Stallions Technologies (“we,” “us,” or “our”) is committed to protecting the privacy and personal data of every individual we interact with. This is our single, authoritative Privacy Policy — governing all personal data we collect and process across every product, service, platform, and interaction carried out under the Stallions Technologies name, now and in the future.
This policy is governed by the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR). It is written in plain English, covers every category of data we may collect across every product and service — including health, wellbeing, financial, and other sensitive data — and requires no separate or supplementary notice. Last reviewed: April 2026.
Who We Are
Stallions Technologies is a UK-registered global technology company specialising in software development, web development, cloud solutions, IT support, and artificial intelligence solutions. We are registered with the Information Commissioner’s Office (ICO) under Registration No: 10307505. Our registered office is 124 City Road, London EC1V 2NX. We also operate from offices at Wolverhampton Science Park, WV10 9TG (UK), Shams Business Center, Sharjah Media City Free Zone (UAE), and Commercial Area Model Town, Lahore (Pakistan).
Stallions Technologies operates in two distinct capacities under data protection law, and this policy covers both:
- As a Data Controller — when we collect and use personal data for our own purposes, such as operating our website, managing client relationships, running our own digital products, and recruiting staff. In this capacity, we determine why and how your data is used, and this policy describes those practices in full.
- As a Data Processor — when we design, build, or operate technology systems on behalf of a business client, and those systems store or process personal data belonging to that client’s own customers, end users, employees, or any other individuals who have a relationship with the client rather than with Stallions Technologies directly. In this capacity, we act solely on the documented instructions of the client, who remains the Data Controller and is responsible for the lawful basis on which that data is collected and held. Our obligations and commitments in this role are set out in Section 16A of this policy.
Where we engage third parties to process personal data on our behalf, those parties act as sub-processors under our instruction and are bound by formal Data Processing Agreements.
Scope & Coverage
This policy applies universally across all Stallions Technologies activities. It covers every individual whose personal data we process, regardless of how or where that interaction takes place — whether through our website, a digital product or application, a commercial engagement, a job application, or any other channel.
It applies to all current services and to any new products or services we launch in the future. No separate or additional privacy notice will ever be required for any new offering — this single document governs all of them from the date of their launch. Every type of data we may collect or process — including health data, wellbeing data, financial data, behavioural data, and any other sensitive category — is addressed explicitly within this policy, most specifically in Section 5.
Importantly, this policy also covers individuals whose personal data is stored or processed within systems built or operated by Stallions Technologies on behalf of a business client — even where those individuals have no direct relationship with Stallions Technologies and may not be aware that their data resides in a Stallions-built system. This includes, for example, the customers, service users, patients, employees, or any other data subjects of an organisation that has commissioned Stallions Technologies to develop or manage a technology platform on their behalf. The rights and protections described in this policy extend to all such individuals. The manner in which those rights are exercised in a processor context is described in Section 16A.
| You are a… | Typical Data Held | Key Sections |
|---|---|---|
| Direct User of a Stallions Product | Account credentials, usage data, and any data submitted within the product | 3, 4, 5, 6, 9, 11 |
| Individual Whose Data is Held in a Client System | Any personal or sensitive data stored in a system built or operated by Stallions Technologies on behalf of a third-party organisation | 5, 16A |
| Website Visitor | IP address, browser cookies, contact form submissions | 3, 4, 12 |
| Business Customer / Client | Contact details, contract records, communications, project files | 3, 4, 7, 9 |
| Partner / Collaborator | Professional contact data, project communications | 3, 7, 15 |
| Job Applicant / Candidate | CV, qualifications, interview notes, references | 3, 4, 9, 14 |
| Research / Academic Partner | Professional details, anonymised and aggregated datasets only | 3, 7, 15 |
| Marketing / Enquiry Contact | Name, email address, enquiry content, consent records | 3, 4, 11 |
Personal Data We Collect
We collect only the personal data that is necessary and proportionate for the purpose for which it is collected. The categories below represent the full range of data that Stallions Technologies may hold across all our activities and interactions:
| Category | Examples | Applies To | Type |
|---|---|---|---|
| Identity Data | Full name, username, date of birth | Product users, customers, candidates | Personal |
| Contact Data | Email address, telephone number, postal address | All categories | Personal |
| Special Category Data | Health, wellbeing, or other sensitive data submitted via any of our products or services where applicable | Applicable product users only, with explicit consent | Special Category |
| Usage & Behavioural Data | Feature interactions, session data, activity logs, in-product behaviour | Digital product users, website visitors | Technical |
| AI Interaction Data | Inputs submitted to any AI-enabled feature; outputs generated in response | Users of AI-enabled products or services | Personal |
| Communications Data | Emails, support tickets, enquiry messages, chat records | All categories | Personal |
| Commercial & Contract Data | Purchase history, invoices, signed agreements, billing records | Customers, partners | Personal |
| Recruitment Data | CV, cover letter, qualifications, interview notes, right-to-work documentation | Job applicants | Sensitive |
| Technical & Device Data | IP address, device identifier, operating system, browser type, crash and error logs | All digital interactions | Technical |
| Marketing & Preference Data | Communication preferences, consent records, opt-out history | Marketing contacts, product users | Preference |
We do not handle payment card details directly. Any payment processing is conducted by certified third-party payment providers operating under their own compliance obligations. We do not collect any data that is not reasonably necessary for the stated purpose at the point of collection.
