Skip to content

    Privacy Policy

    How amarti Ltd collects, uses and protects personal data.

    Document control
    Reference AM-POL-013
    Version 1.0
    Classification Public
    Owner James Peachey, Co-founder
    Approved by James Peachey, Co-founder, on 2 September 2026
    Next review 2 September 2027
    Applies to Website visitors, clients, candidates, suppliers and associates
    Standards alignment UK GDPR; Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025); PECR

    amarti Ltd (“amarti”, “we”, “us”) is a UK software and data engineering consultancy. We are registered in England and Wales under company number 12543976, with a registered office at 61 Westway, Caterham, England, CR3 5TQ.

    For the personal data described in this policy, amarti Ltd is the data controller. Our data protection lead is James Peachey, Co-founder, who can be contacted at james@amarti.io or through info@amarti.io. amarti is not required to appoint a statutory Data Protection Officer and has not done so.

    This policy explains what personal data we collect, why, what we do with it, how long we keep it, and what rights you have. It reflects the UK GDPR and the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025.

    2. When we are a controller and when we are a processor

    Section titled “2. When we are a controller and when we are a processor”

    This distinction matters, so we state it plainly.

    For the personal data of our own website visitors, client contacts, candidates, employees, associates and suppliers, amarti is the controller. This policy applies and you should contact us directly.

    When we build, operate or support a data platform for a client, we normally process personal data on that client’s instructions. In that situation the client is the controller and amarti is the processor. Our client’s own privacy notice applies, not this one, and we act only on their documented instructions under a written data processing agreement meeting Article 28 of the UK GDPR.

    If you contact us about data we hold as a processor, we will tell you promptly and pass your request to the client controller so they can respond.

    Who you are What we collect Why Lawful basis
    Website visitor Pages viewed, referring source, approximate location, device and browser information, only if you allow analytics To understand how the site is used and improve it Consent (and consent under PECR for the analytics cookies)
    Enquirer Name, employer, job title, email, phone, and the content of your enquiry To respond to you and, where relevant, discuss how we might work together Legitimate interests: responding to a request you made
    Client contact Name, job title, business contact details, correspondence, engagement records, meeting notes To deliver the engagement, manage the relationship, invoice and meet our contractual and record-keeping obligations Contract and legitimate interests
    Candidate CV, work history, qualifications, right to work evidence, interview notes, references To assess your application and, if successful, prepare to employ or engage you Legitimate interests, steps prior to a contract, and legal obligation for right to work
    Employee, contractor or associate Full HR record including contact details, payroll and pension data, absence records, performance notes, and where relevant health information for adjustments and sickness To employ or engage you, pay you, meet employment and tax law obligations and protect health and safety Contract, legal obligation, legitimate interests, and (for health data) employment law obligations under Article 9(2)(b) and Schedule 1 DPA 2018
    Supplier contact Name, business contact details, contract and payment details, due diligence responses To manage the supplier relationship and meet our assurance obligations Contract and legitimate interests
    Marketing recipient Name, employer, business email, engagement with our communications To send occasional insight and event information about our services Legitimate interests, subject to PECR and an unsubscribe link in every message

    Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that our interests do not override your rights and freedoms. You can ask us for a summary of that assessment. Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal.

    The Data (Use and Access) Act 2025 introduced a category of recognised legitimate interests for which no balancing test is required, such as processing necessary for safeguarding vulnerable individuals or responding to an emergency. We would rely on this only in the narrow circumstances the law provides for, and we do not use it for marketing.

    Most of the personal data we hold comes directly from you. We also obtain data from your employer where you are our client contact, from recruitment agencies and referrers where you are a candidate or associate, from publicly available professional sources such as LinkedIn and company websites when researching prospective clients, and from our clients where we act as their processor.

    We do not sell personal data and we do not share it for anyone else’s marketing. We share it only where there is a clear reason to:

    • Service providers who process data on our behalf under a written contract: our cloud productivity and collaboration platform, cloud infrastructure providers, accounting and payroll providers, our HR system, our website analytics provider, and IT support.
    • Clients, where you are a consultant we are placing on an engagement and they need to know who is working on their account.
    • Professional advisers (accountants, lawyers, insurers and our certification body) where they need it to advise or audit us.
    • Regulators, law enforcement or other authorities where we are legally required to disclose, or to establish, exercise or defend legal claims.
    • A purchaser or successor, if amarti is sold or reorganised. We would tell you if that happened and the same protections would apply.

