Legal

Privacy Policy

How ODEIS Limited collects, uses, and protects your personal data — in accordance with the UK GDPR and the Data Protection Act 2018.

Organisation ODEIS Limited
Company Number 15749949
Effective Date 29 June 2026
Registered in England & Wales
Website www.odeis.co.uk
Regulatory Framework UK GDPR & DPA 2018

This Privacy Policy explains how ODEIS Limited collects, uses, shares, and protects personal data relating to website visitors, clients, job applicants, suppliers, and other business contacts. Please read it carefully. If you have any questions, contact us at .

Section 01

Who We Are

ODEIS Limited (“ODEIS”, “we”, “us”, or “our”) is a data analysis and environmental consultancy registered in England and Wales (Company No. 15749949). We collect, use, share, and protect personal data in connection with our website at www.odeis.co.uk, our consultancy and data analysis services, our recruitment activities, and our relationships with suppliers and other business contacts.

ODEIS is committed to processing personal data fairly, lawfully, and transparently, in accordance with the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018 (“DPA 2018”).

ODEIS is registered with the Information Commissioner’s Office (the “ICO”) under registration number ZC184547. If you have a concern about how we handle your data, you have the right to complain to the ICO at any time (see Section 16).

Section 02

Scope of This Policy

This Policy applies to personal data that ODEIS collects and uses as a Data Controller, including data relating to:

  • Visitors to our Website
  • Individuals who contact us directly
  • Current, former, and prospective clients and their staff
  • Job applicants
  • Suppliers, contractors, and other business contacts

In the course of providing consultancy and data analysis Services, ODEIS may also process personal data on behalf of, and strictly on the instructions of, a client — for example, where a client dataset contains personal data, including health-related or other special category data — acting as a Data Processor rather than a Data Controller. This Policy does not apply to that processing. Where ODEIS acts as a processor, the relevant client (as Data Controller) is responsible for providing its own privacy notice to the individuals concerned, and the relevant Engagement Document and any data processing agreement govern that processing. If you believe ODEIS holds personal data about you in this capacity, please contact the organisation that instructed ODEIS in the first instance.

This Policy should be read alongside our Terms of Business, which governs use of the Website and the provision of our Services.

Section 03

Definitions

Term Definition
Personal Data Any information relating to an identified or identifiable living individual.
Special Category Data Personal data revealing health, racial or ethnic origin, religious beliefs, sexual orientation, trade union membership, genetic or biometric data, and similar categories defined in Article 9 UK GDPR.
Data Controller The organisation that determines the purposes and means of processing personal data.
Data Processor An organisation that processes personal data on behalf of, and under the instructions of, a Data Controller.
Cookies Small text files placed on your device when you visit a website, used to make websites work, or work more efficiently, and to provide reporting information (see Section 5).
Section 04

Information We Collect and Why

4.1 Visitors to Our Website

4.1.1 When you visit our Website, we may automatically collect technical information including your device and browser type, IP address, approximate location derived from your IP address, the pages you visit, how you arrived at the Website, and the date and time of your visit. This is collected through cookies and similar technologies — see Section 5 for full details.

4.1.2 If you submit an enquiry through the “Get in touch” form on our Website, we collect the information you provide — typically your name, organisation, email address and the content of your message — in order to respond to your enquiry. We do not currently operate an email newsletter sign-up; if this changes, we will update this Policy accordingly.

4.2 People Who Contact Us Directly

4.2.1 If you contact us by email, telephone, or post, we will collect your name, contact details, and the content of your message, in order to respond to your enquiry and keep a record of the correspondence.

4.3 Clients and Client Contacts

4.3.1 Where an organisation engages ODEIS to provide Services, we collect business contact details of relevant individuals at that organisation (such as name, job title, employer, email address and telephone number), together with information relating to the engagement, such as instructions, correspondence and billing contacts.

4.3.2 We use this information to perform our contract with the client, manage the engagement, issue invoices, and comply with our legal and accounting obligations.

4.3.3 As explained in Section 2, this clause does not cover personal data contained within Client Data that ODEIS processes as a Data Processor on a client’s instructions.

4.4 Job Applicants

4.4.1 If you apply for a role with ODEIS, we collect information you provide in your application, CV and covering letter, together with interview notes, references, and right-to-work documentation where relevant.

