VISIBLEby TNG Designs← Back to Sign Up
Legal

Privacy Policy

Last updated: August 2026  ·  Data Controller: TNG Designs  ·  Governing law: UK GDPR & Data Protection Act 2018

Your privacy matters to us. This Policy explains what personal data we collect, why we collect it, how we use it, and your rights under UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR). Please read it carefully.

1. Who We Are (Data Controller)

The data controller responsible for your personal data is:

TNG Designs
Address: Executive Suite 20, St. James Court, Wilderspool Causeway, Warrington, Cheshire, WA4 6PS
Email: tanya@tngdesigns.co.uk
Website: tngdesigns.co.uk

If you have any questions about how we handle your personal data, or wish to exercise any of your rights, please contact us at the email address above.

We are registered with / notified to the Information Commissioner’s Office (ICO). Our ICO registration reference is: ZA809920.

2. What Personal Data We Collect

We collect and process the following categories of personal data:

Account & Identity Data

  • Full name and email address (provided at sign-up)
  • Password (stored in encrypted form via Supabase Auth — we never see your plain-text password)
  • Business name, job title, and industry sector
  • Profile photo or logo (if uploaded)

Brand DNA & Platform Data

  • Brand DNA information you input (target audience, values, services, positioning, competitors)
  • AI chat conversations with the Brand Advisor
  • Content preferences, ticked content ideas, goals, and progress data
  • Brand Guidelines customisations (colours, fonts)
  • Feature suggestions you submit

Usage & Technical Data

  • Login timestamps and last-active dates
  • IP address and general geographic location (country/region)
  • Browser type and device information
  • Pages visited within the Platform

Payment Data

  • Subscription plan and billing status
  • Payment card details are not stored by us — they are handled directly and securely by Stripe (our PCI-DSS compliant payment processor). We only receive a transaction reference and your billing status.

3. How We Collect Your Data

We collect personal data in the following ways:

  • Directly from you — when you sign up, complete onboarding, fill in your Brand DNA, use the Brand Advisor, or submit a feature suggestion
  • Automatically — through your use of the Platform (login activity, usage patterns, technical logs)
  • From third parties — Stripe provides payment and subscription status information; Supabase Auth handles authentication

4. Legal Basis for Processing

We process your personal data on the following legal grounds under UK GDPR Article 6:

  • Contract performance (Art. 6(1)(b)): processing your account data, Brand DNA, and usage data is necessary to provide you with the VISIBLE subscription service you have signed up for.
  • Legitimate interests (Art. 6(1)(f)): analysing usage patterns to improve the Platform, identifying at-risk accounts for customer support purposes, and maintaining security. Our interests do not override your rights and freedoms.
  • Legal obligation (Art. 6(1)(c)): retaining financial records as required by HMRC and applicable accounting regulations.
  • Consent (Art. 6(1)(a)): for any optional marketing communications we may send you. You may withdraw consent at any time by clicking “unsubscribe” in any email or by contacting us.

5. How We Use Your Data

We use your personal data to:

  • Create and manage your account and deliver the VISIBLE platform to you
  • Personalise AI-generated brand strategy, messaging, and content ideas using your Brand DNA
  • Process and manage your subscription and payments via Stripe
  • Send essential service communications (account confirmations, billing notices, service updates)
  • Provide customer support
  • Monitor Platform usage for security, fraud prevention, and performance improvement
  • Comply with legal obligations (e.g., tax record-keeping)
  • Send marketing communications about VISIBLE or TNG Designs services, where you have consented or where we have a legitimate interest and you have not opted out

We will never sell your personal data to third parties.

6. AI Processing & Your Brand Data

Your Brand DNA and chat messages are sent to our AI provider (Anthropic / Claude API) to generate personalised outputs. This processing is necessary to deliver the core service. We have appropriate data processing agreements in place with our AI provider.

Your Brand DNA data is used solely to generate content for your account. It is not used to train AI models or shared with other users of the Platform.

AI conversations are stored in our database to provide continuity of your Brand Advisor chat history. You may request deletion of your chat history at any time by contacting us.

7. Data Sharing & Third Parties

We share your data only with the following trusted third-party service providers, each under appropriate data processing agreements:

  • Supabase — database, authentication, and file storage (servers in EU/US with appropriate safeguards)
  • Stripe — payment processing (PCI-DSS Level 1 certified)
  • Anthropic (Claude API) — AI content generation (your prompts and Brand DNA are processed to generate outputs)
  • Vercel — platform hosting and deployment (EU/US infrastructure)

We may also disclose your data where required to do so by law, court order, or regulatory authority, or to protect the rights and safety of TNG Designs, our users, or the public.

We do not share your data with advertisers or data brokers.

8. International Data Transfers

Some of our third-party service providers operate outside the UK and European Economic Area (EEA). Where data is transferred internationally, we ensure appropriate safeguards are in place, including:

  • UK International Data Transfer Agreements (IDTAs) or standard contractual clauses
  • Adequacy decisions by the UK Secretary of State or European Commission where applicable
  • The UK-US Data Bridge (for US-based providers who participate)

You may request further information about the safeguards in place for specific transfers by contacting us.

9. Data Retention

We retain your personal data for as long as your account is active and for a period afterwards as required by law or legitimate business need:

  • Account and Brand DNA data: retained for the duration of your Subscription and for 30 days after cancellation, after which it is permanently deleted (unless you request earlier deletion)
  • Financial/payment records: retained for 7 years as required by HMRC
  • Usage logs and technical data: retained for up to 12 months for security and performance monitoring
  • Marketing consent records: retained until you withdraw consent, plus a reasonable period thereafter for compliance evidence

When data is deleted, it is permanently and securely erased from our systems and from those of our processors, subject to any legal retention requirements.

10. Your Rights Under UK GDPR

As a data subject under UK GDPR, you have the following rights. To exercise any of these rights, please contact us at tanya@tngdesigns.co.uk. We will respond within one calendar month.

  • Right of access — you may request a copy of the personal data we hold about you (a Subject Access Request)
  • Right to rectification — you may request correction of inaccurate or incomplete data
  • Right to erasure (“right to be forgotten”) — you may request deletion of your data, subject to legal retention obligations
  • Right to restriction of processing — you may request that we limit processing of your data in certain circumstances
  • Right to data portability — you may request your data in a structured, commonly used, machine-readable format
  • Right to object — you may object to processing based on legitimate interests or for direct marketing purposes
  • Right not to be subject to automated decision-making — we do not make solely automated decisions that have legal or similarly significant effects on you
  • Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing

If you are not satisfied with our response to any request, or believe we are processing your data unlawfully, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO):

ICO helpline: 0303 123 1113
Website: ico.org.uk
Postal address: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

11. Cookies & Local Storage

VISIBLE uses the following technologies to store data in your browser:

Authentication cookies

Strictly necessary cookies are set by Supabase Auth to maintain your login session. These cannot be disabled without preventing you from logging in.

Local storage

We use your browser’s local storage (not cookies) to save Platform preferences such as your generated brand strategy content, content idea selections, and progress goals. This data is stored locally on your device and is not transmitted to our servers unless you interact with the Platform.

Analytics

We do not currently use third-party analytics cookies (e.g., Google Analytics). If this changes, we will update this Policy and seek your consent where required under PECR.

You can clear local storage and cookies at any time via your browser settings. Doing so will log you out and reset any locally stored preferences.

12. Security

We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or destruction. These include:

  • Encrypted data transmission (HTTPS/TLS)
  • Encrypted password storage via Supabase Auth (bcrypt hashing)
  • Row-level security policies on our database
  • Access controls limiting who can view user data
  • Third-party processors selected for their security certifications and standards

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware of it, and will notify affected individuals without undue delay where required.

13. Children

VISIBLE is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately and we will take steps to delete it.

14. International Users & EU GDPR

This Policy is written primarily with reference to UK GDPR and the Data Protection Act 2018. If you are located in the European Union or European Economic Area, equivalent protections apply under EU GDPR (Regulation 2016/679). In such cases, references to the ICO should be read as references to your local supervisory authority.

If you are located outside the UK or EU, your local data protection laws may provide additional or different rights. We will comply with applicable local requirements to the extent required by law.

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will notify you by email or via an in-platform notice at least 14 days before the changes take effect.

The date at the top of this page shows when this Policy was last updated. Continued use of the Platform after the effective date of any changes constitutes your acceptance of the updated Policy.

16. Contact Us

For any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact:

TNG Designs — Data Privacy
Company Registration No: 12241351  ·  ICO Ref: ZA809920
Email: tanya@tngdesigns.co.uk
Address: Executive Suite 20, St. James Court, Wilderspool Causeway, Warrington, Cheshire, WA4 6PS

Terms & Conditions →|Back to Sign Up|Contact Us

© 2026 TNG Designs Group Limited. VISIBLE™ is a trademark of TNG Designs Ltd. Company No. 12241351  ·  ICO Ref. ZA809920. All rights reserved.