Why We Use Your Data — Lawful Bases
Every processing activity carried out by Stallions Technologies is underpinned by a documented lawful basis under UK GDPR Article 6. Where we process Special Category data, a further condition under Article 9 also applies. The table below sets out our processing purposes and the basis for each:
| Processing Purpose | Lawful Basis | Who It Applies To |
|---|---|---|
| Providing the products or services you have requested | Contract — Art. 6(1)(b) | Product users, customers |
| Processing Special Category data (e.g. health or wellbeing data) | Explicit Consent — Art. 9(2)(a) | Applicable product users only |
| Sending service communications and account-related updates | Contract — Art. 6(1)(b) | Product users, customers |
| Sending marketing and promotional communications | Consent — Art. 6(1)(a) | Any individual who has opted in |
| Improving our products and services through analytics | Legitimate Interests — Art. 6(1)(f) | All digital users |
| Responding to enquiries, complaints, and support requests | Legitimate Interests — Art. 6(1)(f) | All categories |
| Evaluating job applications and managing recruitment | Legitimate Interests / Legal — Art. 6(1)(f)/(c) | Job applicants |
| Performing and managing contracts with business customers | Contract — Art. 6(1)(b) | Customers, commercial partners |
| Legal and regulatory compliance, fraud prevention, and safety | Legal Obligation — Art. 6(1)(c) | All categories |
| Academic or scientific research (anonymised data only) | Research Exemption / Consent — Art. 9(2)(j) / (a) | Research and academic partners |
Where we rely on Legitimate Interests as a lawful basis, we have carried out a Legitimate Interests Assessment (LIA) to confirm that our interests do not override your fundamental rights and freedoms. You may request a summary of any LIA by contacting support@stallions.tech.
Special Category & Sensitive Data
Some Stallions Technologies products and services, by their nature, require the collection and processing of data that is classified as Special Category data under UK GDPR Article 9, or that is otherwise inherently sensitive. This section sets out in full how every such category of sensitive data is handled, regardless of which product or service is involved. No separate notice or addendum is required — this policy is the complete and authoritative statement of our practices for all sensitive data across all current and future products and services.
