Privacy Policy and Data Protection – Compliance Tablet

Privacy Policy

Privacy Policy

Last updated: 12/06/2026

 

1. About this Privacy Policy

This Privacy Policy explains how Thames Innovation Systems Limited collects, uses, stores and shares personal information when you:

  • visit the OnePal website;
  • create or use a OnePal account;
  • purchase or enquire about OnePal services;
  • communicate with us;
  • attend a demonstration, meeting or event;
  • receive marketing communications from us; or
  • otherwise interact with Thames Innovation Systems Limited.

It also explains the circumstances in which we process personal information on behalf of organisations using the OnePal platform.

Please read this Privacy Policy carefully. By using our website or services, you acknowledge that you have been informed about how we process personal information.

This Privacy Policy should be read alongside our:

  • Terms and Conditions;
  • Cookie Policy;
  • Data Processing Agreement;
  • Subprocessor List; and
  • any additional privacy information provided when information is collected.

2. Who We Are

OnePal is operated by:

Thames Innovation Systems Limited
Trading as OnePal, Compliance Tablet
Company number: 16057073 
Registered office: The Block, 52 Richmond Court, Exeter, Devon, United Kingdom, EX4 3RD
Privacy email: support@compliancetablet.co.uk
Website: https://www.compliancetablet.co.uk

Thames Innovation Systems Limited is responsible for deciding how and why personal information is used where we act as a data controller.

In this Privacy Policy:

  • “OnePal”, “we”, “us” and “our” mean Thames Innovation Systems Limited;
  • “Customer” means a business or organisation that purchases, trials or uses OnePal;
  • “User” means an individual authorised to access a OnePal account; and
  • “Customer Data” means information uploaded, recorded or otherwise processed through OnePal by or on behalf of a Customer.

3. Our Role as Controller and Processor

Our legal role depends on why personal information is being processed.

3.1 When we act as a controller

We normally act as a data controller for personal information used to:

  • operate our website;
  • register and administer Customer accounts;
  • manage subscriptions and payments;
  • communicate with Customers and Users;
  • provide customer support;
  • maintain platform security;
  • investigate suspicious activity;
  • manage sales enquiries and business relationships;
  • conduct lawful business-to-business marketing;
  • comply with legal and regulatory obligations; and
  • establish, exercise or defend legal claims.

As controller, we determine why and how this information is processed.

3.2 When we act as a processor

When a Customer enters information about its staff, clients, residents, service users, contractors or other individuals into OnePal, the Customer will normally be the data controller and Thames Innovation Systems Limited will normally act as its data processor.

In these circumstances:

  • the Customer decides why the information is collected;
  • the Customer decides what information is entered;
  • the Customer determines which Users may access it;
  • the Customer is responsible for identifying a lawful basis;
  • the Customer is responsible for providing appropriate privacy information to affected individuals; and
  • we process the information on the Customer’s documented instructions.

Our processing of Customer Data is also governed by our Data Processing Agreement.

Individuals seeking to exercise rights concerning information entered by a Customer should normally contact that Customer first. We will provide reasonable assistance to the Customer where required.

4. Personal Information We Collect

Depending on how you interact with us, we may collect the following categories of personal information.

4.1 Identity information

This may include:

  • name;
  • job title;
  • employer or organisation;
  • username;
  • account identifier;
  • profile photograph, where provided; and
  • signature or confirmation of completed activities.

4.2 Contact information

This may include:

  • business email address;
  • telephone number;
  • business address;
  • billing address; and
  • preferred communication method.

4.3 Account and organisation information

This may include:

  • organisation name;
  • business sector;
  • site or location information;
  • account role;
  • user permissions;
  • subscription plan;
  • licence allocation;
  • account status;
  • activation information; and
  • records of accepted terms and policies.

4.4 Payment and transaction information

This may include:

  • billing contact details;
  • invoice information;
  • payment status;
  • transaction references;
  • subscription history;
  • VAT information; and
  • partial payment-method information supplied by our payment provider.

Full payment-card details will normally be collected and processed directly by our payment provider rather than stored by OnePal.

4.5 Communications

This may include:

  • emails;
  • support messages;
  • enquiry forms;
  • meeting notes;
  • demonstration requests;
  • feedback;
  • complaints;
  • telephone call notes; and
  • communications through professional networking or social-media platforms.

