GDPR COMPLIANCE POLICY
Our full privacy policy
Document owner: Networkd. Version 1.0. Effective date: 3 August 2026. Approved by Jan McGinley, Founder.
Contents
- Introduction and Scope
- Definitions
- Data Controller and Processor Responsibilities
- Lawful Bases for Processing
- Types of Personal Data Collected
- Data Collection Methods
- Purposes of Processing
- Data Subject Rights
- Automated Decision-Making and Profiling
- Data Sharing Between Stakeholder Groups
- International Data Transfers
- Data Retention
- Data Security Measures
- Data Breach Notification
- Data Protection Impact Assessments
- Sub-Processor Management
- Data Protection Officer
- Staff Training and Awareness
- Record of Processing Activities
- Policy Review and Updates
- Complaints and Enforcement
Background
Networkd operates a startup ecosystem platform that connects founders, mentors, investors, and partners (the "Platform").
In the course of operating the Platform, Networkd collects and processes Personal Data from and about its stakeholders and is committed to complying with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), and all applicable data protection legislation.
This Policy sets out the principles, procedures, and responsibilities that govern how Networkd processes Personal Data.
1. Introduction and Scope
Purpose
This GDPR Compliance Policy (the "Policy") establishes the framework by which Networkd manages its data protection obligations under the UK General Data Protection Regulation (Regulation (EU) 2016/679 as it forms part of the law of England and Wales by virtue of section 3 of the European Union (Withdrawal) Act 2018, as amended) (the "UK GDPR") and the Data Protection Act 2018 (the "DPA 2018").
Scope
This Policy applies to:
- all Personal Data processed by Networkd, whether in the capacity of Data Controller or Data Processor;
- all employees, contractors, temporary workers, consultants, and any other person who processes Personal Data on behalf of Networkd (collectively, "Personnel");
- all departments, functions, and systems within Networkd;
- all processing activities conducted through or in connection with the Platform; and
- all stakeholder groups, including founders, mentors, investors, and partners who use the Platform.
Regulatory framework
This Policy is designed to ensure compliance with:
- the UK GDPR;
- the DPA 2018;
- guidance issued by the Information Commissioner's Office (the "ICO"); and
- any applicable codes of conduct or certification mechanisms approved under the UK GDPR.
Global compliance aspirations
Networkd recognises that, as the Platform grows, it may process Personal Data of individuals located in jurisdictions beyond the United Kingdom. In particular, Networkd aspires to achieve compliance with:
- the European Union General Data Protection Regulation (Regulation (EU) 2016/679) (the "EU GDPR");
- the California Consumer Privacy Act of 2018 and the California Privacy Rights Act of 2020 (the "CCPA/CPRA"); and
- other applicable state, federal, and international privacy laws.
Separate policy addenda or a modular policy structure shall be developed as Networkd expands into non-UK jurisdictions. Any such addenda shall be appended to this Policy or maintained as standalone supplements, cross-referenced herein.
2. Definitions
Defined terms
In this Policy, unless the context otherwise requires, the following terms shall have the meanings set out below:
- "Adequacy Decision" means a decision made by the Secretary of State under section 17A of the DPA 2018 (or, where applicable, a decision of the European Commission under Article 45 of the EU GDPR) that a third country or territory ensures an adequate level of protection for Personal Data.
- "Appropriate Safeguards" means the safeguards referred to in Articles 46 and 47 of the UK GDPR, including Standard Contractual Clauses, binding corporate rules, and approved codes of conduct or certification mechanisms.
- "Consent" means any freely given, specific, informed, and unambiguous indication of the Data Subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her, as defined in Article 4(11) of the UK GDPR.
- "Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed, as defined in Article 4(12) of the UK GDPR.
- "Data Controller" means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data, as defined in Article 4(7) of the UK GDPR.
- "Data Processor" means a natural or legal person, public authority, agency, or other body which processes Personal Data on behalf of the Data Controller, as defined in Article 4(8) of the UK GDPR.
- "Data Protection Impact Assessment" or "DPIA" means an assessment carried out in accordance with Article 35 of the UK GDPR to evaluate the impact of proposed Processing operations on the protection of Personal Data.
- "Data Protection Officer" or "DPO" means the individual designated in accordance with Articles 37 to 39 of the UK GDPR to oversee compliance with data protection legislation.
- "Data Subject" means an identified or identifiable natural person whose Personal Data is being processed, as defined in Article 4(1) of the UK GDPR.
- "International Data Transfer" means any transfer of Personal Data to a recipient located in a country or territory outside the United Kingdom.
- "Lawful Basis" means one of the legal bases for Processing Personal Data set out in Article 6(1) of the UK GDPR (and, where Special Category Data is concerned, Article 9(2) of the UK GDPR).
- "Legitimate Interests Assessment" or "LIA" means a documented assessment conducted to determine whether Processing based on legitimate interests is lawful, balancing the interests of Networkd against the rights and freedoms of the Data Subject.
- "Networkd" means the organisation operating the Platform, acting as Data Controller and, where applicable, Data Processor in relation to Personal Data processed through the Platform.
- "Personal Data" means any information relating to an identified or identifiable natural person, as defined in Article 4(1) of the UK GDPR.
- "Processing" means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, as defined in Article 4(2) of the UK GDPR.
