Skip to main content
VEXBE No. 17005285

Interface specification

Privacy notice

VEXBE LTD Company number 17005285 Issue date 15 August 2026 Revision 1.0

Section 1

Notation, and why a notice is written this way

This company specifies interfaces for a living. An interface contract names two endpoints, states which way each field travels, fixes what may cross and what may not, and says what happens when the flow fails. A privacy notice answers exactly the same questions about you. So this one is drafted in the same notation rather than in the softer register most notices use, and it can be audited the same way.

Each numbered interface below carries a header block with six lines. Endpoints names the two parties. Direction says which way the payload travels. Payload lists the fields that actually cross. Authorisation cites the Article that permits the flow. Guarantee is what this company undertakes about the flow. Expiry is the condition on which the stored payload is destroyed.

Article numbers refer to the UK GDPR, meaning the General Data Protection Regulation as retained in domestic law by the European Union (Withdrawal) Act 2018 and amended for the United Kingdom, read alongside the Data Protection Act 2018. Where another statute governs, it is named at the point of use.

Two things follow from the notation that are worth saying plainly. An interface not listed here does not exist; if a flow of your personal data is not specified below, it is not running. And a guarantee written into a header block is a commitment this company can be held to, not a description of current habit.

Section 2

Endpoint identity: the party publishing this

VEXBE LTD carries company number 17005285 on the register for England and Wales, where it is incorporated as a private limited company. Throughout this document "the company" and "VEXBE" refer to that legal person and to nobody else. Its registered office is recorded against that number on the public register kept by Companies House, and that address is the one with statutory effect when a document is formally served.

Every data protection matter routes through one address: [email protected]. Put "Data protection request" at the front of the subject line and it lands in the right queue immediately. Formal notice may instead be served by post at the registered office; that path works, but it is forwarded post, so it is measured in days where the mailbox is measured in hours.

Article 37 sets out when a data protection officer becomes mandatory, and none of its three triggers reaches this company. No public authority is exercised. The core activity is integration engineering, not monitoring people at scale. Neither of the heightened-risk categories described at section 10 is handled at volume. Accountability therefore sits with the company's officers, whose particulars are published by Companies House against company number 17005285.

Establishment is in the United Kingdom, and the services are offered to organisations located here. Nothing about that offering targets people living across the European Economic Area in the way Article 3(2) of the EU GDPR contemplates, which is why no Article 27 representative has been appointed. Should the reach of the business change, this section changes ahead of the activity rather than after it.

Section 3

The role boundary, and which side you address

Data protection law splits responsibility across a single line. On one side stands the party that decides the purpose of a processing operation and the means of carrying it out; on the other stands the party executing that decision under written instruction. VEXBE stands on both sides at different moments, over different payloads, and the sections below are labelled accordingly.

3.1 Where the company decides

For traffic to this website, for correspondence sent to the mailbox, for the records of an engagement it contracts for, and for its own supplier arrangements, VEXBE sets the purpose itself. Interfaces IF-01 through IF-04 sit here, and so do sections 8 and 12 through 19. Requests under section 17 are answered by VEXBE directly.

3.2 Where the company executes

Inside a client engagement, personal data belonging to that client may pass through a system VEXBE is integrating or migrating. Purpose and means belong to the client; VEXBE executes. Interface IF-05 and section 9 govern that arrangement, and a contract satisfying Article 28(3) is signed before the first credential is issued.

3.3 Reading the boundary correctly

The label decides where a request should go. If your relationship is with VEXBE, whether as a correspondent, a client contact or a supplier, address the company directly. If your relationship is with an organisation whose systems VEXBE happens to be working inside, the decision-making party is that organisation, and law prevents VEXBE from acting on your data at its own initiative. Section 9.4 sets out what the company does with a request that arrives at the wrong endpoint, and it is not silence.

Section 4

IF-01, browser to edge network

IF-01 · Visitor browser → content delivery edge

Endpoints: your browser, and the edge network operated by Cloudflare, Inc. on this company's behalf.
Direction: inbound request, outbound file. Nothing is written back to your device by the site itself.
Payload: source address, request timestamp, requested path, response code, byte count, user agent string, referring page.
Authorisation: Article 6(1)(f). Named interest: serving a public web page reliably and keeping automated abuse off it.
Guarantee: the payload is not exported into any record this company keeps, not joined to any other dataset, and not used to build a picture of a visitor.
Expiry: on the hosting provider's own rolling cycle, measured in days.

