Privacy Policy
8Employ Ltd
Version 3.1 · 8Employ Ltd
8Employ Ltd, registered in England and Wales, company number 17082344. Registered office: as filed at Companies House. Registered with the Information Commissioner's Office (ICO), registration number ZC104872. We trade as 8Employ; our product is called Eira.
For anything in this policy, including any request about your own information, email support@8employ.uk. We have not appointed a Data Protection Officer and are not required to.
This policy sits alongside the two documents you accept when you join a pilot: the Pilot Agreement (https://8employ.uk/pilot-agreement) and the Data Processing Agreement (https://8employ.uk/data-processing-agreement). Those you agree to. This one is for information.
In short
- We turn your venue's sales data into a weekly report, delivered to your portal and your inbox.
- To write it we send your figures, your notes and your venue's public Google reviews to Anthropic, an AI company in the United States. Anthropic's contract says it does not train on them and deletes them within 30 days.
- We also learn from your data to improve the product. We do not use your Google reviews for that. Tell us to stop and you still get your reports.
- We show your reports to prospective customers only if you ticked the separate optional box.
- We do not want your customers' personal information and ask you not to send it.
- If your till sends us staff names, or you type them into notes, tell your staff: section 2a is for them.
- We keep your data while you are with us, apart from a record of what you agreed to. Ask us to delete it and we do it by hand within 30 days.
- Complain to us first if you like: we acknowledge within 30 days. You can also go straight to the ICO.
- Google reviewers: section 14 is written for you.
1. Who we are, and who is in charge of your data
8Employ Ltd is a three-person company in Swansea, Wales. We provide a weekly business intelligence report and a client portal to independent cafes, pubs and restaurants.
"You" in this policy means the business that uses Eira. Where that business is a limited company, the owner or manager who deals with us is the company's contact, and the parts of this policy about names, email addresses and sign-in details are about them personally.
The law splits responsibility in two. A controller decides why and how information is used; a processor uses it on someone else's instructions. We are both, at different moments, and would rather say so than pretend otherwise.
- Producing your weekly report from your data: we are your processor, acting on your instructions, which the Data Processing Agreement sets out.
- Improving the product, collecting your venue's Google reviews, holding your contact details, and showing your figures to a prospective customer with your permission: we are the controller.
Roles follow the facts, not the labels. You are under no legal obligation to give us your data, but without a data connection there is no report.
2. What information we collect
If you are a venue owner, manager or contact
Your name, business name and trading address, email address, and a phone number if you give us one. If you use the portal we hold your sign-in details: a password stored as a scrambled value we cannot reverse, or a magic-link token sent to your email.
We also record your acceptance of the Pilot Agreement, the Data Processing Agreement and the optional demo box: the wording shown to you, the version, the date and time in UTC, and the IP address it came from. The law expects us to be able to show what you agreed to.
Your business data
Sales and transaction totals, trading hours, covers, product and menu lines, discounts, payment methods, waste and stock figures where your till records them, bookings and no-shows, and financial summaries from your accounting platform if you connect one.
We do not seek your individual customers' personal information and ask you not to send it. Card and till feeds give us amounts, dates and product names, not cardholders. One thing that may surprise you: when you connect Square, its permission screen asks us to approve customer and loyalty access as part of the standard set. We never call those parts of Square and hold no customer records from it.
Two honest exceptions to "no personal information":
- Staff names, in three ways. If your till is Square, its team member and shift records are stored with your report data; they are not used in the analysis and are never sent to the AI. If you name a member of staff in a note you type into the portal, that note goes to the AI with your next report. If a Google reviewer names a member of staff, the review and the suggested reply may name them. You are responsible for telling your staff; section 2a is written for them.
- Anything you type or upload can contain whatever you put in it.
Notes you type into the portal
Your Sunday check-in note, your answers to our questions, and your day notes. These are used in your report, and they also go into next week's AI prompt so the report picks up where you left off.
Google reviewers
Where your venue has a Google listing we collect the reviewer's public display name, star rating, review text and date, for up to five reviews Google returns for that venue. Google chooses which five, usually the ones it thinks most relevant. Not profile links or photos. Section 14 is the notice for reviewers.
Website visitors and waitlist sign-ups
Your name and email address, and whatever you write to us. Section 8 has the detail.
Security records
When anyone signs in to our admin system or your portal we store the session token, IP address, user-agent string and time, and the same for failed sign-ins, portal page visits and an audit log of administrative actions. These sit on disk in our database. They are not held only in memory; our previous policy said they were, and that was wrong.