Health & Physical Wellbeing Data
Where any Stallions Technologies product or service collects information relating to a user’s physical health, medical conditions, symptoms, physical activity, physiological measurements, or any other data that directly or indirectly reveals information about a person’s physical health status, the following applies:
- This data is classified as Special Category data under UK GDPR Article 9(1) and is subject to the highest standard of protection we apply
- It is collected and processed solely on the basis of your explicit, freely given, and granular consent (Article 9(2)(a)), obtained via a clearly labelled, standalone consent screen before any such data is collected — distinct from acceptance of any general terms of use
- It is used exclusively to deliver the specific functionality of the product or service for which you gave consent — it is never used for advertising, profiling, resale, or any secondary commercial purpose
- It is stored in encrypted, segregated storage that is physically and logically isolated from all other categories of personal data
- Access is limited exclusively to authorised technical personnel operating under strict role-based controls and documented confidentiality obligations
- You may withdraw your consent at any time via the privacy settings within the relevant product or by contacting us directly — withdrawal does not affect processing that took place before withdrawal, but will result in the deletion of your health data within 30 days
- It is never shared with any third party in identifiable form. Where health-related data contributes to research or analytics, it is irreversibly anonymised and aggregated before any such use
Mental Wellbeing & Emotional Data
Where any Stallions Technologies product or service collects information relating to a user’s mental health, emotional state, psychological wellbeing, mood, stress levels, or behavioural patterns that may reveal information about mental health, the same protections as health data apply in full. Additionally:
- This data is never used to make inferences about a user’s character, suitability for employment, or any other purpose beyond the direct delivery of the product’s stated function
- Any automated analysis of emotional or behavioural data produces advisory outputs only — it does not constitute clinical assessment, diagnosis, or mental health advice of any kind
- Users are always able to view, correct, download, or permanently delete their emotional and behavioural data, independently of other account data, via their in-product privacy settings or by contacting us
Financial & Payment-Related Data
Where any Stallions Technologies product or service involves financial transactions, billing, or the collection of commercially sensitive financial information:
- Payment card data and bank details are never stored by Stallions Technologies directly — all payment processing is handled exclusively by certified third-party payment processors operating under PCI DSS compliance and their own regulated data protection frameworks
- Billing records, invoice history, and transaction records are retained for 7 years in accordance with UK financial and tax law obligations
- Any financial data held by us (such as billing addresses or invoice records) is accessible only to authorised finance personnel under role-based controls, and is never used for any purpose other than the management of the commercial relationship with you
Behavioural & Usage Pattern Data Processed by AI
Where any Stallions Technologies product uses artificial intelligence or machine learning to process your usage patterns, in-product behaviour, or interaction history to generate personalised outputs or predictions:
- Such processing requires your explicit consent before it begins, and may be withdrawn at any time
- All AI-generated outputs derived from behavioural data are probabilistic and advisory in nature — they do not represent factual determinations about you as an individual
- Your behavioural data is not used to train shared or third-party AI models without your explicit, separately obtained consent
- You have the right to request a human review of any AI-generated output that you believe has been generated incorrectly or that has had an adverse effect on you
Biometric Data
Where any Stallions Technologies product or service involves the processing of biometric data — such as fingerprint authentication, facial recognition, or voice identification — this constitutes Special Category data under UK GDPR Article 9(1). It is only collected with your explicit consent, used solely for the purpose of authentication or identification within the specific product, and is never shared with any third party or used for any secondary purpose. Biometric templates are stored in a one-way hashed or encrypted format that cannot be reverse-engineered to reconstruct the original biometric.
Sensitive Recruitment Data
Where, in the context of a job application, you voluntarily provide or we are required to collect information relating to disability, ethnicity, criminal convictions, or other sensitive categories — for example as part of equal opportunities monitoring or legal right-to-work verification — such data is:
- Collected only where legally required or where you have actively chosen to provide it for a stated purpose such as diversity monitoring
- Processed separately from your core application materials and accessible only to authorised HR personnel
- Used solely for the stated purpose and deleted once that purpose is fulfilled, within the timelines set out in Section 14
- Never used in any way that disadvantages your application or employment prospects
Universal Principles Applying to All Sensitive Data
Across every category of sensitive data described above, the following principles apply universally and without exception across all Stallions Technologies products, services, and activities:
- Consent first: sensitive data is never collected without clear, prior, explicit consent — separate from any general agreement — which you may withdraw at any time without consequence
- Purpose limitation: sensitive data is used only for the specific purpose for which consent was given and never repurposed without obtaining fresh consent
- Strict access controls: access to sensitive data is restricted to the minimum number of authorised personnel required, all of whom operate under documented confidentiality obligations
- Segregated storage: sensitive data is held in independently encrypted, isolated storage systems and never commingled with standard personal data
- No advertising use: sensitive data is never used for advertising, marketing profiling, or commercial targeting of any kind
- No identifiable third-party sharing: sensitive data is never shared with any external party in a form that identifies you as an individual
- Deletion on request: you may request permanent deletion of any sensitive data at any time, which will be completed within 30 days, subject only to any overriding legal retention obligation
- Data Protection Impact Assessment: a DPIA is conducted before any new product feature or processing activity involving sensitive data is introduced
AI-Based Processing & Automated Decisions
Stallions Technologies develops and operates products and services that incorporate artificial intelligence and automated processing capabilities. Where any such feature is present in a product you use, the following principles apply:
AI-Generated Outputs
Where a product uses AI to generate personalised recommendations, guidance, analysis, or responses, those outputs are produced through automated processing of the data you have submitted. All AI-enabled features require your explicit consent before activation and may be disabled by you at any time. The purpose and general mechanism of any AI feature will be disclosed to you within the relevant product.