Role: controller

What makes this interface narrow is that the pages are inert. There is no application server behind them, no account, no session, no comment thread, no embedded player and no measurement tag. The fields listed above are produced by the mechanics of an HTTP request; a static site cannot avoid generating them and this one adds nothing on top.

One further request leaves your browser on each page load, and it is worth separating from the rest because it goes somewhere else. The stylesheet references two typefaces held by Google Fonts, so your browser opens a connection to fonts.googleapis.com and fonts.gstatic.com and discloses its address and headers to Google LLC in doing so. That connection is issued by your browser rather than by any code of ours, but this notice claims it as ours anyway, because the reference in the stylesheet is what causes it. Blocking those two hostnames costs you nothing except the typefaces.

IF-01 field register
Field Originates Consumed for Crosses to
Source address Transport layer of your request Routing the response; rate limiting an abusive source Cloudflare, Inc. only
Path, status, byte count The web server answering Confirming pages are served rather than failing Cloudflare, Inc. only
User agent, referrer Headers your browser chooses to send Distinguishing a reader from an automated crawler Cloudflare, Inc. only
Bot score, rule matches Derived at the edge from the fields above Deciding whether to answer, challenge or drop a request Cloudflare, Inc. only
Font request headers Your browser, resolving the stylesheet Delivering two typefaces to render the page Google LLC, on its own terms

Device storage attached to this interface is covered separately in the cookie notice, which specifies the single strictly necessary item the security layer may write and the reason no consent gate stands in front of it.

Section 5

IF-02, correspondent to mailbox

IF-02 · Correspondent → [email protected]

Endpoints: the person composing a message, and the company mailbox.
Direction: inbound, initiated entirely by you. The company holds no route by which to obtain your details otherwise.
Payload: whatever your message and its headers contain, typically a name, an address, an employer, a role, sometimes a telephone number, and the substance of what you wrote.
Authorisation: Article 6(1)(b) where you write on your own account; Article 6(1)(f) where an employer is behind the message; the interest named is answering business correspondence addressed to this company.
Guarantee: a message is read for the purpose of answering it and for no other purpose. It is never added to a distribution list, never enriched from an outside source, and never passed to a third party for that party's own use.
Expiry: 24 months after the final message in the thread, unless the thread becomes an engagement, in which case section 14 governs.

Role: controller

This is the busiest interface the company operates and it has exactly one entry point. No submission form is published anywhere on the site, which means nothing about you is captured before you decide to press send in a client you control. It also means the record of the exchange sits in two mailboxes rather than one, and you keep your half of it.

Two payload classes are refused at this boundary and it is worth stating them here rather than burying them. Do not send credentials, keys, certificates or database extracts in an opening message; none of that is needed to work out whether the company can help, and holding it would create risk on both sides for no benefit. Do not send special category data about a third party either. If either arrives unsolicited, section 10 sets out what happens to it.

Where a message opens into an engagement, the correspondence continues under the same interface but its expiry condition changes, because the record then evidences what two contracting parties agreed. Contract documents, proposals, acceptance records and billing sit under IF-03 rather than here.

Section 6

IF-03, client organisation to engagement file

IF-03 · Client organisation → engagement file

Endpoints: the contracting organisation and the people who act for it, and the file VEXBE keeps for that piece of work.
Direction: bidirectional. Documents pass both ways and both parties hold a copy.
Payload: signatory name and role, business contact details, decisions recorded in writing, scope and acceptance criteria, variations, purchase references, invoice and payment records, and a note of which accounts were issued to VEXBE on the client estate.
Authorisation: Article 6(1)(b) toward the contracting party; Article 6(1)(f) toward its individual staff, on the named interest of delivering the work and evidencing what was agreed; Article 6(1)(c) for the accounting entries the Companies Act 2006 and tax law compel.
Guarantee: access credentials issued to VEXBE are destroyed when the work closes. The record that access existed survives; the means of using it does not.
Expiry: six years from the close of the engagement, or from the end of the financial year for accounting entries, extended where a dispute is live.

