Legal & privacy

Privacy Policy

This notice explains how AcxiomFlow Limited uses personal data when you visit our website, contact us, do business with us, or interact with us in a professional capacity.

Last updated: 7 August 2026

1. Who we are and which laws apply

AcxiomFlow Limited is a company based in the United Kingdom. For the personal data covered by this notice, AcxiomFlow Limited is normally the data controller, meaning we decide why and how that data is used.

We apply the UK GDPR and the Data Protection Act 2018 as amended, including relevant changes introduced by the Data (Use and Access) Act 2025. We also comply with the Privacy and Electronic Communications Regulations (PECR) where they apply to electronic marketing, cookies and similar technologies.

Where our processing falls within the territorial scope of the EU GDPR, we also apply the EU GDPR and relevant EEA privacy and electronic-marketing requirements.

When we process personal data solely on a client's instructions as part of an automation or technology service, the client will normally be the controller and AcxiomFlow Limited will act as a processor. In that situation, the client's own privacy notice and our data-processing agreement govern that processing.

2. Personal data we collect directly

When you use our website contact form, we may collect:

  • name and email address;
  • company, website, role and industry;
  • tools or systems you currently use;
  • your goal, workflow bottleneck or business problem;
  • any other information you include in your message;
  • the source of the submission and the time it was submitted.

We may also collect correspondence, meeting notes, proposal information, contract details, billing records and other information you provide during a business relationship.

Please do not send special-category data or highly sensitive personal information through our general contact form unless it is genuinely necessary and we have agreed an appropriate way to handle it.

3. Personal data we may obtain from other sources

For business-to-business relationship development, we may obtain limited professional information from publicly available or commercially available business sources. This may include company websites, professional profiles, public business records, referrals, directories and business-data providers where their use is lawful.

This information can include a person's name, employer, professional role, business contact details, company website or domain, publicly available professional information and notes about why our services may be relevant to the organisation.

We do not treat publicly available information as exempt from data-protection law. We still apply purpose limitation, data minimisation, accuracy, security, transparency and the right to object.

4. Why we use personal data and our lawful bases

PurposeTypical dataLawful basis
Responding to enquiries and arranging audits, calls or proposalsContact details, company information and the information you submitLegitimate interests in responding to business enquiries and, where relevant, steps requested before entering into a contract
Providing services and managing client or supplier relationshipsContact, account, contract, project, billing and correspondence informationContract, legitimate interests in managing business relationships, and legal obligations where applicable
Business-to-business prospecting and relationship developmentProfessional contact details, employer, role, public business information, correspondence and internal relevance notesLegitimate interests in developing our business, subject to applicable direct-marketing rules and your right to object
Operating, securing and improving our website and systemsTechnical request data, device/browser information, security events and diagnostic informationLegitimate interests in running a secure, reliable service and preventing misuse
Complying with law and protecting legal rightsRelevant records, communications, transaction or account informationLegal obligation and/or legitimate interests in establishing, exercising or defending legal claims
Optional marketing where consent is requiredContact details and marketing preferencesConsent where required; otherwise another lawful basis only where applicable law permits it

Where we rely on legitimate interests, those interests include responding to business enquiries, developing and managing business relationships, improving operations, protecting our systems and preventing fraud or misuse. We consider the impact on the individual and do not rely on legitimate interests where the person's rights and freedoms override those interests.

5. AI-assisted processing and automated decisions

As an AI workflow automation business, we may use AI-assisted tools for tasks such as research, summarisation, classification, drafting, data extraction, routing and quality checks. We aim to limit the personal data sent to AI providers to what is necessary for the task and to use appropriate contractual, technical and organisational safeguards.

We do not use website enquiries or ordinary business-contact data to make decisions based solely on automated processing that produce legal effects or similarly significant effects on an individual. Where human judgement matters, our intended operating model is to keep an appropriate human review or approval point.

6. Cookies, storage/access technologies and embedded content

Our website may use technologies that are strictly necessary to deliver, secure or operate the service. We do not intentionally use non-essential storage or access technologies unless there is an applicable legal exception or the required choice or consent has been obtained.

Some pages contain YouTube videos. We use a click-to-load approach and YouTube's privacy-enhanced embedding mode so the YouTube player is not loaded until you choose to load the video. If you load a video, Google/YouTube may receive technical information and may use cookies or similar technologies under its own policies.

