FLASH OPS LTD
Privacy Policy
Last updated: 8 August 2026
FLASH OPS LTD processes personal data in line with UK GDPR and the Data Protection Act 2018 when operating flashops.uk, intake forms, invoicing, payments orchestration, and client portals.
1. Data Controller
The data controller is FLASH OPS LTD, Company No. 17375809, United Kingdom. Contact: contact@flashops.uk.
2. Categories of Data We Process
We may process identity and contact data, project briefs, billing details, payment references (not full card PANs — handled by Stripe/PayPal), technical logs, and onboarding materials you voluntarily submit. Do not submit passwords or production secrets through public forms.
3. Purposes & Legal Bases (UK GDPR)
We process data to respond to enquiries (legitimate interests / contract steps), perform contracts and invoicing (contract), meet accounting and legal obligations (legal obligation), and improve security of our services (legitimate interests). Where consent is required (e.g. optional analytics cookies), we will request it.
4. Processors & International Transfers
We use carefully selected processors (e.g. email delivery, payment providers, hosting). Where data leaves the UK/EEA, we rely on appropriate safeguards such as UK IDTA/SCCs. Payment card data is processed directly by PCI-DSS compliant providers.
5. Retention, Security & Your Rights
We retain data only as long as needed for the stated purposes and statutory retention (e.g. financial records). We apply access controls, encryption in transit, and least-privilege practices. You may request access, rectification, erasure, restriction, portability, or object to certain processing by emailing contact@flashops.uk. You may complain to the UK ICO.
6. Updates to this Policy
We may update this Privacy Policy to reflect operational or legal changes. The “Last updated” date at the top will change when revisions are published on flashops.uk.
Company No. 17375809 · United Kingdom · contact@flashops.uk
