Introduction
This privacy notice explains how Etralo processes personal data when individuals:
- Use our website or other online services
- Contact us (e.g. by email, phone, or contact form)
- Inquire about our services
It sets out what personal data we collect, why we use it, who we share it with, how long we keep it, and your rights under UK data protection law (UK GDPR and Data Protection Act 2018).
This notice is written for individuals (data subjects). It primarily covers our public website and general enquiries. Separate service, licensing, or other agreements may include their own data‑processing addenda or more specific privacy terms; where there is a conflict, the more specific notice or contractual provision applies.
Who is responsible for your personal data?
For the Etralo public website and general enquiries, the data controller is:
Etralo Consilium Ltd (Company No. 17366633), an operating subsidiary of Etralo Limited (Company No. 17248391).
Registered Office: Etralo Consilium Ltd, 15 London End, Beaconsfield, Buckinghamshire, HP9 2HN, United Kingdom
Registered in England and Wales.
Unless otherwise specified, Etralo Consilium Ltd is the controller for personal data processed in connection with the Etralo public website and general enquiries. Any separate contract or agreement may designate a different controller on a case‑by‑case basis (identified in the relevant contract, order form, service notice, or engagement documentation).
If you have questions about which controller applies, contact us using the details at the end of this notice and we will direct you to the appropriate Data Protection Officer or contact point.
Who this notice applies to
This notice applies to:
- Website visitors and users of our online services
- People who contact us via email, phone, or online forms
- Prospective clients and suppliers (including their employees and contacts)
- Other individuals whose data we process in connection with our business activities
If you are a client or supplier under contract, some processing may be further specified in your engagement documents or a separate B2B privacy notice.
Personal data we collect
1. Technical and security information
When you use our website, our infrastructure, hosting, and CDN providers may process limited technical information, including:
- IP addresses
- Browser type and version
- Device and system information (e.g. operating system, device type)
- Request details (e.g. URLs accessed, timestamps, HTTP method, status codes)
This information is used to:
- Operate, secure, and maintain the website and related systems
- Prevent abuse, fraud, and attacks
- Maintain reliability and monitor performance
- Investigate misuse and comply with lawful requests from authorities
Our lawful basis for this processing is our legitimate interests in ensuring the security and integrity of our website and services, and/or compliance with legal obligations where applicable.
We do not use this information to identify individuals beyond what is necessary for security and operational purposes, and we do not combine it with other data to build profiles of individual website visitors.
Some limited technical data may be processed by our infrastructure, CDN, and hosting providers as part of normal operation (e.g. IP addresses in server logs). This processing is carried out on our behalf as processors or as part of the underlying service infrastructure, and is subject to contractual and security obligations. It is separate from any use of cookies or similar technologies, which we do not employ on our public website.
We may also process limited, pseudonymised technical data for basic analytics (e.g. aggregate page views, referral sources, and performance metrics). This is used to understand overall usage trends and improve our services. It does not identify individuals and is not used for profiling or marketing. Our lawful basis is our legitimate interests in monitoring and improving site performance and reliability.
2. Voluntarily submitted information
When you contact us (e.g. via contact forms, email, or phone), you may choose to provide personal data such as:
- Names and contact details (e.g. email address, phone number)
- Company name and job title
- Details of your inquiry or message
- Any other information you include in your communication
Please do not send special-category personal data (e.g. health or biometric data) unless we specifically request it or it is necessary for a matter you are asking us to handle.
We use this information to:
- Respond to your inquiry
- Provide information about our services
- Take steps prior to entering into a contract (e.g. scoping, quotations)
- Keep records of communications for compliance and quality purposes
Our lawful bases for this processing include:
- Contract / pre‑contractual steps – where processing is necessary to take steps at your request before entering into a contract.
- Legitimate interests – in managing enquiries, maintaining records, and improving our services.
- Legal obligation – where we must retain data for legal or regulatory reasons.
