Legal

Privacy Policy

Last updated: 13 June 2026  ·  Effective: 13 June 2026

This Privacy Policy explains how DataShark ("we", "us", "our"), operating at thedatashark.com, collects, uses, stores, and protects your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who we are

Data Controller: DataShark
Website: thedatashark.com
Contact: hello@thedatashark.com

If you have any questions about how we handle your personal data, please contact us at the email address above.

2. What data we collect

We collect the following categories of personal data:

3. How we use your data

PurposeLawful basis
Creating and managing your accountContract (Article 6(1)(b))
Generating your policy documentsContract (Article 6(1)(b))
Processing paymentsContract (Article 6(1)(b))
Sending transactional emails (document ready, receipts)Contract (Article 6(1)(b))
Improving our platform and fixing bugsLegitimate interests (Article 6(1)(f))
Complying with legal obligationsLegal obligation (Article 6(1)(c))

4. Third-party processors

We share your data with the following third-party processors who act on our instructions:

ProcessorPurposeLocation
Paddle.comPayment processing and tax complianceUK/US
SendGrid (Twilio)Transactional email deliveryUS (SCCs in place)
NamecheapWebsite hosting and infrastructureUS (SCCs in place)

We do not sell your personal data to any third parties.

5. Data retention

We retain your account data for as long as your account is active. If you close your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or accounting purposes (up to 7 years for financial records).

Generated policy documents are retained and available for download for the period specified at the time of purchase.

6. Your rights

Under the UK GDPR, you have the following rights:

To exercise any of these rights, contact us at hello@thedatashark.com. We will respond within one calendar month.

7. Cookies

We use strictly necessary cookies to keep you logged in to your account (session cookies). We do not currently use advertising or analytics cookies. You can control cookies through your browser settings.

8. Security

We implement appropriate technical and organisational measures to protect your data, including HTTPS encryption, password hashing, and access controls. In the event of a data breach that poses a risk to your rights, we will notify the ICO within 72 hours and affected individuals without undue delay.

9. International transfers

Some of our processors are based outside the UK. Where we transfer data internationally, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the ICO.

10. Complaints

If you are unhappy with how we handle your data, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113. We would appreciate the opportunity to address your concerns first — please contact us at hello@thedatashark.com.

11. Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email. The current version is always available at thedatashark.com/privacy-policy.