Legal
Privacy Policy
Last updated 30 September 2026
1. Who we are
OSP Retail Limited (“OSP”, “we”, “us”) provides retail space planning consultancy and software, including the MSO (Macro Space Optimisation) and Windlass platforms. We trade as OSP Retail.
| Registered company | OSP Retail Limited, registered in England and Wales, company number 09186420 |
|---|---|
| Registered office | 227a West Street, Fareham, Hampshire, PO16 0HZ, United Kingdom |
| Privacy contact | privacy@osp-retail.co.uk |
| Website | www.osp-retail.co.uk (osp-retail.com redirects here) |
We have not appointed a Data Protection Officer because the law does not require one for our activities. Our CTO, Shaun Brown, is responsible for data protection and can be reached at privacy@osp-retail.co.uk.
2. What this policy covers
This policy explains how we handle personal data when we act as a controller, meaning we decide why and how it is used. When we process data on a customer’s behalf inside our SaaS products, we act as a processor, and our contract with that customer governs the processing.
| Who you are | Our role | What governs your data |
|---|---|---|
| Visitor to our website | Controller | This policy |
| Prospect, enquirer or event contact | Controller | This policy |
| Contact at a customer, partner or supplier (for the business relationship) | Controller | This policy |
| User of a SaaS product: account, sign-in, security and usage data we need to run the service | Controller | This policy |
| Person whose data a customer loads into a SaaS product (e.g. staff names, store data, photos) | Processor | The customer’s own privacy notice, and our Data Processing Agreement (DPA) with that customer |
Consultancy projects. When we work inside a client’s own systems, such as their RELEX environment, we act as that client’s processor or sub-processor. The client’s contract with us governs that data.
Our SaaS products are the MSO (Macro Space Optimisation) and Windlass platforms, supported by our helpdesk. Business customers use them under separate SaaS contracts, which include our DPA.
This policy does not cover third-party websites we link to, such as RELEX Solutions. Please read their own privacy notices.
3. Personal data we collect
We collect business contact and technical data. We do not seek special category data, such as health or ethnicity, and ask you not to send it to us.
| Category | Examples | Where it comes from |
|---|---|---|
| Enquiry and demo requests | First and last name, work email, company, role, your message | You, via our contact page or email |
| Business relationship data | Name, job title, employer, work email and phone, meeting notes, correspondence | You, your colleagues, LinkedIn, events, RELEX and other partners who introduce you |
| Marketing preferences | Whether you have opted in or out, and your interactions with our emails and LinkedIn content | You, Microsoft Dynamics 365, LinkedIn |
| SaaS account data | Name, work email, user ID, tenant/organisation, role and permissions, account status, last sign-in | Your organisation’s Microsoft Entra ID or Google account when you sign in, and your organisation’s administrators |
| SaaS security and diagnostic data | IP address, device and browser type, pages and API endpoints used, timestamps, error logs linked to your email, diagnostic bundles you choose to send | Generated automatically when you use the service |
| Support data | Tickets you raise, your messages and attachments, and our replies | You, via our helpdesk or email |
| Website technical data | IP address, browser, requested pages and timestamps in our hosting provider’s server logs | Generated automatically when you visit |
| Supplier and partner contacts | Name, work contact details, contract and payment contacts | You or your organisation |
How the contact form works today. When you submit the form, it opens your own email client with your details filled in, and nothing is sent to us until you press send.
4. How we use your data and our lawful basis
We rely mainly on legitimate interests, meaning running and growing a B2B business in ways you would reasonably expect. We have balanced these interests against your rights. You can object at any time (section 10).
| Purpose | Data used | Lawful basis |
|---|---|---|
| Respond to enquiries and arrange demos | Enquiry data | Legitimate interests (answering you); contract steps if you are entering into a contract |
| Manage customer, partner and supplier relationships | Business relationship data | Legitimate interests; performance of our contract with your organisation |
| Provide, secure and support our SaaS products | SaaS account, diagnostic and support data | Legitimate interests (delivering the service your organisation has bought, and keeping it secure); performance of contract where you are the customer |
| Monitor and improve our products and website | Diagnostic and technical data, aggregated where possible | Legitimate interests |
| Send B2B marketing about our services and events | Business contact data, marketing preferences | Legitimate interests for corporate contacts; consent where PECR requires it (e.g. sole traders and individual subscribers). Every email has an unsubscribe link |
| Comply with law, resolve disputes, enforce our terms | Any relevant data | Legal obligation; legitimate interests |
| Business transactions, such as a sale or restructuring of OSP | Any relevant data | Legitimate interests |
Automated decisions. We do not make decisions about you that have legal or similarly significant effects based solely on automated processing.
5. Cookies and similar technologies
Our website currently sets no cookies and uses no analytics or advertising trackers. Our fonts are served from our own site, so your browser does not contact Google or other third parties when you visit.
Our SaaS products use strictly necessary browser storage to sign you in and keep your session secure. This includes Microsoft or Google sign-in tokens and your workspace preferences. They cannot work without it, so it does not need consent.
If we add analytics or marketing tools, we will update this section. We will ask for your consent through a banner before setting any non-essential cookie. Since February 2026, UK law allows first-party analytics that only produce statistics about our site to run without consent, if we explain them clearly and give an easy way to object. Advertising tracking still needs consent.
