Skip to content
NorvyxSolutions
Services Approach Pricing How it works FAQ
+44 7482 913064 Get in touch

Privacy Policy

How Norvyx Solutions Ltd handles personal data under the UK GDPR and the Data Protection Act 2018.

Last updated: 16 September 2026

Contents

  1. Who we are
  2. Data we collect
  3. Data in client systems
  4. Purposes and legal bases
  5. Sharing with third parties
  6. International transfers
  7. Retention
  8. Security
  9. Cookies
  10. Your rights
  11. Complaints
  12. Age limit
  13. Changes to this policy
  14. Contact

1. Who we are

Norvyx Solutions Ltd (trading as Norvyx Solutions) is an IT consultancy registered in England and Wales, company number 17131613, with its registered office at 61 Bridge Street, Kington, United Kingdom, HR5 3DJ.

For the personal data described in section 2 we act as the data controller. For personal data we encounter inside client systems during an engagement we normally act as a processor — see section 3.

Questions about this policy or about how we handle data: [email protected] or +44 7482 913064. We have not appointed a Data Protection Officer, as we are not required to.

2. Data we collect as a controller

Enquiry and contact data

When you email or call us we receive your name, email address, telephone number, job title, company name and website, and whatever you choose to tell us about your situation.

Engagement data

During a project we hold the contact details of the people we work with on your side, meeting notes, interview records, correspondence, contracts, invoices and payment records.

Technical information about your estate

An audit produces information about your infrastructure: hardware and software inventories, network layout, licence positions, supplier contracts, configuration details and identified weaknesses. This is commercially sensitive information about your organisation and is treated as confidential; where it names individuals it is personal data as well.

Website data

This site has no contact form, no analytics and no tracking scripts. Our hosting provider keeps standard server logs, which may include IP addresses, for security and availability purposes.

We do not ask for and do not want special category data (such as health, biometric or trade union data) or criminal offence data. Please do not send it to us.

3. Personal data inside client systems

To carry out an audit we may be given access to your systems — file shares, mail systems, business applications, directories — which contain personal data about your staff, customers and suppliers. In that part of the work you remain the controller and we act as your processor.

That processing is governed by a written agreement meeting the requirements of Article 28 UK GDPR, under which we:

  • process personal data only on your documented instructions;
  • keep the data confidential and limit access to the people who need it for the engagement;
  • engage sub-processors only with your authorisation and under equivalent obligations;
  • return or delete the material at the end of the engagement, at your choice;
  • assist you with requests from data subjects and with your own compliance duties;
  • notify you without undue delay if we become aware of a personal data breach affecting your data.

We use read-only access where it is technically possible, take the minimum extract needed, and pseudonymise or aggregate data in reports and internal working materials wherever the finding does not depend on identifying individuals. Information about weaknesses in your systems is never used for any purpose other than delivering your engagement.

4. Purposes and legal bases

  • Responding to enquiries and preparing proposals — legitimate interests (responding to a business approach) or steps taken at your request prior to entering a contract.
  • Delivering consulting services — performance of a contract with you, or our legitimate interest in performing a contract with the organisation you represent.
  • Invoicing, accounting and tax records — legal obligation under UK company and tax law.
  • Managing our own security, records and insurance, and establishing or defending legal claims — legitimate interests in running the business responsibly.
  • Sending occasional updates about our services to existing business contacts — legitimate interests, or consent where the law requires it. You can opt out at any time by replying to any message or emailing us.

Where we rely on legitimate interests, we have considered the impact on you and use only what is necessary. You can ask us for details of that assessment.

5. Sharing with third parties

We do not sell personal data and do not share it for advertising. We disclose it only to:

  • IT service providers who support our own operations — email and file storage, project and note-taking tools, website hosting, backup services;
  • our accountants, auditors, insurers and legal advisers, where relevant;
  • payment and banking providers, for invoicing and settlement;
  • specialist contractors we bring in for part of an engagement, and only with your prior agreement;
  • public authorities, courts or regulators where we are legally obliged to disclose.

Suppliers act on our instructions under written contracts and may not use the data for their own purposes. We receive no commission, referral fee or other payment from software or hardware vendors, and any relationship that could be perceived as a conflict is disclosed to you in writing.

6. International transfers

Our data is normally held in the United Kingdom or the European Economic Area. Some of our IT suppliers may process data outside the UK. Where that happens we rely on UK adequacy regulations, or on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with any additional safeguards the transfer requires. Client system data is not transferred outside the UK or EEA without your instruction.

7. How long we keep data

  • Enquiries that do not lead to work: up to 12 months.
  • Project files, reports and correspondence: 6 years from the end of the engagement, in line with the limitation period for contractual claims.
  • Invoices and accounting records: 6 years after the end of the relevant accounting period, as required by tax law.
  • Detailed technical material about your estate, including vulnerability findings: deleted within 3 months of the engagement ending, unless you ask us to retain it for follow-on work. Only the finished report is kept with the project file.
  • Material processed on your behalf under section 3: returned or deleted at the end of the engagement as agreed.

When a retention period ends we delete the data or anonymise it irreversibly.

8. Security

We use encrypted laptops and storage, encrypted transfer for anything we receive from clients, multi-factor authentication on our accounts, least-privilege access, separate storage areas per client, and regular backups. Sensitive technical findings are kept in restricted storage and shared only with the people you name. Staff and contractors are bound by written confidentiality obligations. No system is perfectly secure, but we review these measures regularly and act on what we find.

9. Cookies

This website sets no cookies of its own and uses no analytics, advertising or tracking technologies, so no consent banner is needed. Web fonts are loaded from Google Fonts, which means your browser requests the font files from Google's servers and Google receives your IP address as part of that request. If you prefer to avoid this, your browser can be configured to block third-party requests; the site remains readable with a system font.

10. Your rights

Under the UK GDPR you have the right to:

  • access the personal data we hold about you and receive a copy;
  • have inaccurate data corrected;
  • have data erased where there is no continuing reason for us to hold it;
  • restrict processing while an issue is being resolved;
  • receive data you gave us in a portable, machine-readable format;
  • object to processing based on our legitimate interests, and to direct marketing at any time;
  • withdraw consent, where we rely on consent, without affecting processing already carried out.

Email [email protected] to exercise any of these rights. We respond within one month and may ask for information to confirm your identity. There is no charge unless a request is manifestly unfounded or excessive. If your request concerns data we hold as a processor for one of our clients, we will pass it to that client and support their response.

11. Complaints

If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF — ico.org.uk, telephone 0303 123 1113.

12. Age limit

Our services are provided to businesses. This website is not directed at children and we do not knowingly collect data about anyone under 18. If you believe we hold such data, contact us and we will delete it.

13. Changes to this policy

We update this policy when our practices or the law change. The current version is always published here with the date it was last updated. Where a change materially affects clients with an ongoing engagement, we tell them directly.

14. Contact

Norvyx Solutions Ltd
61 Bridge Street, Kington, United Kingdom, HR5 3DJ
Company number 17131613

[email protected]
+44 7482 913064

NorvyxSolutions

Independent IT consulting for UK small and medium businesses. Audits, solution selection and implementation planning — without selling you the software.

Email the team

Services

Infrastructure audit Solution selection Migration plan Cyber Essentials readiness

Company

Approach How it works Pricing FAQ

Contact

[email protected] +44 7482 913064

61 Bridge Street, Kington,
United Kingdom, HR5 3DJ

Legal

Privacy policy

Company number 17131613

Registered in England and Wales

© 2026 Norvyx Solutions Ltd. All rights reserved.

norvyxsolutions.co.uk