Privacy Policy
September 2026

This Privacy Policy explains how 3DEC Limited (“3DEC”, “we”, “us”, “our”) collects and uses personal data when you visit our websites, contact us, or use our online services. It also describes your data protection rights and how to exercise them.

We are committed to complying with the EU/EEA General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018, as well as applicable ePrivacy rules for cookies and direct marketing.

  1. Who we are (Controller)

3DEC is the data controller for the processing described in this notice.

Registered office: Beaumont Chancery, 44 Southampton Buildings, London, England, WC2A 1AP
Contact: PMO@3DEC.co.uk

If we act as a processor for a client (for example, by hosting content for them), that client is the controller for those activities and its privacy policy applies.

If 3DEC has appointed a Data Protection Officer (DPO), you may contact the DPO at PMO@3DEC.co.uk

  1. Personal data we collect

We collect personal data when you interact with us. The categories of data depend on how you use our site and services:

  • Contact & identity data: name, email address, phone number, company, role, and the content of your messages when you submit a contact form, request support, or sign up for updates.
  • Usage & device data: IP address, device and browser type, operating system, referral URLs, pages viewed, links clicked, approximate location (derived from IP), timestamps, and similar technical information collected via cookies and similar technologies.
  • Recruitment data: CV details, cover letters and interview notes when you apply for a role.
  • Marketing preferences: your consent and preferences for receiving marketing communications.
  • Support records: information you provide to our teams (including tickets, emails and call notes) and logs relevant to resolving issues.

You can choose not to provide certain data, but this may limit our ability to provide services or respond to enquiries.

  1. How we collect data
  • Directly from you when you complete forms, subscribe to communications, download materials, register for events, or correspond with us.
  • Automatically via cookies and similar technologies when you browse our websites (see Section 8 – Cookies & similar technologies).
  • From third parties such as recruitment platforms, analytics and advertising partners, event partners, or references you provide.
  1. Purposes and legal bases

We only process personal data where we have a valid legal basis. The main purposes and legal bases are:

Purpose Examples Legal basis
Provide and secure our websites & services Operate the site, load pages, keep services secure, prevent abuse Legitimate interests (IT security, service provision) and/or legal obligation
Respond to enquiries & provide support Respond to contact form submissions, schedule demos, resolve tickets Legitimate interests (responding to requests) and/or contract (pre‑contract steps or performance)
Marketing & newsletters Send product updates, event invites; manage preferences Consent (for electronic direct marketing to individuals) and legitimate interests for B2B where permitted; you can opt out at any time
Analytics & site improvement Measure and improve site performance and content Consent for non‑essential/analytics cookies; legitimate interests for strictly necessary operations
Recruitment Evaluate and manage applications Legitimate interests and legal obligation (employment law)
Compliance, enforcement & record‑keeping Regulatory reporting, exercising or defending legal claims Legal obligation and legitimate interests

Where we rely on consent, you may withdraw it at any time (see Section 11). Where we rely on legitimate interests, we balance our interests against your rights and expectations.

  1. Sharing your personal data

We share personal data only as needed and with appropriate safeguards:

  • Service providers (processors): hosting, security, analytics, marketing, communications, CRM, applicant‑tracking, and professional advisers – bound by contracts and confidentiality.
  • Business partners: when you register for joint events/webinars or download co‑branded content.
  • Legal and regulatory: competent authorities, courts, law enforcement, and regulators when required or appropriate.
  • Corporate transactions: in connection with a merger, acquisition or corporate reorganisation, subject to appropriate protections.

We do not sell your personal data. We do not allow third parties to use your data for their own purposes without your permission.

  1. International transfers

Where we transfer personal data outside the EEA/UK, we ensure an adequate level of protection by using one or more of the following:

  • Adequacy decisions (e.g., transfers to organisations in jurisdictions recognised by the European Commission as adequate, including participants in the EU‑US Data Privacy Framework where applicable);
  • Standard Contractual Clauses (SCCs) adopted by the European Commission, together with transfer impact assessments and supplementary safeguards as required; and
  • Any other mechanism approved by data protection authorities.

Information about specific transfers and safeguards is available on request (see Section 11).

  1. Data retention

We keep personal data only as long as necessary for the purposes described above, including to meet legal, tax, accounting or reporting requirements, and to resolve disputes. Retention periods vary by category and context; when no longer required, data is securely deleted or anonymised in accordance with our retention policies.

  1. Cookies & similar technologies

We use cookies and similar technologies to operate our site, remember your preferences, perform analytics, and (with your consent) tailor advertising. You can manage your preferences via our Cookie Banner and in your browser settings. For details about the categories of cookies we use, their purposes and lifespans, please see our Cookie Policy.

Strictly necessary cookies are essential for the site to function and are set without consent. Analytics/advertising cookies are optional and set only with your consent, which you can withdraw at any time.

  1. Direct marketing

We may send electronic direct marketing (e.g., email newsletters) in accordance with your preferences and applicable ePrivacy rules. You can opt out at any time by using the unsubscribe link in our emails or by contacting us.

  1. Security

We apply appropriate technical and organisational measures to protect personal data, access controls, least‑privilege practices, logging and monitoring, vulnerability management, and staff training. No system is 100% secure, but we continuously improve our safeguards.

  1. Your rights

Depending on your location and subject to conditions/exceptions, you may have the right to:

  • Information & transparency about our processing;
  • Access your personal data;
  • Rectification of inaccurate data;
  • Erasure (“right to be forgotten”);
  • Restriction of processing;
  • Data portability;
  • Object to processing based on legitimate interests and to direct marketing;
  • Withdraw consent at any time where processing is based on consent; and
  • Lodge a complaint with a supervisory authority (see below).

To exercise your rights, contact us using the details in Section 12. We may need to verify your identity before responding.

  1. How to contact us & complaints

Contact 3DEC:

Email: PMO@3DEC.co.uk

Postal: Beaumont Chancery, 44 Southampton Buildings, London, England, WC2A 1AP

Supervisory authority: If you are in the EU/EEA, you can lodge a complaint with your local supervisory authority. In Ireland, this is the Data Protection Commission (DPC). See the DPC’s website for contact options and guidance:

https://www.dataprotection.ie/en/contact/how-contact-us

  1. Changes to this policy

We will update this policy from time to time. When we make material changes, we will post a prominent notice on our websites and update the effective date at the bottom of this page. If required by law, we will obtain your consent for material changes.

Updated [15 September 2026]