Privacy Policy
This notice explains how Tidalux Ltd processes personal data under UK GDPR and the Data Protection Act 2018. It is written for website visitors, customers, portal users and people who contact us for support. If you use WaveCheck, WaveSites or our paid plans, this notice sits alongside the contract terms in our Terms of Service.
Tidalux Ltd
Registered in England and Wales · Company No. 17019367 · ICO registration ZC091301 Registered office: Studio 9, 50-54 St Paul's Square, Birmingham B3 1QS, United Kingdom legal@tidalux.io · hello@tidalux.io
1. Who we are
Tidalux Ltd is a company registered in England and Wales, company number 17019367. Registered office: Studio 9, 50-54 St Paul's Square, Birmingham B3 1QS, United Kingdom. We are registered with the Information Commissioner's Office (ICO Reg. ZC091301) as a data controller.
Our Data Protection contact is legal@tidalux.io. You can contact us there about any data protection matter.
2. What data we collect
We collect only the data we need. Depending on how you interact with us, this may include:
- Contact information - your name, email address and any message content when you contact us via our website forms.
- Account information - email address, hashed password and account preferences if you register for a Tidalux product or service.
- Billing information - name and address for invoicing. We do not store card details; payments are processed by Stripe (who are separately PCI-DSS compliant).
- Usage data - log data (IP address, browser type, pages visited) collected automatically via our infrastructure.
- Cookies - see our Cookie Policy for details.
- Newsletter - email address only, if you subscribe.
- WaveCheck scans - if you leave an email so we can send the PDF, we keep that as a lead. If you do not, we still keep the domain you checked, the score, and the time of the completed scan so we can count demand in aggregate. We do not store your IP address or browser against those anonymous rows.
3. How we use your data
We use your data to:
- Provide and maintain our services to you.
- Respond to your enquiries and support requests.
- Process transactions and send related information (receipts, invoices).
- Send you service-related communications (e.g. downtime notices, policy updates).
- Send marketing communications - only with your explicit consent, and you can unsubscribe at any time.
- Comply with legal obligations.
- Improve our products and services (using anonymised analytics only).
4. Legal basis for processing (UK GDPR)
We rely on the following legal bases:
- Contract - processing necessary to fulfil a contract with you (e.g. providing services you have purchased).
- Legitimate interests - security monitoring, fraud prevention, product improvement.
- Consent - marketing emails, non-essential cookies. You can withdraw consent at any time.
- Legal obligation - where we must retain data for tax, accounting or other legal requirements.
5. Data sharing
We do not sell, rent or trade your personal data. We share it only where necessary:
- Stripe - payment processing.
- Google (Google Analytics 4) - aggregate website analytics, and only where you have consented via our cookie banner. Google acts as our processor under its data processing terms; we do not enable advertising or cross-site tracking features, and Google Analytics 4 does not store your full IP address.
- Data centre and infrastructure operators - specialist third-party companies that run the UK data centres, servers, networking and backup storage our platform uses. See “Where your data is hosted” below.
- Proton Mail - outbound email for enquiries, billing and service messages.
- Legal/regulatory authorities - where required by law.
All third-party processors are subject to appropriate data processing agreements.
6. Where your data is hosted
Tidalux designs, runs and supports the platform your website, email and applications sit on. We do not own or operate data centres. The underlying infrastructure, meaning the buildings, servers, networking, power and backup storage, is enterprise infrastructure located in the United Kingdom and operated for us by specialist third-party companies under contract. That is normal for a studio of our size, and it is why your site sits on resilient equipment with round-the-clock cover behind it.
What this means for you in practice: Tidalux remains the party responsible to you for the service. We are your point of contact, we hold the contract with you, and we are accountable for delivery, security and support. Those third-party operators act as our processors, or as sub-processors where we handle personal data on your behalf, and they are bound by written data processing terms that flow down the obligations we owe you.
If you are a business customer and you need the identity of the specific sub-processors used for your service, for your own UK GDPR record of processing or a supplier due-diligence pack, email legal@tidalux.io and we will provide it in writing under our data processing agreement.
7. Data retention
We retain personal data only as long as necessary for the purpose for which it was collected, or as required by law. Account data is retained for the duration of your account plus 7 years for tax purposes. Enquiry data (contact form submissions) is retained for 2 years. You can request deletion at any time (see Your Rights below).
8. Your rights
Under UK GDPR, you have the right to:
- Access - request a copy of the data we hold about you (often called a subject access request or DSAR).
- Rectification - ask us to correct inaccurate data.
- Erasure - ask us to delete your data (subject to legal retention requirements).
- Restriction - ask us to restrict processing of your data.
- Portability - receive your data in a structured, machine-readable format.
- Object - object to processing based on legitimate interests.
- Withdraw consent - at any time, where processing is based on consent.
To exercise any of these rights, email legal@tidalux.io. We will respond within 30 days. You also have the right to lodge a complaint with the ICO at ico.org.uk.
9. Data security
We implement appropriate technical and organisational measures to protect your data, including encrypted connections (HTTPS/TLS), access controls limiting who can access customer data, and regular review of our hosting and backup practices. Despite these measures, no internet transmission is 100% secure. If we become aware of a data breach that is likely to affect your rights, we will notify you and the ICO as required.
10. International transfers
We primarily process personal data in the United Kingdom and the European Economic Area. Where we use processors or sub-processors outside the UK/EEA, we put in place appropriate safeguards under UK GDPR (for example, the UK International Data Transfer Agreement or Addendum, or adequacy regulations), and we assess risk before any transfer proceeds.
For Google Analytics 4 specifically, if you consent, data may be processed by Google outside the UK/EEA. Google relies on Standard Contractual Clauses with the UK Addendum and participates in the EU-US Data Privacy Framework (and its UK extension) as a safeguard for such transfers.
11. Cookies
We use cookies for essential functionality, analytics and preferences. For full details, please see our Cookie Policy.
12. Changes to this policy
We may update this policy from time to time. The “last updated” date at the top of this page will always reflect the current version. Significant changes are described on this page when they take effect.
13. Contact us
For any questions about this policy or our data practices, please contact us at legal@tidalux.io or write to us at our registered office address above.