Privacy policy
Effective date: 19 August 2026.
1.1 This notice explains how RENDUS LTD, of 37 Sandy Lane, WOKINGHAM, RG41 4SS United Kingdom, obtains, uses, discloses, protects and retains personal data in connection with https://rendus.help, enquiries, proposals and the delivery of database design and management and related information technology services. It is intended for website visitors, prospective and current clients, client personnel, suppliers, professional contacts, job applicants and other individuals who interact with us.
1.2 For the processing described in this notice, RENDUS LTD is usually the controller. Contact us at about@rendus.help or +44 7399 888999. The email address is presented as plain text to reduce ambiguity about the correct privacy contact. We have not appointed a data protection officer because our present core activities do not require one, but privacy matters are overseen by senior management.
1.3 This notice applies where we decide why and how personal data is used. When we process personal data held in a client's databases, applications, cloud tenancy or analytics environment solely on documented client instructions, the client is normally controller and we are processor. The relevant services agreement and data processing terms then govern that processing; individuals should ordinarily direct rights requests concerning that data to the client.
2. Personal data we collect
2.1 This section concerns identity, business contact and relationship data. Depending on the interaction, this can include names, roles, employer details, postal addresses, telephone numbers, email addresses, correspondence history and meeting notes. We process it to identify contacts, communicate accurately and maintain an accountable record of the relationship.
2.2 Data may be supplied directly, generated during dealings with us, or received from an employer, colleague, referral source or public professional profile.
2.3 We apply purpose limitation and data minimisation: personnel may use the information only for authorised tasks, access is reviewed against current need, and a new incompatible use requires a fresh legal assessment. Accuracy concerns are investigated against reliable source records rather than silently overwriting information that may be relevant to audit or dispute history.
2.4 Before introducing a material new use, system or recipient, we consider necessity, transparency, access, retention, security and the effect on individuals. Higher-risk processing is subject to a documented impact assessment where UK law requires one, with unresolved high risk escalated before deployment rather than accepted by default.
2.5 Information relevant to this section is not sold. It is not disclosed for another organisation's unrelated advertising, and it is not combined with confidential client datasets to create consumer profiles. Any exception required by law is interpreted narrowly, recorded and limited to the information properly required.
3. Website and technical information
3.1 This section concerns device, connection and usage data. Depending on the interaction, this can include IP address, approximate location, browser type, operating system, referring page, requested resources, timestamps, security events and consent selections. We process it to operate the site, diagnose faults, understand aggregate use and resist malicious traffic.
3.2 We do not seek to infer sensitive characteristics from ordinary website telemetry, and optional analytics are subject to the cookie choices described in our cookie policy.
3.3 We apply purpose limitation and data minimisation: personnel may use the information only for authorised tasks, access is reviewed against current need, and a new incompatible use requires a fresh legal assessment. Accuracy concerns are investigated against reliable source records rather than silently overwriting information that may be relevant to audit or dispute history.
3.4 Before introducing a material new use, system or recipient, we consider necessity, transparency, access, retention, security and the effect on individuals. Higher-risk processing is subject to a documented impact assessment where UK law requires one, with unresolved high risk escalated before deployment rather than accepted by default.
3.5 Information relevant to this section is not sold. It is not disclosed for another organisation's unrelated advertising, and it is not combined with confidential client datasets to create consumer profiles. Any exception required by law is interpreted narrowly, recorded and limited to the information properly required.
4. Enquiries, proposals and client administration
4.1 This section concerns enquiry and transaction records. Depending on the interaction, this can include requirements, budgets, procurement details, proposal feedback, contractual contacts, billing references and service communications. We process it to respond to requests, scope work, form and administer contracts and manage client relationships.
4.2 We may record who approved a statement of work, change request or access decision so that delivery and accountability can be demonstrated.
4.3 We apply purpose limitation and data minimisation: personnel may use the information only for authorised tasks, access is reviewed against current need, and a new incompatible use requires a fresh legal assessment. Accuracy concerns are investigated against reliable source records rather than silently overwriting information that may be relevant to audit or dispute history.
4.4 Before introducing a material new use, system or recipient, we consider necessity, transparency, access, retention, security and the effect on individuals. Higher-risk processing is subject to a documented impact assessment where UK law requires one, with unresolved high risk escalated before deployment rather than accepted by default.
