Skip to main content
VEXBE No. 17005285

Legal document

Privacy notice

VEXBE LTD Company number 17005285 Effective 7 August 2026 Version 1.0

Section 1

About this notice

This notice explains how VEXBE LTD collects, uses, shares and retains personal data. It meets the transparency requirements of Articles 13 and 14 of the UK General Data Protection Regulation, being Regulation (EU) 2016/679 as retained in United Kingdom law by section 3 of the European Union (Withdrawal) Act 2018, read with the Data Protection Act 2018. Article references below are to that instrument unless another statute is named.

It covers people who visit vexbe.co.uk, people who contact us about work, people at organisations that engage us, and people at our suppliers. Sections 8 and 9 deal separately with the narrower role we take when personal data belonging to a client passes through our hands during an engagement. Where a fact is not yet settled it is marked in the text rather than covered by a vague phrase, and where a section states a position for something we have not launched, its first sentence says so. Nothing here describes a system, supplier or practice that does not exist as at the effective date of 7 August 2026. This version replaces any earlier notice at this address.

Section 2

Who we are and how to contact us

VEXBE LTD is a private limited company registered in England and Wales under company number 17005285, with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. It was incorporated on 1 February 2026 and carries on business as an IT consultancy and systems integration practice under SIC codes 62012 and 62020. "We", "us" and "our" mean VEXBE LTD.

The contact route for every data protection matter is hello@vexbe.co.uk, with "Data protection request" in the subject line. It is the only contact route the company operates. Formal notice may also be served by post at the registered office, which is slower because post is forwarded.

We are not required to appoint a data protection officer under Article 37 and have not appointed one. We are not a public authority, our core activities do not involve regular and systematic monitoring of data subjects on a large scale, and we do not process special category or criminal offence data on a large scale. Responsibility sits with the company's officers, whose details are on the public Companies House record for company number 17005285. We are established in the United Kingdom and do not currently offer goods or services to individuals in the European Economic Area in a way that engages Article 3(2) of the EU GDPR, so no Article 27 representative has been appointed. If that changes, this section changes first.

Section 3

The two roles we act in

A controller decides why and how personal data is processed. A processor acts only on a controller's documented instructions. VEXBE LTD is both, at different times and over different data, so every section below is marked with the role it describes.

3.1 Role A, controller

We are the controller for data about website visitors, people who contact us, people at client organisations, and people at our suppliers. Sections 4, 5, 6, 7, 12, 13, 14, 15, 16, 17, 18, 19 and 22 describe this role, and rights under section 17 are exercised against us.

3.2 Role B, processor

During an engagement we may handle personal data belonging to a client, such as records inside a database we are migrating. The client is the controller and we are the processor, working under a written contract meeting Article 28(3). Section 8 describes this role.

3.3 Why it matters to you

The distinction decides who you go to. If you emailed us, we hold that as a controller and you can ask us directly. If you are a customer of a company that engaged us to move its records, we hold nothing about you of our own volition and cannot lawfully act without our client's instruction, so the route is to that company. We will not use this as a way of dodging a question: where we are a processor we say so, pass the request on promptly, and name the controller where permitted.

Section 4

Website visitors, data inventory

Role: controller

This website is a set of static files. No accounts, no login, no comments, no chat widget, no embedded video, no advertising or analytics tags. It is served through Cloudflare, Inc. The result is that a visit generates very little personal data, and what it does generate comes from the infrastructure rather than from anything we chose to add.

Inventory, website visitors, controller
Category Example fields Source Purpose Lawful basis Retention Recipients
Connection data IP address, timestamp, requested URL, HTTP status, bytes served, user agent, referrer Generated by the edge server when your browser requests a page Serving the page, keeping the site available, detecting abusive traffic Article 6(1)(f). Interest: keeping a public website online, secure and correctly served Held by the hosting provider on its own schedule, measured in days. Not exported by us Cloudflare, Inc.
Security signals Request rate per address, bot score, firewall rule matches Derived by the edge network from connection data Deciding whether a request is automated abuse Article 6(1)(f). Interest: protecting the site from attack and from cost inflicted by bots Minutes to days, by the provider Cloudflare, Inc.
Font requests IP address and user agent sent to fonts.googleapis.com and fonts.gstatic.com Sent by your browser, not by us, when it resolves the stylesheet link Rendering the two typefaces the site is set in Article 6(1)(f). Interest: a legible, consistent page. Low impact, and blocking those hostnames leaves the site fully usable in system fonts Not retained by us Google LLC, Google Fonts
Cookies None set by this site Not applicable Not applicable No consent required under regulation 6 of the Privacy and Electronic Communications Regulations 2003, because nothing non essential is stored or read Not applicable Not applicable

The cookie notice gives the full position, including the strictly necessary cookie our hosting provider may set during a security challenge.

