Privacy Policy
This Privacy Policy describes how TABLELOOP LTD ("TABLELOOP LTD", "we", "us", "our") collects, uses, discloses, stores and protects personal data when you visit tableloop.work, enquire about our digital library solutions, engage our library software development services, use software we deliver, or otherwise interact with us. We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (PECR), and guidance published by the Information Commissioner's Office (ICO).
TABLELOOP LTD is a United Kingdom company specialising in digital library solutions, archive management software, library automation systems and custom library applications for institutions including universities, public library services, museums, corporate archives and research organisations. Because our work involves catalogue metadata, patron access systems, digitisation workflows and archival data management, we may process personal data belonging to your staff, patrons, researchers, suppliers and other individuals connected to your organisation.
We are committed to transparency, data minimisation, integrity and confidentiality. This policy explains what personal data we process, our lawful bases, retention practices, security measures, international transfers, your rights, and how to contact us or complain to a supervisory authority. Please read it carefully alongside our Cookie Policy, Terms of Service and Terms and Conditions.
1. Data Controller and Contact Information
TABLELOOP LTD is the data controller for personal data described in this Privacy Policy unless we process data solely on your instructions as a data processor, in which case a separate data processing agreement applies.
Our registered office is 82a James Carter Road, Mildenhall, United Kingdom, IP28 7DE. For privacy enquiries, data subject requests, or complaints, contact us at help@tableloop.work, telephone +447446967065, or by post to the registered address. We respond within one month unless an extension is permitted under UK GDPR Article 12.
1.1 Scope
This policy applies to personal data collected via our website, email, telephone, contracts, demonstrations, support channels, events, and professional engagements.
It does not govern third-party websites linked from tableloop.work or systems operated independently by clients after handover, except where we remain a processor under contract.
1.2 Processor Activities
When delivering hosted library platforms or processing patron records during migrations, we act as processor. Clients remain controllers and must provide lawful bases and privacy notices to their users.
2. Categories of Personal Data
We collect only personal data adequate, relevant and limited to what is necessary for specified purposes.
2.1 Identity and Contact Data
Names, titles, employer, email, phone, billing and delivery addresses provided when contacting us, contracting, or using services.
2.2 Account and Access Data
Usernames, role assignments, authentication logs, IP addresses, device identifiers for portals, demos and support access.
2.3 Project and Technical Data
Requirements, metadata samples, workflow notes, integration configs. Samples may contain patron or staff identifiers if supplied by clients.
2.4 Usage and Analytics Data
Pages viewed, referral sources, interaction events collected via cookies and similar technologies as described in our Cookie Policy.
2.5 Financial Data
Invoice details, payment references, tax identifiers. Card data is processed by payment providers, not stored by us.
2.6 Communications
Emails, call notes, support tickets, meeting records relating to engagements.
2.7 Special Category Data
We do not routinely collect special category data. If accessibility or equal opportunities information is volunteered, we process it only with explicit consent or another permitted basis.
3. Sources of Personal Data
We obtain personal data directly from you, from your organisation, from public professional profiles, from referrals with consent, from service providers, and from automated technologies on our website.
During library software projects, clients may supply exports containing patron or employee records for migration testing. We require contractual instructions governing such transfers.
4. Purposes and Lawful Bases
We process personal data only where a lawful basis under UK GDPR Article 6 applies, and for special category data where Article 9 conditions are met.
- Contract performance: delivering digital library solutions, custom development, support, and account administration.
- Legitimate interests: improving services, securing systems, preventing fraud, B2B marketing to corporate contacts where balanced against rights.
- Legal obligation: tax, accounting, regulatory compliance, responding to lawful requests.
- Consent: non-essential cookies, optional newsletters, where required.
- Vital interests and public interest: rarely applicable; used only in exceptional circumstances.
5. How We Use Personal Data
Personal data is used to respond to enquiries, prepare proposals, deliver and support library software, manage billing, conduct quality assurance, train staff, comply with law, and protect our rights.
We do not use personal data for automated decision-making producing legal or similarly significant effects without explicit disclosure and safeguards.