4.5 Information relevant to this section is not sold. It is not disclosed for another organisation's unrelated advertising, and it is not combined with confidential client datasets to create consumer profiles. Any exception required by law is interpreted narrowly, recorded and limited to the information properly required.
5. Service delivery and support
5.1 This section concerns operational and support data. Depending on the interaction, this can include support tickets, diagnostic extracts, system identifiers, audit trails, user IDs, configuration information and incident communications. We process it to design, integrate, secure, monitor and support client technology.
5.2 We minimise production data in development and support workflows, favour masked or synthetic records where practicable, and restrict access according to assigned responsibilities.
5.3 We apply purpose limitation and data minimisation: personnel may use the information only for authorised tasks, access is reviewed against current need, and a new incompatible use requires a fresh legal assessment. Accuracy concerns are investigated against reliable source records rather than silently overwriting information that may be relevant to audit or dispute history.
5.4 Before introducing a material new use, system or recipient, we consider necessity, transparency, access, retention, security and the effect on individuals. Higher-risk processing is subject to a documented impact assessment where UK law requires one, with unresolved high risk escalated before deployment rather than accepted by default.
5.5 Information relevant to this section is not sold. It is not disclosed for another organisation's unrelated advertising, and it is not combined with confidential client datasets to create consumer profiles. Any exception required by law is interpreted narrowly, recorded and limited to the information properly required.
6. Recruitment and workforce contacts
6.1 This section concerns candidate and recruitment data. Depending on the interaction, this can include CV information, work history, qualifications, interview notes, availability, right-to-work evidence and referee details. We process it to assess suitability, arrange interviews, make offers and comply with employment-related duties.
6.2 We ask candidates not to provide unnecessary special-category information. Where equality monitoring is undertaken, it is separated from selection decisions and used only where lawful safeguards apply.
6.3 We apply purpose limitation and data minimisation: personnel may use the information only for authorised tasks, access is reviewed against current need, and a new incompatible use requires a fresh legal assessment. Accuracy concerns are investigated against reliable source records rather than silently overwriting information that may be relevant to audit or dispute history.
6.4 Before introducing a material new use, system or recipient, we consider necessity, transparency, access, retention, security and the effect on individuals. Higher-risk processing is subject to a documented impact assessment where UK law requires one, with unresolved high risk escalated before deployment rather than accepted by default.
6.5 Information relevant to this section is not sold. It is not disclosed for another organisation's unrelated advertising, and it is not combined with confidential client datasets to create consumer profiles. Any exception required by law is interpreted narrowly, recorded and limited to the information properly required.
7. Suppliers and professional advisers
7.1 This section concerns supplier and adviser information. Depending on the interaction, this can include contact details, service records, due diligence answers, insurance details, payment administration and professional correspondence. We process it to select and manage suppliers, obtain advice, maintain business records and protect our legal position.
7.2 Information may also be checked against lawful fraud-prevention, sanctions or corporate registers where proportionate to the engagement.
7.3 We apply purpose limitation and data minimisation: personnel may use the information only for authorised tasks, access is reviewed against current need, and a new incompatible use requires a fresh legal assessment. Accuracy concerns are investigated against reliable source records rather than silently overwriting information that may be relevant to audit or dispute history.
7.4 Before introducing a material new use, system or recipient, we consider necessity, transparency, access, retention, security and the effect on individuals. Higher-risk processing is subject to a documented impact assessment where UK law requires one, with unresolved high risk escalated before deployment rather than accepted by default.
7.5 Information relevant to this section is not sold. It is not disclosed for another organisation's unrelated advertising, and it is not combined with confidential client datasets to create consumer profiles. Any exception required by law is interpreted narrowly, recorded and limited to the information properly required.
8. Purposes and lawful bases
8.1 This section concerns the legal grounds for processing. Depending on the interaction, this can include contract necessity, steps requested before contract, legitimate interests, legal obligation and consent where required. We process it to ensure every material use has an identified UK GDPR basis.
8.2 Our legitimate interests include running a secure IT consultancy, communicating with business contacts, improving service quality, preventing misuse, recovering debts and establishing or defending legal claims. We balance those interests against individual rights and reasonable expectations.