Section 5

Enquirers and clients, data inventory

Role: controller

This is the largest category we hold as controller, and nearly all of it arrives because somebody chose to email us. There is no form on this site, so nothing is collected passively at the point of enquiry.

Inventory, enquirers and client contacts, controller
Category Example fields Source Purpose Lawful basis Retention Recipients
Enquiry correspondence Name, email address, employer, job title, any telephone number, and what you wrote You, by email Reading the enquiry, deciding whether it is work we can do, replying Article 6(1)(b) where you enquire on your own behalf. Article 6(1)(f) where you write for an organisation, the interest being replying to a business enquiry addressed to us 24 months from the last message Our email hosting provider
Engagement correspondence Name, business email, job title, telephone, meeting notes, decisions recorded in writing You or your colleagues during the engagement Carrying out the work and evidencing what was agreed and when Article 6(1)(b) for the counterparty. Article 6(1)(f) for their employees, the interest being delivery and a defensible record 6 years from the end of the engagement Email hosting provider; accounting provider where billing related
Contract and proposal records Signatory name and job title, signature, dates, scope, acceptance criteria, variations You, during contracting Forming and evidencing the contract, resolving disputes about scope Article 6(1)(b), and Article 6(1)(c) for records required under the Companies Act 2006 6 years from the end of the engagement, longer if a dispute is live Accounting provider; professional advisers if a dispute arises
Billing records Billing contact and address, purchase order reference, amounts, VAT treatment, payment dates You, and generated by us on invoicing Invoicing, collecting payment, keeping statutory accounting records Article 6(1)(c) under the Companies Act 2006 and the Value Added Tax Act 1994. Article 6(1)(b) for collecting the debt 6 years from the end of the relevant financial year Accounting provider, our bank, HM Revenue and Customs where required
Access records Usernames issued to us on your systems, and who authorised the access Your organisation, when access is granted Doing the work, and proving access was authorised and later removed Article 6(1)(f). Interest: evidencing that access we held was properly granted and properly revoked Credentials destroyed at the end of the engagement; the record that access existed kept 6 years No one outside the company
Complaints Name, contact details, what you complained about, what we found and did You Investigating and answering a complaint Article 6(1)(f). Interest: answering a complaint properly and evidencing that we did 6 years from closure Professional advisers if it escalates

We do not buy contact data, use contact enrichment services, or scrape professional networks to build a prospect list. Every record above exists because somebody wrote to us or because we did work for their employer.

Section 6

Suppliers and subcontractors, data inventory

Role: controller

Inventory, suppliers and subcontractors, controller
Category Example fields Source Purpose Lawful basis Retention Recipients
Supplier contacts Name, business email, job title, telephone The supplier, or its published website Running the supply relationship, support, renewal and cancellation Article 6(1)(f). Interest: administering the company's own supply chain Duration of the relationship plus 6 years Accounting provider, where the record is an invoice
Subcontractor records Name, company number if incorporated, contact details, contract, insurance evidence, bank details The subcontractor Engaging and paying them, disclosing them to the client as our terms require, evidencing our checks Article 6(1)(b) where they contract personally, Article 6(1)(c) for records required by law, otherwise Article 6(1)(f) for competent supplier management 6 years from the last engagement worked on The client whose engagement they work on, accounting provider, our bank
Unsolicited approaches Name, email address, whatever the sender included Sent to us unsolicited Reading the message and deciding whether to reply Article 6(1)(f). Interest: reading correspondence addressed to the company. That interest does not extend to keeping it, hence the short period Deleted within 6 months unless it becomes a genuine enquiry Email hosting provider
Section 7

Lawful bases and our legitimate interests

Role: controller

Article 6(1) requires a lawful basis for every processing operation. We use four and not the others.

7.1 Contract, Article 6(1)(b)

Necessary for a contract you are party to, or for steps taken at your request before one. This covers answering your own enquiry, delivering an engagement you contract for personally, and collecting payment.

7.2 Legal obligation, Article 6(1)(c)

Necessary to comply with a legal obligation on VEXBE LTD, principally the accounting and tax records we must keep, and any disclosure compelled by a court order or statutory power.

7.3 Legitimate interests, Article 6(1)(f)

Article 6(1)(f) requires the interest to be named and balanced against your rights, not gestured at. Ours are these, each assessed before being relied on.

  • Keeping a public website available and secure. Low impact. Transient connection metadata, not combined with anything else and not used to profile a visitor. Publishing a site with no abuse protection is not a realistic alternative.
  • Corresponding with people who write to us for an organisation. Low impact and expected: someone who emails a business to ask about a service anticipates a reply. Limited by a defined retention period rather than indefinite storage.
  • Delivering contracted work and keeping a defensible record. Confined to business contact details and work correspondence, and as much in the client's interest as ours.
  • Administering our own supply chain. Business contact data used only to run a relationship the individual's employer entered into.
  • Establishing, exercising or defending legal claims. Narrowed by retaining only what is relevant and using it for nothing else.

