Privacy Policy
How amarti Ltd collects, uses and protects personal data.
| Document control | |
|---|---|
| Reference | AM-POL-013 |
| Version | 1.0 |
| Classification | Public |
| Owner | James Peachey, Co-founder |
| Approved by | James Peachey, Co-founder, on 2 September 2026 |
| Next review | 2 September 2027 |
| Applies to | Website visitors, clients, candidates, suppliers and associates |
| Standards alignment | UK GDPR; Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025); PECR |
1. Who we are
Section titled “1. Who we are”amarti Ltd (“amarti”, “we”, “us”) is a UK software and data engineering consultancy. We are registered in England and Wales under company number 12543976, with a registered office at 61 Westway, Caterham, England, CR3 5TQ.
For the personal data described in this policy, amarti Ltd is the data controller. Our data protection lead is James Peachey, Co-founder, who can be contacted at james@amarti.io or through info@amarti.io. amarti is not required to appoint a statutory Data Protection Officer and has not done so.
This policy explains what personal data we collect, why, what we do with it, how long we keep it, and what rights you have. It reflects the UK GDPR and the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025.
2. When we are a controller and when we are a processor
Section titled “2. When we are a controller and when we are a processor”This distinction matters, so we state it plainly.
For the personal data of our own website visitors, client contacts, candidates, employees, associates and suppliers, amarti is the controller. This policy applies and you should contact us directly.
When we build, operate or support a data platform for a client, we normally process personal data on that client’s instructions. In that situation the client is the controller and amarti is the processor. Our client’s own privacy notice applies, not this one, and we act only on their documented instructions under a written data processing agreement meeting Article 28 of the UK GDPR.
If you contact us about data we hold as a processor, we will tell you promptly and pass your request to the client controller so they can respond.
3. What we collect and why
Section titled “3. What we collect and why”| Who you are | What we collect | Why | Lawful basis |
|---|---|---|---|
| Website visitor | Pages viewed, referring source, approximate location, device and browser information, only if you allow analytics | To understand how the site is used and improve it | Consent (and consent under PECR for the analytics cookies) |
| Enquirer | Name, employer, job title, email, phone, and the content of your enquiry | To respond to you and, where relevant, discuss how we might work together | Legitimate interests: responding to a request you made |
| Client contact | Name, job title, business contact details, correspondence, engagement records, meeting notes | To deliver the engagement, manage the relationship, invoice and meet our contractual and record-keeping obligations | Contract and legitimate interests |
| Candidate | CV, work history, qualifications, right to work evidence, interview notes, references | To assess your application and, if successful, prepare to employ or engage you | Legitimate interests, steps prior to a contract, and legal obligation for right to work |
| Employee, contractor or associate | Full HR record including contact details, payroll and pension data, absence records, performance notes, and where relevant health information for adjustments and sickness | To employ or engage you, pay you, meet employment and tax law obligations and protect health and safety | Contract, legal obligation, legitimate interests, and (for health data) employment law obligations under Article 9(2)(b) and Schedule 1 DPA 2018 |
| Supplier contact | Name, business contact details, contract and payment details, due diligence responses | To manage the supplier relationship and meet our assurance obligations | Contract and legitimate interests |
| Marketing recipient | Name, employer, business email, engagement with our communications | To send occasional insight and event information about our services | Legitimate interests, subject to PECR and an unsubscribe link in every message |
Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that our interests do not override your rights and freedoms. You can ask us for a summary of that assessment. Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal.
The Data (Use and Access) Act 2025 introduced a category of recognised legitimate interests for which no balancing test is required, such as processing necessary for safeguarding vulnerable individuals or responding to an emergency. We would rely on this only in the narrow circumstances the law provides for, and we do not use it for marketing.
4. Where the data comes from
Section titled “4. Where the data comes from”Most of the personal data we hold comes directly from you. We also obtain data from your employer where you are our client contact, from recruitment agencies and referrers where you are a candidate or associate, from publicly available professional sources such as LinkedIn and company websites when researching prospective clients, and from our clients where we act as their processor.
5. Who we share it with
Section titled “5. Who we share it with”We do not sell personal data and we do not share it for anyone else’s marketing. We share it only where there is a clear reason to:
- Service providers who process data on our behalf under a written contract: our cloud productivity and collaboration platform, cloud infrastructure providers, accounting and payroll providers, our HR system, our website analytics provider, and IT support.
- Clients, where you are a consultant we are placing on an engagement and they need to know who is working on their account.
- Professional advisers (accountants, lawyers, insurers and our certification body) where they need it to advise or audit us.
- Regulators, law enforcement or other authorities where we are legally required to disclose, or to establish, exercise or defend legal claims.
- A purchaser or successor, if amarti is sold or reorganised. We would tell you if that happened and the same protections would apply.