- "Record of Processing Activities" or "ROPA" means the record required under Article 30 of the UK GDPR documenting all Processing activities.
- "Special Category Data" means Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning health, or data concerning a natural person's sex life or sexual orientation, as set out in Article 9(1) of the UK GDPR.
- "Standard Contractual Clauses" or "SCCs" means the contractual clauses approved by the Secretary of State (or, where applicable, the European Commission) for the purposes of providing Appropriate Safeguards for International Data Transfers under Article 46(2)(c) of the UK GDPR, including the International Data Transfer Agreement (IDTA) and the International Data Transfer Addendum to the EU SCCs issued by the ICO.
- "Sub-Processor" means any third-party Data Processor engaged by Networkd (or by another Processor acting on behalf of Networkd) to carry out specific Processing activities.
- "Supervisory Authority" means the ICO or any other independent public authority responsible for monitoring the application of data protection legislation.
- "UK Extension to the EU-US Data Privacy Framework" means the extension to the EU-US Data Privacy Framework that enables UK-US data transfers, as recognised by the Secretary of State's adequacy regulations.
Interpretation
In this Policy:
- references to legislation are to that legislation as amended, re-enacted, or replaced from time to time;
- references to Articles are to Articles of the UK GDPR unless otherwise stated;
- references to Sections are to sections of this Policy;
- headings are for convenience only and shall not affect the interpretation of this Policy; and
- words in the singular include the plural and vice versa.
3. Data Controller and Processor Responsibilities
Networkd as Data Controller
Networkd acts as Data Controller when it determines the purposes and means of Processing Personal Data. This includes, without limitation, Processing in connection with:
- user registration and account management on the Platform;
- the matchmaking and networking features of the Platform (connecting founders with mentors, investors, and partners);
- organising and managing events and networking sessions;
- communications with stakeholders (including marketing, newsletters, and service announcements);
- compliance with legal and regulatory obligations; and
- internal analytics and business intelligence relating to Platform usage.
Networkd as Data Processor
Networkd acts as Data Processor when it processes Personal Data on behalf of another Data Controller. This may arise where:
- a corporate partner, investor, or accelerator programme engages Networkd to manage or host data relating to that partner's own stakeholders through the Platform;
- Networkd provides white-label or co-branded platform services to a third party, processing that third party's user data under their instruction; or
- Networkd processes data under a data processing agreement where the third party retains controllership.
When acting as Data Processor, Networkd shall:
- process Personal Data only on documented instructions from the Data Controller, unless required to do so by law;
- ensure that all Personnel who process Personal Data are bound by obligations of confidentiality;
- implement appropriate technical and organisational security measures as set out in Section 13;
- not engage any Sub-Processor without the prior written authorisation of the Data Controller, subject to the requirements of Section 16;
- assist the Data Controller in fulfilling its obligation to respond to Data Subject requests;
- assist the Data Controller in ensuring compliance with its obligations regarding data security, Data Breach notification, DPIAs, and prior consultation with the ICO;
- at the choice of the Data Controller, delete or return all Personal Data upon termination of the processing arrangement; and
- make available to the Data Controller all information necessary to demonstrate compliance and allow for audits and inspections.
Data protection principles
In all Processing activities, whether as Data Controller or Data Processor, Networkd shall adhere to the data protection principles set out in Article 5 of the UK GDPR:
- "Lawfulness, Fairness, and Transparency": Personal Data shall be processed lawfully, fairly, and in a transparent manner in relation to the Data Subject;
- "Purpose Limitation": Personal Data shall be collected for specified, explicit, and legitimate purposes and not further processed in a manner that is incompatible with those purposes;
- "Data Minimisation": Personal Data shall be adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed;
- "Accuracy": Personal Data shall be accurate and, where necessary, kept up to date;
- "Storage Limitation": Personal Data shall be kept in a form which permits identification of Data Subjects for no longer than is necessary for the purposes for which the Personal Data is processed;
- "Integrity and Confidentiality": Personal Data shall be processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful Processing and against accidental loss, destruction, or damage; and
- "Accountability": Networkd shall be responsible for, and be able to demonstrate compliance with, the foregoing principles.
4. Lawful Bases for Processing
Overview
Networkd shall ensure that all Processing of Personal Data is supported by a valid Lawful Basis under Article 6(1) of the UK GDPR. The Lawful Basis shall be identified and documented before Processing begins.