4.6 Technical and usage information

This may include:

  • IP address;
  • browser type;
  • device type;
  • operating system;
  • login times;
  • session information;
  • pages or features accessed;
  • error and diagnostic information;
  • security events;
  • approximate location derived from an IP address;
  • cookie identifiers; and
  • platform activity and audit logs.

4.7 Marketing information

This may include:

  • marketing preferences;
  • communication history;
  • responses to campaigns;
  • event attendance;
  • professional interests;
  • publicly available business information; and
  • records of objections, unsubscribes or suppression preferences.

4.8 Customer Data

Customers and Users may enter a wide range of information into OnePal, including:

  • digital assessments;
  • compliance records;
  • photographs;
  • incident reports;
  • audit records;
  • tasks and operational records;
  • staff information;
  • training records;
  • documents;
  • site information;
  • messages;
  • schedules;
  • timesheets;
  • signatures;
  • form responses; and
  • information concerning residents, clients, patients or service users.

The exact information processed depends on how each Customer configures and uses OnePal.

5. Special-Category and Sensitive Information

Customer Data may contain information that is sensitive or subject to additional legal protection, including information concerning:

  • physical or mental health;
  • disabilities;
  • racial or ethnic origin;
  • religious or philosophical beliefs;
  • trade-union membership;
  • biometric information;
  • sexual orientation;
  • safeguarding matters;
  • medication or care;
  • workplace incidents; or
  • criminal allegations or offences.

Customers must not enter special-category or criminal-offence information into OnePal unless:

  • it is necessary for a legitimate business, care, employment, safety or regulatory purpose;
  • the Customer has identified an appropriate lawful basis;
  • an additional legal condition applies where required;
  • affected individuals have received appropriate privacy information;
  • access is restricted to authorised Users; and
  • suitable organisational and security measures are in place.

Where we process this information as a processor, we do so on the Customer’s documented instructions and not for our own independent purposes.

We do not use Customer Data containing health, care, employment or safeguarding information for advertising.

6. How We Obtain Personal Information

We may obtain personal information:

  • directly from you;
  • from a Customer that creates an account for you;
  • from another User within your organisation;
  • through use of the OnePal website or platform;
  • from payment and technology providers;
  • from event organisers or professional networks;
  • from public business websites and directories;
  • from Companies House or similar public registers;
  • from professional social-media profiles;
  • from referral partners; and
  • from other lawful public or commercial business sources.

Where we obtain personal information indirectly, we will provide privacy information where required unless an applicable legal exception applies.

7. How and Why We Use Personal Information

We only use personal information where we have an appropriate lawful basis.

7.1 Providing and administering OnePal

We use account, identity, contact and organisation information to:

  • register Users;
  • create and maintain accounts;
  • authenticate access;
  • activate subscriptions;
  • deliver requested platform functionality;
  • administer licences;
  • communicate about the service;
  • provide support; and
  • manage renewals and cancellations.

Our lawful bases are:

  • performance of a contract;
  • steps requested before entering into a contract; and
  • our legitimate interests in supplying and administering a business software service.

7.2 Payments and financial administration

We use billing and transaction information to:

  • collect subscription payments;
  • issue invoices;
  • maintain financial records;
  • manage overdue payments;
  • prevent payment fraud; and
  • meet tax and accounting obligations.

Our lawful bases are:

  • performance of a contract;
  • compliance with legal obligations; and
  • our legitimate interests in receiving payment and maintaining accurate financial records.

7.3 Customer support and communications

We use contact and communication information to:

  • respond to enquiries;
  • resolve technical issues;
  • provide onboarding;
  • arrange demonstrations;
  • investigate complaints;
  • provide service notices; and
  • maintain records of Customer communications.

Our lawful bases are:

  • performance of a contract;
  • steps requested before entering into a contract; and
  • our legitimate interests in supporting Customers and improving our service.

7.4 Platform operation and improvement

We may use technical, usage and diagnostic information to:

  • operate the platform;
  • diagnose errors;
  • monitor performance;
  • improve usability;
  • understand feature use;
  • test updates;
  • develop new functionality; and
  • maintain compatibility with devices and infrastructure.

Our lawful basis is our legitimate interest in operating, maintaining and improving OnePal.

Where consent is required for a particular cookie or similar technology, we will rely on consent instead.

We may use aggregated or anonymised information that no longer identifies an individual for analytics, research, service planning and product development.