You may object to legitimate interests processing. Section 17.6 explains how, and the objection is absolute where the purpose is direct marketing.

7.4 Consent, Article 6(1)(a)

Relied on only where the law requires it and where we are actually asking. As at the effective date we run no marketing list, no newsletter and no non-essential cookies, so there is nothing you have consented to. If that changes, consent will be an unticked opt in, recorded with a date, and withdrawable by a single reply.

7.5 Bases we do not use

We do not rely on vital interests under Article 6(1)(d) or public task under Article 6(1)(e). We are not a public authority and nothing we do is done under official authority.

Section 8

Client personal data we process for a client

Role: processor

8.1 The contract that governs it

Before any client personal data is accessible to us, a written data processing agreement meeting Article 28(3) is in place. It records the subject matter, duration, nature and purpose of the processing, the types of data and categories of data subject, and commits us to process only on documented instructions, impose confidentiality on anyone we authorise, take Article 32 measures, obtain written authorisation before engaging a sub-processor, assist with data subject requests and Articles 32 to 36, delete or return the data at the end, and make available the information needed to demonstrate compliance.

8.2 How we limit exposure

We ask for the narrowest access that lets the work proceed, in writing. Where the work can be done against structurally realistic but non identifying data we ask for that instead of a production extract, and much of an integration build genuinely can be. Where production data is unavoidable it stays in the client's environment. We do not routinely copy client personal data onto our own machines, and any unavoidable temporary copy is recorded, time boxed and destroyed with written confirmation.

8.3 Instructions we will refuse

Article 28(3) requires a processor to tell the controller when an instruction infringes data protection law, and we do that in writing. It arises most often when a migration is scoped to carry across records the controller no longer has a basis to keep, or when a test environment is to be filled with live personal data with no assessment behind the decision. We raise it, put it in writing, and decline that specific instruction if it is not resolved.

8.4 If you are an individual in a client system

Send your request to the organisation that holds the data, because it is the controller. If it reaches us instead we will not act on it ourselves, because we are not permitted to. We will forward it to the controller without undue delay, tell you we have done so, and name them where they allow it. We will not delete, correct or export your data on our own authority, since doing so is itself a breach by a processor.

8.5 Sub-processors on an engagement

No sub-processor is engaged on client personal data without the client's prior written authorisation. A proposed subcontractor is named in writing before starting, bound by terms no less protective than ours, and we remain fully liable for their performance. The table in section 12 lists sub-processors used in our own controller capacity, which is a different list and is not a list of approved sub-processors for any engagement.

Section 9

Special category and criminal offence data

Role: controller and processor

As controller we do not seek or knowingly hold special category data under Article 9(1), being data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic data, biometric data used to identify a person, health data, or data concerning sex life or sexual orientation. Nor do we hold criminal offence data under Article 10 and section 10 of the Data Protection Act 2018. If such data reaches us unsolicited, for example a health matter mentioned in an email explaining a delay, we do not use it, do not copy it elsewhere, and delete it when the correspondence period expires.

As processor the position depends on the client's systems. Some estates hold health data and a migration in that sector will involve it. Where it does, the data processing agreement records it explicitly, the client identifies its own Article 9(2) condition and any Schedule 1 condition under the Data Protection Act 2018, and additional handling controls are agreed in writing before access is granted. We will not start work on an estate containing special category data under a general agreement that does not name it.

Section 10

Children

Role: controller

This website and this business are directed at organisations and the people who work in them, not at children. We do not knowingly collect data about anyone under 18 as controller, and we do not offer an information society service to a child within the meaning of section 9 of the Data Protection Act 2018. If you believe we hold data about a child, write to hello@vexbe.co.uk and we will investigate and delete it if that is the right outcome. Where a client engagement involves children's data the client is the controller and holds the assessment permitting it, including any consideration of the Age Appropriate Design Code, and we would expect the work to be scoped without production data wherever technically possible.

Section 11

What we never do with personal data

Role: controller

The most useful statements in a privacy notice are the negative ones, because they are falsifiable. Each of these is a commitment, not a description of circumstances that might quietly change.

  • We do not sell, licence or rent personal data, or make it available for a third party's own purposes.
  • We do not use personal data for advertising, and carry no advertising technology on this site.
  • We do not run behavioural analytics, session recording, heat mapping or device fingerprinting.
  • We do not profile visitors, enquirers or clients, and do not enrich records from data brokers.
  • We do not carry out automated decision making with legal or similarly significant effects under Article 22.
  • We do not use client personal data encountered during an engagement for our own purposes, including training any model, building a reusable dataset, or making demonstration or marketing material.
  • We do not send marketing email to enquirers, and we do not add anyone to a list.
Section 12

Recipients and sub-processors

Role: controller

These organisations process personal data on our behalf in our controller capacity, or receive it as independent recipients. Each is named, because naming is the only thing that makes the disclosure meaningful. A supplier not yet settled is marked rather than omitted, and no processing is happening through an unnamed supplier in the meantime.