Marketing to business contacts relies on legitimate interests or consent. You may opt out of marketing at any time by contacting help@tableloop.work.
6. Sharing and Disclosure
We share personal data with trusted parties only where necessary and under appropriate safeguards.
6.1 Service Providers
Hosting, cloud infrastructure, analytics, email delivery, payment processing, professional advisers bound by confidentiality.
6.2 Clients and Partners
Where joint delivery requires sharing contact details for project coordination.
6.3 Legal and Regulatory
Disclosure where required by court order, law enforcement, or regulatory authority.
6.4 Business Transfers
In merger, acquisition or asset sale, personal data may transfer subject to continued protection commitments.
7. International Transfers
Primary processing occurs in the United Kingdom. Where data is transferred internationally, we implement UK IDTA, UK Addendum to EU SCCs, or rely on adequacy regulations.
Transfers to subprocessors are documented in our register and restricted by Article 28 compliant agreements.
8. Retention
We retain personal data only as long as necessary for purposes collected, including legal, accounting, and reporting requirements.
Typical periods: enquiry records up to twenty-four months; contract records six years after termination; support logs three years; marketing suppression indefinitely; security logs twelve months unless incident investigation requires longer retention.
Retention schedules are reviewed periodically. Data is securely deleted or anonymised when no longer required.
9. Security Measures
We implement technical and organisational measures including encryption in transit, access controls, secure development practices, vulnerability management, backup procedures, and staff training.
No system is completely secure. We maintain incident response procedures and will notify controllers, individuals, and the ICO of personal data breaches where required by law.
10. Your Rights
Under UK GDPR you may have rights to access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making.
To exercise rights, contact help@tableloop.work. We may request verification. You may lodge a complaint with the ICO at ico.org.uk.
11. Children's Data
Our services are directed at institutions and professionals. We do not knowingly collect data from children under thirteen without parental or institutional authority.
12. Third-Party Links
Our website may link to external resources. Their privacy practices are governed by their own policies.
13. Changes to This Policy
We may update this Privacy Policy to reflect legal or operational changes. Material updates will be posted on tableloop.work with a revised date.
14. Contact
Data controller: TABLELOOP LTD. Address: 82a James Carter Road, Mildenhall, United Kingdom, IP28 7DE. Email: help@tableloop.work. Phone: +447446967065.
For cookie-specific information, see cookie-policy.html. For contractual terms, see terms-of-service.html and terms-and-conditions.html.
15. Detailed Lawful Basis Analysis for Common Processing Activities
When you submit an output request through our website, we process identity and contact data under Article 6(1)(b) UK GDPR because processing is necessary to respond to your enquiry and, where applicable, to take pre-contractual steps at your request.
When we send service-related communications about an active project, we rely on Article 6(1)(b) for contract performance or Article 6(1)(f) for legitimate interests in administering the relationship, balanced against your rights.
When we send optional marketing about new digital library capabilities to corporate contacts, we rely on Article 6(1)(f) legitimate interests for B2B communications or consent where required, always providing an opt-out.
16. International Data Transfers in Detail
Our primary hosting and development infrastructure is located in the United Kingdom. Where we use cloud services with global infrastructure, we configure regions to prioritise UK or EEA data centres when available.
Standard contractual clauses approved for use in the United Kingdom, including the UK International Data Transfer Agreement, are executed with subprocessors located in countries without adequacy regulations.
Transfer impact assessments document the laws of destination countries, supplementary measures such as encryption, and on-request summaries are available to clients under confidentiality obligations.
17. Data Subject Rights Procedures
Access requests are fulfilled by providing a structured summary of categories processed, purposes, recipients, retention, rights, and sources unless disclosure would adversely affect rights of others.
Rectification requests are actioned within statutory timeframes; where data is cached in backups, erasure or correction propagates according to backup rotation schedules.
Objection to processing based on legitimate interests is evaluated case-by-case; we cease processing unless compelling grounds override your interests or processing is required for legal claims.
