Privacy Policy

NOTTINFRA LIMITED (company number 17052791) respects your privacy and is committed to protecting your personal data. This notice explains what personal data we collect, why, and what rights you have over it.

It's important that the personal data we hold about you is accurate and current — please keep us informed if it changes.

If you're interacting with a specific NOTTINFRA product that has its own privacy notice, that product-specific notice applies in addition to this general policy.

More information about your data protection rights can be found on the Information Commissioner's Office (ICO) website.

1. Who we are

NOTTINFRA LIMITED is the controller responsible for your personal data, unless stated otherwise. For how to reach us, see How to contact us at the end of this notice.

2. How we collect your data

  • Directly from you — when you fill in a form on our website, request a demo, correspond with us, or are set up as a user on a Customer's account.
  • Automatically — technical data about your device and browsing activity, collected via cookies, server logs, and similar technologies as you use our website. See our Cookie Policy for full detail.
  • From third parties or public sources — including our Customers, analytics providers, our hosting and infrastructure providers, and public sources such as Companies House.

3. The personal data we collect and how we use it

We only use your personal data when the law allows. Depending on how you interact with us:

What we collect Why Lawful basis
Contact and account details you give us when requesting a demo or asking a question To respond to you and, where relevant, progress toward a contract Legitimate interests / steps prior to a contract
Login credentials, authentication records, user provisioning and configuration data To operate your account and provide support Performance of a contract
Customer Data we host or process on a Customer's behalf We act as a processor, not a controller — see Section 5 Governed by our Data Processing Agreement
Technical and usage data collected To understand and improve how our services perform Consent (see Section 9)

Marketing. We'll get your opt-in consent before sending marketing communications, or rely on the limited legitimate-interest exceptions available for B2B marketing where permitted. You can opt out anytime by emailing dataprotection@nottinfra.co.uk. Opting out of marketing won't affect communications we need to send you about a contract or other non-marketing matter.

If we want to use your data for a new purpose. We'll only use your data for the purpose we collected it for, unless a new purpose is compatible with the original one — in which case we'll tell you and explain the legal basis. Where the law permits it, we may occasionally process your data without notifying you first.

4. Who we share your data with

We do not sell personal data. We may share it with:

  • Hosting and infrastructure providers, under contract
  • Analytics providers — see our Cookie Policy
  • Professional advisers (accountants, lawyers, auditors) where necessary
  • HMRC, regulators, and other authorities where required by law, regulation, court order, or lawful request
  • A successor business, if we sell, transfer, or merge parts of our business or assets

We require every third party to protect your data and use it only for the purposes we specify — never for their own purposes.

5. Customer Data we process on behalf of clients

Where a Customer's use of our System involves data about their own employees, users, or contacts, we act as a processor for that data, under the terms of our Data Processing Agreement.

If you have a question about Customer Data, please contact the relevant Customer directly — they are the controller of that data, and best placed to help.

6. International transfers

We primarily store and process data within the UK and EEA. Some third parties — including Google, for Google Analytics — are based outside the UK/EEA, so using them involves a transfer of your data.

Whenever we or our infrastructure providers transfer personal data outside the UK/EEA, we use an appropriate safeguard such as the UK International Data Transfer Addendum or the EU Standard Contractual Clauses.

7. Data security

We use appropriate technical and organisational measures to protect your data — including encryption in transit and at rest, access controls, secrets management, and ongoing security monitoring. Access is limited to those who need it, and everyone with access is bound by confidentiality obligations.

If a personal data breach occurs, we have procedures in place to respond, and we'll notify you and any applicable regulator where we're legally required to.

8. Data retention

We keep personal data only as long as necessary for the purpose we collected it, including to meet legal, accounting, or reporting requirements. In deciding how long, we weigh the sensitivity of the data, the risk of harm from misuse, and any applicable legal requirements.

Data category Typical retention
Account and Customer Data For the life of the relevant agreement, plus a limited period after — see our Data Export Following Termination terms
General enquiries and correspondence Up to 6 years
Analytics 12–26 months (see our Cookie Policy)

For anything not listed here, email dataprotection@nottinfra.co.uk. We may anonymise data for statistics, at which point we can keep it indefinitely without further notice.

9. Cookies

Full detail on the cookies we use, their purpose, and duration is in our Cookie Policy. Manage your preferences via the cookie banner or the Change your consent control on that page.

10. Your legal rights

You have the right to:

  • Access — get a copy of the data we hold about you and check we're processing it lawfully.
  • Correction — fix incomplete or inaccurate data (we may need to verify anything new you provide).
  • Erasure — ask us to delete data where there's no good reason to keep it, where you've objected successfully, where we processed it unlawfully, or where the law requires it. We'll explain if we can't comply.
  • Object — to processing based on legitimate interests or for direct marketing. We may show compelling grounds that override your objection.
  • Restrict processing — for example, while we verify accuracy, or while assessing an objection.
  • Data portability — get a structured, machine-readable copy of data you gave us, where we process it by consent or contract.
  • Withdraw consent — at any time, where we rely on consent. This won't affect processing already carried out, but may mean we can no longer provide certain Services.

To exercise any of these, email dataprotection@nottinfra.co.uk.

  • Fees — usually free. We may charge a reasonable fee, or decline, if a request is unfounded, repetitive, or excessive.
  • Identity checks — we may ask for information to confirm who you are, as a security measure.
  • Timing — we aim to respond within one month; complex or multiple requests may take longer, and we'll keep you updated if so.

11. Children

Our website and Services are directed at businesses and not intended for individuals under 18. We do not knowingly collect personal data from children.

12. Changes to this notice

We review this notice regularly and will update the date above if we make significant changes.

How to contact us

If you have questions about this notice, need further information about our privacy practices, or wish to raise a complaint about how we've handled your personal data, contact our Data Protection team, who will investigate the matter.

NOTTINFRA LIMITED — Data Protection dataprotection@nottinfra.co.uk

How to complain

If you're not satisfied with our response, you can complain to our regulator:

The Information Commissioner's Office (ICO) Wycliffe House Water Lane Wilmslow Cheshire SK9 5AF

Tel: 0303 123 1113 www.ico.org.uk/concerns

Appendix: Definitions

Term Meaning
Anonymous data Data from which an individual's identity has been removed, so they can no longer be identified.
Consent Your freely given, specific, informed, and unambiguous agreement to processing — e.g. for non-essential cookies or marketing. You can withdraw it anytime.
Controller The organisation that decides why and how personal data is processed. NOTTINFRA is the controller for data we collect for our own purposes, unless stated otherwise.
Customer A person, company, or organisation with a Software Subscription and Services Agreement (or equivalent) with NOTTINFRA.
Customer Data Personal data about a Customer's own employees, users, or contacts, which we host or process on the Customer's behalf under a signed agreement.
Legitimate interest Our interest in running our business well, balanced against the impact on you. Ask dataprotection@nottinfra.co.uk for detail on a specific assessment.
Legal or regulatory obligation Processing required for us to comply with the law.
Performance of a contract Processing necessary to deliver a contract we have (or are about to have) with you — e.g. providing our Services or billing.
Personal data Any information from which a living individual can be identified. Excludes anonymous data.
Processor An organisation that processes personal data on a controller's documented instructions only.
Services The software, hosting, support, and related services NOTTINFRA supplies to a Customer under a Software Subscription and Services Agreement.
System The software platform(s) NOTTINFRA operates and makes available to Customers and their Users.
User An individual authorised by a Customer to access a System on the Customer's account.

Back to home