Privacy Policy

Last updated 30 August 2026

1. About this policy

This Privacy Policy explains how Inteknix Limited (“Inteknix”, “we”, “us” and “our”) collects, uses, shares and protects personal data. It covers people who visit our website at https://inteknix.alacartesvc.com (the “Website”), who contact us with an enquiry, who receive our marketing communications, who work for our clients, suppliers and partners, and who apply to work with us.

It should be read alongside our Cookie Policy, which explains in detail how we use cookies and similar technologies.

We have written this policy to be read, not to be endured. If anything in it is unclear, please contact us using the details in section 16 and we will explain it.

2. Who we are

Inteknix Limited is a Microsoft consultancy specialising in Power Platform, SharePoint, Microsoft 365 and AI services. For the personal data described in this policy, Inteknix Limited is the data controller unless section 3 says otherwise.
Company Inteknix Limited
Registered in England and Wales
Company number 08303402
VAT registration 152130753
Address Apex Office Space, 1 Water Vole Way, Doncaster, DN4 5JP, United Kingdom
Email info@inteknix.alacartesvc.com
Telephone 0203 005 5215
We are not required to appoint a statutory Data Protection Officer. Responsibility for data protection sits with [INSERT ROLE OR NAME], who can be reached at the address above.

3. When we are a controller and when we are a processor

The distinction matters, because it determines who you should approach about your data.

We act as a controller for personal data we decide the purposes of ourselves. This includes Website visitors, people who submit enquiries, marketing contacts, our own client and supplier relationship contacts, and job applicants. This policy governs that processing.

We act as a processor when we handle personal data inside a client’s environment while delivering services, for example during a SharePoint migration, a Power Platform build, an ALM remediation exercise, or the support of a system we have delivered. In those cases our client is the controller. We process that data only on their documented instructions, under a written data processing agreement that meets Article 28 of the UK GDPR, and their own privacy notice applies to it, not this one.

If you believe we hold your personal data as a processor and you wish to exercise your rights, please contact the organisation whose system it is. If you are unsure who that is, contact us and we will help you identify them.

4. The personal data we collect

4.1 Information you give us
What we collect When
Name, job title, employer, email address, telephone number When you submit an enquiry or contact form, request a proposal, or subscribe to our updates
The content of your enquiry or message When you contact us by form, email, telephone or social media
Correspondence, meeting notes and call records Throughout a commercial discussion or a live engagement
Contract, billing and payment details When you become a client or supplier
CV, employment history, qualifications and right to work information When you apply for a role with us
In the course of business development we may collect limited professional contact information from publicly available sources, including company websites, LinkedIn, Companies House, published tender and framework notices, and reputable business data providers. This is limited to business contact details and role information. We do not build profiles from personal social media activity.

Where we obtain your details this way, we will tell you at the point of first contact where we got them, in line with Article 14 of the UK GDPR.
4.2 Information collected automatically When you visit the Website, we and our analytics providers automatically collect technical information including your IP address, browser type and version, operating system, device characteristics, language preferences, referring URL, the pages you view, and the dates and times of your visit.

We want to be clear about something that many privacy notices get wrong: this information is personal data. An IP address is treated as personal data under the UK GDPR, and combined with browsing behaviour it can identify a device and, in many cases, an individual. We do not describe it as anonymous.

Most of this collection depends on cookies and similar technologies, and other than the strictly necessary elements it only happens if you have consented. Our Cookie Policy sets out exactly which cookies are used and how to change your choices.
4.3 Information we obtain from other sources In the course of business development we may collect limited professional contact information from publicly available sources, including company websites, LinkedIn, Companies House, published tender and framework notices, and reputable business data providers. This is limited to business contact details and role information. We do not build profiles from personal social media activity.

Where we obtain your details this way, we will tell you at the point of first contact where we got them, in line with Article 14 of the UK GDPR.
4.4 Special category data We do not seek to collect special category data (such as health, ethnicity, religious belief or trade union membership) through the Website or in the ordinary course of business development. If it becomes necessary during a recruitment process, for example to make a reasonable adjustment, we will tell you why and identify the additional condition we rely on under Article 9.

