1. Identity of the controller
ASHLAR TECHNOLOGIES LTD is a company operating from 22 William Street, Blackwood, Wales, NP12 1NW, United Kingdom. For personal data processed through https://ashlartechnologies.ink and through ordinary commercial correspondence, ASHLAR TECHNOLOGIES LTD is the data controller. You may write to the same address, telephone +44 7411 527577, or send a message to commercial@ashlartechnologies.ink. This Privacy Policy explains how we collect, use, store, share and delete personal data when you visit our website, request CCTV app development or related digital surveillance services, or otherwise deal with us as a business contact in England and Wales.
We develop software. We are not, by default, the operator of your cameras, the employer of your guards, or the occupier of your sites. Where a client instructs us to host, process or view live video, recorded footage, access-control events or analytics alerts, the allocation of controller and processor roles is set in the relevant contract and, where required, in a data processing schedule. This policy does not replace that contract. It describes our own website and business-contact processing and the principles we apply when we handle personal data in the United Kingdom.
If you are an individual whose image appears on a client’s CCTV estate, you should ordinarily contact the organisation that operates those cameras. We will assist a client in responding to a valid rights request that touches software we maintain, but we will not disclose another organisation’s footage merely because a request arrived at our Blackwood address.
2. Law that applies
We process personal data in accordance with the United Kingdom General Data Protection Regulation as it forms part of UK law, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 as amended, and guidance published by the Information Commissioner’s Office. Because our operating address is in Wales, we also pay attention to the practical expectations of Welsh public and private bodies that procure security software, including duties around transparency, fairness and security of monitoring systems.
Where a project involves a public-space surveillance system, we expect clients to consider the Surveillance Camera Code of Practice issued under the Protection of Freedoms Act 2012. We are a software house. We do not replace a client’s obligation to complete data protection impact assessments, to display signage, to set retention, or to appoint a data protection officer where the law requires one. We will, if contracted to do so, design software features that make those obligations easier to perform, such as role-based access, audit logs and retention controls.
Nothing in this policy creates rights beyond those granted by statute, or reduces rights that statute already gives you. If a later statute or a binding decision of a UK court changes the meaning of a term used here, that later meaning prevails. If you are outside the United Kingdom, local rules may also apply to you, but our primary compliance frame remains UK law.
3. Categories of people we deal with
We typically process data about website visitors, people who send a batch request through our contact form, email correspondents, telephone callers, suppliers, subcontractors, recruitment candidates, and staff of organisations that buy or consider buying CCTV app development, a video security platform, surveillance mobile software, live video monitoring products, remote security management, video analytics software, an access control application, or a security operations platform.
We do not seek special category data through the public website. We do not ask the public form to collect criminal offence data. If a commercial discussion later requires limited sharing of incident examples, we prefer anonymised or synthetic samples. If a client insists on sharing real footage for discovery, that transfer is a client-controlled disclosure and must be lawful at the client’s end before it reaches our line in Blackwood.
Children are not our audience. Our services are business-to-business. We do not knowingly collect data from anyone under sixteen through {SITE}. If you believe a child has submitted a form, write to {MAIL} and we will delete the record unless a legal duty requires us to keep a short note of the incident.
4. Data collected through the website
When you load pages on {SITE} your browser will typically transmit a technical set of facts: IP address, approximate location derived from that address at a coarse level, browser type, device type, language, referring URL, pages viewed, date and time, and error codes. These facts exist because the internet works that way. We use them to keep the site available, to diagnose faults, to understand which service flavours are read, and to protect the site from abuse.
If you complete the batch request label we collect your name, email address and the message you type. You control the message. Do not paste passwords, badge numbers, live credentials, or footage of identifiable people into that box. We asked for a description of sticky operational input, not a dump of an estate’s secrets. If you paste such material anyway, we will treat it as confidential commercial correspondence and delete it when it is no longer needed for the enquiry, unless we must keep it to deal with a security incident you created.
We do not require an account to read this website. We do not run a public customer portal on {SITE}. Payment card data is not collected on this site. If a later contract requires payment, that will occur through a method named in the invoice or in the relevant terms, not through a hidden field in the public form.
5. Cookies, similar technologies and this policy’s boundary
Short technical cookies or local storage items may be used to keep the site stable, to remember that a menu was opened, or to measure coarse traffic. The detail lives in our Cookie Policy, which you should read as a companion document. We do not use this Privacy Policy to hide a shopper-profile advertising network. We are a CCTV software company, not a retail media company.
