1. Who we are
IngrIntel Ltd ("IngrIntel", "we", "us") is a private limited company registered in England and Wales under company number [Company number], with its registered office at [Registered office address], United Kingdom. We are registered with the Information Commissioner's Office (ICO) under registration number [ICO registration number].
For the personal data described in this policy we are the controller. Where our business customers upload their own data (for example formulation or supplier information) to the platform, we act as their processor under our Data Processing Addendum.
Contact us about privacy at privacy@ingrintel.co.uk or by post to our registered office. We are not required to appoint a Data Protection Officer; privacy matters are handled by our founder.
2. The data we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Name, work email, company, hashed password, plan | You, at sign-up |
| Usage data | Searches, ingredients viewed, comparisons and substitution runs | Your use of the dashboard |
| Enquiry data | Name, email, company, message content | Contact form or email |
| Billing data | Billing contact, invoices, VAT number (card details are collected and held by Stripe, never by us) | You / payment processor |
| Technical data | IP address, browser type, device, security logs | Automatically when you visit |
| Cookie data | See our Cookie Policy | Your browser |
| Marketing preferences | Whether you opted in to product emails | You |
We do not knowingly collect special category data and ask you not to submit any. Our service is intended for businesses and is not directed at children under 16.
3. How and why we use it (lawful bases)
| Purpose | Lawful basis (UK GDPR Art. 6) |
|---|---|
| Creating and running your account; providing the platform | Contract (6(1)(b)) |
| Account security, fraud prevention, rate limiting, logs | Legitimate interests (6(1)(f)) — keeping the service secure |
| Showing your recent activity and usage statistics in the dashboard | Contract (6(1)(b)) |
| Responding to enquiries and demo requests | Legitimate interests (6(1)(f)) or steps prior to contract (6(1)(b)) |
| Service emails (password resets, security notices, billing) | Contract (6(1)(b)) |
| Marketing emails | Consent (6(1)(a)) — withdraw any time |
| Analytics and marketing cookies | Consent (6(1)(a)) and PECR reg. 6 |
| Improving the product, including aggregated and de-identified analytics | Legitimate interests (6(1)(f)) |
| Accounting, tax and legal obligations | Legal obligation (6(1)(c)) |
We do not sell personal data, and we do not use customer formulation data to train models made available to other customers. We do not carry out automated decision-making that produces legal or similarly significant effects on you.
4. Who we share it with
We share personal data only with service providers who process it on our instructions under written contracts, including:
- Cloud hosting and database providers (infrastructure)
- Transactional email providers (password resets, notifications)
- Stripe Payments Europe, Ltd. and its affiliates (subscriptions, payments, invoicing and fraud prevention) — Stripe acts as an independent controller for some payment data; see Stripe's Privacy Policy
- Analytics providers — only if you consent to analytics cookies
- Professional advisers (lawyers, accountants) and, where required by law, regulators, courts or law enforcement
- A buyer or successor in the event of a merger, acquisition or sale of assets, subject to equivalent protections
A current list of sub-processors is available on request from privacy@ingrintel.co.uk.
5. International transfers
We aim to store data in the UK or EEA. Where a provider processes data outside the UK, we rely on UK adequacy regulations, or the ICO International Data Transfer Agreement / UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment. For EU users, transfers from the EEA to the UK rely on the European Commission's UK adequacy decision.
6. How long we keep it
| Data | Retention |
|---|---|
| Account data | For the life of your account, then deleted within 30 days of closure (backups roll off within 90 days) |
| Dashboard activity history | 12 months, then automatically deleted |
| Contact enquiries | 24 months from last contact |
| Billing and tax records | 6 years after the end of the financial year (HMRC requirements) |
| Security logs | Up to 90 days |
| Consent records | For as long as the consent applies plus 6 years |
7. How we protect it
Passwords are hashed with scrypt and never stored in plain text. Sessions use encrypted, HTTP-only, SameSite cookies. Data is encrypted in transit (TLS). We apply least-privilege access, rate limiting and regular security reviews. If a personal data breach is likely to result in a risk to your rights we will notify the ICO within 72 hours and, where required, inform you without undue delay.
8. Your rights
Under UK GDPR (and EU GDPR where applicable) you have the right to:
- Access your personal data — download it instantly from Dashboard → Settings → Export, or ask us
- Rectify inaccurate data — edit your profile in Settings
- Erase your data — delete your account in Settings
- Restrict or object to processing based on legitimate interests
- Data portability — receive your data in a machine-readable format
- Withdraw consent at any time (marketing emails, cookies) without affecting prior processing
- Object at any time to direct marketing
We respond within one month (extendable by two months for complex requests). There is normally no fee. We may need to verify your identity.
9. Complaints
Please contact us first so we can try to resolve your concern. You also have the right to complain to the UK Information Commissioner's Office: ico.org.uk/make-a-complaint, telephone 0303 123 1113. If you are in the EU/EEA you may complain to your local supervisory authority.
10. Changes
We will post any changes on this page and update the "last updated" date. If changes are material we will notify account holders by email before they take effect.