Public policy

Privacy Policy

Effective 3 August 2026 · Review 3 August 2027

1. Who we are

TACTICARC LTD (company number 17233014) is the controller for the personal information described in this policy, unless a customer agreement identifies a different role.

Registered office: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ.
Privacy contact: anthony@tacticarc.co.uk.

This policy covers tacticarc.co.uk, business enquiries and administration, and TacticArc’s own use of the separate Engage platform. Where TacticArc processes information only on a client’s instructions, the client agreement or data-processing terms should define the parties’ roles.

2. Information we process

Website and enquiries

Names, business contact details, enquiry contents and correspondence, plus website security and server information generated when the site or form is used.

Customer and supplier administration

Business contacts, role and organisation, address, proposals, scopes, approvals, invoice information, payment status, support history and service records.

Relationship and sales records

Professional names, business contact details, organisation, role, source, interests, correspondence and interaction history held for enquiries, opportunities and relevant outreach.

Engage campaigns

Venue and customer business contacts, administration, content, branding, approvals and standard campaign analytics.

XR projects

Builds, source, CAD or 3D assets, logs, test evidence, access details and project correspondence supplied for an agreed engagement.

Standard Engage campaigns do not collect end-customer personal information by default unless a specific campaign feature is separately configured. Standard analytics may include non-identifying activity such as scans, starts, completions, result activity, reward or redemption events, venue or campaign identifiers, timestamps and aggregated activity.

3. Where information comes from

  • You, your employer or another authorised project contact.
  • The public website, business email, invoices, proposals, meetings and support interactions.
  • Campaign, product or technical systems used for an agreed service.
  • Public professional sources where lawful business outreach is used.
  • Service providers that generate security, delivery or technical records.

4. Why we use information

Enquiries and proposals

To respond, assess fit and prepare a proposal. Basis: steps requested before a contract and legitimate interests in responding to business enquiries.

Service delivery and support

To deliver campaigns, technical services or projects. Basis: contract performance and legitimate interests in delivering and improving business services.

Administration and records

For customer administration, invoicing and record-keeping. Basis: contract, legal obligation and legitimate business interests.

Security and operation

To operate, protect and troubleshoot websites, forms and platforms. Basis: legitimate security and availability interests, and legal obligation where applicable.

Campaign activity

To provide agreed campaign activity and analytics. Basis: the customer contract and legitimate interests in measurable campaign activity. Results are not guaranteed.

Outreach and legal rights

For relevant business outreach where permitted, and to establish, exercise or defend legal rights. You may object to direct marketing at any time.

5. Children and sensitive information

The public enquiry route is not intended for children’s data or special-category data. Please do not submit it unless TacticArc has expressly agreed the purpose and safeguards. Projects involving such information, profiling or significant automated decisions must be agreed and documented before supply.

6. Providers and disclosures

We do not sell personal information. We disclose it only where necessary, authorised or legally required.

  • Squarespace — public website hosting, delivery and website enquiry form.
  • Google Workspace — business email.
  • Google reCAPTCHA Enterprise — enquiry-form security and abuse prevention.
  • Vercel and Supabase — hosting, application delivery and backend services for the separate Engage platform.
  • Internal business records — customer relationship, sales, administration, outreach and support records.
  • Advisers, authorities and agreed project providers — only where needed for advice, compliance, protection of rights or an agreed customer project.

7. International processing

Service providers may process information, or make it accessible, outside the UK. Locations depend on the service, configuration, sub-processors and current provider terms.

Where UK law treats processing as a restricted transfer, safeguards may include UK adequacy regulations, contractual safeguards, recognised transfer mechanisms and provider data-processing terms.

8. Retention

  • Enquiries and prospective-customer correspondence — normally up to 24 months after the last meaningful interaction, subject to active opportunities, disputes or legal obligations.
  • Customer agreements, invoices, accounting and associated commercial records — six years or the applicable statutory period.
  • Relationship, sales and outreach records — while active and normally up to 24 months after the last meaningful interaction; a limited suppression record may be kept to honour an opt-out.
  • Campaign analytics — only for operation, reporting, administration and legitimate service improvement, with periodic review.
  • Technical project files — normally removed from active working systems within 30 days after completion, subject to agreed or reasonably necessary exceptions.

9. Security

TacticArc uses proportionate controls including least-privilege and bounded project access, version control where applicable, confidential build and source handling, controlled handover and access removal. Production credentials should not be supplied unless specifically agreed and securely handled. No certification or guaranteed security is claimed.

10. Your rights

Depending on the circumstances, you may ask for access, correction, deletion, restriction or portability, or object to processing. You may withdraw consent where consent is the basis and may always object to direct marketing. Rights can be limited by law and do not all apply to every activity.

Contact anthony@tacticarc.co.uk. Identity evidence may be requested where reasonably necessary.

11. Marketing, cookies and links

You may opt out of marketing using the route provided or by emailing us. Necessary service and project communications may still be sent. The separate Cookie Policy explains cookies and similar technologies. External links and the separate Engage platform may have distinct technical functions.

12. Questions and complaints

Please contact anthony@tacticarc.co.uk first so TacticArc can investigate. You may also complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint.

TacticArc has completed the ICO fee assessment and is completing its registration.

13. Changes

We update the effective and review dates when this policy changes. Material changes should be highlighted where appropriate.