HOURS: Mon - Fri, 9:00 AM - 5:00 PM GMT/BST PHONE: +44 131 560 6795 EMAIL: support@onlineadventures.co.uk
LAST UPDATED: SEPTEMBER 2026

Privacy Notice (UK GDPR & DPA 2018)

“This website is operated by ONLINE ADVENTURES LTD (trading as Flowpilot, Company No. SC661043). Registered address: Redyetts, Brucefield Estate, Forestmill, Alloa, Clackmannanshire, Scotland, FK10 3QF, United Kingdom.”

1. Data Controller Identification & Statutory Lineage

This statutory Privacy Notice outlines the data processing obligations, lawful bases, and consumer data rights maintained by ONLINE ADVENTURES LTD, trading as Flowpilot ("we", "us", "our"). As a commercial software automation engineering entity registered in Scotland (Company Number SC661043), we act as the designated Data Controller under the Data Protection Act 2018 and the retained Regulation (EU) 2016/679 (the UK GDPR).

We are committed to absolute transparency regarding the personal and corporate data we collect, store, process, and retain through our production web services at onlineadventures.co.uk and our associated technical APIs.

// Data Protection Officer & Statutory Point of Contact

Corporate Entity: ONLINE ADVENTURES LTD (trading as Flowpilot)

Registered & Facility Address: Redyetts, Brucefield Estate, Forestmill, Alloa, Clackmannanshire, Scotland, FK10 3QF, United Kingdom

Direct Telephone Line: +44 131 560 6795

Data Protection Inquiries: support@onlineadventures.co.uk

Escalation / Corporate Accounts: accounts@onlineadventures.co.uk

2. Categories of Personal & Corporate Data Collected

In the delivery of production-grade AI automation architectures, technical assessments, and client ticketing support, we process the following data classes:

  • Direct Identity & Contact Attributes: Full individual names, corporate organization names, business email addresses, direct work telephone numbers, and job titles provided during inquiry transmissions.
  • Technical Engagement Scopes: Project specifications, business process bottleneck descriptions, system architecture notes, target ERP/CRM integration schemas, and communications sent through our ingestion forms.
  • Commercial & Billing Data: Transaction records, corporate registered addresses, company registration numbers, VAT registration details (where applicable), BACS transfer references, and billing settlement histories.
  • Telemetry & Access Logs: IP addresses, browser user-agent tokens, TLS handshake telemetry, referrers, and diagnostic session identifiers collected for security auditability and denial-of-service mitigation.

3. Lawful Bases for Processing under UK GDPR Article 6

In strict compliance with Article 6(1) of the UK GDPR, we never collect or process personal data without an explicit, verifiable legal ground:

Data Category Processing Purpose Lawful Basis (UK GDPR Art. 6)
Inquiry Ingestion & Contact Records Triage commercial requests, prepare technical automation quotes, and respond to incoming inquiries. Article 6(1)(b) — Performance of a contract or taking steps at the data subject's request prior to entering into a contract.
Client System Access Credentials & Project Logs Deployment, monitoring, and orchestration of bespoke AI agents and enterprise automation workflows. Article 6(1)(b) — Execution and fulfillment of contracted Statement of Work (SOW).
Invoicing, Tax & Accounting Records Statutory accounting, corporation tax reporting, VAT reconciliation, and anti-fraud verification. Article 6(1)(c) — Compliance with legal and statutory obligations (Companies Act 2006, HMRC).
Security Telemetry & Server Audit Logs Protect infrastructure against cyber threats, unauthorized API abuse, and intrusion attempts. Article 6(1)(f) — Legitimate interests in securing enterprise systems and ensuring continuous uptime.
Performance & Analytical Cookies Measuring aggregated platform traffic, conversion metrics, and system usability under Google Consent Mode v2. Article 6(1)(a) — Explicit, affirmative consent granted via our Cookie Management Banner.

4. Data Retention Periods & Erasure Schedules

We adhere to the UK GDPR principle of storage limitation. Data is retained only for as long as necessary to fulfill the operational, legal, and financial purposes for which it was originally collected:

  • Unconverted Inquiries & Scoping Data: Retained for a maximum of 24 months from the date of initial transmission to allow follow-up architecture discussions, after which records are cryptographically wiped.
  • Active Client Production Contracts & Deliverables: Retained for the duration of the commercial relationship plus 6 years in accordance with the UK statutory limitation period for contractual disputes.
  • Financial & VAT Tax Invoices: Retained for 6 statutory years following the end of the relevant financial tax year pursuant to HMRC and Companies House requirements.
  • Security & Web Server Audit Logs: Retained in rotating immutable log wells for 90 days before automated deletion.

5. Third-Party Data Processors & Hosting Architecture

We do not sell, rent, or trade personal data to marketing brokers or unverified third parties. Personal data is shared exclusively with certified cloud sub-processors bound by stringent Data Processing Agreements (DPAs) compliant with UK GDPR Article 28:

  • Cloud Infrastructure: Amazon Web Services (AWS UK/London Region) and Google Cloud Platform (europe-west2) for sovereign cloud compute and encrypted database storage.
  • Corporate Banking & Financial Settlement: Regulated UK financial institutions and merchant banking networks for BACS, Faster Payments, and credit clearance.
  • Analytics Infrastructure: Google LLC (Google Analytics 4 configured under Google Consent Mode v2 with default denied states and IP anonymization).

6. International Transfers Outside the United Kingdom

Where technical automation services necessitate data processing outside the United Kingdom or European Economic Area (EEA), transfers occur strictly under valid legal transfer mechanisms recognized under UK data protection law:

  • To countries with formal UK Adequacy Regulations issued by the Secretary of State; or
  • Pursuant to the International Data Transfer Addendum to the European Commission Standard Contractual Clauses (SCCs), accompanied by documented Transfer Risk Assessments (TRAs).

7. Your Statutory Rights under the UK GDPR

As an individual whose personal data is processed by ONLINE ADVENTURES LTD, you possess enforceable statutory rights:

  • Right of Access (Subject Access Request / SAR): You have the right to request a confirmation of processing and a free digital copy of your personal data.
  • Right to Rectification: You may require us to rectify inaccurate or incomplete corporate contact data immediately.
  • Right to Erasure ("Right to be Forgotten"): You may request the deletion of your personal data where retention is no longer justified under legal bases.
  • Right to Restriction of Processing: You may request that we temporarily halt processing while data accuracy or lawful basis is contested.
  • Right to Data Portability: You may request your data in a structured, commonly used, machine-readable format (JSON/CSV).
  • Right to Object: You may object to data processing conducted under legitimate interests at any time.
  • Rights Regarding Automated Profiling: We do not conduct automated profiling producing legal effects without human engineering intervention.

8. How to Exercise Your Rights

To exercise any of the statutory rights enumerated above, submit a formal request to our operations desk:

Email: support@onlineadventures.co.uk
Postal Mail: Data Protection Officer, ONLINE ADVENTURES LTD, Redyetts, Brucefield Estate, Forestmill, Alloa, Clackmannanshire, Scotland, FK10 3QF, United Kingdom.
Statutory Response Timeline: We respond to all verified requests within one calendar month (30 days) at zero administrative fee, as mandated by the UK GDPR.

9. Right to Lodge a Complaint with the UK ICO

If you have concerns regarding our data processing practices or consider our response unsatisfactory, you have the statutory right under Section 165 of the Data Protection Act 2018 to lodge a complaint directly with the UK supervisory authority:

// Information Commissioner's Office (ICO)

Supervisory Body: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Helpline Telephone: 0303 123 1113 (UK national rate) / +44 1625 545 745

Official Website: https://ico.org.uk