contractual Clauses, issued by the Information Commissioner.
Binding Corporate Rules approved by the Information Commissioner, where the receiving group operates them.
Recipient	Route relied on
Salesforce	Hosted in the United Kingdom, so the data is stored here. Salesforce may access it from outside the United Kingdom to support and operate the service, and for that we rely on Salesforce’s UK Processor Binding Corporate Rules approved by the Information Commissioner, the EU Standard Contractual Clauses as modified by the UK Addendum, and the UK Extension to the EU-US Data Privacy Framework for certified Salesforce entities
Pardot (Salesforce Account Engagement)	The same Salesforce safeguards: the UK Processor Binding Corporate Rules approved by the Information Commissioner, the EU Standard Contractual Clauses as modified by the UK Addendum, and the UK Extension to the EU-US Data Privacy Framework for certified Salesforce entities
Cloudflare	The UK Extension to the EU-US Data Privacy Framework, with the UK Addendum as a fallback
Usercentrics (Cookiebot)	The UK adequacy regulations. Usercentrics A/S is established in Denmark and keeps the record of your cookie choice with Microsoft in Ireland, with fail-over to the Netherlands, and a transfer to any of those countries is covered by those regulations. Usercentrics acts as our processor. The banner is delivered, and your location worked out, through Akamai Technologies, Inc. in the United States, one of Usercentrics’ sub-processors, and for that transfer we rely on the UK Extension to the EU-US Data Privacy Framework, under Akamai Technologies, Inc.’s certification, which includes the UK Extension
Google (Tag Manager, Analytics)	UK adequacy regulations for the transfer to Google’s Irish or European entity, then the UK Addendum or Google’s alternative transfer solution for the onward transfer to the United States
Google (Ads, AdSense)	The UK Extension to the EU-US Data Privacy Framework where Google has adopted it, otherwise the UK Addendum applied to controller-to-controller Standard Contractual Clauses
LinkedIn	The UK Addendum applied to controller-to-controller Standard Contractual Clauses, incorporated by LinkedIn’s Independent Controller Addendum
Reddit	The UK Extension to the EU-US Data Privacy Framework, with the Standard Contractual Clauses and the UK Addendum as a fallback
OpenAI	The UK Addendum to the EU Standard Contractual Clauses, Module One (controller to controller), incorporated in OpenAI’s Ad Tools Data Processing Addendum and deemed signed when those terms take effect. We are the exporter and OpenAI OpCo, LLC in San Francisco is the importer, and OpenAI’s terms route United Kingdom data to that entity whichever OpenAI company we contract with
Microsoft (Microsoft 365)	Stored at rest in the United Kingdom. Microsoft’s Product Terms commit it to keeping our email, calendar, Teams and file content in its United Kingdom datacentres. Where any of that data does leave the United Kingdom, for example when Microsoft’s support engineers access it or for a service that carries no residency commitment, the Microsoft Products and Services Data Protection Addendum applies the EU Standard Contractual Clauses as modified by the UK Addendum issued by the Information Commissioner. Microsoft acts as our processor for these services, a different role from the one it plays for the session replay described in section 7.2
Microsoft (Clarity)	The UK Extension to the EU-US Data Privacy Framework, under Microsoft Corporation’s certification, which is active, includes the UK Extension and covers non-HR data. Microsoft acts as an independent controller of what Clarity collects
Automattic (WordPress.com)	The UK Addendum to the EU Standard Contractual Clauses (Decision (EU) 2021/914), incorporated in the executed WordPress.com Data Processing Agreement, one account-level agreement covering both provenworks.com and impowr.io. The counterparty for a UK customer is Aut O’Mattic A8C Ireland Ltd, covered by the UK adequacy regulations, and onward transfers to the United States affiliates are under the incorporated clauses
Breathe HR	The UK adequacy regulations. Breathe stores the data for its service in the United Kingdom and in France, and a transfer to France is covered by those regulations. Breathe’s licence terms bar it from transferring our data outside the European Economic Area
Calendly	The UK Extension to the EU-US Data Privacy Framework, under Calendly’s certification, which its Data Processing Addendum names as the route for transfers from the United Kingdom to the United States, where Calendly is located and the data is held. If the Framework ceases to be available, the same addendum switches the transfer to the EU Standard Contractual Clauses (processor module) with the UK Addendum. Calendly acts as our processor
Xero	The UK Addendum to the Standard Contractual Clauses, which Xero’s processing addendum incorporates automatically on subscription rather than by separate signature. Xero acts as our processor. Card payment runs through Xero’s own invoicing, and so through a payment provider Xero appoints, which the same addendum covers
YouTube (Google)	The UK Extension to the EU-US Data Privacy Framework, under Google LLC’s certification, which is active, includes the UK Extension and covers non-HR data. Google LLC is the Google entity providing Google services, including YouTube, to users in the United Kingdom, and acts as an independent controller of what the embed collects. No data reaches Google unless you choose to load a video: the player is held behind a placeholder until you select it and accept marketing cookies
You can ask us for a copy of the safeguards that apply to a particular transfer by emailing legal@provenworks.com.