18. Security Measures in Detail
Production systems segregate client environments using logical isolation, network controls, and separate credentials. Development and staging environments use synthetic or anonymised data unless otherwise agreed.
Vulnerability scanning, dependency updates, and penetration testing occur on schedules proportionate to system criticality. Critical patches are prioritised according to risk ratings.
Personnel access to production systems requires multi-factor authentication and is logged. Access reviews occur at least quarterly for privileged accounts.
19. Processing of Patron and Reader Data in Client Projects
When migrating patron records into library automation systems, we process data as processor under client instructions documented in data processing agreements and migration runbooks.
Clients must ensure privacy notices cover migration activities and that lawful bases exist for sharing exports with Supplier personnel under confidentiality obligations.
We recommend minimised field sets for migration trials, deletion of trial datasets after validation, and encryption of files in transit using secure file transfer mechanisms.
20. Automated Decision-Making and Profiling
We do not deploy automated decision-making producing legal or similarly significant effects concerning individuals without explicit contractual scope and appropriate safeguards.
Website analytics may create aggregated profiles of navigation behaviour without identifying natural persons by name unless combined with account data you provide voluntarily.
21. Complaints and Supervisory Authority
We encourage you to contact us first at help@tableloop.work so we may address concerns promptly. You have the right to lodge a complaint with the Information Commissioner's Office.
Our internal complaint log tracks privacy complaints, remediation actions, and root cause analysis to prevent recurrence.
22. Records of Processing Activities
We maintain Article 30 records describing processing purposes, data categories, recipients, transfers, retention, and security measures. Records are updated upon material changes to processing activities.
We maintain a lawful basis register documenting why each category of personal data is processed, which helps us respond consistently to data subject enquiries and regulatory reviews.
When conducting data protection impact assessments for new library software modules that process patron identifiers, we evaluate necessity, proportionality, and residual risk before deployment.
Our staff receive periodic training on confidentiality obligations, secure handling of migration datasets, and escalation procedures for suspected personal data breaches.
We apply role-based access controls so that personnel may access personal data only where required for their assigned duties in software development, support, or administration.
Where clients instruct us to anonymise or pseudonymise catalogue records during testing, we document the techniques applied and retain evidence of successful transformation.
We review subprocessors annually and require contractual commitments aligned with UK GDPR Article 28 before authorising processing on our behalf.
Retention schedules for project correspondence, support tickets, and access logs are reviewed biannually to ensure data is not kept longer than necessary.
When transferring personal data outside the United Kingdom, we implement appropriate safeguards such as International Data Transfer Agreements or adequacy decisions.
We log data subject requests centrally, monitor response deadlines, and verify identity proportionately before disclosing or modifying personal data.
Marketing preferences are stored separately from operational contact records to prevent accidental promotional contact to individuals who have opted out.
We pseudonymise analytics identifiers where feasible so that website usage statistics cannot readily be linked to named individuals without additional information.
Security monitoring tools may process IP addresses and user agent strings for fraud prevention; such processing is limited to what is necessary and proportionate.
Client administrators using demonstration environments must not upload live patron exports unless a data processing agreement and migration protocol are in place.
We maintain records of consent for optional communications including event invitations, product update newsletters, and beta programme enrolments.
Personal data within bug reports is redacted where possible before sharing with engineering teams; reporters are encouraged to use synthetic reproduction steps.
We evaluate new library automation features for privacy by design, including default privacy settings, minimal data collection, and clear administrator controls.
Where we act as processor, we assist clients with data protection impact assessments by providing technical documentation about processing operations and security measures.
We do not sell personal data to data brokers or use institutional contact details for unrelated third-party marketing without explicit consent.
Backup media containing personal data is encrypted and access is restricted to authorised infrastructure personnel with logged administrative actions.
Deletion requests are propagated to active systems and scheduled backups according to documented erasure procedures, subject to legal retention exceptions.
We publish summary statistics about data subject request volumes internally to monitor compliance performance and allocate resources to privacy operations.
Vendor management includes due diligence questionnaires covering security certifications, subprocessors, breach history, and data location for hosting providers.
