| Data controller | Suitxen Ltd, registered in England & Wales (company number 17284189) |
| Registered office | 71-75 Shelton Street, Covent Garden, London WC2H 9JQ |
| Contact | info@suitxen.co.uk |
| ICO registration | ZC207632 |
| Version / last updated | 1.1 — 21 September 2026 (updated for the Data (Use and Access) Act 2025) |
1. About this notice
This notice explains how Suitxen Ltd (“we”, “us”) collects and uses personal data when you visit our website, enquire about or use our service, or work with us. It covers the data for which we are the controller.
We have assessed the criteria in Article 37 UK GDPR and concluded that we are not required to appoint a statutory Data Protection Officer: we are not a public authority; our core activities do not involve large-scale, regular and systematic monitoring of individuals; and special-category data is processed only where a customer firm chooses to include it, as processor on that firm’s instructions, minimised by design — not at large scale as a core activity of our own. We review that conclusion annually and whenever our processing changes materially. Privacy queries are handled by our data-protection lead (a director of Suitxen Ltd) at info@suitxen.co.uk. Our service is business-to-business: our website and platform are not directed at children and we do not knowingly collect children’s personal data.
| Client data processed in our platform: When we provide our service to a financial planning firm, we process that firm’s clients’ personal data as a processor on the firm’s behalf. The firm is the controller of that data. If you are a client of such a firm, please contact your adviser/firm about how your data is used; their privacy notice applies. |
2. What we collect and why
| Purpose | Data | Lawful basis |
|---|---|---|
| Responding to your enquiries | Name, work email/phone, job title, firm | Legitimate interests (responding to a professional enquiry you have made) |
| Marketing our service to advice firms (business-to-business only) | Name, work email, job title, firm — from you, or from public professional sources (see below) | Article 6 basis: legitimate interests (Article 6(1)(f)) for corporate subscribers and for qualifying soft-opt-in contacts — assessment recorded in our Legitimate Interests Assessment; where we rely on your PECR consent (individual subscribers such as sole traders and unincorporated partnerships, outside the soft opt-in), your consent (Article 6(1)(a)) is also the Article 6 basis, and you can withdraw it at any time. Separately, PECR governs the electronic message itself: corporate subscribers are contacted on an opt-out basis; individual subscribers only with consent or under the PECR soft opt-in; messages on professional social networks are assessed by the recipient account’s subscriber status, not the employer’s corporate form. Every message includes an unsubscribe link. |
| Providing & administering the service to customer firms | Account & contact details, login identifiers, correspondence | Contract (where you are the contracting party, e.g. a sole trader); legitimate interests (administering the account where you act for your firm) |
| Support & product correspondence | Name, work email, content of messages | Legitimate interests |
| Website operation & analytics | IP address, device/browser type, aggregate page-usage statistics, security logs | Legitimate interests (Article 6(1)(f): operating and securing the website and understanding aggregate usage). Our analytics are cookieless (Vercel Web Analytics): no analytics cookie is set, the provider distinguishes visits using a short-lived identifier derived from the incoming request that is discarded within 24 hours, and we receive aggregate statistics only. Any future first-party statistical or functional cookies would be used on the opt-out basis permitted by PECR as amended by the DUAA 2025 where its conditions are met, and any marketing cookies only with your consent — see section 7 |
| Billing | Billing-contact & payment details | Contract; legal obligation |
| Engaging staff & contractors | Identity, contact, engagement records | Contract; legal obligation; legitimate interests |
Where we rely on legitimate interests, we have balanced those interests against your rights and consider the processing proportionate: it involves limited business-contact data, is what you would reasonably expect in a professional context, and has minimal privacy impact. You can object at any time (section 6). We do not use your personal data for advertising to consumers, for profiling, or for any purpose other than those listed above; our only marketing is information about our own service sent to professional contacts at advice firms.
Where we have not collected your details directly — for example prospect business contacts — we obtain them from public professional sources, such as your firm’s website, professional directories, or your public LinkedIn profile. That a business contact is publicly available is not treated as permission to market to it: we contact only role-relevant professional contacts, provide this notice (or a link to it) in our first communication — and in any event within one month of obtaining your details — and stop on request.
You are not obliged to provide personal data, but without core account, contact and billing details we cannot provide or administer the service.
