Last updated: 12 September 2026
This policy explains how tScrub ("we", "us", "our") collects and uses personal data when you use our website or software. We process personal data lawfully, fairly, and transparently, in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).
tScrub is a trading name of TFix Ltd (company number 07892418), which is the data controller for personal data collected through this website. You can contact us at [email protected] or by post at Generator Business Centre, 95 Miles Road, Mitcham, Surrey, CR4 3FH. TFix Ltd is registered with the Information Commissioner's Office under registration number ZB787416.
We collect the minimum personal data necessary to provide the service. We do not collect data beyond what is needed for the purposes below, and we do not engage in profiling.
| Category | Examples | Source |
|---|---|---|
| Contact details | Work email address | You (download form) |
| Correspondence | Content of enquiries | You |
| Technical data | IP address, user agent | Web server logs |
The tScrub software processes hardware identifiers (drive and system serial numbers) to produce sanitisation reports. These are not personal data in our hands; when you run tScrub on your own media, you remain the data controller for any personal data stored on that media.
| Purpose | Legal basis |
|---|---|
| Provide the requested service | Performance of a contract / legitimate interest |
| Respond to enquiries | Legitimate interest |
| Send requested product updates | Consent |
| Maintain website security and prevent misuse | Legal obligation / legitimate interest |
We do not sell personal data. We share it only with service providers who help us operate the service (for example, an email delivery provider), under written contracts that require equivalent protection. We may disclose data where required by law, by a court, or by a regulator such as the ICO or the FCA.
We store and process personal data within the UK. Where a service provider transfers data outside the UK, we ensure appropriate safeguards are in place, such as the International Data Transfer Agreement (IDTA), the UK Addendum, or an adequacy decision.
We retain personal data only for as long as necessary for the purposes set out above, or as required by law. Enquiry correspondence is retained for up to 12 months unless a longer period is required; marketing contact details are retained until you withdraw consent or ask us to delete them.
We apply appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage. These include access controls, encryption in transit, and secure processing agreements with suppliers. We will notify you and the ICO of a personal data breach where required to do so.
We do not use personal data for automated decision-making or profiling that produces legal or similarly significant effects.
Our service is intended for business users and is not directed at children. We do not knowingly collect personal data from children.
Under UK GDPR you have the right to:
To exercise any right, email us at the address above. We will respond within one month (extendable by a further two months for complex requests) and may ask you to verify your identity. You may also complain to the Information Commissioner's Office (ICO).
Our website is static and does not set tracking cookies or serve advertising. It loads fonts from Google Fonts, which may involve a request to Google's servers; Google's processing is subject to its own privacy policy.
Our website may link to third-party sites. We are not responsible for their privacy practices; please review their policies.
We may update this policy from time to time. The date at the top of this page shows when it was last revised. Material changes will be notified where required.
If you have concerns about how we handle your personal data, contact us in the first instance. You have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection.