Privacy Policy
Last updated: 28 July 2026
This notice explains what personal data we collect when you use TIDE, why we collect it, who we share it with, and the rights you have under the UK General Data Protection Regulation (UK GDPR). It is written in plain English. If anything is unclear, contact us at paul@thwaite.me.uk.
1. Who we are
Itarck Ltdis the data controller for personal data processed through TIDE. Itarck Ltd is a company registered in England & Wales (company number 12930155). Registered office: Mansion House, Manchester Road, Altrincham, Cheshire, WA14 4RW.
TIDE — the Transformation Readiness Diagnostic — is the diagnostic product operated by Itarck Ltd under the TIDEOS brand.
For any privacy question or to exercise a right described below, contact paul@thwaite.me.uk. We aim to respond within 30 days.
2. What we collect and why
We only collect the data we need to run the diagnostic, follow up on enquiries, and keep the service secure. The main categories:
Diagnostic data
When you complete a TIDE diagnostic we record the programme name and description you provide, your responses to the facilitated questions, the facilitator's email, and the resulting report. We use this to deliver your diagnostic and to send you your report.
Access codes (vouchers)
If you redeem an access code we record the code and the email address it was redeemed against. This lets us link the diagnostic to your access entitlement and prevent code reuse.
If you request an access code via the "Request access" form, we collect your name, email, organisation, and the reason you're asking. We use this to decide whether to issue a code and to follow up.
Contact-form submissions
If you contact us via the landing-page form we collect your name, email, and any optional details you provide (organisation, role, message, LinkedIn URL). We use this only to reply.
We also record the submission's IP address and user-agent for short-window abuse protection (rate-limiting).
Hosting and platform telemetry
Our hosting provider (Vercel) and database provider (Supabase) process technical request logs as part of operating the infrastructure. These are not used to profile you.
Cookies
TIDE uses a small set of essential cookies needed to run the diagnostic flow. We do not use marketing or advertising cookies. For details, see our Cookie Policy.
3. Why we are allowed to process your data (lawful basis)
Under UK GDPR every use of personal data needs a lawful basis. The ones we rely on:
- Contract — to provide the diagnostic you requested, send your report, and manage your access code. We cannot deliver the diagnostic without processing these details.
- Legitimate interests — to keep TIDE secure (rate-limiting abuse), to improve the service, and to follow up on enquiries from prospective users. We have considered the privacy impact of these uses and limited what we collect accordingly.
- Consent — where we ask for it explicitly (for example, non-essential analytics cookies, if and when we introduce them). You can withdraw consent at any time.
- Legal obligation — to retain limited records where UK law requires it (for example, financial records for tax purposes if you become a paying customer).
4. Who we share your data with
We use a small number of trusted sub-processors to operate TIDE. Each is bound by a written agreement to use your data only on our instructions.
- Supabase — application database and file storage. Hosts the assessment, response, and report records. EU region (Ireland).
- Anthropic — provides the language model that facilitates the diagnostic conversation. Receives the programme context and your responses turn by turn so it can generate the next question. Anthropic does not use this data to train its models.
- Vercel— application hosting and execution. Our application code runs on Vercel’s infrastructure in London, so all requests pass through it. Vercel also provides content delivery for static assets.
- Resend — transactional email delivery (used to notify us of new contact / access-request submissions and to send you operational emails about your diagnostic).
We do not sell your personal data, and we do not share it with advertising networks.
5. International data transfers
Some sub-processors are based outside the UK or process data outside the UK / European Economic Area:
- Anthropic is based in the United States. Diagnostic content sent to Anthropic for facilitation crosses an international border. This transfer is covered by the UK-approved International Data Transfer Addendum (IDTA) to the EU Standard Contractual Clauses, which provide UK-recognised safeguards for personal data leaving the UK.
- Vercel and Resend are US companies whose UK service uses equivalent transfer safeguards.
- Supabase hosts your data in the EU (Ireland). No international transfer occurs for stored diagnostic records.
6. How long we keep your data
We keep personal data only as long as we need it for the purpose we collected it. Retention defaults below — these can change if you ask us to delete sooner (see § 7).
| Data | Retention |
|---|---|
| Diagnostic responses, transcripts, and reports | Duration of the engagement plus 90 days |
| Access codes (issued vouchers and their redemption record) | Indefinitely as an audit log; code becomes inactive after use or expiry |
| Access-code requests | 12 months from submission |
| Contact-form submissions | 12 months from submission |
| Rate-limit logs (IP address, user-agent) | 30 days |
| Financial records (if you become a paying customer) | 6 years from the end of the financial year (UK tax law) |
Marketing records
After this period we keep no record of who the entry related to, only that a basis was asserted and when. If you ask us what we told our marketing platform about you more than 24 months after the event, we will not be able to tell you.
7. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you.
- Correct data that is inaccurate or incomplete.
- Deleteyour data (the "right to be forgotten") where there is no compelling reason for us to keep it.
- Restrict how we use your data while a question or complaint is being resolved.
- Object to our use of your data where we are relying on legitimate interests.
- Portability — receive a copy of the data you gave us in a structured, machine-readable format.
- Withdraw consent at any time where consent is the lawful basis.
To exercise any of these rights, email paul@thwaite.me.ukwith enough information to identify your record (for example, the email address you used when completing a diagnostic). We'll respond within 30 days.
8. Complaints to the ICO
If you're unhappy with how we handle your data and we haven't been able to resolve it directly, you have the right to complain to the UK Information Commissioner's Office (ICO). The ICO is the UK's data protection regulator.
Contact details and the online complaints form are at ico.org.uk/make-a-complaint.
We'd prefer the chance to put things right first — please contact us at paul@thwaite.me.uk before escalating.
9. Changes to this notice
We may update this notice as TIDE changes — for example if we add a new sub-processor or change a retention period. Material changes will be reflected here and the "Last updated" date at the top will move.
The current version is dated 28 July 2026. Historic versions are tracked in our source-control history.