Last updated: June 2026
DELTAOS LIMITED ("DELTAOS", "we", "us", or "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, retain, and safeguard personal data when you visit our website at https://deltaos.my (the "Website"), communicate with us, engage our custom computer programming and software development services, or otherwise interact with us (collectively, the "Services").
This Privacy Policy is issued in compliance with the UK General Data Protection Regulation (UK GDPR) as retained in domestic law by the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (PECR), and applicable guidance from the Information Commissioner's Office (ICO). Please read this policy carefully to understand our practices regarding your personal data.
The data controller responsible for your personal data is:
DELTAOS LIMITED
15 Water Lane
COBHAM, KT11 2PA
United Kingdom
Telephone: +44 7490 447700
Email: tech@deltaos.my
Website: https://deltaos.my
For the purposes of UK data protection legislation, DELTAOS LIMITED determines the purposes and means of processing personal data described in this policy, except where we act as a data processor on behalf of a client, as described in Section 12 below.
This Privacy Policy applies to personal data we process about:
This policy does not apply to third-party websites, applications, or services that may be linked from our Website or integrated into deliverables we develop for clients. Those third parties operate under their own privacy policies, and we encourage you to review them independently.
Personal data means any information relating to an identified or identifiable natural person. We may collect, use, store, and transfer different categories of personal data about you, grouped as follows:
This includes your name, job title, company name, postal address, email address, telephone number, and other contact details you provide when completing forms on our Website, corresponding with us, or entering into a service agreement.
This includes your Internet Protocol (IP) address, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform, device identifiers, pages visited, time and date of visits, time spent on pages, referral source, clickstream data, and other technology on the devices you use to access our Website. We collect this data through cookies and similar technologies as described in our Cookie Policy.
This includes the content of emails, messages, support tickets, meeting notes, and other communications you send to us, together with metadata associated with such communications.
This includes details of services you have enquired about or purchased, project specifications, statements of work, invoices, payment records, bank account details (where applicable for billing or refunds), and correspondence relating to contractual matters.
Where you engage our services, we may process information you provide in connection with software development projects, including business requirements, technical specifications, credentials for development environments (handled under strict security protocols), test data, feedback, and acceptance records. We treat such data as confidential in accordance with our contractual obligations.
This includes your preferences in receiving marketing communications from us, your communication preferences, and records of consents you have given or withdrawn.
We may aggregate personal data so that it can no longer identify you. We may use aggregated data for analytics, service improvement, and business reporting. Aggregated data is not personal data under UK GDPR and is not subject to this policy.
We collect personal data through the following methods:
We process your personal data only where we have a lawful basis under UK GDPR. The table below describes the primary purposes for which we use your personal data and the corresponding legal bases:
We process personal data where necessary for the performance of a contract to which you are a party, or to take steps at your request prior to entering into a contract. This includes processing necessary to provide quotations, deliver software development services, manage projects, issue invoices, process payments, and provide support under our service agreements.
We process personal data where necessary for the purposes of our legitimate interests, provided those interests are not overridden by your rights and freedoms. Our legitimate interests include:
Where we rely on legitimate interests, we conduct balancing assessments to ensure our interests do not disproportionately impact your rights. You may request further information about our balancing assessments by contacting us.
We process personal data based on your consent where required by law, including for non-essential cookies, certain marketing communications, and other processing activities where consent is the appropriate legal basis. You may withdraw consent at any time by contacting us or using the unsubscribe mechanism in marketing emails. Withdrawal does not affect the lawfulness of processing before withdrawal.
We process personal data where necessary to comply with legal obligations to which we are subject, including tax and accounting requirements, responding to lawful requests from public authorities, and complying with court orders.
In rare circumstances, we may process personal data where necessary to protect the vital interests of you or another natural person, such as in emergency situations involving health or safety.
We use personal data for the following purposes:
We may send you marketing communications about our services, industry insights, and company updates where you have consented to receive them or where we have a legitimate interest and you have not opted out. Marketing communications may be sent by email or, where appropriate, by telephone or post.
You may opt out of marketing communications at any time by clicking the unsubscribe link in any marketing email, contacting us at tech@deltaos.my, or updating your preferences through any preference centre we provide. Opting out of marketing does not affect transactional or service-related communications necessary for the performance of our contract with you.
We use cookies and similar tracking technologies to collect Technical and Usage Data. Cookies are small data files placed on your device that help us improve our Website and your experience. We use strictly necessary cookies, functional cookies, analytics cookies, and, with your consent, marketing cookies. For detailed information about the cookies we use, their purposes, durations, and how to manage your preferences, please refer to our Cookie Policy, which forms part of our data protection framework and should be read in conjunction with this Privacy Policy.
We may share your personal data with the following categories of recipients, subject to appropriate safeguards:
We engage third-party companies and individuals to facilitate our Website and services, including hosting providers, cloud infrastructure providers, email service providers, payment processors, analytics providers, customer relationship management platforms, and professional advisers. These parties process personal data on our instructions and under data processing agreements that require them to protect your data in accordance with UK GDPR.