8.3 We apply purpose limitation and data minimisation: personnel may use the information only for authorised tasks, access is reviewed against current need, and a new incompatible use requires a fresh legal assessment. Accuracy concerns are investigated against reliable source records rather than silently overwriting information that may be relevant to audit or dispute history.
8.4 Before introducing a material new use, system or recipient, we consider necessity, transparency, access, retention, security and the effect on individuals. Higher-risk processing is subject to a documented impact assessment where UK law requires one, with unresolved high risk escalated before deployment rather than accepted by default.
8.5 Information relevant to this section is not sold. It is not disclosed for another organisation's unrelated advertising, and it is not combined with confidential client datasets to create consumer profiles. Any exception required by law is interpreted narrowly, recorded and limited to the information properly required.
9. Special-category and criminal-offence data
9.1 This section concerns information requiring additional protection. Depending on the interaction, this can include health or accessibility details voluntarily supplied for meetings, security incident material, and screening information where legally justified. We process it to make appropriate arrangements, investigate events or meet a specific legal obligation.
9.2 We do not intentionally collect such data through general website forms. If client systems expose it during authorised technical work, access is limited, logged and governed by client instructions and the applicable Article 9 or Schedule 1 condition.
9.3 We apply purpose limitation and data minimisation: personnel may use the information only for authorised tasks, access is reviewed against current need, and a new incompatible use requires a fresh legal assessment. Accuracy concerns are investigated against reliable source records rather than silently overwriting information that may be relevant to audit or dispute history.
9.4 Before introducing a material new use, system or recipient, we consider necessity, transparency, access, retention, security and the effect on individuals. Higher-risk processing is subject to a documented impact assessment where UK law requires one, with unresolved high risk escalated before deployment rather than accepted by default.
9.5 Information relevant to this section is not sold. It is not disclosed for another organisation's unrelated advertising, and it is not combined with confidential client datasets to create consumer profiles. Any exception required by law is interpreted narrowly, recorded and limited to the information properly required.
10. Sources of information
10.1 This section concerns direct and indirect data sources. Depending on the interaction, this can include individuals, their organisations, authorised client administrators, service providers, public registers, professional networks and technical systems. We process it to keep records accurate and obtain context needed for legitimate business dealings.
10.2 Where data is not obtained from the individual, we consider whether notice is required and provide it within the statutory period unless an exemption or disproportionate-effort rule properly applies.
10.3 We apply purpose limitation and data minimisation: personnel may use the information only for authorised tasks, access is reviewed against current need, and a new incompatible use requires a fresh legal assessment. Accuracy concerns are investigated against reliable source records rather than silently overwriting information that may be relevant to audit or dispute history.
10.4 Before introducing a material new use, system or recipient, we consider necessity, transparency, access, retention, security and the effect on individuals. Higher-risk processing is subject to a documented impact assessment where UK law requires one, with unresolved high risk escalated before deployment rather than accepted by default.
10.5 Information relevant to this section is not sold. It is not disclosed for another organisation's unrelated advertising, and it is not combined with confidential client datasets to create consumer profiles. Any exception required by law is interpreted narrowly, recorded and limited to the information properly required.
11. Sharing and recipients
11.1 This section concerns controlled disclosure of personal data. Depending on the interaction, this can include hosting providers, communications vendors, accountants, insurers, legal advisers, specialist subcontractors and public authorities. We process it to obtain necessary infrastructure and expertise, meet obligations and respond to lawful demands.
11.2 Recipients receive only information reasonably required for their function. Vendors are assessed for security and privacy, bound by confidentiality and data-protection terms, and prohibited from using processor data for independent purposes.
11.3 We apply purpose limitation and data minimisation: personnel may use the information only for authorised tasks, access is reviewed against current need, and a new incompatible use requires a fresh legal assessment. Accuracy concerns are investigated against reliable source records rather than silently overwriting information that may be relevant to audit or dispute history.
11.4 Before introducing a material new use, system or recipient, we consider necessity, transparency, access, retention, security and the effect on individuals. Higher-risk processing is subject to a documented impact assessment where UK law requires one, with unresolved high risk escalated before deployment rather than accepted by default.