3. Who we share data with
We share personal data with carefully selected sub-processors who help us run the service (e.g. hosting, authentication, email, payments, and our AI model provider), under written data-processing terms. The current list, including each provider’s location and the transfer safeguards that apply, is published at www.suitxen.co.uk/legal/sub-processors. A small number of recipients act as independent controllers for their own limited purposes — for example our payment provider (fraud prevention and its own regulatory duties) and our accountant (professional obligations) — as identified in that register. We do not sell personal data. We disclose personal data to law enforcement, regulators or other authorities only where we are legally required to do so, and we assess the validity of every request before responding.
4. International transfers
Some providers are outside the UK. Where personal data is transferred internationally, we rely on an appropriate safeguard for each provider — either UK “adequacy” arrangements such as the UK Extension to the EU–US Data Privacy Framework (the UK–US Data Bridge), or the UK IDTA / Standard Contractual Clauses with the UK Addendum — supported by a transfer risk assessment and additional measures such as encryption and pseudonymisation. The mechanism applying to each provider is recorded in our Sub-processor Register, and you can request a copy of the relevant safeguard from us using the contact details below.
5. How long we keep data
We keep personal data only as long as necessary, in line with our Data Retention & Deletion Policy, then delete it. Client data processed within the platform is pseudonymised and subject to short-cycle automated deletion; we do not retain it beyond the period necessary to provide the service. Key periods: client case data in the platform — deleted automatically seven calendar days after the case is created; customer firm account records (contract, billing and business correspondence) — the duration of the relationship plus 6 years, while login credentials and operational account settings are deleted within 30 days of account closure; support and product correspondence — up to 24 months from last contact; prospect contacts — until you opt out or after 24 months of inactivity; billing and tax records — 6 years; staff and contractor engagement records — the engagement plus 6 years; system and security logs — 12 months; encrypted backups — residual copies overwritten on a rolling cycle (currently seven days; no more than 30 days); complaints and rights-request records — 6 years from closure; marketing suppression records — a minimal record (name, contact identifier, date) kept while we conduct marketing, to honour your objection. Full details, including how deleted data is handled if a backup is ever restored, are in our Data Retention & Deletion Policy, available on request.
6. Your rights
Subject to conditions, you have the right to access, rectify, erase, restrict, or object to processing of your personal data, to data portability, and to withdraw consent where we rely on it. To exercise these rights, contact us at info@suitxen.co.uk. We respond within one calendar month; for complex or multiple requests this may be extended by up to two further months, in which case we will tell you within the first month. We may need to verify your identity, and requests are free of charge unless manifestly unfounded or excessive. You can object to direct marketing at any time — every marketing email includes an unsubscribe link — and where we rely on legitimate interests you can object to the processing itself.
Automated decision-making: we do not make solely automated decisions that have a legal or similarly significant effect on you (within the meaning of Articles 22A–22D UK GDPR, as inserted by the DUAA 2025). Documents produced in our platform are working drafts that a qualified adviser must review, edit and sign off before any use — that review is a genuine, meaningful human decision, recorded in the platform’s audit trail — so no such automated decision is made there either.
7. Cookies
Browsing our website sets no cookies of our own, and our website analytics are cookieless. Strictly necessary cookies (for authentication, security and payment fraud prevention) are set only when you sign in to the platform or use a payment flow, and do not require consent. If we ever introduce low-risk first-party statistical or functional cookies, the Data (Use and Access) Act 2025 permits them on an opt-out basis where its conditions are met, and we would meet those conditions — clear information and a working, free, always-available opt-out — before setting them; any advertising, profiling or cross-site tracking cookies would be used only with your prior consent. See our Cookie Policy for the current list and controls.
8. Complaints
If you have a concern about how we handle your personal data, please contact us at info@suitxen.co.uk and we will try to resolve it directly. We will acknowledge any data-protection complaint within 30 days of receiving it, tell you how we will deal with it, take appropriate steps to investigate it, keep you informed of progress, and tell you the outcome without undue delay; if we cannot resolve it within 30 days of receiving it, we will explain why and when you can expect our response. Our internal Data-Protection Complaints & Rights Requests Procedure sets out how we do this, and we keep a record of complaints and rights requests for six years from closure (section 5). You have the right to complain to the Information Commissioner’s Office at any time (ico.org.uk; 0303 123 1113) — you do not need our permission and do not have to complain to us first, although we would welcome the chance to address your concern.
9. Contact
We may update this notice from time to time; the version and date at the top show the current one, and we will draw attention to material changes on our website (and by email where we hold your address). Questions about this notice or your data: our data-protection lead, info@suitxen.co.uk, Suitxen Ltd, 71-75 Shelton Street, Covent Garden, London WC2H 9JQ.
Document control: version 1.1, approved for publication by the Director (data-protection lead) on 21 September 2026. Approval records are held internally.