Privacy Policy
How we collect, use and protect personal information through the Insightnix website and Data Services.
1. Who controls your information
Insightnix is an online data platform operated by Isodev Limited, a company registered in England and Wales under company number 16866628, with its registered office at Bartle House, 9 Oxford Court, Manchester, England, M2 3WQ.
Isodev Limited, operating under the Insightnix name, is the data controller for personal information we use for our own purposes. This includes information collected through insightnix.com, website forms, public-dashboard interactions, newsletters, business communications, enquiries, quotations, contracts, billing, security records and the administration of our Data Services. As controller, we determine why and how that information is used.
Where a client gives us access to personal information solely so that we can provide dashboard, reporting, integration, migration, forecasting, maintenance or support services on the client’s documented instructions, the client will normally remain the controller and Isodev Limited will act as its processor. Section 6 explains this distinction.
This policy applies to the Insightnix website, public dashboards, forms, newsletters, business communications and Data Services administration. It does not govern independent third-party websites or platforms linked from our website.
In this policy, “personal information” and “personal data” mean information relating to an identified or identifiable living person. Information that has been irreversibly anonymised so that no individual is reasonably identifiable is not personal data. Pseudonymised information remains personal data where it can be linked to a person using additional information.
Related documents
This policy should be read with our Cookie Policy, Terms of Use, Data Practices and, where relevant, our Data Services Terms, an accepted quotation, statement of work or client-specific Data Processing Agreement. A project-specific privacy notice or data-processing schedule may provide additional information for a particular engagement.
2. Information we collect
You can view most public dashboards without creating an account or directly giving us your name. We collect personal information when you provide it, communicate with us, use a restricted or client portal, enter into a business relationship with us, or when our systems generate records needed to operate and secure our services.
- Data Services enquiries: your name, business email address, telephone number, organisation, role, organisation size, location, message, selected platform, data sources, licence status, estimated viewer numbers, refresh frequency, requested features and other service options you submit.
- Dashboard suggestions and contact forms: your name, email address, organisation, request details, attachments where enabled, and information included in your message.
- Newsletter records: your email address, name where requested, subscription status, consent evidence, delivery information, and unsubscribe or suppression records.
- Client-portal and account information: your name, business contact details, organisation, account identifier, assigned role, access permissions, authentication and login records, and activity or support records associated with your account.
- Client and supplier administration: business contact details, quotations, contracts, project instructions, correspondence, meeting notes, invoices, payment status, support records, and information needed for accounting, insurance, compliance or legal purposes.
- Technical and security information: IP address, browser and device information, operating system, requested pages, timestamps, referring page, cookie choices, server and application logs, error information, form-submission records, rate-limiting records, and indicators of suspected misuse or malicious activity.
- Rights requests and complaints: contact details, correspondence, the nature of the request or complaint, information reasonably needed to verify identity or authority, and records of our investigation and response.
Where the information comes from
We normally receive information directly from you. We may also receive business contact information from your employer, a colleague or authorised representative, a referral, a service provider, or a public professional or corporate source where this is necessary and appropriate.
If information about another person is supplied to us, the person or organisation providing it is responsible for ensuring that the disclosure is lawful and that any required privacy information has been provided.
Information we do not ordinarily request
Our general website forms are not designed to collect passwords, private cryptographic keys, full payment-card details, passport copies, medical records, special-category information, criminal-offence information, children’s information or other high-risk personal information. Please do not submit such information unless it is genuinely necessary, lawful and specifically agreed with us through an appropriate secure method.
If we receive information that is clearly excessive or unrelated, we may delete it, restrict access to it or ask for a reduced or appropriately redacted version.
3. How and why we use personal information
We use personal information only where we have an appropriate lawful basis. The purposes and bases that most commonly apply are:
- Enquiries, calls and quotations: to understand requirements, respond, arrange discussions and prepare proposals. We rely on steps taken at your request before entering a contract, where applicable, and our legitimate interests in operating and developing our business.
- Service delivery and client administration: to establish, manage and perform engagements, communicate with authorised contacts, provide support, invoice and maintain project records. We rely on contract where you are personally party to it, our legitimate interests in managing business relationships, and legal obligations.
- Client portals and account management: to create and administer accounts, assign permissions, authenticate users, provide requested functionality, support users and maintain audit records. We rely on contract, legitimate interests and security obligations as applicable.
- Dashboard suggestions and platform development: to assess requested topics, available datasets and potential improvements. We rely on our legitimate interests in developing Insightnix.
- Newsletter and optional electronic marketing: to send communications you requested or that are otherwise permitted. We normally rely on consent and the applicable electronic-marketing rules. You may unsubscribe at any time.
- Website operation, fraud prevention and security: to deliver pages, maintain sessions, record cookie choices, limit abusive submissions, diagnose faults, investigate attacks and protect systems and users. We rely on legitimate interests, legal obligations and the rules governing storage and access technologies.
