Privacy Policy

How Hexalogic IT handles personal data.

This policy explains what personal data we collect through our website and business services, why we use it, who we may share it with and the choices available to you.

Draft for reviewLast updated: 10 September 2026Applies to website visitors, prospects and clients
Review before final sign-off

This is a 90% ready draft. The final legal entity name, registered address, privacy contact email, supplier list and retention schedule should be confirmed before marking it as final.

Overview

Hexalogic IT respects the privacy of the people and organisations we work with. We only collect personal data where it helps us respond to enquiries, provide managed IT services, protect systems, manage client relationships or meet legal and contractual duties.

This policy is written for website visitors, prospective clients, suppliers, client contacts and authorised users who interact with Hexalogic IT. It should be read alongside our Terms of Use and Cookie Policy.

Who We Are

Hexalogic IT provides managed IT support, cyber security, infrastructure, data management, device management and vendor management services for organisations in the UK.

The organisation responsible for your personal data is currently shown as Hexalogic IT. Final company registration details, registered address and privacy contact details are to be confirmed before final publication.

Data We Collect

Depending on how you interact with us, we may collect:

  • Contact details such as name, job title, organisation, email address and telephone number.
  • Enquiry information such as services of interest, business size, support needs, timelines and messages submitted through the website.
  • A generated website enquiry reference so we can identify the message in follow-up communications.
  • Client administration details needed to manage accounts, proposals, contracts, invoices, support communications and service reviews.
  • Technical and service information supplied to us as part of managed IT support, such as device, user, ticket, network, supplier or security context.
  • Website and device information such as browser type, pages visited, approximate location, referral source and cookie preferences, where such tools are active.

The current website contact form forwards enquiries through the hosted email delivery route and does not create a separate website database record for each enquiry.

Sensitive informationPasswords, credentials, payment card numbers and highly sensitive system information should not be sent through general website forms.

How We Use Data

We use personal data to respond to enquiries, prepare proposals, provide and improve services, manage client relationships, administer contracts, protect client systems, maintain service records and meet legal or regulatory obligations.

Where a client asks Hexalogic IT to provide technical support, we may process personal data on the client's behalf under the relevant service agreement. In that situation, the client may be the controller of the data and Hexalogic IT may act as processor.

Lawful Basis

Our lawful basis will depend on the situation. We may process personal data because it is necessary to take steps before entering into a contract, perform a contract, comply with a legal obligation, pursue legitimate business interests or use consent where required.

Legitimate interests may include responding to business enquiries, managing relationships, improving services, securing systems, maintaining audit records and communicating with business contacts about relevant services.

Sharing Data

We do not sell personal data. We may share data with trusted service providers, professional advisers, hosting and communication platforms, support tooling providers, payment or accounting services, security and monitoring services, and regulators or authorities where required.

The final supplier list should be reviewed against the live website, support stack, form delivery tooling and client service tools before final sign-off.

Retention

We keep personal data only for as long as needed for the purpose it was collected, including enquiry follow-up, service delivery, account management, dispute handling, security, audit and legal record keeping.

Retention periods may vary by record type. Enquiry data, client records, support tickets, contractual records, financial records and security logs may each need different periods. The final retention schedule is to be confirmed before this policy is marked final.

Your Rights

Under UK data protection law, you may have rights to access, correct, erase, restrict, object to or receive a copy of your personal data. You may also have the right to withdraw consent where processing is based on consent.

You can raise a privacy request using the contact route provided on this website. We may need to verify your identity before acting on a request.

Security

Hexalogic IT takes reasonable technical and organisational steps to protect personal data against unauthorised access, loss, misuse or disclosure. These steps may include access controls, secure configuration, monitoring, staff awareness, supplier review and appropriate service procedures.

No website, email route or IT environment can be guaranteed completely secure. If you believe data has been sent to us in error or there is a security concern, please contact us promptly.

Contact

Questions about this policy or requests about personal data should be sent through the contact page until the dedicated privacy contact is confirmed.

If you are unhappy with how a privacy matter is handled, you may have the right to contact the UK Information Commissioner's Office.