Privacy Policy

Effective Date: January 2025 | Version 1.0

Harper Automation Ltd ("Harper", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data.


1. Who We Are

Data Controller:
Harper Automation Ltd
Registered in England and Wales
Email: [email protected]

For data protection matters, contact: [email protected]


2. Scope of This Policy

This Privacy Policy applies to:

  • Visitors to our website (harperautomation.co.uk)
  • Prospective and current clients
  • Users of our platform and Services
  • Business contacts and partners

Important: When we process data on behalf of our clients (as a data processor), our clients' privacy policies apply to that data. This policy covers data we control directly.


3. Data We Collect

3.1 Website Visitors

When you visit our website, we may collect:

Data Type Examples Purpose
Contact Information Name, email, phone, business name Respond to enquiries
Business Information Industry, company size, challenges Tailor our services
Business Metrics Data Industry, lead volume, conversion rates, staff costs, revenue estimates Calculate ROI projections, tailor service recommendations
Technical Data IP address, browser type, pages visited Website functionality and security

3.2 Clients and Platform Users

When you become a client or use our platform:

Data Type Examples Purpose
Account Information Name, email, business details Account management
Billing Information Payment method, billing address Process payments
Usage Data Features used, credits consumed Service delivery, billing
Communication Records Support tickets, emails, calls Customer support
Authentication Data Login credentials, security settings Account security

3.3 Data Processed on Behalf of Clients

When you use our platform to manage your contacts and communications, we process:

Data Type Examples Your Role Our Role
Contact Data Names, phone numbers, emails Controller Processor
Communication Content SMS messages, call transcripts, emails Controller Processor
Engagement Data Opens, clicks, responses Controller Processor

Note: For data we process as a processor on behalf of clients, please refer to our Data Processing Agreement.


4. How We Collect Data

We collect data:

  • Directly from you: When you fill out forms, contact us, or use our Services
  • Automatically: Through cookies and similar technologies (see Section 10)
  • From third parties: From publicly available sources or partners you've authorised

5. How We Use Your Data

5.1 Lawful Bases

Under UK GDPR, we process personal data on the following legal bases:

Purpose Lawful Basis
Providing Services Performance of contract
Billing and payments Performance of contract
Customer support Performance of contract
Service improvements Legitimate interest
Security and fraud prevention Legitimate interest
Legal compliance Legal obligation
Marketing to existing clients Legitimate interest (soft opt-in)
Marketing to prospects Consent

5.2 Specific Purposes

We use your data to:

  • Deliver Services: Provide, maintain, and improve our automation and AI services
  • Process Payments: Handle billing, invoicing, and payment processing via Stripe
  • Provide Support: Respond to enquiries, troubleshoot issues, and provide assistance
  • Communicate: Send service updates, security alerts, and administrative messages
  • Improve: Analyse usage patterns to enhance our Services
  • Secure: Detect, prevent, and respond to security incidents
  • Comply: Meet legal and regulatory obligations
  • Market: With consent or where we have a legitimate interest, send relevant offers and updates

6. Data Sharing

6.1 Categories of Recipients

We share personal data with:

Recipient Type Purpose Examples
Service Providers Operate our infrastructure Cloud hosting, payment processing
Communication Providers Deliver SMS, calls, emails SMS gateway providers, telephony platforms
AI Providers Power AI features Large language model providers
Professional Advisors Legal, accounting, compliance Solicitors, accountants
Authorities Legal obligations Regulators, law enforcement (when required)

6.2 Sub-Processors

We use carefully selected third-party sub-processors in the following categories:

  • CRM and workflow automation platform
  • SMS and voice communication providers
  • Payment processing services
  • Database and application hosting
  • AI and machine learning providers

A detailed list of our current sub-processors is available upon request for clients who have signed a Data Processing Agreement. Contact [email protected] for details.

6.3 No Data Sales

We do not sell your personal data. We do not share personal data for third-party advertising or marketing purposes.


7. International Transfers

Some of our sub-processors are located outside the UK and EEA, primarily in the United States.

