Privacy Policy
Privacy Policy
Last updated: 12/06/2026
1. About this Privacy Policy
This Privacy Policy explains how Thames Innovation Systems Limited collects, uses, stores and shares personal information when you:
- visit the OnePal website;
- create or use a OnePal account;
- purchase or enquire about OnePal services;
- communicate with us;
- attend a demonstration, meeting or event;
- receive marketing communications from us; or
- otherwise interact with Thames Innovation Systems Limited.
It also explains the circumstances in which we process personal information on behalf of organisations using the OnePal platform.
Please read this Privacy Policy carefully. By using our website or services, you acknowledge that you have been informed about how we process personal information.
This Privacy Policy should be read alongside our:
- Terms and Conditions;
- Cookie Policy;
- Data Processing Agreement;
- Subprocessor List; and
- any additional privacy information provided when information is collected.
2. Who We Are
OnePal is operated by:
Thames Innovation Systems Limited
Trading as OnePal, Compliance Tablet
Company number: 16057073
Registered office: The Block, 52 Richmond Court, Exeter, Devon, United Kingdom, EX4 3RD
Privacy email: support@compliancetablet.co.uk
Website: https://www.compliancetablet.co.uk
Thames Innovation Systems Limited is responsible for deciding how and why personal information is used where we act as a data controller.
In this Privacy Policy:
- “OnePal”, “we”, “us” and “our” mean Thames Innovation Systems Limited;
- “Customer” means a business or organisation that purchases, trials or uses OnePal;
- “User” means an individual authorised to access a OnePal account; and
- “Customer Data” means information uploaded, recorded or otherwise processed through OnePal by or on behalf of a Customer.
3. Our Role as Controller and Processor
Our legal role depends on why personal information is being processed.
3.1 When we act as a controller
We normally act as a data controller for personal information used to:
- operate our website;
- register and administer Customer accounts;
- manage subscriptions and payments;
- communicate with Customers and Users;
- provide customer support;
- maintain platform security;
- investigate suspicious activity;
- manage sales enquiries and business relationships;
- conduct lawful business-to-business marketing;
- comply with legal and regulatory obligations; and
- establish, exercise or defend legal claims.
As controller, we determine why and how this information is processed.
3.2 When we act as a processor
When a Customer enters information about its staff, clients, residents, service users, contractors or other individuals into OnePal, the Customer will normally be the data controller and Thames Innovation Systems Limited will normally act as its data processor.
In these circumstances:
- the Customer decides why the information is collected;
- the Customer decides what information is entered;
- the Customer determines which Users may access it;
- the Customer is responsible for identifying a lawful basis;
- the Customer is responsible for providing appropriate privacy information to affected individuals; and
- we process the information on the Customer’s documented instructions.
Our processing of Customer Data is also governed by our Data Processing Agreement.
Individuals seeking to exercise rights concerning information entered by a Customer should normally contact that Customer first. We will provide reasonable assistance to the Customer where required.
4. Personal Information We Collect
Depending on how you interact with us, we may collect the following categories of personal information.
4.1 Identity information
This may include:
- name;
- job title;
- employer or organisation;
- username;
- account identifier;
- profile photograph, where provided; and
- signature or confirmation of completed activities.
4.2 Contact information
This may include:
- business email address;
- telephone number;
- business address;
- billing address; and
- preferred communication method.
4.3 Account and organisation information
This may include:
- organisation name;
- business sector;
- site or location information;
- account role;
- user permissions;
- subscription plan;
- licence allocation;
- account status;
- activation information; and
- records of accepted terms and policies.
4.4 Payment and transaction information
This may include:
- billing contact details;
- invoice information;
- payment status;
- transaction references;
- subscription history;
- VAT information; and
- partial payment-method information supplied by our payment provider.
Full payment-card details will normally be collected and processed directly by our payment provider rather than stored by OnePal.
4.5 Communications
This may include:
- emails;
- support messages;
- enquiry forms;
- meeting notes;
- demonstration requests;
- feedback;
- complaints;
- telephone call notes; and
- communications through professional networking or social-media platforms.