Our application and web-server logs record activity too, and those entries can include your email address and the sign-in links we sent you. Section 11 says how long they last.
2a. If you work at a venue that uses Eira
Your employer may have connected a till that sends us your name and shift times (today only Square does), typed your name into a note, or a customer may have named you in a Google review. Your employer decides to share that and is responsible for telling you; we hold it on their instructions to produce their report.
We also use the data we hold, which can include those notes, to improve the product (section 6). For that we are the controller, on the basis of legitimate interests, and this section is your notice. Names in notes and reviews reach Anthropic in the United States as part of writing the report (sections 5 and 10); Square records do not. We keep it for as long as your employer's reports exist (section 11). We build nothing about you and never contact you.
Email support@8employ.uk to see what we hold, have it corrected or deleted, or to object; the timings in section 13 apply, and you can complain under section 19.
3. Where your information comes from
From you: the setup wizard, the portal, spreadsheets and CSV files you upload, and emails you send us.
From your till, card or accounting provider: we connect to the accounts you authorise, which today means SumUp, GoodTill, Square, EposNow, Xero and Dojo. Where there is no usable connection, you send us a weekly export or spreadsheet and one of us loads it by hand and maps it into the same format. You authorise every connection through the provider's own consent screen or by giving us a key, and can revoke it whenever you like. When you do, we stop using that source from the next scheduled run and do not attempt to reconnect.
From Google: we query the Google Places API with your venue's name and location to fetch a small number of its recent public reviews, which we use to draft insights and suggested replies.
4. Why we use your information, and our lawful basis
| What we do | Lawful basis | Information used |
|---|---|---|
| Produce and deliver your weekly report and run your portal | We are your business's processor for this. Your business decides its own lawful basis and instructs us through the Data Processing Agreement | Business data, portal notes |
| Run your account: sign you in, send reports, sign-in links and service emails, record what you agreed to | Contract, Art 6(1)(b), where you are the business. Where your business is a company and you are its contact, legitimate interests, Art 6(1)(f): ours and your business's in running the service it asked for | Name, email, sign-in details, consent record |
| Collect and analyse your venue's public Google reviews, and draft replies | Legitimate interests, Art 6(1)(f) | Reviewer name, rating, review text, date |
| Improve Eira: testing, tuning, checking outputs, comparing across venues | Legitimate interests, Art 6(1)(f) | Business data, reports |
| Keep the platform secure: sign-in records, rate limiting, audit log, bot checks | Legitimate interests, Art 6(1)(f) | IP address, user-agent, usernames, timestamps |
| Answer your emails and support requests | Legitimate interests, Art 6(1)(f) | Name, email, message content |
| Show your reports or figures to prospective customers | Consent, Art 6(1)(a): the optional box | Whatever the report contains |
| Contact you after a waitlist sign-up | Consent, Art 6(1)(a) | Name, email |
| Meet our tax and company law duties | Legal obligation, Art 6(1)(c) | Financial records, contact details |
The interests we rely on, specifically: ours and your business's in running the account you asked for; your interest in answering your reviews and ours in providing that feature; ours in building a product that works (section 6); both of ours in keeping the platform secure; and ours in replying to someone who wrote to us. You can object to any of them (section 13).
Where we rely on consent you can withdraw it at any time by emailing support@8employ.uk. Withdrawing is as easy as giving it, does not make anything lawful beforehand unlawful, and does not affect your service.
5. How we use AI
Your data is sent to an AI provider. To write your report we send your figures, your notes and your venue's public Google reviews to Anthropic, an AI company based in the United States, using its Claude service. Anthropic's contract with us says it acts on our instructions, does not use what we send to train its models, and deletes it within 30 days unless its safety systems flag it or the law requires it to keep it longer.
What we send. Daily sales figures, menu lines and margins, waste, bookings and no-shows, your business name, the public review text and reviewer names for your venue, the notes you typed into the portal since the last report, and the short notes we keep about how you like your report, which can refer to you by name. We never send your email address, and the only place your name could appear is in those notes.
What the AI does. It reads the numbers, writes the summary and observations, and suggests things you might do. A second AI step checks that work against the same figures before anything reaches you; that check is part of producing your report. Where you have reviews it also drafts suggested replies, written in your voice as the owner; if a reviewer named a member of your staff, the draft may name them too. We never post anything to Google. You decide whether to use a draft, change it or ignore it.
