This GDPR Compliance Notice summarises how Terrapps Limited, trading as Infinity Technologies, approaches compliance with the General Data Protection Regulation (EU) 2016/679 (“EU GDPR”) and, where applicable, the United Kingdom GDPR (“UK GDPR”).
This Notice supplements our Privacy Policy and Cookie Policy. It does not replace those documents and is not a certification of compliance by a regulator or certification body.
Infinity Technologies is a trading brand operated principally by Terrapps Limited, a company registered in England and Wales under company number 15099631, with registered office at 101 King's Cross Road, London, England, WC1X 9LP, United Kingdom.
For personal data collected through infinitytechnologies.pro and www.infinitytechnologies.pro, Terrapps Limited is the data controller unless another Infinity Technologies affiliated entity is expressly identified for a particular interaction.
Affiliated entities may support service delivery, recruitment, sales, administration or other business activities. Group membership alone does not make every affiliated entity a joint controller. Where another entity acts as an independent or joint controller, its role will be identified where required by applicable law.
Where we process personal data solely on a customer's documented instructions, we act as a processor or service provider rather than as the controller for that processing. In those circumstances, the customer's privacy information governs the relevant controller processing.
Where the EU GDPR or UK GDPR applies, our handling of personal data is designed around the following principles:
We do not rely on a single legal basis for every activity. Depending on the context, the bases we may rely on include:
Our Privacy Policy describes the principal purposes for which we process personal data and the typical legal bases associated with those purposes.
Where consent is required for optional website technologies, our Website provides controls that allow visitors to accept all optional technologies, reject them, or manage categories individually.
Functional and Analytics categories are switched off by default. Optional technologies assigned to those categories remain disabled unless the visitor actively enables the relevant category or chooses Accept all.
Consent choices can be changed or withdrawn later through the Cookie Preferences link in the Website footer. Withdrawing consent does not affect processing that was lawful before the withdrawal.
Further details about the technologies currently used on the Website are available in our Cookie Policy.
Where the EU GDPR or UK GDPR applies, individuals may have the following rights, subject to the conditions and exemptions in applicable law:
Requests can be made by emailing info@infinitytechnologies.pro. We may request proportionate information needed to verify identity or authority. Where the GDPR applies, we normally respond within one month, subject to any extension or other rule permitted by applicable law.
We may use service providers to support hosting, forms, communications, cloud infrastructure, security, analytics, administration and other business functions.
Where applicable law requires a controller-processor agreement, the relevant parties are required to put appropriate contractual terms in place addressing matters such as the subject matter and duration of processing, confidentiality, security, subprocessors, assistance with data-subject rights, deletion or return of data, and compliance information.
Affiliated Infinity Technologies entities may receive personal data where reasonably necessary for a defined business function. Their role depends on the actual processing activity and is not determined solely by membership in the Infinity Technologies group.
Infinity Technologies operates internationally, and personal data may be processed in countries other than the country where it was collected.
Where the EU GDPR or UK GDPR restricts an international transfer, the responsible controller is required to use an appropriate transfer mechanism. Depending on the destination and recipient, this may include an applicable adequacy decision, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, together with any additional safeguards required by the circumstances.
Further information about relevant transfer safeguards may be requested using the contact details below.
When designing or materially changing systems and processes involving personal data, we seek to take data-protection principles into account from an early stage, including purpose limitation, data minimisation, access controls, retention and appropriate security.
We use technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. The measures appropriate to a particular activity depend on the nature of the data, the processing and the associated risks.
We retain personal data only for as long as reasonably necessary for the relevant purpose, legal obligations, security needs and the establishment, exercise or defence of legal claims. More detailed retention criteria are described in our Privacy Policy.
Where required by applicable law and appropriate to the activity, our data-protection approach may include:
The specific measures applicable to a processing activity depend on its nature, scale, context and risk.
Personal-data incidents are assessed against applicable breach-notification requirements. Where a personal-data breach triggers a legal notification obligation, the responsible controller must notify the relevant supervisory authority within the applicable legal timeframe and inform affected individuals where applicable law requires it.
Not every security incident constitutes a reportable personal-data breach. Notification decisions are made based on the facts, risk to individuals and applicable legal requirements.
If you have a data-protection concern, you can contact us using the details below. We will review the concern and respond in accordance with applicable legal requirements.
If you are in the United Kingdom, you may also complain to the Information Commissioner's Office (ICO). If you are in the European Economic Area, you may complain to the competent data-protection supervisory authority, including the authority in the country of your habitual residence, place of work or the alleged infringement, as applicable.
Terrapps Limited
trading as Infinity Technologies
Company number: 15099631
101 King's Cross Road
London, England, WC1X 9LP
United Kingdom
Email: info@infinitytechnologies.pro
Website: https://infinitytechnologies.pro
This Notice may be updated as our processing activities, systems or applicable legal requirements change. The date shown with this document identifies the current version.