Processors and recipients used by VEXBE LTD as controller, at 7 August 2026
Organisation Role What they process Why Location
Cloudflare, Inc. Processor Connection data from requests to vexbe.co.uk, including IP address and user agent Hosting on Cloudflare Pages, content delivery, DNS, protection against automated abuse Global edge network; United Kingdom requests normally served from a United Kingdom or European location. See section 13
Google LLC, Google Fonts Independent controller of its own service logs IP address and user agent, sent by your browser directly when it fetches the web fonts Delivery of the Azeret Mono and Schibsted Grotesk typefaces Global, under Google's own terms
[TO CONFIRM: business email hosting provider and its data processing terms] Processor The content of correspondence to and from hello@vexbe.co.uk, including sender details and attachments Operating the company's email To be recorded here before the provider is treated as settled
[TO CONFIRM: accounting and bookkeeping software provider] Processor Billing contact, billing address, invoice and payment records Statutory accounts, VAT returns, management of receivables To be recorded here before adoption
HM Revenue and Customs Independent controller Information in statutory returns Compliance with tax law United Kingdom
Companies House Independent controller Information in statutory filings Compliance with the Companies Act 2006 United Kingdom
Professional advisers, if instructed Independent controllers Whatever is relevant to the advice or dispute Legal or accountancy advice, conduct of a claim United Kingdom
Named subcontractors, if engaged Processor Only what the piece of work requires Delivery of a specific engagement, disclosed to the client beforehand Disclosed at the time

We may also disclose where required by law, a court order or a regulator acting within its powers, and where necessary to establish, exercise or defend a legal claim. If a business transfer ever affected the company, personal data could pass to the acquiring entity, which would be required to continue handling it in accordance with this notice, and materially affected individuals would be told.

Section 13

International transfers

Role: controller and processor

Chapter V restricts transfers of personal data outside the United Kingdom. A restricted transfer is lawful only under one of the routes in Articles 45 to 49.

13.1 Adequacy regulations

Under Article 45 and section 17A of the Data Protection Act 2018 the Secretary of State may find that a country provides an adequate level of protection, and transfers made under such regulations need no further safeguard. The European Economic Area is covered, as are several other jurisdictions. Transfers to a United States organisation certified under the UK Extension to the EU to US Data Privacy Framework are also covered, for as long as that certification is live and covers the data. Where a supplier is certified we rely on it and check the certification is current rather than assume it.

13.2 The International Data Transfer Agreement

Where adequacy is unavailable we use the International Data Transfer Agreement, the IDTA, issued by the Information Commissioner under section 119A of the Data Protection Act 2018 and laid before Parliament. It is a standalone United Kingdom transfer agreement and is our default for a direct arrangement with a supplier outside the United Kingdom.

13.3 The UK Addendum to the EU standard contractual clauses

Where a supplier already operates on the European Commission's standard contractual clauses, we use the Addendum issued by the Commissioner under the same power, which modifies those clauses so they work as a valid United Kingdom transfer tool. This is the more common route in practice, because a supplier with a global customer base usually offers the EU clauses plus the Addendum in its standard terms rather than negotiating a separate IDTA. Either is acceptable. A supplier offering neither, and asking us to rely on a general assurance, is not.

13.4 The transfer risk assessment

Neither instrument is enough on its own. Before relying on either we assess the destination country's laws on government access, the sensitivity of the data, the technical measures protecting it in transit and at rest, and any practical experience the recipient has of access requests. Where the assessment does not support the transfer we look for a supplier that keeps the data in the United Kingdom, which at our volume is usually achievable.

13.5 The transfers happening today

Cloudflare, Inc. is incorporated in the United States and runs a global network, so content delivery involves processing at the edge location nearest the visitor. The data is transient connection metadata, covered by our provider's data processing terms, which incorporate the standard contractual clauses together with the UK Addendum. The Google Fonts request in section 4 is made by your browser directly to Google rather than by us, although we name it because we caused it. Email and accounting suppliers are marked as to be confirmed in section 12, and the location of processing will be settled and recorded before either is adopted.

13.6 Client engagements

As processor we do not move client personal data out of the United Kingdom, or out of whatever jurisdiction the client's environment sits in, without the client's written instruction. Because we work inside client environments rather than copying data out, this arises rarely, and when it does the client makes the Chapter V decision as controller and we implement it.

Section 14

Retention

Role: controller

Article 5(1)(e) requires data to be kept in identifiable form no longer than necessary. A period with no reason behind it is not a policy, so every row carries its reason.

