Legal
Privacy Policy
This policy explains what personal data Isodev Limited collects, why we collect it, who we share it with and what you can ask us to do about it.
1. Who we are
Isodev Limited is a company registered in England and Wales under company number 16866628, with its registered office at Bartle House, 9 Oxford Court, Manchester, M2 3WQ. In this policy, "we", "us" and "our" mean Isodev Limited.
We provide software development, IT consultancy, data processing and information services, and we own and operate the Insightnix and OpenStat platforms.
We are registered with the Information Commissioner's Office as a data controller. Registration reference: ZC073124.
For anything in this policy, contact us at hello@isodev.co.uk or write to the registered office above, marked for the attention of the data protection contact.
2. What this policy covers
This policy covers personal data we handle through this website, through enquiries and correspondence, and in the course of providing services to our clients and suppliers.
Our products are run on separate domains and have their own notices. If you use insightnix.com or openstat.uk, read the privacy notice published on that site as well as this one.
This policy does not cover third party websites we link to. We are not responsible for how those sites handle your data.
3. Controller and processor
Data protection law distinguishes between the organisation that decides why and how personal data is used (the controller) and the organisation that processes it on the controller's instructions (the processor). Both roles apply to us, in different situations.
- We are the controller for enquiry and contact data, supplier and client relationship data, marketing correspondence, recruitment enquiries and website technical logs.
- We are a processor for personal data contained in client systems and datasets that we build, migrate, transform, host or report on under a services agreement. In that case the client decides what happens to the data, we act on their documented instructions, and our obligations are set out in a written data processing agreement. If your data is held by one of our clients and you want it corrected or deleted, contact that organisation, not us. We will support them in responding.
4. Information we collect
4.1 Information you give us
When you submit the enquiry form or email us, we collect your name, email address, company name if you provide one, the topic you select and the content of your message. If an enquiry becomes a project, we also collect the business contact details, correspondence and documents needed to run the engagement.
4.2 Information we collect automatically
Our web server and content delivery network record standard technical data for every request: IP address, date and time, the page requested, referring page, browser and operating system, and the outcome of the request. These logs exist for security, troubleshooting and abuse prevention. We do not use them to build profiles of visitors.
4.3 Information we receive from others
We may receive your business contact details from a colleague who refers you, from a public business directory or from Companies House when we carry out standard checks on a prospective client or supplier.
4.4 Information we do not want
Please do not send us special category data (such as health, ethnicity, religious beliefs, trade union membership or biometric data) or financial account details through the enquiry form. If a project genuinely requires sensitive data, we will agree the handling arrangements in writing first.
5. Why we use it and our lawful basis
We only use personal data where the law allows. The table sets out each purpose and the lawful basis we rely on under UK GDPR.
| What we do | Lawful basis |
|---|---|
| Reply to your enquiry and discuss possible work | Legitimate interests: responding to someone who has approached us. Steps taken at your request before entering a contract. |
| Deliver services, manage projects and support clients | Performance of a contract, or legitimate interests where the contract is with your employer. |
| Invoicing, credit control and accounting records | Legal obligation, and legitimate interests in running the business. |
| Keep the website and our systems secure, prevent spam and abuse | Legitimate interests in protecting our systems and our clients' data. |
| Send occasional updates about our services to business contacts | Legitimate interests, or consent where the law requires it. Every message includes an unsubscribe option. |
| Meet regulatory, tax and legal requirements, and handle disputes | Legal obligation, and legitimate interests in establishing or defending legal claims. |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and we have concluded it is not. You can object to that processing at any time using the contact details in section 14, and we will stop unless we have compelling grounds to continue.
We do not carry out automated decision making or profiling that produces legal or similarly significant effects.
8. International transfers
Our website and email are hosted within the United Kingdom or the European Economic Area. Some providers, including Cloudflare and Google, operate global networks, so data may be processed outside the UK.
Where that happens we rely on UK adequacy regulations, or on the International Data Transfer Agreement or the UK Addendum to the European Commission's standard contractual clauses, together with any additional safeguards the transfer requires. You can ask us for details of the safeguards applied to a specific transfer.
9. How long we keep information
We keep personal data only as long as we need it, then delete it or anonymise it.
| Record | Retention |
|---|---|
| Enquiries that do not lead to work | 12 months from the last contact |
| Client project records and correspondence | 6 years from the end of the engagement |
| Accounting and tax records | 6 years from the end of the relevant financial year, as required by the Companies Act 2006 |
| Marketing contacts | Until you unsubscribe, or 24 months of no engagement |
| Server and security logs | Up to 12 months |
| Personal data we process for a client | As instructed by that client in the data processing agreement, then returned or deleted |
10. Security
We take appropriate technical and organisational measures to protect personal data, including encryption in transit over HTTPS, access control on a need to know basis, unique credentials with multi factor authentication where available, hardened form handling, regular patching, and backups held separately from live systems.
No system is completely secure. If a personal data breach is likely to result in a risk to your rights, we will report it to the Information Commissioner's Office within 72 hours and tell you directly where the law requires it.
11. Your rights
Under UK data protection law you have the right to:
- be told how your data is used, which is the purpose of this policy;
- get a copy of the personal data we hold about you;
- have inaccurate data corrected;
- have data deleted, where we no longer have grounds to keep it;
- restrict how we use your data while a concern is resolved;
- receive data you gave us in a portable, machine readable format;
- object to processing based on legitimate interests, and to direct marketing at any time, which we always honour;
- withdraw consent where consent is the basis we rely on, without affecting anything done before you withdrew it.
To exercise any of these, email hello@isodev.co.uk. We respond within one month. If a request is complex we may extend that by two months and will tell you why. We may ask you to confirm your identity before releasing information. There is no fee unless a request is manifestly unfounded or excessive.
12. Children
Our website and services are aimed at businesses and are not directed at children. We do not knowingly collect data about anyone under 18. If you believe a child has given us personal data, tell us and we will delete it.
13. Changes to this policy
We review this policy at least once a year and whenever our processing changes. The version number and date at the top of the page show the current edition. Material changes are notified directly to clients whose engagements are affected.
14. Contact and complaints
Data protection contact:
hello@isodev.co.uk
Isodev Limited, Bartle House, 9 Oxford Court, Manchester, M2 3WQ
If you are unhappy with how we have handled your data, tell us first so we can put it right. You can also complain to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, by telephone on 0303 123 1113, or at ico.org.uk. Complaining to us does not affect your right to go to the ICO.