DSB Tech Consultancy Ltd

Privacy Policy

This policy explains how DSB Tech Consultancy Ltd collects, uses, protects, and retains personal data when authorised users access VisonDoc.

Last updated: 2 October 2026

1. Who we are

DSB Tech Consultancy Ltd is the controller for account and service-administration data processed through VisonDoc. Our address is 24 The Pines, Leigh WN7 3JS, United Kingdom. Contact our privacy team at dpo@dsb-tech.co.uk.

2. Information we process

  • Account data: email address, account identifier, role, sign-in and security information.
  • Service records: client connection details, review names, selected ticket types, review status, dates, and internal open-item notes.
  • Halo configuration: configuration requested live from an authorised Halo tenant while a review or export is prepared. The configuration response itself is not retained as a saved review payload.
  • Technical data: IP address, browser and device information, security events, diagnostics, and service logs where required to operate and protect the service.
  • AI drafting data: extracted Halo configuration facts needed to draft guide narrative. Configuration values are not invented.

3. Why and how we use information

  • To provide authorised access, reviews, document generation, and approved Halo publishing.
  • To secure accounts, investigate errors, prevent misuse, and maintain service availability.
  • To meet legal obligations and establish, exercise, or defend legal claims.
  • To administer our business and deliver contracted services to clients.

Our lawful bases may include performance of a contract, legitimate interests in operating and securing an internal business service, and compliance with legal obligations. Where DSB processes client-controlled data on a client’s instructions, DSB may act as a processor under the applicable agreement.

4. Sharing and processors

We may use carefully selected providers for hosting, authentication, security, and AI-assisted drafting. We share only what is necessary for those services. We may also disclose information where required by law, to protect rights or safety, or in connection with a lawful business transfer. We do not sell personal data.

5. International transfers

Some service providers may process information outside the United Kingdom. Where this occurs, we use recognised safeguards such as UK adequacy regulations or approved contractual protections.

6. Retention

We keep account and review metadata only for as long as needed for the service, contractual requirements, security, and legal obligations. Live Halo configuration responses are not stored as review payloads. Retention periods are reviewed and data is deleted or anonymised when no longer required.

7. Security

We use access controls, encrypted connections, protected credentials, and other reasonable technical and organisational measures. No transmission or storage method can be guaranteed to be completely secure.

8. Your rights

Depending on the circumstances, UK GDPR gives you rights to access, correct, erase, restrict, or object to processing; request data portability; and complain about how your information is used. Some rights are subject to legal exceptions. Contact dpo@dsb-tech.co.uk to make a request.

9. Complaints

Please contact us first so we can try to resolve your concern. You also have the right to complain to the UK Information Commissioner’s Office at ico.org.uk.

10. Children

This internal service is for authorised adult business users and is not directed to children.

11. Changes

We may update this policy when the service or legal requirements change. The latest version and update date will remain available on this page.