When transferring data internationally, we ensure appropriate safeguards through:

  • UK International Data Transfer Agreement (IDTA) for UK-origin data
  • EU Standard Contractual Clauses (SCCs) for EEA-origin data
  • Adequacy decisions where applicable
  • Supplementary measures as needed based on transfer impact assessments

8. Data Retention

We retain personal data only as long as necessary for the purposes described in this policy:

Data Type Retention Period
Website enquiries 24 months from last contact
Client account data Duration of relationship + 30 days
Billing records 7 years (legal requirement)
Communication logs 18 months (carrier/regulatory requirement)
Support tickets 3 years from resolution
Marketing preferences Until consent withdrawn

After the retention period, data is securely deleted or anonymised.


9. Your Rights

9.1 UK and EU GDPR Rights

Under UK and EU data protection law, you have the right to:

Right Description
Access Request a copy of your personal data
Rectification Request correction of inaccurate data
Erasure Request deletion of your data ("right to be forgotten")
Restriction Request we limit processing of your data
Portability Receive your data in a machine-readable format
Object Object to processing based on legitimate interests
Withdraw Consent Withdraw consent at any time (where consent is the basis)
Automated Decisions Not be subject to solely automated decisions with legal effects

9.2 California (CCPA/CPRA) Rights

If you are a California resident, you have additional rights:

Right Description
Right to Know Know what personal information we collect, use, and disclose
Right to Delete Request deletion of your personal information
Right to Correct Request correction of inaccurate information
Right to Opt-Out Opt-out of "sale" or "sharing" of personal information
Non-Discrimination Not be discriminated against for exercising your rights

California Disclosures:

  • We do NOT sell personal information
  • We do NOT share personal information for cross-context behavioural advertising
  • We do NOT use or disclose sensitive personal information beyond what is necessary

9.3 Exercising Your Rights

To exercise any of these rights:

  • Email: [email protected]
  • Subject Line: "Privacy Rights Request"

We will respond within 30 days (or 45 days for California requests, extendable by an additional 45 days if necessary).

We may need to verify your identity before processing your request.

9.4 Complaints

If you are unsatisfied with our response, you have the right to lodge a complaint with:

UK: Information Commissioner's Office (ICO)
Website: ico.org.uk
Phone: 0303 123 1113

EU: Your local data protection authority


10. Cookies and Tracking

10.1 Our Cookie Policy

We use cookies and similar technologies on our website.

10.2 Types of Cookies

Category Purpose Consent Required
Strictly Necessary Essential for website function (security, session management) No
Functional Remember preferences and settings Yes
Analytics Understand how visitors use our site Yes
Marketing Deliver relevant advertisements Yes

10.3 Current Cookie Usage

As of January 2025, we use minimal cookies:

  • Session cookies: For security and user sessions (strictly necessary)
  • Preference cookies: To remember your choices (optional)

We do NOT currently use:

  • Third-party advertising cookies
  • Cross-site tracking cookies
  • Social media tracking pixels

10.4 Managing Cookies

You can control cookies through:

  • Your browser settings
  • Our cookie consent banner (where applicable)
  • Opting out of specific analytics providers

Note: Blocking strictly necessary cookies may affect website functionality.


11. Security

We implement appropriate technical and organisational measures to protect your data, including:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Access controls and authentication
  • Regular security assessments and updates
  • Staff training on data protection
  • Incident response procedures

While we strive to protect your data, no method of transmission or storage is 100% secure. Please protect your account credentials and report any suspected security issues immediately.


12. Children's Privacy

Our Services are not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.


13. Third-Party Links

Our website and Services may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.


14. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes:

  • We will update the "Effective Date" at the top
  • For significant changes affecting your rights, we will notify you via email
  • Previous versions are available upon request

Continued use of our Services after changes take effect constitutes acceptance of the updated policy.


15. Contact Us

For any questions about this Privacy Policy or our data practices:

Harper Automation Ltd
Email: [email protected]
General enquiries: [email protected]
Website: harperautomation.co.uk


Last updated: January 2025