4.4.2 We use this information to assess your suitability for a role, to administer the recruitment process, to comply with our legal obligations (for example, verifying eligibility to work in the UK), and, where you are successful, to set up your engagement with ODEIS.

4.4.3 If your application is unsuccessful, we will normally retain your application data for 6 months after the recruitment process ends, after which it will be securely deleted — unless you have given us consent to retain it for longer to consider you for future roles, or we are required to keep it for longer to comply with a legal obligation or to deal with a dispute.

4.5 Suppliers, Contractors and Other Business Contacts

4.5.1 Where we engage suppliers, subcontractors, associates or other business contacts, we collect business contact details and, where relevant, payment and bank details, in order to manage the business relationship, process payments, and comply with our accounting and tax obligations.

Section 05

Cookies and Similar Technologies

Our Website uses cookies and similar technologies to make the Website work properly and to help us understand how visitors use it.

Category Purpose Examples / Provider
Strictly Necessary Required for the Website to function correctly (e.g. security, load balancing). These cannot be switched off. Cloudflare security and performance cookies (e.g. cf_clearance, __cf_bm), set by our hosting provider.
Analytics / Performance Help us understand how visitors interact with the Website, such as pages visited and time spent on site, so we can improve it. Google Analytics 4 (_ga, _ga_<container-id>).
Functionality Remember choices you make on the Website to provide enhanced, personalised features. Not currently used.

Where required by law, we will ask for your consent before setting non-essential cookies (such as analytics cookies), via a cookie banner or settings tool on the Website. You can change your preferences at any time using that tool, or via your browser settings.

Most web browsers allow you to control cookies through their settings, including refusing all cookies or being notified when a cookie is set. Further guidance is available at www.aboutcookies.org. Please note that if you disable cookies, some parts of the Website may not function as intended.

Section 06

Lawful Basis for Processing

Under Article 6 UK GDPR, we rely on the following lawful bases, depending on the activity:

Consent

For example, for non-essential cookies, or to retain an unsuccessful job applicant’s details for longer than our standard retention period.

Performance of a Contract

To provide our Services to clients, to manage supplier relationships, and to take steps towards entering into an employment or engagement contract with successful job applicants.

Legal Obligation

For example, to retain accounting and tax records, or to carry out right-to-work checks.

Legitimate Interests

For example, to respond to enquiries, to maintain and improve our Website, to manage our business relationships, and to assess job applications, where these interests are not overridden by your rights and interests.

Section 07

Special Category Data

7.1 We do not generally expect to collect special category data about website visitors, suppliers or job applicants, save where you choose to disclose it to us (for example, health information relevant to a reasonable adjustment during recruitment), in which case we will rely on the lawful basis of explicit consent, or processing necessary for employment-related purposes, as relevant under Article 9 UK GDPR and Schedule 1 DPA 2018.

7.2 Where ODEIS processes special category data, including health-related data, within Client Data as a Data Processor under a client’s instructions (see Section 2), the relevant client is responsible for identifying an appropriate Article 9 condition and, where required, an appropriate policy document under the DPA 2018. ODEIS implements appropriate technical and organisational safeguards (including encryption, access controls and confidentiality obligations) when processing such data on a client’s behalf.

Section 08

Sharing Your Personal Data

8.1 ODEIS does not sell personal data. We may share personal data with the following categories of recipient, where necessary and proportionate:

  • IT, hosting, email and cloud storage providers who support our Website and business operations;
  • professional advisers, including accountants, solicitors, auditors and insurers;
  • subcontractors and associates engaged to assist with the provision of Services, who are bound by confidentiality and data protection obligations;
  • HMRC, regulators, the ICO, and other public bodies, where we are required to do so by law;
  • a prospective buyer (and its advisers) in the event of a sale, merger or restructuring of our business; and
  • law enforcement or other authorities, where required or permitted by law.
Section 09

International Data Transfers

9.1 Some of the service providers we use to operate our Website and business (for example, cloud hosting or software providers) may store or process personal data outside the UK.

9.2 Where this occurs, we ensure an appropriate safeguard is in place, such as the UK’s International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or a UK adequacy decision in respect of the destination country, as applicable.

