Home/Privacy policy
Privacy policy
How Vytal Technology Ltd handles personal data, written to be read rather than skipped.
Last updated: 11 August 2026
Contents
- Who we are
- What this policy covers
- Personal data we collect
- Why we use it, and our lawful bases
- When we act for a client
- Research participants
- Who we share data with
- International transfers
- How long we keep data
- Security
- Your rights
- Cookies and this website
- Children
- Changes to this policy
- Contact and complaints
1. Who we are
This website is operated by Vytal Technology Ltd (“Vytal Technology”, “we”, “us”, “our”), a private company limited by shares registered in England and Wales under company number 17046663, with its registered office at 3rd Floor, 86-90 Paul Street, London, England, United Kingdom, EC2A 4NE.
For the personal data described in this policy, Vytal Technology Ltd is the data controller unless section 5 says otherwise. You can reach us about any privacy matter at info@vytaltech.org.
We are not required to appoint a statutory Data Protection Officer. Responsibility for data protection sits with the company's director.
2. What this policy covers
This policy applies to personal data we handle as a controller: visitors to vytaltech.org, people who contact us, client and supplier contacts, research participants we recruit directly, and job applicants. It does not describe how our clients use their own systems. Where we process personal data inside a client's system on their instructions, section 5 applies and the client's own privacy notice governs that processing.
3. Personal data we collect
Information you give us
- Contact and enquiry data — your name, email address, telephone number, employer, job title and anything else you choose to put in an email to us.
- Client relationship data — the contact details of the people we work with at a client organisation, correspondence, meeting notes and project records.
- Billing data — billing contact, billing address, purchase order references and payment records. We do not store card details; payments are made by bank transfer.
- Research data — where you take part in an interview, usability session or survey, the responses you give and any notes or recordings made with your consent.
- Recruitment data — if you apply to work with us, your CV, covering message, work history and right-to-work information where required.
Information collected automatically
- Server log data — our hosting provider records the IP address, request time, page requested, referring page, user-agent string and response status for requests to this website. These logs exist to keep the service running and secure.
- Technical data — approximate location derived from IP address, device type and browser, as reflected in those logs.
This website does not run advertising trackers, third-party analytics or social media pixels. See our cookie policy for detail.
Information from other sources
- Publicly available business information, such as company registers and professional networking profiles, used to verify a corporate contact.
- Referrals, where an existing contact passes on your details. If that happens, we will tell you who referred you the first time we get in touch.
4. Why we use it, and our lawful bases
| Purpose | Data used | Lawful basis (UK GDPR Art. 6) |
|---|---|---|
| Answering enquiries and preparing quotations | Contact and enquiry data | Legitimate interests — responding to someone who contacted us; or steps prior to entering a contract |
| Delivering contracted services | Client relationship data | Performance of a contract, or legitimate interests where the contract is with your employer |
| Invoicing and collecting payment | Billing data | Performance of a contract; legal obligation for tax records |
| Running research studies | Research data | Consent, which you may withdraw at any time |
| Keeping the website available and secure | Server log data | Legitimate interests — network and information security |
| Meeting statutory accounting and company law duties | Billing and correspondence records | Legal obligation |
| Establishing, exercising or defending legal claims | Any relevant records | Legitimate interests — protecting the company's legal position |
| Considering job applications | Recruitment data | Steps prior to entering a contract; legitimate interests |
| Occasional service updates to existing clients | Contact data | Legitimate interests — keeping clients informed; you can opt out at any time |
Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights and concluded they are not. You can ask us for the balancing assessment behind any of these, and you can object — see section 11.
We do not carry out automated decision-making that produces legal or similarly significant effects, and we do not sell personal data.
5. When we act for a client
When we build, host, maintain or research on behalf of a client, we usually handle personal data that the client controls — for example the records in a system we are developing. In that situation the client is the controller and Vytal Technology Ltd is a processor. We act only on the client's documented instructions under a written agreement covering:
- the subject matter, duration, nature and purpose of the processing;
- the categories of data subject and personal data involved;
- confidentiality obligations on everyone we allow to access the data;
- the security measures we will apply;
- the sub-processors we may use and how the client is told about changes;
- assistance with data subject requests, breach notification and impact assessments;
- deletion or return of the data at the end of the engagement.
If you are a customer or employee of one of our clients and want to exercise your rights over that data, please contact the client. If you contact us instead, we will pass the request on promptly and tell you we have done so.