Nothing the AI produces decides anything about anybody. It has no legal effect and no similarly significant effect on you, your staff or your customers. The rules on automated decisions (Articles 22A to 22D of the UK GDPR, as changed on 5 February 2026) bite only where a significant decision is made without meaningful human involvement. Our reports are advice; a person at your venue decides what to do with them.
What we actually operate, and nothing more. One of us reads your first report before it is released; after that, each week's report passes an approval check before you see it. Ask, and one of us will go through any part of a report with you. Ask, and we will produce your reports with no AI analysis at all.
6. How we learn from your data
We learn from your data. As well as producing your reports, we use what we learn from your data to improve how Eira works for everyone: testing changes against past weeks, tuning the instructions we give the AI, checking whether the output was any good, and comparing patterns across venues. We never show your figures to another venue. We do not use your Google reviews for this.
This is our own purpose, not something we do on your instructions, so we are the controller for it and rely on legitimate interests.
How it is kept separate from your weekly report. The checks that run while your report is being written — the second AI step and the quality gate — are part of producing your report, and we do them as your processor. The improvement work happens afterwards, outside the weekly run, on copies of past report data. It is a job a person starts, not something that happens automatically.
The limits we work to:
- One venue never sees another venue's figures.
- Access to client data is limited to the three of us.
- Anything we publish about what we learn across venues is aggregated so no venue and no person can be identified.
- We have decided not to use data from Square or Xero connections, or Google review content, for improvement work — Square's and Xero's terms restrict it, and we have taken reviews out of it entirely. Neither pilot uses Square or Xero today; before we connect either one for you we will have a way of keeping that data out of this work.
You can object. Email support@8employ.uk and we stop using your data for product improvement. We keep a written exclusion list; one of us checks it before any evaluation, backtest or comparison run. If you object we add your venue within 30 days and record the date. Your weekly report carries on exactly as before.
7. Showing your reports as an example
Being an example is your choice. We only show your reports or figures to prospective customers if you ticked the separate, optional box when you signed up. Leaving it unticked changes nothing at all about your service.
The box says, word for word:
"I'm happy for 8Employ to show my reports and figures to prospective customers as an example of their work. (Optional — everything works exactly the same if you leave this unticked.)"
If you did tick it, we may show your report, figures and venue name to people considering the service. Before we show anything we remove the reviews section from it.
Change your mind at any time by emailing support@8employ.uk. Within 7 days we stop using your material in anything new. We cannot pull back something already printed or sent to somebody, and we will tell you if that applies.
8. If you visit our website or join the waitlist
The waitlist form. We store your name, email address, the status of your entry and any notes we add. The basis is your consent, and we use it to contact you about the service and nothing else. Reply to any message, or email support@8employ.uk, and we will take you off.
Emailing us. Messages to support@8employ.uk arrive in our Google Workspace inbox and become a support ticket holding your name, email address, subject and full message. We do not add you to a marketing list without asking.
Bot checks. Cloudflare Turnstile may be used on our public forms to check a submission comes from a person rather than a bot. Cloudflare sees your IP address and some technical signals from your browser to make that judgement. It does not see what you typed into the form.
Fonts and icons. Our pages load web fonts from Google's servers, and some load an icon library from unpkg, a public code delivery network. When your browser fetches those files, your IP address and basic browser details are disclosed to those providers.
Traffic. Cloudflare sits in front of our site and portal, so it sees every request, including IP addresses. We look only at the totals it reports back: requests, page views, unique visitors. We run no advertising, analytics or tracking cookies and build no profiles of visitors.
9. Who else sees your information
We do not sell, rent or trade personal information. The companies in this table handle it for us, on our instructions, and we have a written data protection contract with each of them.
| Who | What they do for us | What they see | Where |
|---|---|---|---|
| Anthropic (Claude API) | Writes and checks your report, drafts review replies | Business figures, portal notes, review text and reviewer names | Contract with Anthropic Ireland Limited; stored in the USA |
| Resend | Sends report emails and PDFs, sign-in links, service emails | Recipient name and email, report content and attachment | USA |
| Cloudflare | Routes and secures traffic, DNS, bot checks | IP addresses, request details, bot-check signals | Global edge; USA and Europe |
| Google Workspace (Google Cloud EMEA Limited, Ireland) | Our company email and support inbox | Anything you email us | Google's global infrastructure |
| 8Employ's own equipment | Runs the system, holds the data | Everything, at rest | Our premises in Swansea, UK |
A tool that receives no personal data about you. When a report run fails, or is waiting for us to approve it, we send ourselves an alert through Slack. It carries a client identifier and an error message. It is not designed to include any name, email address or other personal data about you; if one ever did, we would treat that as a breach under section 16.