Predictive & Analytical Processing
Where a product generates predictions, risk indicators, or pattern analysis based on your data, these outputs are statistical estimates only. They are designed to inform and support decision-making, not to replace human judgement. No output generated by a Stallions Technologies automated system constitutes professional medical, legal, financial, or clinical advice.
Automated Decision-Making
Under UK GDPR Article 22, you have the right not to be subject to a decision based solely on automated processing where that decision produces a significant legal or similarly significant effect on you. Stallions Technologies does not make any such decisions. All automated outputs across our products are advisory only and require a human actor to interpret and act upon them. If you have concerns about how any automated feature has processed your data, contact us at support@stallions.tech to request a human review.
AI and automated features within Stallions Technologies products are decision-support tools only. If you require urgent professional, medical, legal, or emergency assistance, please contact an appropriately qualified professional or the relevant emergency services.
Who We Share Your Data With
Stallions Technologies does not sell, rent, exchange, or otherwise trade personal data to or with any third party. We share data only in the limited and specific circumstances described below:
Service Providers (Data Processors)
We engage carefully selected third-party processors who act solely on our documented instructions under binding Data Processing Agreements. These may include:
- Cloud hosting and infrastructure providers — for secure, encrypted data storage and processing (e.g. AWS, Google Cloud, Microsoft Azure)
- Analytics platforms — operating exclusively on anonymised or aggregated data to support product improvement
- Customer support and communications platforms — for managing enquiries and client relationships
- Payment processors — for secure handling of commercial transactions
- Cybersecurity providers — for monitoring, threat detection, and incident response
Research & Academic Partners
Where Stallions Technologies collaborates with academic or research institutions, any data shared for research purposes is fully anonymised and aggregated prior to transfer. No individual can be identified from data shared in this context. All such sharing is governed by a formal Data Sharing Agreement, is subject to appropriate ethical approvals, and prohibits any attempt at re-identification.
Business Transfers
In the event of a merger, acquisition, restructuring, or sale of assets, personal data may be transferred to a successor entity. We will provide advance notice to affected individuals and ensure the receiving party is bound by standards of protection no less stringent than this policy.
Subcontractors & Technical Partners
Technical specialists and subcontractors engaged to deliver contracted services may receive limited personal data strictly necessary for that purpose, under documented confidentiality obligations.
Legal & Regulatory Disclosures
We may disclose personal data where required by law, court order, or regulatory obligation, including to enforcement authorities and regulators. We will always disclose the minimum data necessary and, where legally permitted, will notify the affected individual in advance.
International Data Transfers
Stallions Technologies operates internationally with offices in the United Kingdom, UAE, and Pakistan. Where personal data is transferred to or accessed from outside the UK, we ensure that appropriate and documented safeguards are in place, including one or more of the following mechanisms:
- Transfer to a country covered by a current UK Adequacy Regulation
- Use of the UK International Data Transfer Agreement (IDTA) or the UK Addendum to EU Standard Contractual Clauses
- Binding Corporate Rules approved by a competent supervisory authority
- Explicit consent of the data subject where no other mechanism applies and the transfer is occasional
Details of any international transfers applicable to your data, and the specific safeguards in place, are available on request. Contact us at support@stallions.tech.