Where a cookie is strictly necessary for the service you requested, we rely on that necessity. Where a cookie is not strictly necessary, we will not set it until the law and our Cookie Policy say we may. You can control cookies through your browser. Blocking some cookies may make the site less convenient; it will not stop you from sending a plain email to {MAIL}.
6. Email, telephone and postal correspondence
If you write to commercial@ashlartechnologies.ink we will process the content of your email, your address, any attachments, and our reply. If you telephone +44 7411 527577 we may keep a short note of the call: who called, when, and what was asked. We do not record all calls as a matter of course. If a particular call is recorded, we will say so at the time or in a project protocol.
Post sent to 22 William Street, Blackwood, Wales, NP12 1NW is opened as business mail. We do not operate a public drop-box for USB drives of footage. Do not post storage media containing personal data unless a contract says we will accept it and names the chain of custody. Unsolicited media may be refused, returned or securely destroyed.
Business cards and meeting notes are treated as ordinary B2B contact data. We use them to continue a commercial conversation you started, to send a flavour map, or to perform a contract. We do not sell lists of contacts.
7. Purposes and lawful bases
We process website logs to pursue the legitimate interests of operating, securing and improving {SITE}, balancing those interests against your right to browse with as little friction as the medium allows. We process contact-form data to take steps at your request before entering a contract, or to pursue the legitimate interest of answering a business enquiry that is not yet a contract. We process supplier and subcontractor data to perform contracts and to meet legal duties such as tax and accounting.
We process client-project personal data, where we are a processor, on documented instructions and on the lawful basis that sits with the client as controller. Where we are a joint or independent controller for a narrow purpose, for example our own billing, our own security logs of our own systems, or our own recruitment, we will say so in the relevant notice or contract.
We may process data to comply with a legal obligation, including bookkeeping, responding to a binding request from a competent UK authority, or establishing, exercising or defending legal claims. We do not rely on consent for ordinary B2B email about a live enquiry you opened. If we ever send optional electronic marketing to individuals who are not existing clients, we will do so only as PECR allows, which in practice means consent or the soft opt-in where those rules fit.
8. Legitimate interests in more detail
Our legitimate interests include running a software business in Wales, keeping our network safe, proving what was agreed, improving the clarity of our service flavours, preventing fraud, and defending the company if a dispute appears. We do not treat legitimate interests as a blank cheque. We ask whether the processing is necessary, whether a less intrusive method exists, and whether a person would reasonably expect a CCTV software house to do what we are doing.
We do not use legitimate interests to justify selling personal data, to justify scraping social profiles of guards, or to justify training a public model on a client’s footage. Those activities are outside our commercial bite. If a future product involved a new intrusive method, we would complete an assessment and, where required, consult before we switched it on.
9. Recipients and processors
We share personal data with people who need it to do their job inside {CO}. We share data with professional advisers such as accountants or solicitors who are themselves bound to confidence. We may share data with hosting, email, domain, error-logging or office-productivity providers that process data on our instructions. We choose providers that can offer an appropriate UK or adequate-protection arrangement.
We may share data with a subcontractor who writes or tests software under a written agreement. We do not casually forward a client estate map to a freelancer’s personal mailbox. If a competent court, regulator or law-enforcement body in the United Kingdom requires disclosure, we will disclose what the law requires and no more, unless a right to challenge that demand is properly exercised.
We do not sell personal data. We do not trade enquiry lists. If the company is sold or merged, contact data may move with the business under appropriate safeguards, and we would expect the successor to honour this policy or to issue a fresh notice.
10. International transfers
Our operating centre is in the United Kingdom. Some tools used to run a modern software practice may store copies in other countries. Where a transfer of personal data leaves the UK, we will use a lawful mechanism: an adequacy regulation, the UK International Data Transfer Agreement or Addendum, or another tool recognised by UK law at the time of the transfer.
We will not send identifiable CCTV footage to a public generative service as a casual convenience. If a project requires a transfer of monitoring data, that transfer will be designed, named and, where needed, assessed. Clients who forbid extra-UK processing can say so in the contract. We will then tell you whether the chosen flavour can still set.
11. Retention
Website logs are kept for a short operational window unless an incident requires a longer look. Contact-form enquiries that do not become a contract are typically kept for up to twenty-four months so we can understand repeat approaches and defend the company against a later complaint about what was said. Enquiries that become a contract follow the retention of the contract file, which is usually the life of the engagement plus a period of six years to match ordinary limitation thinking in England and Wales, unless a longer statutory period applies.