We may disclose personal data to lawyers, accountants, auditors, insurers, and other professional advisers where necessary for the provision of their services to us or to you in connection with our business relationship.
If DELTAOS is involved in a merger, acquisition, reorganisation, sale of assets, or insolvency proceeding, your personal data may be transferred as part of that transaction. We will provide notice before your personal data becomes subject to a different privacy policy and will ensure appropriate safeguards are in place.
We may disclose personal data where required to do so by law, regulation, legal process, or governmental request, or where we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.
We do not sell your personal data to third parties. We do not share your personal data with third parties for their own direct marketing purposes without your explicit consent.
Your personal data may be transferred to, stored at, and processed in countries outside the United Kingdom, including countries that may not provide the same level of data protection as the UK. This may occur when we use cloud services, development tools, or service providers with infrastructure located outside the UK, or when personnel or subcontractors involved in delivering services are located abroad.
Where we transfer personal data outside the UK, we ensure a similar degree of protection is afforded to it by implementing appropriate safeguards as required by UK GDPR, which may include:
You may request a copy of the safeguards we use for international transfers by contacting us at tech@deltaos.my.
We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage. These measures include, where appropriate:
While we strive to protect your personal data, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security but are committed to maintaining safeguards appropriate to the nature of the data we process and the risks involved.
When delivering custom software development services, we may process personal data on behalf of our clients. In such circumstances, our client is the data controller and DELTAOS acts as a data processor. We process such data only in accordance with our client's documented instructions, our service agreements, and applicable data processing terms. Clients remain responsible for ensuring they have a lawful basis for providing personal data to us and for fulfilling data subject rights requests relating to data we process on their behalf. We assist clients in fulfilling their obligations under UK GDPR to the extent required by law and our contractual arrangements.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. The retention period depends on the context of processing:
When personal data is no longer required, we securely delete or anonymise it. In some circumstances, we may anonymise personal data for research or statistical purposes, in which case we may use the anonymised information indefinitely without further notice.
Under UK data protection law, you have the following rights in relation to your personal data, subject to certain exceptions and limitations:
You have the right to request a copy of the personal data we hold about you and information about how we process it. This is commonly known as a subject access request.
You have the right to request correction of inaccurate personal data and to have incomplete personal data completed.
You have the right to request deletion of your personal data in certain circumstances, including where the data is no longer necessary for the purposes for which it was collected, where you withdraw consent and no other legal basis applies, or where you object to processing and we have no overriding legitimate grounds.
You have the right to request restriction of processing in certain circumstances, such as where you contest the accuracy of the data or where processing is unlawful but you prefer restriction to erasure.
Where processing is based on consent or contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller where technically feasible.
You have the right to object to processing based on legitimate interests or for direct marketing purposes. Where you object to direct marketing, we will cease processing for that purpose without exception.
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. We do not currently engage in automated decision-making that produces such effects.
Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
To exercise any of these rights, please contact us at tech@deltaos.my. We will respond within one month of receiving your request, which may be extended by a further two months where requests are complex or numerous, in which case we will inform you of the extension. We may need to verify your identity before processing your request. There is no fee for exercising your rights unless your request is manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable fee or refuse to act on the request.
Our Website and services are not directed at individuals under the age of eighteen (18), and we do not knowingly collect personal data from children. If you are a parent or guardian and believe that your child has provided personal data to us, please contact us at tech@deltaos.my. If we become aware that we have collected personal data from a child without verification of parental consent, we will take steps to delete that information promptly.
We do not use personal data for automated decision-making or profiling that produces legal or similarly significant effects on individuals. We may use analytics tools to understand aggregate user behaviour on our Website, but such analysis does not result in automated decisions affecting your legal rights or interests.
Where processing is likely to result in a high risk to the rights and freedoms of individuals, we conduct data protection impact assessments (DPIAs) in accordance with UK GDPR requirements. DPIAs help us identify and mitigate privacy risks before commencing high-risk processing activities.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. The "Last updated" date at the top of this page indicates when this policy was last revised. Where changes are material, we will take reasonable steps to notify you, which may include posting a prominent notice on our Website or sending a direct communication where appropriate. We encourage you to review this policy periodically to stay informed about how we protect your personal data.
If you have concerns about how we handle your personal data, we encourage you to contact us first at tech@deltaos.my so that we can attempt to resolve the matter. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
United Kingdom
Website: https://ico.org.uk
Telephone: 0303 123 1113
We do not routinely collect or process special categories of personal data as defined under UK GDPR Article 9, such as data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health data, or data concerning sex life or sexual orientation. Where processing of special category data becomes necessary in connection with a software development project at your direction, we will process such data only in accordance with your documented instructions, applicable data processing terms, and a lawful basis under Article 9, such as explicit consent or necessity for legal claims. We implement enhanced safeguards for any special category data we are instructed to process, including restricted access controls, encryption, and limited retention periods.