How Long We Keep Your Data
We retain personal data only for as long as is necessary for the purpose for which it was collected, or as required by applicable law. The table below sets out our standard retention periods across all categories:
| Data Category | Retention Period | Basis |
|---|---|---|
| Digital product account and identity data | Duration of active account + 12 months following closure | Service delivery and dispute resolution |
| Special Category data (e.g. health or wellbeing) | Duration of active account; deleted upon account closure or consent withdrawal | Consent — deleted promptly on valid request |
| AI and automated processing interaction logs | 24 months from last interaction; anonymised at 12 months | Product improvement and safety monitoring |
| Client, customer, and contract records | Duration of service engagement + 7 years | UK legal and tax obligations |
| Recruitment data — unsuccessful candidates | 12 months from application close, then securely deleted | Legitimate interests and potential future roles (with consent) |
| Recruitment data — successful candidates | Duration of employment + 7 years | Employment law obligations |
| Marketing consent and opt-out records | Until withdrawal of consent + 3 years | Evidence of lawful processing basis |
| Website and product analytics data | 26 months (anonymised; no personal identifiers retained) | Product and service improvement |
| General communications and correspondence | 3 years from the date of last interaction | Legitimate interests |
| Legal, regulatory, and compliance records | 7 years minimum from the relevant event | UK statutory and regulatory requirements |
Data is securely deleted or irreversibly anonymised at the end of its applicable retention period. You may request early deletion of your personal data at any time — see Section 11 for your rights.
Security
We implement technical and organisational security measures appropriate to the risk level of each processing activity, as required by UK GDPR Article 32. Our security framework includes:
Technical Measures
- TLS 1.3 encryption for all personal data in transit across all Stallions Technologies platforms and services
- AES-256 encryption for personal data at rest, with enhanced protection for Special Category data
- Physically and logically segregated storage for Special Category data
- Role-based access controls with principle of least privilege enforced across all internal systems
- Multi-factor authentication required for all staff accessing systems containing personal data
- Firewalls, intrusion detection and prevention systems, and automated threat monitoring
- Regular penetration testing, vulnerability scanning, and independent security assessments
- Automated backups and tested disaster recovery procedures
Organisational Measures
- Mandatory data protection training for all staff with access to personal data
- Documented confidentiality obligations as part of all employment and contractor agreements
- Data Protection Impact Assessments (DPIAs) conducted for all new high-risk processing activities
- Formal incident response procedures with defined escalation paths and notification timelines
- Vendor due diligence and security reviews for all third-party processors prior to engagement
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office (ICO) within 72 hours of becoming aware of the breach, and will inform affected individuals without undue delay, as required by UK GDPR Articles 33 and 34.
Your Data Protection Rights
Under UK GDPR, you have the following rights in relation to your personal data. We will respond to all valid and verified requests within one calendar month at no charge, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline to act and will explain why.
Right to Be Informed
To know what data we hold about you, why we hold it, and how it is used — fulfilled by this policy and any product-level notices.
Right of Access (SAR)
To request a copy of all personal data Stallions Technologies holds about you, free of charge.
Right to Rectification
To ask us to correct any inaccurate or incomplete personal data we hold about you.
Right to Erasure
To request deletion of your personal data where there is no overriding lawful reason to retain it (“right to be forgotten”).
Right to Data Portability
To receive a copy of your personal data in a structured, commonly used, machine-readable format, and to transfer it to another controller.
Right to Object
To object to processing based on legitimate interests, including any profiling or analytics activities.
Right to Restrict Processing
To ask us to pause all processing of your data while a complaint or accuracy dispute is being resolved.
Right to Withdraw Consent
To withdraw any consent you have given at any time and without detriment. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
To exercise any of these rights, please email support@stallions.tech with the subject line “Privacy Inquiry – [Your Name]”. We may need to verify your identity before processing a request. Where a request is made through an in-product feature, identity is verified automatically via your authenticated session.
Cookies & Tracking Technologies
Stallions Technologies uses cookies and similar tracking technologies across its website and digital products, in accordance with the Privacy and Electronic Communications Regulations (PECR) and UK GDPR. We operate a three-tier approach:
- Strictly Necessary: Technologies essential for our platforms to function correctly, including authentication tokens, security identifiers, and session management. These do not require consent but are disclosed here for transparency.
- Analytics & Performance: Anonymised data collected to understand how users interact with our platforms and to improve their quality and reliability. These require your consent and may be enabled or disabled at any time via our cookie preferences centre.