If we introduce analytics, advertising pixels or other non-essential tracking in future, we will update this notice and implement the consent or other controls required by the law before using them.

7. Who we share personal data with

We share personal data only where reasonably necessary for the purposes described above. Recipients may include:

  • website hosting, infrastructure, security and technical service providers;
  • Google services used to receive and store contact-form submissions;
  • Google/YouTube when you actively load an embedded video;
  • email, calendar, communications and collaboration providers;
  • CRM, automation, integration and workflow service providers;
  • AI providers used for specific assisted-processing tasks;
  • professional advisers such as accountants, lawyers or insurers where necessary;
  • regulators, courts, law-enforcement bodies or other parties where disclosure is legally required or necessary to protect legal rights.

We do not sell personal data. We require service providers handling personal data on our behalf to process it under appropriate instructions and safeguards.

8. International transfers

Some technology providers may process personal data outside the UK and/or the EEA. Where a transfer is restricted under applicable data-protection law, we use an appropriate legal transfer mechanism and any additional safeguards required for that transfer.

Depending on the transfer, this may include an applicable adequacy regulation or decision, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, the EU Standard Contractual Clauses, and any required transfer-risk or data-protection assessment and supplementary measures.

9. How long we keep personal data

We do not keep personal data for longer than we reasonably need it. Our normal approach is:

  • Website enquiries and sales correspondence: normally up to 24 months after the last meaningful interaction, unless a longer period is needed for an ongoing relationship or legal reason.
  • Business prospect information: normally up to 24 months after the last meaningful interaction or validation of relevance. If someone opts out, we may retain a minimal suppression record for longer so we can respect that choice.
  • Client, supplier, contractual and accounting records: for the relationship and normally up to six years afterwards where needed for legal, tax, accounting or dispute purposes.
  • Security and technical records: for the period reasonably necessary for security, fraud prevention, troubleshooting and service integrity, taking account of provider settings and legal requirements.
  • Consent and preference records: for as long as needed to honour the preference and demonstrate compliance.

We may delete or anonymise information earlier where it is no longer necessary.

10. Your data-protection rights

Depending on the circumstances and the law that applies, you may have rights to:

  • be informed about how your personal data is used;
  • request access to your personal data;
  • ask us to correct inaccurate or incomplete data;
  • ask us to erase personal data in certain circumstances;
  • ask us to restrict processing in certain circumstances;
  • receive or transfer certain data in a portable format;
  • object to processing based on legitimate interests;
  • object at any time to processing for direct marketing;
  • withdraw consent at any time where consent is the lawful basis;
  • exercise applicable rights relating to solely automated decisions and profiling.

These rights are not absolute and exemptions may apply. We may need to verify your identity before acting on a request.

11. Direct marketing and opting out

We apply PECR and, where relevant, applicable EEA direct-marketing and ePrivacy rules. The rules can differ depending on the type of recipient, the communication channel and the country involved.

You can object to direct marketing or ask us not to contact you for marketing at any time. We may keep a minimal suppression record so that we do not accidentally contact you again for the same purpose.

12. Security

We use reasonable technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, loss or destruction. Measures are selected according to the nature of the information, the systems involved and the risk.

No online system can be guaranteed to be completely secure, so we also use monitoring, access controls, review processes and incident-response measures appropriate to our operations.

13. Children

Acxiomflow is a business-to-business service and our website is not directed at children. We do not knowingly seek personal data from children through our sales or business-development processes.

14. Changes to this notice

We review this policy when our services, technology providers or legal obligations change. If we make a material change to how we use personal data, we will update this page and, where required, provide additional notice before the new use begins.

15. Contact us and make a complaint

To exercise a privacy right or ask a privacy question, use the Acxiomflow contact form and write “Privacy request” in your message. Please provide enough information for us to understand the request, but do not send unnecessary sensitive information.

If you are unhappy with how we handle your personal data, please contact us first so we can investigate. You also have the right to complain to the UK Information Commissioner's Office (ICO). Where the EU GDPR applies, you may also have the right to complain to the competent supervisory authority in the EEA.

Important: This website notice describes AcxiomFlow Limited's intended privacy practices and does not replace client-specific contracts, data-processing agreements or privacy notices where we process data on behalf of a client.