4.6 Technical and usage information
This may include:
- IP address;
- browser type;
- device type;
- operating system;
- login times;
- session information;
- pages or features accessed;
- error and diagnostic information;
- security events;
- approximate location derived from an IP address;
- cookie identifiers; and
- platform activity and audit logs.
4.7 Marketing information
This may include:
- marketing preferences;
- communication history;
- responses to campaigns;
- event attendance;
- professional interests;
- publicly available business information; and
- records of objections, unsubscribes or suppression preferences.
4.8 Customer Data
Customers and Users may enter a wide range of information into OnePal, including:
- digital assessments;
- compliance records;
- photographs;
- incident reports;
- audit records;
- tasks and operational records;
- staff information;
- training records;
- documents;
- site information;
- messages;
- schedules;
- timesheets;
- signatures;
- form responses; and
- information concerning residents, clients, patients or service users.
The exact information processed depends on how each Customer configures and uses OnePal.
5. Special-Category and Sensitive Information
Customer Data may contain information that is sensitive or subject to additional legal protection, including information concerning:
- physical or mental health;
- disabilities;
- racial or ethnic origin;
- religious or philosophical beliefs;
- trade-union membership;
- biometric information;
- sexual orientation;
- safeguarding matters;
- medication or care;
- workplace incidents; or
- criminal allegations or offences.
Customers must not enter special-category or criminal-offence information into OnePal unless:
- it is necessary for a legitimate business, care, employment, safety or regulatory purpose;
- the Customer has identified an appropriate lawful basis;
- an additional legal condition applies where required;
- affected individuals have received appropriate privacy information;
- access is restricted to authorised Users; and
- suitable organisational and security measures are in place.
Where we process this information as a processor, we do so on the Customer’s documented instructions and not for our own independent purposes.
We do not use Customer Data containing health, care, employment or safeguarding information for advertising.
6. How We Obtain Personal Information
We may obtain personal information:
- directly from you;
- from a Customer that creates an account for you;
- from another User within your organisation;
- through use of the OnePal website or platform;
- from payment and technology providers;
- from event organisers or professional networks;
- from public business websites and directories;
- from Companies House or similar public registers;
- from professional social-media profiles;
- from referral partners; and
- from other lawful public or commercial business sources.
Where we obtain personal information indirectly, we will provide privacy information where required unless an applicable legal exception applies.
7. How and Why We Use Personal Information
We only use personal information where we have an appropriate lawful basis.
7.1 Providing and administering OnePal
We use account, identity, contact and organisation information to:
- register Users;
- create and maintain accounts;
- authenticate access;
- activate subscriptions;
- deliver requested platform functionality;
- administer licences;
- communicate about the service;
- provide support; and
- manage renewals and cancellations.
Our lawful bases are:
- performance of a contract;
- steps requested before entering into a contract; and
- our legitimate interests in supplying and administering a business software service.
7.2 Payments and financial administration
We use billing and transaction information to:
- collect subscription payments;
- issue invoices;
- maintain financial records;
- manage overdue payments;
- prevent payment fraud; and
- meet tax and accounting obligations.
Our lawful bases are:
- performance of a contract;
- compliance with legal obligations; and
- our legitimate interests in receiving payment and maintaining accurate financial records.
7.3 Customer support and communications
We use contact and communication information to:
- respond to enquiries;
- resolve technical issues;
- provide onboarding;
- arrange demonstrations;
- investigate complaints;
- provide service notices; and
- maintain records of Customer communications.
Our lawful bases are:
- performance of a contract;
- steps requested before entering into a contract; and
- our legitimate interests in supporting Customers and improving our service.
7.4 Platform operation and improvement
We may use technical, usage and diagnostic information to:
- operate the platform;
- diagnose errors;
- monitor performance;
- improve usability;
- understand feature use;
- test updates;
- develop new functionality; and
- maintain compatibility with devices and infrastructure.
Our lawful basis is our legitimate interest in operating, maintaining and improving OnePal.
Where consent is required for a particular cookie or similar technology, we will rely on consent instead.
We may use aggregated or anonymised information that no longer identifies an individual for analytics, research, service planning and product development.
