Legal

Privacy Policy

Last updated 30 September 2026

1. Who we are

OSP Retail Limited (“OSP”, “we”, “us”) provides retail space planning consultancy and software, including the MSO (Macro Space Optimisation) and Windlass platforms. We trade as OSP Retail.

Registered companyOSP Retail Limited, registered in England and Wales, company number 09186420
Registered office227a West Street, Fareham, Hampshire, PO16 0HZ, United Kingdom
Privacy contactprivacy@osp-retail.co.uk
Websitewww.osp-retail.co.uk (osp-retail.com redirects here)

We have not appointed a Data Protection Officer because the law does not require one for our activities. Our CTO, Shaun Brown, is responsible for data protection and can be reached at privacy@osp-retail.co.uk.

2. What this policy covers

This policy explains how we handle personal data when we act as a controller, meaning we decide why and how it is used. When we process data on a customer’s behalf inside our SaaS products, we act as a processor, and our contract with that customer governs the processing.

Who you areOur roleWhat governs your data
Visitor to our websiteControllerThis policy
Prospect, enquirer or event contactControllerThis policy
Contact at a customer, partner or supplier (for the business relationship)ControllerThis policy
User of a SaaS product: account, sign-in, security and usage data we need to run the serviceControllerThis policy
Person whose data a customer loads into a SaaS product (e.g. staff names, store data, photos)ProcessorThe customer’s own privacy notice, and our Data Processing Agreement (DPA) with that customer

Consultancy projects. When we work inside a client’s own systems, such as their RELEX environment, we act as that client’s processor or sub-processor. The client’s contract with us governs that data.

Our SaaS products are the MSO (Macro Space Optimisation) and Windlass platforms, supported by our helpdesk. Business customers use them under separate SaaS contracts, which include our DPA.

This policy does not cover third-party websites we link to, such as RELEX Solutions. Please read their own privacy notices.

3. Personal data we collect

We collect business contact and technical data. We do not seek special category data, such as health or ethnicity, and ask you not to send it to us.

CategoryExamplesWhere it comes from
Enquiry and demo requestsFirst and last name, work email, company, role, your messageYou, via our contact page or email
Business relationship dataName, job title, employer, work email and phone, meeting notes, correspondenceYou, your colleagues, LinkedIn, events, RELEX and other partners who introduce you
Marketing preferencesWhether you have opted in or out, and your interactions with our emails and LinkedIn contentYou, Microsoft Dynamics 365, LinkedIn
SaaS account dataName, work email, user ID, tenant/organisation, role and permissions, account status, last sign-inYour organisation’s Microsoft Entra ID or Google account when you sign in, and your organisation’s administrators
SaaS security and diagnostic dataIP address, device and browser type, pages and API endpoints used, timestamps, error logs linked to your email, diagnostic bundles you choose to sendGenerated automatically when you use the service
Support dataTickets you raise, your messages and attachments, and our repliesYou, via our helpdesk or email
Website technical dataIP address, browser, requested pages and timestamps in our hosting provider’s server logsGenerated automatically when you visit
Supplier and partner contactsName, work contact details, contract and payment contactsYou or your organisation

How the contact form works today. When you submit the form, it opens your own email client with your details filled in, and nothing is sent to us until you press send.

4. How we use your data and our lawful basis

We rely mainly on legitimate interests, meaning running and growing a B2B business in ways you would reasonably expect. We have balanced these interests against your rights. You can object at any time (section 10).

PurposeData usedLawful basis
Respond to enquiries and arrange demosEnquiry dataLegitimate interests (answering you); contract steps if you are entering into a contract
Manage customer, partner and supplier relationshipsBusiness relationship dataLegitimate interests; performance of our contract with your organisation
Provide, secure and support our SaaS productsSaaS account, diagnostic and support dataLegitimate interests (delivering the service your organisation has bought, and keeping it secure); performance of contract where you are the customer
Monitor and improve our products and websiteDiagnostic and technical data, aggregated where possibleLegitimate interests
Send B2B marketing about our services and eventsBusiness contact data, marketing preferencesLegitimate interests for corporate contacts; consent where PECR requires it (e.g. sole traders and individual subscribers). Every email has an unsubscribe link
Comply with law, resolve disputes, enforce our termsAny relevant dataLegal obligation; legitimate interests
Business transactions, such as a sale or restructuring of OSPAny relevant dataLegitimate interests

Automated decisions. We do not make decisions about you that have legal or similarly significant effects based solely on automated processing.

5. Cookies and similar technologies

Our website currently sets no cookies and uses no analytics or advertising trackers. Our fonts are served from our own site, so your browser does not contact Google or other third parties when you visit.

Our SaaS products use strictly necessary browser storage to sign you in and keep your session secure. This includes Microsoft or Google sign-in tokens and your workspace preferences. They cannot work without it, so it does not need consent.

If we add analytics or marketing tools, we will update this section. We will ask for your consent through a banner before setting any non-essential cookie. Since February 2026, UK law allows first-party analytics that only produce statistics about our site to run without consent, if we explain them clearly and give an easy way to object. Advertising tracking still needs consent.