Personal data in archived project repositories is subject to the same retention limits as primary systems and is included in periodic data minimisation reviews.
We provide privacy information to client procurement teams during tender processes, including standard contractual clauses and security appendix materials.
Telephone support calls may be logged with caller number, duration, and summary notes; call recording occurs only with prior notice where recording is enabled.
We maintain a lawful basis register documenting why each category of personal data is processed, which helps us respond consistently to data subject enquiries and regulatory reviews.
When conducting data protection impact assessments for new library software modules that process patron identifiers, we evaluate necessity, proportionality, and residual risk before deployment.
Our staff receive periodic training on confidentiality obligations, secure handling of migration datasets, and escalation procedures for suspected personal data breaches.
We apply role-based access controls so that personnel may access personal data only where required for their assigned duties in software development, support, or administration.
Where clients instruct us to anonymise or pseudonymise catalogue records during testing, we document the techniques applied and retain evidence of successful transformation.
We review subprocessors annually and require contractual commitments aligned with UK GDPR Article 28 before authorising processing on our behalf.
Retention schedules for project correspondence, support tickets, and access logs are reviewed biannually to ensure data is not kept longer than necessary.
When transferring personal data outside the United Kingdom, we implement appropriate safeguards such as International Data Transfer Agreements or adequacy decisions.
We log data subject requests centrally, monitor response deadlines, and verify identity proportionately before disclosing or modifying personal data.
Marketing preferences are stored separately from operational contact records to prevent accidental promotional contact to individuals who have opted out.
We pseudonymise analytics identifiers where feasible so that website usage statistics cannot readily be linked to named individuals without additional information.
Security monitoring tools may process IP addresses and user agent strings for fraud prevention; such processing is limited to what is necessary and proportionate.
Client administrators using demonstration environments must not upload live patron exports unless a data processing agreement and migration protocol are in place.
We maintain records of consent for optional communications including event invitations, product update newsletters, and beta programme enrolments.
Personal data within bug reports is redacted where possible before sharing with engineering teams; reporters are encouraged to use synthetic reproduction steps.
We evaluate new library automation features for privacy by design, including default privacy settings, minimal data collection, and clear administrator controls.
Where we act as processor, we assist clients with data protection impact assessments by providing technical documentation about processing operations and security measures.
We do not sell personal data to data brokers or use institutional contact details for unrelated third-party marketing without explicit consent.
Backup media containing personal data is encrypted and access is restricted to authorised infrastructure personnel with logged administrative actions.
Deletion requests are propagated to active systems and scheduled backups according to documented erasure procedures, subject to legal retention exceptions.
We publish summary statistics about data subject request volumes internally to monitor compliance performance and allocate resources to privacy operations.
Vendor management includes due diligence questionnaires covering security certifications, subprocessors, breach history, and data location for hosting providers.
Personal data in archived project repositories is subject to the same retention limits as primary systems and is included in periodic data minimisation reviews.
We provide privacy information to client procurement teams during tender processes, including standard contractual clauses and security appendix materials.
Telephone support calls may be logged with caller number, duration, and summary notes; call recording occurs only with prior notice where recording is enabled.
We maintain a lawful basis register documenting why each category of personal data is processed, which helps us respond consistently to data subject enquiries and regulatory reviews.
When conducting data protection impact assessments for new library software modules that process patron identifiers, we evaluate necessity, proportionality, and residual risk before deployment.
Our staff receive periodic training on confidentiality obligations, secure handling of migration datasets, and escalation procedures for suspected personal data breaches.
We apply role-based access controls so that personnel may access personal data only where required for their assigned duties in software development, support, or administration.
Where clients instruct us to anonymise or pseudonymise catalogue records during testing, we document the techniques applied and retain evidence of successful transformation.
We review subprocessors annually and require contractual commitments aligned with UK GDPR Article 28 before authorising processing on our behalf.
Retention schedules for project correspondence, support tickets, and access logs are reviewed biannually to ensure data is not kept longer than necessary.