- No Advertising Trackers: Stallions Technologies does not deploy third-party advertising, behavioural profiling, or cross-site tracking technologies on any of its platforms.
You may review and update your cookie preferences at any time via the Cookie Settings link in the footer of stallions.tech. For full details, see our Cookie Policy.
Children’s Privacy
Stallions Technologies products and services are directed at adults and are not intended for use by children. Unless a specific product is explicitly designed for younger users and carries appropriate safeguards in accordance with the ICO’s Children’s Code (Age Appropriate Design Code), our services are intended for individuals aged 16 and over, with a minimum age of 18 applying to any product that collects health, wellbeing, or other Special Category data.
We do not knowingly collect personal data from anyone below the applicable minimum age. If we become aware that such data has been collected, we will delete it promptly without requiring a formal request. If you believe a child’s data has been submitted to any of our platforms, please notify us immediately at support@stallions.tech.
Job Applicants & Recruitment
When you apply for a position at Stallions Technologies — whether through our website, a third-party job platform, or a recruitment agency — we collect and use your personal data for the sole purpose of evaluating your application and managing the recruitment process.
Data Collected During Recruitment
- Identity and contact data: name, email address, telephone number, postal address
- Application materials: CV, cover letter, portfolio, work samples, and any supporting documents you provide
- Professional background: qualifications, employment history, and professional references
- Assessment records: interview notes, test results, and evaluation outcomes
- Right to work documentation: collected only at the conditional offer stage and only as required by UK law
How We Use Recruitment Data
- To assess your suitability for the role applied for and to communicate with you throughout the process
- To verify information you have provided and to conduct lawful pre-employment checks
- Where you separately consent, to retain your details on file for consideration for future suitable vacancies
Retention of Recruitment Data
- Unsuccessful applicants: data is retained for 12 months from the close of the application process, then securely and permanently deleted
- Successful applicants: data transitions to an employment record and is retained for the duration of employment plus 7 years in accordance with UK statutory obligations
If you were referred to us by a recruitment agency, that agency acts as an independent data controller for its own processing. We apply this policy to your data from the point we receive it. Please review the agency’s own privacy policy for details of their practices.
Research & Academic Partners
Stallions Technologies engages in collaborative research and development activities with academic and research institutions. Our approach to personal data in all such relationships is governed by the following non-negotiable principles:
- No personally identifiable data is shared with any academic or research partner under any circumstances
- Any data contributed to a research collaboration is fully anonymised and aggregated before transfer, such that no individual can be identified from it
- All data sharing arrangements are governed by a formal, written Data Sharing Agreement that is fully compliant with UK GDPR and the Data Protection Act 2018
- A Data Protection Impact Assessment (DPIA) is conducted prior to the commencement of any new research processing activity
- All research partners are contractually prohibited from attempting to re-identify anonymised data or using it for any purpose beyond the agreed and documented research scope
- Any academic publications or research outputs that draw on Stallions Technologies data will not disclose or enable identification of any individual
Changes to This Policy
This Privacy Policy is reviewed at least annually and whenever there is a material change to our processing activities, products, services, or applicable law. Because this policy is designed to be universal and product-agnostic, it will not need to be reissued each time a new Stallions Technologies product is launched — new products and services are automatically covered from the date of their launch.
When we make material changes to this policy, we will:
- Update the “Last Reviewed” date at the top of this page
- Display a prominent notice within any affected digital products at the next user login session
- Directly notify registered users by email where changes materially affect their rights or the legal basis on which we process their data
- Obtain fresh explicit consent where any change affects the processing of Special Category data
The previous version of this policy is available on request. Continued use of Stallions Technologies products or services following the effective date of an updated policy constitutes acceptance of the updated terms, except in cases where fresh consent is specifically required.
When Stallions Technologies Acts as a Data Processor
A significant part of Stallions Technologies’ work involves designing, building, and operating technology systems for business clients. When we do this, those systems may store or process personal data belonging to individuals who have a relationship with our client — not with Stallions Technologies. These individuals may never interact with us directly and may not know that their personal data resides within a system we have built or maintain.
