Infinity Technologies
Agentic Transformation
/
Enterprise / Product / SDLC
Let's Talk!
Schedule free discovery call
Talk to us
01 Our Story Discover our company → 02 Our Insights Read articles created by our team → 03 Our Success Stories Explore our projects → 04 Our Vacancies Join our team → 05 Our Documents Rules We Follow → 06 Featured Forbes Insights Insights from our CEO →
Talk to us
DOCUMENTS

GDPR Compliance Notice

5 October 2026
Our approach to GDPR and data protection

This GDPR Compliance Notice summarises how Terrapps Limited, trading as Infinity Technologies, approaches compliance with the General Data Protection Regulation (EU) 2016/679 (“EU GDPR”) and, where applicable, the United Kingdom GDPR (“UK GDPR”).

This Notice supplements our Privacy Policy and Cookie Policy. It does not replace those documents and is not a certification of compliance by a regulator or certification body.

1. Controller and scope

Infinity Technologies is a trading brand operated principally by Terrapps Limited, a company registered in England and Wales under company number 15099631, with registered office at 101 King's Cross Road, London, England, WC1X 9LP, United Kingdom.

For personal data collected through infinitytechnologies.pro and www.infinitytechnologies.pro, Terrapps Limited is the data controller unless another Infinity Technologies affiliated entity is expressly identified for a particular interaction.

Affiliated entities may support service delivery, recruitment, sales, administration or other business activities. Group membership alone does not make every affiliated entity a joint controller. Where another entity acts as an independent or joint controller, its role will be identified where required by applicable law.

Where we process personal data solely on a customer's documented instructions, we act as a processor or service provider rather than as the controller for that processing. In those circumstances, the customer's privacy information governs the relevant controller processing.

2. Data protection principles

Where the EU GDPR or UK GDPR applies, our handling of personal data is designed around the following principles:

  • lawfulness, fairness and transparency — personal data should be processed on an appropriate legal basis and in a way that is understandable to the individual;
  • purpose limitation — personal data should be collected for specified and legitimate purposes and not reused incompatibly;
  • data minimisation — we seek to process only personal data that is relevant and reasonably necessary for the relevant purpose;
  • accuracy — we take reasonable steps to keep personal data accurate and to correct material inaccuracies where appropriate;
  • storage limitation — personal data should not be kept for longer than is reasonably necessary for the relevant purpose and applicable legal requirements;
  • integrity and confidentiality — personal data should be protected by appropriate technical and organisational measures; and
  • accountability — the responsible controller should be able to demonstrate its approach to data-protection obligations.

3. Lawful bases for processing

We do not rely on a single legal basis for every activity. Depending on the context, the bases we may rely on include:

  • contract and pre-contractual steps, where processing is necessary to enter into or perform a contract with the individual;
  • legitimate interests, where processing is reasonably necessary for a legitimate business or security purpose and those interests are not overridden by the individual's rights and interests;
  • legal obligations, where processing is required to comply with applicable law;
  • consent, where applicable law requires or permits us to rely on freely given, specific, informed and unambiguous consent; and
  • vital interests, in exceptional circumstances where processing is necessary to protect someone's life or physical safety.

Our Privacy Policy describes the principal purposes for which we process personal data and the typical legal bases associated with those purposes.

4. Consent and website technologies

Where consent is required for optional website technologies, our Website provides controls that allow visitors to accept all optional technologies, reject them, or manage categories individually.

Functional and Analytics categories are switched off by default. Optional technologies assigned to those categories remain disabled unless the visitor actively enables the relevant category or chooses Accept all.

Consent choices can be changed or withdrawn later through the Cookie Preferences link in the Website footer. Withdrawing consent does not affect processing that was lawful before the withdrawal.

Further details about the technologies currently used on the Website are available in our Cookie Policy.

5. Rights of individuals

Where the EU GDPR or UK GDPR applies, individuals may have the following rights, subject to the conditions and exemptions in applicable law:

  • the right to be informed about how personal data is processed;
  • the right of access to personal data;
  • the right to rectification of inaccurate or incomplete personal data;
  • the right to erasure in applicable circumstances;
  • the right to restriction of processing;
  • the right to data portability where the legal conditions are satisfied;
  • the right to object to processing based on legitimate interests and an absolute right to object to direct marketing;
  • the right to withdraw consent where processing is based on consent; and
  • rights relating to certain decisions based solely on automated processing where the relevant legal conditions apply.