Mapping of lawful bases to processing activities
The following table sets out the principal Lawful Bases relied upon by Networkd for its key Processing activities:
| Processing activity | Lawful basis | Justification |
|---|---|---|
| User registration and account creation | Contractual Necessity (Article 6(1)(b)) | Processing is necessary for the performance of the Platform terms of service |
| Founder-investor and mentor matching | Legitimate Interests (Article 6(1)(f)) | Networkd's legitimate interest in operating the Platform's core networking function, balanced against Data Subject rights via a Legitimate Interests Assessment |
| Sending service-related communications | Contractual Necessity (Article 6(1)(b)) | Notifications necessary for the provision of Platform services |
| Marketing and promotional communications | Consent (Article 6(1)(a)) | Data Subjects provide explicit opt-in Consent, which may be withdrawn at any time |
| Identity verification (photo ID collection) | Legal Obligation (Article 6(1)(c)) | Compliance with anti-money laundering, know-your-customer, and fraud prevention requirements |
| Processing bank details for payments | Contractual Necessity (Article 6(1)(b)) | Necessary for the performance of payment obligations under the Platform's terms |
| Event registration and attendance tracking | Legitimate Interests (Article 6(1)(f)) | Networkd's legitimate interest in managing events and ensuring participant safety |
| Internal analytics and Platform improvement | Legitimate Interests (Article 6(1)(f)) | Networkd's legitimate interest in improving the Platform, balanced against Data Subject rights |
| Responding to Data Subject requests | Legal Obligation (Article 6(1)(c)) | Compliance with UK GDPR Data Subject rights provisions |
| Sharing profiles between stakeholder groups | Consent (Article 6(1)(a)) | Data Subjects consent to their profile information being visible to specified stakeholder categories |
Legitimate Interests Assessments
Where Networkd relies on Legitimate Interests as the Lawful Basis for Processing, a Legitimate Interests Assessment shall be conducted and documented before Processing begins. Each Legitimate Interests Assessment shall:
- identify the legitimate interest pursued by Networkd or a third party;
- demonstrate that the Processing is necessary to achieve that interest;
- balance the interest against the rights and freedoms of Data Subjects; and
- be reviewed at least annually, or whenever there is a material change to the Processing activity.
Consent management
Where Consent is relied upon as the Lawful Basis, Networkd shall ensure that:
- Consent is obtained through a clear affirmative act (such as ticking a box or clicking a button) and not through pre-ticked boxes, silence, or inactivity;
- the Data Subject is informed of the specific purposes for which their Personal Data will be processed before providing Consent;
- Consent is freely given, meaning it is not bundled with acceptance of terms and conditions for unrelated Processing;
- a record is maintained of when and how Consent was obtained;
- Data Subjects are informed of their right to withdraw Consent at any time, and the withdrawal mechanism is as easy as the mechanism for giving Consent; and
- where Consent is withdrawn, Networkd shall cease the relevant Processing without undue delay, unless another Lawful Basis applies.
Special Category Data
Networkd does not routinely process Special Category Data. If any Processing of Special Category Data becomes necessary, Networkd shall:
- identify an additional condition for Processing under Article 9(2) of the UK GDPR and, where relevant, Schedule 1 of the DPA 2018;
- obtain explicit Consent from the Data Subject, where the condition relied upon is Consent;
- conduct a DPIA before commencing such Processing; and
- document the additional condition relied upon in the Record of Processing Activities.
5. Types of Personal Data Collected
Categories of Personal Data
Networkd collects and processes the following categories of Personal Data:
- "Identity Data": full name, date of birth, nationality, gender, and professional title;
- "Contact Data": postal address, email address, telephone number, and social media profiles;
- "Financial Data": bank account details, payment card information, and transaction history;
- "Identity Verification Data": copies of photographic identification documents (such as passports and driving licences) provided for verification purposes;
- "Profile Data": biographical information, professional experience, skills, interests, investment preferences, sector focus, and any other information provided by the Data Subject through their Platform profile;
- "Platform Usage Data": log-in times, pages visited, features used, search queries, connection requests, messages sent and received, and event attendance records;
- "Technical Data": IP addresses, browser type and version, device type, operating system, time zone setting, and other technology identifiers collected through cookies and similar technologies;
- "Communication Data": the content and metadata of communications sent to or through the Platform, including emails, messages, and call records; and
- "Event Data": event attendance, dietary requirements (where voluntarily provided), accessibility needs, and event feedback.
Data relating to specific stakeholder groups
The types of Personal Data collected may vary by stakeholder group:
- Founders: Identity Data, Contact Data, Profile Data (including business plans and pitch materials), Financial Data (where fundraising or payments are involved), and Platform Usage Data;
- Mentors: Identity Data, Contact Data, Profile Data (including areas of expertise and availability), and Platform Usage Data;
- Investors: Identity Data, Contact Data, Profile Data (including investment criteria, portfolio information, and sector preferences), Financial Data, Identity Verification Data, and Platform Usage Data; and
- Partners: Identity Data, Contact Data, Profile Data (including organisational information and partnership details), and Platform Usage Data.
6. Data Collection Methods
Methods of collection
Networkd collects Personal Data through the following methods:
- Platform Registration: Personal Data provided by the Data Subject when creating an account on the Platform, including the completion of profile fields and the uploading of identity documents;
- Events and Networking Sessions: Personal Data collected during registration for and attendance at events, workshops, and networking sessions organised or facilitated by Networkd, whether in-person or virtual;
- Direct Communication: Personal Data provided through direct correspondence, including emails, telephone calls, video calls, and in-person meetings;
- Third-Party Integrations: Personal Data received from third-party services integrated with the Platform (such as LinkedIn, CRM systems, and payment processors), subject to the Data Subject's authorisation and the third party's own privacy policies;
- Cookies and Tracking Technologies: Technical Data and Platform Usage Data collected automatically through cookies, web beacons, pixel tags, and similar technologies, in accordance with Networkd's cookie policy; and
- Publicly Available Sources: Personal Data obtained from publicly available sources (such as Companies House records, professional networking sites, and publicly available business registries) for the purpose of verifying identity or supplementing Profile Data.