Retention schedule, VEXBE LTD as controller
Record Period Runs from Reason
Accounting records, invoices, receipts and supporting documents 6 years End of the financial year they relate to Section 388 of the Companies Act 2006 requires a private company to preserve accounting records for 6 years from the date they are made, and HM Revenue and Customs requires business records to be kept at least 6 years for VAT. A statutory floor, not a preference, and not shortened on request
Signed contracts, proposals, variations, acceptance records 6 years, or 12 where executed as a deed End of the engagement The limitation period on a simple contract is 6 years under section 5 of the Limitation Act 1980, and 12 years for a deed under section 8, so a claim can be brought or defended
Engagement correspondence and decision records 6 years End of the engagement Aligned to the contractual limitation period, because what was agreed often sits in correspondence rather than in the contract
Enquiry correspondence that led nowhere 24 months The last message Long enough to recognise a returning enquirer, short enough that a conversation that went nowhere does not sit in an inbox for years. Not tied to any statutory period
Unsolicited approaches 6 months at most Receipt No reason to keep something we did not ask for and did not act on, beyond recognising repeated unwanted contact
Complaint files 6 years Closure Aligned to the limitation period, since a complaint can become a claim
Record that access was granted and revoked 6 years End of the engagement Evidence that access was authorised and removed. Credentials themselves are destroyed at the end of the engagement and never kept for this period
Data subject request files 3 years Completion of the request To evidence that the request was handled properly and in time, and to answer any later complaint about the handling
Breach records under Article 33(5) 6 years Date of the record Article 33(5) requires documentation sufficient for the Commissioner to verify compliance. 6 years aligns it with our other governance records
Website server and security logs Days rather than months The request Held by the hosting provider on its own schedule and not exported by us. The operational purpose expires quickly
Client personal data held as processor As instructed by the client End of the engagement or task We are not the controller and cannot set the period. The data processing agreement provides for deletion or return at the client's election, and temporary working copies are destroyed at the end of the task

Where a period expires but the record is relevant to a live dispute, regulatory enquiry or legal hold, we keep it until that concludes and then delete it. Deletion means deletion from live systems, with backup copies expiring on the backup cycle rather than being individually extracted. We state that limitation rather than imply otherwise.

Section 15

Security

Role: controller and processor

Article 32 requires measures appropriate to the risk. These are the measures actually in place. They are modest, because the company is small and holds little, and overstating them would be the opposite of a security control.

  • The site is served over HTTPS only with HTTP Strict Transport Security, response headers restricting framing, content type sniffing and referrer leakage, and a content security policy limiting what the page may load.
  • The site is static: no database, no server side application code, no administrative interface exposed to the internet.
  • Company accounts use unique passwords in a password manager, with multi factor authentication wherever the provider supports it.
  • Company devices use full disk encryption and automatic screen locking and stay on supported operating system versions.
  • Access to client systems is requested at the narrowest scope that works, authorised in writing, and confirmed revoked at the end.
  • Client personal data is not routinely copied to our own devices; unavoidable temporary copies are recorded, time boxed and destroyed with written confirmation.
  • Anyone we authorise to process personal data, including any subcontractor, is under a written confidentiality obligation.

VEXBE LTD does not hold ISO 27001 certification, a SOC 2 Type 1 or Type 2 report, or Cyber Essentials or Cyber Essentials Plus certification. Those schemes are named here only so this denial is unambiguous. If your procurement requires a certified supplier we do not meet it, and we will say so at qualification rather than let it surface later. We will complete a security questionnaire honestly, and several answers will be negative. No set of measures makes a system immune, which is what section 16 is for.

Section 16

Personal data breaches

Role: controller and processor

A personal data breach is a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. It is wider than a hacking incident: an email to the wrong recipient, a lost laptop and an accidental deletion all qualify.

16.1 Detection and containment

Anyone who suspects a breach should write to hello@vexbe.co.uk with "Security" in the subject line. We would rather receive a report that turns out to be nothing. On becoming aware we contain the incident, establish what data and how many people are affected, and record the time of awareness, because the Article 33 clock runs from awareness rather than from the incident.

16.2 Notifying the Commissioner, Article 33

Where we are controller and the breach is likely to result in a risk to people's rights and freedoms, we notify the Information Commissioner without undue delay and, where feasible, within 72 hours of becoming aware. A later notification is accompanied by the reasons for the delay, as Article 33(1) requires. The notification describes the nature of the breach, the categories and approximate numbers of individuals and records, the likely consequences, and the measures taken or proposed. Where the full picture is not available inside 72 hours we notify on what we have and supply the rest in phases under Article 33(4), rather than delaying to finish the investigation.

16.3 Notifying individuals, Article 34

Where the breach is likely to result in a high risk to individuals we tell them without undue delay, in clear and plain language, with a contact point, the likely consequences, the measures taken or proposed, and any useful steps they can take. Article 34(3) permits us not to communicate where the data was rendered unintelligible, for example by strong encryption, where later measures have removed the high risk, or where individual communication would take disproportionate effort, in which case a public communication is made instead. We will not use the disproportionate effort route to dodge an inconvenient notification.

