What we do with data,
and what we refuse to do.
Aftermath operates platforms that sit close to people: learner drivers, salon customers, staff on a shop floor. This page records the standards those systems are held to, including the things the company has decided it will not build.
- Commitments
- 5 stated
- Refusals
- 5 stated
- Applies to
- Every product the group ships
- Certification
- None held, and none claimed
Judged on what it refuses to do.
No facial recognition, no inference about people, no listening, no automated decisions about staff, and no figure published without a source. The standards below apply to every product the group ships.
Measurement, not identification.
Where Aftermath systems observe a physical space, they measure activity. They do not identify people, and they are not built to.
- Money and permissions are deterministicBalances, permissions, availability and every reported measure are computed in code. The AI explains them and proposes what to change; it does not calculate them.
- A person approves anything that mattersAgents propose. A human approves anything that moves money, changes a record or speaks for the company.
- Every measure has a written definitionA number means the same thing on Monday as it does at the end of the quarter, in every report that carries it.
- Detection stays on siteWhere cameras are used, processing happens on the premises. Only anonymous, structured events leave the building.
- We stand behind our own counterThe group operates businesses on its own software. UrbanCuts runs on BarberData, which makes it the platform’s first and most demanding user.
- No facial recognitionNo face matching, no biometric identity, and no tracking of a person between visits.
- No inference about peopleNo emotion, age, gender or ethnicity inference anywhere in the group’s systems.
- No listeningAudio is off. Nothing is recorded or transcribed from a room.
- No automated decisions about staffNothing in these systems makes a disciplinary, dismissal or pay decision. Material decisions about people are made by people.
- No figures we cannot show the source forEstimates are labelled as estimates, with the period and the assumptions stated. Where a figure has not been verified, it is not published.
Every Aftermath platform processes personal data for a stated purpose, keeps it for a configured period and provides export, correction and deletion. Privacy notices, records of processing and data-subject request handling are part of the product rather than a policy bolted to the side of it.
This website itself collects nothing beyond what an enquiry form needs. It sets no analytics or advertising cookies, makes no third-party request, and self-hosts its typefaces so that no visitor’s address is handed to anyone else in exchange for a font. Cookies.
Security — the ordinary disciplines, done
Transport encryption everywhere, secrets held outside the document root, role-based access with server-side checks, rate limiting on anything public, audited administrative actions, and encrypted backups that are restored rather than assumed. Access to any system that holds customer data is granted by role and reviewed.
Aftermath does not hold ISO 27001, SOC 2, PCI DSS or HIPAA certification, and does not claim to. Where a client requires a certified processor for part of a system, we say so and use one.
Your data, and your right to take it back.
Aftermath Ltd operates within the European Union and processes personal data under EU data protection law. Where Aftermath acts as a processor for a client, the terms of that processing are written down before the processing begins.
Individuals may request access to, correction of, or deletion of their personal data. Contact the company and select General; the request will be routed to the platform that holds the record.
Tell us, and we will fix it.
If you believe you have found a security issue in any Aftermath system or website, report it through the contact form, selecting General and writing Security as the first word of your message. Please include enough detail to reproduce the issue and give us a reasonable period to remedy it before publishing.
We do not operate a paid bounty programme. We do read every report, and we will tell you what we did about it.