Transparency at point of collection
At each point of collection, Networkd shall provide the Data Subject with a clear and concise privacy notice containing the information required by Articles 13 and 14 of the UK GDPR, including:
- the identity and contact details of Networkd as Data Controller;
- the contact details of the Data Protection Officer (once appointed);
- the purposes and Lawful Basis for Processing;
- the categories of Personal Data concerned (where data is not obtained directly from the Data Subject);
- any recipients or categories of recipients of the Personal Data;
- details of any International Data Transfers;
- the retention periods or criteria used to determine them; and
- the Data Subject's rights under the UK GDPR.
7. Purposes of Processing
Enumerated purposes
Networkd processes Personal Data for the following purposes:
- Platform Operation and Management: to create and manage user accounts, authenticate users, and provide the core features and functionality of the Platform;
- Matchmaking and Networking: to connect founders with mentors, investors, and partners through the Platform's algorithmic and curated matching features, including recommending connections based on Profile Data and stated preferences;
- Communication: to facilitate communications between Networkd and its stakeholders (including service announcements, updates, and newsletters) and to enable communications between stakeholders on the Platform;
- Event Management: to organise, manage, and facilitate events and networking sessions, including registration, attendance tracking, and post-event follow-up;
- Payment Processing: to process payments, manage subscriptions, and administer billing, including the collection and verification of Financial Data;
- Identity Verification: to verify the identity of stakeholders where required for regulatory compliance (including anti-money laundering and know-your-customer obligations) or fraud prevention;
- Compliance and Legal Obligations: to comply with applicable laws, regulations, and legal processes, including responding to lawful requests from public authorities;
- Analytics and Platform Improvement: to analyse Platform usage trends, improve the user experience, develop new features, and conduct business intelligence;
- Marketing: to send promotional communications and materials to Data Subjects who have provided their Consent, including information about Platform features, events, and partner offerings; and
- Security and Fraud Prevention: to protect the security and integrity of the Platform, detect and prevent fraud, and enforce the Platform's terms of service.
Purpose limitation
Networkd shall not process Personal Data for any purpose that is incompatible with the purposes listed above unless:
- the Data Subject has provided Consent for the new purpose;
- the Processing is required by law; or
- a compatibility assessment has been carried out in accordance with Article 6(4) of the UK GDPR and the new purpose has been determined to be compatible with the original purpose.
8. Data Subject Rights
Overview
The UK GDPR grants Data Subjects a number of rights in relation to their Personal Data. Networkd is committed to facilitating the exercise of these rights in accordance with applicable law.
Rights and procedures
Data Subjects have the following rights:
- Right of Access (Article 15): the right to obtain confirmation as to whether Personal Data concerning the Data Subject is being processed and, where that is the case, access to the Personal Data together with supplementary information as specified in Article 15(1);
- Right to Rectification (Article 16): the right to obtain the rectification of inaccurate Personal Data and, taking into account the purposes of the Processing, the right to have incomplete Personal Data completed;
- Right to Erasure (Article 17): the right to obtain the erasure of Personal Data where one of the grounds set out in Article 17(1) applies, subject to the exceptions in Article 17(3);
- Right to Restriction of Processing (Article 18): the right to obtain the restriction of Processing in the circumstances set out in Article 18(1);
- Right to Data Portability (Article 20): the right to receive Personal Data in a structured, commonly used, and machine-readable format and to transmit that data to another controller, where the Processing is based on Consent or Contractual Necessity and is carried out by automated means;
- Right to Object (Article 21): the right to object, on grounds relating to the Data Subject's particular situation, to Processing based on Legitimate Interests, and the right to object at any time to Processing for direct marketing purposes;
- Right Not to Be Subject to Automated Decision-Making (Article 22): the right not to be subject to a decision based solely on automated Processing, including profiling, which produces legal effects or similarly significantly affects the Data Subject, except where the conditions in Article 22(2) are met; and
- Right to Withdraw Consent: where Processing is based on Consent, the right to withdraw that Consent at any time, without affecting the lawfulness of Processing based on Consent before its withdrawal.
How to exercise rights
Data Subjects may exercise their rights by contacting Networkd at:
- Email: jan@networkd.co.uk
- Post: 71-75 Shelton St, London WC2H 9JQ
- Platform: through the "My Data" or equivalent section within the Data Subject's Platform account settings.
Networkd may request verification of the Data Subject's identity before processing a request.
Response timeframes
Networkd shall respond to Data Subject requests without undue delay and in any event within one calendar month of receipt of the request.
The one-month period may be extended by a further two months where necessary, taking into account the complexity and number of requests received. Networkd shall inform the Data Subject of any such extension within one month of receipt of the request, together with the reasons for the delay.
Where Networkd decides not to take action on a request, it shall inform the Data Subject without delay and at the latest within one month of receipt of the request, providing reasons and informing the Data Subject of the right to complain to the ICO and to seek a judicial remedy.
No fee required
Data Subject requests shall be handled free of charge. However, Networkd may charge a reasonable fee based on administrative costs where requests are manifestly unfounded or excessive, in particular because of their repetitive character, or may refuse to act on the request.
9. Automated Decision-Making and Profiling
Overview
The Platform includes algorithmic features that process Personal Data to recommend connections, suggest matches between founders and investors or mentors, and personalise the user experience. This Section sets out the safeguards Networkd implements in relation to automated decision-making and profiling under Article 22 of the UK GDPR.