- Accounting, taxation, legal claims and compliance: to keep required records, obtain professional advice, respond to lawful requests, enforce agreements and establish, exercise or defend legal rights. We rely on legal obligations and legitimate interests.
- Rights requests and data protection complaints: to verify, investigate, respond, keep people informed and demonstrate how the matter was handled. We rely on legal obligations and legitimate interests in maintaining appropriate compliance records.
Legitimate interests
Where we rely on legitimate interests, we consider the purpose, whether the processing is necessary, whether it is reasonably expected, and the possible effect on individuals. Safeguards may include collecting less information, restricting access, reducing retention, using aggregated information, offering an opt-out or requiring human review.
Required information
Required fields are identified on our forms. You do not have to submit an enquiry, request or newsletter subscription, but without necessary contact or project information we may be unable to respond, prepare a quotation, create an account or provide a requested service. Contract, identity, tax or payment information may be required before or during a client engagement.
Consent and changing purposes
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing that was lawful before it was withdrawn. We will not use personal information for a materially incompatible new purpose unless the law permits or requires it, and we will provide further information or seek consent where required.
We do not sell personal information or disclose it for third-party advertising.
4. How long we keep personal information
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, security, insurance and dispute-management requirements. Our normal approach is:
- Enquiries, dashboard requests and unsuccessful quotations: normally for up to 24 months after the last meaningful contact or final decision.
- Client, contractual, project and financial records: normally for the engagement and up to six years afterwards, or longer where required for tax, insurance, an active dispute or another legal obligation.
- Client-portal accounts: for as long as the account or relevant service remains active, followed by a reasonable period for security, audit, support and contractual records.
- Newsletter subscriptions: until you unsubscribe or the list is discontinued. We may retain a minimal suppression record afterwards so that we continue to respect your preference.
- Routine server and diagnostic logs: normally for up to 90 days. Security, rate-limiting or incident records may be kept for up to 12 months or longer where necessary to investigate an incident or protect legal rights.
- Cookie and consent records: for the period reasonably required to remember and demonstrate your choice, as described in our Cookie Policy.
- Rights requests and data protection complaints: normally for up to six years after closure where needed to demonstrate compliance or manage related claims.
Client personal information processed on a client’s behalf is retained according to the applicable Order, Data Processing Agreement and the client’s documented instructions.
A record may be kept for longer where it is subject to a legal hold, active dispute, fraud or security investigation, regulatory request, insurance matter or unresolved complaint. It may be deleted sooner where the purpose has ended and no legal or operational reason requires continued retention.
Deleted information may remain temporarily in protected backups until the relevant backup is overwritten in the normal cycle. During that period, it is kept beyond ordinary use and remains protected.
We periodically review retention and securely delete, anonymise or restrict information that is no longer required.
5. Who we share personal information with
We disclose personal information only where necessary and proportionate. Recipients may include:
- website hosting, cloud infrastructure, database, backup and security providers;
- business email, newsletter, form, collaboration, customer-management and support providers;
- accounting, invoicing, banking and payment providers;
- authorised employees, contractors and subprocessors who need access for their responsibilities and are subject to appropriate confidentiality obligations;
- accountants, insurers, solicitors, auditors and other professional advisers;
- courts, regulators, law-enforcement bodies, tax authorities or other recipients where disclosure is required or permitted by law; and
- a prospective buyer, investor or successor in connection with a genuine financing, restructuring, sale or transfer of all or part of the business, subject to appropriate protections.
Where a provider acts as our processor, we require appropriate contractual commitments concerning instructions, confidentiality, security, subprocessors and assistance with data-protection obligations. Some recipients, including banks, professional advisers, insurers, courts and regulators, may act as independent controllers for their own purposes.
International transfers
Some providers may store or access personal information outside the United Kingdom. Where this creates a restricted international transfer, we use an available lawful mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another safeguard permitted by law. Where required, we assess the transfer and apply additional contractual, organisational or technical safeguards.
You may contact us for further information about the categories of recipients and safeguards relevant to your information. We may withhold details that would compromise security, confidentiality or another person’s rights.
6. Client data and Data Services
We act as controller for our own client-management information, including business contacts, quotations, contracts, invoices, communications, access and security records, and legal or compliance records.
Where a client determines why and how personal information in a dataset is used and gives us access solely to provide dashboard, reporting, integration, migration, forecasting, maintenance or support services, the client normally remains the controller and Isodev Limited acts as processor.
As processor, we handle personal information only on documented instructions and subject to appropriate confidentiality, security, subprocessor, assistance, audit and deletion or return obligations. The detailed processor terms are set out in section 12 of our Data Services Terms and may be supplemented or replaced by a client-specific Data Processing Agreement.
The client is responsible for identifying an appropriate lawful basis, providing required privacy information, handling individual rights, limiting information to what is necessary and ensuring that information is lawfully supplied to us. Our operational principles are described in our Data Practices.
If an individual contacts us about information held solely on behalf of a client, we will normally refer the request to that client and provide reasonable contractual assistance. We will not independently alter, disclose or erase processor-held information unless instructed by the controller or required by law.
