Initializing Infrastructure
Legal Document

Privacy Policy

Last updated: 17 June 2026

RamX Web Solutions Ltd (trading as RamX Digital) is committed to protecting your privacy. This policy explains what personal information we collect, why, who we share it with, how long we keep it, and the rights you have under UK data protection law.

01. What We Collect

Information You Provide

  • Contact details (name, email, phone, website URL) from our forms
  • Project details you share (budget, timeline, enquiry type)
  • Business information shared during consultations
  • Direct email correspondence and project briefs

Collected Automatically

  • Usage data (pages visited, time on site, interactions) — only with your analytics consent
  • Device information (IP address, browser type, OS)
  • Referral sources and navigation paths

We do not collect special category data, and we do not knowingly collect data from children. We do not take payments through this website.

02. How We Use Your Information

  • To respond to enquiries and deliver agreed-upon services
  • To send requested audits, technical reports, and proposals
  • To communicate about ongoing project milestones
  • To keep our site secure and prevent spam and fraudulent submissions
  • To understand and improve website performance (with your consent)
  • To comply with our legal and regulatory obligations

Our Promise: We will never sell your personal information. Your data is used solely to conduct business with you and to run our website.

03. Our Legal Bases (UK GDPR)

Under Article 6 of the UK GDPR we must have a lawful basis for each purpose. The basis we rely on depends on what we are doing:

What we do Lawful basis
Provide a service you have engaged us for, and take steps at your request before entering a contract Contract — Art 6(1)(b)
Respond to general enquiries, run and secure our business, prevent spam/fraud, and send relevant business-to-business updates to existing contacts Legitimate interests — Art 6(1)(f)
Set analytics cookies and similar measurement technologies Consent — Art 6(1)(a) / PECR
Keep accounting and tax records Legal obligation — Art 6(1)(c)

Where we rely on legitimate interests, we have carried out a balancing assessment and will provide a summary on request. Where we rely on consent, you can withdraw it at any time without affecting earlier processing.

04. Cookies & Analytics

We use strictly necessary cookies to run the site (these do not need consent) and, only with your consent, analytics cookies from Google Analytics and Microsoft Clarity to measure how the site is used. No analytics technology runs until you accept it, and you can change or withdraw your choice at any time.

Read our full Cookie Policy

05. Data Retention

Data Type Retention Period
Enquiry Data 2 years from last contact
Client Project Data 6 years after contract termination
Accounting & Tax Records 6 years (HMRC requirement)
Analytics Data 26 months

06. Who We Share Your Data With

We do not sell your data. We share it only with trusted service providers (processors) who help us run our business, and only as necessary. Each operates under its own privacy terms and a data processing agreement with us.

Provider Purpose Region
Hostinger Website & server hosting EU / UK
Resend Sending our enquiry/confirmation emails USA
Cloudflare (Turnstile) Anti-spam / bot protection on forms USA / global
Google (Analytics) Website analytics (consent only) USA
Microsoft (Clarity) Website analytics (consent only) USA
Calendly Booking calls, if you choose to book USA

We may also disclose data where required by law or to establish, exercise or defend legal claims.

07. International Transfers

Some of our providers are based outside the UK. We make sure every international transfer is protected by an appropriate safeguard under UK data protection law:

  • Hosting (Hostinger) is located in a UK or EU region, so your hosting data stays within the UK/EEA; any onward transfer relies on the EU Standard Contractual Clauses and the UK International Data Transfer Agreement.
  • US-based providers (Resend, Cloudflare, Google, Microsoft and Calendly) are certified under the UK Extension to the EU-US Data Privacy Framework (the 'UK-US Data Bridge'), backed by the UK Addendum to the EU Standard Contractual Clauses in their data processing terms.

You can ask us which safeguard applies to a particular provider.

08. Your Rights Under UK GDPR

Access

Request a copy of the personal data we hold about you.

Rectification

Correct any inaccurate or incomplete personal data.

Erasure

Request deletion of your data ('right to be forgotten').

Restrict

Request that we limit how we use your personal data.

Portability

Receive your data in a structured, portable format.

Object

Object to processing based on legitimate interests, and to direct marketing at any time.

Withdraw Consent

Where we rely on consent (e.g. analytics), withdraw it at any time.

We will respond to any request within one month. For an access request, we will carry out a reasonable and proportionate search, and—where we genuinely need more information to find your data or verify your identity—we may ask you to clarify your request, which can pause that one-month period until you reply.

09. How to Make a Complaint

If you are unhappy with how we have handled your personal data, you have the right to complain to us directly, and we want to put things right.

1

How to complain: email us at cisco@ramxdigital.com, or write to our registered address below. You can also ask us for a simple complaint form.

2

Acknowledgement: we will acknowledge your complaint within 30 days of receiving it.

3

Our response: we will look into it and tell you the outcome without undue delay, keeping you informed of progress along the way.

4

Escalating to the ICO: if you are not satisfied with our response, you can complain to the Information Commissioner's Office (ICO), the UK regulator, at ico.org.uk/make-a-complaint, by calling 0303 123 1113, or by writing to Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. We would, however, appreciate the chance to resolve your concerns first.

10. Data Controller & ICO Registration

RamX Web Solutions Ltd (registered in England and Wales, Companies House no. 16953804), trading as RamX Digital, is the data controller responsible for your personal information.

Registered Address

3 Dunscombe Cottages, Newton St. Cyres,
Exeter, EX5 5BB, United Kingdom

ICO Registration

Registered with the Information Commissioner's Office under the Data Protection Act 2018. Reference: ZC159587

For any data-protection enquiry, contact us at cisco@ramxdigital.com.

Data Security

We implement appropriate technical and organisational measures—including TLS/SSL encryption, secure access controls, and regular reviews—to protect your data against unauthorised access, alteration, disclosure, or destruction.

Changes to This Policy

We may update this policy from time to time. The 'last updated' date at the top shows when it last changed. Material changes will be reflected here.

Change Log

  • 17 Jun 2026 — Added complaints procedure (DPA 2018 s.164A); mapped lawful bases per purpose; named processors and international transfers; expanded rights (consent withdrawal, access-request handling); linked to a dedicated Cookie Policy.
  • May 2026 — Previous version.

Questions?

If you have any questions regarding this policy, please contact us at cisco@ramxdigital.com

Step 1 of 3