Who is responsible
Arcwright Ltd is the data controller for the personal data described in this notice. We are registered in England and Wales and maintain a registration with the Information Commissioner’s Office. Our Norwegian studio operates as part of the same legal entity, so a single controller is responsible wherever your data is processed.
Questions about this notice, and any request to exercise the rights described in it, go to the address at the foot of this page. They are read by the Head of Security & Assurance, not by a shared marketing inbox.
What this website collects
The site is statically generated and served without a session, an account system or a tracking script. The only personal data that reaches us from it is data you type into a form and submit.
| Source | Data | Why we hold it | Retention |
|---|---|---|---|
| Enquiry form | Name, work email, organisation, optional phone number, selected capabilities, budget range, your message | To answer your enquiry and, if it becomes an engagement, to establish the contract | 24 months from the last contact, then deleted |
| Newsletter form | Email address only | To send the engineering note you asked for | Until you unsubscribe, then deleted within 30 days |
| Server logs | IP address, user agent, requested path, timestamp | Security monitoring and abuse prevention at the hosting layer | 30 days, then rotated out |
We do not ask for special category data, and you should not send any. If a brief needs to describe clinical, biometric or financial records, describe the system rather than its contents — we will take the detail under a signed agreement instead.
The lawful basis for each use
Under UK GDPR every use of personal data needs a lawful basis. Ours are as follows, and we do not rely on legitimate interests for anything you would be surprised by.
| Processing | Basis | Notes |
|---|---|---|
| Answering an enquiry | Legitimate interests | You approached us about professional services; a reply is what you asked for |
| Newsletter | Consent | Given by the subscription form, withdrawable from any issue in one click |
| Delivering an engagement | Contract | Processing necessary to perform the contract you have signed with us |
| Security logging | Legal obligation and legitimate interests | Keeping a client-facing system secure is a duty under our own certifications |
Where it is processed
Personal data collected through this site is processed in the United Kingdom and the European Economic Area. Our Oslo studio is inside the EEA, and data moving between the two studios travels under the UK adequacy regulations for the EEA and the corresponding EEA decision for the UK.
Where an engagement requires data to be processed elsewhere, that is agreed in the engagement contract with a named transfer mechanism, not under this notice.
Your rights, and how to use them
You can exercise any of the following by emailing the address at the foot of this page. We answer within one month and there is no charge.
- Access — a copy of the personal data we hold about you.
- Rectification — correction of anything inaccurate or incomplete.
- Erasure — deletion, where we have no overriding obligation to keep it.
- Restriction — a pause on processing while a dispute is resolved.
- Portability — the data you gave us, in a machine-readable format.
- Objection — to any processing we carry out under legitimate interests.
- Withdrawal of consent — at any time, without affecting what happened before.
If we get it wrong, you can complain to the Information Commissioner’s Office in the UK or to your local supervisory authority in the EEA. We would rather you told us first, but that is your choice, not a precondition.
How it is protected
We hold ISO 27001 certification and clear the NHS Data Security and Protection Toolkit annually. In practice that means enforced multi-factor authentication, encrypted storage and transport, least-privilege access reviewed quarterly, and an incident process that has been rehearsed rather than merely written.
If a breach affects your personal data and is likely to result in a risk to your rights, we will tell you — and the relevant supervisory authority within 72 hours. We would tell you about it before an auditor found it; that is an operating principle here, not a legal minimum.
Changes to this notice
This notice is versioned, and the version and effective date are printed in the title block at the top of the page. Material changes take effect no earlier than 30 days after publication, and anyone with an open enquiry or a live engagement is told directly rather than being left to notice.
Ask us about any of this
Data protection questions, subject access requests and complaints all go to the same address. It is monitored by a named person, and you will get a named reply.
§PR · v2.1 · Last updated: 16 August 2026