7.5 Security and misuse prevention
We use account, technical and activity information to:
- authenticate Users;
- monitor access;
- detect suspicious behaviour;
- investigate attempted misuse;
- prevent fraud;
- protect Customer Data;
- enforce licence restrictions;
- maintain audit trails; and
- protect our systems, Customers and Users.
Our lawful bases are:
- our legitimate interests in protecting OnePal and its Users;
- compliance with legal obligations; and
- establishment, exercise or defence of legal claims where necessary.
7.6 Legal and regulatory compliance
We may process information to:
- respond to lawful requests;
- comply with court orders;
- cooperate with regulators;
- fulfil tax and accounting requirements;
- investigate security incidents;
- respond to data-protection requests; and
- establish, exercise or defend legal claims.
Our lawful bases are:
- compliance with legal obligations;
- our legitimate interests in protecting our legal rights; and
- substantial public-interest conditions where applicable.
7.7 Business-to-business marketing
We may use professional contact information to communicate with existing and prospective business Customers about:
- OnePal products and services;
- demonstrations;
- trials;
- relevant platform features;
- events;
- regulatory or industry information; and
- related business services.
Depending on the circumstances, we rely on:
- consent;
- our legitimate interests in promoting OnePal to relevant business contacts; or
- the existing-customer marketing provisions permitted by applicable law.
We will not send marketing where doing so would be unlawful.
Every electronic marketing communication will identify us and provide a clear method of opting out.
You may object to direct marketing at any time. We may retain limited information on a suppression list to ensure that your preference is respected.
7.8 Corporate transactions
We may process and disclose relevant information in connection with:
- investment;
- financing;
- restructuring;
- a merger;
- an acquisition;
- the sale of assets; or
- the sale of all or part of the OnePal business.
Our lawful basis is our legitimate interest in managing and developing our business.
Any recipient will be required to handle personal information confidentially and lawfully.
8. Where Information Is Required
Some information is required to create an account, enter into a contract, process payments or provide the service.
Where required information is not supplied, we may be unable to:
- create or maintain an account;
- provide a subscription;
- process a payment;
- authenticate a User;
- respond to an enquiry; or
- provide requested support.
Optional fields will normally be identified as optional or may simply be left incomplete.
9. Sharing Personal Information
We may share personal information with the following categories of recipient where reasonably necessary.
9.1 Technology and service providers
These may include providers of:
- cloud hosting;
- database infrastructure;
- website hosting;
- authentication;
- email and communications;
- customer support;
- analytics;
- monitoring and error reporting;
- document generation;
- payment processing;
- accounting;
- customer relationship management;
- cybersecurity; and
- data backup.
These providers may act as processors, subprocessors or independent controllers, depending on the service they provide.
Our current service providers that process Customer Data should be identified in our Subprocessor List.
9.2 Professional advisers
We may disclose information to:
- solicitors;
- accountants;
- auditors;
- insurers;
- consultants; and
- other professional advisers
where reasonably necessary for advice, compliance, insurance, dispute management or protection of our rights.
9.3 Authorities and other lawful recipients
We may disclose information to:
- courts;
- law-enforcement bodies;
- regulators;
- tax authorities;
- government departments;
- fraud-prevention bodies; and
- other organisations
where required by law or reasonably necessary to prevent harm, investigate unlawful activity or protect legal rights.
9.4 Corporate transaction recipients
Information may be disclosed under appropriate confidentiality arrangements to prospective investors, purchasers, lenders or professional advisers involved in a corporate transaction.
10. No Sale of Personal Information
We do not sell Customer Data or personal information to data brokers.
We do not use Customer Data submitted through the OnePal platform to build advertising profiles or advertise unrelated third-party products to the individuals described in that data.
11. International Data Transfers
Some suppliers may process or permit access to personal information from countries outside the United Kingdom.
Where a restricted international transfer takes place, we will use an appropriate legal safeguard, which may include:
- a UK adequacy regulation;
- the UK International Data Transfer Agreement;
- the UK Addendum to approved standard contractual clauses;
- another legally recognised transfer mechanism; or
- a specific exception where permitted by law.
Where required, we will assess whether the transfer mechanism provides an appropriate level of protection and whether supplementary safeguards are necessary.