When transferring personal data outside the United Kingdom, we implement appropriate safeguards such as International Data Transfer Agreements or adequacy decisions.
We log data subject requests centrally, monitor response deadlines, and verify identity proportionately before disclosing or modifying personal data.
Marketing preferences are stored separately from operational contact records to prevent accidental promotional contact to individuals who have opted out.
We pseudonymise analytics identifiers where feasible so that website usage statistics cannot readily be linked to named individuals without additional information.
Security monitoring tools may process IP addresses and user agent strings for fraud prevention; such processing is limited to what is necessary and proportionate.
Client administrators using demonstration environments must not upload live patron exports unless a data processing agreement and migration protocol are in place.
We maintain records of consent for optional communications including event invitations, product update newsletters, and beta programme enrolments.
Personal data within bug reports is redacted where possible before sharing with engineering teams; reporters are encouraged to use synthetic reproduction steps.
We evaluate new library automation features for privacy by design, including default privacy settings, minimal data collection, and clear administrator controls.
Where we act as processor, we assist clients with data protection impact assessments by providing technical documentation about processing operations and security measures.
We do not sell personal data to data brokers or use institutional contact details for unrelated third-party marketing without explicit consent.
Backup media containing personal data is encrypted and access is restricted to authorised infrastructure personnel with logged administrative actions.
Deletion requests are propagated to active systems and scheduled backups according to documented erasure procedures, subject to legal retention exceptions.
We publish summary statistics about data subject request volumes internally to monitor compliance performance and allocate resources to privacy operations.
Vendor management includes due diligence questionnaires covering security certifications, subprocessors, breach history, and data location for hosting providers.
Personal data in archived project repositories is subject to the same retention limits as primary systems and is included in periodic data minimisation reviews.
We provide privacy information to client procurement teams during tender processes, including standard contractual clauses and security appendix materials.
Telephone support calls may be logged with caller number, duration, and summary notes; call recording occurs only with prior notice where recording is enabled.
We maintain a lawful basis register documenting why each category of personal data is processed, which helps us respond consistently to data subject enquiries and regulatory reviews.
When conducting data protection impact assessments for new library software modules that process patron identifiers, we evaluate necessity, proportionality, and residual risk before deployment.
Our staff receive periodic training on confidentiality obligations, secure handling of migration datasets, and escalation procedures for suspected personal data breaches.
We apply role-based access controls so that personnel may access personal data only where required for their assigned duties in software development, support, or administration.
Where clients instruct us to anonymise or pseudonymise catalogue records during testing, we document the techniques applied and retain evidence of successful transformation.
We review subprocessors annually and require contractual commitments aligned with UK GDPR Article 28 before authorising processing on our behalf.
Retention schedules for project correspondence, support tickets, and access logs are reviewed biannually to ensure data is not kept longer than necessary.
When transferring personal data outside the United Kingdom, we implement appropriate safeguards such as International Data Transfer Agreements or adequacy decisions.
We log data subject requests centrally, monitor response deadlines, and verify identity proportionately before disclosing or modifying personal data.
Marketing preferences are stored separately from operational contact records to prevent accidental promotional contact to individuals who have opted out.
We pseudonymise analytics identifiers where feasible so that website usage statistics cannot readily be linked to named individuals without additional information.
Security monitoring tools may process IP addresses and user agent strings for fraud prevention; such processing is limited to what is necessary and proportionate.
Client administrators using demonstration environments must not upload live patron exports unless a data processing agreement and migration protocol are in place.
We maintain records of consent for optional communications including event invitations, product update newsletters, and beta programme enrolments.
Personal data within bug reports is redacted where possible before sharing with engineering teams; reporters are encouraged to use synthetic reproduction steps.
We evaluate new library automation features for privacy by design, including default privacy settings, minimal data collection, and clear administrator controls.
Where we act as processor, we assist clients with data protection impact assessments by providing technical documentation about processing operations and security measures.
We do not sell personal data to data brokers or use institutional contact details for unrelated third-party marketing without explicit consent.