9. How Long We Keep It
Where a period is set by one of the providers in section 7 rather than by us, the table says so.
What	How long we keep it
Customer contracts and licensing records	Up to 7 years after the contract expires or is terminated. We keep them for at least 6 years, for potential contract claims under the Limitation Act 1980, and delete them in the seventh year
Invoices, accounting and tax records	Up to 7 years. We keep them for at least 6 years, as required for VAT and company accounts, and delete them in the seventh year
Marketing consent records	While the consent is active, and up to 4 years afterwards, as proof that it was given. The proof is kept for at least 3 years after the consent ends and deleted in the fourth year
Enquiries and marketing contact data	If your organisation becomes a customer, the duration of that relationship and then up to 7 years, the same clock as customer contracts above: at least 6 years, deleted in the seventh. If it does not, 6 years from the last time we heard from you, including any engagement with our marketing
The booking record you create on one of our booking pages (Calendly)	The same period as enquiries above
Call recordings (the audio and video file)	Deleted automatically about 4 months after the call. Where a recording is deliberately kept, 6 years from the date of the call at the most, the same ceiling as transcripts below
Call transcripts	6 years from the date of the call at the most, and sooner if your contact record is deleted first
Meeting recap and action items produced by the meeting platform	5 years, the platform’s configured retention for this content, after which the platform deletes it. This is a separate store from the recording and the transcript above, and it has its own clock
The score and grade on your contact record	These are not kept as a separate record with their own clock. They are values on your contact record that rise and fall with your activity, so they last as long as that record does and reduce on their own if you stop interacting with us
The record of your cookie choice on provenworks.com or impowr.io, kept by our consent banner provider (Cookiebot, section 6.1), which holds the choice you made, when you made it, the site you made it on, a reference number for the record, information about your browser, and your IP address or part of it	12 months, after which Usercentrics deletes it and keeps only aggregated, anonymised statistics. It is deleted at once, before then, if we close our Cookiebot account. This is Usercentrics’ period, and we cannot require Usercentrics to change it. We keep no copy of our own
Session replay data (Microsoft Clarity)	Session recordings are kept for 30 days, and the aggregated click and heatmap data derived from them for 9 months, after which Microsoft deletes them including from backups. These are Microsoft’s periods and we cannot shorten them
The IP address and device information our providers receive to serve you a page (section 6)	We keep no copy of our own. How long the provider keeps it is set by that provider under the plan we are on, and we have no means to shorten it
Website analytics data (Google Analytics 4)	Event-level data is retained for 2 months and user-level data for 14 months, as configured in the tool, after which Google deletes it. Aggregated reporting derived from it is not personal data
If you never become a customer, the six years run from the last time we heard from you: any reply, any enquiry, or any engagement with our marketing, such as opening an email or selecting a link in it.
10. Marketing and Your Right to Object
You have an absolute right to object to direct marketing. If you tell us to stop sending you marketing, we stop. We do not weigh that request against our own interests, we do not ask you to justify it, and there is no exception to it. This right comes from UK GDPR Article 21(2) and (3), and it is separate from, and stronger than, the general right to object described in section 11.5.
It covers the scoring too. Article 21(2) extends to profiling to the extent that it relates to direct marketing, so objecting stops the score and grade described in section 5 as well as the emails. You do not have to object to them separately.
How to stop marketing email. Email legal@provenworks.com and we stop.
11. Your Rights
You have the following rights over your personal data. To use any of them, email legal@provenworks.com or write to the postal address in section 1.
11.1 Access
You can ask for confirmation of whether we process your personal data, for a copy of it, and for the supplementary information about that processing. You are entitled to what we can provide on the basis of a reasonable and proportionate search.
11.2 Rectification
If what we hold about you is inaccurate or incomplete, you can ask us to correct or complete it.