Role: controller

An engagement file exists so that a question asked eighteen months later has an answer. Scope arguments are the ordinary failure mode of consultancy, and they are settled by documents rather than by memory, which is why this interface retains more than the others and retains it longer.

Personal data inside the file is limited to business identity. Names, roles, business addresses, and the substance of professional correspondence. The file does not carry anything about a person's private life, and no assessment of an individual's performance is written into it.

The one asymmetry worth flagging is the accounting subset. Once an invoice is raised, the entries behind it stop being discretionary and become a statutory record. Section 14 gives the period and section 17.4 explains why an erasure request cannot reach them.

Section 7

IF-04, supplier to ledger

IF-04 · Supplier or subcontractor → company ledger

Endpoints: an organisation or individual the company buys from, and the company's own supplier records.
Direction: inbound for onboarding detail, outbound for payment instruction.
Payload: contact name, business address, role, company number where incorporated, contract terms, insurance evidence, bank details for settlement.
Authorisation: Article 6(1)(b) where an individual contracts personally; Article 6(1)(c) where the record is one the law requires; otherwise Article 6(1)(f), on the named interest of running the company's own supply chain competently.
Guarantee: a subcontractor who will touch a client engagement is disclosed to that client in writing before work starts, never afterwards.
Expiry: six years after the relationship or the last engagement worked on, whichever runs later.

Role: controller

Unsolicited approaches sit at the edge of this interface and are treated as a distinct payload class. Sales messages, recruitment approaches and partnership propositions are read once, because correspondence addressed to a company gets read. The interest that justifies reading a message does not extend to keeping it, so anything that does not turn into a genuine supply conversation is removed within six months.

Bank details supplied by a payee are held for settlement and for nothing else. They are never quoted in correspondence, never confirmed by return of email, and any change to them is verified by a channel other than the one carrying the change request.

Section 8

Authorisation register: the lawful bases

Role: controller

Article 6(1) requires an authorisation for every operation, chosen before the operation runs rather than defended afterwards. Four of the six are in use here. The register below is the whole of it.

Authorisation register under Article 6(1)
Authorisation Attached to Scope and limit
Contract, under Article 6(1)(b) IF-02 where you write personally, IF-03, IF-04 where a person contracts in their own name Covers steps taken at your request before a contract exists as well as performance afterwards. Falls away entirely when the contract does
Legal obligation, under Article 6(1)(c) Accounting entries within IF-03 and IF-04; any disclosure compelled by court order or statutory power Fixed by statute, so it cannot be narrowed by agreement or waived on request
Legitimate interests, under Article 6(1)(f) IF-01 in full; IF-02 and IF-03 toward employees of an organisation; IF-04; the record of access having been granted and revoked Each interest is named in the interface header and balanced before reliance. Objectable under section 17.6
Consent, under Article 6(1)(a) Reserved. No operation currently runs on it If ever used it will be an unticked affirmative act, dated, logged, and reversible by a single reply

8.1 The balancing exercise behind Article 6(1)(f)

Legitimate interests is the only basis that requires the controller to weigh its own purpose against your rights and record the result. Four weighings sit behind the register above.

  • Keeping a public page online and defended. The payload is transient request metadata that never leaves the edge provider. Impact on a visitor is close to nothing, and publishing an undefended site is not a serious alternative.
  • Answering a business message. Anyone writing to a company about its services expects a reply, which makes the processing entirely within reasonable expectation. It is bounded by a stated expiry rather than left open.
  • Evidencing a delivered engagement. Confined to business identity and professional correspondence, and the evidential value runs in the client's favour at least as much as the company's.
  • Defending or advancing a legal claim. Narrow by construction, since only material relevant to the claim is retained and it is used for nothing else.

8.2 Bases held in reserve and bases not available

Vital interests under Article 6(1)(d) has no application to a business-to-business consultancy and is not relied on. Public task under Article 6(1)(e) requires official authority, which this company does not exercise. Neither will appear in this register without a corresponding revision recorded in section 22.

