01 · SCOPE AND CONTROLLER
Who is responsible for your information
Sapien Tech Ltd is the controller for personal data collected through this website, for its own business contacts and for the test accounts it administers in Predict Staging. In a future production customer service, the customer may be the controller for its workforce and operational data while Sapien Tech acts as processor. Those roles and instructions must be documented in writing before production customer data is enabled.
Mayfair, London W1S 4JL
United Kingdom
Registered officeFlat 3 Elleray, Pembroke Road
Woking GU22 7DQ
United Kingdom
Predict Staging is for controlled testing, not production customer data. A production deployment still requires approved data-processing terms, deployment details, a current processor list and an agreed retention schedule.
02 · DATA WE HANDLE
What information is involved
- Contact details and message content you submit to us.
- Basic request, device and security information needed to deliver and protect the site.
- Essential preferences and demonstration actions saved on your own device.
- Simulated machine readings shown only to explain the product workflow.
- Account identity, organisation membership, access role, sign-in and session records.
- MFA enrolment, authenticator status, recovery requests and password-reset events.
- Organisation, site, equipment, sensor and Hub details.
- Device telemetry such as vibration, temperature, battery, signal and timestamps.
- Alerts, acknowledgements, work orders, notes and timestamped audit history.
- Import files, extracted or staged records, review decisions and file-integrity identifiers.
- Notification destinations, routing choices and delivery status where alert delivery is enabled.
- Predict AI questions, recent chat context and the authorised records needed to answer them where AI is enabled.
We receive information directly from you, from an authorised customer administrator, from connected nodes and Hubs, or from an integration or document that the customer has chosen to provide. A connected customer controls which sites, devices and users are brought into its service. The Staging portal can contain real account data even when its machine and operational records are test or simulated data.
There is no statutory requirement to send us an enquiry. We need the marked contact details and message to respond. A connected customer contract will identify the account and operational data needed to provide that service; without it, the relevant feature may not work.
03 · WHY WE USE IT
Purpose and lawful basis
Under UK data-protection law, we need a lawful basis for each use. The basis depends on the information and the context. The typical categories are:
- Respond to enquiries and prepare a requested service
- Steps requested before a contract, or our legitimate interest in answering business enquiries.
- Provide and support a contracted Predict service
- Performance of a contract and, for business-user contacts, legitimate interests in delivering the service.
- Secure accounts, devices and the platform
- Legitimate interests in preventing misuse, investigating faults and protecting customers, plus legal obligations where they apply.
- Maintain reliability and improve the product
- Contract and legitimate interests, using the least personal data reasonably needed.
- Send optional communications
- Your consent where required, or legitimate interests where business communications are permitted. You can opt out.
- Meet legal and regulatory duties
- Compliance with a legal obligation or the establishment, exercise or defence of legal claims.
05 · HOW LONG WE KEEP IT
We keep data only while there is a reason
Retention depends on why the information was collected, the test or service context, support and security needs, any legal or accounting requirement, and whether a dispute is active. We use these criteria rather than keeping every category indefinitely.
- Enquiry records are kept while we respond and for a reasonable follow-up and business-record period.
- Staging account and test records are kept only while needed to operate, secure and evaluate the staging service and to meet applicable record-keeping needs.
- Security and audit records may be kept longer where needed to investigate misuse, demonstrate accountability or meet legal requirements.
- When information is no longer needed, we delete it or irreversibly anonymise it, subject to limited backup cycles.
This notice does not invent fixed deletion periods that have not yet been approved. A category-by-category retention and deletion schedule must be agreed before production customer data is accepted.
06 · PREDICT AI AND PEOPLE
AI supports a decision; it does not own it
Predict AI is designed to summarise evidence, explain a measured change, rank attention and suggest a next step. Its output is advisory and can be incomplete or wrong. Predict AI is read only: it cannot approve a diagnosis, change a setting, create or close a work order, stop a machine or make a safety decision. An authorised person must review the source evidence and approve any operational action.
Where the Staging AI feature is enabled, the question, up to the recent conversation shown in the portal and a tenant-scoped operational snapshot are sent to the configured AI provider to prepare an answer. The Sapien audit record stores a cryptographic digest of the question and request metadata rather than the raw question. We do not use Predict AI to make a decision about a person that has legal or similarly significant effects without meaningful human review.
Do not put passwords, authenticator codes, Hub access keys, special-category personal data, safety instructions or information outside your authorised organisation into Predict AI.
07 · YOUR RIGHTS
You can ask about your personal data
Depending on the circumstances, you may have the right to access, correct or erase your personal data; restrict or object to its use; receive certain data in a portable format; and withdraw consent at any time. These rights are not absolute and some legal exceptions may apply.
Email info@sapientech.co.uk with enough detail for us to understand the request. We may need to verify your identity. If your data belongs to a customer-managed account, we may direct the request to that customer as controller.
To make a formal data-protection complaint, use our website enquiry form and choose “Data-protection complaint”, or email the privacy contact with that subject. We will acknowledge a data-protection complaint within 30 days and respond without undue delay. This does not affect your right to complain directly to the ICO.
Your right to object: where we rely on legitimate interests, you can object to that use. Tell us what concerns you and we will assess the request and stop the processing unless we have a lawful reason to continue.
08 · BROWSER STORAGE
Essential storage only; no advertising or cross-site tracking
Across the current site, essential browser storage is used for dismissed notices and other device-local preferences. The public demo also saves the simulated settings, work orders and node details you choose to keep on that device. The installable phone experience may cache a small same-origin application shell so its interface can open reliably. These details are not used for behavioural advertising.
The authenticated Staging portal also uses strictly necessary local browser storage to maintain and refresh the signed-in session and support account security. It is separate from the simulated demo data stored on the device. If we introduce non-essential analytics or optional cookies, we will explain them and ask for consent before they are used where the law requires it.
09 · SECURITY, CHILDREN AND CHANGES
How we protect information
The current source uses role-limited access, MFA for privileged actions, tenant-scoped records and an audit trail. No internet service can be guaranteed completely secure, and source controls alone do not prove a production deployment. Security testing, processor due diligence, incident responsibilities and written production terms must be completed before live customer data is connected.
Children
Our website and Predict service are for organisations and workplace users. They are not directed to children under 18, and we do not knowingly seek their personal data.
Changes to this notice
We may update this notice when the service, providers or law changes. We will post the revised date here and use an appropriate additional notice if a change materially affects how we use personal data.
Ask us in plain English.
Use the enquiry form for a privacy question, rights request or data-protection complaint.
Open the privacy enquiry route →