Cookies and similar technologies
We do not use cookies or similar storage/access technologies on our public website. A separate Cookies Policy describes any cookies or similar technologies that may be used in other contexts (e.g. authenticated client portals). Where required by PECR, we will obtain your prior consent with an easy way to accept or reject.
How and why we use your personal data
1. Providing and improving products and services
Purposes: To negotiate, enter into, and perform contracts; deliver services; manage projects; provide support; and improve our offerings.
Data categories:
- Names and contact details (e.g. business email, phone number)
- Business addresses
- Records of meetings, calls, and decisions (including minutes and notes)
- Audio recordings of calls (where applicable and notified)
- Project and service delivery records
Lawful basis:
- Contract – processing is necessary to perform our contract with you or your organisation.
- Legitimate interests – for internal improvements, quality assurance, and service development, where this does not override your rights.
- Legal obligation – where we must process data to comply with law (e.g. tax, accounting, regulatory requirements).
2. Operating client and customer accounts
Purposes: To create and manage accounts; authenticate users; provide access to services; handle billing and payments; and maintain security.
Data categories:
- Names and contact details
- Business addresses
- Account information (usernames, access credentials, roles)
- Purchase and service history
- Payment and billing information
- Technical data (e.g. IP address, browser, operating system, device information)
- Security logs and access records
- Marketing preferences related to account communications
Lawful basis:
- Contract – necessary to operate your account and provide the services you have requested.
- Legal obligation – for accounting, tax, anti‑fraud, and regulatory compliance.
- Legitimate interests – for security, fraud prevention, and network/system integrity.
3. Information updates and marketing
Purposes: To send you service updates, product news, relevant marketing, and invitations to events or webinars (where permitted).
Data categories:
- Names and contact details
- Business addresses
- Purchase or account history (to tailor communications)
- Marketing preferences and communication history
Lawful basis:
- Consent – where we rely on your explicit opt‑in (e.g. for certain types of electronic marketing to individuals). You can withdraw consent at any time.
- Legitimate interests – for B2B marketing to corporate subscribers where permitted by PECR and UK GDPR, subject to your right to object.
- Contract – for service‑related communications that are necessary to perform our contract (e.g. important service notices).
We may send service communications that are necessary to administer an account or perform a contract. These are not marketing communications.
We may send electronic direct marketing only where permitted by PECR. Depending on the recipient and circumstances, this may require prior consent or may be permitted under the existing-customer soft opt-in, subject to the applicable conditions and an opportunity to opt out.
You can object to or opt out of marketing at any time using the unsubscribe link in our emails or by contacting us.
4. Complying with legal and regulatory requirements
Purposes: To meet legal, regulatory, and contractual compliance obligations (e.g. tax, audit, regulatory reporting).
Data categories:
- Name
- Contact information
- Identification documents (e.g. company registration details, ID where required)
- Any other personal data required by law or regulation
Lawful basis:
- Legal obligation – processing is necessary to comply with applicable laws and regulations.
Where specific legal obligations apply, some of your rights (e.g. erasure, objection, portability) may be limited by law.
5. Dealing with queries, complaints, or claims
Purposes: To respond to enquiries; handle complaints; manage disputes; and defend or pursue legal claims.
Data categories:
- Names and contact details
- Business addresses
- Purchase or service history
- Call recordings (where applicable and notified)
- Correspondence (emails, letters, chat logs)
- Notes of investigations and outcomes
Lawful basis:
- Contract – where the query relates to an existing or prospective contract.
- Legitimate interests – to manage complaints, improve services, and protect our legal rights.
- Legal obligation – where we must retain or process data for legal or regulatory reasons (e.g. dispute resolution, regulatory investigations).
Where we get your personal data from
We typically collect data:
- Directly from you (e.g. via forms, email, phone calls, meetings, contracts)
- From your organisation (client/supplier contact details)
- From regulatory authorities, legal bodies, or professional advisers where relevant or necessary
- From publicly available sources (company registers, professional networks) where lawful and appropriate
How long we keep your data
We do not keep personal data longer than necessary.