Section 9

IF-05, client estate to processor

IF-05 · Client estate → VEXBE, acting under instruction

Endpoints: a client system holding records about that client's own people, and VEXBE personnel working on it.
Direction: read and write inside the client environment. Extraction outward is the exception and requires a written instruction.
Payload: whatever the specified task requires, and nothing beyond it.
Authorisation: the client's own basis as the deciding party, carried into a contract satisfying Article 28(3).
Guarantee: no purpose of VEXBE's own attaches to this payload, at any time, including after the engagement ends.
Expiry: on closure of the task, the client elects between return and destruction, and the signed agreement records which.

Role: processor

9.1 The contract that has to exist first

No credential is issued and no extract is opened before a written processing agreement is signed. That document fixes the subject matter, the duration, the nature and purpose of the work, the categories of record and of person involved, and it binds VEXBE to act only on documented instruction, to impose confidentiality on every person authorised, to apply the measures Article 32 demands, to seek written approval before involving any further party, to assist with individual requests and with Articles 32 to 36, to destroy or hand back once the work closes, and to supply whatever is needed to demonstrate all of that.

9.2 Reducing the surface before reducing the risk

The cheapest control available on an integration project is asking for less. VEXBE requests the narrowest privilege that permits the task, in writing, and prefers a structurally faithful but non-identifying dataset over a production extract wherever the work permits one, which on interface and mapping work it very often does. Where live records are genuinely required the work happens inside the client environment rather than on company hardware. A temporary copy, if unavoidable, is logged when made, given a destruction date when logged, and confirmed destroyed in writing.

9.3 Instructions that get refused

Article 28(3) obliges a processor to speak up when an instruction would break data protection law, and this company does so in writing. Two patterns account for nearly every occurrence. A migration scoped to carry forward records the client can no longer justify keeping, and a test environment to be populated with live records because it is quicker than generating a synthetic set. Both are raised, both are put in writing, and the specific instruction is declined if the client does not resolve it.

9.4 If your data sits in a client system

Your rights are exercised against the organisation that holds the records, because that organisation makes the decisions. Should a request reach VEXBE instead, the company will not act on it, because a processor acting unilaterally on someone's records commits its own breach in doing so. What happens instead: the request is passed to the deciding organisation promptly, you are told that it has been passed on, and that organisation is identified to you wherever its contract permits the disclosure.

9.5 Further parties on an engagement

Nobody outside VEXBE touches client records without the client's prior written approval. A proposed subcontractor is named before starting, held to terms at least as strict as those binding VEXBE, and VEXBE stays answerable to the client for their work. The recipients listed in section 12 belong to the company's own controller-side arrangements and are a separate list; approval of one is not approval of the other.

Section 10

Payload classes refused at the boundary

Role: controller and processor

Article 9(1) marks out a class of data carrying heightened risk: material revealing racial or ethnic origin, political opinion, religious or philosophical conviction or trade union membership, together with genetic material, biometrics used for identification, health information, and anything concerning sex life or sexual orientation. Article 10, read with section 10 of the Data Protection Act 2018, marks out records of criminal offences and convictions.

On the controller side, neither class is sought and neither is knowingly retained. This company's own dealings run on business identity, and there is no field anywhere in its records designed to hold anything from either class. Material of this kind occasionally arrives by accident inside ordinary correspondence, most often a health reason mentioned to explain a delay. Where that happens it is not acted on, not copied anywhere, and goes when the surrounding thread reaches its expiry.

On the processor side the answer depends on the estate. Some sectors hold health records as a matter of course, and a migration in one of them will move them. Where that is the case the processing agreement records the fact explicitly, the client identifies which Article 9(2) condition and which Schedule 1 condition of the Data Protection Act 2018 it relies on, and any additional handling control is settled in writing before a credential exists. Work does not begin on an estate of that kind under a general agreement that fails to name it.

Section 11

Children

Role: controller

Both this website and the practice behind it address organisations and the people who work in them. Nothing here is designed to interest a person under 18, and no information society service is offered to a child within the meaning of section 9 of the Data Protection Act 2018.

Acting as the deciding party, this company holds no data it knows to concern anybody under 18. If you have reason to think otherwise, write to [email protected] and the company will look into it and erase what it finds where erasure is the correct outcome.

