Privacy Policy
Effective 30 April 2026
1. Who we are
This site and the TotalPath product are operated by Nopaque Limited, a company registered in England and Wales. Our registered office is 86-90 Paul Street, London, England, EC2A 4NE. In this policy, "we", "us", and "our" mean Nopaque Limited.
We are the data controller for the personal data described below. If you have any questions about this policy or how we handle your data, contact us at info@nopaque.co.uk.
2. What we collect
We collect personal data in the following ways:
- Account data when you sign up for TotalPath. This includes your name, email address, and any workspace details you provide.
- Contact form submissions when you reach out via the website. This includes anything you choose to send us.
- Usage data generated as you use TotalPath. This includes the tests you run, the calls TotalPath places on your behalf, the recordings produced by those calls, and metadata about your activity in the platform.
- Analytics data if you accept analytics cookies. See our cookie policy for the specifics.
- Technical data such as IP address, browser type, and request timestamps, captured in our server logs for security and debugging.
3. How we use it
- To provide TotalPath and let you sign in, run tests, and view results.
- To respond to enquiries you send via the contact form.
- To bill you for usage and maintain accurate financial records.
- To investigate abuse, secure our infrastructure, and meet legal obligations.
- To understand how the marketing site is used, if you accept analytics cookies.
We do not sell your personal data. We do not use your usage data to train third-party AI models.
4. Lawful bases for processing
Under UK GDPR we rely on the following lawful bases:
- Contract for processing necessary to deliver TotalPath under our terms with you.
- Legitimate interests for securing our services, responding to enquiries, and keeping records.
- Consent for analytics cookies and any optional marketing communications.
- Legal obligation for tax records and other statutory requirements.
5. Who we share it with
We share data with a small number of service providers who process it on our behalf:
- Cloud hosting and infrastructure providers (AWS).
- Telephony providers used to place real calls during tests.
- Email and customer-support tooling.
- Payment processors for billing.
- Google Analytics, only if you accept analytics cookies.
Each provider is contractually bound to process data only on our instructions and to keep it secure. We may also disclose data when required by law, by court order, or to protect our rights or those of our users.
6. International transfers
Some of our service providers are based outside the UK. Where personal data is transferred internationally, we rely on the UK Government's adequacy decisions, the UK's International Data Transfer Agreement (IDTA), or the EU Standard Contractual Clauses with the UK Addendum, as appropriate. Google Analytics traffic, if enabled, is governed by Google's standard data-protection terms.
7. Retention
We keep personal data only as long as we need it for the purposes set out above. Account data is kept while your account is active and for a reasonable period afterwards to handle disputes and meet legal obligations. Test recordings and usage data follow the retention windows in our terms and your workspace settings. Analytics data is retained according to the limits configured in Google Analytics.
8. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you.
- Have inaccurate data corrected.
- Have your data erased in certain circumstances.
- Restrict or object to our processing.
- Receive your data in a portable format.
- Withdraw consent at any time, where we rely on consent.
To exercise any of these rights, email us at info@nopaque.co.uk. We will respond within one month.
If you are unhappy with how we handle your data, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk. We would appreciate the chance to address your concerns first.
9. Security
We use reasonable technical and organisational measures to protect personal data, including encryption in transit, encryption at rest where appropriate, access controls, and regular reviews of our infrastructure. No system is completely secure. If we ever detect a breach affecting your data we will notify you and the ICO as required by law.
10. Updates
We may update this policy from time to time. The effective date at the top of the page reflects the latest version. Material changes will be flagged on the site or notified to account holders by email.