1. Who we are
Prophoenix Solutions Tech (“we”, “us”, “our”) operates prophoenixsolutions.com. We are the data controller for personal data collected through this website and through our client engagements.
Registered office: 27 Old Gloucester Street, London, England, WC1N 3AX. Company number 17064165. Licensed by the Information Commissioner’s Office, registration number ZA786198. We are authorised and regulated by the Financial Conduct Authority and are entered on the Financial Services Register under reference number 946605. You can reach our data protection contact at [email protected].
2. What personal data we collect
We collect the following categories of data:
- Information you give us. Name, work email address, telephone number, company name, website URL, budget range, service interest and the content of any message you send through our contact form or by email.
- Technical data. IP address, browser type and version, device type, operating system, referring URL, pages viewed and timestamps.
- Usage and analytics data. How you interact with the site, including pages visited, time on page and interactions with forms and links.
- Client engagement data. For clients, the business contact details and account information necessary to deliver our services.
We do not knowingly collect special category data (such as health, ethnicity or political opinions) and ask that you do not include it in form submissions.
3. Why we use it and our lawful basis
| Purpose | Lawful basis (UK GDPR Art. 6) |
|---|---|
| Responding to enquiries and preparing proposals | Legitimate interests; steps prior to entering a contract |
| Delivering contracted services to clients | Performance of a contract |
| Site security, fraud and spam prevention | Legitimate interests |
| Analytics and improving the website | Consent (where non-essential cookies are used) |
| Marketing emails about our services | Consent, or soft opt-in for existing clients |
| Meeting legal, tax and accounting obligations | Legal obligation |
4. How your data is processed when you use our form
Contact form submissions are transmitted over HTTPS to a serverless function hosted on Cloudflare, which forwards the content to our internal inbox by email and sends you a confirmation copy. We apply a hidden anti-spam field and a per-IP rate limit; the IP address used for rate limiting is held transiently and is not used for profiling.
5. Who we share data with
We do not sell personal data. We share it only with processors who help us operate, each bound by a data processing agreement:
- Cloudflare, Inc. for website hosting, CDN, security and form processing
- Our transactional email provider, for delivery of form notifications and confirmations
- Google LLC for website analytics, where you have consented to analytics cookies
- Our CRM and productivity providers, for managing enquiries and client work
- Professional advisers, auditors and regulators, where legally required
6. International transfers
Some of our processors are based outside the UK. Where personal data is transferred internationally, we rely on UK adequacy regulations or on the International Data Transfer Agreement / UK Addendum to the EU Standard Contractual Clauses, together with appropriate supplementary safeguards.
7. How long we keep it
- Enquiries that do not become clients: 24 months from last contact
- Client records: the engagement plus 6 years, to meet contractual and tax rules
- Marketing consents and opt-out records: until withdrawn, plus a suppression record
- Server and security logs: up to 12 months
8. Your rights
Under UK GDPR you have the right to:
- access a copy of the personal data we hold about you;
- have inaccurate data corrected;
- request erasure where we no longer need the data;
- restrict or object to processing based on legitimate interests;
- data portability for data you provided under contract or consent;
- withdraw consent at any time, without affecting prior processing.
To exercise any right, email [email protected]. We respond within one month. If you are unhappy with our response you may complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113.
9. Security
We apply TLS encryption in transit, access controls on a least-privilege basis, multi-factor authentication on administrative accounts, and regular review of third-party access. No transmission over the internet is completely secure, so we cannot guarantee absolute security.
10. Children
Our services are directed at businesses. We do not knowingly collect data from anyone under 18. If you believe a child has provided us data, contact us and we will delete it.
11. Changes to this policy
We review this policy at least annually. Material changes will be posted here with an updated revision date, and where required we will notify you directly.