Privacy Policy
Version 1.3 · Effective 30 July 2026
This application is a private, invitation-only presentation tool provided as a business-to-business service: everyone whose data it processes uses it in a business capacity. It collects the minimum personal data needed to control access and keep the service secure (sign-in details, connection addresses and one essential cookie) and nothing else, beyond the one-off delivery address described below when a take-away pack is emailed at a prospect’s request. There is no analytics, no advertising and no marketing.
01Who is responsible for your data
Future Engine Limited, a company registered in England and Wales under company number 16640272, whose registered office is at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom, operates this application and is the controller of the personal data described in this policy. The application is provided as a business-to-business service: Future Engine is engaged directly by the client whose project it presents, on a project-by-project basis, and acts as the application’s super administrator: it creates and manages every user account and provides the related account management and support to that client and its project team, within the scope agreed by contract. The client may determine who on its team is given access; day-to-day processing within the application is carried out by Future Engine Limited.
The people whose data this policy covers (account holders and those connecting to the application) use it in a business capacity, as the client’s own team or as professionals engaged on the client’s project. The application is not offered to consumers and does not process consumer data.
02What this policy covers
This policy covers personal data processed by this presentation application only. It does not cover other dealings you may have with Future Engine Limited or with the client outside the application.
03The data we collect
- Account details: the username, role and a securely hashed password for each managed account. Usernames are short three-character identifiers (two letters and a number) rather than full names, and we never store passwords in readable form.
- Connection data: the network (IP) address of each connection, which is checked against a list of trusted locations to decide which sign-in the connection is offered, and which may appear in technical logs. When an address is added to (or approved onto) the trusted list, we derive an approximate location label for it (city / region level) using a third-party IP geolocation service, which receives that address for the lookup; see “Who we share it with” below.
- Session data: one signed, essential session cookie that keeps you signed in and records your access role. It contains no tracking identifiers.
- Technical logs: routine server logs (times, addresses, requested pages, errors) kept for security and troubleshooting.
- Take-away delivery address: when a presenter emails a take-away pack to a prospect at the prospect’s request, the email address typed for that send is used once to deliver that email and is not stored by the application.
The application does not collect analytics, does not profile you, does not use advertising or tracking technologies, and does not knowingly collect data about children. A small number of on-device preferences (such as which screen mode a device uses) are stored locally on the device itself and never sent to us.
04Why we use it and our legal bases
- To provide access: authenticating sign-ins and maintaining your session (performance of a contract, and our legitimate interest in operating the service).
- To keep the service secure: checking connections against the trusted-location list, pausing sign-in from a connection after repeated failed attempts (and alerting the administrator to sustained ones), preventing unauthorised access and investigating misuse (our and our clients’ legitimate interests in protecting confidential material).
- To meet legal obligations: where we are required to retain or disclose information by law.
05Cookies
The application sets a single, strictly necessary session cookie when you sign in. It exists only to keep you signed in securely and is removed when you sign out or when it expires. Because it is essential to providing the service you asked for, no consent banner is required and no optional cookies exist to configure.
06Who we share it with
We do not sell or rent personal data, ever. Data is shared only with:
- our hosting, infrastructure and email delivery providers, who store and process it on our behalf under contract (the email delivery provider handles the addresses that the application’s emails, such as an emailed take-away pack or an administrative alert, are sent to);
- a third-party IP geolocation service (currently ipwho.is), which receives the network address of a connection being added to the trusted-location list, solely to estimate its approximate location so the administrator can recognise the entry. Only the address is sent (never a name, account or any other data), and only for addresses added to (or approved onto) the trusted list, not for routine visits;
- the relevant client, where necessary to manage who has access to their presentation or to investigate a suspected breach of the Terms of Use; and
- professional advisers and authorities, where required by law or to protect our or our clients’ legal rights.
07International transfers
Data is stored with reputable hosting providers. Where any processing takes place outside the United Kingdom, we ensure an adequate level of protection through recognised safeguards (such as adequacy regulations or standard contractual clauses).
08How long we keep it
Account details are kept for as long as the account is needed for the engagement and are deleted when the account is removed. Session cookies expire automatically. Technical logs are retained on a short rolling basis for security and troubleshooting, and longer only where needed to investigate an incident or meet a legal obligation. Records of past sign-ins (when and from which connection address a session ran, and the terms version accepted) are kept for the life of the deployment as evidence of terms acceptance and access control, until the administrator deletes them.
09How we protect it
Access to the application is controlled by authentication and role-based permissions; passwords are stored only as strong one-way hashes; sessions are cryptographically signed; and administrative functions are restricted to designated administrators.
10Your rights
Under UK data protection law you have rights over your personal data, including the rights to access it, to have it corrected or deleted, to restrict or object to its processing, and to data portability where applicable. To exercise any of these rights, contact Future Engine Limited via the contact details provided with your engagement, or in writing to its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. You also have the right to complain to the Information Commissioner’s Office (ico.org.uk) if you are unhappy with how your data has been handled.
11Changes to this policy
We may update this policy from time to time; the version and effective date at the top of this page identify the current one. Material changes will be brought to your attention at your next password sign-in.