An engagement touching children's records is a different question, and one where the client is the deciding party. That client holds the assessment permitting the processing, including whatever consideration the Age Appropriate Design Code requires of it. VEXBE's position on such work is set at the scoping stage: the build proceeds against a synthetic dataset wherever the technology allows one, and the reason for any departure from that is recorded in the processing agreement.

Section 12

Outbound edges: recipients

Role: controller

An outbound edge is any point at which a payload leaves this company for another organisation. Naming those organisations is the only thing that makes the disclosure checkable, so the register below identifies each one rather than describing it as a category. Where an entry gives a role instead of a trading name, the name and the processing location are supplied to any client or correspondent who asks for them.

Outbound edge register, controller side
Recipient Standing Payload crossing Interface Processing location
Cloudflare, Inc. Acts on instruction Request metadata described in IF-01 IF-01 Global edge; a United Kingdom visitor is normally answered from a United Kingdom or European node. See section 13
Google LLC, Google Fonts Decides for itself, over its own service logs Address and headers your browser sends when fetching a typeface IF-01 Global, governed by Google's terms rather than ours
Mailbox provider under contract; named on request Acts on instruction Message bodies, headers and attachments passing through [email protected] IF-02, IF-03, IF-04 Given together with the provider name on request
Accounting software provider under contract; named on request Acts on instruction Billing identity, invoice lines, settlement records IF-03, IF-04 Supplied with the provider name on request
HM Revenue and Customs Decides for itself Whatever a statutory return contains IF-03, IF-04 United Kingdom
Companies House Decides for itself Whatever a statutory filing contains Company records United Kingdom
Solicitors or accountants, where instructed Decide for themselves Material relevant to the advice sought or the claim in issue IF-03 United Kingdom
Named subcontractors, where engaged Act on instruction Strictly what their piece of the work requires IF-04, IF-05 Disclosed to the client at the time of naming

Two edges exist that no register can schedule in advance. One opens where disclosure is compelled, by a court order, by a statutory power, or by a regulator operating inside its own remit; and the second when material is needed to bring or resist a legal claim. Both are used only to the extent the demand actually reaches.

One further edge would open on a sale or reorganisation of the business. An acquirer would receive the records and would be bound to continue handling them on the terms specified here, and anyone materially affected would be told directly rather than through a quiet amendment to this page.

Section 13

Cross-border edges: international transfers

Role: controller and processor

Chapter V treats the United Kingdom border as a boundary that a payload may cross only on one of the routes Articles 45 to 49 provide. Three of those routes are relevant to a company of this size, and each has a precondition attached.

13.1 Adequacy

Section 17A of the Data Protection Act 2018 lets the Secretary of State determine that a destination protects personal data adequately, and a transfer made under such a determination needs no further instrument. The European Economic Area is covered, along with a number of other jurisdictions. A United States organisation certified under the United Kingdom extension of the Data Privacy Framework is covered as well, for as long as its certification is live and reaches the data in question. Where a supplier claims that route the certification is checked rather than assumed.

13.2 The International Data Transfer Agreement

Where no adequacy determination reaches the destination, the instrument used is the IDTA, which the Information Commissioner issues under a power conferred by section 119A of the Data Protection Act 2018. It is a self-contained United Kingdom agreement, and it is the default whenever this company contracts directly with a supplier outside the country.

13.3 The Addendum route

A supplier operating at scale usually runs already on the clauses the European Commission publishes, offering the Commissioner's Addendum on top of them, which converts that instrument into a valid United Kingdom transfer tool. In practice this is the route most often taken, because it is the one already sitting in a large supplier's standard terms. Either instrument is acceptable to this company. A supplier offering neither, and proposing that a general assurance should stand in place of one, is not.

13.4 The precondition attached to both

Neither instrument does the work on its own. Before reliance, this company assesses the destination's law on state access to data, how sensitive the payload actually is, what technical protection surrounds it in transit and at rest, and whether the recipient has practical experience of access demands. Where the assessment does not support the transfer, the response is to find a supplier that keeps the data in the United Kingdom, which at this company's volumes is usually available.