11.3 Erasure
You can ask us to delete your personal data where:
we no longer need it for the purpose we collected it for
you withdraw the consent we relied on, and there is no other basis for keeping it
you object to processing based on legitimate interests and we have no overriding grounds
you object to direct marketing
we have processed it unlawfully
we have to delete it to comply with a legal obligation
There is one further statutory ground, for personal data collected from a child in connection with online services offered to children. We do not offer our services to children, so it does not arise.
This right is not absolute. We may keep data where we still need it for the right of freedom of expression and information, to comply with a legal obligation, or to establish, exercise or defend legal claims, as set out in UK GDPR Article 17(3).
11.4 Restriction
You can ask us to pause our use of your personal data where:
you have told us it is inaccurate, while we check
our processing is unlawful but you would rather we restricted it than deleted it
we no longer need it, but you need us to keep it for a legal claim of your own
you have objected under section 11.5, while we consider that objection
11.5 Objection
You can object, on grounds relating to your particular situation, to processing we base on legitimate interests. We will stop unless we can show compelling legitimate grounds that override your rights. For direct marketing the right is absolute, needs no reasons, and section 10 applies instead.
11.6 Portability
Where we process data you gave us by automated means, on the basis of consent or a contract, you can ask us to give it to you, or send it to another controller, in a structured, commonly used and machine-readable format.
11.7 Withdrawing Consent
Where we rely on your consent, you can withdraw it at any time. Withdrawing it does not make our earlier use of the data unlawful.
11.8 How Long We Take, and What It Costs
We respond within one month of receiving your request. If your request is complex, or you have made several, we may extend that by up to two further months, and we will tell you within the first month that we are doing so and why.
Where you have asked for access to your data and we reasonably need more information to identify what you are asking about, we will ask you for it, and the time between our asking and your replying does not count towards the month.
There is no fee. If a request is manifestly unfounded or excessive, we may charge a reasonable fee or refuse it. If we refuse, we will tell you why, and tell you that you can complain to us (section 12), complain to the Information Commissioner, and seek a remedy through the courts.
11.9 If There Is a Data Breach
If a personal data breach is likely to result in a high risk to your rights and freedoms, we will tell you without undue delay, and describe what happened and what you can do about it. Not every breach meets that threshold.
12. How to Complain to Us
If you are unhappy with how we have handled your personal data, you can complain to us directly. This is a right under section 164A of the Data Protection Act 2018.
We will:
acknowledge your complaint within 30 days of receiving it
take appropriate steps to respond to it
tell you the outcome
You do not have to complain to us before going to the Information Commissioner. You can do either, or both, in any order.
You can complain to us at legal@provenworks.com, or by post to the Data Protection Officer at the address in section 1. We have a complaint form, and we will send it to you on request either in a format you can complete on a computer or printed so you can fill it in by hand. You do not have to use it: a letter or an email telling us what is wrong is enough.
13. How to Complain to the Information Commissioner
You have the right to complain to the Information Commissioner’s Office, the UK supervisory authority for data protection. You can do this at any time. It does not depend on you having complained to us first, and it does not depend on our having responded to you in any particular way.
Online: https://ico.org.uk/make-a-complaint/
Telephone: 0303 123 1113
Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
14. Security
We take appropriate technical and organisational measures to protect personal data.
Data in transit is encrypted using TLS 1.2 or above.
ProvenWorks holds Cyber Essentials Plus certification, covering the whole organisation.
Access to personal data is restricted to those who need it for their role.
We may ask you to verify your identity before we disclose personal data to you.
Please remember that email and other messages sent over the internet are not secure unless they have been encrypted, and that they may pass through several countries before reaching us. That is how the internet works, and it is outside our control.
15. Other Things You Should Know
15.1 Changes to This Notice
We may change this notice. When we do, we will publish the updated version on our websites, and the version and date at the end of this notice will change.
15.2 Information About Organisations
Data protection law protects information about people, not about companies and other organisations. This notice is about personal data. Information that identifies only an organisation is not covered by it.
Business contact details of a named person, such as your name, job title and work email address at your employer, are personal data and are covered by this notice.
We market to named people at organisations, in their work capacity, and not to individuals in a personal capacity. Whichever capacity you are in, your absolute right to object to marketing under section 10 is the same.
15.3 Getting a Copy of This Notice
You can ask us for a copy by emailing legal@provenworks.com or writing to the address in section 1.
Version 2.0. Published 24 September 2026.