11.5 Information relevant to this section is not sold. It is not disclosed for another organisation's unrelated advertising, and it is not combined with confidential client datasets to create consumer profiles. Any exception required by law is interpreted narrowly, recorded and limited to the information properly required.
12. International transfers
12.1 This section concerns movement of data outside the United Kingdom. Depending on the interaction, this can include limited transfers arising from cloud hosting, remote support or globally operated business tools. We process it to use suitable technology and specialist support while preserving UK protections.
12.2 Before a restricted transfer we use an adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to approved EU clauses, or another lawful mechanism. We assess destination-law and practical risks and apply supplementary encryption, access or minimisation measures where needed.
12.3 We apply purpose limitation and data minimisation: personnel may use the information only for authorised tasks, access is reviewed against current need, and a new incompatible use requires a fresh legal assessment. Accuracy concerns are investigated against reliable source records rather than silently overwriting information that may be relevant to audit or dispute history.
12.4 Before introducing a material new use, system or recipient, we consider necessity, transparency, access, retention, security and the effect on individuals. Higher-risk processing is subject to a documented impact assessment where UK law requires one, with unresolved high risk escalated before deployment rather than accepted by default.
12.5 Information relevant to this section is not sold. It is not disclosed for another organisation's unrelated advertising, and it is not combined with confidential client datasets to create consumer profiles. Any exception required by law is interpreted narrowly, recorded and limited to the information properly required.
13. Retention and deletion
13.1 This section concerns the period for which information is kept. Depending on the interaction, this can include active relationship records, contract evidence, financial records, security logs, support records, unsuccessful candidate files and consent evidence. We process it to meet operational, tax, limitation, audit and security needs without retaining data indefinitely.
13.2 Retention is determined by purpose, volume, sensitivity, legal duties, dispute risk and whether the record can be anonymised. Routine deletion and account closure are supplemented by backup expiry; immutable backups are isolated and data is not restored for ordinary use after deletion.
13.3 We apply purpose limitation and data minimisation: personnel may use the information only for authorised tasks, access is reviewed against current need, and a new incompatible use requires a fresh legal assessment. Accuracy concerns are investigated against reliable source records rather than silently overwriting information that may be relevant to audit or dispute history.
13.4 Before introducing a material new use, system or recipient, we consider necessity, transparency, access, retention, security and the effect on individuals. Higher-risk processing is subject to a documented impact assessment where UK law requires one, with unresolved high risk escalated before deployment rather than accepted by default.
13.5 Information relevant to this section is not sold. It is not disclosed for another organisation's unrelated advertising, and it is not combined with confidential client datasets to create consumer profiles. Any exception required by law is interpreted narrowly, recorded and limited to the information properly required.
14. Security
14.1 This section concerns technical and organisational safeguards. Depending on the interaction, this can include access control, multifactor authentication, encryption, secure configuration, vulnerability handling, logging, backups, supplier review and staff confidentiality. We process it to preserve confidentiality, integrity, availability and resilience proportionate to risk.
14.2 No internet service is risk-free, but we maintain layered controls, review access, separate client environments where appropriate and investigate suspected incidents. Individuals should avoid sending credentials in ordinary messages and should use an agreed secure channel for sensitive material.
14.3 We apply purpose limitation and data minimisation: personnel may use the information only for authorised tasks, access is reviewed against current need, and a new incompatible use requires a fresh legal assessment. Accuracy concerns are investigated against reliable source records rather than silently overwriting information that may be relevant to audit or dispute history.
14.4 Before introducing a material new use, system or recipient, we consider necessity, transparency, access, retention, security and the effect on individuals. Higher-risk processing is subject to a documented impact assessment where UK law requires one, with unresolved high risk escalated before deployment rather than accepted by default.
14.5 Information relevant to this section is not sold. It is not disclosed for another organisation's unrelated advertising, and it is not combined with confidential client datasets to create consumer profiles. Any exception required by law is interpreted narrowly, recorded and limited to the information properly required.
15. Your data protection rights
15.1 This section concerns rights available under UK law. Depending on the interaction, this can include access, rectification, erasure, restriction, objection, portability, withdrawal of consent and safeguards relating to automated decisions. We process it to give individuals meaningful control and transparency.