We do not sell Client Data, use it for third-party advertising, publish it on Insightnix, use it for another client or use identifiable Client Data to train a general-purpose artificial-intelligence model.
Information that has been irreversibly anonymised and aggregated so that neither the client nor an individual is reasonably identifiable may be used for internal security analysis, service improvement, capacity planning and general statistical understanding.
7. Cookies, children and automated processing
Cookies and similar technologies
Insightnix uses cookies and similar storage or access technologies for website operation, security, consent management and, where enabled, optional analytics. Non-exempt technologies that require consent are not used before the required consent is given. You can accept, reject or change optional choices through our cookie settings tool. Further details are available in our Cookie Policy.
Children
The general Insightnix website and Data Services enquiry process are intended for adults acting personally or on behalf of businesses and organisations. They are not designed to knowingly collect personal information directly from children. Please contact us if you believe a child has submitted personal information without appropriate authority.
A client engagement may exceptionally involve information relating to children where the client lawfully provides education, research, health or public services. Such processing must be expressly agreed, limited to the client’s documented instructions and supported by appropriate safeguards. The client remains responsible for lawful basis, transparency and any age-appropriate protections.
Automated processing
We do not use personal information collected through the general Insightnix website to make decisions about individuals based solely on automated processing where the decision produces legal or similarly significant effects.
Dashboards, forecasting and machine-learning tools supplied through Data Services may identify patterns, segment information or estimate outcomes. Unless expressly agreed otherwise, they are analytical aids rather than independent decision-makers. A client using an output in a decision-making process remains responsible for assessing accuracy, fairness, explainability, human oversight and any legal restrictions relevant to that use.
8. Security
We use technical and organisational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure and access. Measures are selected according to the nature and risk of the processing and may include encrypted connections, multi-factor authentication, role-based access, least-privilege permissions, secure configuration, secrets management, security updates, backups, logging, monitoring, supplier review, confidentiality obligations and incident-response procedures.
Access is limited to people and providers who need the information for an authorised purpose. We review safeguards in light of the information involved, available technology and the possible impact of a breach.
Security also depends on clients and users protecting credentials, maintaining their systems, restricting permissions, reviewing authorised users, applying vendor updates and promptly reporting suspected compromise.
No internet transmission or storage system can be guaranteed completely secure. Please avoid sending unnecessary sensitive or confidential information through general website forms. If we identify a personal-data breach, we will investigate, contain and remediate it and make any notifications required by law or contract.
9. Your rights and complaints
Depending on the circumstances and lawful basis, you may have rights to:
- be informed about how your personal information is used;
- request access to your personal information;
- have inaccurate or incomplete information corrected;
- request erasure or restriction where the legal conditions apply;
- receive certain information in a portable format;
- object to processing based on legitimate interests;
- object at any time to direct marketing;
- withdraw consent at any time where processing relies on consent; and
- challenge certain significant decisions made solely by automated means, where applicable.
Your right to object
Where we rely on legitimate interests, you may object based on your particular situation. We will stop the relevant processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims. Your right to object to direct marketing is absolute.
How to exercise a right
Email [email protected] with the subject line “Data Protection Rights Request” and enough information to help us identify the relevant records. Requests are normally free of charge. We may request proportionate evidence of identity or authority where reasonably necessary.
We respond without undue delay and normally within one calendar month after receiving a valid request and any information reasonably required to confirm identity or clarify the request. Where the law permits an extension because of complexity or the number of requests, we will explain this within the initial response period.
Data protection complaints
Email [email protected] with the subject line “Data Protection Complaint”. Please explain what happened, when it occurred and the outcome you are seeking.
We will acknowledge receipt within 30 days, take appropriate steps to investigate without undue delay, keep you informed where necessary and communicate the outcome without undue delay.
You may also complain to the Information Commissioner’s Office. Contacting us first gives us an opportunity to address the matter but does not affect your right to approach the ICO or seek another legal remedy.
10. Changes to this policy
We may update this policy to reflect changes to our services, systems, suppliers, processing activities, legal obligations or regulatory guidance. The current version will be published on this page with a fixed last-updated date.
Where a change materially affects how we use personal information already collected, we will take reasonable steps to draw attention to it and obtain consent where the law requires it. Previous versions may be made available on request where reasonably practicable.
11. Contact
Insightnix Privacy
Email: [email protected]
Legal operator and controller: Isodev Limited, company number 16866628
Registered office: Bartle House, 9 Oxford Court, Manchester, England, M2 3WQ
For a rights request, use the subject line “Data Protection Rights Request”. For a complaint, use “Data Protection Complaint”. Please do not send passports, driving licences, financial records, production credentials or other sensitive information unless we specifically request an appropriate and proportionate form of verification through a suitable method.
You may act through an authorised representative. We may ask for evidence that the representative is authorised and may still need to verify the identity of the person whose information is concerned.