Effective 5 August 2026

Privacy notice

This notice explains how ClariFlux Ltd collects, uses, shares and protects personal information when you visit our website, communicate with us, receive business-to-business communications from us, or work with us.

Who is responsible for your information

ClariFlux Ltd is the controller of the personal information described in this notice. We are registered in England and Wales under company number 17376364, with registered office at 128 City Road, London, EC1V 2NX, United Kingdom.

For privacy questions, rights requests or data protection complaints, email legal@clariflux.co.uk.

Information we collect

Depending on how you interact with us, we may collect:

  • Identity and professional contact details, such as your name, job title, employer, business email address, business telephone number and LinkedIn profile.
  • Business and enquiry information, such as your organisation, engineering context, recruitment plans, delivery challenges, areas of interest and the contents of messages, calls or meeting notes.
  • Booking and relationship information, including meeting details, attendance, correspondence, proposals, preferences, objections and agreed next steps.
  • Client and engagement information, including authorised stakeholder details, interview notes, documents, technical evidence and access records needed to deliver an agreed service.
  • Commercial and financial information, such as contracts, purchase orders, billing contacts, invoices, payments and transaction references. We do not receive your full payment-card details.
  • Website technical information, such as IP address, browser and device information, requested pages, timestamps and security events processed by our hosting and security providers.

We do not intentionally collect special category information or criminal-offence information for sales or marketing. Please do not send such information unless it is genuinely necessary and has been agreed in advance.

Where information comes from

We receive information directly from you when you email, telephone, book a call, attend a meeting, request a proposal or work with us. We may also receive professional information from your employer, colleagues, referrals and introductions.

For carefully targeted business-to-business outreach, we may use professional information made public through LinkedIn, company websites, job advertisements, Companies House and professional directories. We use this to identify people whose professional responsibilities appear relevant to ClariFlux services. We currently contact limited companies and their professional representatives only, and we do not buy personal information from contact-data or email-enrichment databases.

Where we obtain information from another source, we normally provide access to this notice in or alongside our first communication and, in any event, within the period required by data protection law.

How and why we use information

Enquiries, meetings and proposals

We use information to respond to enquiries, arrange diagnostic calls, understand your organisation's needs, decide whether our services are suitable and prepare proposals. We rely on our legitimate interests in operating the business and responding to prospective clients, and on steps requested before entering a contract where that basis applies.

Delivering services and managing client relationships

We use information to plan and deliver engagements, communicate with authorised stakeholders, produce agreed outputs, manage access, administer contracts and maintain appropriate client records. We rely on our legitimate interests in delivering and administering services, performance of a contract where the individual is a party to it, and legal obligations where applicable.

Relevant business-to-business outreach

We may contact professional representatives of limited companies by business email, LinkedIn message or telephone where we reasonably believe the communication is relevant to their role. We rely on our legitimate interests in developing ClariFlux and bringing relevant services to the attention of organisations that may benefit from them, subject to applicable direct-marketing and electronic-communications rules.

We consider the relevance, likely expectations and potential impact of an approach before contacting someone. We do not use personal information for indiscriminate mass marketing.

Administration, security and legal compliance

We use information to issue invoices, maintain accounting and tax records, protect our website and systems, prevent misuse, establish or defend legal claims, handle rights requests and complaints, and meet legal or regulatory obligations. We rely on legal obligations and our legitimate interests in operating securely and protecting the business and others.

Your right to object to direct marketing

You may ask us at any time to stop using your personal information for direct marketing. Reply to the relevant message, use any opt-out method provided, or email legal@clariflux.co.uk. We will stop the marketing and may retain limited details on a suppression list solely so that we continue to respect your preference.

Client engagement data

During an engagement, ClariFlux may receive read-only access to delivery systems, records and documentation. The permitted scope, security requirements, access method and retention arrangements are agreed in the statement of work or related contractual terms.

Client-identifying material, personal data and interview content are not entered into public or general-purpose AI tools. Any software-assisted analysis of anonymised or aggregated technical information is disclosed in advance and recorded in the statement of work.

In some engagements, the client is the controller and ClariFlux processes information only on the client's documented instructions. In that situation, the client's privacy information applies to the underlying processing and our contract sets out our processor obligations.

