JK IT GROUP LTD operates Trace2Trace. For privacy questions, data access requests or project-specific data handling questions, contact info@trace2trace.com.
1. Who we are
JK IT GROUP LTD, United Kingdom, operates Trace2Trace and is the organisation responsible for the processing described in this policy unless a project agreement states that we act only as a processor for a customer. Contact: info@trace2trace.com.
2. Scope of this policy
This policy covers the public Trace2Trace website, business enquiries, proposals, contracts, support and project work. It also covers personal data that may appear incidentally in domain, operator, company, supplier or enforcement research. It does not govern third-party websites that we investigate or link to.
3. Our role: controller or processor
For our own website, security, business administration, customer relationship management and independently determined public-source research, we normally act as controller. Where a customer gives us personal data and instructs us exactly how to process it for a project, we may act as processor; the relevant agreement or data-processing terms will govern that activity.
4. Data we may collect
We may process names, business contact details, organisation and job title, enquiry and correspondence content, contract and billing information, account or project identifiers, IP address and basic server logs, language preference, and records of support or project communication. We do not need payment-card data for ordinary Trace2Trace enquiries.
5. Investigation and public-source data
Project work can include domains, URLs, redirect paths, operator and company names, public contact details, licence statements, public legal notices, public technical data, hosting or certificate information, public enforcement material and other information visible in lawful public sources. Customers may also provide internal domain lists, supplier questions, case references or other project material.
6. Why we use personal data
We use personal data to answer enquiries, prepare and perform contracts, deliver investigations and monitoring, communicate findings, maintain project records, protect our systems, prevent misuse, manage billing, improve service quality and comply with legal obligations. We do not use investigation material for unrelated advertising profiles.
7. Legal bases
Depending on the activity, processing may be necessary for a contract or steps requested before a contract, for compliance with a legal obligation, or for our legitimate interests in operating a secure B2B service, conducting professional research and protecting our legal rights. Where consent is the appropriate basis, it can be withdrawn for future processing.
8. Sensitive and criminal-offence data
We do not ask customers to send special-category data or criminal-offence data unless it is genuinely necessary for a lawful assignment. If such data is processed, we apply an appropriate UK GDPR lawful basis and any additional condition required by the Data Protection Act 2018, limit access and avoid collecting more than the assignment requires.
9. Sharing and service providers
We may use carefully selected hosting, infrastructure, security, communications, cloud, research and professional service providers where needed to run Trace2Trace or complete an assignment. Information may also be disclosed to advisers, insurers, auditors or public authorities where legally required or reasonably necessary to protect rights. We do not sell personal data to advertisers.
10. International transfers
Some technical or professional providers may process data outside the United Kingdom or the country in which you are located. Where data-protection law requires safeguards, we use an applicable adequacy decision, approved contractual clauses or another lawful transfer mechanism, taking account of the nature and sensitivity of the information.
11. Security
We use technical and organisational measures designed to protect project and business information, including controlled access, authentication, system logging, separation of access where appropriate, secure transmission and supplier review. No internet service can promise absolute security, so particularly sensitive projects can be given additional agreed handling requirements.
12. Retention and deletion
We keep personal data only for as long as reasonably needed for the purpose for which it was collected, including project delivery, evidence and audit needs, contractual records, security, dispute handling and legal obligations. Retention periods therefore vary by data type and assignment. Specific deletion, return or retention requirements can be agreed for confidential projects, subject to legal and backup constraints.
13. Cookies, logs and external fonts
The public site may store a language-preference cookie so your selected language is remembered. Our servers may record standard technical logs such as IP address, request time, requested page and browser information for security and reliability. The site currently loads web fonts from Google Fonts, which may cause your browser to contact Google; we do not intentionally use advertising cookies on the public Trace2Trace site.
14. Your data-protection rights
Subject to applicable law and exemptions, you may ask for access to your personal data, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may also withdraw consent where consent is used. We may need to verify identity and may be unable to disclose information that would adversely affect another person's rights, confidential investigations or legal obligations.
15. Customer instructions and third-party rights
If we process personal data on behalf of a customer, requests from individuals may need to be handled through that customer as controller. Customers are responsible for having a lawful basis to provide personal data to us and for giving any required notices to the people concerned. We will reasonably assist with valid requests where our role and the applicable agreement require it.
16. Complaints
Please contact info@trace2trace.com first if you have a concern so we can investigate it. Where UK data-protection law applies, you also have the right to complain to the UK Information Commissioner's Office (ICO), and you may have rights to contact another competent supervisory authority depending on where you are located.
17. Changes and contact
We may update this policy as Trace2Trace, our providers or applicable law changes. The current version and update date are published on this page. For privacy questions, rights requests, processor arrangements or project-specific retention and security requirements, contact info@trace2trace.com.
Contact us if you want to exercise a privacy right or discuss how information will be handled for a specific investigation.