The Portal, Farringdon, by J.P. Morgan

Privacy Policy

Version 2.1 · Effective 14 August 2026

This application is a private, invitation-only presentation tool provided as a business-to-business service: everyone whose data it processes uses it in a business capacity. It collects the minimum personal data needed to control access and keep the service secure (sign-in details, the devices approved for each person, connection addresses and two essential cookies), together with a record of what each presentation showed and for how long, and nothing else, beyond the one-off delivery address described below when a take-away pack is emailed at a prospect’s request. There is no analytics of your browsing, no advertising and no marketing.

01Who is responsible for your data

Future Engine Limited, a company registered in England and Wales under company number 16640272, whose registered office is at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom, operates this application and is the controller of the personal data described in this policy. The application is provided as a business-to-business service: Future Engine is engaged directly by the client whose project it presents, on a project-by-project basis, and acts as the application’s super administrator: it creates and manages every user account and provides the related account management and support to that client and its project team, within the scope agreed by contract. The client may determine who on its team is given access; day-to-day processing within the application is carried out by Future Engine Limited.

The people whose data this policy covers (account holders and those connecting to the application) use it in a business capacity, as the client’s own team or as professionals engaged on the client’s project. The application is not offered to consumers and does not process consumer data.

02What this policy covers

This policy covers personal data processed by this presentation application only. It does not cover other dealings you may have with Future Engine Limited or with the client outside the application.

03The data we collect

  • Account details: the username, role and a securely hashed password for each managed account. Usernames are short three-character identifiers (two letters and a number) rather than full names, and we never store passwords in readable form.
  • Connection data: the network (IP) address each sign-in came from. It is a record, not a gate: it is kept with the sign-in history, it is what a pause after repeated failed attempts is counted against, and it may appear in technical logs. It never decides who is allowed in.
  • Device data: for each device approved for a person, a description of it as the browser reports it (for example “Safari on iPad”), when it was approved, when it was last used and the address it was last seen at. For each approved device, and for each request still waiting to be approved, we derive an approximate location label from that address (city / region level) using a third-party IP geolocation service, which receives that address for the lookup; see “Who we share it with” below.
  • Session data: two essential cookies. A signed session cookie keeps you signed in and records your access role, and a device-marker cookie holds a random value identifying this browser so an approved device is recognised at your next sign-in. Neither contains tracking identifiers; see “Cookies” below.
  • Presentation activity: for each presentation given through the application, whether it was launched as a tenant presentation or a rehearsal, the sections, drawer trays and floor plans it showed, the order they were shown in, and how long each was on screen. It is kept with the session that gave the presentation, so it is associated with the account signed in at the time; a session started with the shared access code identifies the device rather than a named person. Time during which nothing is touched anywhere in the session is capped, and both the capped and the plain elapsed figures are kept. It is visible only to the super administrator.
  • Technical logs: routine server logs (times, addresses, requested pages, errors) kept for security and troubleshooting.
  • Take-away delivery address: when a presenter emails a take-away pack to a prospect at the prospect’s request, the email address typed for that send is used once to deliver that email and is not stored by the application.

The application does not track your browsing, does not profile you, does not use advertising or tracking technologies, and does not knowingly collect data about children. A small number of on-device preferences (such as which screen mode a device uses) are stored locally on the device itself and never sent to us.

04Why we use it and our legal bases

  • To provide access: authenticating sign-ins and maintaining your session (performance of a contract, and our legitimate interest in operating the service).
  • To keep the service secure: checking that a sign-in is on a device approved for that person, pausing sign-in from a connection after repeated failed attempts (and alerting the administrator to sustained ones), preventing unauthorised access and investigating misuse (our and our clients’ legitimate interests in protecting confidential material).
  • To understand how the presented material performs: recording which parts of a presentation were shown and for how long, so the material can be judged and improved (our and our clients’ legitimate interests in the quality of the material they commission). A presentation given on the shared access-code account is not attributable to a named person.
  • To establish, exercise or defend legal claims: keeping the record of who accepted the Terms of Use and when, together with the record of sign-ins, devices, sessions and presentations given, so that we and the relevant client can evidence and pursue a breach of those terms, including a presentation shown without the client’s permission (our and our clients’ legitimate interests in enforcing their rights).
  • To meet legal obligations: where we are required to retain or disclose information by law.

05Cookies

The application sets two strictly necessary cookies, both http-only and neither used for tracking, analytics or advertising. The session cookie keeps you signed in securely and is removed when you sign out or when it expires. The device-marker cookie holds a random value that identifies this browser so a device approved for you is recognised the next time you sign in; it deliberately outlasts the session (up to 400 days, the longest a browser allows) and therefore remains after you sign out, and it carries nothing about you, only that value. Clearing it, or using a different browser or a private window, simply makes this look like a new device, which means a fresh approval request at the next sign-in. Because both cookies are essential to providing the service you asked for, no consent banner is required and no optional cookies exist to configure.

06Who we share it with

We do not sell or rent personal data, ever. Data is shared only with:

  • our hosting, infrastructure and email delivery providers, who store and process it on our behalf under contract (the email delivery provider handles the addresses that the application’s emails, such as an emailed take-away pack or an administrative alert, are sent to);
  • a third-party IP geolocation service (currently ipwho.is), which receives the network address a trusted device was last seen at, or the address a request waiting for approval came from, solely to estimate its approximate location so the administrator can recognise it. Only the address is sent (never a name, account or any other data), and only for those devices and requests, not for routine visits;
  • the relevant client, where necessary to manage who has access to their presentation, to report on how the presented material performed, or to investigate a suspected breach of the Terms of Use; and
  • professional advisers and authorities, where required by law or to protect our or our clients’ legal rights.

07International transfers

Data is stored with reputable hosting providers. Where any processing takes place outside the United Kingdom, we ensure an adequate level of protection through recognised safeguards (such as adequacy regulations or standard contractual clauses).

08How long we keep it

Account details are kept for as long as the account is needed for the engagement and are deleted when the account is removed. Session cookies expire automatically. Technical logs are retained on a short rolling basis for security and troubleshooting, and longer only where needed to investigate an incident or meet a legal obligation. Records of past sign-ins (when a session ran, from which connection address, on which device, and the terms version accepted) are kept for the life of the deployment as evidence of terms acceptance and access control, until the administrator deletes them, either one session at a time or all of one person’s records at once. The presentation activity described above is kept with the session that produced it, for the same period, and is deleted with it. A device stops being approved when the administrator revokes it or when it goes unused for longer than its set period.

09How we protect it

Access to the application is controlled by authentication and role-based permissions; passwords are stored only as strong one-way hashes; sessions are cryptographically signed; and administrative functions are restricted to designated administrators.

10Your rights

Under UK data protection law you have rights over your personal data, including the rights to access it, to have it corrected or deleted, to restrict or object to its processing, and to data portability where applicable. To exercise any of these rights, contact Future Engine Limited via the contact details provided with your engagement, or in writing to its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. You also have the right to complain to the Information Commissioner’s Office (ico.org.uk) if you are unhappy with how your data has been handled.

11Changes to this policy

We may update this policy from time to time; the version and effective date at the top of this page identify the current one. Material changes will be brought to your attention at your next password sign-in.