Types of automated processing
Networkd employs the following types of automated Processing:
- Founder-Investor Matching: algorithms that analyse Profile Data (including sector focus, investment stage, investment size, and geographic preferences) to suggest potential investor matches for founders and potential deal flow for investors;
- Mentor Matching: algorithms that analyse Profile Data (including areas of expertise, industry experience, and stated mentoring preferences) to suggest mentor-mentee pairings; and
- Content and Connection Recommendations: algorithms that analyse Platform Usage Data and Profile Data to recommend relevant events, content, and connections within the ecosystem.
Safeguards
No decision that produces legal effects concerning a Data Subject, or similarly significantly affects a Data Subject, shall be based solely on automated Processing. All matching and recommendation outcomes are presented as suggestions, and Data Subjects retain full discretion as to whether to act upon them. Networkd shall implement the following safeguards:
- human oversight of all matching and recommendation algorithms, with periodic review of outputs by qualified Personnel;
- the right of any Data Subject to request human intervention in relation to any automated recommendation or matching outcome;
- the right of any Data Subject to express their point of view and to contest an automated outcome;
- transparency regarding the logic involved in automated Processing, provided to Data Subjects through the Platform's privacy notice and upon request; and
- regular audits of automated Processing systems to detect and mitigate bias, inaccuracy, and unfairness.
Data Protection Impact Assessments
Before deploying any new automated decision-making or profiling feature, Networkd shall conduct a DPIA in accordance with Section 15 of this Policy.
10. Data Sharing Between Stakeholder Groups
Principles of data sharing
The core functionality of the Platform depends on the controlled sharing of certain Personal Data between stakeholder groups. This Section sets out the rules governing such sharing.
Profile visibility
When a Data Subject creates a profile on the Platform, they shall be informed of which elements of their profile will be visible to other stakeholders and given the ability to control visibility settings.
The default profile visibility settings shall be set to the minimum level necessary for the Platform's core functionality. Data Subjects may choose to increase their profile visibility.
Sharing scenarios
Personal Data may be shared between stakeholder groups in the following circumstances:
- Founder-Investor Matching: limited Profile Data (such as name, business summary, sector, and investment stage) may be shared between founders and investors where both parties have been matched by the Platform or have expressed mutual interest;
- Mentor-Founder Matching: limited Profile Data (such as name, areas of expertise, and industry experience) may be shared between mentors and founders where both parties have been matched or have expressed mutual interest;
- Event Participation: limited Identity Data and Contact Data (such as name and professional title) may be shared among event participants for networking purposes, subject to the Data Subject's Consent at the point of event registration;
- Partner Introductions: limited Profile Data may be shared with partners where the Data Subject has opted in to partner engagement programmes; and
- Aggregated and Anonymised Data: anonymised or aggregated data that does not constitute Personal Data may be shared with any stakeholder group for analytical or reporting purposes.
Consent and control
Where data sharing between stakeholder groups is based on Consent:
- Consent shall be obtained at the point of profile creation, event registration, or before the sharing takes place;
- Consent shall be granular, allowing the Data Subject to choose which categories of data are shared and with which stakeholder groups;
- Data Subjects shall be able to withdraw Consent and modify their sharing preferences at any time through the Platform's account settings; and
- withdrawal of Consent shall be given effect without undue delay.
Data sharing agreements
Where Networkd shares Personal Data with external partners or third parties (as opposed to between Platform users), Networkd shall enter into appropriate data sharing agreements that:
- specify the purposes and Lawful Basis for the sharing;
- define the categories of Personal Data to be shared;
- impose obligations of confidentiality and data security on the recipient;
- restrict the recipient from processing the Personal Data for purposes other than those specified; and
- provide for the return or deletion of Personal Data upon termination of the arrangement.
11. International Data Transfers
General principle
Networkd shall not transfer Personal Data to a country or territory outside the United Kingdom unless one of the conditions set out in Chapter V of the UK GDPR is satisfied.
Transfer mechanisms
Networkd may rely on the following mechanisms for International Data Transfers:
- Adequacy Decisions: the Secretary of State has determined that the recipient country or territory ensures an adequate level of protection for Personal Data (Article 45 of the UK GDPR);
- Standard Contractual Clauses: the International Data Transfer Agreement (IDTA) issued by the ICO, or the International Data Transfer Addendum to the EU Standard Contractual Clauses (Article 46(2)(c) of the UK GDPR);
- UK Extension to the EU-US Data Privacy Framework: for transfers to certified organisations in the United States, reliance on the UK Extension to the EU-US Data Privacy Framework as recognised under the UK's adequacy regulations; and
- Derogations: in limited circumstances, reliance on the derogations set out in Article 49 of the UK GDPR, including explicit Consent or necessity for the performance of a contract.
Transfer impact assessments
Before relying on Standard Contractual Clauses or other Appropriate Safeguards, Networkd shall conduct a Transfer Impact Assessment to evaluate whether the laws and practices of the recipient country provide an adequate level of protection, taking into account:
- the nature of the Personal Data being transferred;
- the purposes of the transfer;
- the legal framework of the recipient country (including government access laws);
- the existence of enforceable Data Subject rights;
- the effectiveness of the chosen transfer mechanism; and
- any supplementary measures that may be required.
Record-keeping
Networkd shall maintain a register of all International Data Transfers, recording:
- the recipient country or territory;
- the identity of the recipient;
- the categories of Personal Data transferred;
- the purposes of the transfer;
- the transfer mechanism relied upon; and
- the date and outcome of any Transfer Impact Assessment.