Indicative retention periods:
- Website logs and technical data: Up to 24 months for security, performance, and abuse prevention purposes. Some limited pseudonymous analytics data may be retained for longer, but is not used in a way that directly identifies individuals.
- Contact form/enquiry data: Up to 12 months from last contact, unless a contract is subsequently entered into. In practice, many enquiries are converted to email and may be retained for longer as part of our business correspondence records. Where this occurs, the data is kept only for as long as necessary for the relevant purpose (e.g. managing the relationship, legal or regulatory requirements, or legitimate business records).
- Contract/service records: Contract duration plus 5 years (or otherwise the limitation period for contractual claims).
- Account and billing data: Retained for at least the statutory period (10+ years) for tax and accounting purposes. After the statutory period, billing records may be redacted or pseudonymised where appropriate, but certain core information may be retained indefinitely for historical and records purposes.
- Marketing data: Until unsubscribe/objection, plus up to 12 months for suppression records.
- Call recordings/security logs: 30 days to 2 years, depending on purpose.
- Regulatory records: As required by applicable law. Where specific legal or regulatory obligations apply, retention periods typically range from 2 to 6 years from the end of the business relationship, but may be longer where required.
Who we share your data with
We may share data with:
- Our staff and authorised personnel who need it to perform their roles
- Data processors acting on our instructions, including:
- Peblor Limited – Our primary technology partner who provides IT infrastructure and technical systems management services. As our processor. Peblor processes personal data only on our documented instructions, subject to a written data-processing agreement and appropriate confidentiality and security obligations.
- Professional and legal advisers (e.g. solicitors, accountants, consultants)
- Regulators/public bodies where required
- Group companies/affiliates where relevant
We do not sell your personal data.
International transfers
Some suppliers or group companies may process data outside the UK, including where Etralo or partners have operating interests (e.g. EEA, US). We use an applicable adequacy regulation or approved mechanism (UK IDTA or UK Addendum to EU SCCs) and any additional measures required by law.
Your data protection rights
Under UK GDPR you may have:
- Right of access
- Right to rectification
- Right to erasure
- Right to restriction
- Right to object (including to direct marketing)
- Right to data portability
- Right to withdraw consent (where processing relies on consent)
Rights may be limited where law requires retention or for legal claims.
To exercise rights, contact us using the details below. We respond within one month (may extend by up to two further months for complex/multiple requests; we will inform you within one month if extended).
How we use legitimate interests
Where we rely on legitimate interests, we identify the interest, ensure necessity, and balance it against your rights.
Examples:
- Security and integrity of our website/systems (e.g. DDoS detection and prevention)
- Fraud, abuse, and unauthorised access prevention
- Performance monitoring and reliability
- Managing enquiries and complaints
- B2B marketing to corporate subscribers (where permitted)
You can object, particularly to direct marketing, by contacting us or using built-in opt‑out mechanisms.
Security
We implement technical and organisational measures (access controls, encryption, secure development, security reviews) and maintain incident response procedures and staff training.
Children’s data
Our services are not directed at children and we do not knowingly collect personal data from individuals under 16. If you believe a child has provided us with data, contact us using the details below.
Changes to this notice
We may update this notice. The latest version will be available on our website or provided in the context of our engagement.
Contact and complaints
Data protection complaints can be submitted by email or via our online contact form. Postal contact details are provided for reference; we do not guarantee processing of complaints sent by post.
Email: privacy@etralo.com
Online form: https://etralo.com/contact
Post:
Etralo Consilium Ltd
15 London End
Beaconsfield
Buckinghamshire
HP9 2HN
United Kingdom
We will investigate and aim to resolve your complaint.
If you remain dissatisfied, you can also complain to the Information Commissioner’s Office (ICO):
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline: 0303 123 1113
Website: https://www.ico.org.uk/make-a-complaint
