GDPR policy
Last updated: 26 August 2026
Last updated: 26 August 2026
Tydeman Nar Limited is committed to protecting personal data and to meeting our obligations under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy sets out how those rules apply to RAMPAGE. It sits alongside our privacy policy, which describes in plain terms what we collect and why.
We handle personal data in line with the UK GDPR principles. Personal data must be:
We are accountable for meeting these principles and can demonstrate how we do so.
We are the controller for the personal data of website visitors, enquirers and the account holders we deal with directly. We are a processor for the personal data our customers enter into their workspace, which they control. When we act as a processor, we process personal data only on the customer's documented instructions.
We identify a lawful basis before processing personal data. Depending on the activity, we rely on legitimate interests, performance of a contract, compliance with a legal obligation, or consent. Where we rely on consent, it is freely given and can be withdrawn at any time. The bases we use are described in our privacy policy.
We respect the rights that individuals have over their personal data, namely the right to be informed, of access, to rectification, to erasure, to restrict processing, to data portability, to object, and rights relating to automated decision making. RAMPAGE does not make decisions about individuals by solely automated means that produce legal or similarly significant effects.
Where a request concerns data held within a customer's workspace, we support that customer, as controller, in responding. We handle requests within the statutory time limit, usually one month, and will explain if we need to extend that in line with the law.
When we process personal data as a customer's processor, we commit to:
We use a small number of trusted providers to help deliver RAMPAGE, for example hosting and email delivery. Each is bound by contract to protect personal data and to process it only as needed to provide their service. The providers we use are named in section 6 of our privacy policy, and a current list is also available on request. We will tell customers before we add or replace a sub-processor that handles their data.
Most personal data in RAMPAGE is hosted in the United Kingdom. One exception applies. Transactional email is delivered by Resend, a provider based in the United States, so a recipient address and the content of that message are processed there. Resend is certified under the UK Extension to the EU to US Data Privacy Framework, and its data processing agreement includes standard contractual clauses covering the transfer. Where any other transfer outside the UK is necessary, we put an appropriate safeguard in place, such as reliance on UK adequacy regulations or the International Data Transfer Agreement, and we assess the transfer where required.
We have procedures to detect, report and investigate personal data breaches. Where a breach is likely to result in a risk to people's rights and freedoms, we will notify the Information Commissioner's Office without undue delay and, where feasible, within 72 hours of becoming aware of it. Where we act as a processor, we will notify the affected customer without undue delay so that they can meet their own obligations.
Customers who need a data processing agreement (DPA) that sets out the Article 28 terms for our processing on their behalf can request one from privacy@rampagehq.co.uk, and we will provide our standard DPA for signature.
For any data protection question, or to exercise a right, contact privacy@rampagehq.co.uk or write to Tydeman Nar Limited, The Depot, Cutting Road, Great Abington, CB21 6AJ. You also have the right to complain to the Information Commissioner's Office at ico.org.uk.