7.5 Security and misuse prevention

We use account, technical and activity information to:

  • authenticate Users;
  • monitor access;
  • detect suspicious behaviour;
  • investigate attempted misuse;
  • prevent fraud;
  • protect Customer Data;
  • enforce licence restrictions;
  • maintain audit trails; and
  • protect our systems, Customers and Users.

Our lawful bases are:

  • our legitimate interests in protecting OnePal and its Users;
  • compliance with legal obligations; and
  • establishment, exercise or defence of legal claims where necessary.

7.6 Legal and regulatory compliance

We may process information to:

  • respond to lawful requests;
  • comply with court orders;
  • cooperate with regulators;
  • fulfil tax and accounting requirements;
  • investigate security incidents;
  • respond to data-protection requests; and
  • establish, exercise or defend legal claims.

Our lawful bases are:

  • compliance with legal obligations;
  • our legitimate interests in protecting our legal rights; and
  • substantial public-interest conditions where applicable.

7.7 Business-to-business marketing

We may use professional contact information to communicate with existing and prospective business Customers about:

  • OnePal products and services;
  • demonstrations;
  • trials;
  • relevant platform features;
  • events;
  • regulatory or industry information; and
  • related business services.

Depending on the circumstances, we rely on:

  • consent;
  • our legitimate interests in promoting OnePal to relevant business contacts; or
  • the existing-customer marketing provisions permitted by applicable law.

We will not send marketing where doing so would be unlawful.

Every electronic marketing communication will identify us and provide a clear method of opting out.

You may object to direct marketing at any time. We may retain limited information on a suppression list to ensure that your preference is respected.

7.8 Corporate transactions

We may process and disclose relevant information in connection with:

  • investment;
  • financing;
  • restructuring;
  • a merger;
  • an acquisition;
  • the sale of assets; or
  • the sale of all or part of the OnePal business.

Our lawful basis is our legitimate interest in managing and developing our business.

Any recipient will be required to handle personal information confidentially and lawfully.

8. Where Information Is Required

Some information is required to create an account, enter into a contract, process payments or provide the service.

Where required information is not supplied, we may be unable to:

  • create or maintain an account;
  • provide a subscription;
  • process a payment;
  • authenticate a User;
  • respond to an enquiry; or
  • provide requested support.

Optional fields will normally be identified as optional or may simply be left incomplete.

9. Sharing Personal Information

We may share personal information with the following categories of recipient where reasonably necessary.

9.1 Technology and service providers

These may include providers of:

  • cloud hosting;
  • database infrastructure;
  • website hosting;
  • authentication;
  • email and communications;
  • customer support;
  • analytics;
  • monitoring and error reporting;
  • document generation;
  • payment processing;
  • accounting;
  • customer relationship management;
  • cybersecurity; and
  • data backup.

These providers may act as processors, subprocessors or independent controllers, depending on the service they provide.

Our current service providers that process Customer Data should be identified in our Subprocessor List.

9.2 Professional advisers

We may disclose information to:

  • solicitors;
  • accountants;
  • auditors;
  • insurers;
  • consultants; and
  • other professional advisers

where reasonably necessary for advice, compliance, insurance, dispute management or protection of our rights.

9.3 Authorities and other lawful recipients

We may disclose information to:

  • courts;
  • law-enforcement bodies;
  • regulators;
  • tax authorities;
  • government departments;
  • fraud-prevention bodies; and
  • other organisations

where required by law or reasonably necessary to prevent harm, investigate unlawful activity or protect legal rights.

9.4 Corporate transaction recipients

Information may be disclosed under appropriate confidentiality arrangements to prospective investors, purchasers, lenders or professional advisers involved in a corporate transaction.

10. No Sale of Personal Information

We do not sell Customer Data or personal information to data brokers.

We do not use Customer Data submitted through the OnePal platform to build advertising profiles or advertise unrelated third-party products to the individuals described in that data.

11. International Data Transfers

Some suppliers may process or permit access to personal information from countries outside the United Kingdom.

Where a restricted international transfer takes place, we will use an appropriate legal safeguard, which may include:

  • a UK adequacy regulation;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to approved standard contractual clauses;
  • another legally recognised transfer mechanism; or
  • a specific exception where permitted by law.

Where required, we will assess whether the transfer mechanism provides an appropriate level of protection and whether supplementary safeguards are necessary.

