Data Protection Complaints Policy

Data Protection Complaints Policy

Thinventory Holdings Limited · Draft v0.1 · 16 June 2026 · Effective from 19 June 2026

Owner: Chief Technology Officer (data protection lead).

Applies to: all Thinventory staff and contractors handling personal data or customer contact.

Review: Annually.

1. Purpose and scope

This policy sets out how Thinventory receives, handles, records and responds to complaints about its use of personal data, to meet the requirements of section 164A of the Data Protection Act 2018, inserted by section 103 of the Data (Use and Access) Act 2025 and in force from 19 June 2026, and our wider UK GDPR accountability obligations. It applies whenever a person believes there has been an infringement of data protection law in connection with their own personal data, for example complaints about security or retention, access or other rights requests, cookies and tracking, marketing consent, accuracy, profiling, or the way personal data has been collected, used or shared.

Where Thinventory acts as a controller (website, marketing, prospect and recruitment data) we resolve complaints under this policy. Where we act as a processor for a customer, we recognise the complaint, route it to the relevant customer-controller without undue delay and assist them as required by our contract.

We will tell individuals about their right to make a data protection complaint to Thinventory at the point personal data is collected, including through our privacy notices, and when responding to data-subject rights requests where appropriate.

2. What counts as a data protection complaint

A data protection complaint is any expression of dissatisfaction however worded, and through any channel about how Thinventory has collected, used, shared, stored, retained, profiled, secured or otherwise handled the complainant’s own personal data, or handled a data-subject rights request. A complaint does not have to use the word “complaint”. Where someone complains on behalf of another person, we verify their authority before disclosing personal data or progressing the complaint in detail.

A complaint is different from:

  • A rights request (e.g. Data Subject Access Request or DSAR): a request to exercise a right (e.g. access, erasure, objection). These run on their own legal clock (one month) and are handled under our rights-request process but a complaint about how a request was handled is a complaint.
  • A general service/customer issue: about service quality, billing or delivery with no data-protection dimension will be handled by customer support.
  • An HR grievance: staff matters will be handled under HR procedures unless it is a grievance with a data protection element which must be logged and handled as a complaint in parallel with any HR process.

If in doubt, treat it as a data protection complaint and log it. Failing to spot complaints is the most common compliance failure.

3. How complaints reach us

Our primary channel is [email protected], which feeds the Data Protection queue in our internal service management tool “Jira”. We also accept complaints by post (Floor 7, The Future Works, Brunel Way, Slough SL1 1FQ), by phone (+44 (0)2476 584 272), through any customer support channel, and through any other route by which the complaint reaches us, including social media. Any complaint received outside the primary channel must be logged into the Jira queue on the same working day so a single, complete record exists. Staff must not reject or ignore a data protection complaint because it was not made through the preferred channel.

4. Our handling commitments (the timetable)

Stage Commitment
Acknowledgement We acknowledge receipt within 30 days of receiving the complaint, with the operational target being same working day wherever possible. The acknowledgement confirms what we understand the complaint to be, who is handling it, whether we need further information or identity/authority evidence, and the expected next step. Automated acknowledgements may be used for electronic complaints, provided the complaint is still reviewed promptly.
Investigation & updates We investigate without undue delay, gather relevant evidence, make appropriate enquiries, and keep the complainant informed at appropriate stages including where we need more information, where there is a delay, or where the expected timeframe changes. The investigation begins when the complaint is received and is not deferred until the end of the 30-day acknowledgement period.
Outcome We communicate the outcome clearly and without undue delay, explaining our findings, any action taken, and the next steps available to the complainant.
Review & escalation If the complainant is dissatisfied they may ask for an internal review by the data protection lead. If the complainant is still dissatisfied following an internal review they can complain to the ICO.

5. Triage and prioritisation

Every complaint is risk-assessed at intake. Prioritise where there is higher data sensitivity, an individual who may be vulnerable, or a systemic/recurring issue that may affect others. High-risk complaints (e.g. those indicating a possible personal data breach or affecting many individuals) are escalated immediately to the data protection lead and assessed against the personal data breach process in parallel, keeping the two records and deadlines separate.

Where a complaint involves a child or a potentially vulnerable individual, we will use clear, accessible and age-appropriate language, consider whether additional support or reasonable adjustments are needed, and avoid unnecessary barriers to making or progressing the complaint.

6. Roles and responsibilities

  • Data protection lead (CTO): owns this policy, oversees handling, decides outcomes on complex/high-risk complaints, reports to senior governance.
  • Complaints handler / deputy: day-to-day triage, investigation, updates and responses; maintains the log.
  • Frontline teams (support, sales, recruitment): recognise potential complaints and route them to the Data Protection queue the same day; do not attempt to resolve them informally.
  • Legal / senior governance: consulted on high-risk matters and potential ICO involvement; receive periodic metrics.
  • All staff and contractors: complete appropriate training so they can recognise data protection complaints, route them promptly, preserve relevant evidence, and avoid disclosing personal data before identity or authority checks are complete.

7. Records, retention and reporting

For every complaint we record: the date received and acknowledged, the complainant and channel, identity and authority checks where relevant, the nature of the complaint, the investigation steps and evidence, progress updates, the decision and rationale, the outcome communicated, any remedial action, and key dates. Records are held in the Jira Data Protection queue with restricted access. Complaint files are retained for six years from closure, unless a longer period is required because of an ongoing dispute, regulatory enquiry, legal hold, insurance matter, repeat complaint, litigation risk or other legitimate business need. They are then securely deleted or anonymised. We report volumes, timeliness, overdue matters, root causes and recurring themes to senior governance periodically, and will be ready to report complaint volumes to the ICO if and when that power is exercised.

8. Links to other processes

This process sits alongside, but is kept separate from, our DSAR / rights-request process (one-month clock) and our personal data breach process (72-hour ICO notification where applicable). Where a complaint overlaps with either, we open and track each record separately so no legal deadline is missed.

The privacy notice, DSAR response templates, customer support scripts and staff training materials must be kept aligned with this policy so individuals are consistently told how to complain to Thinventory and, if dissatisfied, to the ICO.