← Back to ENX Solutions

Privacy Policy

ENX Solutions Ltd ("ENX", "we", "us" or "our") is a limited company registered in England and Wales under Company Number 17196500. This policy explains what personal data we collect, why we collect it, how we use and protect it, and the rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Last updated: 4 July 2026

This document is a general template made available for information only. It is not a substitute for bespoke legal advice, and you should consult a qualified solicitor before relying on it for any specific matter.

1. Who we are and how to contact us

ENX Solutions Ltd is the data controller for personal data you provide to us through this website, by email, or in the course of engaging us as a client. You can contact us about this policy or your personal data at stef@enxsolutions.net. We are not currently required to appoint a Data Protection Officer, but the founder is the point of contact for all privacy matters.

2. Personal data we collect

Depending on how you interact with us, we may collect:

  • Contact and enquiry data: your name, business name, email address, phone number, website URL, and any information you include in a contact form submission, enquiry email, or booked call, including project brief, goals, budget range and timelines.
  • Client account and billing data: contact details, billing address, VAT number, purchase order references, bank details for outgoing payments to you where relevant, and a record of proposals, contracts and invoices.
  • Correspondence: emails, messages and meeting notes exchanged with us.
  • Content you provide during an engagement: brand assets, copy, images, credentials for third party tools, and any personal data contained in files, spreadsheets or databases you ask us to work with.
  • Technical and usage data: IP address, device type, browser type, operating system, referring URL, pages visited, time spent, and other information collected automatically when you use the website through cookies and similar technologies (see section 9 below).
  • Marketing data: your preferences in receiving marketing from us and any updates to those preferences.

We do not knowingly collect special category data (for example health, racial or ethnic origin, political opinions) and we do not target the website at children. Please do not send us that type of information through the site.

3. How we collect personal data

  • Directly from you, when you submit a form, email us, book a call, sign a proposal, or send us project files.
  • Automatically, when you use the website, through cookies, server logs and analytics tools.
  • From third parties, such as our payment processor, our accountant, hosting providers, publicly available business records, and platforms you connect to during an engagement (only where you have authorised us to access them).

4. Why we use it and our lawful basis

Under the UK GDPR, we must have a lawful basis for each purpose for which we process your personal data. The main purposes and lawful bases we rely on are:

  • Responding to enquiries and providing quotes: performance of a contract and taking steps at your request prior to entering a contract, and our legitimate interests in operating our business.
  • Delivering and supporting the services: performance of the contract between us and our legitimate interests in providing and improving our services.
  • Sending service related emails (project updates, invoices, technical notices): performance of the contract and our legitimate interests.
  • Accounting, tax and record keeping: compliance with legal obligations.
  • Securing and improving the website: our legitimate interests in keeping our systems safe, preventing fraud, and understanding how the site is used.
  • Marketing communications: consent where required, or our legitimate interests in promoting our services to existing business customers, in each case with a clear way to opt out.

Where we rely on legitimate interests, we have carried out a balancing exercise and are satisfied that our interests are not overridden by your rights and freedoms. You can ask us for more detail on that assessment.

5. Who we share personal data with

We do not sell your personal data. We share it only with trusted third parties acting as our processors, and only to the extent they need it to help us run our business. Categories include:

  • Hosting, infrastructure and content delivery providers.
  • Analytics providers helping us understand how the website is used.
  • Email delivery and communication providers used to send transactional and marketing emails.
  • Customer relationship management, project management, scheduling and file storage tools we use internally.
  • Payment processors and our accountant or bookkeeper.
  • Professional advisers such as lawyers and insurers where necessary.
  • Authorities and regulators where we are required to do so by law, or to protect our rights, property or safety.
  • A successor entity in the event of a sale, merger, restructure or transfer of assets.

Each processor is bound by a written contract requiring it to protect your data and to act only on our documented instructions.

6. International transfers

Some of our processors are located outside the United Kingdom. Where personal data is transferred outside the UK, we rely on one of the following safeguards recognised under the UK GDPR: an adequacy decision by the UK government, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, together with any additional measures required by law.

7. How long we keep personal data

We keep personal data only for as long as we need it for the purposes set out in this policy, or for longer where the law requires us to. As a general guide:

  • Enquiry data from prospects that do not become clients: up to 24 months from last contact.
  • Client project files and correspondence: for the duration of the engagement and up to 6 years after the end of the last engagement, to deal with any queries, disputes or warranty claims.
  • Financial and tax records: at least 6 years, as required by UK tax law.
  • Website analytics data: usually up to 26 months, or as configured in the relevant analytics tool.

When we no longer need personal data, we delete or anonymise it.

8. How we protect personal data

We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration or disclosure. These include access controls, strong passwords and multi factor authentication where available, encryption in transit, restricted admin access, and the use of reputable service providers. No system is 100 percent secure, but we take our obligations seriously and continually review our practices.

9. Cookies and similar technologies

The website uses strictly necessary cookies to run correctly and may use privacy friendly analytics to help us understand how the site is used. Where required by law, we ask for your consent before setting non essential cookies. You can control cookies at any time through your browser settings, but disabling certain cookies may affect how the site works.

10. Your rights

Under the UK GDPR you have the right to:

  • Request access to the personal data we hold about you.
  • Ask us to correct inaccurate or incomplete personal data (rectification).
  • Ask us to delete your personal data in certain circumstances (erasure or the "right to be forgotten").
  • Ask us to restrict how we process your personal data in certain circumstances.
  • Object to processing based on our legitimate interests or for direct marketing.
  • Ask us to transfer certain personal data to you or another controller in a structured, commonly used, machine readable format (portability).
  • Withdraw consent at any time where we rely on it.
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not carry out such decision making.

To exercise any of these rights, email stef@enxsolutions.net. We will respond within one month, or explain why we need more time. You will not usually have to pay a fee. We may need to verify your identity before we can act on a request.

You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk or on 0303 123 1113. We would appreciate the chance to deal with your concerns first, so please do contact us before you complain.

11. Third party links

The website may contain links to third party sites. We are not responsible for their content or privacy practices, and encourage you to read their privacy notices.

12. Changes to this policy

We may update this policy from time to time. Material changes will be posted on this page with a new "last updated" date at the top.

13. Contact

Questions about this policy or your data? Email stef@enxsolutions.net.