Data protection

Our products handle very little personal data — they measure soil and rock, not people. This page sets out what personal data is involved, where it sits, and how we meet UK GDPR and the Data Protection Act 2018.

This page complements our privacy policy

Our full privacy notice, covering website visitors, customers and enquiries, is on the main site: gdsinstruments.com privacy policy. This page addresses the questions we get asked in supplier assessments about the products themselves.

Personal data in our products

Our control and acquisition software processes measurement data — load, displacement, pressure, volume change, temperature. That is not personal data. The personal data that does appear is incidental and stays on your systems:

DataWhere it livesWho controls it
Operator name or user account recorded against a test On your control machine, in your test records You
Names typed into free-text fields — technician, project engineer, client contact In your test and project records You
Licence holder details Your licence file, and our licensing records Joint: you for your copy, GDS for ours

Our software does not transmit test data or personal data to GDS. There is no telemetry, no usage analytics and no automatic error reporting in the control path. If you send us a data file or a log to help diagnose a problem, that is an explicit act by you, and we handle what you send as described below.

We are not a processor for your test data

Our products as sold today run on your machines and return nothing to us, so in respect of the test records they produce GDS is not a data processor. That usually means a data processing agreement is unnecessary for the software licence itself. If your procurement process requires one anyway, or if you use a service where we do process data on your behalf, contact us and we will put the appropriate agreement in place.

Data you send us for support

Diagnosing a problem often means sending us a test file, a log or a screenshot, which may contain project names, client references or operator names. When you do:

  • We use it only to resolve your enquiry.
  • We hold it in our support system, which is a hosted service — see international transfers — for as long as needed for that purpose and for our warranty and quality obligations.
  • We do not use your test data to develop products, train models, or for any purpose beyond supporting you, without asking you first.
  • If you would rather send anonymised data, say so and we will tell you which fields we actually need.

Please do not send us personal data you do not need to send. If a log will do, a spreadsheet of named individuals will not help us diagnose a transducer fault.

Data in vulnerability reports

If you report a vulnerability, we process the contact details you give us in order to correspond with you, credit you if you wish, and keep a record of how the report was handled. We keep that record for as long as the affected product is supported, because we may need to demonstrate to a regulator how a report was managed.

You may report anonymously. It makes it harder for us to ask follow-up questions, but we will still investigate.

This website

This site is deliberately plain:

  • No cookies are set. There is nothing to consent to, which is why you have not been shown a banner.
  • No analytics, no tag managers, no third-party scripts, no embedded fonts or content loaded from other domains.
  • Server access logs record the visitor’s IP address, the date and time, the request line, the response status and size, the referring page and the user agent. They are kept for 30 days for security and diagnostics, not analytics, and are then deleted.

Your rights

Where GDS is the controller of your personal data, you have the rights given by UK GDPR: access, rectification, erasure, restriction, objection, portability, and the right not to be subject to solely automated decisions with significant effects. To exercise them, or to ask a data protection question, contact info@gdsinstruments.com.

We respond within one month. If you are not satisfied you may complain to the Information Commissioner's Office at ico.org.uk, though we would rather you raised it with us first.

International transfers

Our own business data sits on servers in our UK office, and our products send us nothing. The one place your data leaves the UK is our support system.

Our support system holds your enquiry, your name and email address, and whatever you attach — including a test file, if you send one. It is hosted in the EU, in Ireland and Frankfurt, which UK adequacy regulations cover without further paperwork, and the provider processes it under a data processing agreement.

If you are sending data to us from the EU, the European Commission’s adequacy decision for the United Kingdom was renewed in December 2025 and runs to December 2031, so you need no additional transfer mechanism at your end either.

If something goes wrong

We maintain an incident response process covering personal data breaches. Where a breach is likely to result in a risk to individuals' rights and freedoms we notify the ICO within 72 hours of becoming aware, and we notify affected individuals where the risk is high.

A personal data breach and a product security incident are different things with different reporting routes — the latter is covered in our CRA statement. An event can be both, and our process treats them together so neither clock is missed.