Backup media containing personal data is encrypted and access is restricted to authorised infrastructure personnel with logged administrative actions.
Deletion requests are propagated to active systems and scheduled backups according to documented erasure procedures, subject to legal retention exceptions.
We publish summary statistics about data subject request volumes internally to monitor compliance performance and allocate resources to privacy operations.
Vendor management includes due diligence questionnaires covering security certifications, subprocessors, breach history, and data location for hosting providers.
Personal data in archived project repositories is subject to the same retention limits as primary systems and is included in periodic data minimisation reviews.
We provide privacy information to client procurement teams during tender processes, including standard contractual clauses and security appendix materials.
Telephone support calls may be logged with caller number, duration, and summary notes; call recording occurs only with prior notice where recording is enabled.
We maintain a lawful basis register documenting why each category of personal data is processed, which helps us respond consistently to data subject enquiries and regulatory reviews.
When conducting data protection impact assessments for new library software modules that process patron identifiers, we evaluate necessity, proportionality, and residual risk before deployment.
Our staff receive periodic training on confidentiality obligations, secure handling of migration datasets, and escalation procedures for suspected personal data breaches.
We apply role-based access controls so that personnel may access personal data only where required for their assigned duties in software development, support, or administration.
Where clients instruct us to anonymise or pseudonymise catalogue records during testing, we document the techniques applied and retain evidence of successful transformation.
We review subprocessors annually and require contractual commitments aligned with UK GDPR Article 28 before authorising processing on our behalf.
Retention schedules for project correspondence, support tickets, and access logs are reviewed biannually to ensure data is not kept longer than necessary.
When transferring personal data outside the United Kingdom, we implement appropriate safeguards such as International Data Transfer Agreements or adequacy decisions.
We log data subject requests centrally, monitor response deadlines, and verify identity proportionately before disclosing or modifying personal data.
Marketing preferences are stored separately from operational contact records to prevent accidental promotional contact to individuals who have opted out.
We pseudonymise analytics identifiers where feasible so that website usage statistics cannot readily be linked to named individuals without additional information.
Security monitoring tools may process IP addresses and user agent strings for fraud prevention; such processing is limited to what is necessary and proportionate.
Client administrators using demonstration environments must not upload live patron exports unless a data processing agreement and migration protocol are in place.
We maintain records of consent for optional communications including event invitations, product update newsletters, and beta programme enrolments.
Personal data within bug reports is redacted where possible before sharing with engineering teams; reporters are encouraged to use synthetic reproduction steps.
We evaluate new library automation features for privacy by design, including default privacy settings, minimal data collection, and clear administrator controls.
Where we act as processor, we assist clients with data protection impact assessments by providing technical documentation about processing operations and security measures.
We do not sell personal data to data brokers or use institutional contact details for unrelated third-party marketing without explicit consent.
Backup media containing personal data is encrypted and access is restricted to authorised infrastructure personnel with logged administrative actions.
Deletion requests are propagated to active systems and scheduled backups according to documented erasure procedures, subject to legal retention exceptions.
We publish summary statistics about data subject request volumes internally to monitor compliance performance and allocate resources to privacy operations.
Vendor management includes due diligence questionnaires covering security certifications, subprocessors, breach history, and data location for hosting providers.
Personal data in archived project repositories is subject to the same retention limits as primary systems and is included in periodic data minimisation reviews.
We provide privacy information to client procurement teams during tender processes, including standard contractual clauses and security appendix materials.
Telephone support calls may be logged with caller number, duration, and summary notes; call recording occurs only with prior notice where recording is enabled.
We maintain a lawful basis register documenting why each category of personal data is processed, which helps us respond consistently to data subject enquiries and regulatory reviews.
When conducting data protection impact assessments for new library software modules that process patron identifiers, we evaluate necessity, proportionality, and residual risk before deployment.
Our staff receive periodic training on confidentiality obligations, secure handling of migration datasets, and escalation procedures for suspected personal data breaches.
We apply role-based access controls so that personnel may access personal data only where required for their assigned duties in software development, support, or administration.
