Who is responsible for your information
Upgraded OS is operated by The Upgrade Authority Ltd, company number 13983241. Our registered office is Henleaze House Business Centre, 13 Harbury Road, Henleaze, Bristol, England, BS9 4PN.
When an organisation uses Upgraded OS to manage its properties, bookings, people and work, that organisation will usually decide why its workspace information is used. The organisation is then the controller and we process that information on its instructions. We remain responsible for the information used to administer accounts, keep the service secure, provide support, improve the product and meet our own legal obligations.
Information we handle
Account information can include your name, email address, telephone number, profile image, job role, organisation, workspace membership and authentication details.
Workspace information can include property and reservation records, contact details, messages, emails, text and chat messages, call recordings and transcripts, tasks, calendars, photos, videos, documents, booking information, transaction records and accounting information. The exact information depends on the features and connected services chosen by your organisation.
Technical information can include internet protocol address, browser and application version, device identifiers, push notification tokens, session and security events, feature activity, diagnostics and performance information. The public website also uses privacy conscious analytics to understand which pages are useful.
How we use information
We use information to provide and secure Upgraded OS, authenticate users, show the correct workspace, deliver messages and notifications, store and retrieve operational records, provide support, diagnose faults, prevent misuse, improve the service and meet legal and contractual duties.
Some features use artificial intelligence to summarise, classify, draft or assist with work. Only the information needed for the requested feature is sent to the relevant service provider. Access controls continue to apply to the result.
Our legal reasons for processing
We process information where it is necessary to provide the service under a contract, where it supports our legitimate interests in operating a secure and useful business service, where we must comply with a legal obligation, or where consent is the appropriate basis. An organisation using Upgraded OS may rely on its own legal reasons when it controls workspace information.
Who receives information
Information is visible to authorised people in the relevant workspace according to their access. We also use carefully selected providers for hosting, storage, communications, application monitoring, analytics, artificial intelligence and customer support. Connected property, booking, payment and communications services receive information when an authorised user chooses or configures that connection.
We may disclose information to professional advisers, regulators, courts, law enforcement or another organisation where the law requires it, where it is necessary to protect people or the service, or as part of a legitimate business transaction. We do not sell personal information.
International transfers
Some service providers may process information outside the United Kingdom. Where this happens, we use the safeguards required by data protection law, such as an adequacy decision or approved contractual protections.
Security
We use encryption in transit, access controls, audit records, authentication controls, restricted administrative access and operational monitoring to protect information. No online service can remove every risk, so organisations and users must also protect their credentials and devices.
How long information is kept
Account information is kept while it is needed to provide access and for a reasonable period afterwards for security, support and legal purposes. Workspace information is kept according to the organisation’s instructions, its agreement with us and the legal duties applying to the records.
Booking, accounting, tax, contractual, safety, fraud prevention and audit records may be kept for up to six years after the relevant relationship or financial period ends. Information may be kept longer where a legal claim, investigation or specific law requires it. Information that is no longer needed is deleted or anonymised.
Your choices and rights
Depending on the circumstances, you may have the right to access, correct, delete or restrict personal information, object to its use, receive a portable copy, or withdraw consent. If your information belongs to an organisation’s workspace, that organisation may need to deal with the request as controller.
To make a privacy request, email hello@theupgradeauthority.co.uk from the address you use for Upgraded OS. You can also read the dedicated account and data deletion instructions. We may need to verify your identity before acting.
You may complain to the UK Information Commissioner’s Office through ico.org.uk. We would appreciate the chance to address the issue first.
Changes to this policy
We update this policy when the service or legal requirements change. The review date at the top shows when the current version was checked.