Skip to content

Legal

Privacy policy

Last updated

This policy explains what personal data Tao Systems collects through this website, why we collect it, how long we keep it and what you can do about it. It's deliberately short. If anything is unclear, email privacy@taosystems.dev.

In short

The controller is Tao Systems, in London. The only personal data this site collects is what you type into the contact form and the request logs Cloudflare keeps for 30 days to keep the site up. There are no analytics scripts, advertising cookies or tracking pixels, and the fonts are served from our own domain. Enquiries are deleted after 24 months. We never sell personal data. Privacy questions go to privacy@taosystems.dev.

Who we are

Tao Systems, is the data controller for the personal data described in this policy. Our address is London, United Kingdom.

Write to privacy@taosystems.dev for anything about how we handle personal data. It reaches us directly, and we acknowledge within one working day.

What this policy covers

This policy covers this website only. It doesn't cover the data inside Relay or Basin when a customer runs them. The contacts, patients, members or policyholders in a customer's system belong to that customer. We only touch that data during installation, onboarding and support sessions, with the customer's permission, and when we do we act as a processor on the customer's instructions under a Data Processing Agreement and, where protected health information under HIPAA is involved, a Business Associate Agreement. Those contracts govern that data, not this page. The security and compliance page describes them.

If you're an end user of a product one of our customers runs (a member of a scheme, a patient, a policyholder), contact that organisation about your data. It's the controller, and we can't act on your request without its instruction.

What we collect

When you use the contact form we collect your name, work email address, company and the message you write, together with the time you sent it. We use these to reply to you and, if the conversation goes somewhere, to set up your subscription. If you email or phone us instead, we keep the correspondence in the same way.

The site is served through Cloudflare, which records each request: your IP address, your user agent (browser and operating system), the page requested and the time. We use these logs to serve the site, spot abuse and block attacks. They're kept for 30 days and then deleted.

That's the complete list. There's no account to create and nothing else on the site that collects personal data.

What we deliberately don't do

We don't run third-party analytics scripts on this site, so there's no Google Analytics, no session-recording tool and nothing reporting your visit to another company. We don't set advertising cookies and we don't use tracking pixels, on pages or in the emails we send you. Fonts are served from our own domain rather than a font provider, so loading a page doesn't tell anyone else you visited.

The only cookies you may see are strictly necessary ones Cloudflare sets to protect the site from attack (for example, to remember that you passed a bot check). They don't identify you to us and we don't read them. That's also why there's no cookie banner: there is nothing to consent to.

Why we're allowed to use it

UK GDPR and EU GDPR require a lawful basis for each use of personal data. We rely on two.

Legitimate interests (Article 6(1)(f)) cover responding to the enquiries you send us and keeping the site secure and available. We've weighed these interests against yours: the data involved is minimal, you'd expect us to use it for exactly these purposes, and none of it is used for anything you'd find surprising.

Contract (Article 6(1)(b)) applies when an enquiry turns into a subscription. From that point we use your details to prepare, sign and perform the contract with your organisation.

How long we keep it

Enquiries, whether they came through the form, by email or by phone, are kept for 24 months from our last contact with you and then deleted. Request logs are kept for 30 days. If your organisation becomes a customer, your contact details move into our customer records, where they're kept for the life of the contract and for whatever period tax law requires afterwards.

Who we share it with

Cloudflare hosts the site, including the server that receives form submissions, and provides the CDN, DNS and DDoS protection in front of it, so it processes request data on our behalf. Cloudflare Email Routing also delivers the notification to us when you submit the form, so it handles the contents of that message in transit. No other provider is involved.

Beyond that, we share personal data only with our professional advisers where needed, and with authorities where the law requires it. We don't sell personal data, we never have, and we don't pass it to advertisers or data brokers.

International transfers

Our own systems are hosted in the UK. Cloudflare operates a worldwide network, so a request, or the email it generates, may be handled at a location near you. Where personal data leaves the UK or the European Economic Area we rely on the UK International Data Transfer Addendum and the EU Standard Contractual Clauses, or on an adequacy decision where one applies.

Your rights

Under UK GDPR and EU GDPR you can:

  • ask for a copy of the personal data we hold about you (access);
  • ask us to correct anything that's wrong or incomplete (rectification);
  • ask us to delete your data (erasure);
  • ask us to stop using it while a dispute is resolved (restriction);
  • ask for a machine-readable copy to take elsewhere (portability);
  • object to processing based on our legitimate interests (objection).

To exercise any of these, email privacy@taosystems.dev. We may ask you to confirm your identity first. We respond within one month, and if a request is unusually complex we'll tell you within that month how much longer we need. There's no charge.

Complaints

If you think we've handled your data badly, tell us first and we'll try to put it right. You also have the right to complain to a supervisory authority at any time. In the UK that's the Information Commissioner's Office at ico.org.uk. In the EU it's the supervisory authority for the country you live or work in; the European Data Protection Board publishes the list at edpb.europa.eu.

Changes to this policy

If our practices change, we'll update this page and the date at the top. For anything material, such as collecting a new category of data or using it for a new purpose, we'll say what changed rather than quietly editing the text.

Contact

Tao Systems
London
United Kingdom
Privacy and data protection
privacy@taosystems.dev
+44 20 7946 0958