Privacy Policy
Last updated: 2 August 2026RamX Web Solutions Ltd (trading as RamX Digital) is committed to protecting your privacy. This policy explains what personal information we collect, why, who we share it with, how long we keep it, and the rights you have under UK data protection law.
01. What We Collect
Information You Provide
- → Contact details (name, email, phone, website URL) from our forms
- → Project details you share (budget, timeline, enquiry type)
- → Business information shared during consultations
- → Direct email correspondence and project briefs
Collected Automatically
- → Aggregate page views and referrers, with no cookie and no identifier that could link them back to you
- → Standard server logs (IP address, browser, page requested), kept for security and troubleshooting and rotated on the schedule in section 05
We do not collect special category data, and we do not knowingly collect data from children. We do not take payments through this website.
02. How We Use Your Information
- → To respond to enquiries and deliver agreed-upon services
- → To send requested audits, technical reports, and proposals
- → To communicate about ongoing project milestones
- → To follow up about an enquiry you made, which you can opt out of at any time
- → To keep our site secure and prevent spam and fraudulent submissions
- → To understand and improve website performance, using aggregate figures that identify nobody
- → To comply with our legal and regulatory obligations
Our Promise: We will never sell your personal information. Your data is used solely to conduct business with you and to run our website.
03. Our Legal Bases (UK GDPR)
Under Article 6 of the UK GDPR we must have a lawful basis for each purpose. The basis we rely on depends on what we are doing:
| What we do | Lawful basis |
|---|---|
| Provide a service you have engaged us for, and take steps at your request before entering a contract | Contract — Art 6(1)(b) |
| Respond to general enquiries, follow up about an enquiry, run and secure our business, prevent spam/fraud, and send relevant business-to-business updates to existing contacts. Every such message carries a clear way to opt out, honoured on receipt | Legitimate interests — Art 6(1)(f) |
| Measure aggregate visitor numbers, with no cookie and no identifier | Legitimate interests — Art 6(1)(f). PECR reg. 6 does not apply: nothing is stored on or read from your device |
| Keep accounting and tax records | Legal obligation — Art 6(1)(c) |
Where we rely on legitimate interests, we have carried out a balancing assessment and will provide a summary on request. There is currently no processing on this site for which we rely on consent: there are no analytics or advertising cookies to agree to, which is why you were never shown a banner. If that ever changes, we will ask first and the consent will be withdrawable at any time, without affecting anything processed before you withdrew it.
04. Cookies & Analytics
This site sets no cookies of its own, and none for analytics or advertising. Visitor numbers are measured with Cloudflare Web Analytics, which stores nothing on your device, assigns you no identifier and cannot follow you to other sites. We use no session recording, no heatmaps and no advertising pixels. The one thing that can write to your device is the anti-bot check on our forms, which is strictly necessary and exempt from consent. That is why you were never asked to accept anything.
Read our full Cookie Policy05. Data Retention
| Data Type | Retention Period |
|---|---|
| Enquiry Data | 2 years from last contact |
| Client Project Data | 6 years after contract termination |
| Accounting & Tax Records | 6 years (HMRC requirement) |
| Server logs (IP addresses) | Up to 30 days, then rotated |
| Analytics Data | Aggregated and anonymous by design. No personal data is retained, so there is nothing to delete |
06. Who We Share Your Data With
We do not sell your data. We share it only with trusted service providers (processors) who help us run our business, and only as necessary. Each operates under its own privacy terms and a data processing agreement with us.
| Provider | Purpose | Region |
|---|---|---|
| Hostinger | Website & server hosting | EU / UK |
| Resend | Sending our enquiry/confirmation emails | USA |
| Cloudflare (Turnstile) | Anti-spam / bot protection on forms | USA / global |
| Cloudflare (Web Analytics) | Aggregate visitor counts. No cookies, no identifier, nothing stored on your device | Global |
| Calendly | Booking calls, if you choose to book | USA |
We may also disclose data where required by law or to establish, exercise or defend legal claims.
07. International Transfers
Some of our providers are based outside the UK. We make sure every international transfer is protected by an appropriate safeguard under UK data protection law:
- → Hosting (Hostinger) is located in a UK or EU region, so your hosting data stays within the UK/EEA; any onward transfer relies on the EU Standard Contractual Clauses and the UK International Data Transfer Agreement.
- → US-based providers (Resend, Cloudflare and Calendly) are certified under the UK Extension to the EU-US Data Privacy Framework (the 'UK-US Data Bridge'), backed by the UK Addendum to the EU Standard Contractual Clauses in their data processing terms.
You can ask us which safeguard applies to a particular provider.
08. Your Rights Under UK GDPR
Access
Request a copy of the personal data we hold about you.
Rectification
Correct any inaccurate or incomplete personal data.
Erasure
Request deletion of your data ('right to be forgotten').
Restrict
Request that we limit how we use your personal data.
Portability
Receive your data in a structured, portable format.
Object
Object to processing based on legitimate interests, and to direct marketing at any time.
Complain
Complain to us first, and to the ICO if we do not put it right. How to complain.
We will respond to any request within one month. For an access request, we will carry out a reasonable and proportionate search, and, where we genuinely need more information to find your data or verify your identity, we may ask you to clarify your request, which can pause that one-month period until you reply.
To exercise any right, email cisco@ramxdigital.com09. How to Make a Complaint
If you are unhappy with how we have handled your personal data, you have the right to complain to us directly, and we want to put things right.
- 1
How to complain: email us at cisco@ramxdigital.com, or write to our registered address below. You can also ask us for a simple complaint form.
- 2
Acknowledgement: we will acknowledge your complaint within 30 days of receiving it.
- 3
Our response: we will look into it and tell you the outcome without undue delay, keeping you informed of progress along the way.
- 4
Escalating to the ICO: if you are not satisfied with our response, you can complain to the Information Commissioner's Office (ICO), the UK regulator, at ico.org.uk/make-a-complaint, by calling 0303 123 1113, or by writing to Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. We would, however, appreciate the chance to resolve your concerns first.
10. Data Controller & ICO Registration
RamX Web Solutions Ltd (registered in England and Wales, Companies House no. 16953804), trading as RamX Digital, is the data controller responsible for your personal information.
Registered Address 3 Dunscombe Cottages, Newton St Cyres,
Exeter, EX5 5BB, United Kingdom
Registered with the Information Commissioner's Office under the Data Protection Act 2018. Reference: ZC159587
For any data-protection enquiry, contact us at cisco@ramxdigital.com.
Data Security
We implement appropriate technical and organisational measures, including TLS/SSL encryption, secure access controls and regular reviews, to protect your data against unauthorised access, alteration, disclosure, or destruction.
Changes to This Policy
We may update this policy from time to time. The 'last updated' date at the top shows when it last changed. Material changes will be reflected here.
Change Log
- 2 Aug 2026 — Brought the date on this policy back in line with what the site actually does. July's changes were never reflected here: Google Analytics 4 and the consent banner were removed on 25 July 2026, so the analytics retention period and the references to consent no longer described anything real. Added server log retention (30 days), split the duplicated 'Object' right into Object and Complain, and removed Google and Microsoft from the list of US providers, since neither processes anything for this site.
- 17 Jun 2026 — Added complaints procedure (DPA 2018 s.164A); mapped lawful bases per purpose; named processors and international transfers; expanded rights (consent withdrawal, access-request handling); linked to a dedicated Cookie Policy.
- May 2026 — Previous version.
Questions?
If you have any questions regarding this policy, please contact us at cisco@ramxdigital.com
