Privacy Policy
1. Who we are
Norvyx Solutions Ltd (trading as Norvyx Solutions) is an IT consultancy registered in England and Wales, company number 17131613, with its registered office at 61 Bridge Street, Kington, United Kingdom, HR5 3DJ.
For the personal data described in section 2 we act as the data controller. For personal data we encounter inside client systems during an engagement we normally act as a processor — see section 3.
Questions about this policy or about how we handle data: [email protected] or +44 7482 913064. We have not appointed a Data Protection Officer, as we are not required to.
2. Data we collect as a controller
Enquiry and contact data
When you email or call us we receive your name, email address, telephone number, job title, company name and website, and whatever you choose to tell us about your situation.
Engagement data
During a project we hold the contact details of the people we work with on your side, meeting notes, interview records, correspondence, contracts, invoices and payment records.
Technical information about your estate
An audit produces information about your infrastructure: hardware and software inventories, network layout, licence positions, supplier contracts, configuration details and identified weaknesses. This is commercially sensitive information about your organisation and is treated as confidential; where it names individuals it is personal data as well.
Website data
This site has no contact form, no analytics and no tracking scripts. Our hosting provider keeps standard server logs, which may include IP addresses, for security and availability purposes.
We do not ask for and do not want special category data (such as health, biometric or trade union data) or criminal offence data. Please do not send it to us.
3. Personal data inside client systems
To carry out an audit we may be given access to your systems — file shares, mail systems, business applications, directories — which contain personal data about your staff, customers and suppliers. In that part of the work you remain the controller and we act as your processor.
That processing is governed by a written agreement meeting the requirements of Article 28 UK GDPR, under which we:
- process personal data only on your documented instructions;
- keep the data confidential and limit access to the people who need it for the engagement;
- engage sub-processors only with your authorisation and under equivalent obligations;
- return or delete the material at the end of the engagement, at your choice;
- assist you with requests from data subjects and with your own compliance duties;
- notify you without undue delay if we become aware of a personal data breach affecting your data.
We use read-only access where it is technically possible, take the minimum extract needed, and pseudonymise or aggregate data in reports and internal working materials wherever the finding does not depend on identifying individuals. Information about weaknesses in your systems is never used for any purpose other than delivering your engagement.
4. Purposes and legal bases
- Responding to enquiries and preparing proposals — legitimate interests (responding to a business approach) or steps taken at your request prior to entering a contract.
- Delivering consulting services — performance of a contract with you, or our legitimate interest in performing a contract with the organisation you represent.
- Invoicing, accounting and tax records — legal obligation under UK company and tax law.
- Managing our own security, records and insurance, and establishing or defending legal claims — legitimate interests in running the business responsibly.
- Sending occasional updates about our services to existing business contacts — legitimate interests, or consent where the law requires it. You can opt out at any time by replying to any message or emailing us.
Where we rely on legitimate interests, we have considered the impact on you and use only what is necessary. You can ask us for details of that assessment.
6. International transfers
Our data is normally held in the United Kingdom or the European Economic Area. Some of our IT suppliers may process data outside the UK. Where that happens we rely on UK adequacy regulations, or on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with any additional safeguards the transfer requires. Client system data is not transferred outside the UK or EEA without your instruction.
7. How long we keep data
- Enquiries that do not lead to work: up to 12 months.
- Project files, reports and correspondence: 6 years from the end of the engagement, in line with the limitation period for contractual claims.
- Invoices and accounting records: 6 years after the end of the relevant accounting period, as required by tax law.
- Detailed technical material about your estate, including vulnerability findings: deleted within 3 months of the engagement ending, unless you ask us to retain it for follow-on work. Only the finished report is kept with the project file.
- Material processed on your behalf under section 3: returned or deleted at the end of the engagement as agreed.
When a retention period ends we delete the data or anonymise it irreversibly.
8. Security
We use encrypted laptops and storage, encrypted transfer for anything we receive from clients, multi-factor authentication on our accounts, least-privilege access, separate storage areas per client, and regular backups. Sensitive technical findings are kept in restricted storage and shared only with the people you name. Staff and contractors are bound by written confidentiality obligations. No system is perfectly secure, but we review these measures regularly and act on what we find.
10. Your rights
Under the UK GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- have inaccurate data corrected;
- have data erased where there is no continuing reason for us to hold it;
- restrict processing while an issue is being resolved;
- receive data you gave us in a portable, machine-readable format;
- object to processing based on our legitimate interests, and to direct marketing at any time;
- withdraw consent, where we rely on consent, without affecting processing already carried out.
Email [email protected] to exercise any of these rights. We respond within one month and may ask for information to confirm your identity. There is no charge unless a request is manifestly unfounded or excessive. If your request concerns data we hold as a processor for one of our clients, we will pass it to that client and support their response.
11. Complaints
If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF — ico.org.uk, telephone 0303 123 1113.
12. Age limit
Our services are provided to businesses. This website is not directed at children and we do not knowingly collect data about anyone under 18. If you believe we hold such data, contact us and we will delete it.
13. Changes to this policy
We update this policy when our practices or the law change. The current version is always published here with the date it was last updated. Where a change materially affects clients with an ongoing engagement, we tell them directly.
14. Contact
Norvyx Solutions Ltd
61 Bridge Street, Kington, United Kingdom, HR5 3DJ
Company number 17131613