16.4 Where we are the processor

Article 33(2) requires a processor to notify the controller without undue delay. Our commitment to clients is tighter: notification to the client's named contact within 24 hours of becoming aware, with what we know at that point, followed by updates. Whether to notify the Commissioner and the affected individuals is the controller's decision, which we assist with rather than pre empt.

16.5 Record keeping

Article 33(5) requires every breach to be documented, including those that are not notifiable, recording the facts, effects and remedial action. We keep that record for 6 years as set out in section 14.

Section 17

Your rights under the UK GDPR

Role: controller

These rights apply to data for which we are controller. Section 8.4 covers the processor position. Each right below states what it lets you do, how to use it, and when it can lawfully be refused. Section 18 covers the process common to all of them.

17.1 The right to be informed, Articles 13 and 14

You are entitled to be told what we do with your personal data in a concise, transparent, intelligible and accessible form. This notice discharges that duty and there is nothing to request. If something here is unclear or wrong, tell us and we will explain or correct it, with the correction recorded in section 24.

17.2 The right of access, Article 15

You may ask whether we hold data about you and receive a copy with the supplementary information in Article 15(1): the purposes, categories of data, recipients, retention period or the criteria for it, your rights, the source where it did not come from you, and whether any automated decision making exists. Email us with "Data protection request" in the subject and say what you want. No particular wording or Article citation is needed, and there is no fee. We may refuse, or charge a reasonable fee, only where a request is manifestly unfounded or excessive under Article 12(5), and if we do we will explain why and how to challenge it. Where a copy would adversely affect the rights of others, including another person's data or a third party's confidential information, we redact rather than withhold the whole response and tell you that we have.

17.3 The right to rectification, Article 16

You may have inaccurate data corrected and incomplete data completed, including by a supplementary statement. Tell us what is wrong and what it should say. Where we can verify the correction we make it. Where accuracy is genuinely disputed, for example where a record reflects an opinion held at the time, we record your position alongside the entry rather than overwrite it, and we tell you that is what we did. Where data has been disclosed, Article 19 requires us to pass the rectification to each recipient unless that is impossible or disproportionate, and we will tell you who they are if you ask.

17.4 The right to erasure, Article 17

You may have data erased on an Article 17(1) ground: it is no longer necessary for the purpose, you withdraw the consent it relied on and there is no other basis, you object under Article 21(1) with no overriding ground, it was unlawfully processed, or erasure is legally required. The right is not absolute. Article 17(3) means we must refuse where processing is necessary to comply with a legal obligation, or for legal claims. This is why an invoice cannot be erased on request: section 388 of the Companies Act 2006 and tax law require it for 6 years, and that outranks the request. Where we refuse in part we say exactly which records are retained and under which ground, and erase everything else.

17.5 The right to restriction, Article 18

You may require us to store data but stop using it, in four situations: you contest its accuracy and we need time to verify, the processing is unlawful but you prefer restriction to erasure, we no longer need it but you need it for a legal claim, or you have objected under Article 21(1) and we are weighing the grounds. While restricted we do nothing with the data except with your consent, for a legal claim, to protect another person's rights, or for important public interest reasons. We tell you before a restriction is lifted.

17.6 The right to object, Article 21

Where processing rests on Article 6(1)(f) you may object on grounds relating to your particular situation, and we must stop unless we can demonstrate compelling legitimate grounds overriding your interests, or the processing is for legal claims. Since most of what we do as controller rests on Article 6(1)(f), this matters, and we treat an objection as a genuine reconsideration rather than a formality. Objection to direct marketing under Article 21(2) is absolute and immediate with no balancing test, although we send none.

17.7 The right to data portability, Article 20

Where processing is based on consent or contract and carried out by automated means, you may receive the data you provided in a structured, commonly used, machine readable format, and have it transmitted to another controller where technically feasible. In our case that is usually the correspondence you sent us, provided as plain text or a standard document format. The right does not extend to data we derived or inferred, nor to data processed under legitimate interests or legal obligation.

17.8 The right to withdraw consent, Article 7(3)

Where processing is based on consent you may withdraw it at any time, as easily as you gave it, without affecting the lawfulness of what happened before. As at the effective date we rely on consent for nothing, so there is nothing to withdraw. If we ever ask, the withdrawal route will be stated at the point of asking and will work by a single reply.

17.9 Rights on automated decision making, Article 22

You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects. We carry out no such processing: no decision about an enquiry, an engagement, a price or a person is taken by an automated system here. If that changed we would say so in this notice before it started and provide the Article 22(3) safeguards, including human intervention, the ability to express a point of view and the ability to contest.