    Every processor we use is bound by a contract meeting Article 28 of the UK GDPR, is assessed under our Supplier Relationship Policy before engagement, and may not use your data for their own purposes. A current list of our processors is available on request.

    We prefer to keep personal data in the UK or the European Economic Area, and we configure our cloud services for UK or EEA regions where the service allows it.

    Where a transfer outside the UK is necessary, for example because a service provider offers support from another country, we make sure it is covered by one of the safeguards permitted by Chapter V of the UK GDPR: a UK adequacy determination, the International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment. Details of the safeguards applying to a specific transfer are available on request.

    Record Retention period
    Website analytics data Up to 14 months from collection
    Enquiries that do not lead to a relationship 12 months from last contact
    Client engagement records and correspondence 6 years from the end of the engagement
    Contracts and commercial records 6 years from expiry or termination
    Unsuccessful candidate records 6 months from the decision, unless you agree to us keeping them longer
    Employee and associate records 6 years from the end of employment or engagement
    Payroll, tax and pension records As required by HMRC and pensions law, generally 6 years
    Right to work evidence 2 years after employment ends
    Complaints and incident records 6 years from closure
    Marketing contact records Until you unsubscribe, then a suppression record indefinitely so we do not contact you again

    At the end of the retention period we securely delete or anonymise the data. Backups are overwritten on their own cycle and deleted data does not persist in backups beyond that cycle.

    amarti holds ISO/IEC 27001:2022 certification for its information security management system, ISO 9001:2015 certification for quality management, and Cyber Essentials certification. Our technical and organisational measures include encryption of data in transit and at rest, multi-factor authentication on all business systems, least-privilege access control with periodic review, endpoint protection and device encryption, logging and monitoring, documented incident response, and security awareness training for everyone who works with us. These are described in our Information Security Policy (AM-POL-014).

    amarti does not make decisions about you by wholly automated means that produce legal effects or similarly significant effects. We do not carry out profiling of individuals for our own purposes.

    Where we build systems for clients that support automated decision-making, the client is the controller and is responsible for the safeguards required by Articles 22A to 22D of the UK GDPR. We raise those safeguards with clients as a matter of professional practice, as set out in our Vulnerable Customer Policy (AM-POL-009).

    Subject to the conditions in the legislation, you have the right to:

    • Be informed about how we use your personal data, which is what this policy is for.
    • Access a copy of the personal data we hold about you.
    • Have inaccurate personal data corrected, and incomplete data completed.
    • Have your personal data erased where there is no good reason for us to keep it.
    • Restrict how we use your data while a concern is being resolved.
    • Receive certain data you gave us in a portable, machine-readable format.
    • Object to processing based on legitimate interests, and to object to direct marketing at any time, which we will always honour without question.
    • Withdraw consent where we rely on it.

    To exercise any of these, email james@amarti.io or info@amarti.io. We will respond within one month. If your request is complex or you have made several, we may extend that by up to two further months and will tell you within the first month if we need to. There is no charge unless a request is manifestly unfounded or excessive.

    If you think we have handled your personal data incorrectly, please tell us first. Under section 164A of the Data Protection Act 2018 you have a statutory right to complain directly to us, and we have a duty to handle that complaint properly.

    • You can complain by email to james@amarti.io, through the contact form at www.amarti.io, or by post to our registered office.
    • We will acknowledge your complaint within 30 calendar days of receiving it. In practice we aim to do so within two working days.
    • We will investigate without undue delay, keep you updated on progress, and tell you the outcome and our reasons.

    Full details are in our Customer Complaint Procedure (AM-PRO-001).

    You also have the right to complain to the Information Commissioner’s Office at any time. The ICO can be contacted through its website, on 0303 123 1113, or at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. We would rather have the chance to put things right first, but that is your choice, not ours.

    Our use of cookies and similar technologies is described separately in our Cookie Policy (AM-POL-012), available at www.amarti.io/cookie-policy.

    We review this policy at least annually and whenever our processing changes. The version and date are shown in the document control table above. Where a change materially affects you, we will draw it to your attention rather than relying on you to notice.

    The first point of contact for this document is James Peachey (james@amarti.io). Where a query is best handled by another member of the leadership team, it will be routed as follows:

    Contact Area Email
    Amardeep Sirha, Co-founder Technical, information security and platform matters amardeep@amarti.io