Back to terms and policies

Two Hat Software Ltd

Data Protection Policy

Download PDF

Policy statement

Two Hat Software Ltd is committed to handling personal data lawfully, fairly and securely. We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as amended.

This policy sets out how we meet those obligations. Our Privacy Notice explains to individuals how we use their data.

Scope

This policy covers all personal data we handle, whether we are the controller, for example our own client and enquiry records, or a processor acting on a client's behalf. It applies to the company's director, to any employees we may take on, and to any substitutes and subcontractors.

Data protection principles

We make sure personal data is:

  1. processed lawfully, fairly and transparently
  2. collected for specified, explicit and legitimate purposes, and not used for anything incompatible with those purposes
  3. adequate, relevant and limited to what is necessary
  4. accurate and kept up to date
  5. kept for no longer than necessary
  6. kept secure

We keep records that show how we meet these principles.

Lawful basis

Before we process personal data as a controller, we identify a lawful basis for it and record it. For most of our processing, the basis is performing a contract, complying with a legal obligation, or our legitimate interests.

When we act as a processor for clients

When we handle personal data on a client's behalf, for example while developing or supporting their systems, we:

  • process it only on the client's documented instructions
  • have written processor terms in place, as our Terms and Conditions require
  • access only the data needed for the task, using the client's systems where possible
  • avoid copying production personal data into development or test environments, unless the client has agreed it and it is properly protected
  • delete or return the data when the work ends
  • tell the client without undue delay about any personal data breach affecting their data

Records and retention

We keep a record of our processing activities. We keep personal data only as long as our retention periods allow, and then delete it securely. The retention periods are set out in our Privacy Notice.

Individuals' rights

We respond to requests from individuals to exercise their rights within one month. We verify the identity of the person making a request before we disclose any data.

Data protection by design

When we build software, we design in data protection from the start. This includes:

  • collecting only the data that is needed
  • protecting it with access controls and encryption
  • setting sensible retention periods
  • making it easy to meet individuals' rights

Where planned processing is likely to result in a high risk to individuals, we carry out a data protection impact assessment, or help the client to carry one out.

Third parties and international transfers

We use only processors that provide sufficient guarantees about security and compliance, and we have contracts with them. We transfer personal data outside the United Kingdom only where an appropriate safeguard is in place.

Personal data breaches

If a personal data breach happens, we will:

  1. contain it and assess the risk to individuals
  2. report it to the Information Commissioner's Office within 72 hours if it is likely to result in a risk to individuals' rights and freedoms
  3. tell the individuals affected without undue delay if the risk is high
  4. record every breach, whether or not it is reported

ICO registration

We pay the data protection fee to the Information Commissioner's Office where the law requires it.

Responsibility and review

The director, George Dennington, is responsible for data protection. We are not required to appoint a data protection officer. Questions about this policy should be sent to admin@twohatsoftware.co.uk.

This policy is reviewed at least once a year, and whenever the law or our processing changes. It took effect on 3 October 2026.