Home/Privacy policy

Privacy policy

How Vytal Technology Ltd handles personal data, written to be read rather than skipped.

Last updated: 11 August 2026

1. Who we are

This website is operated by Vytal Technology Ltd (“Vytal Technology”, “we”, “us”, “our”), a private company limited by shares registered in England and Wales under company number 17046663, with its registered office at 3rd Floor, 86-90 Paul Street, London, England, United Kingdom, EC2A 4NE.

For the personal data described in this policy, Vytal Technology Ltd is the data controller unless section 5 says otherwise. You can reach us about any privacy matter at info@vytaltech.org.

We are not required to appoint a statutory Data Protection Officer. Responsibility for data protection sits with the company's director.

2. What this policy covers

This policy applies to personal data we handle as a controller: visitors to vytaltech.org, people who contact us, client and supplier contacts, research participants we recruit directly, and job applicants. It does not describe how our clients use their own systems. Where we process personal data inside a client's system on their instructions, section 5 applies and the client's own privacy notice governs that processing.

3. Personal data we collect

Information you give us

  • Contact and enquiry data — your name, email address, telephone number, employer, job title and anything else you choose to put in an email to us.
  • Client relationship data — the contact details of the people we work with at a client organisation, correspondence, meeting notes and project records.
  • Billing data — billing contact, billing address, purchase order references and payment records. We do not store card details; payments are made by bank transfer.
  • Research data — where you take part in an interview, usability session or survey, the responses you give and any notes or recordings made with your consent.
  • Recruitment data — if you apply to work with us, your CV, covering message, work history and right-to-work information where required.

Information collected automatically

  • Server log data — our hosting provider records the IP address, request time, page requested, referring page, user-agent string and response status for requests to this website. These logs exist to keep the service running and secure.
  • Technical data — approximate location derived from IP address, device type and browser, as reflected in those logs.

This website does not run advertising trackers, third-party analytics or social media pixels. See our cookie policy for detail.

Information from other sources

  • Publicly available business information, such as company registers and professional networking profiles, used to verify a corporate contact.
  • Referrals, where an existing contact passes on your details. If that happens, we will tell you who referred you the first time we get in touch.

4. Why we use it, and our lawful bases

PurposeData usedLawful basis (UK GDPR Art. 6)
Answering enquiries and preparing quotationsContact and enquiry dataLegitimate interests — responding to someone who contacted us; or steps prior to entering a contract
Delivering contracted servicesClient relationship dataPerformance of a contract, or legitimate interests where the contract is with your employer
Invoicing and collecting paymentBilling dataPerformance of a contract; legal obligation for tax records
Running research studiesResearch dataConsent, which you may withdraw at any time
Keeping the website available and secureServer log dataLegitimate interests — network and information security
Meeting statutory accounting and company law dutiesBilling and correspondence recordsLegal obligation
Establishing, exercising or defending legal claimsAny relevant recordsLegitimate interests — protecting the company's legal position
Considering job applicationsRecruitment dataSteps prior to entering a contract; legitimate interests
Occasional service updates to existing clientsContact dataLegitimate interests — keeping clients informed; you can opt out at any time

Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights and concluded they are not. You can ask us for the balancing assessment behind any of these, and you can object — see section 11.

We do not carry out automated decision-making that produces legal or similarly significant effects, and we do not sell personal data.

5. When we act for a client

When we build, host, maintain or research on behalf of a client, we usually handle personal data that the client controls — for example the records in a system we are developing. In that situation the client is the controller and Vytal Technology Ltd is a processor. We act only on the client's documented instructions under a written agreement covering:

  • the subject matter, duration, nature and purpose of the processing;
  • the categories of data subject and personal data involved;
  • confidentiality obligations on everyone we allow to access the data;
  • the security measures we will apply;
  • the sub-processors we may use and how the client is told about changes;
  • assistance with data subject requests, breach notification and impact assessments;
  • deletion or return of the data at the end of the engagement.

If you are a customer or employee of one of our clients and want to exercise your rights over that data, please contact the client. If you contact us instead, we will pass the request on promptly and tell you we have done so.

6. Research participants

Market and user research is one of our registered activities. If you take part in a study we run, before it starts we will tell you who the research is for, what will be asked, whether the session is recorded, how long the material will be kept and who will see it. Taking part is voluntary and consent can be withdrawn at any point, including after the session, in which case we delete your contribution unless it has already been irreversibly aggregated.

