Privacy Policy
Cavefish Ltd — Last updated April 2026 — ICO Registration ZB915623
Cavefish Ltd (Reg. 15127122) is registered with the Information Commissioner's Office under reference ZB915623. This policy governs all data processed through cavefish.ai and any associated services. Contact: hello@cavefish.co.uk — 15 Neptune Court, Vanguard Way, Cardiff CF24 5PJ.
What Data We Collect
When you submit a contact or demo request form on this site, we collect the personal data you provide — including name, work email address, organisation name, job title and any message content. We also collect standard server log data including IP address and browser user agent string to help with spam detection and site security.
How We Use Your Data
Personal data submitted via forms on cavefish.ai is used solely to respond to your enquiry, arrange demonstrations of EchoDepth, and provide the information you have requested. We do not use your data for automated decision-making. We do not sell your data to third parties. We do not use your data for unsolicited marketing without your explicit consent.
Legal Basis for Processing
We process your personal data on the basis of legitimate interests (responding to business enquiries) and, where applicable, your explicit consent. All processing is conducted in compliance with UK GDPR and the Data Protection Act 2018.
Biometric Data Processing
EchoDepth processes biometric data within the meaning of UK GDPR Article 9 — specifically, facial Action Unit measurements derived from video or image analysis of identifiable individuals. This constitutes special category data. Processing of biometric data by Cavefish is conducted only where: (1) the data subject has given explicit informed consent in writing; (2) a documented purpose of processing exists; (3) a Data Protection Impact Assessment (DPIA) has been completed; and (4) a signed data processing agreement is in place between Cavefish and the client organisation. Biometric data is never processed without explicit consent. No biometric data is used for automated decision-making without human oversight.
Form Submissions and Third-Party Processors
Contact forms on this site submit data via Formspree (formspree.io), a third-party form processing service. Formspree processes submitted data on our behalf and is governed by their own privacy policy and data processing agreement. Google Analytics 4 (GA4) is used to collect anonymised site usage data. GA4 data is processed by Google LLC under standard contractual clauses. We do not enable Google Signals or cross-device tracking.
Cookies
This site uses essential cookies required for functionality (session management). We use Google Analytics cookies for anonymised traffic analysis. No advertising, retargeting or profiling cookies are set. You may disable cookies in your browser settings — essential site functionality does not depend on cookies.
Embedded Content
Pages on this site may include embedded content (videos, images, social media posts). Embedded content from other websites behaves in the same way as if you had visited those websites directly. These third-party sites may collect data about you, use cookies and monitor your interaction with embedded content.
How Long We Retain Your Data
Enquiry data submitted via contact forms is retained for up to 24 months from the date of submission, after which it is deleted unless an active commercial relationship exists. Where we have a legitimate reason to retain data for longer (for example, for ongoing contractual obligations), we will retain it only for as long as necessary.
Your Rights Under UK GDPR
You have the right to: access the personal data we hold about you; request correction of inaccurate data; request erasure of your data; object to processing; request restriction of processing; and data portability. To exercise any of these rights, contact us at hello@cavefish.co.uk. We will respond within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with the ICO at ico.org.uk.
Data Security
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure or destruction. Data submitted via forms is transmitted over HTTPS encrypted connections. Access to personal data within Cavefish Ltd is restricted to individuals who require it to process your enquiry.
International Transfers
Where data is processed by third-party services (Formspree, Google Analytics) that operate outside the UK, such transfers are governed by UK adequacy decisions or standard contractual clauses. We do not transfer personal data outside the UK/EEA without appropriate safeguards in place.
Changes to This Policy
We may update this privacy policy from time to time. Material changes will be notified via the cavefish.ai website. The date of last update is shown at the top of this page.
Contact
Data Controller: Cavefish Ltd, 15 Neptune Court, Vanguard Way, Cardiff CF24 5PJ. Email: hello@cavefish.co.uk. ICO Registration: ZB915623.