Further information about relevant suppliers and processing locations may be provided in our Subprocessor List or on request.
12. Data Security
We use technical and organisational measures designed to protect personal information against:
- unauthorised access;
- unlawful processing;
- accidental loss;
- alteration;
- destruction;
- unauthorised disclosure; and
- damage.
Depending on the nature of the information and service, these measures may include:
- access controls;
- user authentication;
- role-based permissions;
- encrypted communications;
- hosting security;
- activity logging;
- monitoring;
- vulnerability management;
- backups;
- staff confidentiality requirements;
- incident-response procedures; and
- restrictions on supplier access.
No internet-based system can be guaranteed to be completely secure or continuously available. Customers are also responsible for maintaining appropriate account permissions, device security, passwords, staff training and independent record-retention arrangements.
13. Personal Data Breaches
We maintain procedures for identifying, investigating and responding to suspected personal-data breaches.
Where we act as controller, we will assess whether notification to the Information Commissioner’s Office or affected individuals is required.
Where we act as a processor, we will notify the relevant Customer without undue delay after becoming aware of a confirmed personal-data breach affecting Customer Data and will provide reasonable assistance with the Customer’s response.
14. Data Retention
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, security and dispute-resolution requirements.
Our standard retention approach is as follows.
14.1 Enquiries and prospective-Customer records
We generally retain enquiry and business-development records for up to three years after the most recent meaningful interaction, unless:
- you object sooner;
- a longer period is justified by an active business relationship; or
- the information is required for a legal claim.
14.2 Customer account and contractual records
We generally retain account, contract and subscription records for the duration of the Customer relationship and for up to six years after it ends, where required for contractual, accounting or legal purposes.
14.3 Financial and transaction records
We generally retain invoices, transaction records and associated accounting information for the period required under applicable tax, accounting and company law, normally up to six years after the relevant financial period.
14.4 Support communications
We generally retain routine support records for up to three years after resolution.
Records connected with a dispute, security incident, complaint or legal claim may be retained longer where necessary.
14.5 Security and technical logs
Security, authentication, diagnostic and activity logs are retained for periods appropriate to their purpose and risk.
Routine logs will normally be retained for between 30 days and 24 months, unless a longer period is required to:
- investigate an incident;
- maintain an audit trail;
- comply with a Customer agreement;
- protect legal rights; or
- meet a legal obligation.
14.6 Marketing records
Marketing contact information is retained while we reasonably believe our services remain relevant and until you object, unsubscribe or the information becomes inaccurate.
Suppression records may be retained for as long as necessary to ensure that we continue to respect an objection or unsubscribe request.
14.7 Customer Data
Customer Data is generally retained:
- during the active subscription;
- for any agreed post-termination retrieval period; and
- within protected backup cycles for a limited period after deletion from active systems.
The applicable Data Processing Agreement, subscription plan or separate contract may specify additional retention or deletion arrangements.
Customers should export required information before cancelling or allowing an account to expire.
14.8 Legal holds
We may retain information beyond the normal period where necessary for:
- pending or anticipated litigation;
- a regulatory investigation;
- fraud prevention;
- a security investigation;
- enforcement of an agreement; or
- compliance with law.
When retention is no longer necessary, information will be deleted, anonymised or securely rendered inaccessible in accordance with our procedures.
15. Automated Decision-Making
We do not currently make decisions producing legal or similarly significant effects about individuals solely through automated processing.
OnePal may use automated rules to:
- generate alerts;
- display reminders;
- identify overdue items;
- organise records;
- flag unusual activity; or
- restrict access for security or payment reasons.
These functions support administration and human decision-making. Customers remain responsible for reviewing outputs and making appropriate decisions.
We will update this Privacy Policy if we introduce materially different automated decision-making.
16. Your Data-Protection Rights
Depending on the circumstances and applicable exemptions, you may have the right to:
- be informed about how your information is used;
- request access to your personal information;
- request correction of inaccurate information;
- request completion of incomplete information;
- request deletion of your information;
- request restriction of processing;
- object to processing based on legitimate interests;
- object at any time to direct marketing;
- request transfer of information you provided in a portable format;
- withdraw consent where processing is based on consent; and
- complain to the Information Commissioner’s Office.