6. Who we share your data with
We do not sell personal data. We share it only with the parties below, under contracts that require them to protect it and use it only on our instructions.
| Recipient | Purpose | Location |
|---|---|---|
| Microsoft (Azure, Microsoft 365, Entra ID, Dynamics 365, Application Insights) | Hosting our website, SaaS products and helpdesk; databases and storage; sign-in; email; CRM; monitoring | UK (Azure UK South and UK West); some Microsoft support and service operations outside the UK |
| Sign-in, for customers who use Google accounts | UK / EU / USA | |
| GitHub (Microsoft) | Source code hosting and deployment; holds no customer data | USA |
| LinkedIn (Microsoft) | B2B marketing and networking | Ireland / USA |
| RELEX Solutions and other implementation partners | Joint projects for shared customers, and introductions | EU / UK |
| Professional advisers (lawyers, accountants, insurers) | Advice and compliance | UK |
| Authorities, regulators, courts | Where the law requires it, or to protect our rights | UK |
| A buyer or investor | If OSP is sold or restructured, under confidentiality terms | Varies |
SaaS customers can get our current list of sub-processors, and advance notice of changes, under their DPA.
7. International transfers
We host our website and SaaS products, and store their data, in Microsoft Azure data centres in the UK (UK South and UK West). Some of our suppliers can access data from outside the UK, for example for support.
When personal data leaves the UK or EEA, we protect it using one of these:
- An adequacy decision (the UK and EU recognise each other, and both recognise some other countries).
- For the USA, the UK Extension to the EU–US Data Privacy Framework, where the recipient is certified.
- The UK International Data Transfer Agreement or UK Addendum, and the EU Standard Contractual Clauses, with a transfer risk assessment.
Contact us for a copy of the relevant safeguards.
8. How long we keep your data
We keep personal data only as long as we need it for the purposes in section 4. Then we delete or anonymise it.
| Data | Retention period |
|---|---|
| Enquiries that do not lead to a relationship | 2 years from last contact |
| Business relationship and contract records | Length of the relationship plus 6 years (the limitation period for contract claims) |
| Marketing preferences and opt-outs | While you are on our list plus 1 year. We keep a minimal suppression record indefinitely so we don’t contact you after you opt out |
| SaaS user accounts | While your organisation’s subscription is active, then deleted within 90 days of it ending, unless the SaaS contract says otherwise |
| SaaS monitoring and diagnostic telemetry | 30 days |
| SaaS error logs linked to a user | 90 days |
| Database server logs | 3 days |
| Database backups | 35 days, on a rolling basis |
| Helpdesk tickets | 3 years from closure |
| Records needed for legal or tax reasons | As the law requires (usually 6 years) |
9. How we keep your data secure
We use appropriate technical and organisational measures to protect personal data, including:
- Encryption in transit (TLS) and at rest in Azure databases and storage.
- Sign-in through Microsoft Entra ID or Google, so your organisation’s own password and multi-factor authentication policies apply.
- Keeping each customer’s data logically separate, with role-based access controls in our products.
- Secrets held in Azure Key Vault, and staff access limited to those who need it.
- Security monitoring, logging and regular review of our systems and suppliers.
- Automated database backups, kept for 35 days.
No system is completely secure. If a breach is likely to put your rights at risk, we will tell you and the ICO as the law requires. Where we act as a processor, we will tell the affected customer without undue delay.
10. Your rights and how to complain
You have rights over your personal data under UK GDPR and, where it applies, EU GDPR. To use any of them, email privacy@osp-retail.co.uk with enough detail for us to identify you. We will reply within one month. We may extend that by up to two further months for complex requests and will tell you if we do.
| Right | What it means |
|---|---|
| Access | Get a copy of the personal data we hold about you |
| Rectification | Have inaccurate or incomplete data corrected |
| Erasure | Have your data deleted where we no longer have a lawful reason to keep it |
| Restriction | Ask us to pause using your data, for example while we check its accuracy |
| Portability | Receive data you gave us in a machine-readable format, where we process it by consent or contract |
| Objection | Object to processing based on legitimate interests, and to direct marketing at any time |
| Withdraw consent | Where we rely on consent, withdraw it at any time without affecting earlier processing |
If you use one of our SaaS products through your employer, your employer controls that data. Please send requests to them first. We will pass on any request we receive and help them respond.
Complaints. Please contact us first, by email to privacy@osp-retail.co.uk, so we can try to put things right. We will acknowledge your complaint within 30 days and respond without undue delay. If you are unhappy with our response, you can complain to the Information Commissioner’s Office (ICO), or its successor, at ico.org.uk/make-a-complaint or on 0303 123 1113. If you are in the EU/EEA, you can also complain to your local data protection authority.
11. Children, changes and contact
Children. Our website and products are for businesses and are not aimed at anyone under 18. We do not knowingly collect children’s data.
Changes to this policy. We may update this policy. The date at the top shows when it last changed. Where a change significantly affects how we use your data, we will tell affected customers and users directly.
Contact us. For any question about this policy or your data, email privacy@osp-retail.co.uk or write to the Privacy Lead, OSP Retail Limited, 227a West Street, Fareham, Hampshire, PO16 0HZ.