Section 10

Data Retention

10.1 We retain personal data only for as long as necessary for the purposes for which it was collected, including to satisfy any legal, accounting or reporting requirements.

Data Category Retention Period
Client engagement and billing records Typically retained for 6 years following the end of the engagement, to meet contractual, accounting and tax record-keeping obligations.
Job applicant data As set out in Section 4.4.3.
Website analytics data Google Analytics 4 retains event-level data for 2 months and user-level data for 14 months from the date of collection, in accordance with our configured retention settings. After these periods, the relevant data is automatically deleted.
Correspondence Retained for as long as reasonably necessary to deal with the matter raised and for a reasonable period afterwards in case of follow-up queries.
Website “Get in touch” enquiries Retained for up to 24 months from your last contact with us, unless that enquiry develops into a client engagement, in which case the client engagement retention period above applies instead.
Section 11

Data Security

11.1 We maintain appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage. These measures include access controls, encryption where appropriate, staff confidentiality obligations, and periodic review of our security practices.

While we take reasonable steps to protect personal data, no method of transmission over the internet, or method of electronic storage, is completely secure, and we cannot guarantee absolute security. If you have a concern about the security of your data or believe there has been a breach, please contact us immediately at . We are obligated to report certain types of data breach to the ICO within 72 hours of becoming aware of them.

Section 12

Your Rights

Subject to certain exemptions and conditions, you have the following rights under the UK GDPR in relation to personal data we hold about you as Data Controller:

Right to Be Informed

About how your personal data is used.

Right of Access

Request a copy of the personal data we hold about you via a Data Subject Access Request (DSAR).

Right to Rectification

Ask us to correct incomplete or inaccurate data we hold about you.

Right to Erasure

Ask us to delete or remove personal data where there is no good reason for us to continue processing it.

Right to Restriction

Ask us to restrict our processing of your personal data in certain circumstances.

Right to Data Portability

Obtain and reuse your personal data for your own purposes, in a structured, machine-readable format.

Right to Object

Object to processing based on legitimate interests, or for direct marketing.

Right to Withdraw Consent

Withdraw consent at any time, where we rely on consent as our lawful basis.

12.1 To exercise any of these rights, please contact us at . We will normally respond within one month of receiving a valid request.

12.2 You also have the right to complain directly to us about how we have handled your personal data, and we will investigate and respond to your complaint without undue delay, in accordance with section 164A of the Data Protection Act 2018 (as inserted by the Data (Use and Access) Act 2025). You also have the right to lodge a complaint with the Information Commissioner’s Office at any time, whether or not you have complained to us first — see Section 16.

Section 13

Automated Decision-Making and Profiling

13.1 ODEIS does not currently use automated decision-making that produces legal effects or similarly significantly affects you, without human involvement. If this changes, we will update this Policy and provide further information about the logic involved and your rights in relation to it.

Section 14

Children’s Privacy

14.1 Our Website and Services are directed at businesses and professionals and are not intended for children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so that we can take appropriate action.

Section 15

Changes to This Policy

15.1 We may update this Policy from time to time, including to reflect changes in our practices, our Services, or the law. The latest version will always be available on our Website, together with its effective date.

Section 16

How to Contact Us and Your Right to Complain

If you have any questions about this Policy, wish to exercise any of your rights, or want to make a data protection complaint, please contact us at:

  • ODEIS Limited, 110 Howard Road, Dartford, DA1 1XH
  • Email: (please mark data protection complaints “Data Protection Complaint” in the subject line)
  • Telephone: 07349 513246
  • Website: www.odeis.co.uk

If you make a data protection complaint to us, we will acknowledge it, make reasonable enquiries into the matters raised, keep you informed of progress, and respond without undue delay.

You also have the right to lodge a complaint with the UK’s supervisory authority for data protection at any time, whether or not you have complained to us first:

  • Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
  • Helpline: 0303 123 1113
  • Website: www.ico.org.uk

We would appreciate the opportunity to address your concerns before you approach the ICO, so please contact us in the first instance.

This Privacy Policy was last reviewed and updated on 29 June 2026. We reserve the right to update this Policy at any time. Material changes will be communicated via our Website.