Who we share information with

We share information only where necessary for the purposes described above. Recipients may include:

  • Microsoft, for Microsoft 365, Outlook email, Bookings, Teams, Excel, OneDrive and SharePoint;
  • Cloudflare, which hosts, delivers and protects this website;
  • Google, because this website currently requests externally hosted Google Fonts;
  • FreeAgent and NatWest, for accounting, invoicing, banking and payment administration;
  • professional advisers, including accountants, solicitors and insurers;
  • contractors or service providers working under appropriate confidentiality and data-protection obligations; and
  • courts, regulators, law-enforcement bodies or other parties where disclosure is required by law or needed to protect legal rights.

We do not sell personal information.

International transfers

Some suppliers may store or access information outside the United Kingdom. Where a transfer is not covered by UK adequacy regulations, we require an appropriate safeguard where required by law, such as approved contractual protections, and any supplementary measures considered necessary. You may contact us for further information about the safeguards relevant to your information.

How long we keep information

We keep personal information only for as long as reasonably required for its purpose, taking account of legal, accounting, contractual and dispute-resolution needs. Our usual periods are:

  • Unconverted enquiries and prospect records: 24 months after the last meaningful interaction.
  • Unsuccessful proposals and diagnostic-call notes: 24 months after the opportunity is closed.
  • Engagement working evidence: active working copies are normally deleted within 90 days after final delivery unless a different period is agreed or retention is required for a legal reason. Residual protected backups may expire through normal backup cycles.
  • Final deliverables and core client records: normally six years after the engagement ends, unless a different contractual or legal period applies.
  • Contracts, invoices and accounting records: at least six years where required for tax, company or accounting purposes.
  • Marketing suppression records: for as long as needed to continue respecting the objection.
  • Website security and operational logs: according to the normal retention settings of the relevant hosting or security provider.

Website, cookies and external services

This website is hosted on Cloudflare Pages. Cloudflare may process IP addresses, request details and security information to deliver and protect the site. ClariFlux does not currently use website analytics, advertising pixels, behavioural tracking, session recording or non-essential marketing cookies.

The site loads fonts from Google, which means your browser may connect to Google's servers and disclose technical information such as your IP address and browser details. Booking links take you to Microsoft Bookings, where Microsoft's own privacy information also applies. Email links open your email application; the website itself does not submit an enquiry form to a ClariFlux server.

If we introduce analytics, advertising technologies or other non-essential storage, we will update this notice and, where required, ask for consent before those technologies are used.

Security

We use proportionate technical and organisational measures intended to protect personal information, including controlled access, secure business accounts, multi-factor authentication where available, limited-access storage and access removal when it is no longer required. No system can be guaranteed completely secure.

Is information required?

Providing information for an initial enquiry is voluntary, but we need enough information to respond and arrange a call. Certain stakeholder, contractual and billing details are required to enter into and administer an engagement. If required information is not provided, we may be unable to respond, contract with your organisation or deliver the service.

Automated decisions

We do not use personal information to make solely automated decisions that produce legal or similarly significant effects.

Your data protection rights

Depending on the circumstances, you may have the right to ask us for access to your personal information, correction, erasure, restriction, portability, or to object to its use. Where we rely on consent, you may withdraw it at any time. These rights can be subject to legal conditions and exceptions.

To exercise a right, email legal@clariflux.co.uk. We may need to confirm your identity and clarify your request. We normally respond within one month, although the law permits an extension in some circumstances.

Data protection complaints

You can complain about how we have handled your personal information by emailing legal@clariflux.co.uk. We will acknowledge a data protection complaint within 30 days, investigate it appropriately, keep you informed where needed and communicate the outcome without undue delay.

You also have the right to complain to the Information Commissioner's Office. Further information is available at ico.org.uk/make-a-complaint. We would appreciate the opportunity to address your concern first, but you are not required to contact us before approaching the ICO.

Changes to this notice

We may update this notice when our services, suppliers, practices or legal obligations change. The latest version will be published on this page with its effective date.

Contact

ClariFlux Ltd
128 City Road
London
EC1V 2NX
United Kingdom

Company number: 17376364
Email: legal@clariflux.co.uk