This Privacy Policy explains how CritiCall Ops Ltd (company number
17364960, registered in England and Wales) (“we”,
“us”) handles personal data when you use our website, contact us, or
use the CritiCall Ops platform. Contact:
contact@criticallops.co.uk.
Registered office: 66 Paul Street, London EC2A 4NA.
1. Roles
CritiCall Ops Ltd provides the software and runs it on UK servers we own and
operate. We do not use operational data (incidents, deployments, staff names, messages, and
similar content) for our own purposes — we process it on the instructions of the customer
organisation that registered.
We are the controller only for our own business data: website and enquiry / demo interest,
account administration contacts, optional marketing sign-ups, and billing records.
For operational data your organisation enters into the platform, your organisation is the
controller and we act as processor. The organisation that signed up holds the
primary responsibility for lawful basis, privacy notices, staff training, retention, and—where the
law requires it—registration with the ICO under the Data Protection (Charges and Information)
Regulations 2018 for operational data it controls.
2. Data we collect
- Contact form: name, organisation, sector, email, message, pilot interest
- Enquiry / demo interest (including any legacy trial request submissions still held): name, organisation, sector, email, team size, notes
- Optional pilot updates: work email if you opt in via the Mailchimp signup on the contact page
- Accounts: login email, name, role, security and audit logs
- Service: operational content submitted by customers and users
- Technical: IP address, browser/device data for security
- Marketing site: if enabled, Meta Pixel for page views and enquiry conversions
- Live chat: messages you send via the Tawk.to widget on this website
- Billing: billing contact details where invoicing applies
3. Why we use it
Contract performance, legitimate interests (security, product operation, B2B communication), legal obligation, and consent where required.
4. Sharing
We use UK hosting and email providers, Stripe for invoicing and card payments (when you pay online), Mailchimp for optional product-update emails when you opt in on the contact page, Meta (Facebook) for website analytics when the Meta Pixel is enabled, and Tawk.to for live chat on the marketing site. We do not sell personal data.
5. Retention
Enquiries: up to 24 months; billing: up to 7 years where required; platform data: subscription term plus reasonable period after termination unless export or law requires longer.
6. Your rights
UK GDPR rights include access, rectification, erasure, restriction, objection, and portability.
Contact us at
contact@criticallops.co.uk
in the first instance. Platform users should also contact their organisation as controller for
operational data held in the service.
If you remain dissatisfied, you may complain to the UK Information Commissioner's Office (ICO):
ico.org.uk/make-a-complaint.
Platform users should contact their organisation as controller for operational data held in the service.
7. Data protection fee (ICO)
Under the Data Protection (Charges and Information) Regulations 2018, organisations
that process personal information as a controller must pay a data protection fee to the
Information Commissioner's Office (ICO) unless an exemption applies. Organisations
that have paid appear on the ICO's public register of fee payers.
We have used the ICO's
registration self-assessment
and confirmed that CritiCall Ops Ltd is exempt for our current controller activities.
That matches ICO guidance: you do not need to pay a fee if you process personal data only for one or more
of the exempt purposes, such as advertising, marketing and public relations in respect of
your own activities, and accounts and records.
How that applies here:
-
Processor. We provide the software on UK servers we own and operate and process
operational data only on the instructions of the customer organisation that registered. We do not
decide why or how that data is used.
-
Controller (your organisation). The organisation that registered for CritiCall Ops is
typically the controller of operational data entered into the platform. It is responsible for its own
lawful basis, privacy notices, and—where the law requires it—its own ICO registration for
that processing.
-
Controller (CritiCall Ops Ltd). We act as controller only for website and enquiry /
demo interest, account administration contacts, and billing records — processing that falls within
the ICO's exempt purposes above (promoting our own services and keeping our own accounts and
records). Legacy trial request submissions (where already received) are handled on the same basis.
As the ICO states: even if you are exempt from paying a fee, you still need to comply with your
other data protection obligations. We meet our UK GDPR and Data Protection Act 2018 duties as
processor and as controller for the limited data we control, including security, processing on documented
instructions, and data subject rights. See our Security & data protection
page and, where required, our data processing agreement.
We will repeat the ICO self-assessment if our controller processing changes materially. Further detail:
ICO exemptions guidance.
8. Cookies
Essential cookies and session storage for security and login. No non-essential advertising cookies at launch.
9. Security
Technical and organisational measures for our servers, encryption, backups, and access control are
described on our
Security & data protection page.
10. Changes
We may update this page with a new “Last updated” date. See also our Terms and Conditions.