Smash Robotics logoSmash Robotics

Legal

Privacy policy

This policy explains what personal data Smash Robotics collects, why we hold it, how long we keep it, and the rights you have over it.

Policy

Privacy policy

Last updated: 21 August 2026

1. Who we are

Smash Robotics ("we", "us") builds and manages automated work stations for industrial customers. We are the data controller for personal data collected through this website and in the course of our commercial relationships. For privacy enquiries, contact privacy@smashrobotics.com. Registered entity and address details are available on request and on our contact page.

2. Personal data we collect

  • Enquiry and site-walk forms: name, company, work email, phone number if given, role, site location, and the message you send us.
  • Customer accounts: name, work email, role, organisation, and authentication records for people we invite into the customer portal.
  • Correspondence: emails, meeting notes, and support messages exchanged with you.
  • Technical data: IP address, browser and device type, pages visited, and error logs generated when you use this site.

We do not knowingly collect special category data, and we do not collect data from children. Do not send us sensitive personal data through the website forms.

3. Why we use it, and our legal basis

  • Responding to enquiries and arranging site walks — legitimate interests in responding to business contact you initiated.
  • Delivering and managing a station, and providing portal access — performance of our contract with your organisation.
  • Security, fraud prevention, and service reliability — legitimate interests in keeping our systems safe.
  • Legal, tax, and accounting records — compliance with legal obligations.
  • Marketing emails, where sent — consent, or legitimate interests for existing business contacts. You can opt out at any time.

4. Customer operational data and trained models

Data produced at a customer's site — task recordings, part images, cycle logs, exception records, and the models trained from them — belongs to the customer. Where we process it, we act as a processor under the customer's instructions and under a data processing agreement that forms part of our services contract. Customers can export this data and the trained models, and they keep running their station if our relationship ends. We do not sell customer data, and we do not use one customer's operational data to train systems for another customer without that customer's written agreement.

5. Who we share data with

We share personal data only with service providers who help us run the business, each bound by contract to process it only on our instructions: cloud hosting and database providers, email delivery providers, error and analytics tooling, and professional advisers such as accountants and lawyers. We also disclose data where we are legally required to. We do not sell personal data or share it with advertising networks.

6. International transfers

Some providers process data outside the UK and the EEA. Where they do, transfers rely on UK adequacy regulations, the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum, together with additional safeguards where needed. Customers with data residency requirements can ask us to keep operational data within a specified region.

7. How long we keep it

  • Enquiries that do not become projects: up to 24 months from last contact.
  • Customer contacts and account records: for the contract term plus 6 years.
  • Financial and tax records: 6 years, as required by law.
  • Website technical logs: up to 12 months.

Customer operational data is retained for the period agreed in the services contract and deleted or returned on request at the end of it.

8. Security

Access to personal data is restricted to staff who need it. We use encryption in transit, access controls and role-based permissions on the customer portal, invitation-only account creation, audit logging of model changes, and regular reviews of our providers. No system is perfectly secure, but we notify affected parties and the relevant regulator where a breach requires it.

9. Cookies

This site uses only cookies and local storage that are strictly necessary to operate it, including keeping you signed in to the customer portal. We do not use advertising cookies or third-party tracking pixels. If that changes, we will ask for consent first.

10. Your rights

You have the right to access your personal data, to correct it, to have it erased, to restrict or object to processing, to data portability, and to withdraw consent where consent is the basis. To exercise any of these, email privacy@smashrobotics.com. We respond within one month. If you are unhappy with our response, you can complain to the UK Information Commissioner's Office at ico.org.uk, or to your local supervisory authority.

11. Changes to this policy

We update this policy when our processing changes. The date at the top shows the current version, and we tell customers directly about material changes that affect them.