Every processor we use is bound by a contract meeting Article 28 of the UK GDPR, is assessed under our Supplier Relationship Policy before engagement, and may not use your data for their own purposes. A current list of our processors is available on request.
6. International transfers
Section titled “6. International transfers”We prefer to keep personal data in the UK or the European Economic Area, and we configure our cloud services for UK or EEA regions where the service allows it.
Where a transfer outside the UK is necessary, for example because a service provider offers support from another country, we make sure it is covered by one of the safeguards permitted by Chapter V of the UK GDPR: a UK adequacy determination, the International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment. Details of the safeguards applying to a specific transfer are available on request.
7. How long we keep it
Section titled “7. How long we keep it”| Record | Retention period |
|---|---|
| Website analytics data | Up to 14 months from collection |
| Enquiries that do not lead to a relationship | 12 months from last contact |
| Client engagement records and correspondence | 6 years from the end of the engagement |
| Contracts and commercial records | 6 years from expiry or termination |
| Unsuccessful candidate records | 6 months from the decision, unless you agree to us keeping them longer |
| Employee and associate records | 6 years from the end of employment or engagement |
| Payroll, tax and pension records | As required by HMRC and pensions law, generally 6 years |
| Right to work evidence | 2 years after employment ends |
| Complaints and incident records | 6 years from closure |
| Marketing contact records | Until you unsubscribe, then a suppression record indefinitely so we do not contact you again |
At the end of the retention period we securely delete or anonymise the data. Backups are overwritten on their own cycle and deleted data does not persist in backups beyond that cycle.
8. How we protect it
Section titled “8. How we protect it”amarti holds ISO/IEC 27001:2022 certification for its information security management system, ISO 9001:2015 certification for quality management, and Cyber Essentials certification. Our technical and organisational measures include encryption of data in transit and at rest, multi-factor authentication on all business systems, least-privilege access control with periodic review, endpoint protection and device encryption, logging and monitoring, documented incident response, and security awareness training for everyone who works with us. These are described in our Information Security Policy (AM-POL-014).
9. Automated decision-making
Section titled “9. Automated decision-making”amarti does not make decisions about you by wholly automated means that produce legal effects or similarly significant effects. We do not carry out profiling of individuals for our own purposes.
Where we build systems for clients that support automated decision-making, the client is the controller and is responsible for the safeguards required by Articles 22A to 22D of the UK GDPR. We raise those safeguards with clients as a matter of professional practice, as set out in our Vulnerable Customer Policy (AM-POL-009).
10. Your rights
Section titled “10. Your rights”Subject to the conditions in the legislation, you have the right to:
- Be informed about how we use your personal data, which is what this policy is for.
- Access a copy of the personal data we hold about you.
- Have inaccurate personal data corrected, and incomplete data completed.
- Have your personal data erased where there is no good reason for us to keep it.
- Restrict how we use your data while a concern is being resolved.
- Receive certain data you gave us in a portable, machine-readable format.
- Object to processing based on legitimate interests, and to object to direct marketing at any time, which we will always honour without question.
- Withdraw consent where we rely on it.
To exercise any of these, email james@amarti.io or info@amarti.io. We will respond within one month. If your request is complex or you have made several, we may extend that by up to two further months and will tell you within the first month if we need to. There is no charge unless a request is manifestly unfounded or excessive.
11. Complaints
Section titled “11. Complaints”If you think we have handled your personal data incorrectly, please tell us first. Under section 164A of the Data Protection Act 2018 you have a statutory right to complain directly to us, and we have a duty to handle that complaint properly.
- You can complain by email to james@amarti.io, through the contact form at www.amarti.io, or by post to our registered office.
- We will acknowledge your complaint within 30 calendar days of receiving it. In practice we aim to do so within two working days.
- We will investigate without undue delay, keep you updated on progress, and tell you the outcome and our reasons.
Full details are in our Customer Complaint Procedure (AM-PRO-001).
You also have the right to complain to the Information Commissioner’s Office at any time. The ICO can be contacted through its website, on 0303 123 1113, or at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. We would rather have the chance to put things right first, but that is your choice, not ours.
12. Cookies and changes to this policy
Section titled “12. Cookies and changes to this policy”Our use of cookies and similar technologies is described separately in our Cookie Policy (AM-POL-012), available at www.amarti.io/cookie-policy.
We review this policy at least annually and whenever our processing changes. The version and date are shown in the document control table above. Where a change materially affects you, we will draw it to your attention rather than relying on you to notice.
Questions about this document
Section titled “Questions about this document”The first point of contact for this document is James Peachey (james@amarti.io). Where a query is best handled by another member of the leadership team, it will be routed as follows:
| Contact | Area | |
|---|---|---|
| Amardeep Sirha, Co-founder | Technical, information security and platform matters | amardeep@amarti.io |