Invoices, tax records and company books are kept as company and tax law require. Recruitment records for unsuccessful candidates are kept only as long as needed to complete the process and to deal with a possible complaint, then deleted or reduced to an anonymous statistic. Client footage used in a discovery exercise is kept only for that exercise unless the contract says we must host it as part of a wrapped product.
When a retention period ends we delete or irreversibly anonymise. Backups expire on their own cycle. Residual copies in email archives are reduced when we next have a lawful opportunity to clean them, unless a hold for legal claims is in place.
12. Security
We use organisational and technical measures that are appropriate to a small United Kingdom software company handling commercial contact data and, under contract, security-software artefacts. Measures include access control, unique credentials, encrypted transport to {SITE}, least-privilege administration, and a refusal to treat production footage as a casual attachment culture.
No method is perfect. The internet remains a hostile network. You should not send highly sensitive credentials through the public form. If you discover a vulnerability on {SITE}, write to {MAIL} with enough detail to reproduce it and without exploiting it beyond what is needed to demonstrate the fault. We will treat good-faith reports as assistance, not as a free invitation to ransack the line.
Staff and contractors who can see personal data are bound by confidentiality. Devices used for work are expected to be locked, patched and free of shared family logins. That is a cultural rule as much as a technical one. A glossy wrapped product still fails if the laptop in a café is left open on a live admin session.
13. Your rights
UK law gives you, in the circumstances the statute describes, rights to be informed, to access, to rectification, to erasure, to restrict processing, to object to processing based on legitimate interests or to direct marketing, and to data portability for data you provided where processing is based on consent or contract and is carried out by automated means. You may also have rights in relation to automated decision-making that produces legal or similarly significant effects. We do not make such public-website decisions about you.
To exercise a right, write to {MAIL} or to {ADDR} with enough information for us to find you in our files and to confirm that we are speaking to the right person. We may ask for additional information to prevent disclosure to the wrong person. We will respond within one month, with the extensions the law allows for complex or numerous requests. There is no fee unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse as the statute permits.
If we are processing as a processor for a client, we will direct you to the client where that is the proper route, and we will support the client as the contract requires. Do not assume that a request sent to a software house automatically unlocks another organisation’s camera archive.
14. Complaints
We would like the chance to wrap a mistake before it hardens. Write to commercial@ashlartechnologies.ink first. If you remain unsatisfied you may complain to the Information Commissioner’s Office, the UK supervisory authority. The ICO publishes current contact methods on its own site. You may also seek a remedy in the courts of England and Wales where the law allows.
A complaint about a client’s camera system should usually go to that client and, if needed, to the ICO naming that client as controller. Naming {CO} as controller when we only wrote software will delay everyone.
15. CCTV, analytics and access-control software we build
Our products may display live video, recorded video, analytic events, maps of sites, and access-control decisions. Those displays contain personal data when a person can be identified. The purpose, the signage, the retention, the sharing with police, and the monitoring of workers are decisions for the operator of the system, not for a generic page on {SITE}.
When we design video analytics software we treat event names as flavour codes that must be understandable. We do not hide a biometric classification behind a cute label. If a feature could constitute biometric processing or another high-risk method, we will say so in the project and we will expect a data protection impact assessment before that feature is switched on in a live estate.
Remote security management and live video monitoring products can create a temptation to watch people more than a task requires. We design role-based views so that a commercial bite does not become a fishing expedition. Clients remain responsible for how their staff use the product, including misuse, curiosity viewing, and retention beyond the named period.
16. Recruitment and suppliers
If you apply to work with us we will process the information you send, notes of interviews, and right-to-work checks as employment and immigration law require. We will not keep unsuccessful applications indefinitely. If we use a recruitment platform, that platform’s notice will also apply to the portion it controls.
Suppliers should send only the personal data needed to contract and to pay. We do not need copies of every employee passport to pay an invoice for a design day.
17. Automated processing
The public website does not profile you to decide your credit, your employment, or your access to a vital service. Form validation checks whether a field looks like an email address. That is not a significant automated decision. Inside products we build, analytics may classify events. Those classifications are tools for a client’s operators. Their legal character depends on how the client uses them, including whether a human reviews an outcome that affects a person in a significant way.
18. Third-party sites and maps
Pages may embed a map of {ADDR}. The map provider is a separate controller for the data it collects when the embed loads. If you do not want that, do not load the contact page, or use browser tools that block third-party content, and write to us instead. Links to other sites are not covered by this policy. Read their notices.
