Privacy Policy
Status: Ready for review
Version: 1.1
Effective date: July 2026
Audience: Website visitors, enquirers, customers and authorised Portal users
Simple, clear information about how we handle your data. No jargon, no surprises.
1. Who we are
Tru-Digital Services Limited is a UK digital services and compliance technology company. We build and operate websites, portals, documentation systems, governance tooling and related managed services.
Our services and brands include:
- Tru-Digital Services — our company and digital services website.
- Tru Data Protection — our data protection service for UK schools and multi-academy trusts.
- Portal — our customer-facing portal used to deliver access to evidence, cases, service records, outputs, policy materials, support information and collaboration workspaces.
- Derrick — our AI/support and platform assistant brand.
This Privacy Policy applies when you use our websites, contact forms, Portal, services or related managed services.
Our details:
Company No.: 16210598
ICO Registration: ZB887707
Address: 3rd Floor, 86-90 Paul Street, London, EC2A 4NE
Data protection email: dpo@trudigital.co.uk
2. What this policy covers
This Privacy Policy explains:
- what personal data we collect;
- why we collect it;
- how we use it;
- who we share it with;
- how long we keep it; and
- your rights.
Who this applies to:
- website visitors;
- people who contact us;
- schools, trusts and organisations who buy or use our services;
- authorised Portal users;
- suppliers and business contacts.
Separate client processing terms:
Where we process school or trust personal data on your instructions, we act as Processor and our Data Processing Agreement applies.
3. What data we collect
When you visit our website
Essential technical data may be automatically collected:
- IP address;
- browser type and version;
- device type;
- pages visited and time spent;
- referring website;
- security and server logs.
Why: To deliver the website, ensure security and fix technical issues.
Legal basis: Legitimate interests in operating and securing our website.
When you contact us
Information you provide via contact form, email, phone or meeting may include:
- name;
- email address;
- phone number;
- school, trust or organisation name;
- pupil count or organisation size;
- role or job title;
- your message, enquiry or support request.
Why: To respond to your enquiry and provide information about our services.
Legal basis: Legitimate interests in responding to enquiries, or consent where you have opted in to marketing.
When you become a customer
Contract and service delivery data may include:
- school, trust or organisation details;
- invoice and payment information;
- service tier, order and contract terms;
- Portal user accounts and access credentials;
- service records, decisions, outputs and support communications;
- information needed to deliver Outsourced DPO, Portal, TruCredits, evidence processing, redaction, policy packs or related services.
Why: To deliver our services and fulfil our contract with you.
Legal basis: Contract, legitimate interests and legal obligation where applicable.
When we deliver data protection services
When we are Controller for our own business/admin data, we process:
- Portal user accounts and access management;
- contract, service administration and support communications;
- billing and payment records;
- security and audit logs;
- internal service records.
When we are Processor for client school/trust data, we may process:
- staff, pupil and parent data as instructed by you;
- SAR and FOI request details;
- breach and incident information;
- policy, DPIA, ROPA and governance documentation;
- evidence, redaction or export material supplied for processing;
- records needed to produce agreed outputs.
Your role as client is usually Data Controller. Our role is Data Processor for client data, and Data Controller for our own business/admin data as described above.
4. How we use your data
Website visitors
- deliver website content;
- ensure security and prevent abuse;
- maintain and improve the website;
- analyse website performance using aggregated or anonymised data where applicable.
Enquirers
- respond to your questions;
- provide information about our services;
- send a quote or proposal;
- follow up on your enquiry where appropriate.
Customers and Portal users
- deliver the services you purchase;
- provide Portal access;
- manage service records, cases, outputs and support;
- invoice and process payments;
- communicate about your service;
- maintain security, audit and access logs;
- comply with legal obligations;
- improve our services.
Marketing
Where you have consented, or where otherwise permitted by law, we may send updates about our services, relevant guidance and resources.
You can opt out at any time by using unsubscribe links or contacting us.
5. Who we share data with
We do not sell or rent your personal data to third parties.
We may share your data with service providers who help us deliver our services, such as:
- Notion;
- Tally;
- Stripe;
- Google Workspace;
- Amazon Web Services;
- other hosting, security, communication or operational suppliers we use to provide the services.
All processors are expected to process data under appropriate contractual safeguards.
We may also disclose data where required by law, including court orders, regulatory investigations or legal proceedings.
6. International transfers
We store data in the UK and EU where possible.
Some service providers may process data outside the UK. Where this happens, we use appropriate safeguards such as adequacy decisions, the UK International Data Transfer Agreement, UK Addendum to Standard Contractual Clauses or other lawful transfer mechanisms.
7. How long we keep your data
Website visitors
- technical logs: typically up to 12 months;
- analytics data, where used: aggregated or anonymised where possible.
Enquirers
- contact form submissions: 2 years from last contact;
- email correspondence: 2 years from last contact, unless it becomes part of a customer record.
Customers
- contract and invoice data: 7 years;
- service administration data: duration of contract plus 2 years unless a longer legal or operational period applies;
- Portal access logs and security logs: retained for a proportionate security period;
- service outputs and records: retained in line with the relevant service terms, Quote, Data Processing Agreement or agreed retention route.
Data we process on your behalf
Client-controlled data is retained as instructed by you as Data Controller, in line with the Data Processing Agreement, your retention schedule and any service-specific deletion process.
After retention periods expire, data is securely deleted or anonymised.
8. Your rights under UK GDPR
You have the following rights:
- right to access;
- right to correction;
- right to erasure;
- right to restrict processing;
- right to data portability;
- right to object;
- right to withdraw consent;
- right to complain to the Information Commissioner's Office.
ICO website: ico.org.uk
9. How to exercise your rights
Contact us:
Email: dpo@trudigital.co.uk
Post: Tru-Digital Services Limited, 3rd Floor, 86-90 Paul Street, London, EC2A 4NE
We will respond within the required legal timeframe.
10. How we protect your data
Security measures we use include:
- encrypted communications;
- secure password policies and multi-factor authentication;
- role-based access controls;
- audit logging;
- regular security reviews and updates;
- staff training on data protection;
- secure backups;
- incident response procedures.
If we discover a data breach that affects you, we will notify you and/or the ICO where required.
11. Cookies and tracking
Our website currently uses essential cookies only.
If we introduce analytics or marketing cookies in the future, we will ask for your consent first and explain what each cookie does.
For more information, see our Cookie Policy.
12. Third-party links
Our website may link to external sites. We are not responsible for the privacy practices or content of those sites.
13. Children's privacy
Our website and commercial services are aimed at educational institutions, not children.
When we process pupil data, we do this on the school or trust's instructions as Data Processor, unless expressly stated otherwise.
14. Automated decision-making
We do not use automated decision-making or profiling that produces legal or similarly significant effects.
Where AI-assisted or automation-supported features are used in our services, they support review, processing or drafting. They do not replace human judgement where a decision is required.
15. Changes to this policy
We may update this policy to reflect changes in law, our services or best practice.
When we make changes, we will update the last updated date. For material changes, we may notify customers or subscribers.
16. Contact us
Questions about this policy or your data?
Data Protection Officer: Gareth Eynon
Email: dpo@trudigital.co.uk
Address: Tru-Digital Services Limited, 3rd Floor, 86-90 Paul Street, London, EC2A 4NE
Last updated: July 2026