15.2 Rights are not absolute. We may retain information needed for legal claims, refuse manifestly unfounded or excessive requests, or protect another person's rights. We explain any applicable limitation and provide information about complaint routes.
15.3 We apply purpose limitation and data minimisation: personnel may use the information only for authorised tasks, access is reviewed against current need, and a new incompatible use requires a fresh legal assessment. Accuracy concerns are investigated against reliable source records rather than silently overwriting information that may be relevant to audit or dispute history.
15.4 Before introducing a material new use, system or recipient, we consider necessity, transparency, access, retention, security and the effect on individuals. Higher-risk processing is subject to a documented impact assessment where UK law requires one, with unresolved high risk escalated before deployment rather than accepted by default.
15.5 Information relevant to this section is not sold. It is not disclosed for another organisation's unrelated advertising, and it is not combined with confidential client datasets to create consumer profiles. Any exception required by law is interpreted narrowly, recorded and limited to the information properly required.
16. Exercising rights and identity checks
16.1 This section concerns request handling. Depending on the interaction, this can include requests sent to about@rendus.help, supporting identity information, correspondence scope and authorised representative evidence. We process it to locate records, prevent unauthorised disclosure and respond within statutory timescales.
16.2 We normally respond within one month, with a permitted extension for complex or numerous requests. Identity evidence is requested only where reasonable doubt exists and is deleted or restricted after verification according to our retention controls.
16.3 We apply purpose limitation and data minimisation: personnel may use the information only for authorised tasks, access is reviewed against current need, and a new incompatible use requires a fresh legal assessment. Accuracy concerns are investigated against reliable source records rather than silently overwriting information that may be relevant to audit or dispute history.
16.4 Before introducing a material new use, system or recipient, we consider necessity, transparency, access, retention, security and the effect on individuals. Higher-risk processing is subject to a documented impact assessment where UK law requires one, with unresolved high risk escalated before deployment rather than accepted by default.
16.5 Information relevant to this section is not sold. It is not disclosed for another organisation's unrelated advertising, and it is not combined with confidential client datasets to create consumer profiles. Any exception required by law is interpreted narrowly, recorded and limited to the information properly required.
17. Direct business communications
17.1 This section concerns service and professional updates. Depending on the interaction, this can include contact details, role, organisation, communication preferences and engagement history. We process it to send relevant business-to-business information where consent or legitimate interests and PECR permit.
17.2 Every outreach is assessed for audience and relevance. Individuals may object at any time. We maintain a minimal suppression record so that an opt-out is respected rather than accidentally reversed by a later contact import.
17.3 We apply purpose limitation and data minimisation: personnel may use the information only for authorised tasks, access is reviewed against current need, and a new incompatible use requires a fresh legal assessment. Accuracy concerns are investigated against reliable source records rather than silently overwriting information that may be relevant to audit or dispute history.
17.4 Before introducing a material new use, system or recipient, we consider necessity, transparency, access, retention, security and the effect on individuals. Higher-risk processing is subject to a documented impact assessment where UK law requires one, with unresolved high risk escalated before deployment rather than accepted by default.
17.5 Information relevant to this section is not sold. It is not disclosed for another organisation's unrelated advertising, and it is not combined with confidential client datasets to create consumer profiles. Any exception required by law is interpreted narrowly, recorded and limited to the information properly required.
18. Automated decision-making and AI
18.1 This section concerns use of automation and machine-assisted tools. Depending on the interaction, this can include structured classification, anomaly signals, drafting assistance and technical analysis outputs. We process it to support human work efficiently without making solely automated decisions with legal or similarly significant effects about ordinary contacts.
18.2 Where client work involves AI or machine learning, roles, purposes, training data, evaluation and human oversight are agreed for that project. We do not place confidential client content into public generative services without authorisation and appropriate contractual safeguards.
18.3 We apply purpose limitation and data minimisation: personnel may use the information only for authorised tasks, access is reviewed against current need, and a new incompatible use requires a fresh legal assessment. Accuracy concerns are investigated against reliable source records rather than silently overwriting information that may be relevant to audit or dispute history.