Findings shared with a client are anonymised or pseudonymised by default. We only attribute a quote to a named individual where that person has separately agreed to it.

7. Who we share data with

We do not sell or rent personal data. We share it only in these circumstances:

  • Service providers acting on our instructions — hosting and infrastructure, email, file storage, accounting and, where relevant, survey platforms. Each is bound by a written contract and may use the data only to provide the service.
  • Professional advisers — accountants, auditors, insurers and lawyers, where they need it and are subject to professional confidentiality.
  • Clients — research findings and project deliverables, anonymised as described above.
  • Authorities — where we are required to disclose by law, court order or a regulator.
  • A successor — if the business or part of it is reorganised or transferred, subject to the same protections and with notice to those affected.

8. International transfers

We prefer to keep data in the United Kingdom or the European Economic Area. Some of our service providers operate outside those areas. Where personal data is transferred to a country without UK adequacy regulations, we put an appropriate safeguard in place — normally the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum — together with a transfer risk assessment. You can ask us which providers are involved and see a copy of the relevant safeguard.

9. How long we keep data

RecordRetention period
Enquiries that do not become projects12 months from the last contact
Client project records and correspondence6 years after the engagement ends
Accounting and tax records6 years after the end of the relevant financial year
Research recordings and transcriptsAs stated in the study consent, normally 12 months
Server logsUp to 90 days
Unsuccessful job applications6 months, unless you ask us to keep them longer
Records of consent and objectionsFor as long as needed to honour them

At the end of a retention period we delete the data or irreversibly anonymise it. Backups are overwritten on a rolling cycle, so a deleted record may persist in a backup for a short further period before it is removed.

10. Security

We apply technical and organisational measures proportionate to the risk, including:

  • encryption in transit (HTTPS/TLS) for this website and our working systems;
  • access on a least-privilege basis, with multi-factor authentication on business accounts;
  • managed devices with disk encryption and automatic updates;
  • separation of client environments, and no use of live personal data in test systems without agreement;
  • dependency and vulnerability monitoring on the systems we maintain;
  • backups with periodic restore testing;
  • confidentiality obligations for everyone who works on client engagements.

No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of becoming aware and, where the risk is high, tell you directly without undue delay.

11. Your rights

Under the UK GDPR you have the right to:

  • be informed about how we use your data — this policy;
  • access a copy of the personal data we hold about you;
  • rectification of inaccurate or incomplete data;
  • erasure of your data where there is no overriding reason to keep it;
  • restrict processing in certain circumstances;
  • data portability for data you gave us, where processing is by consent or contract and carried out by automated means;
  • object to processing based on legitimate interests, and to direct marketing at any time;
  • withdraw consent where consent is the basis, without affecting what was done before;
  • not be subject to solely automated decisions with legal or similarly significant effects.

To exercise any of these, email info@vytaltech.org with “Data protection request” in the subject line. We will acknowledge within five working days and respond within one month; if the request is complex we may extend by up to two further months and will explain why. There is no charge unless a request is manifestly unfounded or excessive. We may ask for information to verify your identity.

12. Cookies and this website

This website is a set of static pages. It sets no cookies of its own, runs no advertising or analytics trackers, and does not attempt to identify individual visitors. Fonts are requested from Google Fonts, which means your browser makes a request to a Google server and that server will see your IP address. Full detail, including how to avoid that request, is in our cookie policy.

13. Children

Our services are aimed at organisations, and this website is not directed at children. We do not knowingly collect personal data from anyone under 13. If you believe a child has given us personal data, contact us and we will delete it. Where a client engagement involves data about children, additional safeguards are agreed in writing before any processing begins.

14. Changes to this policy

We may update this policy to reflect changes in our services, providers or the law. The version in force is the one published here, dated at the top of the page. Where a change materially affects how we use data we already hold, we will tell affected people directly where we have a means of doing so.

15. Contact and complaints

Privacy questions and requests: info@vytaltech.org, or by post to Vytal Technology Ltd, 3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE.

If you are unhappy with how we have handled your personal data you can complain to the Information Commissioner's Office, the UK supervisory authority: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF · 0303 123 1113 · ico.org.uk. We would appreciate the chance to put things right first.