Last updated: September 28, 2026


1. About this Privacy Policy:

Nexient Ltd (“Nexient”, “we”, “us” or “our”) respects your privacy and is committed to protecting your personal data.
This Privacy Policy explains how we collect, use, store and protect personal data when you:

  • visit our website;
  • contact us;
  • request a quotation;
  • purchase or use our services;
  • communicate with us;
  • interact with us in connection with an existing or prospective business relationship.

For the purposes of applicable data-protection legislation, Nexient is generally the data controller for personal data we process for our own business purposes.

2. Data protection legislation:
Where we process personal data on behalf of a customer as part of providing website development, hosting, maintenance or related services, we may instead act as a data processor. Further information about this is provided in Section 13.

We process personal data in accordance with applicable UK data-protection legislation, including the:
UK General Data Protection Regulation (UK GDPR);
Data Protection Act 2018;
Data (Use and Access) Act 2025, where applicable; and
Privacy and Electronic Communications Regulations (PECR), where applicable. This policy will be updated where necessary to reflect changes in applicable legislation, regulatory guidance or our processing activities.

3. Personal data we collect:
The information we collect depends on how you interact with us.

Information you provide:

  • name
  • business name
  • job title or role
  • email address
  • telephone number
  • postal or business address
  • information contained in enquiries
  • information supplied when requesting a quotation
  • project requirements
  • information relating to services purchased
  • correspondence and communications
  • billing and payment information
  • information supplied during customer support

Information collected automatically:

When you use our website, we may collect technical information such as:

  • IP address
  • browser type and version
  • operating system
  • device type
  • screen characteristics
  • approximate geographical location derived from IP address
  • pages visited
  • referring website
  • date and time of visits
  • interaction with website features
  • technical and security logs

Information obtained from other sources:

Where permitted by law, we may obtain business contact information from publicly
available sources, referrals, professional networks or third-party services.

Where we obtain personal data from a source other than the individual,
we will provide the required privacy information in accordance with applicable law.

4. How we use personal data:

We may process personal data for the following purposes.

Enquiries and quotations to:

  • respond to enquiries;
  • discuss your requirements;
  • prepare quotations and proposals;
  • communicate about potential projects.

Providing services to:

  • design and develop websites;
  • provide hosting;
  • maintain websites;
  • provide technical support;
  • provide e-commerce services;
  • provide bespoke web applications;
  • provide CRM or other digital services;
  • manage projects;
  • communicate with customers.

Customer administration to:

  • manage customer accounts;
  • issue invoices;
  • process payments;
  • maintain contractual records;
  • provide customer support;
  • administer agreements.

Security and technical operations to:

  • protect our systems;
  • detect and prevent malicious activity;
  • maintain website security;
  • investigate security incidents;
  • troubleshoot technical problems;
  • maintain appropriate backups;
  • monitor performance and availability.

Marketing:
Where permitted by law, we may use personal data to send information about our services, news, events or offers.
Where consent is required, we will obtain consent before sending the relevant marketing communications.
You may opt out of marketing communications at any time.

Legal Purposes:
We may process personal data where necessary to:

  • comply with legal obligations;
  • establish, exercise or defend legal claims;
  • prevent fraud or unlawful activity;
  • protect our rights, property and systems.

5. Lawful bases for processing:

We will only process personal data where we have an appropriate lawful basis.

Depending on the circumstances, these may include:

Contract:
We may process personal data where necessary to enter into or perform a contract with you.
Legitimate interests.We may process personal data where necessary for our legitimate interests,
provided those interests are not overridden by your rights and freedoms.

Our legitimate interests may include:

  • operating and developing our business;
  • responding to genuine business enquiries;
  • managing customer relationships;
  • maintaining system and website security;
  • preventing fraud and abuse;
  • improving our services;
  • protecting our business and legal interests.

Legal obligation:

We may process personal data where necessary to comply with a legal or regulatory obligation.

Consent:
Where consent is required, we will ask for consent before processing personal data for the relevant
purpose. You may withdraw consent at any time. Withdrawal of consent does not affect processing
carried out lawfully before consent was withdrawn.

6. Legitimate interests:

Where we rely on legitimate interests, we will consider whether:
1. there is a legitimate interest;
2. the processing is necessary to achieve that interest; and
3. the individual’s rights and freedoms do not override that interest.