We do not routinely process personal data relating to criminal convictions and offences. If such processing is required for a specific project, it will be governed by Article 10 of the UK GDPR and conducted only under appropriate legal authority and contractual safeguards agreed with the relevant data controller.
As required by UK GDPR Article 30, DELTAOS maintains records of processing activities documenting the categories of processing we carry out as a data controller and, where applicable, as a data processor. These records include the purposes of processing, categories of data subjects and personal data, recipients of personal data, international transfers, retention periods, and a general description of technical and organisational security measures. We review and update these records periodically to reflect changes in our processing activities.
We implement data protection by design and by default in accordance with UK GDPR Article 25. This means we consider data protection principles throughout the development of our Website, internal systems, and client deliverables where we have responsibility for data processing architecture. Measures include minimising data collection to what is necessary, pseudonymisation where appropriate, transparency in our processing practices, and embedding privacy controls into system design from the outset rather than as an afterthought.
In the event of a personal data breach affecting personal data we control, we shall notify the Information Commissioner's Office without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of the breach, where the breach is likely to result in a risk to the rights and freedoms of individuals. Where the breach is likely to result in a high risk to individuals, we shall also communicate the breach to affected data subjects without undue delay. Where we act as a data processor, we shall notify the relevant client controller without undue delay upon becoming aware of a personal data breach, providing sufficient information to enable the controller to meet its notification obligations. Our breach response procedures include containment, assessment, documentation, notification, and post-incident review to prevent recurrence.
For transparency, the following table summarises typical processing activities and their lawful bases. This is illustrative and not exhaustive; specific processing in connection with your engagement may differ.
Where you engage DELTAOS for software development services and provide personal data for incorporation into deliverables, you act as the data controller for that personal data. You are responsible for ensuring that you have a lawful basis for collecting and sharing personal data with us, that data subjects have been provided with appropriate privacy notices, that data shared with us is adequate, relevant, and limited to what is necessary, and that you comply with data subject rights requests relating to data processed on your behalf. We will assist you in fulfilling your obligations to the extent required by UK GDPR and our contractual arrangements, but primary responsibility for compliance with data protection law in respect of your end users and customers remains with you.
Our web servers automatically log certain information when you visit our Website, including your IP address, request timestamp, HTTP method, requested URL, HTTP response status code, bytes transferred, referrer URL, and user agent string. We use server logs for security monitoring, troubleshooting, capacity planning, and detecting abusive or malicious activity. Server logs are retained for a limited period, typically not exceeding ninety (90) days, unless retention is necessary for security investigations or legal compliance. Log data may constitute personal data where IP addresses or other identifiers can be linked to identifiable individuals; we process such data on the basis of our legitimate interests in operating a secure and reliable Website.
If you interact with us through social media platforms or professional networking sites, those platforms operate as independent data controllers. Any personal data you submit through such platforms is governed by the privacy policies of the respective platforms. We may collect and process personal data you voluntarily provide through social media interactions, such as messages sent to our company profiles, for the purpose of responding to enquiries and managing our business relationships. We encourage you to review the privacy settings and policies of any third-party platforms you use to communicate with us.
If you apply for employment or contract opportunities with DELTAOS, we may process personal data contained in your application, curriculum vitae, cover letter, references, interview notes, and correspondence. We process recruitment data for the purpose of evaluating your application, conducting interviews, verifying qualifications and references, and complying with employment law obligations. Recruitment data is retained for the duration of the recruitment process and, where permitted by law and with your consent, for a reasonable period thereafter for consideration in future opportunities. Unsuccessful applicants' data is typically deleted within twelve (12) months unless a longer retention period is required or you consent to longer retention.
If you have any questions about this Privacy Policy, our data practices, or wish to exercise your data protection rights, please contact us:
DELTAOS LIMITED
15 Water Lane
COBHAM, KT11 2PA
United Kingdom
Telephone: +44 7490 447700
Email: tech@deltaos.my
Website: https://deltaos.my
We monitor guidance published by the Information Commissioner's Office and other relevant regulatory bodies to ensure our data protection practices remain current with evolving standards and expectations. Where ICO guidance is updated in ways that affect our processing activities, we assess the impact and implement necessary changes within a reasonable timeframe. Our data protection practices are also informed by applicable industry standards for information security and software development, including ISO 27001 principles where relevant to our operations.
Transparency is a core principle of our approach to data protection. We are committed to providing clear, accessible information about our data practices and to responding promptly and fully to data subject requests. Accountability means that we can demonstrate compliance with data protection principles through documented policies, procedures, training records, and regular internal reviews. Senior management at DELTAOS LIMITED takes active responsibility for data protection governance and ensures that adequate resources are allocated to maintain effective data protection practices across all areas of our business.