In this capacity, Stallions Technologies acts as a Data Processor under UK GDPR Article 28, and the business client is the Data Controller — the organisation legally responsible for the lawful basis on which that personal data was collected and is held. This distinction is important: the client determines why personal data is collected and what it is used for; Stallions Technologies determines only how it is technically stored, secured, and managed.
Our Commitments as a Data Processor
Regardless of the industry, sector, or nature of the personal data involved, Stallions Technologies commits to the following in every system we build or operate on behalf of a client:
- Instruction-only processing: we process personal data held within client systems solely on the documented, written instructions of the client. We will never use, access, copy, or otherwise process that data for any purpose of our own
- Data Processing Agreement: every client engagement involving the processing of personal data is governed by a formal Data Processing Agreement (DPA) that complies with UK GDPR Article 28, setting out the subject matter, duration, nature, and purpose of processing, and the type of personal data and categories of data subjects involved
- Confidentiality: all Stallions Technologies personnel and contractors with access to personal data held in client systems are bound by documented confidentiality obligations. Access is restricted to the minimum number of individuals necessary to perform the contracted service
- Security: the technical and organisational security measures described in Section 10 of this policy apply in full to all data held within client systems, regardless of whose data subjects it belongs to
- Sub-processors: where we engage a sub-processor — for example a cloud hosting provider — to support the operation of a client system, we obtain the client’s prior written authorisation and impose the same data protection obligations on the sub-processor as apply to us under the DPA
- Assistance with data subject rights: where an individual whose data is held in a client system contacts Stallions Technologies directly to exercise a right under UK GDPR — such as a request for access, erasure, or rectification — we will promptly redirect that request to the relevant client and provide the client with any technical assistance they need to fulfil it
- Breach notification: in the event of a personal data breach affecting data held in a client system, we will notify the affected client without undue delay and in any event within 72 hours of becoming aware of the breach, providing sufficient information to enable the client to meet their own notification obligations to the ICO and to affected individuals
- Return or deletion on contract end: at the conclusion of any client engagement, we will, at the client’s election, either securely return all personal data held in that system to the client or permanently delete it, and provide written confirmation that deletion has been completed. No copies are retained unless required by law
- Audit rights: clients have the right to request evidence of our compliance with our processor obligations, including through audit or inspection, and we will cooperate fully with any such request
Sensitive & Special Category Data in Client Systems
Where a system built or operated by Stallions Technologies on behalf of a client stores or processes Special Category data or other inherently sensitive personal data — regardless of the domain or industry the client operates in — all of the protections described in Section 5 of this policy apply in full to that data at the technical infrastructure level. The client, as Data Controller, remains responsible for ensuring that the appropriate legal basis exists for collecting and holding that sensitive data in the first place. Stallions Technologies will not store, access, or process sensitive personal data in a client system beyond what is strictly necessary to deliver the contracted technical service.
Rights of Individuals Whose Data is Held in Client Systems
If you are an individual whose personal data is stored within a system built or operated by Stallions Technologies on behalf of a third-party organisation, and you wish to exercise any of your rights under UK GDPR — including the right to access, correct, delete, or restrict the processing of your data — you should contact the organisation that collected your data in the first instance, as they are the Data Controller responsible for responding to your request.
If you are uncertain who that organisation is, or if you believe your data has been mishandled at the infrastructure level, you are welcome to contact Stallions Technologies at support@stallions.tech and we will direct your enquiry appropriately and provide what assistance we are able to within the bounds of our processor role.
Contact Us & Right to Complain
For any question about this policy, to exercise any of your data protection rights, or to raise a privacy concern, please contact our Data Protection Lead directly:
We aim to respond to all privacy enquiries within one calendar month of verified receipt.
Right to Complain to the ICO
If you are not satisfied with our response to a privacy concern, or if you believe that Stallions Technologies is processing your personal data unlawfully, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s independent supervisory authority for data protection:
- Website: ico.org.uk
- Helpline: 0303 123 1113 (Mon–Fri, 9am–5pm)
- Post: ICO, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
We would always welcome the opportunity to address any concern directly before a formal complaint is submitted, and commit to responding promptly, transparently, and in good faith.
Questions about your data?
Our team is ready to help with any privacy enquiry or data subject request.