19. Changes
We will update this policy when our processing, our tools, or the law changes. The updated text will appear on this page with a revised date. Material changes that affect people we already hold will be communicated in a manner proportionate to the change, for example a note in a client bulletin or a line on {SITE}. Continued use of the website after an update constitutes awareness of the new text for website processing. Contracts are varied only as those contracts allow.
20. Company records, accounts and legal claims
Company law and tax law require us to keep certain records. Those records may include names of directors’ contacts, payment references and correspondence that proves a supply. We keep them because the law says we must, and because we may need to establish or defend a claim. This basis sits beside, and sometimes outlasts, the original commercial conversation.
If a dispute begins, we will place a hold on deletion of the file that is in play. That hold is not a punishment. It is how a software house in Wales stays able to tell a court what actually happened on the belt.
21. Accuracy and your duties
Please give us accurate contact details. If you write from a shared inbox, tell us who should receive the flavour map. If you are not authorised to instruct a CCTV project for your employer, do not pretend that you are. We rely on the person in the form being a proper commercial contact.
You should not use our form to harass, to dump malware, or to send unlawful images. We may keep limited data about abuse so we can protect the line and, if needed, report a crime.
22. Special category and criminal offence data
We do not invite special category data through {SITE}. Footage of a person’s health, trade-union activity, or similar categories can appear inside a live camera scene without anyone intending it. That is a property of cameras, not a product feature we advertise. Clients must set policies for incidental capture. We will help design software controls if that is in the batch.
Criminal offence data, including allegations, can appear in incident clips. Handling that class of data is tightly regulated in the UK. We will not accept a casual transfer of offence files to a public mailbox. If a project requires it, the contract and the client’s lawful basis must be explicit before the first clip is copied.
23. Data protection by design in our delivery method
Our melt-mix-shape-set-wrap-ship method includes asking which personal data a flavour actually needs. A live video monitoring bite may need live tiles and a short clip share. It may not need a permanent face gallery. We push back when a brief asks for collection that cannot be justified. That push-back is part of commercial clarity, not a refusal to help.
Audit trails, named roles, and retention switches are treated as wrap-standard ingredients for security operations platforms. If a client disables them after handover, that is the client’s controller choice and the client’s risk.
24. Subprocessors on client work
Where we act as processor we will not appoint a subprocessor that can see client personal data without the contract mechanism the client agreed, whether that is prior written consent or a right to object to a named list. We will impose written terms that flow down the duties that UK law requires to be flowed down. We remain responsible to the client for the subprocessor’s performance of those flowed-down duties as the contract says.
25. Personal data of our own staff visible on the site
Photographs or names of staff, if any appear, are published as business information. Staff may ask us to adjust a public biography. We will not publish home addresses. The company address remains {ADDR}.
26. How to read this policy with other documents
Read this policy with the Cookie Policy, the Terms of Service, the Terms and Conditions, and any statement of work. If a signed contract says we are a processor, that contract’s processing schedule wins over a marketing sentence on the homepage. If this policy and a contract conflict on a point of client-project processing, the contract wins for that project. If they conflict on website browsing, this policy wins for that browsing.
27. Contact for privacy
Privacy enquiries: commercial@ashlartechnologies.ink. Postal: ASHLAR TECHNOLOGIES LTD, 22 William Street, Blackwood, Wales, NP12 1NW. Telephone: +44 7411 527577. Website: https://ashlartechnologies.ink. We are a small line. We still answer. We just refuse to pretend that a software house is the same thing as every camera it ever helped to wrap.
Last updated 17 August 2026. This version applies to processing from that date, and to older records still held, except where a previous notice and a still-running contract say otherwise for a closed batch.
28. Detailed website log examples
A typical log line may show that an address in the United Kingdom requested services.html at a given time using a current browser. We use aggregates of such lines to see whether the flavour batch map is being read. We do not use these lines to guess your salary, your politics, or your movements through Blackwood. We do not attempt to re-identify a visitor from a log line unless we are investigating an attack, a legal demand, or a serious abuse of the form.
If a bot hammers the site, we may block an address range. That is a security action. It is not a judgement about a human’s character. If you are a researcher scanning the site politely, write to {MAIL} so we can tell a block from a visit.
Error logs may contain a fragment of a URL or a form field if a page failed. We try not to log passwords because we do not ask for passwords on the public site. If an error ever captured a sensitive string, we will treat that log as a mini-incident and purge it when the diagnosis ends.