6. Who we share your data with

We do not sell personal data. We share it only with the parties below, under contracts that require them to protect it and use it only on our instructions.

RecipientPurposeLocation
Microsoft (Azure, Microsoft 365, Entra ID, Dynamics 365, Application Insights)Hosting our website, SaaS products and helpdesk; databases and storage; sign-in; email; CRM; monitoringUK (Azure UK South and UK West); some Microsoft support and service operations outside the UK
GoogleSign-in, for customers who use Google accountsUK / EU / USA
GitHub (Microsoft)Source code hosting and deployment; holds no customer dataUSA
LinkedIn (Microsoft)B2B marketing and networkingIreland / USA
RELEX Solutions and other implementation partnersJoint projects for shared customers, and introductionsEU / UK
Professional advisers (lawyers, accountants, insurers)Advice and complianceUK
Authorities, regulators, courtsWhere the law requires it, or to protect our rightsUK
A buyer or investorIf OSP is sold or restructured, under confidentiality termsVaries

SaaS customers can get our current list of sub-processors, and advance notice of changes, under their DPA.

7. International transfers

We host our website and SaaS products, and store their data, in Microsoft Azure data centres in the UK (UK South and UK West). Some of our suppliers can access data from outside the UK, for example for support.

When personal data leaves the UK or EEA, we protect it using one of these:

  • An adequacy decision (the UK and EU recognise each other, and both recognise some other countries).
  • For the USA, the UK Extension to the EU–US Data Privacy Framework, where the recipient is certified.
  • The UK International Data Transfer Agreement or UK Addendum, and the EU Standard Contractual Clauses, with a transfer risk assessment.

Contact us for a copy of the relevant safeguards.

8. How long we keep your data

We keep personal data only as long as we need it for the purposes in section 4. Then we delete or anonymise it.

DataRetention period
Enquiries that do not lead to a relationship2 years from last contact
Business relationship and contract recordsLength of the relationship plus 6 years (the limitation period for contract claims)
Marketing preferences and opt-outsWhile you are on our list plus 1 year. We keep a minimal suppression record indefinitely so we don’t contact you after you opt out
SaaS user accountsWhile your organisation’s subscription is active, then deleted within 90 days of it ending, unless the SaaS contract says otherwise
SaaS monitoring and diagnostic telemetry30 days
SaaS error logs linked to a user90 days
Database server logs3 days
Database backups35 days, on a rolling basis
Helpdesk tickets3 years from closure
Records needed for legal or tax reasonsAs the law requires (usually 6 years)

9. How we keep your data secure

We use appropriate technical and organisational measures to protect personal data, including:

  • Encryption in transit (TLS) and at rest in Azure databases and storage.
  • Sign-in through Microsoft Entra ID or Google, so your organisation’s own password and multi-factor authentication policies apply.
  • Keeping each customer’s data logically separate, with role-based access controls in our products.
  • Secrets held in Azure Key Vault, and staff access limited to those who need it.
  • Security monitoring, logging and regular review of our systems and suppliers.
  • Automated database backups, kept for 35 days.

No system is completely secure. If a breach is likely to put your rights at risk, we will tell you and the ICO as the law requires. Where we act as a processor, we will tell the affected customer without undue delay.

10. Your rights and how to complain

You have rights over your personal data under UK GDPR and, where it applies, EU GDPR. To use any of them, email privacy@osp-retail.co.uk with enough detail for us to identify you. We will reply within one month. We may extend that by up to two further months for complex requests and will tell you if we do.

RightWhat it means
AccessGet a copy of the personal data we hold about you
RectificationHave inaccurate or incomplete data corrected
ErasureHave your data deleted where we no longer have a lawful reason to keep it
RestrictionAsk us to pause using your data, for example while we check its accuracy
PortabilityReceive data you gave us in a machine-readable format, where we process it by consent or contract
ObjectionObject to processing based on legitimate interests, and to direct marketing at any time
Withdraw consentWhere we rely on consent, withdraw it at any time without affecting earlier processing

If you use one of our SaaS products through your employer, your employer controls that data. Please send requests to them first. We will pass on any request we receive and help them respond.

Complaints. Please contact us first, by email to privacy@osp-retail.co.uk, so we can try to put things right. We will acknowledge your complaint within 30 days and respond without undue delay. If you are unhappy with our response, you can complain to the Information Commissioner’s Office (ICO), or its successor, at ico.org.uk/make-a-complaint or on 0303 123 1113. If you are in the EU/EEA, you can also complain to your local data protection authority.

11. Children, changes and contact

Children. Our website and products are for businesses and are not aimed at anyone under 18. We do not knowingly collect children’s data.

Changes to this policy. We may update this policy. The date at the top shows when it last changed. Where a change significantly affects how we use your data, we will tell affected customers and users directly.

Contact us. For any question about this policy or your data, email privacy@osp-retail.co.uk or write to the Privacy Lead, OSP Retail Limited, 227a West Street, Fareham, Hampshire, PO16 0HZ.