We do not run on a public cloud. If we add or change a sub-processor we email you at least 30 days beforehand and you can object; the Data Processing Agreement says what happens then.
Data sources and other controllers
These are not our sub-processors. They are either your own suppliers, chosen and authorised by you, or organisations that decide for themselves what to do with information.
| Who | What they are | What passes | Who is in charge |
|---|---|---|---|
| SumUp, GoodTill, Square, EposNow, Xero, Dojo, ICRTouch and similar | Your till, card or accounting providers | Your sales and financial data, on your authorisation | Your suppliers, under your contract with them |
| Google (Places API) | Source of your venue's public reviews | Your venue's name and location go out as a query; the public reviews come back | Google, as an independent controller under its own terms |
We may also disclose information if the law, a regulator or a court requires it, or to establish or defend legal claims.
10. Sending information outside the UK
Some of the companies above are outside the UK. The law allows that where one of a small number of protections is in place. Here is which applies to whom.
| Recipient | Country | How the transfer is protected |
|---|---|---|
| Anthropic | Ireland (our contract), stored in the USA | Ireland is covered by UK adequacy. For the US storage, Anthropic's terms include the EU standard contractual clauses with the ICO's UK Addendum, and we rely on those whether or not Anthropic is certified under the UK Extension to the EU-US Data Privacy Framework |
| Resend | USA | We rely on the standard contractual clauses with the UK Addendum in Resend's terms; Resend is also listed under the UK Extension to the EU-US Data Privacy Framework |
| Cloudflare | USA and global edge | UK Extension to the EU-US Data Privacy Framework, with standard contractual clauses as a fallback |
| Google Workspace | Google's global infrastructure | Google's Workspace data-processing terms; Google LLC is certified under the UK Extension for any US leg |
Where we rely on standard contractual clauses we have carried out the assessment the law requires (the data protection test, previously the transfer risk assessment) and concluded the protection is not materially lower after the transfer. If a protection stops being available we will move to another or stop the transfer. Ask us for a copy of the safeguards for any transfer.
11. How long we keep things
We keep information for as long as we need it and no longer. Rather than invent countdowns we do not operate, here are the rules we work to.
- Your reports and the data behind them: while you are with us, because each week is compared against the weeks before it and that history is what makes the report useful. Deleted when you leave, or whenever you ask.
- Your contact details, account, portal notes and check-ins: while you are with us, deleted when you leave.
- Sign-in and admin records (our audit log, failed sign-ins, expired admin sessions): cleared when older than 12 months. An automatic routine does this. It runs when our service restarts rather than on a timer, so an entry can survive a little past 12 months.
- Portal visit and portal session records, and our application logs, which can hold your email address and the sign-in links we sent you: kept until your data is deleted. The logs rotate on a 12 month cycle and our deletion routine does not reach them, so a mention of your email address can remain in a log for up to 12 months after everything else has gone.
- Your consent record (what you agreed, the version, the time and the IP address), kept so we can prove what was agreed: up to 6 years from the end, deleted when the reason ends.
- Google review data held for you: inside your report archive, deleted with it. In practice that means for as long as you are a client. We have no automatic clear-out yet; when we build one we will set a maximum period here.
- Waitlist entries: until you ask to come off, or until we close the waitlist and delete it.
- Support emails you send us: no automatic clear-out exists. We delete them by hand when you ask, or with the rest of your data.
- Our accounting records: six years from the end of the financial year, because company and tax law requires it.
When your pilot ends. We stop generating reports and switch off portal access within 5 working days. We then return or delete your data, as you choose, within 30 days.
Deletion is something a person does, not a timer. When you ask, or when your pilot ends, we delete your data by hand within 30 days and confirm when it is done. Zak Armitage, our director, is responsible for that and for the annual review below. We run no automatic clear-out on a schedule, so if you want something gone sooner, ask.
Backups. We do not keep separate backup copies of your reports or of the portal database, so there is nothing extra to purge. The one copy we do keep is a rotating same-machine backup of our client list, which is cleared on the next save after we delete your record. If we introduce backups they will be covered by the same procedure: put beyond use from the day we delete your live data, meaning not opened, searched or restored from, and deleted on the next backup cycle.
At least once a year we review what we still hold and delete anything we no longer need.