Some rights apply only in particular circumstances. We may need to verify your identity before acting on a request.
Where OnePal processes information solely on behalf of a Customer, we may refer your request to that Customer.
We will not normally charge a fee for exercising a data-protection right. A reasonable fee may be permitted where a request is manifestly unfounded, excessive or repetitive, or we may be permitted to refuse the request.
To exercise a right, contact:
support@compliancetablet.co.uk
Please include sufficient information for us to identify you and understand the request.
17. Withdrawing Consent
Where we rely on consent, you may withdraw it at any time.
Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
You may withdraw marketing consent or unsubscribe by:
- using the unsubscribe option in an email;
- updating available account preferences; or
- contacting us at support@compliancetablet.co.uk
18. Complaints
Please contact us first if you have concerns about how personal information has been handled:
Privacy contact: Peter Jackson, Director
Email: support@compliancetablet.co.uk
Postal address: The Block, 52 Richmond Court, Exeter, Devon, United Kingdom, EX4 3RD
You also have the right to complain to the UK supervisory authority:
Information Commissioner’s Office
You can find current contact and complaint information on the ICO website at:
https://ico.org.uk/make-a-complaint/
If you are located outside the United Kingdom, you may also have the right to contact the data-protection authority in your jurisdiction.
19. Cookies and Similar Technologies
Our website and platform may use cookies, local storage, pixels, software development kits and similar technologies.
These technologies may be used to:
- provide essential website functions;
- maintain sessions;
- remember security or accessibility settings;
- authenticate Users;
- prevent fraud;
- measure performance;
- understand website use; and
- improve the service.
Where consent is legally required, non-essential technologies will not be used until an appropriate choice has been made.
You can manage available choices through our cookie banner or preference tool.
Further information, including the names, purposes and durations of technologies used, should be provided in our Cookie Policy.
Essential technologies cannot always be disabled because they are required for security, authentication or delivery of the service.
20. External Websites and Services
Our website or platform may contain links to websites, integrations or services operated by other organisations.
Those organisations are responsible for their own privacy practices. We recommend reviewing their privacy information before providing personal information or connecting an external service.
21. Children
OnePal is a business platform and is not intended to be registered or independently used by children.
Users creating accounts must be at least 18 years old or otherwise legally capable of entering into a binding business agreement.
Customer Data may contain information concerning children where a Customer lawfully uses OnePal for care, safeguarding, education, employment or another permitted organisational purpose.
In those circumstances, the Customer is responsible for:
- ensuring the processing is lawful;
- providing appropriate privacy information;
- applying suitable access restrictions;
- considering the interests and rights of the child; and
- complying with any additional sector-specific obligations.
22. Customer Responsibilities
Customers using OnePal are responsible for:
- deciding what Customer Data is collected;
- identifying lawful bases and any additional processing conditions;
- giving required privacy information;
- responding to data-subject requests;
- maintaining accurate records;
- assigning appropriate User permissions;
- preventing unauthorised access;
- configuring retention and exports appropriately;
- maintaining separate backups where required;
- notifying us promptly of suspected account compromise; and
- complying with applicable data-protection, employment, care, safeguarding and sector-specific laws.
This section does not reduce our own responsibilities under applicable data-protection law.
23. Changes to This Privacy Policy
We may update this Privacy Policy to reflect:
- changes to OnePal;
- changes in our processing activities;
- new suppliers or technologies;
- changes in law or regulatory guidance;
- security improvements; or
- changes to our business structure.
The updated version will be published with a revised “Last updated” date.
Where a change materially affects how we use personal information, we will take reasonable steps to provide additional notice through the website, platform or email.
24. Contact Us
For questions about this Privacy Policy or our handling of personal information, contact:
Thames Innovation Systems Limited
Trading as OnePal
Company number: 16057073
Registered office: The Block, 52 Richmond Court, Exeter, Devon, United Kingdom, EX4 3RD
Privacy contact: Peter Jackson, Director
Email: support@compliancetablet.co.uk
Website: https://www.compliancetablet.co.uk