17.10 The right to complain, Article 77

You may complain to the Information Commissioner at any time, without coming to us first, although we would prefer the chance to fix it. Section 19 has the full details.

Section 18

Exercising a right, and how we respond

Role: controller

18.1 How to make a request

Email hello@vexbe.co.uk with "Data protection request" in the subject. Say which right you are using, or simply describe what you want to happen, and give enough detail to find the data, such as the address you corresponded from and rough dates. A request may be made verbally or in writing, to any part of the organisation, and is valid whether or not it uses legal language; the subject line simply routes it faster. Someone may act on your behalf, in which case we ask for evidence of their authority.

18.2 Verifying who you are

Article 12(6) permits us to ask for more information where we have reasonable doubts about identity. We will not use this as an obstacle or demand documents we do not need. Usually a request sent from the address that appears in the correspondence we hold is enough on its own and we simply answer it. Where the request concerns data not linked to an address we hold, or where there is genuine doubt, we ask for the minimum evidence that resolves it and explain what it is for. Identity evidence is used only to verify the request and is deleted afterwards. The clock in 18.3 does not start until we have what we reasonably need.

18.3 Timing

We respond without undue delay and in any event within one month of receipt, as Article 12(3) requires. The month runs from receipt, or from verification of identity where that was necessary, and ends on the corresponding date of the following month. Where a request is complex, or where you have made several, the period may be extended by up to two further months, and we will tell you within the first month that it applies and why. We acknowledge receipt within five working days, which is our commitment rather than a legal obligation.

18.4 What a response looks like

In writing, by email to the address you wrote from unless you ask otherwise. It states what we found, what we have done, and where any part is refused, exactly which part and on which ground. Information is free. For further copies of the same data we may charge a reasonable administrative fee based on actual cost, as Article 15(3) allows.

18.5 Grounds on which we may refuse

Only on a ground the legislation provides: the request is manifestly unfounded or excessive under Article 12(5); an exemption in Schedule 2 to the Data Protection Act 2018 applies, such as legal professional privilege or the exemption for negotiations with the requester; compliance would adversely affect another person's rights under Article 15(4); or, for erasure, an Article 17(3) exception applies, most often the obligation to keep accounting records. Cost and inconvenience are not grounds. Where we refuse we say why, tell you that you may complain to the Commissioner, and tell you that you may seek a judicial remedy under Article 79.

18.6 If you are unhappy with our response

Reply and say so, and a fresh pair of eyes will review it. If that does not resolve it, the Commissioner's process is open and free, and you lose no right by trying us first.

Section 19

Complaints and the ICO

Role: controller

If you are concerned about how VEXBE LTD has handled your personal data, please raise it with us first at hello@vexbe.co.uk with "Complaint" in the subject. We acknowledge complaints within three working days and answer within twenty working days. You also have the right under Article 77 to complain to the supervisory authority, which for the United Kingdom is the Information Commissioner's Office, whether or not you contact us.

Information Commissioner's Office

Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
United Kingdom

Helpline: 0303 123 1113
Website: ico.org.uk/make-a-complaint

The Commissioner asks that you give the organisation a chance to respond first, but this is not a precondition and costs you nothing either way. You also have the right under Article 79 to an effective judicial remedy, and under Article 82 to compensation for material or non material damage resulting from an infringement.

Section 20

Mobile applications and device permissions

Role: controller, forward looking

This section states a position in advance. As at 7 August 2026 VEXBE LTD has published no mobile application on the Apple App Store, on Google Play or anywhere else, and none is in distribution under this company's name. Nothing here describes something you can download today. It is published now because our classification under SIC 62012 includes software development, because an application may follow, and because the honest time to commit to a permissions position is before there is a product whose commercial needs might bend it. These commitments apply to any application VEXBE LTD publishes under its own name; an application built for a client and published under the client's name is governed by that client's own notice.

20.1 The permissions position

No permission is requested at first launch as a matter of course. Each is requested at the moment the feature needing it is used, with a plain explanation shown before the operating system dialogue. Every permission is optional. Declining one will never stop the application opening and will never disable a feature that does not actually need it.

Device permissions position for any future VEXBE LTD application
Permission Purpose Required or optional If you decline Revoke on iOS Revoke on Android
Camera Only to scan a code or capture a document you chose to attach Optional Scan and capture are unavailable; you can attach an existing file and everything else works Settings, Privacy and Security, Camera, turn the app off Settings, Apps, the app, Permissions, Camera, Do not allow
Photo library Only to let you pick a file to attach Optional You cannot attach from the library. On iOS you may grant selected photos only, which we would prefer Settings, Privacy and Security, Photos, choose None or Limited Access Settings, Apps, the app, Permissions, Photos and videos, Do not allow
Notifications Only to alert you to something you asked to be alerted about, such as a job completing Optional No alerts. The same information is visible in the app when you open it Settings, Notifications, the app, Allow Notifications off Settings, Notifications, App settings, the app, off
Precise location Not requested. No feature needs your location and we do not intend to build one Not applicable Not applicable Not applicable Not applicable
Contacts Not requested. A technical tool has no reason to read your address book Not applicable Not applicable Not applicable Not applicable
Microphone Not requested Not applicable Not applicable Not applicable Not applicable
Biometric unlock Only to unlock the app locally if you turn it on. The biometric never leaves your device and is never seen by us Optional The app unlocks with your device passcode or an ordinary sign in Settings, Face ID and Passcode, Other Apps, the app off Settings, Security, Biometrics, remove the app authorisation
Tracking, App Tracking Transparency Not requested. See section 21 Not applicable Not applicable Not applicable Not applicable

