MomentumStorm
Trust and privacy

UK & EU GDPR Compliance Statement

Last updated July 11, 2026. This statement explains how Momentum Support Co-operation LTD supports compliance with the UK GDPR, the EU GDPR, and the Data Protection Act 2018 across Momentum OS. It is provided for transparency and works alongside our Privacy Policy at /privacy-policy, Data Processing Addendum at /dpa, Subprocessor Notice at /subprocessors, and Security Overview at /security. It is a template kept under review and does not replace advice from a qualified data-protection adviser.

Effective date
July 11, 2026
Return homeOpen workspace

1. Controller and processor roles

Momentum Support Co-operation LTD, company number 17078117, of 5 Brayford Square, London, E1 0SG, United Kingdom, is the controller for account, billing, security, and business-administration data. When a customer uploads their own records into Momentum OS, the customer is the controller and Momentum Support Co-operation LTD acts as processor on the customer's documented instructions.

Our data-protection and privacy contact, including for any Data Protection Officer role, is leon@momentumos.co.uk. Data-subject requests, breach reports, and formal legal notices should be sent there. General product and support questions can be sent to info@momentumos.co.uk.

2. Categories of personal data we process

As a business-operations platform, Momentum OS can process customer contact and CRM records, employee HR and payroll data, commerce and payment-related data, call recordings and transcripts, meeting media, support communications, and uploaded identity documents such as passports or proof-of-address where a customer configures those workflows.

We also process account, authentication, billing, device, and usage data needed to operate, secure, and improve the service. A fuller list is set out in the Privacy Policy at /privacy-policy.

3. Lawful bases for processing

For data where we are controller, we rely on performance of a contract to deliver the service, legitimate interests to secure, maintain, and improve the platform and prevent abuse, compliance with legal obligations such as tax and accounting duties, and consent where it is required, for example for certain non-essential cookies or optional marketing.

For customer-uploaded personal data we process as processor, the lawful basis is chosen and documented by the customer as controller. Special-category data and criminal-offence data require an additional condition under Articles 9 and 10 and the Data Protection Act 2018, which remains the customer's responsibility to establish and record.

4. Data-subject rights

Subject to applicable law, individuals have the right to be informed, the right of access, the right to rectification, the right to erasure, the right to restrict processing, the right to data portability, the right to object, and rights relating to automated decision-making and profiling. Where processing relies on consent, that consent can be withdrawn at any time.

If a customer holds your data in Momentum OS, that customer is the controller and you should contact them first; we will support them in responding. Where we are the controller of your data, you can exercise your rights using the contact details below.

5. How to exercise your rights

Data-subject requests can be sent to leon@momentumos.co.uk. We may need to verify identity before acting and will respond within the statutory timeframe, normally one month, which can be extended for complex or numerous requests as permitted by law.

Workspace administrators can also use in-product export and deletion tools to service many requests directly, including structured data export for portability and record removal for erasure requests. Some data may be retained where a legal obligation, legal hold, or fraud-prevention need applies.

6. International transfers

Where personal data is transferred outside the UK or EEA, we use a lawful transfer mechanism such as a UK or EU adequacy decision, the EU Standard Contractual Clauses, or the UK International Data Transfer Addendum to the SCCs, together with any supplementary measures a transfer risk assessment identifies.

The Subprocessor Notice at /subprocessors identifies the providers we use and the safeguards that apply. Customers remain responsible for assessing transfers created by their own connected applications and internal processes.

7. Retention and deletion

Customer service data is normally retained for the subscription term plus 90 days. Backups are retained for 35 days, security and audit logs for 12 months, billing and tax records for 7 years, and recordings and transcripts for 90 days by default, or a shorter customer-configured period.

We delete or anonymise personal data when it is no longer needed for the purpose it was collected, subject to legal retention duties. Data held in protected backups is removed on the normal backup-expiry cycle.

8. Security and breach notification

We maintain technical and organisational measures appropriate to the risk, including encryption in transit and at rest, role-based access control, tenant isolation, multi-factor authentication, and audit logging. These are described in the Security Overview at /security.

If we become aware of a personal-data breach, we will assess it without undue delay, notify affected customers as required, support their own notification duties, and, where we are controller, notify the ICO within 72 hours where the breach is likely to result in a risk to individuals.

9. Complaints and supervisory authority

You can raise any data-protection concern with us at leon@momentumos.co.uk and we will work to resolve it. People in the UK also have the right to complain to the Information Commissioner's Office at ico.org.uk. Our ICO registration reference is [ICO registration number].

Individuals in the EEA may lodge a complaint with their local supervisory authority. We would, however, appreciate the chance to address your concern before you approach a regulator.