Sub-Processor transfers
Where a Sub-Processor is located outside the United Kingdom or transfers Personal Data internationally, Networkd shall ensure that the Sub-Processor has implemented Appropriate Safeguards in accordance with this Section.
12. Data Retention
General principle
Networkd shall not retain Personal Data for longer than is necessary for the purposes for which it was collected, in accordance with the Storage Limitation principle.
Retention periods
The following retention periods apply:
| Data category | Retention period | Justification |
|---|---|---|
| Identity Data and Contact Data (active users) | Duration of the account plus 12 months | Necessary for account management and to allow for re-activation |
| Identity Data and Contact Data (inactive users) | 24 months after last Platform activity | Legitimate interest in re-engagement; deleted thereafter |
| Financial Data (transaction records) | 7 years from the date of the transaction | Compliance with HMRC requirements and Limitation Act 1980 |
| Identity Verification Data (photo ID) | Duration of the verification process plus 12 months, or as required by anti-money laundering legislation | Minimum retention necessary for verification; longer where legally required |
| Profile Data | Duration of the account plus 12 months | Deleted when the account is closed, subject to the re-activation period |
| Platform Usage Data | 24 months from the date of collection | Necessary for analytics and Platform improvement |
| Technical Data (logs) | 12 months from the date of collection | Necessary for security monitoring and incident investigation |
| Communication Data | 36 months from the date of the communication | Necessary for dispute resolution and regulatory compliance |
| Event Data | 24 months from the date of the event | Necessary for event analytics and follow-up |
| Marketing Consent records | Duration of Consent plus 24 months after withdrawal | To evidence that Consent was validly obtained |
The retention periods set out above represent industry-standard defaults considered reasonable for a platform of this nature. Networkd shall review and, where necessary, adjust these periods based on operational requirements, legal advice, and regulatory guidance.
Deletion and anonymisation
Upon expiry of the applicable retention period, Networkd shall:
- securely delete the Personal Data using methods that render it irrecoverable; or
- anonymise the Personal Data such that it can no longer be attributed to a specific Data Subject, in which case the anonymised data may be retained for analytical purposes.
Litigation hold
Where Networkd is aware of actual or reasonably anticipated litigation, regulatory investigation, or audit, it shall suspend the deletion of relevant Personal Data until the matter is resolved, regardless of the applicable retention period.
13. Data Security Measures
Overview
Networkd shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the UK GDPR.
Technical measures
Networkd shall implement the following technical measures:
- Encryption: encryption of Personal Data in transit (using TLS 1.2 or higher) and at rest (using AES-256 or equivalent industry-standard encryption);
- Access Controls: role-based access controls ensuring that Personnel can access only the Personal Data necessary for their role, with multi-factor authentication required for access to systems containing Personal Data;
- Pseudonymisation: pseudonymisation of Personal Data where feasible, to reduce the risks associated with Processing;
- Network Security: firewalls, intrusion detection and prevention systems, and network segmentation to protect systems containing Personal Data;
- Vulnerability Management: regular vulnerability scanning and penetration testing of Platform infrastructure, with prompt remediation of identified vulnerabilities;
- Secure Development: adherence to secure software development practices, including code review, security testing, and dependency management;
- Backup and Recovery: regular encrypted backups of Personal Data with tested disaster recovery procedures to ensure the ability to restore availability and access in the event of a physical or technical incident; and
- Logging and Monitoring: audit logging of access to Personal Data and security events, with real-time monitoring for anomalous activity.
Organisational measures
Networkd shall implement the following organisational measures:
- Information Security Policy: maintenance of an information security policy that is communicated to all Personnel;
- Confidentiality Obligations: all Personnel and contractors who process Personal Data shall be bound by contractual confidentiality obligations;
- Access Reviews: periodic reviews of access rights to ensure that access is appropriate and promptly revoked upon change of role or termination of engagement;
- Incident Response Plan: maintenance of a documented incident response plan aligned with the Data Breach notification procedures in Section 14;
- Physical Security: where Personal Data is stored on premises, physical access controls (including locked server rooms and visitor management); and
- Supplier Security: assessment of the security practices of Sub-Processors and third-party service providers before engagement and on an ongoing basis.
Regular testing and evaluation
Networkd shall regularly test, assess, and evaluate the effectiveness of its technical and organisational measures, including through:
- annual penetration testing by a qualified independent assessor;
- periodic internal security audits;
- tabletop exercises simulating Data Breach scenarios; and
- review and update of security measures following any Data Breach or significant security incident.
14. Data Breach Notification
Detection and reporting
All Personnel shall report any actual or suspected Data Breach to the Data Protection Officer (or, until a DPO is appointed, to the designated data protection lead) immediately upon becoming aware of it.
Networkd shall maintain a Data Breach register recording all Data Breaches, including those that do not require notification to the ICO.
Assessment
Upon receiving a report of a Data Breach, Networkd shall promptly:
- assess the nature and scope of the breach;
- identify the categories and approximate number of Data Subjects affected;
- identify the categories and approximate number of Personal Data records affected;
- assess the likely consequences of the breach for Data Subjects; and
- determine the measures taken or proposed to address the breach and mitigate its effects.
