1. Introduction
OnPath Testing (“we”, “us”, “our”) provides software consulting and related services to clients in various countries. This Privacy and Security Policy explains how we collect, use, disclose, and protect personal information when you visit our website, interact with our content, or communicate with us.
By using our website, submitting information through our forms, or otherwise providing personal information to us, you acknowledge that you have read and understood this Policy.
2. Who we are and contact details
The data controller responsible for your personal information is:
If you have questions about this Policy or how your information is handled, you can contact us at the details above.
3. Information we collect
If you engage us for services, we may also collect billing details and limited account administration information for you and your team.
This information is usually collected via cookies, analytics tools, and similar technologies (see “Cookies and similar technologies” below).
We may receive limited personal information about you from:
4. Legal bases for processing (GDPR / UK GDPR)
Where GDPR or UK GDPR applies, we rely on one or more of the following legal bases to process personal information:
5. How we use personal information
We use the personal information described above for the following purposes:
6. Cookies and similar technologies
Our website may use cookies, pixels, and similar technologies to:
Where required by law, you will be presented with a cookie banner or consent tool that allows you to accept or manage non-essential cookies. You can also configure your browser to refuse or delete cookies, though this may affect some website features.
7. How we share information
We do not sell personal information for monetary compensation. We may share personal information with the following categories of recipients where appropriate:
Where we engage third parties, they are only allowed to process personal information as necessary to perform services on our behalf and must implement appropriate security measures.
8. International transfers
Because we work with clients and engineering teams in multiple countries, your personal information may be transferred to and processed in jurisdictions outside your own, including countries that may not provide the same level of data protection as your home country.
Where required by GDPR or UK GDPR, we implement appropriate safeguards for such transfers, such as:
9. Data retention
We retain personal information only for as long as necessary to fulfill the purposes described in this Policy or as required by law. Factors that influence retention periods include:
When personal information is no longer required, we will delete, anonymize, or otherwise securely dispose of it.
10. Your rights
If you are a resident of California or certain other US states with privacy laws, you may also have specific rights regarding “sale” or “sharing” of personal information, sensitive information, and the right not to be discriminated against for exercising your rights.
You can exercise your rights by contacting us using the details in Section 2, and we will respond as required by applicable law. We may need to verify your identity before fulfilling your request.
11. Marketing communications
Where permitted by law, we may send you emails or other communications about our services, events, or content that we think may be relevant to your role or organization. You can opt out at any time by:
Opting out of marketing will not affect important service or transactional communications related to active projects or contracts.
12. Children’s privacy
Our website and services are directed at business professionals and are not intended for children under the age of 16. We do not knowingly collect personal information from children; if you believe a child has provided us with personal information, please contact us so we can delete it where required.
13. Security measures
We use a combination of technical, organizational, and physical safeguards to help protect personal information from unauthorized access, use, alteration, or destruction. These measures may include:
No method of transmission or storage is completely secure, and we cannot guarantee absolute security, but we aim to maintain safeguards proportionate to the risks associated with our processing activities.
14. Use of onshore and offshore engineers
In delivering consulting and engineering services, we may use both onshore and offshore personnel and subcontractors. These individuals or entities may access limited personal information where necessary to perform their work, such as contact details and project-related context.
All such access is governed by written agreements that include confidentiality, data protection, and security obligations, as well as internal policies that restrict access to what is necessary for the assigned tasks.
15. Third‑party websites and services
Our website may contain links to third‑party websites, content, or services (including external blogs, social media, or partner sites). This Policy does not govern those third parties, and we are not responsible for their privacy or security practices.
You should review the privacy policies of any third‑party websites or services you visit or use.
16. Changes to this Policy
We may update this Privacy and Security Policy from time to time to reflect changes in our practices, technologies, or legal requirements. When we make material changes, we will update the “Last updated” date at the top of this page and, where appropriate, provide additional notice.
Your continued use of our website or services after changes take effect will signify that you have read and understood the updated Policy, to the extent permitted by law.
17. How to contact us or lodge a complaint
If you have questions or concerns about this Policy or how we handle personal information, you can contact us using the details in Section 2.
If you are in the EU, EEA, UK, or another jurisdiction with a supervisory authority, you may also have the right to lodge a complaint with your local data protection authority if you believe our processing of your personal information violates applicable law.