Legal
Privacy Policy
Last updated: 12 August 2026 · Version 1.0
This policy explains what personal data Algosoup Ltd collects, why we collect it, who we share it with, and what you can ask us to do about it. It covers two different situations: this website and our business contacts, where we decide how data is used; and client engagements, where we handle data on a client's behalf and under their instructions.
Who we are
Algosoup Ltd is a forward-deployed engineering company registered in England and Wales, company number 17111484. Our registered office is 13 St. Ronans Avenue, Bristol, BS6 6EP, United Kingdom.
For anything in this policy, whether a question, a request about your data or a suspected security incident, contact security@algosoup.ai. It is monitored by the company's directors, who own data protection and information security at Algosoup.
For personal data we handle on this website and in our own business dealings, Algosoup Ltd is the data controller under UK GDPR.
The two capacities we act in
Almost every question about how we handle personal data depends on which of these two situations applies.
Controller: this website and our business contacts
We decide what is collected and why. This covers enquiries sent through the site, calls booked with us, job applications, and the contact details of people at client and prospective client organisations. Sections 3 to 5 describe this in detail.
Processor: client engagements
We build and run software inside our clients' businesses, including e-commerce and order-management integrations, for example syncing TikTok Shop orders into a client's systems. In that work we process end-customer personal data, such as buyer names, delivery addresses, contact details and order contents, strictly on the documented instructions of the client, who is the controller. Section 6 describes this in detail.
What this website collects
We have kept this list specific rather than generic. It describes what the site actually loads and stores, verified against the running site.
Enquiry form
The contact form collects your name, email address, company and message. It is delivered to our team by email and used only to reply to you and to carry on the conversation you started.
Booking a call
The booking calendar is a Cal.com booker embedded from cal.eu. What you enter into it (your name, email address, chosen time and any answers you give) is collected by Cal.com and passed to us as a booking. If you accepted analytics cookies, we also pass the booker a short record of how your visit began (referral source, the page you landed on, and which pages you viewed) so we can tell which channel an enquiry came from.
Analytics
We use Google Analytics 4 to understand how the site is used: which pages are read, which referrer or search brought you here, broad device and browser information, and approximate location at country or region level, derived by Google from your IP address. Its script is not loaded at all until you accept, so nothing reaches Google before then. Once accepted it sets the cookies listed in section 4.
Attribution stored in your browser
We store two small records in your browser's own storage, not in cookies: as_visit (for the current session) and as_first_touch (kept between visits). They hold the referral source and medium, the page you landed on, the pages you have viewed, the date of your first visit and how many times you have visited. They are only written if you accept, and they stay in your browser, reaching us only if you go on to book a call.
Job applications
Application forms on our role pages are embedded from Tally. Whatever you submit through them goes to Tally and to us, and is used to assess your application.
Hosting and request logs
Our host, Vercel, logs requests to the site (IP address, user agent, URL and timestamp), which we use to deliver the site, keep it secure and diagnose faults.
Fonts and embedded assets
Typefaces load from Google Fonts, and the booking calendar and homepage graphics load assets from Cal.com's avatar service, Spline and unpkg. Requests to those providers expose your IP address to them. We did not observe any of them setting cookies, apart from the Cal.com and Cloudflare cookies noted in section 4.
What we do not do: we run no advertising or retargeting pixels, we do not sell or share personal data for advertising, we do not use your data for automated decisions that have a legal or similarly significant effect, and we do not ask for special category data.
Why we process it, and on what basis
Under UK GDPR we rely on the following lawful bases, and we collect only what the purpose actually requires.
Contract, and steps taken before entering one
Replying to your enquiry, holding a call you booked, agreeing scope, and delivering an engagement we have been contracted for.
Consent
Analytics and the attribution records described in section 3. We do not store either until you choose to allow it, and you can withdraw that at any time using the Cookies link in the footer.
Legitimate interests
Running and securing this website, keeping records of our business contacts, and assessing job applications. We have weighed these against your interests and rights, and limited the processing to what those purposes need. You can object to processing based on legitimate interests, as described in section 11.
Legal obligation
Keeping the accounting and tax records we are required by law to keep.
For personal data we process on a client's behalf, the lawful basis is the client's to establish as controller. We act on their instructions.
Client engagements
When we build and operate software for a client, we act as a processor. This is the capacity in which we handle e-commerce and order-management data, including integrations with platforms such as TikTok Shop, where we process end-customer order and buyer data on the client's behalf.
