Privacy Policy & UK GDPR Notice

Designated Data Controller

ASAD ECHO LIMITED acts as the Data Controller responsible for personal data processed through our website (asadecho.ltd), client portal, customer support, and commercial communications.

• Registered Office: Office 7578 58 Peregrine Road Hainault Ilford, London, Essex, United Kingdom, IG6 3SZ

• Data Protection Officer: info@asadecho.ltd

• Direct Telephone: +447477215384

 

1. Categories of Information Collected

In our capacity as a website and software development agency, we collect and process information strictly necessary for commercial engagement and technical execution:

  • Direct Contact Information: Name, professional email address, phone number, company name, and job title provided when requesting technical consultations.
  • Project Specifications: Technical requirements, architectural briefs, code repository URLs, and system access credentials provided under NDA.
  • Billing & Transactional Records: Invoicing address, VAT/tax identifiers, payment confirmation tokens, and BACS bank transfer references. (We do not store raw credit card numbers; payment processing is handled by PCI-DSS compliant gateways).
  • Technical & Telemetry Data: IP address, browser type, operating system version, time stamps, and server logs collected strictly for security auditing and DDoS mitigation.

2. Legal Grounds for Processing

Under Article 6 of the UK GDPR, we process personal and commercial data under the following legal bases:

  • Performance of Contract: Executing engineering scopes, milestone deliverables, software deployments, and invoicing.
  • Legitimate Interests : Protecting platform infrastructure against malicious requests, fraud prevention, and enhancing service quality.
  • Statutory Compliance : Complying with UK statutory financial reporting, HMRC audit mandates, and Companies House corporate filings.
  • Informed Consent : Optional telemetry, subscription to technical architecture updates, and cookie preferences.

3. Data Security & Storage Architecture

We implement defense-in-depth security measures to protect client assets and communications:

  • End-to-end TLS 1.3 encryption for all web communications and API endpoints.
  • AES-256 encryption for data at rest, encrypted cloud database backups, and hardware-secured SSH keys.
  • Strict role-based access control (RBAC) limiting client source repositories and specifications to verified engineers under non-disclosure agreements.
  • Primary data centers located within the United Kingdom and EEA with ISO 27001 and SOC 2 Type II certifications.

4. Your Statutory UK GDPR Rights

As a data subject in the United Kingdom, you possess clear statutory rights regarding your personal records:

  • Right of Access: Request a complete copy of all personal records we hold about you.
  • Right to Rectification: Request prompt correction of inaccurate or incomplete records.
  • Right to Erasure (“Right to be Forgotten”): Request deletion of your data where no overriding statutory or contractual obligation exists.
  • Right to Data Portability: Receive your data in a structured, commonly used machine-readable format.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk.

Contact Our Privacy Officer

To exercise any statutory data subject rights or submit privacy-related questions: