Politique de confidentialité
Ce que nous collectons, pourquoi nous le conservons, qui y accède, et vos droits.
Who we are
ACSS (SW) LTD ("ACSS", "we", "us") is a company registered in England and Wales, company number 10932637, VAT number 276 2096 86, with its registered office at 2A Ledbury Mews N, London W11 2AF, United Kingdom. ACSS is part of the Wakeflow group.
We make software for the fish and seafood trade: the Aquarius processing and administration system, and the Hooked ordering app that customers of a seafood merchant use to place their orders.
For anything in this policy, write to enquiries@acss.co.uk or call +44 7715 905 265.
The two different roles we play
This is the part that decides which rights you have and who you should ask, so it comes before the detail.
When you visit this website, email us, or ask us for a demonstration, we decide what to do with your information. In data protection terms we are the controller, and this policy governs.
When one of our customers — a seafood merchant — runs Aquarius or Hooked, the information inside their system belongs to them. Their staff, their customers, their orders, their prices. They decide what goes in and how long it stays. We only handle it to provide and support the software, on their written instructions. In data protection terms they are the controller and we are the processor.
So if you are a chef, a buyer or an employee of a business that uses Aquarius, and you want to know what is held about you or want it corrected or erased, ask that business first. They hold the relationship and the decision. Tell us and we will help them answer, but we cannot make that call for them.
What we collect when you deal with us directly
From this website and from ordinary business contact:
- Your name, business email address, telephone number, company name and role, when you send an enquiry, ask for a demonstration or exchange emails with us.
- What you told us you need, so that we can answer sensibly and remember the conversation if you come back.
- Records of our correspondence, quotations, contracts and invoices.
We do not run advertising trackers or third-party analytics profiling on this website, and we do not sell or rent anyone's information to anybody, ever.
What is inside a customer's Aquarius or Hooked system
We are the processor for this, not the controller, but you are entitled to know what the software handles:
- Accounts for the merchant's own staff, including name, email address, permission level, and factory-floor operator codes used at weighing and packing stations.
- The merchant's trading records: their customers and suppliers, contacts and delivery addresses, orders, prices, stock, batches and traceability data, invoices and credit notes.
- Sign-in information. Accounts are authenticated by Google Firebase Authentication using an email address and password, or by signing in with a Google or Microsoft account. We never see or store the password of a Google or Microsoft account.
- For Hooked: orders placed in the app, by telephone, by email or by asking the in-app assistant. Where a customer places an order by voice, the app records the audio and converts it to text so the order can be read and confirmed. That recording is order information belonging to the merchant, and is kept and deleted on their terms.
Why we are allowed to hold it
For our own contacts and enquiries we rely on legitimate interests — running and marketing a business-to-business software company to people who approached us or work in our trade — and on the performance of a contract once you become a customer, and on legal obligation for the records tax law requires us to keep.
For anything inside a customer's system, the lawful basis is the customer's to establish. We act on their instructions under a written data processing agreement.
Where we ever rely on consent — a mailing list, for example — you can withdraw it at any time and it takes effect from then on.
Who else sees it
A short list, and we would rather name it than describe it vaguely:
- Google Cloud Platform and Firebase (Google Ireland Limited), which host the software, its databases and its sign-in. Data is held in the United Kingdom and the European Union.
- Microsoft, where a user chooses to sign in with a Microsoft work or personal account — Microsoft confirms who they are; we receive the email address and name, and no password.
- Our email, telephony and accounting providers, for the ordinary running of the business.
- Our professional advisers, and any authority we are legally obliged to tell.
Every supplier that handles personal information for us is bound by a contract that restricts them to our instructions. We will name our current sub-processors in writing on request. We do not sell personal information.
Where it is held, and for how long
Our systems and their backups are hosted in the United Kingdom and the European Union. Where any supplier transfers information outside the UK or the EEA, that transfer is covered by UK adequacy regulations or by the International Data Transfer Agreement or Addendum.
Enquiries that do not become business are kept for up to two years, so we recognise you if you come back. Records of a customer relationship are kept for the life of the contract and then for six years, which is what company and tax law requires. Anything inside a customer's system is kept for as long as that customer instructs, and returned or deleted when their contract ends.
Your rights
Under the UK GDPR you can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular use, object to processing we base on legitimate interests, and ask for your information in a portable form.
Write to enquiries@acss.co.uk. We will answer within one month. There is no charge.
If you think we have got it wrong, please tell us first — we would rather fix it. You also have the right to complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.
Cookies
This website uses only what it needs to work: a small amount of local browser storage that remembers which language you chose, so the site is not in English again on your next visit. It is not shared with anyone and it is not used to track you between sites.
The Aquarius and Hooked applications use storage and cookies necessary to keep you signed in.
Security
Access to customer systems is restricted to the staff who need it, over encrypted connections, with sign-in through Google Firebase Authentication. Each customer's data is separated at the database level so one customer cannot read another's. Traffic is encrypted in transit and data is encrypted at rest by our hosting provider.
No system is perfect. If a breach ever affects your information and is likely to be a risk to you, we will tell you and the Information Commissioner's Office within the time the law allows.
Changes
We update this policy when what we do changes. The date at the top is when it last changed; this version is dated 8 September 2026. If a change matters to you, we will tell customers directly rather than relying on you to notice.