Further information about relevant suppliers and processing locations may be provided in our Subprocessor List or on request.

12. Data Security

We use technical and organisational measures designed to protect personal information against:

  • unauthorised access;
  • unlawful processing;
  • accidental loss;
  • alteration;
  • destruction;
  • unauthorised disclosure; and
  • damage.

Depending on the nature of the information and service, these measures may include:

  • access controls;
  • user authentication;
  • role-based permissions;
  • encrypted communications;
  • hosting security;
  • activity logging;
  • monitoring;
  • vulnerability management;
  • backups;
  • staff confidentiality requirements;
  • incident-response procedures; and
  • restrictions on supplier access.

No internet-based system can be guaranteed to be completely secure or continuously available. Customers are also responsible for maintaining appropriate account permissions, device security, passwords, staff training and independent record-retention arrangements.

13. Personal Data Breaches

We maintain procedures for identifying, investigating and responding to suspected personal-data breaches.

Where we act as controller, we will assess whether notification to the Information Commissioner’s Office or affected individuals is required.

Where we act as a processor, we will notify the relevant Customer without undue delay after becoming aware of a confirmed personal-data breach affecting Customer Data and will provide reasonable assistance with the Customer’s response.

14. Data Retention

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, security and dispute-resolution requirements.

Our standard retention approach is as follows.

14.1 Enquiries and prospective-Customer records

We generally retain enquiry and business-development records for up to three years after the most recent meaningful interaction, unless:

  • you object sooner;
  • a longer period is justified by an active business relationship; or
  • the information is required for a legal claim.

14.2 Customer account and contractual records

We generally retain account, contract and subscription records for the duration of the Customer relationship and for up to six years after it ends, where required for contractual, accounting or legal purposes.

14.3 Financial and transaction records

We generally retain invoices, transaction records and associated accounting information for the period required under applicable tax, accounting and company law, normally up to six years after the relevant financial period.

14.4 Support communications

We generally retain routine support records for up to three years after resolution.

Records connected with a dispute, security incident, complaint or legal claim may be retained longer where necessary.

14.5 Security and technical logs

Security, authentication, diagnostic and activity logs are retained for periods appropriate to their purpose and risk.

Routine logs will normally be retained for between 30 days and 24 months, unless a longer period is required to:

  • investigate an incident;
  • maintain an audit trail;
  • comply with a Customer agreement;
  • protect legal rights; or
  • meet a legal obligation.

14.6 Marketing records

Marketing contact information is retained while we reasonably believe our services remain relevant and until you object, unsubscribe or the information becomes inaccurate.

Suppression records may be retained for as long as necessary to ensure that we continue to respect an objection or unsubscribe request.

14.7 Customer Data

Customer Data is generally retained:

  • during the active subscription;
  • for any agreed post-termination retrieval period; and
  • within protected backup cycles for a limited period after deletion from active systems.

The applicable Data Processing Agreement, subscription plan or separate contract may specify additional retention or deletion arrangements.

Customers should export required information before cancelling or allowing an account to expire.

14.8 Legal holds

We may retain information beyond the normal period where necessary for:

  • pending or anticipated litigation;
  • a regulatory investigation;
  • fraud prevention;
  • a security investigation;
  • enforcement of an agreement; or
  • compliance with law.

When retention is no longer necessary, information will be deleted, anonymised or securely rendered inaccessible in accordance with our procedures.

15. Automated Decision-Making

We do not currently make decisions producing legal or similarly significant effects about individuals solely through automated processing.

OnePal may use automated rules to:

  • generate alerts;
  • display reminders;
  • identify overdue items;
  • organise records;
  • flag unusual activity; or
  • restrict access for security or payment reasons.

These functions support administration and human decision-making. Customers remain responsible for reviewing outputs and making appropriate decisions.

We will update this Privacy Policy if we introduce materially different automated decision-making.

16. Your Data-Protection Rights

Depending on the circumstances and applicable exemptions, you may have the right to:

  • be informed about how your information is used;
  • request access to your personal information;
  • request correction of inaccurate information;
  • request completion of incomplete information;
  • request deletion of your information;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • object at any time to direct marketing;
  • request transfer of information you provided in a portable format;
  • withdraw consent where processing is based on consent; and
  • complain to the Information Commissioner’s Office.

Some rights apply only in particular circumstances. We may need to verify your identity before acting on a request.