29. Marketing restraint
We may email a person who asked for a flavour map about that map, about scheduling, and about the wrap of the same brief. That is service email. We may email an existing client about a related capability that sits next to software they already bought, where PECR’s existing-customer rules fit and an opt-out is honoured. We do not buy lists of facilities managers. We do not cold-text mobile numbers scraped from the web.
If you opt out of optional marketing, we will keep a suppression note so we do not email you again for that purpose. The note is a small piece of personal data kept for a protective reason. Deleting it would make the opt-out worse, not better.
30. Hosting geography and backups
Whenever we can, we host {SITE} and ordinary mail in the United Kingdom or in a country the UK treats as adequate. Backups are copies. They exist so a disk failure does not melt the batch directory. Backups are protected and aged off. A deletion request that arrives after a backup is taken will be reflected in the live system first and in the backup when that generation expires, unless a legal hold says otherwise.
Clients who need a named region for product hosting must say so in the statement of work. A website privacy policy cannot freeze every future product topology. It can promise that we will not hide a transfer.
31. Training and internal access
People inside {CO} see personal data only if their role requires it. A designer does not need a copy of every invoice. A director may need to see an enquiry that became a dispute. Access is reviewed when roles change. Departing personnel lose access. That sentence is dull on purpose. Dull access control is how sticky data stays wrapped.
32. Incidents
If a personal-data breach occurs that meets the UK thresholds for notifying the ICO or individuals, we will do so in the time and manner the law requires. Where we are a processor, we will notify the client without undue delay after becoming aware, with the facts we have. We will not delay a notice to protect a marketing calendar.
You can help by using unique passwords on your own side, by not forwarding our quotes to public channels, and by telling us if an email that looks like ours asks for a change of bank details. We will never ask you to pay a CCTV project through an instant personal wallet because a syrup-coloured message said the belt would stop.
33. Records of processing
As a controller for our own business data we maintain records that describe purposes, categories, recipients, transfers, retention and security at a level appropriate to a company of our size. As a processor we maintain the records the contract and Article 30 of the UK GDPR require. These records are not public. A regulator may see them. A competitor may not.
34. Data protection impact thinking
We carry out impact thinking when we start a processing that is likely to be high risk. Building a public brochure site is not high risk. Building a live monitoring product that can be used to watch workers all shift may be. In the second case we expect the client’s DPIA to exist, and we will contribute technical facts. We will not sign a sentence that says a product is ‘GDPR compliant’ as if that were a flavour of paint. Compliance is a practice, not a sticker.
35. Joint work with installers
Installers, integrators and guarding firms often sit beside us on a project. Each remains responsible for the personal data it collects. We do not become the installer’s controller because we wrote a mobile view. We do not become the guarding firm’s HR department because a roster appeared in a workshop. Contracts should name the seams. If they do not, we will ask for the seam to be named before the wrap.
36. Language and accessibility of notices
This policy is issued in English because that is the language of our commercial line. If a client needs a Welsh-language summary for their own staff, that can be a wrapped extra. It is not automatically produced by loading {SITE}. We try to write in readable sentences. Legal precision still needs length. Length is not a trick to hide a sale of data. There is no sale of data.
37. Supervisory cooperation
We will cooperate with the ICO as UK law requires, including answering information notices that are properly given. We will not waive legal privilege by accident in a chatty email. We will not obstruct. Those two sentences can live together.
38. End of relationship with a correspondent
If you ask us to stop emailing you about a dead enquiry, we will stop the commercial chase and keep only what we must. If you are a client and the contract is live, stopping marketing does not stop operational mail about the batch. Operational mail is how software is shipped.
39. Photographs on this site
Images on {SITE} are synthetic candy-industrial stills and professional objects. They are not photographs of your staff. They are not evidence. Do not treat a glossy slab as a picture of a real incident. Alt text exists to describe the image for people who cannot see it, and for machines that index the page, not to encode a hidden dossier.
40. Closing statement on purpose limitation
ASHLAR TECHNOLOGIES LTD collects personal data to answer commercial demand for CCTV app development and neighbouring flavours, to run a lawful company at 22 William Street, Blackwood, Wales, NP12 1NW, and to keep https://ashlartechnologies.ink standing. We do not collect it to amuse a model, to rank workers, or to sell a list. If a future purpose appears that you would not reasonably expect, we will tell you and we will find a lawful basis before we pivot. That is the sugar-glass rule: the purpose should be visible in the wrap.
Questions that are not answered here can be sent to commercial@ashlartechnologies.ink. Bring the sticky part. We will wrap a clear answer or we will tell you who else must answer it.