5. Why we use your personal data, and our lawful bases

Purpose Personal data used Lawful basis
Responding to your enquiry and providing information you have asked for Contact details, enquiry content Legitimate interests (responding to a request directed to us), or steps prior to entering a contract
Preparing proposals, quotations and statements of work Contact and organisational details, requirement details Steps prior to entering a contract
Delivering our services and managing the client relationship Contact details, correspondence, engagement records Performance of a contract
Invoicing, credit control and accounting Contact and billing details Performance of a contract, and legal obligation
Sending marketing communications about our services Business contact details Consent, or the soft opt-in under PECR regulation 22 where you are an existing client. See section 6
Business development and outreach to organisations we believe we can help Business contact details, role information Legitimate interests (promoting our services to relevant businesses)
Understanding how the Website is used and improving it Technical and usage data Consent (given through the cookie banner)
Measuring the performance of our online advertising Technical and usage data Consent (given through the cookie banner)
Protecting the Website and our systems against fraud, spam and abuse Technical data, form submission data Legitimate interests (security of our systems)
Recruitment Application data Steps prior to entering a contract, and legitimate interests (assessing suitability)
Complying with legal, regulatory and tax obligations, and establishing or defending legal claims As applicable Legal obligation, and legitimate interests
Where we rely on legitimate interests, we have carried out a balancing assessment to satisfy ourselves that our interests do not override your rights and freedoms. You may ask us for a summary of that assessment, and you have the right to object as described in section 12.

6. Marketing communications

We send marketing communications to business contacts about our Microsoft consultancy services.

If you are not an existing client, we will only send you marketing emails where you have consented, or where we are contacting you in a business capacity at a corporate address in reliance on our legitimate interests, in a manner permitted by PECR.

If you are an existing client, we may send you information about similar services under the soft opt-in in regulation 22 of PECR, because you gave us your details in the course of a sale or negotiation and were offered the chance to opt out at that time.

Every marketing email contains an unsubscribe link. You can also email info@inteknix.alacartesvc.com at any time and we will remove you.

The right to object to direct marketing is absolute. If you tell us to stop, we stop, and we do not require a reason. We will keep a minimal record of your details on a suppression list so that we do not contact you again by mistake.

7. Cookies and similar technologies

The Website uses cookies and similar technologies. Only strictly necessary cookies are set before you make a choice. Everything else requires your consent, which you can give, refuse or withdraw at any time through the cookie preferences panel.

Full details, including a live table of every cookie in use, are in our Cookie Policy.

8. Who we share your personal data with

We do not sell your personal data. We share it only in the circumstances below.

Service providers acting as our processors. These are engaged under written contracts that require them to process personal data only on our instructions, to keep it secure, and to return or delete it at the end of the engagement. They fall into the following categories:
Category What they do for us
Cloud productivity, email and file storage Host our business email, documents and collaboration workspaces
Website hosting, infrastructure security and content delivery Run and protect the Website and its underlying infrastructure
Website forms and enquiry handling Receive and route the enquiries you submit through the Website
Website analytics and advertising measurement Report on how the Website is used and how our advertising performs
Customer relationship management and email marketing Hold our contact records and send our marketing communications
Accounting, invoicing and payment processing Support billing, credit control and statutory financial reporting
Recruitment and applicant tracking Manage job applications where we are hiring
We use Microsoft services for our own productivity and collaboration, and Google services for website analytics and advertising measurement. Beyond those, we do not publish the identity of individual suppliers, because disclosing the detail of our infrastructure and toolchain would weaken our own security posture. This does not limit your rights: if you want to know which providers process your personal data, or the safeguards applying to a particular transfer, contact us using the details in section 16 and we will tell you.

Our Cookie Policy separately names the third parties that set cookies on the Website, because you need that information to make a meaningful choice about them.

Professional advisers. Our accountants, auditors, insurers and legal advisers, where necessary and under a duty of confidentiality.

Public authorities and regulators. Where we are required to disclose information by law, by a court order, or by a properly made regulatory request.

In connection with a corporate transaction. If we are involved in a merger, acquisition, financing or sale of assets, personal data may be disclosed to the other party, subject to appropriate confidentiality protections.

Clients, where we act as a processor. As described in section 3.

9. Transfers outside the United Kingdom

Some of our service providers are based outside the UK, principally in the United States and the European Economic Area. This means your personal data may be transferred to, stored in, or accessed from those countries.

Where personal data is transferred outside the UK, we ensure that an appropriate safeguard under Chapter V of the UK GDPR is in place. Depending on the recipient, this will be one of the following:

A UK adequacy decision, which covers transfers to the EEA and to other approved countries.
The UK Extension to the EU-US Data Privacy Framework, where the recipient is certified under it.
The International Data Transfer Agreement, or the International Data Transfer Addendum to the European Commission’s Standard Contractual Clauses, supported by a transfer risk assessment.