Requests can be made by emailing info@infinitytechnologies.pro. We may request proportionate information needed to verify identity or authority. Where the GDPR applies, we normally respond within one month, subject to any extension or other rule permitted by applicable law.

6. Processors, service providers and affiliated entities

We may use service providers to support hosting, forms, communications, cloud infrastructure, security, analytics, administration and other business functions.

Where applicable law requires a controller-processor agreement, the relevant parties are required to put appropriate contractual terms in place addressing matters such as the subject matter and duration of processing, confidentiality, security, subprocessors, assistance with data-subject rights, deletion or return of data, and compliance information.

Affiliated Infinity Technologies entities may receive personal data where reasonably necessary for a defined business function. Their role depends on the actual processing activity and is not determined solely by membership in the Infinity Technologies group.

7. International transfers

Infinity Technologies operates internationally, and personal data may be processed in countries other than the country where it was collected.

Where the EU GDPR or UK GDPR restricts an international transfer, the responsible controller is required to use an appropriate transfer mechanism. Depending on the destination and recipient, this may include an applicable adequacy decision, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, together with any additional safeguards required by the circumstances.

Further information about relevant transfer safeguards may be requested using the contact details below.

8. Data protection by design, security and retention

When designing or materially changing systems and processes involving personal data, we seek to take data-protection principles into account from an early stage, including purpose limitation, data minimisation, access controls, retention and appropriate security.

We use technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. The measures appropriate to a particular activity depend on the nature of the data, the processing and the associated risks.

We retain personal data only for as long as reasonably necessary for the relevant purpose, legal obligations, security needs and the establishment, exercise or defence of legal claims. More detailed retention criteria are described in our Privacy Policy.

9. Data protection impact and accountability measures

Where required by applicable law and appropriate to the activity, our data-protection approach may include:

  • documenting relevant processing activities;
  • assessing legitimate interests before relying on that legal basis;
  • conducting data-protection impact assessments for processing likely to result in a high risk to individuals;
  • reviewing vendors and contractual data-protection terms;
  • limiting access to personal data according to business need;
  • maintaining processes for data-subject requests and privacy complaints; and
  • reviewing material changes to website technologies and consent controls.

The specific measures applicable to a processing activity depend on its nature, scale, context and risk.

10. Personal data breaches

Personal-data incidents are assessed against applicable breach-notification requirements. Where a personal-data breach triggers a legal notification obligation, the responsible controller must notify the relevant supervisory authority within the applicable legal timeframe and inform affected individuals where applicable law requires it.

Not every security incident constitutes a reportable personal-data breach. Notification decisions are made based on the facts, risk to individuals and applicable legal requirements.

11. Complaints and supervisory authorities

If you have a data-protection concern, you can contact us using the details below. We will review the concern and respond in accordance with applicable legal requirements.

If you are in the United Kingdom, you may also complain to the Information Commissioner's Office (ICO). If you are in the European Economic Area, you may complain to the competent data-protection supervisory authority, including the authority in the country of your habitual residence, place of work or the alleged infringement, as applicable.

12. Contact

Terrapps Limited
trading as Infinity Technologies
Company number: 15099631
101 King's Cross Road
London, England, WC1X 9LP
United Kingdom
Email: info@infinitytechnologies.pro
Website: https://infinitytechnologies.pro

This Notice may be updated as our processing activities, systems or applicable legal requirements change. The date shown with this document identifies the current version.

Tell us about your project needs

We use the information you submit to respond to your enquiry. See our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Contact us and turn your project into a success story
Roman Reznikov
CEO & Partner
US contact address
Address: 1521 Concord Pike, Suite 301-249, Wilmington, Delaware 19803, USA
EU contact address
Address: Harju maakond, Tallinn, Kesklinna linnaosa, Ahtri tn 12, 15551
UK registered office
Address: London, England
WC1X 9LP
101 King's Cross Road
GDPR Compliance NoticeAccessibility StatementCopyright NoticeCookie PolicyCookie PreferencesTerms of UsePrivacy policySite map
© 2026 Terrapps Limited trading as Infinity Technologies. All rights reserved. Company No. 15099631 · Registered in England and Wales.