Document Version: 1.1
Effective Date: 25.06.2026
Last Reviewed: 25.06.2026
1. Purpose
This Privacy Policy explains how PD4ML (“the Organization”, “we”, “our”, or “us”) collects, uses, stores, shares, and protects personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and other applicable data protection laws.
We are committed to protecting the privacy and rights of individuals whose personal data we process.
2. Scope
This Privacy Policy applies to:
• Website visitors
• Customers
• Prospective customers
• Employees and job applicants (where applicable)
• Suppliers and contractors
• Business partners
• Any individual whose personal data is processed by the Organization
3. Data Controller
If appointed, our Data Protection Officer (DPO) can be contacted at:
Email: @
4. Personal Data We Collect
Depending on your relationship with us, we may collect the following categories of personal data:
Identification Data
• Name
• Username
• Customer ID
Contact Information
• Email address
• Postal address
Employment Information
• Job title
• Employer
• Department
Account Information
• Login credentials
• Authentication records
• Account preferences
Technical Information
• IP address
• Browser type
• Operating system
• Device identifiers
• Cookies and similar technologies
Usage Information
• Website usage
• Application usage
• Security logs
• Audit trails
Financial Information
Where necessary:
• Billing address
• Payment information (processed through approved payment providers)
We do not intentionally collect special category personal data unless required by law or with an appropriate legal basis.
5. How We Collect Personal Data
We collect personal data:
• Directly from you
• Through our website
• Through customer support
• During contract negotiations
• Through recruitment processes
• From publicly available sources where permitted
• From business partners
• Through cookies and analytics technologies
6. Legal Basis for Processing
We process personal data under one or more of the following legal bases:
Contract
Processing necessary to perform a contract with you.
Examples include:
• Providing products or services
• Customer support
• Account management
Legal Obligation
Processing necessary to comply with legal obligations.
Examples include:
• Tax requirements
• Employment law
• Regulatory compliance
Legitimate Interests
Processing necessary for our legitimate business interests, provided those interests are not overridden by your rights.
Examples include:
• Fraud prevention
• Information security
• Network security
• Service improvement
• Internal administration
Consent
Where required, we rely on your consent.
Examples include:
• Marketing communications
• Certain cookies
• Optional services
You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
7. How We Use Personal Data
We may use personal data to:
• Deliver products and services
• Manage customer relationships
• Process transactions
• Verify identity
• Respond to enquiries
• Improve our services
• Maintain information security
• Prevent fraud
• Monitor system performance
• Comply with legal obligations
• Conduct internal reporting and analytics
• Send marketing communications where permitted
8. Cookies
Our website uses cookies and similar technologies to:
• Enable website functionality
• Improve user experience
• Remember preferences
• Analyse website traffic
• Enhance security
Where legally required, we obtain your consent before placing non-essential cookies.
You may manage cookie preferences through your browser settings or our cookie consent tool.
9. Disclosure of Personal Data
We may disclose personal data to:
• Service providers
• Cloud hosting providers
• Payment processors
• IT support providers
• Professional advisers
• Auditors
• Government authorities where legally required
• Law enforcement agencies where legally required
All third parties are required to protect personal data and process it only on our documented instructions where applicable.
10. International Transfers
Where personal data is transferred outside the European Economic Area (EEA) or the United Kingdom, we ensure appropriate safeguards are implemented, including, where applicable:
• European Commission Adequacy Decisions
• Standard Contractual Clauses (SCCs)
• Binding Corporate Rules (BCRs)
• Other lawful transfer mechanisms under applicable data protection law
11. Data Retention
We retain personal data only for as long as necessary to:
• Fulfil contractual obligations
• Meet legal requirements
• Resolve disputes
• Enforce agreements
• Maintain appropriate business records
Retention periods vary depending on the type of information and applicable legal requirements.
When no longer required, personal data will be securely deleted or anonymised.
12. Information Security
We implement appropriate technical and organisational measures to protect personal data, including:
• Encryption
• Multi-factor authentication
• Access controls
• Network security controls
• Logging and monitoring
• Vulnerability management
• Regular security assessments
• Employee security awareness training
• Backup and disaster recovery procedures
No method of electronic transmission or storage is completely secure; however, we continually work to reduce risk through appropriate safeguards.
13. Automated Decision-Making and Profiling
We do not make decisions based solely on automated processing that produce legal or similarly significant effects on individuals unless permitted by law or with your explicit consent.
Where automated decision-making is used, you will be informed of the logic involved, its significance, and your rights.
14. Your GDPR Rights
Subject to applicable law, you have the following rights:
• Right to be informed
• Right of access
• Right to rectification
• Right to erasure (“right to be forgotten”)
• Right to restrict processing
• Right to data portability
• Right to object to processing
• Rights relating to automated decision-making and profiling
• Right to withdraw consent at any time where processing is based on consent
Requests may be submitted using the contact details provided in this Privacy Policy.
We will respond within the time limits required by applicable law.
15. Data Breach Notification
Where required by law, we will notify the relevant supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it.
Where the breach is likely to result in a high risk to individuals, affected individuals will also be notified where required.
16. Children’s Privacy
Our services are not directed to children under the age required by applicable law for independent consent to information society services.
We do not knowingly collect personal data from children without appropriate parental or guardian consent where required.
17. Marketing Communications
Where permitted by law, we may send marketing communications about our products or services.
You may opt out at any time by:
• Clicking the unsubscribe link in marketing emails
• Contacting us using the details provided in this Privacy Policy
• Updating your communication preferences
18. Complaints
If you believe your personal data has been processed unlawfully, you have the right to lodge a complaint with the competent data protection supervisory authority in your country of residence, place of work, or where the alleged infringement occurred.
We encourage you to contact us first so we can attempt to resolve your concerns.
19. Changes to this Privacy Policy
We may update this Privacy Policy from time to time.
Material changes will be communicated through appropriate channels, including our website where applicable.
The latest version will always be available upon request or on our website.
20. Contact Us
For questions regarding this Privacy Policy or the processing of your personal data, please contact:
@