12. How we protect your information
Only what is true today:
- Encryption at rest, where it exists. Our client registry (your contact details and consent record) and the access tokens for your till and accounting connections are encrypted, and readable only by the account that runs the service.
- What is not encrypted. Your report files and our database are ordinary files with restricted permissions, on our own equipment in our own premises in the UK. Our previous policy claimed all client data was encrypted; that was not true, and we would rather correct it than repeat it.
- Encryption in transit. Our website and portal are served over HTTPS with strict transport security. TLS terminates at the Cloudflare edge, and the connection on to our machine runs inside a private tunnel not exposed to the internet.
- Sign-in security. Passwords are hashed with scrypt and a random salt, so we never hold the password itself. Session tokens are 256 bits of cryptographically random data.
- Web protections. Cross-site request forgery protection on state-changing requests, and security headers on every response.
- Audit log. Administrative actions such as creating a client, generating a report or deleting data are recorded.
- Access. Only the three of us have access to client data.
- Security review. We carried out an internal review of our own code and systems in August 2026 and are working through its findings. We hold no independent security certification. Everything above describes a control that exists now.
13. Your rights
These rights are not absolute and some exemptions apply, but here they are.
- Access (Art 15). A copy of the personal information we hold about you. We search in a way that is reasonable and proportionate; we will not rebuild deleted records.
- Rectification (Art 16). Have anything wrong or incomplete corrected.
- Erasure (Art 17). Have your information deleted from our live systems, including report files, portal notes and your account, within 30 days. We confirm when it is done.
- Restriction (Art 18). Have us pause while a concern is sorted out: we stop generating reports, stop sending email and block new sign-ins. One honest limitation, an open portal session on a device keeps working until it expires, up to 30 days. Tell us and we will clear it.
- Portability (Art 20). The data you gave us, in a structured, machine-readable format. We put it together by hand; there is no self-service export button that produces it.
- Objection (Art 21). Object to anything we do on the basis of legitimate interests, including product improvement and review analysis. We stop unless we can show compelling grounds that override your rights.
- Automated decisions (Arts 22A to 22D). We make no significant decisions about people by automated means. You can still ask for a person to review any AI-written output, and for reports with no AI analysis.
- Withdrawing consent. Where we rely on consent (the demo box, the waitlist), at any time and as easily as you gave it.
How long we take. We answer within one month. That month starts when we have your request and, if we need it, proof of who you are. If we have to ask you to narrow down what you are looking for, the clock pauses from the day we ask until you reply. If your request is complicated, or you have sent several, we can take up to two extra months, and we will write to you inside the first month to say why.
We do not charge, unless a request is clearly unfounded or excessive. To use any of these rights, email support@8employ.uk.
14. Information for Google reviewers
This section is for you if you left a public review on Google Maps for a venue that uses our service. You have never dealt with us, and you are entitled to know what we do.
What we hold, and where it came from. Your Google display name, star rating, review text and date, for up to five reviews Google returns for that venue. Google chooses which five, usually the ones it thinks most relevant. Not your profile link or photo. It comes from the Google Places API: the review you published publicly on Google Maps. Google decides for itself what it does with our query and is not acting for us.
What we do with it, honestly, as things stand today. Your review, including your display name, is sent to Anthropic, an AI company in the United States, as part of the material used to analyse the venue's reviews and draft a reply. Your name appears in the venue's weekly report, portal, PDF and email. Where the venue uses the reply feature, your name and review are used to draft a suggested reply written in the owner's voice, which the owner may post on Google; if you named a member of staff the draft may name them too. We do not use your review to test or improve our product.
Who else handles it. Section 9 lists everyone else who handles the report your review sits in, including the service that emails it, and section 10 says how the transfer to the United States is protected. If the venue has ticked the optional demo box, a prospective customer may be shown one of its reports; before we show anything we take the reviews section out of it.
Our lawful basis, and what our assessment found. Legitimate interests (Art 6(1)(f)): the venue's interest in reading and answering what its customers say, and ours in providing that feature. We have written that assessment down, dated 2 September 2026. It is a working document, still being reviewed and not yet signed off, and we will send you a summary if you ask.
It found for us on the analysis: you published the review publicly, addressed to that venue, and it is reasonable to expect the venue to read it and act on it. It found against us on one point. Your display name is necessary for drafting a reply, because a reply has to address you, but not for analysing what the review says, where the text alone would do. We have decided to keep passing the name on both paths rather than strip it, and we would rather say so than hide it: the name is one you published yourself, it stays with the single venue you reviewed, we never link it to reviews you left anywhere else, and we do not use your review to improve our product at all. If you would rather we did not hold it, tell us and we will delete it.