Paths vary between operating system versions and Android manufacturers. Where the path above does not match your device, long press the app icon and choose App info on Android, or find the app near the bottom of the main Settings list on iOS.

Section 21

App Tracking Transparency and Data Safety

Role: controller, forward looking

21.1 App Tracking Transparency on iOS

Apple's framework requires permission before an app tracks a user across other companies' apps and websites, or accesses the device advertising identifier. Our position is that no application we publish will present the App Tracking Transparency prompt, because none will track you across other companies' apps or websites and none will touch the advertising identifier. There is no advertising software development kit, no attribution network and no cross app analytics in anything we would ship. An app that does not track does not need to ask, and asking anyway hoping for a yes would be a dark pattern.

21.2 Google Play Data Safety

Google Play requires a Data Safety declaration covering what an app collects and shares, whether it is encrypted in transit, and whether deletion can be requested. Any declaration we file will match this notice in substance even where the vocabulary differs. No data would be declared as shared with third parties for advertising or analytics, because none is. Collection would be limited to what the described feature requires. All data in transit would be declared encrypted, because it would be. The declaration would confirm that deletion can be requested by the route in section 22. If a future application ever needed to collect something not contemplated here, this notice would be updated first and the declaration updated to match, not the other way round.

21.3 Consistency

A store listing, a Data Safety declaration, an in app disclosure and this notice must describe the same processing the same way. If you find a difference, treat it as an error and tell us at hello@vexbe.co.uk. We will correct whichever is wrong and say which it was.

Section 22

Account closure and data deletion

Role: controller

This website has no accounts, so there is nothing to close. This section covers how to have the correspondence we hold deleted, and the deletion route that will apply to any future application that does have accounts.

22.1 Deleting correspondence we hold

Email hello@vexbe.co.uk with "Data protection request" in the subject and ask for erasure. That is an Article 17 request and section 17.4 explains the limits. We identify everything we hold about you, delete what we are free to delete, and tell you specifically what is retained and under which obligation, which in practice means invoices and the contract documents behind them.

22.2 The in app route for any future application

Any application we publish with user accounts will carry an in app deletion path reachable without contacting anyone, at Settings, then Account, then Delete account. It will be available on the same terms to a user who signed up through an app store as to one who did not, and it will not sit behind a support conversation designed to talk you out of it.

22.3 The email route

The email route is always available as an alternative and produces the same outcome. Neither is preferred and neither is slower.

22.4 What happens and how long it takes

On a verified deletion request the account is disabled immediately so it cannot be signed into. Deletion from live systems is completed within 30 days. Backups are not individually edited, because extracting a single record from an encrypted backup set is not reliably possible; backup copies age out on the normal cycle, which does not exceed 90 days, and no restored backup is used to reinstate deleted data. We confirm completion in writing.

22.5 What is retained afterwards

Three things survive, each for a stated reason. Invoices and the accounting records behind them, for 6 years under section 388 of the Companies Act 2006 and tax law. Contract documents and the correspondence recording what was agreed, for 6 years under the Limitation Act 1980 so a claim can be brought or defended. A minimal suppression record, being the email address alone, where you have asked not to be contacted, because honouring that instruction requires remembering it. Nothing else is kept, and none of it is used for any other purpose.

Section 23

Cookies and similar technologies

Role: controller

This site sets no cookies of its own, uses no local or session storage, and carries no analytics, advertising or social media tags. Because nothing non essential is stored on or read from your device, regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 does not require a consent banner, and you will not see one. The full position, including the strictly necessary cookie our hosting provider may set during a security challenge, is in the cookie notice.

Section 24

Changes to this notice

Role: controller

This notice will change as the company does, most obviously when the suppliers marked as to be confirmed in section 12 are settled. The effective date and version number at the top change with it and a short note is added below. Where a change is material, meaning a new category of data, purpose, lawful basis or recipient, it is made before the new processing starts rather than after, and affected clients are told by email rather than left to re read a web page.

Version history

  • Version 1.0, effective 7 August 2026. First publication.

The current version is always the one at vexbe.co.uk/privacy.html. If you were sent a copy as a document, check it against this address before relying on it.

Back to contents