# **PIIQ - Privacy Policy**

**Document Version:** 1.0.0
**Effective Date:** January 5, 2026

This Privacy Policy (Part B) describes how Nearfield.ai Ltd ("Nearfield.ai" or "the Processor") handles the Subscriber's data and the sensitive Source Data uploaded for processing via the PIIQ Service.

---

## **1. The PIIQ Data Model (Data Controller vs. Processor)**

The Subscriber acknowledges and agrees that:

- **Subscriber's Role:** The Subscriber is typically the **Data Controller** (or joint Controller/Processor) acting on behalf of their clients.
- **Company's Role:** Nearfield.ai acts solely as a **Data Processor** with respect to the Source Data (the DSAR/FOIA files) uploaded by the Subscriber for automated processing and redaction. We process this data strictly under the instructions of the Subscriber.

See the Data Processing Agreement (Part C) for full processor obligations on Source Data.

---

## **2. Information Collected**

We collect two types of information:

**2.1 Subscriber Account Data**
Information provided directly by the Subscriber (e.g., name, contact details, billing information, account login credentials). This is used solely for service provision, billing, and technical support.

**2.2 Source Data (for Processing)**
The files containing PII uploaded by the Subscriber for DSAR/FOIA fulfillment. This data is the most sensitive and is handled under strict security protocols (see Section 4).

---

## **3. Use of Information**

**3.1 Service Provision**
Subscriber Account Data is used to manage the subscription, provide technical support, and process payments.

**3.2 Legal Basis for Processing**
- **Subscriber Account Data:** Processed under Article 6(1)(b) - performance of contract
- **Source Data:** Processed under Article 6(1)(f) - legitimate interests (DSAR/FOIA compliance) or Article 6(1)(c) - legal obligation, as instructed by the Data Controller

---

## **4. Data Security, Sovereignty, and Retention**

**4.1 UK Data Storage & Processing**
All Source Data is processed and temporarily stored in secure, certified **UK Data Centres**.

**4.2 Encryption**

- **Data in Transit:** All data transmission is protected using HTTPS, with a minimum of TLS 1.2 and TLS 1.3 negotiated by default.
- **Data at Rest:** Uploaded files are encrypted at rest using AES-256 encryption on AWS infrastructure. Data is processed in secure, isolated compute environments (AWS Lambda). Processing occurs in volatile memory with automatic destruction upon completion. No persistent storage of Source Data beyond temporary processing caches. All infrastructure uses AWS-managed encryption keys.
- **Data Deletion:** Volatile memory is automatically cleared when processing completes. Temporary files are securely deleted immediately after use. No Source Data retained on processing servers.

---

## **5. Data Sharing and Disclosure**

The Processor **does not sell** any Subscriber Account Data or Source Data to third parties. Data is only shared:

- **As required by law or legal process.**
- **With approved sub-processors** (e.g., UK-based cloud infrastructure partners) under strict contractual terms ensuring GDPR compliance and data security equal to or greater than the Company's standards.

---

## **6. User Data Subject Rights**

**6.1 Data Subject Request Handling**
All data subject requests must be directed to the Subscriber (Data Controller). Nearfield.ai will assist Partners in responding to such requests within 72 hours of notification.

**6.2 Right to Erasure**
Subscribers may request immediate deletion of Source Data at any time via the platform dashboard or by contacting compliance@nearfield.ai

**6.3 Data Portability**
Upon request, Nearfield.ai will provide Source Data in a structured, commonly used format within 30 days.

**6.4 Right to Complain**
Subscribers have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) if they believe their data protection rights have been violated:

**Information Commissioner's Office**
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Tel: 0303 123 1113
Website: ico.org.uk

---

## **7. Changes to the Privacy Policy**

We reserve the right to update this Privacy Policy periodically to reflect changes in our practices or legal requirements. Changes will be effective upon posting. Continued use of the Service constitutes acceptance of the updated policy.

---

## **8. Contact Information**

For any inquiries or concerns regarding this Privacy Policy, please contact:

**Email:** compliance@nearfield.ai

**Nearfield.ai Ltd**
44 Queens Drive, Stockport, SK4 3JW