- We process personal data only on the client's documented instructions and only for the purpose we were contracted for. We do not decide the purposes of that processing.
- We do not sell personal data, and we never use client or end-customer data for our own purposes or for anything unrelated to the engagement.
- Integrations request only the API scopes and fields the contracted purpose requires. Where a platform masks personal data before it reaches us, we preserve that masking rather than work around it.
- Personal data is retained only for as long as the engagement requires, and is deleted or returned at the end of the engagement or on request.
- Sub-processors and any international transfers are identified per engagement, and client data is kept separate from other clients' data.
- We assist our clients, and the platforms they sell on, in responding to requests from individuals and to security incidents, as described in sections 11 and 12.
Where data is stored
Our processing is UK-primary, with some processing in the United States. Systems we build and run for clients use compute pinned to London and managed PostgreSQL hosted in the United Kingdom. Bookings and job applications stay within the European Union.
This website itself is hosted by Vercel and delivered from its global edge network, and the providers named in section 7 as United States are exactly that: Google Analytics, Google Fonts, Google Workspace and our email delivery provider process data in the US.
Where personal data is transferred outside the UK, we rely on the UK's adequacy regulations, or on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with the safeguards those require.
How we protect it
Our full approach is set out in our internal Information Security Policy, adopted 11 August 2026 and reviewed at least annually. In summary:
- All data in transit is encrypted with TLS 1.2 or higher, including API, webhook and database connections.
- Data at rest is encrypted by our managed platform providers.
- Access follows least privilege: people get only the access their role requires, it is reviewed when roles change, and it is revoked on offboarding.
- Multi-factor authentication is required on all critical services, including source control, hosting, databases and partner platforms. Accounts are individual and shared credentials are prohibited.
- Credentials and API keys are never committed to source control, and are rotated on personnel change or any suspicion of exposure.
- We operate no self-hosted servers and no internal corporate network. Production workloads run on managed cloud platforms certified to SOC 2 or ISO 27001, with production, preview and development environments kept separate.
- Work devices use full-disk encryption, automatic screen lock and current security updates. Client data is not stored on removable media.
- Code changes are reviewed before reaching production, and dependency vulnerability alerts are triaged on receipt.
How long we keep it
- Enquiries and booking records: kept for as long as we are in conversation with you, and for up to two years afterwards so we have context if you come back to us.
- Business contact records: kept while the relationship is live, and reviewed periodically after that.
- Job applications: kept for up to twelve months after a decision, unless you ask us to delete them sooner.
- Client and end-customer personal data: kept only for the duration the engagement requires, then deleted or returned at the end of the engagement or on request.
- Analytics: retained in Google Analytics under the retention period configured on our property, after which only aggregate reporting remains.
- Accounting records: kept for the period UK law requires.
Your rights
Under UK GDPR you have the right to request access to the personal data we hold about you, to have inaccurate data rectified, to have data erased, to restrict how we process it, to receive it in a portable form, and to object to processing we carry out on the basis of legitimate interests. Where processing relies on consent, you can withdraw it at any time.
Exercise any of these by emailing security@algosoup.ai. We will respond within one month. We do not charge for this, and we will not treat you differently for asking.
Where the data is one we process on a client's behalf, the client is the controller and the request is theirs to decide. In that case we will pass your request to them promptly and assist them in answering it. We assist our clients and the platforms they sell on, including TikTok Shop, with requests for access, rectification and deletion, without undue delay.
If you are unhappy with how we have handled your personal data, you can complain to the Information Commissioner's Office at ico.org.uk, or by calling their helpline on 0303 123 1113. We would appreciate the chance to address it first.
Breach notification
If a personal data breach occurs, we contain it, assess the scope and the data affected, and notify the affected clients and platforms without undue delay. Where the breach is reportable, we notify the Information Commissioner's Office within 72 hours of becoming aware of it, and we inform affected individuals where the law requires. Every incident is followed by a review that records what happened and the corrective actions taken.
Report a suspected security incident to security@algosoup.ai.
Changes to this policy
We review this policy at least annually, and whenever there is a material change to how we handle personal data or after any security incident. When we change it, we update the date at the top of the page. Material changes will be made clear on this page rather than buried in it.
Questions about this policy, or about anything in it, go to security@algosoup.ai.

