UK DATA PROTECTION & PRIVACY COMPLIANCE

Privacy Policy

How Frontier Systems collects, manages, and protects personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Jurisdiction: England & Wales (UK)·Effective Date: 17 September 2026·Regulated by: Information Commissioner's Office (ICO)
Summary in Plain English

We respect your privacy. We only collect the minimal information needed to deliver high-quality technology solutions, communicate with clients, and ensure platform security. We do not sell your personal data, and we do not use client confidential data to train public artificial intelligence models.

1. Introduction & UK GDPR

Frontier Systems (“Frontier Systems”, “we”, “our”, or “us”) is a UK-based technology firm delivering custom software development, artificial intelligence (AI) automation, SaaS platforms, and enterprise digital solutions.

This Privacy Policy explains how we collect, process, store, and safeguard your personal data when you visit our website (frontiersystems.co), engage our consulting and engineering services, or communicate with our team. We operate in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), and the Privacy and Electronic Communications Regulations (PECR).

2. Data Controller Details

Under the UK GDPR, Frontier Systems acts as the Data Controller for personal data collected directly through our public website, marketing inquiries, and client account administration.

Frontier Systems

22 Gladstone Street, Walsall, WS2 8BL, United Kingdom

Direct Inquiries: hello@frontiersystems.co

Note: When we build bespoke systems, host client databases, or implement workflows where the client provides their own end-user data, Frontier Systems typically acts as a Data Processor under a separate, binding Data Processing Agreement (DPA) executed with the client.

3. Personal Data We Collect

We only collect data that is strictly necessary for fulfilling our contractual commitments, answering inquiries, and maintaining cyber defence standards:

A. Contact & Commercial Data

When you initiate contact, book a consultation, or request a proposal: name, business email address, phone number, company name, job role, and project requirements submitted via email or contact forms.

B. Technical & Operational Information

When accessing our web services: IP address, operating system, browser type and version, device identifiers, time-zone settings, and diagnostic logs utilised solely for infrastructure health, DDoS prevention, and routing.

C. Billing & Project Administration

For corporate clients: billing contact details, company registration numbers, VAT identifiers, invoicing address, and payment transaction confirmations (processed via secure banking or PCI-DSS certified gateways).

4. AI & Automation Data Processing

Strict AI Data Governance Policy

Frontier Systems adheres to rigorous standards regarding machine learning and automated reasoning tools.

  • No Public Model Training: We do not submit client confidential data, proprietary code, business logic, or customer records to public machine learning models for training or reinforcement.
  • Zero-Retention Enterprise APIs: Where third-party AI APIs (e.g., Anthropic Claude, OpenAI Enterprise, AWS Bedrock) are incorporated into client architectures, they are configured under enterprise agreements featuring explicit zero-data-retention and non-training clauses.
  • Human-in-the-Loop Safeguards: Autonomous agents and automation pipelines designed by Frontier Systems enforce deterministic fallback logic, audit logging, and administrative oversight to prevent unmonitored decision-making.

5. Lawful Bases for Processing (UK GDPR Art. 6)

We process your personal information only when there is a valid lawful basis under UK law:

Purpose of ProcessingData CategoriesUK GDPR Lawful Basis
Responding to inquiries & project scopingName, email, project briefLegitimate Interests / Pre-contract
Delivering bespoke software & consultingClient contacts, technical accessPerformance of a Contract
Statutory accounting & tax records (HMRC)Invoices, company billing infoLegal Obligation
Website security & firewall protectionIP address, server error logsLegitimate Interests (Cybersecurity)

6. How We Use Your Data

We use the data collected strictly for legitimate operational purposes:

  • To negotiate, execute, and deliver client software development contracts;
  • To provide ongoing support, bug remediation, and infrastructure maintenance;
  • To invoice for professional services rendered and maintain corporate accounts;
  • To detect, prevent, and mitigate cyber security threats and malicious traffic;
  • To comply with statutory legal and regulatory obligations in the United Kingdom.

7. Sharing & Third-Party Processors

We never sell, rent, or trade your personal data. We only share data with vetted sub-processors that maintain ISO 27001, SOC 2, or UK GDPR-compliant data processing agreements:

  • Hosting & CDN Providers: Vercel Inc., Amazon Web Services (AWS), and Cloudflare for edge routing, security headers, and website availability.
  • Communication & Productivity: Google Workspace / Microsoft 365 for secure corporate communications under UK/EU data residency guarantees.
  • Statutory Authorities: UK law enforcement or regulatory bodies (such as HMRC) where required by a binding legal court order.

8. International Data Transfers

As a UK company, our primary processing occurs within the United Kingdom and the European Economic Area (EEA). Where technical infrastructure requires transfer to jurisdictions outside the UK, we ensure appropriate safeguards are implemented in compliance with Chapter V of the UK GDPR, such as:

  • UK International Data Transfer Agreements (IDTA);
  • The UK Addendum to EU Standard Contractual Clauses (SCCs); or
  • Countries covered by UK adequacy regulations.

9. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected:

  • General Inquiries: Retained for 12 months following last contact unless a commercial project contract ensues.
  • Client Contract & Project Deliverables: Retained for 6 years following project completion in accordance with the UK Limitation Act 1980.
  • Statutory Financial Records: Retained for 6 years plus the current financial year to satisfy UK HMRC corporate tax requirements.

10. Your UK GDPR Rights

Under UK data protection law, you possess significant rights regarding your personal information:

Right of Access

Request a copy of the personal data we hold about you (Subject Access Request).

Right to Rectification

Require us to correct incomplete or inaccurate personal data promptly.

Right to Erasure

Request the deletion of your personal data where no legal ground requires its retention.

Right to Restriction

Ask us to pause processing your data under specific contested circumstances.

Right to Data Portability

Receive your personal data in a structured, commonly used, machine-readable format.

Right to Object

Object to processing based on legitimate interests or direct marketing.

To exercise any of these rights, email us at hello@frontiersystems.co. We respond to verified requests within one calendar month, free of charge.

11. Technical & Organisational Security

We implement industry-grade technical safeguards to prevent accidental loss, unauthorised access, alteration, or disclosure of data:

  • End-to-end encryption in transit via modern TLS 1.3 protocols;
  • Encryption at rest using AES-256 for all databases and project repositories;
  • Strict role-based access control (RBAC) and mandatory multi-factor authentication (MFA);
  • Continuous dependency auditing and automated vulnerability monitoring.

12. Contact Us & ICO Complaints

If you have questions, concerns, or requests regarding this Privacy Policy, please reach out directly to our privacy officer:

Frontier Systems — Data Privacy

Email: hello@frontiersystems.co

Information Commissioner's Office (ICO)

You have the right to lodge a complaint at any time with the UK data protection supervisory authority:

Website: ico.org.uk · Helpline: 0303 123 1113

We would appreciate the chance to address your concerns before you approach the ICO, so please feel welcome to contact us first.