Where OnePal processes information solely on behalf of a Customer, we may refer your request to that Customer.

We will not normally charge a fee for exercising a data-protection right. A reasonable fee may be permitted where a request is manifestly unfounded, excessive or repetitive, or we may be permitted to refuse the request.

To exercise a right, contact:

support@compliancetablet.co.uk

Please include sufficient information for us to identify you and understand the request.

17. Withdrawing Consent

Where we rely on consent, you may withdraw it at any time.

Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

You may withdraw marketing consent or unsubscribe by:

  • using the unsubscribe option in an email;
  • updating available account preferences; or
  • contacting us at support@compliancetablet.co.uk

18. Complaints

Please contact us first if you have concerns about how personal information has been handled:

Privacy contact: Peter Jackson, Director
Email: support@compliancetablet.co.uk
Postal address: The Block, 52 Richmond Court, Exeter, Devon, United Kingdom, EX4 3RD

You also have the right to complain to the UK supervisory authority:

Information Commissioner’s Office

You can find current contact and complaint information on the ICO website at:

https://ico.org.uk/make-a-complaint/

If you are located outside the United Kingdom, you may also have the right to contact the data-protection authority in your jurisdiction.

19. Cookies and Similar Technologies

Our website and platform may use cookies, local storage, pixels, software development kits and similar technologies.

These technologies may be used to:

  • provide essential website functions;
  • maintain sessions;
  • remember security or accessibility settings;
  • authenticate Users;
  • prevent fraud;
  • measure performance;
  • understand website use; and
  • improve the service.

Where consent is legally required, non-essential technologies will not be used until an appropriate choice has been made.

You can manage available choices through our cookie banner or preference tool.

Further information, including the names, purposes and durations of technologies used, should be provided in our Cookie Policy.

Essential technologies cannot always be disabled because they are required for security, authentication or delivery of the service.

20. External Websites and Services

Our website or platform may contain links to websites, integrations or services operated by other organisations.

Those organisations are responsible for their own privacy practices. We recommend reviewing their privacy information before providing personal information or connecting an external service.

21. Children

OnePal is a business platform and is not intended to be registered or independently used by children.

Users creating accounts must be at least 18 years old or otherwise legally capable of entering into a binding business agreement.

Customer Data may contain information concerning children where a Customer lawfully uses OnePal for care, safeguarding, education, employment or another permitted organisational purpose.

In those circumstances, the Customer is responsible for:

  • ensuring the processing is lawful;
  • providing appropriate privacy information;
  • applying suitable access restrictions;
  • considering the interests and rights of the child; and
  • complying with any additional sector-specific obligations.

22. Customer Responsibilities

Customers using OnePal are responsible for:

  • deciding what Customer Data is collected;
  • identifying lawful bases and any additional processing conditions;
  • giving required privacy information;
  • responding to data-subject requests;
  • maintaining accurate records;
  • assigning appropriate User permissions;
  • preventing unauthorised access;
  • configuring retention and exports appropriately;
  • maintaining separate backups where required;
  • notifying us promptly of suspected account compromise; and
  • complying with applicable data-protection, employment, care, safeguarding and sector-specific laws.

This section does not reduce our own responsibilities under applicable data-protection law.

23. Changes to This Privacy Policy

We may update this Privacy Policy to reflect:

  • changes to OnePal;
  • changes in our processing activities;
  • new suppliers or technologies;
  • changes in law or regulatory guidance;
  • security improvements; or
  • changes to our business structure.

The updated version will be published with a revised “Last updated” date.

Where a change materially affects how we use personal information, we will take reasonable steps to provide additional notice through the website, platform or email.

24. Contact Us

For questions about this Privacy Policy or our handling of personal information, contact:

Thames Innovation Systems Limited
Trading as OnePal
Company number: 16057073
Registered office: The Block, 52 Richmond Court, Exeter, Devon, United Kingdom, EX4 3RD
Privacy contact: Peter Jackson, Director
Email: support@compliancetablet.co.uk 
Website: https://www.compliancetablet.co.uk

Plymouth Office: 25 The Crescent, Plymouth PL1 3AD | Limited Company Number: 16057073 | VAT Number: GB491313989 ©Copyright. All rights reserved.

Information icon

We need your consent to load the translations

We use a third-party service to translate the website content that may collect data about your activity. Please review the details in the privacy policy and accept the service to view the translations.