Presentient Technologies Ltd Customer Privacy Notice
Last Updated: 15 September 2026
This privacy notice tells you what to expect us to do with your personal information. This Notice covers the personal information we collect and use as a controller in our own right, for example information about visitors to our website, prospective and existing customers and their contacts, and users of our platform. It does not cover the data our customers upload to the platform, which we process on their behalf as a processor, see “When we act as a processor” below. We are not a controller of clinical trial or patient health data.
Our staff are based in the United Kingdom and we do not outsource or offshore any of our operations. Our staff may occasionally access our systems while travelling for work, subject to the same access controls that apply in the UK, including individual accounts, multi-factor authentication, encryption and access logging. We do not accept card payments and do not hold card details.
We may update this Notice from time to time. Any update will be posted on this page with a revised “Last updated” date, and will apply to our processing of personal information from that date onwards. Where a change is material, we will take reasonable steps to bring it to your attention.
Contact details
Data Protection Officer: our Chief Operating Officer is responsible for data protection. You can contact them at: dpo@presentient.com
EU Representative: The contact details for our Representative for GDPR purposes are as follows: dpo_eu@presentient.com
What information we collect, use, and why
We collect or use the following information to provide services:
- Names and contact details
- Website user information (including user journeys and cookie tracking)
We collect or use the following information for the operation of customer accounts:
- Names and contact details
- Account information, including registration details
- Login and authentication data, and data about your use of the platform, including audit logs
We collect or use the following information to comply with legal requirements:
- Name
- Contact information
We collect or use the following personal information for dealing with queries, complaints or claims:
- Names and contact details
Lawful bases and data protection rights
Under UK data protection law, we must have a "lawful basis" for collecting and using your personal information. There is a list of possible lawful bases in the UK GDPR. You can find out more about lawful bases on the ICO's website.
Which lawful basis we rely on may affect your data protection rights which are set out in brief below. You can find out more about your data protection rights and the exemptions which may apply on the ICO's website:
- Your right of access – You have the right to ask us for copies of your personal information. You can request other information such as details about where we get personal information from and who we share personal information with. There are some exemptions which means you may not receive all the information you ask for. Read more about the right of access.
- Your right to rectification – You have the right to ask us to correct or delete personal information you think is inaccurate or incomplete. Read more about the right to rectification.
- Your right to erasure – You have the right to ask us to delete your personal information. Read more about the right to erasure.
- Your right to restriction of processing – You have the right to ask us to limit how we can use your personal information. Read more about the right to restriction of processing.
- Your right to object to processing – You have the right to object to the processing of your personal data. Read more about the right to object to processing.
- Your right to data portability – You have the right to ask that we transfer the personal information you gave us to another organisation, or to you. Read more about the right to data portability.
- Your right to withdraw consent – When we use consent as our lawful basis you have the right to withdraw your consent at any time. Read more about the right to withdraw consent.
How to Withdraw your consent
We are committed to making it easy to withdraw your consent, depending on the type of processing you consented to, you can withdraw consent in the following ways:
- Cookies and tracking technologies: Update your cookie preferences at any time by clicking the "Cookie Settings" link in the footer of our website, or by adjusting your browser settings.
- Other consent-based processing: Contact us directly at dpo@presentient.com
If you make a request, we will respond without undue delay and in any event within one month. If your request is complex, or if you have made several requests, we may extend this by up to two further months, however, we will tell you within the first month if we need to do so, and why. If we reasonably need you to confirm your identity or to clarify what you are asking for, we may pause the one-month period until you reply.
To make a data protection rights request, please contact us using the contact details at the top of this privacy notice.
Our lawful bases for the collection and use of your data
Our lawful bases for collecting or using personal information to provide services and goods are:
- Consent – we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time (See How to Withdraw consent).
- Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
- Legal obligation – we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object and the right to data portability.
Our lawful bases for collecting or using personal information for the operation of customer accounts and guarantees are:
- Consent – we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.
- Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
Our lawful bases for collecting or using personal information for service updates or marketing purposes are:
- Consent – we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.
- Legitimate interests – we're collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are:
- To provide, improve, and customise our website and services, which furthers our legitimate interest in operating our business and communicating with the public regarding our website and services; supporting or provisioning users' procurement, access to, and use of our website or services; analysing, understanding, and obtaining insights into how our website and services are being used by users and how users are communicating with us; benchmarking, auditing, developing, and improving our website, services, and communications; monitoring the health, performance, and security of our website and services; and exploring and developing new methods of developing and growing our business.
For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.
Our lawful bases for collecting or using personal information for legal requirements are:
- Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
- Legal obligation – we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object and the right to data portability.
Our lawful bases for collecting or using personal information for dealing with queries, complaints or claims are:
- Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
Where we get personal information from
- Directly from you
- Third parties:
- Our customers, who may provide contact details of their staff so that we can set up platform accounts and administer their agreement with us.
When we act as a processor
Our customers upload data to the platform. For that data our customer is the controller and we act only on its instructions under a data processing agreement. Our customer’s own privacy information governs that data, and our customer is responsible for informing individuals about it and for having a valid lawful basis and condition for the processing. If you believe an organisation has uploaded your data to our platform and you wish to exercise your rights, please contact that organisation, or contact us and we will pass your request on.
