Privacy Policy
Last updated: 22 August 2026
This policy explains what personal data Visibool Tech collects through this website and its client portal, why we collect it, who processes it, how long we keep it, and what you can ask us to do with it.
Who we are
Visibool Tech is a technology services company based in the United Kingdom. We build and support web applications, software, mobile apps, cloud infrastructure and security for other businesses.
For the purposes of UK GDPR we are the data controller for the personal data described below. You can reach us at hello@visibool.com.
Our services are sold to businesses rather than to consumers. Most of the personal data we hold is therefore about people acting for their employer — a name, a work email address, and what they told us about a project.
What we collect and why
When you use the contact form
We collect your name, email address, the service you are asking about and your message. A company name and phone number are optional. We use this only to understand your enquiry and reply to it.
When you have a portal account
Portal accounts are created by invitation. We hold your email address and an authentication record. We never see or store your password: it is handled by our authentication provider, which stores a cryptographic hash rather than the password itself, and there is no screen anywhere in our systems that can display it.
What you put into the portal
While a project is running, the portal holds the material you and we exchange: project descriptions, requirements you write, answers to our onboarding questions, files you upload, and messages between us. Some of that may contain personal data if you choose to put it there — a document with names in it, for example. We use it to deliver the work you have engaged us for and for no other purpose.
Anyone in your organisation who has a portal account can see all of it. There are no private messages and no per-person visibility inside an organisation. Nobody outside your organisation can see any of it.
Server logs
Our hosting provider records the ordinary information a web server sees: IP address, browser type, the page requested and the time. This is standard for any website and is used to serve pages, spot abuse and diagnose faults.
What we do not collect
We do not use any analytics tool. We do not use advertising or tracking cookies. We do not build profiles of visitors, and we do not sell or share personal data with anyone for marketing. See our Cookie Policy for the short version.
Our legal basis for using it
Under Article 6 of the UK GDPR we rely on:
- Performance of a contract — for everything in the client portal. We cannot deliver a project without holding what the project consists of.
- Legitimate interests — for contact form enquiries and server logs. Our interest is in replying to people who ask us to, and in keeping the site running and secure. We have considered whether this overrides your interests and think it does not, because the data is limited and you chose to send it.
- Legal obligation — where we have to keep records, for example for tax purposes.
We do not rely on consent for any of the above, which is why you are not asked for it. If that ever changes, we will ask properly rather than assume.
Who else processes it
We use a small number of service providers. Each is a data processor acting on our instructions, and none of them is permitted to use your data for their own purposes. We will name any of them on request.
Nothing else is involved. This site loads no fonts, icons, scripts or images from anyone else’s servers, so browsing it does not reveal your IP address to any third party.
- Database and authentication provider
- Stores portal accounts, project data, files and messages. Hosted in the EU (Ireland) region.
- Website hosting provider
- Serves this website and processes visitor IP addresses in order to route requests. Our host operates a global network, so a request may be handled outside the UK or EU.
- Email delivery provider
- Delivers the notifications this system sends: an alert to us when an enquiry or a project is submitted, and a message to you when a project is activated. Email addresses and the contents of those messages pass through this provider.
How long we keep it
- Contact enquiries — until the enquiry is resolved, or two years, whichever comes first.
- Portal accounts — for as long as the account exists. Tell us to close it and we will.
- Project data — for the duration of the engagement and for a reasonable period afterwards, so that we can answer questions about work we did and meet our own record-keeping obligations.
- Server logs — retained by our hosting provider under their schedule, not ours.
How deletion works
When you withdraw a file in the portal, it stops being shown and stops being downloadable, but the underlying file is not immediately destroyed. It remains in storage until it is removed as part of routine housekeeping. If you need something genuinely erased, ask us and we will do it properly.
Some records are deliberately append-only, because they document what was agreed: answers you give to project decisions, and the version history of requirements. Neither we nor you can edit or delete those through the portal. They can still be erased on request, but that is a manual operation rather than a button.
Your rights
You have the right to:
- ask what personal data we hold about you, and get a copy
- have inaccurate data corrected
- ask us to erase data, where we have no overriding reason to keep it
- ask us to restrict how we use it while a question about it is resolved
- receive data you gave us in a portable format
- object to processing we carry out on the basis of legitimate interests
To exercise any of these, email hello@visibool.com. We will respond within one month. We will not charge you, and we will not ask you to justify the request.
If you are not satisfied with how we have handled your data, you can complain to the Information Commissioner’s Office at ico.org.uk. We would rather you told us first so we can put it right.
International transfers
Our database is configured in the EU (Ireland). Our hosting provider operates a global network, so serving a page to you may involve processing in a country outside the UK or EU — including the United States. Our email provider may likewise process message contents outside the UK.
Where that happens, it is covered by the transfer safeguards in those providers’ terms, such as the UK International Data Transfer Addendum or Standard Contractual Clauses.
Security
Access to the portal is by invitation only and requires a password. Each client’s data is isolated from every other client’s, and that isolation is enforced independently of the interface, so it holds even if a fault were introduced in the interface itself. Data is encrypted in transit, and files are never left at publicly reachable addresses.
Those protections are covered by a verified suite of security checks that we run against the system and require to pass. We keep our systems patched and review access regularly.
If you believe you have found a vulnerability, email hello@visibool.com. We investigate every report and will keep you informed of the outcome.
Changes to this policy
We update this page when what we do changes. The date at the top tells you when it last changed. If a change materially affects how we use data about you, we will contact portal account holders directly rather than relying on you noticing.
Contact
Questions about this policy, or about anything we hold: hello@visibool.com. You can also use our contact form.