You may request further information about the safeguards applying to a particular transfer by contacting us.

10. How long we keep your personal data

We keep personal data only for as long as we need it. The periods below are our standard retention rules. Where a longer period is required by law, or where data is relevant to an actual or anticipated legal claim, we will retain it for as long as necessary.
Category Retention period
Website enquiries that do not lead to an engagement 24 months from the last contact
Prospect and business development contacts 24 months from the last meaningful engagement, then reviewed
Client contract, engagement and project records 7 years from the end of the relationship, reflecting statutory accounting and limitation periods
Invoices, accounting and tax records 7 years from the end of the relevant financial year
Marketing consents and preference records For the duration of the consent, and for 24 months after it is withdrawn, to evidence the withdrawal
Marketing suppression lists Indefinitely, so that we can honour your objection
Cookie consent records 12 months from the date consent was given or refused
Website analytics data 14 months, in line with our Google Analytics retention setting
Unsuccessful job applications 6 months from the outcome, unless you agree to us keeping them longer
When a retention period ends, we securely delete the personal data, or anonymise it so that it can no longer be linked to you. Where deletion is not immediately possible because data sits in a backup, we isolate it from further processing until the backup cycle removes it.

11. How we keep your personal data secure

We maintain technical and organisational measures appropriate to the risk, including access controls and least privilege, multi-factor authentication on our business systems, encryption of data in transit and at rest, logging and monitoring, staff training, supplier due diligence, and documented incident response procedures.

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner’s Office within 72 hours of becoming aware of it, and we will notify you directly where the risk to you is high.

Security is our responsibility, not yours. We will not attempt to disclaim it.

12. Your rights

Under the UK GDPR you have the following rights. Not all of them apply in every situation, and we will explain if an exemption applies to your request.
Right What it means
To be informed To know how we use your personal data. This policy is how we meet that obligation.
Of access To obtain a copy of the personal data we hold about you, and information about how we use it.
To rectification To have inaccurate personal data corrected, and incomplete data completed.
To erasure To have your personal data deleted where there is no continuing lawful reason for us to hold it.
To restrict processing To have us pause our use of your data in certain circumstances, for example while we verify its accuracy.
To data portability To receive personal data you provided to us in a structured, commonly used, machine-readable format, where we process it by automated means on the basis of consent or a contract.
To object To object to processing based on our legitimate interests. Where the processing is direct marketing, your objection is absolute and we will stop immediately.
To withdraw consent To withdraw consent at any time, where consent is the basis on which we process. This does not affect the lawfulness of processing carried out before withdrawal.
Regarding automated decisions Not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make such decisions. See section 13.
To exercise any of these rights, email info@inteknix.alacartesvc.com or write to us at the address in section 2. You do not need to use a particular form of words, and you do not need to complete our contact form.

We will respond within one month. If your request is complex or you have made several requests, we may extend that by up to two further months, and we will tell you within the first month if that is the case. There is no charge unless a request is manifestly unfounded or excessive. We may ask you for information to verify your identity before we act.

13. Automated decision-making and our use of AI

We do not make decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you.

We are an AI consultancy, so we want to be specific about what that means in practice. We use AI tools internally to support our own work, for example in drafting and research. We do not use your personal data to train publicly available AI models, and we do not submit client data to third-party AI services outside the terms agreed with that client. Where we build AI solutions for clients, the client is the controller and their own governance and privacy arrangements apply.

14. Do Not Track and Global Privacy Control

There is no settled technical standard for browser-based tracking signals, and we do not currently respond automatically to Do Not Track headers. Our cookie banner gives you a direct and effective way to refuse non-essential tracking, and we honour those choices. If a recognised standard is adopted that applies to us, we will support it and update this policy.

15. Changes to this policy

We may update this policy from time to time. The date at the top shows when it was last revised. Where we make material changes, we will draw them to your attention, for example by a prominent notice on the Website or by contacting you directly. We recommend reviewing this policy periodically.

16. Contact us and how to complain

For any question about this policy, or to exercise your rights:

Email: info@inteknix.alacartesvc.com
Post: Inteknix Limited, Apex Office Space, 1 Water Vole Way, Doncaster, DN4 5JP, United Kingdom
Telephone: 0203 005 5215
If you are unhappy with how we have handled your personal data, please tell us first. We would like the opportunity to put it right. You also have the right to complain to the UK supervisory authority at any time:
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113
Website: https://ico.org.uk/make-a-complaint/