The only sub-processor with access to data our customers upload is Amazon Web Services, which provides the hosting infrastructure for the platform.
Your BRAKES platform account
If you use our BRAKES platform, we collect and use your account and contact details, your login and authentication data, and data about your use of the platform including audit logs. We use this to provide, administer and secure the platform, to communicate with you about it, to provide support, and to meet our legal and regulatory obligations. Our lawful bases are the performance of our contract with your organisation and our legitimate interests in operating and securing the platform. This is separate from the data your organisation uploads to the platform.
Automated decision-making
We do not make decisions about you by automated means that have legal effects or otherwise significantly affect you. Where our platform produces analysis for a customer, decisions about that analysis are taken by the customer, not by us.
How long we keep information
| Information Type | Use of Data | Retention Period |
|---|---|---|
| Names and contact details | Provision of Goods and Services | 6 years |
| Website user information | Provision of Goods and Services | 1 year |
| Names and contact details | Operation of Customer Accounts | 6 years |
| Account information, including registration details | Operation of Customer Accounts | 6 years |
| Names and contact details | Legal Requirements | 6 years |
| Names and contact details | Dealing with queries and complaints | 3 years |
For more information on how long we store your personal information or the criteria we use to determine this please contact us using the details provided above.
Who we share information with
Data processors
Amazon Web Services. Infrastructure provider for hosting our web application and the BRAKES platform.
Atlassian. Management of support tickets
Google. Google Workspace, for email, documents and data storage; and Google Analytics, for website analytics using aggregate statistics only (we do not enable Google Signals or advertising features).
Hubspot. Customer relationship management, website forms and cookie consent records.
Sharing information outside the UK
Some of our processors can access personal information from outside the UK. Where they do, appropriate safeguards are in place under the UK GDPR, as set out below. Our own staff access is from the UK, or occasionally from abroad while travelling for work, in each case under the same access controls. Where our contract is with a processor based in a country covered by UK adequacy regulations, no additional safeguard is needed for our transfer to that processor, and any onward transfer by that processor is its own responsibility.
For further information or to obtain a copy of the appropriate safeguard for any of the transfers below, please contact us using the contact information provided above.
Organisation name: Amazon Web Services
Category of recipient: Infrastructure and platform hosting
Where the personal information can be accessed from: Our contract is with Amazon Web Services EMEA SARL, which is located in Luxembourg. Data is stored in the EU. Amazon Web Services may access it from other countries, including the United States, in order to provide support.
How the transfer complies with UK data protection law: Luxembourg is in the European Economic Area, which is covered by UK adequacy regulations. No additional transfer safeguard is therefore required for our transfer to Amazon Web Services. Any onward transfer by Amazon Web Services is governed by its own data processing terms, which require appropriate safeguards to be in place.
Organisation name: Google (Workspace and Analytics)
Category of recipient: Email, documents and storage; website analytics
Where the personal information can be accessed from: Data residency in the UK, with access on a global basis
How the transfer complies with UK data protection law: Google’s UK Controller-to-Processor Standard Contractual Clauses, and the EU Standard Contractual Clauses where the EU GDPR applies
Organisation name: Hubspot
Category of recipient: Customer relationship management, website forms and cookie consent
Where the personal information can be accessed from: Data residency in the EU, with access on a global basis including the United States
How the transfer complies with UK data protection law: The UK Extension to the EU-US Data Privacy Framework, under which HubSpot, Inc. is certified, or otherwise the EU Standard Contractual Clauses together with the UK Addendum
Organisation name: Atlassian
Category of recipient: Support ticket management
Where the personal information can be accessed from: Data residency in the UK, with access on a global basis
How the transfer complies with UK data protection law: EU Standard Contractual Clauses together with the UK Addendum (version B1.0)
Children’s privacy
We may update this Notice from time to time. Any update will be posted on this page with a revised “Last updated” date and will apply from that date onwards. Where a change is material, we will take reasonable steps to bring it to your attention.
Changes to this policy
We may update this Notice from time to time. Any update will be posted on this page with a revised “Last updated” date and will apply from that date onwards. Where a change is material, we will take reasonable steps to bring it to your attention.
How to complain
You have the right to complain to us if you think we have not handled your personal information properly. You can complain by email to dpo@presentient.com, or by post to Presentient Technologies Ltd, 3 More London Riverside, London, SE1 2RE. You do not have to use either route and we will accept your complaint however it reaches us. We will acknowledge your complaint within 30 days of receiving it, make appropriate enquiries into it without undue delay, keep you informed of progress, and tell you the outcome and the reasons for it.
If you remain unhappy after complaining to us, you can also complain to the Information Commissioner’s Office, the UK data protection regulator. Where you are in the EEA, you may also complain to the supervisory authority in your country of residence.
The ICO's address:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline number: 0303 123 1113
Website: https://www.ico.org.uk/make-a-complaint
Last Updated: 15 September 2026