18.4 Before introducing a material new use, system or recipient, we consider necessity, transparency, access, retention, security and the effect on individuals. Higher-risk processing is subject to a documented impact assessment where UK law requires one, with unresolved high risk escalated before deployment rather than accepted by default.
18.5 Information relevant to this section is not sold. It is not disclosed for another organisation's unrelated advertising, and it is not combined with confidential client datasets to create consumer profiles. Any exception required by law is interpreted narrowly, recorded and limited to the information properly required.
19. Children
19.1 This section concerns information relating to minors. Depending on the interaction, this can include incidental website or correspondence data. We process it to operate a business-to-business service not directed at children.
19.2 We do not knowingly solicit data from children through this site. If a parent or guardian reasonably believes a child has supplied personal data, they should contact us so that we can investigate and delete it where no lawful reason requires retention.
19.3 We apply purpose limitation and data minimisation: personnel may use the information only for authorised tasks, access is reviewed against current need, and a new incompatible use requires a fresh legal assessment. Accuracy concerns are investigated against reliable source records rather than silently overwriting information that may be relevant to audit or dispute history.
19.4 Before introducing a material new use, system or recipient, we consider necessity, transparency, access, retention, security and the effect on individuals. Higher-risk processing is subject to a documented impact assessment where UK law requires one, with unresolved high risk escalated before deployment rather than accepted by default.
19.5 Information relevant to this section is not sold. It is not disclosed for another organisation's unrelated advertising, and it is not combined with confidential client datasets to create consumer profiles. Any exception required by law is interpreted narrowly, recorded and limited to the information properly required.
20. Complaints and regulator
20.1 This section concerns privacy concerns and regulatory recourse. Depending on the interaction, this can include the issue raised, relevant records, desired outcome and our response. We process it to investigate fairly, correct mistakes and demonstrate accountability.
20.2 Please contact us first so that we can address the concern. Individuals may complain to the Information Commissioner's Office, the UK supervisory authority, and may seek a judicial remedy. Raising a concern does not affect any other legal right.
20.3 We apply purpose limitation and data minimisation: personnel may use the information only for authorised tasks, access is reviewed against current need, and a new incompatible use requires a fresh legal assessment. Accuracy concerns are investigated against reliable source records rather than silently overwriting information that may be relevant to audit or dispute history.
20.4 Before introducing a material new use, system or recipient, we consider necessity, transparency, access, retention, security and the effect on individuals. Higher-risk processing is subject to a documented impact assessment where UK law requires one, with unresolved high risk escalated before deployment rather than accepted by default.
20.5 Information relevant to this section is not sold. It is not disclosed for another organisation's unrelated advertising, and it is not combined with confidential client datasets to create consumer profiles. Any exception required by law is interpreted narrowly, recorded and limited to the information properly required.
21. Changes to this notice
21.1 This section concerns notice governance. Depending on the interaction, this can include version date, material amendments and historical rationale. We process it to keep this explanation accurate as services, vendors and law develop.
21.2 We publish the current notice on https://rendus.help. Material changes are highlighted through an appropriate channel where their significance warrants direct notice. Continued contact does not convert consent into the lawful basis where fresh consent is legally required.
21.3 We apply purpose limitation and data minimisation: personnel may use the information only for authorised tasks, access is reviewed against current need, and a new incompatible use requires a fresh legal assessment. Accuracy concerns are investigated against reliable source records rather than silently overwriting information that may be relevant to audit or dispute history.
21.4 Before introducing a material new use, system or recipient, we consider necessity, transparency, access, retention, security and the effect on individuals. Higher-risk processing is subject to a documented impact assessment where UK law requires one, with unresolved high risk escalated before deployment rather than accepted by default.
21.5 Information relevant to this section is not sold. It is not disclosed for another organisation's unrelated advertising, and it is not combined with confidential client datasets to create consumer profiles. Any exception required by law is interpreted narrowly, recorded and limited to the information properly required.
22. Contact details
22.1 Questions, requests and concerns may be addressed to RENDUS LTD, 37 Sandy Lane, WOKINGHAM, RG41 4SS United Kingdom; email about@rendus.help; telephone +44 7399 888999. Please identify the relationship or project concerned without sending passwords, secret keys or unnecessary copies of identity documents in the first message.