Skip to content
§PRPrivacyv2.1

What we collect, and what we do not.

This site collects nothing until you send it something. There is no analytics, no advertising network, no session recording and no third-party script. What follows is the full account of the personal data we hold, why we hold it, and how to make us delete it.

Version
2.1
Last updated
16 August 2026
In force from
1 September 2026
Clauses
8
§01

Who is responsible

Arcwright Ltd is the data controller for the personal data described in this notice. We are registered in England and Wales and maintain a registration with the Information Commissioner’s Office. Our Norwegian studio operates as part of the same legal entity, so a single controller is responsible wherever your data is processed.

Questions about this notice, and any request to exercise the rights described in it, go to the address at the foot of this page. They are read by the Head of Security & Assurance, not by a shared marketing inbox.

§02

What this website collects

The site is statically generated and served without a session, an account system or a tracking script. The only personal data that reaches us from it is data you type into a form and submit.

Personal data collected through this website
SourceDataWhy we hold itRetention
Enquiry formName, work email, organisation, optional phone number, selected capabilities, budget range, your messageTo answer your enquiry and, if it becomes an engagement, to establish the contract24 months from the last contact, then deleted
Newsletter formEmail address onlyTo send the engineering note you asked forUntil you unsubscribe, then deleted within 30 days
Server logsIP address, user agent, requested path, timestampSecurity monitoring and abuse prevention at the hosting layer30 days, then rotated out

We do not ask for special category data, and you should not send any. If a brief needs to describe clinical, biometric or financial records, describe the system rather than its contents — we will take the detail under a signed agreement instead.

§03

The lawful basis for each use

Under UK GDPR every use of personal data needs a lawful basis. Ours are as follows, and we do not rely on legitimate interests for anything you would be surprised by.

Lawful bases relied on
ProcessingBasisNotes
Answering an enquiryLegitimate interestsYou approached us about professional services; a reply is what you asked for
NewsletterConsentGiven by the subscription form, withdrawable from any issue in one click
Delivering an engagementContractProcessing necessary to perform the contract you have signed with us
Security loggingLegal obligation and legitimate interestsKeeping a client-facing system secure is a duty under our own certifications
§04

Who else sees it

We do not sell personal data, and we do not share it for anybody else’s marketing. A small number of processors handle it on our instructions under written agreements:

  • Our hosting provider, which serves this site and retains the server logs described above.
  • Our email provider, which carries correspondence between us and you.
  • Our accounting and contract systems, where an enquiry becomes an engagement.

Each processor is assessed before it is used and reassessed annually. None of them is permitted to use your data for their own purposes, and none is located in a country without an adequacy decision or an equivalent transfer mechanism.

§05

Where it is processed

Personal data collected through this site is processed in the United Kingdom and the European Economic Area. Our Oslo studio is inside the EEA, and data moving between the two studios travels under the UK adequacy regulations for the EEA and the corresponding EEA decision for the UK.

Where an engagement requires data to be processed elsewhere, that is agreed in the engagement contract with a named transfer mechanism, not under this notice.

§06

Your rights, and how to use them

You can exercise any of the following by emailing the address at the foot of this page. We answer within one month and there is no charge.

  • Access — a copy of the personal data we hold about you.
  • Rectification — correction of anything inaccurate or incomplete.
  • Erasure — deletion, where we have no overriding obligation to keep it.
  • Restriction — a pause on processing while a dispute is resolved.
  • Portability — the data you gave us, in a machine-readable format.
  • Objection — to any processing we carry out under legitimate interests.
  • Withdrawal of consent — at any time, without affecting what happened before.

If we get it wrong, you can complain to the Information Commissioner’s Office in the UK or to your local supervisory authority in the EEA. We would rather you told us first, but that is your choice, not a precondition.

§07

How it is protected

We hold ISO 27001 certification and clear the NHS Data Security and Protection Toolkit annually. In practice that means enforced multi-factor authentication, encrypted storage and transport, least-privilege access reviewed quarterly, and an incident process that has been rehearsed rather than merely written.

If a breach affects your personal data and is likely to result in a risk to your rights, we will tell you — and the relevant supervisory authority within 72 hours. We would tell you about it before an auditor found it; that is an operating principle here, not a legal minimum.

§08

Changes to this notice

This notice is versioned, and the version and effective date are printed in the title block at the top of the page. Material changes take effect no earlier than 30 days after publication, and anyone with an open enquiry or a live engagement is told directly rather than being left to notice.

Ask us about any of this

Data protection questions, subject access requests and complaints all go to the same address. It is monitored by a named person, and you will get a named reply.

§PR · v2.1 · Last updated: 16 August 2026