Notification to the ICO
Where a Data Breach is likely to result in a risk to the rights and freedoms of natural persons, Networkd shall notify the ICO without undue delay and, where feasible, not later than 72 hours after becoming aware of the breach, in accordance with Article 33 of the UK GDPR. The notification to the ICO shall include:
- a description of the nature of the Data Breach, including the categories and approximate number of Data Subjects and Personal Data records affected;
- the name and contact details of the Data Protection Officer (or designated contact point);
- a description of the likely consequences of the breach; and
- a description of the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects.
Where it is not possible to provide all information at the time of notification, information may be provided in phases without undue further delay.
Communication to Data Subjects
Where a Data Breach is likely to result in a high risk to the rights and freedoms of natural persons, Networkd shall communicate the breach to the affected Data Subjects without undue delay, in accordance with Article 34 of the UK GDPR. The communication shall:
- describe the nature of the breach in clear and plain language;
- provide the name and contact details of the Data Protection Officer (or designated contact point);
- describe the likely consequences of the breach; and
- describe the measures taken or proposed to address the breach, including measures the Data Subject can take to protect themselves.
Processor breach notification
Where Networkd acts as Data Processor, it shall notify the Data Controller of any Data Breach without undue delay after becoming aware of it.
Post-breach review
Following any Data Breach, Networkd shall conduct a post-breach review to:
- identify the root cause of the breach;
- evaluate the effectiveness of the response;
- identify any improvements to technical or organisational measures; and
- update this Policy, the incident response plan, and training materials as necessary.
15. Data Protection Impact Assessments
When a DPIA is required
Networkd shall carry out a DPIA before commencing any Processing that is likely to result in a high risk to the rights and freedoms of natural persons, in accordance with Article 35 of the UK GDPR. A DPIA shall be required in the following circumstances, without limitation:
- the introduction of new automated decision-making or profiling features on the Platform;
- large-scale Processing of Special Category Data or criminal offence data;
- systematic monitoring of publicly accessible areas;
- Processing that involves innovative use of technology or novel Processing methods;
- Processing that involves International Data Transfers to countries without an Adequacy Decision; and
- any other Processing identified as requiring a DPIA under ICO guidance or the UK GDPR.
DPIA process
Each DPIA shall:
- contain a systematic description of the proposed Processing, including its purpose and the Lawful Basis;
- assess the necessity and proportionality of the Processing in relation to the purpose;
- identify and assess the risks to the rights and freedoms of Data Subjects;
- identify the measures envisaged to address those risks, including safeguards, security measures, and mechanisms to ensure the protection of Personal Data; and
- document the views of Data Subjects or their representatives, where appropriate.
Consultation
Where a DPIA indicates that the Processing would result in a high risk in the absence of measures taken to mitigate the risk, Networkd shall consult the ICO before commencing the Processing, in accordance with Article 36 of the UK GDPR.
Review
Networkd shall review DPIAs at regular intervals and whenever there is a material change to the Processing activity to which the DPIA relates.
16. Sub-Processor Management
Engagement of Sub-Processors
Networkd shall not engage any Sub-Processor to process Personal Data without first:
- conducting appropriate due diligence on the Sub-Processor's technical and organisational security measures, data protection practices, and financial standing;
- entering into a written contract with the Sub-Processor that imposes data protection obligations equivalent to those set out in this Policy and in any applicable data processing agreement; and
- obtaining, where Networkd is acting as Data Processor, the prior specific or general written authorisation of the Data Controller.
Contractual requirements
Each Sub-Processor contract shall include, at a minimum:
- the subject matter, duration, nature, and purpose of the Processing;
- the types of Personal Data and categories of Data Subjects;
- the obligations and rights of Networkd as the instructing party;
- an obligation on the Sub-Processor to process Personal Data only on documented instructions from Networkd;
- obligations of confidentiality for all persons authorised to process the Personal Data;
- appropriate technical and organisational measures to protect Personal Data;
- conditions for engaging further Sub-Processors;
- obligations to assist Networkd in fulfilling its obligations to respond to Data Subject requests;
- obligations to assist Networkd in ensuring compliance with Articles 32 to 36 of the UK GDPR;
- an obligation to delete or return all Personal Data upon termination of the sub-processing arrangement; and
- provisions for audits and inspections by Networkd or its appointed auditors.
Approved Sub-Processor list
Networkd shall maintain a list of approved Sub-Processors, including:
- the name and contact details of each Sub-Processor;
- the Processing activities performed by each Sub-Processor;
- the location(s) of Processing;
- the transfer mechanism relied upon (where applicable); and
- the date of the most recent due diligence review.
The approved Sub-Processor list shall be reviewed at least annually.
Monitoring
Networkd shall monitor Sub-Processor compliance through:
- periodic review of Sub-Processor security certifications and audit reports;
- conducting or commissioning audits of Sub-Processors where warranted by risk; and
- requiring prompt notification by the Sub-Processor of any Data Breach or material change to its processing operations.
17. Data Protection Officer
Appointment
Networkd shall appoint a Data Protection Officer where required by Article 37 of the UK GDPR, or where it determines that appointment is appropriate having regard to the nature, scope, and context of its Processing activities.
As at the date of this Policy, Networkd has not yet appointed a DPO. Networkd shall complete the appointment of a DPO (whether an internal employee or an external service provider) within three months of the Effective Date, or within three months of reaching a processing volume that triggers the mandatory appointment requirement under Article 37, whichever is earlier.
