Privacy Policy
Last Updated: 22 July 2026
1. About This Policy
Tandem Creative Dev Limited ("Tandem", "we", "us", or "our") is a company registered in England and Wales under company number 16681301, with its registered office at 113-115 Fonthill Road, London, N4 3HH.
We are committed to protecting personal data and handling it lawfully, fairly and transparently. This policy explains how we handle personal data under the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018 ("DPA 2018").
We handle personal data in two distinct capacities, and different parts of this policy apply to each:
- As a data controller, for personal data we collect through our own website and in the ordinary course of running our business. Section 2 applies.
- As a data processor, for personal data we handle on behalf of our clients when designing, building, hosting or maintaining systems for them. Section 3 applies.
2. When We Act as a Data Controller
This section covers personal data we decide the purposes and means for ourselves.
2.1 Information we collect
When you submit an enquiry through our contact form or contact us directly, we collect:
- Name: first and last name
- Company name: if provided
- Email address
- Phone number: if provided
- Message content
We also hold contact details for clients, suppliers and prospective clients in the normal course of business correspondence.
2.2 How we use it and our lawful basis
We use this information solely to respond to your enquiry and to communicate with you about your request, and to manage our relationships with clients and suppliers.
Our lawful basis is legitimate interests: responding to people who contact us and administering our business relationships. Where you contact us about engaging our services, we may also rely on the need to take steps at your request prior to entering into a contract.
We do not use your information for marketing, and we do not sell personal data or share it with third parties for their own purposes.
2.3 Who we share it with
Enquiries are received and handled by email. We use third-party email and website hosting providers who act as our processors under written contracts and may handle this information on our behalf. We may also disclose information where we are required to do so by law.
2.4 How long we keep it
We keep enquiry correspondence for no longer than is necessary. Where an enquiry does not lead to an engagement, we delete it within 24 months of our last contact with you. Where an enquiry leads to an engagement, correspondence is retained for the duration of that engagement and for six years afterwards, in line with our legal and accounting obligations.
3. When We Act as a Data Processor
We design, build, host and maintain software for our clients. Where those systems hold personal data about our clients' own users, our client is the data controller and we act as their data processor. We process that data only on our client's documented instructions and never for our own purposes.
If you are a user of a system we have built for a client, that client's own privacy notice governs how your personal data is handled and is the right place to look for details of what is collected, why, and on what lawful basis. This policy does not replace it.
In that role we commit to the following:
- We process personal data only on the documented instructions of the controller, including in relation to any transfers outside the UK.
- We engage sub-processors, such as infrastructure and hosting providers, only with the controller's authorisation and under written contracts imposing equivalent obligations.
- We ensure that anyone authorised to process the data is subject to a duty of confidentiality.
- We implement appropriate technical and organisational security measures, as described in Section 4.
- We assist the controller in responding to requests from individuals exercising their rights, and in meeting their obligations around security, breach notification and data protection impact assessments.
- We notify the controller without undue delay on becoming aware of a personal data breach.
- At the end of an engagement, we delete or return personal data at the controller's choice, except where we are required by law to retain it.
- We make available the information necessary to demonstrate compliance with these obligations.
Requests from individuals about data held in a client system are passed to the relevant controller, who is responsible for responding. If you contact us directly about such a request, we will tell you who the controller is and forward your request to them.
4. How We Protect Personal Data
We apply technical and organisational measures appropriate to the risk, including:
- Encryption of data in transit using current TLS standards, and encryption at rest on the managed platforms we use
- Multi-factor authentication on the administrative accounts and services we use to operate client systems
- Individually assigned accounts with no shared credentials, and access granted on a least-privilege basis
- Key-based authentication for server access, with password authentication disabled
- Credentials and secrets held outside version control and injected at runtime
- Automated dependency and vulnerability scanning in our development pipelines, with security updates applied promptly
- Restricting access to correspondence and client systems to those who need it
No method of transmission or storage is completely secure, but we review these measures regularly and update them as our systems and the threat landscape change.
5. Transfers Outside the United Kingdom
Some of the infrastructure and service providers we use operate outside the United Kingdom. Where personal data is transferred outside the UK, we rely on an appropriate safeguard, which will be either the UK's adequacy regulations for the destination country, or the International Data Transfer Agreement, or the EU Standard Contractual Clauses together with the UK Addendum.
Where we act as a processor, the specific arrangements for a given system are set out in the relevant client's own privacy notice, and any transfers are made on that client's instructions.
6. Your Data Protection Rights
Under the UK GDPR and DPA 2018 you have the right to:
- Be informed about how we collect and use your personal data
- Access the personal data we hold about you
- Have inaccurate personal data corrected
- Have your personal data erased in certain circumstances
- Restrict our processing of your personal data in certain circumstances
- Receive your personal data in a structured, commonly used and machine-readable format, and have it transmitted to another organisation, in certain circumstances
- Object to our processing of your personal data, including at any time where it is processed for direct marketing
- Not be subject to decisions based solely on automated processing which produce legal or similarly significant effects
- Withdraw your consent at any time, where our processing is based on consent
To exercise any of these rights in relation to data we hold as a controller, contact us at max@runintandem.com. We will respond within one month. There is no charge, unless a request is manifestly unfounded or excessive.
If your request relates to a system we operate on behalf of a client, please see Section 3.
7. Cookies
Our website does not use analytics, advertising or tracking cookies.
8. Complaints
If you have a concern about how we have handled your personal data, please contact us first at max@runintandem.com so that we can try to resolve it.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection:
- Website: ico.org.uk/make-a-complaint
- Telephone: 0303 123 1113
9. Changes to This Policy
We may update this policy from time to time. Any changes will be posted on this page with a revised date. Where changes are significant, we will take reasonable steps to bring them to the attention of those affected.
10. Contact Us
For any questions about this policy or how we handle personal data:
Email: max@runintandem.com
Address: Tandem Creative Dev Limited, 27 Dingley Pl, London EC1V 8BR