Effective date: 6 August 2026
About this policy
UCDeck operates this website and is responsible for the personal information collected through it. You can contact us about this policy or your information at info@ucdeck.com.
Information we collect
We may handle the following information when you use the site:
- Contact-form information, including your name, email address, optional company, optional machine or UCCNC setup, and message.
- Contact notification status, including whether the related email notification is pending, sent, or failed.
- Information you include when you contact us directly by email.
- For administrator sign-in, the approved email address, login request time, keyed IP-address hash, code-delivery status, failed-attempt count, and session timing or revocation status. Numeric login codes and session bearer tokens are not stored in plaintext.
- For customer access requests and registered accounts, the email address, optional name, approval status and decision history, keyed request-IP hash, notification-delivery status, support-access setting, account lifecycle, login-code security records, and revocable session records.
- Support ticket references, subjects, priorities, statuses, conversation messages, authorship, and lifecycle history.
- Download-release records such as release name, file size, checksum, public availability, upload attribution, and download event.
- Append-only audit records containing the acting account when known, action, affected record, time, limited event metadata, and a keyed request-IP hash when available.
- Website analytics such as page title, page address, referrer, session and pseudonymous visitor identifiers, and page-visibility timing.
- Technical information ordinarily created when a website is accessed, such as IP address, browser, device, request, and security-log information available to our service providers.
The current AI Brain analytics script uses browser local storage and session storage to recognise a visitor and a browsing session. The script does not itself set analytics cookies.
How and why we use information
- To receive, assess, and respond to enquiries.
- To retain a reliable administrative inbox when an email notification is delayed, unavailable, or unsuccessful.
- To discuss product information, availability, and support.
- To operate, secure, diagnose, and improve the website.
- To authenticate approved administrators without storing account passwords and to prevent abusive login-email requests.
- To acknowledge and review customer access requests, communicate approval decisions, authenticate approved customers without passwords, operate support tickets, and enforce each account's support permission.
- To publish active software releases and record download events for operational, security, and service-improvement purposes.
- To preserve an operational audit history of access and data changes for accountability, security, and recovery.
- To understand which pages and information are useful to visitors.
- To maintain records where reasonably needed for legal, security, or business purposes.
Depending on the circumstances, these uses may rely on steps you ask us to take before entering a contract, our legitimate interests in responding to enquiries and operating the site, or compliance with a legal obligation. Where consent is required, you may withdraw it at any time.
Service providers and sharing
We do not sell personal information. We use a limited number of providers to operate the site and process enquiries:
- OpenAI Sites and Cloudflare provide website hosting, server-side form processing, database storage, and protected file storage for the administration, customer, support, and download systems.
- Resend provides email delivery for contact-form enquiries and single-use administrator and registered-customer login codes, access-request acknowledgements and decisions, administrator account-review notices, contact notifications, and support-ticket notifications.
- AI Brain provides the analytics service loaded on the homepage.
These providers receive information only as needed to provide their services. We may also disclose information where required by law, to protect legal rights or security, or as part of a genuine business reorganisation.
Contact enquiries may be viewed by authorised UCDeck administrators who sign in and pass the site's email allowlist. Administrator access is limited to people who need the information to review and respond to enquiries. Administrators can archive enquiries from the main inbox or restore them later. Archiving preserves the enquiry record.
Administrators sign in only with a single-use code sent to an approved email address. The resulting secure, HTTP-only session cookie expires after 12 hours, and the server-side administrator email allowlist is checked on every protected request.
A valid email submitted through the customer sign-in form may be stored as a pending access request. The applicant and authorised administrators are notified, and an administrator can approve or decline the request. Approved customers receive a separate secure, HTTP-only session cookie after using a single-use email code. Customer access is checked against the approved, active account record on every protected request. Customers can see only their own support conversation. Support access may be enabled or disabled for each account by an authorised administrator. Active software releases are available publicly and do not require a customer session.
Administrators can create, update, archive, and restore customer, ticket, and release records. Archiving preserves the record and its history. Audit events are append-only and are not available to registered customers.
International processing
Some providers may process information in countries other than your own. Where data-protection law requires it, the relevant provider or UCDeck will use an approved transfer safeguard or another lawful transfer mechanism.
How long information is kept
We keep enquiry information only for as long as reasonably needed to respond, provide follow-up or support, maintain appropriate business records, resolve disputes, and meet legal or security obligations. Administrator and customer login, session, account, support, download, and audit records are retained only as reasonably needed for service delivery, access control, abuse prevention, security review, business continuity, and legal obligations. Archived records remain preserved unless a separate lawful retention or erasure decision is made outside ordinary portal controls. Analytics and technical records are retained according to the applicable service configuration and operational need.
Your data-protection rights
Depending on the law that applies, you may have rights to request access to, correction of, deletion of, restriction of, or a copy of your personal information, and to object to certain processing. You may also have the right to complain to your local data-protection authority.
To make a request, email info@ucdeck.com. If you are in Ireland, you can also contact the Data Protection Commission.
Security
We use reasonable technical and organisational measures intended to protect information. No internet transmission or storage system can be guaranteed completely secure, so please avoid submitting sensitive information that is not needed for your enquiry.
Children
This product-information website is not directed to children, and we do not knowingly seek personal information from children.
Third-party websites
Links to suppliers and other external websites are governed by those websites' own privacy information. Please review their terms before submitting information or placing an order with them.
Changes to this policy
We may update this policy when the website, providers, or legal requirements change. The effective date at the top of this page identifies the current version.