This policy explains what personal data Voxalone Limited collects, why we collect it, and what rights you have over it. It covers this website and our dealings with clients, candidates and suppliers.
Who we are
Voxalone Limited is the data controller for the personal data described in this policy. We are registered in England and Wales under company number , with a registered office at 82A James Carter Road, Mildenhall, IP28 7DE, United Kingdom.
For any question about this policy or about how we handle your data, contact privacy@voxalone.com.
What personal data we collect
Information you give us
- Your name, email address, telephone number and organisation when you submit an enquiry form or email us
- The content of your enquiry, including any project details you choose to share
- Your CV, work history and application correspondence if you apply for a role
- Contact and billing details if you become a client or supplier
Information collected automatically
- Standard server log data, including IP address, browser type and the pages requested
- Aggregate, non-identifying analytics about how the website is used, where analytics is enabled
We do not use advertising cookies, cross-site trackers or marketing automation pixels on this website. See our cookie policy for detail.
Why we use it
- To respond to your enquiry. Answering your question and, where relevant, preparing a proposal.
- To deliver our services. Managing engagements, contracts and invoicing.
- To recruit. Assessing applications and communicating with candidates.
- To operate and improve the website. Ensuring it works, is secure, and is useful.
- To meet legal obligations. Accounting, tax and statutory record-keeping.
We do not sell personal data, and we do not add enquiry contacts to a marketing list without a separate, explicit opt-in.
Lawful basis for processing
- Legitimate interests — responding to business enquiries, operating and securing our website, and managing supplier relationships. We have assessed that this does not override your rights and freedoms.
- Performance of a contract — delivering services to clients and managing our engagements.
- Consent — where you have explicitly opted in, for example to non-essential analytics. You may withdraw consent at any time.
- Legal obligation — retaining financial records as required by law.
Who we share it with
We share personal data only with processors who help us operate, each under a written contract that restricts their use of it:
- Cloud hosting and website infrastructure providers
- Email, calendar and business productivity providers
- Accounting, invoicing and payment providers
- Professional advisers, where necessary and under a duty of confidentiality
We will disclose personal data where required by law, court order or a regulator with jurisdiction over us. A current list of our sub-processors is available on request.
How long we keep it
- Enquiries that do not proceed — up to 24 months, then deleted.
- Client records — for the engagement and 7 years afterwards, to meet accounting and limitation-period requirements.
- Unsuccessful applications — 12 months, unless you ask us to keep them longer or to delete them sooner.
- Server logs — typically 30 to 90 days.
International transfers
Our primary infrastructure is located in the United Kingdom and the European Economic Area. Where a provider processes data outside the UK, we rely on UK adequacy regulations or on the International Data Transfer Agreement or Addendum, together with appropriate supplementary measures. Client engagements may specify stricter data residency requirements, which we implement contractually and technically.
Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit and at rest, role-based access control, least-privilege access, multi-factor authentication, dependency and secret scanning in our build pipelines, and logging of access to systems holding personal data. No system is perfectly secure, but we treat a breach as a serious operational failure and maintain an incident response process accordingly.
Your rights
Under the UK GDPR you have the right to:
- Be informed about how your data is used — which this policy is intended to do
- Access a copy of the personal data we hold about you
- Have inaccurate data corrected
- Have your data erased in certain circumstances
- Restrict processing in certain circumstances
- Data portability, where processing is based on consent or contract and is automated
- Object to processing based on legitimate interests
- Withdraw consent at any time, where consent is the basis for processing
To exercise any of these, email privacy@voxalone.com. We will respond within one month. There is no charge unless a request is manifestly unfounded or excessive.
Personal data within client projects
Where we build or operate systems that process personal data on behalf of a client, the client is the data controller and Voxalone Limited acts as a processor. That relationship is governed by a written data processing agreement covering scope, security measures, sub-processors, breach notification, international transfers and deletion or return of data at the end of the engagement. This privacy policy does not govern that processing.
Changes to this policy
We may update this policy to reflect changes in our practices or the law. The date at the top of this page shows when it was last revised. Material changes affecting how we use data you have already given us will be communicated directly where we hold contact details for you.
Complaints
If you are unhappy with how we have handled your personal data, please raise it with us first at privacy@voxalone.com — we would rather resolve it directly. You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority, at ico.org.uk or on 0303 123 1113.