Sensitive information in a review. Review text reaches our AI analysis in full — we cannot filter it in advance and we do not control what a reviewer writes. If a review happens to contain sensitive information about someone, we do not go looking for it, we do not build on it, and we will take it out of a suggested reply. Requests about it are handled the same way as any other request below.
What we never do, and how long we keep it. We do not contact reviewers, build a profile of you, link your reviews across venues, use your data for marketing, or sell it. Your review is only shown back to the venue you reviewed. We keep it inside that venue's reports for as long as those reports exist; they are deleted when the venue leaves or asks us to delete them. In practice that means for as long as the venue is a client. We have no automatic clear-out yet; when we build one we will set a maximum period here. We will delete your review data sooner if you ask.
Why we did not write to you. We cannot: Google gives us a display name, not an address, and writing to every reviewer would be disproportionate. The law (Article 14(5)(e) of the UK GDPR) then allows us to publish this information instead of sending it to each person, provided we make it publicly available. This section is that publication.
Your rights, without an account. Email support@8employ.uk. You do not need an account or to be a customer. Tell us the venue and the display name on the review. If a reviewer contacts us we search by venue and display name by hand, using the procedure in our deletion and requests runbook, and answer within one month. We have no automated way to find a reviewer's data across our report files. We will give you access to what we hold, correct it, delete it, or stop the processing if you object, on the timings in section 13, and you can complain to us or to the ICO under section 19.
16. If something goes wrong with your data
If there is a personal data breach that puts anyone's rights at risk we will:
- tell the ICO within 72 hours of becoming aware of it, as Article 33 requires;
- tell the people affected without undue delay where the risk to them is high, as Article 34 requires;
- tell our venue clients as the Data Processing Agreement requires, without undue delay and in any event within 48 hours of becoming aware;
- write down what happened, what it affected and what we did.
We have no real-time alerting that would tell us the moment something went wrong, so "becoming aware" means when one of us notices it or someone tells us.
If you think your information may have been exposed, email support@8employ.uk and say so.
17. Children
Our service is for businesses and is not aimed at children. We do not knowingly collect information about anyone under 18, and none of our data sources is directed at children. One honest caveat: a Google reviewer could be under 18 and we have no way of telling. If that is you, email support@8employ.uk and we will remove the review data.
18. Changes to this policy
We update this policy when what we do changes, when the law changes, or when we find something in it that is not accurate. Every change produces a new version number and date; we do not edit a published version in place. We keep every published version; ask and we will send you the one that was current when you joined. Where a change is significant we email our clients before it takes effect. The current version is always at https://8employ.uk/privacy-policy.
| Version | Date | What changed |
|---|---|---|
| 2.0 | March 2026 | Earliest version we still hold |
| 3.0 | 2 September 2026 | Rewritten against what our systems actually do, and against the Data (Use and Access) Act 2025. Corrects retention, encryption, backups, email provider and integrations; adds sections on AI, product improvement, demo use and our website; adds the right to complain to us; rewrites the reviewer notice |
| 3.1 | 4 September 2026 | Adds a notice for venue staff (section 2a); corrects the lawful basis for report production and for company contacts; takes Google reviews out of product improvement and out of demo material; corrects sub-processor notice to 30 days; states retention for portal and application logs and for the consent record; corrects the backup, security-review and reviewer-name statements |
At our next review we will check whether the ICO has been replaced by the Information Commission, which is expected but has not yet happened.
19. Complaints
Come to us first, if you can. Since 19 June 2026 you have a right to complain directly to us about how we handle your personal data (section 164A of the Data Protection Act 2018). Email support@8employ.uk, or reach us any other way that suits you: we accept a complaint however it arrives and you do not have to use any particular form of words. We acknowledge it within 30 days of receiving it, look into it properly and keep you posted, and tell you the outcome.
You can also go to the ICO. You have a right to complain to the Information Commissioner under section 165 of the Data Protection Act 2018. Complaining to us does not take that right away, and you do not have to come to us first.
Information Commissioner's Office Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF Telephone: 0303 123 1113 Website: https://ico.org.uk
8Employ Ltd · Company number 17082344, registered in England and Wales · Registered office as filed at Companies House · ICO registration ZC104872 · support@8employ.uk Privacy Policy version 3.1 · 4 September 2026 · replaces version 2.0 (March 2026)