Where appropriate, we will document our assessment.

7. Who we share personal data with:
We may share personal data with organisations that help us operate our business and provide our services.
Depending on our actual technology and service arrangements, these may include:

  • payment providers;
  • accounting providers;
  • legal advisers;
  • regulators and public authorities where required.

We will not sell personal data to third parties. Where a third party processes personal data on our
behalf, we will take appropriate steps to ensure that suitable contractual and security protections
are in place.

8. How long we keep information:
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, unless we are legally required or permitted to retain it for longer.

Our retention schedule is:
Website enquiries:
2 years
Quotations/proposals:
2 years
Customer records:
2 years
Project records:
2 years
Marketing records:
2 years
Security logs:
2 years

We may retain information for longer where necessary to comply with legal obligations or establish, exercise or defend legal claims.

9. Security:

We take appropriate technical and organisational measures to protect personal data.
Depending on the circumstances, these measures may include:

  • access controls;
  • authentication;
  • restricted administrative access;
  • secure hosting;
  • encryption where appropriate;
  • software and security updates;
  • malware and security protection;
  • backups;
  • monitoring and logging;
  • confidentiality obligations;
  • appropriate staff access controls

No method of transmission or storage is completely secure. However, we take reasonable and proportionate steps to protect the information we hold.

10. Personal data breaches:

If we become aware of a personal-data breach, we will assess and investigate it and take appropriate steps to contain and remedy the incident.
Where legally required, we will notify the Information Commissioner’s Office and/or affected individuals.
Where Nexient is acting as a processor, we will notify the relevant controller in accordance with the applicable data-processing agreement.

11. Your rights:
Subject to applicable law and any relevant exemptions, you may have the right to:

  • obtain access to your personal data;
  • have inaccurate information corrected;
  • request deletion of personal data;
  • request restriction of processing;
  • object to certain processing;
  • request data portability where applicable;
  • withdraw consent where processing is based on consent;
  • object to direct marketing.

You may also have rights relating to automated decision-making or profiling where applicable.
These rights are not absolute and exceptions may apply.

13. Website customers and processing on their behalf:

When Nexient hosts, maintains or operates a website for a customer, that website may collect personal data belonging to the customer’s users or customers.

Examples include:

  • contact-form submissions;
  • booking information;
  • customer account information;
  • enquiry information;
  • order information;
  • newsletter subscriptions.

In these circumstances, the customer will generally be the data controller and Nexient will act as a data processor for the relevant processing.
Nexient will process such data only in accordance with the customer’s documented instructions and the applicable agreement, except where applicable law requires otherwise. Where required, Nexient will enter into a written Data Processing Agreement with the customer.

14. Cookies:

Our website uses cookies and similar technologies.
Some cookies are necessary for the website to function. Other cookies may be used for analytics, preferences or other purposes.
Where consent is legally required, we will obtain consent before using non-essential cookies.
For full details, see our Cookie Policy.

15. Direct marketing:

We may contact you with marketing communications where permitted by law.
Where consent is required, we will obtain consent before sending marketing communications.
You can opt out at any time by:

  • using the unsubscribe facility included in a marketing email; or
  • contacting us using the details in this policy.

16. Third-party websites:

Our website may contain links to third-party websites. We are not responsible for the privacy practices or content
of third-party websites. You should review the privacy policy of any third-party website before providing personal information.

17. Children’s data:

Our services are intended primarily for businesses and adults. We do not knowingly seek to collect children’s personal data through our website.
If you believe a child has provided personal data to us, please contact us.

18. Changes to this Privacy Policy:

We may update this policy from time to time. The latest version will be published on our website with the relevant “Last updated” date.
Where appropriate, we may provide additional notice of material changes.

19. Complaints:

If you have a concern about how we have processed your personal data, please contact us first.
You also have the right to complain to the Information Commissioner’s Office (ICO):

Information Commissioner’s Office
Website: https://ico.org.uk/make-a-complaint/

21. Contact us:

Nexient Ltd
Company number: 17219870
Registered office: The Limes, Bayshill Road, Cheltenham, United Kingdom, GL50 3AW
Email: hello@nexient.net
Telephone: 07849 143874
Last reviewed: September 28th, 2026