Privacy Policy
Last updated July 11, 2026. This policy explains how Momentum Support Co-operation LTD collects, uses, stores, shares, and protects personal data through Momentum OS, our business-operations platform spanning CRM, HR and payroll, commerce, communications, and AI features. It works alongside our GDPR statement at /gdpr, Data Processing Addendum at /dpa, Subprocessor Notice at /subprocessors, Cookie Policy at /cookie-policy, and Security Overview at /security.
1. Who we are and how to contact us
Momentum Support Co-operation LTD, company number 17078117, registered in England and Wales at 5 Brayford Square, London, E1 0SG, United Kingdom, operates Momentum OS. For the personal data described in this policy we are the controller for account, billing, security, and business-administration data, and the processor acting on a customer's documented instructions for the data that customer uploads into the platform.
Privacy questions and data-subject requests can be sent to leon@momentumos.co.uk. General product and support questions can be sent to info@momentumos.co.uk or by phone on +44 1263 808887. People in the UK also have the right to complain to the Information Commissioner's Office at ico.org.uk; our ICO registration reference is [ICO registration number].
2. Controller and processor roles
Where you interact with us directly — signing up, being billed, receiving support, or being an administrator of a workspace — Momentum Support Co-operation LTD is the controller and decides how and why that data is processed. This account data includes names, work contact details, authentication and device information, billing records, and usage and audit events.
Where a customer uploads their own records into Momentum OS, that customer is the controller and we act only as their processor. This customer-uploaded data is governed by the customer's own privacy notices and by our Data Processing Addendum at /dpa. If your data is held in a customer's workspace, you should contact that organisation first to exercise your rights, and we will support them in responding.
3. Personal data we collect
As a business-operations platform, Momentum OS can process a broad range of personal data depending on the modules a customer enables. This includes CRM contact and lead records; employee HR and payroll data such as pay, leave, and role information; commerce, order, and payment-related data; call recordings and transcripts; meeting media; support communications; and uploaded identity documents such as passports or proof of address where a customer configures those workflows.
We also collect the account, profile, company, authentication, billing, device, browser, and usage data needed to operate, secure, and improve the service, together with audit and diagnostic logs. Depending on configuration, the platform may process integrations data from email, calendar, telephony, payment, workforce, and other connected applications a customer chooses to link.
4. How and why we use personal data
We use personal data to provide the service, authenticate users, manage customer relationships, route communications, deliver HR, commerce, and support workflows, automate follow-up work, improve reliability, detect and prevent abuse, meet contractual commitments, and comply with legal obligations such as tax and accounting duties.
If AI features are enabled, the platform may use conversation and workflow context to generate summaries, suggestions, classifications, routing recommendations, and operational insights. Teams should review AI-generated output before relying on it for legal, financial, HR, medical, or similarly sensitive decisions. We do not sell personal data.
5. Lawful bases and special-category data
For data where we are the controller, we rely on performance of a contract to deliver the service, our legitimate interests in securing, maintaining, and improving the platform and preventing abuse, compliance with legal obligations, and consent where it is required, for example for certain non-essential cookies described in our Cookie Policy at /cookie-policy.
For customer-uploaded data we process as processor, the lawful basis is chosen and documented by the customer as controller. Special-category data under Article 9 and criminal-offence data under Article 10 of the UK GDPR require an additional condition, which remains the customer's responsibility to establish. You should avoid placing payment card numbers, authentication secrets, or unnecessary health or identity details into free-text notes unless your compliance model and redaction controls are in place.
6. Sharing, subprocessors, and integrations
We use vetted hosting, database, security, payment, communications, telephony, and AI providers where needed to operate the service or deliver features a customer selects. Our Subprocessor Notice at /subprocessors identifies these providers, their purpose, and where they process data, and distinguishes core infrastructure from optional customer-enabled services.
We may also disclose information where required by law, to establish or defend legal claims, to protect the rights and safety of people or the service, or as part of a corporate transaction such as a merger or acquisition, subject to appropriate confidentiality safeguards. Customer-enabled providers process data according to the customer's configuration and their own applicable terms.
7. International transfers
Where personal data is transferred outside the UK or EEA, we use a lawful transfer mechanism such as a UK or EU adequacy decision, the EU Standard Contractual Clauses, or the UK International Data Transfer Addendum to the SCCs, together with any supplementary measures a transfer risk assessment identifies.
The Subprocessor Notice at /subprocessors sets out the providers we use and the safeguards that apply. Customers remain responsible for assessing transfers created by their own connected applications and internal processes.
8. Retention and deletion
Customer service data is normally retained for the subscription term plus 90 days. Backups are retained for 35 days, security and audit logs for 12 months, billing and tax records for 7 years, and recordings and transcripts for 90 days by default, or a shorter customer-configured period.
We delete or anonymise personal data when it is no longer needed for the purpose it was collected, subject to legal retention duties, a legal hold, fraud prevention, or dispute preservation. Data held in protected backups is removed on the normal backup-expiry cycle.
9. Your rights and how to exercise them
Subject to applicable law, you may have the right to be informed, to access your data, to rectification, to erasure, to restrict or object to processing, to data portability, and rights relating to automated decision-making and profiling. Where processing relies on consent, you can withdraw it at any time.
Where we are the controller, requests can be sent to leon@momentumos.co.uk; we may need to verify your identity and will respond within the statutory timeframe, normally one month. Where your data sits in a customer's workspace, that customer is the controller and administrators can use in-product export and deletion tools to service many requests directly. Some data may be retained where a legal, contractual, security, or fraud-prevention obligation applies.
10. Security and breach notification
We maintain technical and organisational measures appropriate to the risk, including encryption in transit and at rest, role-based access control, tenant isolation, multi-factor authentication support, and audit logging. These are described in our Security Overview at /security. No system can guarantee perfect security, so customers should also enforce strong authentication, least-privilege access, and secure integration credentials.
If we become aware of a personal-data breach, we will assess it without undue delay, notify affected customers as required so they can meet their own duties, and, where we are the controller, notify the ICO within 72 hours where the breach is likely to result in a risk to individuals.
11. Children's data
Momentum OS is a business tool that is not directed at children and is not intended for use by anyone under 16. We do not knowingly collect personal data from children as a controller.
If a customer uses the platform in a context that involves data about children, the customer is the controller and is responsible for the additional protections, lawful basis, and any parental-consent requirements that apply.
12. Cookies, changes, and contact
Momentum OS uses cookies and similar technologies for authentication, session management, security, preferences, and measurement, as described in our Cookie Policy at /cookie-policy. Where local law requires consent for non-essential cookies, we ask for it before those cookies are set.
We may update this policy from time to time. Material changes will update the date above and be communicated through the website, application, or account communications. Questions can be sent to leon@momentumos.co.uk or info@momentumos.co.uk.