Pending appointment of a DPO, the data protection lead designated by the senior management of Networkd shall assume interim responsibility for overseeing compliance with this Policy.
Role and responsibilities
The DPO shall:
- inform and advise Networkd and its Personnel of their obligations under the UK GDPR and the DPA 2018;
- monitor compliance with the UK GDPR, the DPA 2018, and this Policy, including awareness-raising, training, and audits;
- provide advice on DPIAs and monitor their performance;
- act as the contact point for the ICO on issues relating to Processing;
- act as the contact point for Data Subjects on all matters relating to the exercise of their rights;
- have due regard to the risk associated with Processing operations; and
- report directly to the highest management level of Networkd on data protection matters.
Independence and resources
The DPO shall:
- not receive instructions regarding the exercise of their tasks;
- not be dismissed or penalised for performing their tasks;
- be provided with the resources necessary to carry out their tasks and to maintain their expert knowledge; and
- be involved, properly and in a timely manner, in all issues relating to the protection of Personal Data.
18. Staff Training and Awareness
Training requirements
Networkd shall ensure that all Personnel who process Personal Data receive appropriate data protection training.
Training programme
The training programme shall include:
- Induction Training: all new Personnel shall receive data protection training as part of their induction, to be completed within 30 days of commencement;
- Annual Refresher Training: all Personnel shall complete annual refresher training on data protection principles, this Policy, and their specific responsibilities;
- Role-Specific Training: Personnel in roles with heightened data protection responsibilities (including those handling Financial Data, Identity Verification Data, or Data Breach response) shall receive additional role-specific training; and
- Ad Hoc Training: additional training shall be provided following material changes to data protection legislation, this Policy, or Processing activities.
Training records
Networkd shall maintain records of all data protection training, including:
- the name and role of each attendee;
- the date and content of the training;
- the training provider; and
- confirmation of completion or assessment results.
Awareness
Networkd shall promote awareness of data protection through:
- making this Policy accessible to all Personnel;
- regular communications on data protection topics;
- clear internal guidance on how to handle common data protection scenarios (such as Data Subject requests and Data Breach reporting); and
- designated data protection champions within each team, where the organisational structure permits.
19. Record of Processing Activities
Obligation
Networkd shall maintain a Record of Processing Activities as required by Article 30 of the UK GDPR.
Controller record
Where Networkd acts as Data Controller, the ROPA shall contain:
- the name and contact details of Networkd and, where applicable, the DPO;
- the purposes of the Processing;
- a description of the categories of Data Subjects and the categories of Personal Data;
- the categories of recipients to whom Personal Data has been or will be disclosed, including recipients in third countries;
- details of International Data Transfers, including the transfer mechanism relied upon;
- the envisaged time limits for erasure of the different categories of data; and
- a general description of the technical and organisational security measures in place.
Processor record
Where Networkd acts as Data Processor, the ROPA shall contain:
- the name and contact details of Networkd, the Data Controller on whose behalf Processing is carried out, and, where applicable, the DPO;
- the categories of Processing carried out on behalf of the Data Controller;
- details of International Data Transfers, including the transfer mechanism relied upon; and
- a general description of the technical and organisational security measures in place.
Maintenance and availability
The ROPA shall be maintained in writing (including electronic form) and shall be made available to the ICO upon request.
Networkd shall review and update the ROPA at least quarterly, and whenever there is a material change to Processing activities.
20. Policy Review and Updates
Review frequency
This Policy shall be reviewed:
- at least annually from the Effective Date;
- following any material Data Breach;
- following any material change to data protection legislation or ICO guidance;
- following any significant change to Networkd's Processing activities, organisational structure, or technology infrastructure; and
- as otherwise directed by the DPO or senior management.
Version control
Networkd shall maintain a version history for this Policy, recording:
- the version number;
- the date of each revision;
- a summary of changes made; and
- the name of the person who approved the revision.
Communication of changes
Material changes to this Policy shall be communicated to:
- all Personnel, through internal communications and training updates;
- Data Subjects, through updates to the privacy notice on the Platform; and
- Data Controllers (where Networkd acts as Data Processor), through direct written notification.
21. Complaints and Enforcement
Internal complaints
Any Data Subject who wishes to raise a complaint about how their Personal Data is processed by Networkd may do so by contacting:
- Email: jan@networkd.co.uk
- Post: 71-75 Shelton St, London WC2H 9JQ
Networkd shall acknowledge receipt of a complaint within five Business Days and provide a substantive response within 30 calendar days.
Escalation
If the Data Subject is not satisfied with Networkd's response, they may escalate the complaint to:
- the Data Protection Officer (once appointed); and
- the senior management of Networkd for further review.
ICO complaint
Data Subjects have the right to lodge a complaint with the ICO at any time. The ICO's contact details are:
- Website: ico.org.uk
- Telephone: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Judicial remedy
Data Subjects also have the right to seek a judicial remedy, including compensation for damage suffered as a result of a breach of the UK GDPR, in the courts of England and Wales.
Internal enforcement
Failure by any Personnel to comply with this Policy may result in disciplinary action, up to and including termination of employment or engagement.
Networkd shall investigate all reported or suspected violations of this Policy and take appropriate corrective action.