6. Research participants
Market and user research is one of our registered activities. If you take part in a study we run, before it starts we will tell you who the research is for, what will be asked, whether the session is recorded, how long the material will be kept and who will see it. Taking part is voluntary and consent can be withdrawn at any point, including after the session, in which case we delete your contribution unless it has already been irreversibly aggregated.
Findings shared with a client are anonymised or pseudonymised by default. We only attribute a quote to a named individual where that person has separately agreed to it.
7. Who we share data with
We do not sell or rent personal data. We share it only in these circumstances:
- Service providers acting on our instructions — hosting and infrastructure, email, file storage, accounting and, where relevant, survey platforms. Each is bound by a written contract and may use the data only to provide the service.
- Professional advisers — accountants, auditors, insurers and lawyers, where they need it and are subject to professional confidentiality.
- Clients — research findings and project deliverables, anonymised as described above.
- Authorities — where we are required to disclose by law, court order or a regulator.
- A successor — if the business or part of it is reorganised or transferred, subject to the same protections and with notice to those affected.
8. International transfers
We prefer to keep data in the United Kingdom or the European Economic Area. Some of our service providers operate outside those areas. Where personal data is transferred to a country without UK adequacy regulations, we put an appropriate safeguard in place — normally the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum — together with a transfer risk assessment. You can ask us which providers are involved and see a copy of the relevant safeguard.
9. How long we keep data
| Record | Retention period |
|---|---|
| Enquiries that do not become projects | 12 months from the last contact |
| Client project records and correspondence | 6 years after the engagement ends |
| Accounting and tax records | 6 years after the end of the relevant financial year |
| Research recordings and transcripts | As stated in the study consent, normally 12 months |
| Server logs | Up to 90 days |
| Unsuccessful job applications | 6 months, unless you ask us to keep them longer |
| Records of consent and objections | For as long as needed to honour them |
At the end of a retention period we delete the data or irreversibly anonymise it. Backups are overwritten on a rolling cycle, so a deleted record may persist in a backup for a short further period before it is removed.
10. Security
We apply technical and organisational measures proportionate to the risk, including:
- encryption in transit (HTTPS/TLS) for this website and our working systems;
- access on a least-privilege basis, with multi-factor authentication on business accounts;
- managed devices with disk encryption and automatic updates;
- separation of client environments, and no use of live personal data in test systems without agreement;
- dependency and vulnerability monitoring on the systems we maintain;
- backups with periodic restore testing;
- confidentiality obligations for everyone who works on client engagements.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of becoming aware and, where the risk is high, tell you directly without undue delay.
11. Your rights
Under the UK GDPR you have the right to:
- be informed about how we use your data — this policy;
- access a copy of the personal data we hold about you;
- rectification of inaccurate or incomplete data;
- erasure of your data where there is no overriding reason to keep it;
- restrict processing in certain circumstances;
- data portability for data you gave us, where processing is by consent or contract and carried out by automated means;
- object to processing based on legitimate interests, and to direct marketing at any time;
- withdraw consent where consent is the basis, without affecting what was done before;
- not be subject to solely automated decisions with legal or similarly significant effects.
To exercise any of these, email info@vytaltech.org with “Data protection request” in the subject line. We will acknowledge within five working days and respond within one month; if the request is complex we may extend by up to two further months and will explain why. There is no charge unless a request is manifestly unfounded or excessive. We may ask for information to verify your identity.
12. Cookies and this website
This website is a set of static pages. It sets no cookies of its own, runs no advertising or analytics trackers, and does not attempt to identify individual visitors. Fonts are requested from Google Fonts, which means your browser makes a request to a Google server and that server will see your IP address. Full detail, including how to avoid that request, is in our cookie policy.
13. Children
Our services are aimed at organisations, and this website is not directed at children. We do not knowingly collect personal data from anyone under 13. If you believe a child has given us personal data, contact us and we will delete it. Where a client engagement involves data about children, additional safeguards are agreed in writing before any processing begins.
14. Changes to this policy
We may update this policy to reflect changes in our services, providers or the law. The version in force is the one published here, dated at the top of the page. Where a change materially affects how we use data we already hold, we will tell affected people directly where we have a means of doing so.
15. Contact and complaints
Privacy questions and requests: info@vytaltech.org, or by post to Vytal Technology Ltd, 3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE.
If you are unhappy with how we have handled your personal data you can complain to the Information Commissioner's Office, the UK supervisory authority: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF · 0303 123 1113 · ico.org.uk. We would appreciate the chance to put things right first.