Data Processing & GDPR Notice
Last updated: June 2025
This notice explains how FluxIQ processes personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It supplements the Privacy Policy with additional technical detail relevant to engineers and business owners.
1. Data Controller
FluxIQ is the data controller for personal data processed through this platform. Contact for data protection matters: privacy@fluxiq.app
2. Categories of Personal Data Processed
| Category | Examples | Legal Basis |
|---|---|---|
| Identity data | Name, email address | Contract |
| Professional credentials | Gas Safe registration number, company | Legal obligation |
| Diagnostic session data | Fault codes, symptoms, AI responses | Contract |
| Feedback data | Engineer notes, outcome ratings | Contract / Legitimate interests |
| Technical data | IP address, browser type, session logs | Legitimate interests |
| Consent records | Accepted documents, versions, timestamps | Legal obligation |
| Payment data | Subscription status (our payment processor holds card data) | Contract |
3. Sub-Processors
FluxIQ uses trusted third-party providers to securely operate the platform, process payments, support AI-assisted diagnostics, and deliver essential functionality. Each provider operates under a written Data Processing Agreement and, where applicable, appropriate international transfer safeguards (such as UK Standard Contractual Clauses).
A current sub-processor list is available on request from privacy@fluxiq.app.
4. Automated Decision-Making
FluxIQ uses AI to generate diagnostic suggestions. This constitutes automated processing but does not constitute solely automated decision-making that produces legal or similarly significant effects. All AI outputs are presented as suggestions for review by a qualified human engineer. No automated decision is taken about you personally; AI suggestions relate to appliances, not individuals.
5. Data Security Measures
FluxIQ uses encryption, access controls, audit logging, and secure operational processes to protect user data. Technical and organisational measures are reviewed regularly and refined as the service evolves.
6. Retention Periods
| Data Type | Retention Period | Basis |
|---|---|---|
| Account / profile data | Account lifetime + 2 years | Contract / Legal |
| Diagnostic session data | 3 years from session date | Legitimate interests |
| Consent records | 6 years | Legal obligation |
| Audit log entries | 6 years | Legal obligation |
| Verification documents | 30 days post-decision | Legal obligation |
| Payment records (payment processor) | 7 years | Tax / Legal obligation |
7. Your Rights and How to Exercise Them
You may exercise your UK GDPR rights by emailing privacy@fluxiq.app. Responses will be provided within 30 calendar days. We may ask you to verify your identity before processing a request. Some rights are subject to exemptions; where an exemption applies we will explain why.
For erasure requests, note that some data (e.g., audit logs, consent records) may be retained where we have an overriding legal obligation to do so.
You may also exercise data management rights directly within your Account Settings page.
8. Data Breach Notification
In the event of a personal data breach we will notify the ICO within 72 hours where required by UK GDPR. Affected individuals will be notified without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
