Privacy Policy
Last updated: May 2026
1. Who we are
DecodedAlgorithms Ltd ("we", "us", "our") is a company registered in England and Wales (No. 17233569). We act as an authorised data rights agent, helping individuals exercise their right to be informed about automated decisions under Article 15(1)(h) of the UK GDPR. Our ICO registration number is .
2. What data we collect
When you use our free improvement‑report service, we collect the information you provide in the form:
- Full name
- Email address
- Company name and website URL
- A description of the decision you are asking about
- Photo ID type and last four characters
- Date of birth
- ID expiry date
- Customer reference, account, or claim number (if provided)
- Preferred contact format and postal address (if selected)
- Explicit consent records (agent authorisation, anonymised data consent)
We also store any files or documents you upload when using our paid instant‑analysis service.
3. How we use your data
We use the information you provide solely to:
- Send a legally binding data subject access request to the company you select, as your authorised agent under Article 15(1)(h) UK GDPR.
- Receive and analyse the company's response in order to produce your personalised improvement report.
- Send the improvement report to the email address you supplied.
- Improve our decoding engine by using anonymised, aggregated data (only with your explicit consent).
We do not use your data for marketing purposes, and we never sell your personal information.
4. Legal basis
Our processing is based on:
- Consent – you explicitly authorise us to act as your agent and agree to our use of your data for this specific purpose.
- Legitimate interests – we have a legitimate interest in improving our service through anonymised, aggregated analysis (only where you have given separate consent for this).
5. Data sharing
We share your personal data with:
- The company you select, to the extent necessary to submit the data subject access request and verify your identity.
- Service providers that help us operate our platform (e.g., Cloudflare for hosting, MailChannels for email delivery). All providers are contractually bound to process data only on our instructions.
We do not share your data with any other third parties unless required by law.
6. Data retention
We keep your personal data only as long as needed to provide the service and comply with our legal obligations. Typically:
- Request details and consent records are kept for up to 6 years after the request is closed, in line with potential legal claims and ICO guidance.
- Company responses and improvement reports are kept until you ask us to delete them, or for a maximum of 6 years.
- Anonymised, aggregated data may be kept indefinitely for research and benchmarking.
7. Your rights
Under the UK GDPR, you have the right to:
- Access the personal data we hold about you.
- Correct any inaccuracies.
- Request erasure of your data.
- Object to or restrict our processing.
- Withdraw your consent at any time (this won't affect the lawfulness of processing already carried out).
- Lodge a complaint with the Information Commissioner's Office (ICO).
To exercise any of these rights, contact us at dpo@supervisingai.co.uk.
8. Security
We implement appropriate technical and organisational measures to protect your data, including encryption in transit and at rest, access controls, and regular security reviews. Our infrastructure is hosted on Cloudflare's secure global network.
9. International transfers
Your data is stored and processed in Cloudflare's global data centres, which may be located outside the UK. We ensure appropriate safeguards are in place, including Standard Contractual Clauses and binding data processing agreements with our service providers.
10. Contact us
If you have any questions about this policy or your data, contact our Data Protection Officer at dpo@supervisingai.co.uk.