13.5 Which crossings are live today

Cloudflare, Inc. is a United States corporation running a global network, so IF-01 involves processing at whichever node is nearest the visitor. The payload is transient request metadata, and the provider's data processing terms carry the standard contractual clauses together with the Commissioner's Addendum. The typeface request described in IF-01 is issued by your browser directly to Google, though this notice names it because the stylesheet reference causes it. For the mailbox and accounting suppliers in section 12, the processing location is supplied on request alongside the provider name.

13.6 Crossings inside an engagement

Acting as processor, this company does not move a client's records out of the United Kingdom, or out of whatever jurisdiction the client's environment occupies, absent a written instruction from that client. Because the working method keeps data inside the client environment rather than pulling it out, the question arises rarely; when it does, the Chapter V decision belongs to the client and VEXBE implements it.

Section 14

Expiry register: retention

Role: controller

Article 5(1)(e) permits identifiable data to be kept only while it is still needed. A period with no reason attached to it is not a policy but a habit, so every line below carries the reason that fixes it.

Expiry register, controller side
Record class Period Clock starts What fixes it
Invoices, receipts and the accounting entries behind them 6 years Close of the financial year concerned Preservation for six years from creation is imposed on a private company by the Companies Act 2006 at section 388, and value added tax rules demand business records over a comparable span. A statutory floor, immune to a shortening request
Executed contracts, proposals, variations, acceptance records 6 years, extending to 12 for an instrument executed as a deed Close of the engagement Six years on a simple contract, and twelve on a deed, are the periods the Limitation Act 1980 lays down at sections 5 and 8 respectively. The file has to outlive whatever window a claim can still be brought in
Engagement correspondence and written decisions 6 years Close of the engagement Matched to the contractual limitation window, because what the parties agreed frequently lives in an email rather than in the contract
Enquiry threads that did not become work 24 months Final message in the thread Long enough to place a correspondent who returns, short enough that a conversation which went nowhere does not sit in a mailbox indefinitely. Chosen, not compelled
Unsolicited approaches 6 months, often less Arrival Reading a message addressed to the company is justified; storing something nobody asked for and nobody acted on is not
Complaint files 6 years Closure of the complaint Matched to the limitation window, since a complaint is capable of maturing into a claim
Note that access was issued and withdrawn 6 years Close of the engagement Evidence that a privilege was properly authorised and properly removed. The credential itself is destroyed at close and never held for this period
Files created answering an IF-06 request 3 years Completion of the request Sufficient to show the request was handled correctly and in time, and to answer any later challenge to the handling
Breach documentation under Article 33(5) 6 years Creation of the entry Article 33(5) requires documentation adequate for the regulator to verify compliance. Six years lines it up with the other governance records
Edge request logs Days, not months The request itself Held by the hosting provider on its own cycle and never exported into company records. The operational purpose is exhausted almost immediately
Client records held under IF-05 Set by the client Close of the task or the engagement The period is not this company's to set. The processing agreement provides for return or deletion at the client's election, and working copies go at the end of the task

A period that expires while the record is caught by a live dispute, a regulatory enquiry or a legal hold does not trigger destruction; the record survives until that concludes and is destroyed then. Destruction means removal from live systems. Backup sets are not opened and edited to extract a single row, because that operation is not reliable; those copies fall away on the backup cycle instead. The limitation is stated here rather than papered over.

Section 15

Channel guarantees: security

Role: controller and processor

Article 32 asks for measures proportionate to the risk actually presented. The measures below apply to the company's own records and to the privileges it is issued on a client estate.

  • Transport to this site is encrypted and enforced, with strict transport security asserted, framing and content type sniffing refused at the header, referrer information trimmed, and a content security policy limiting which hosts a page is permitted to contact.
  • Nothing sits behind the published pages: no database, no application code executing on a server, no administrative surface reachable from the internet. That absence removes the attack classes behind most website compromise.
  • Every company account uses a distinct generated secret held in a password manager, with a second authentication factor enabled wherever the provider offers one.
  • Company machines run full-disk encryption, lock automatically, and stay on operating system versions still receiving security updates.
  • Privilege on a client estate is requested at the narrowest scope that permits the task, authorised in writing by someone entitled to authorise it, and confirmed withdrawn at the close.
  • Client records are not routinely copied onto company machines; an unavoidable working copy is logged, dated for destruction, and confirmed destroyed in writing.
  • Every person authorised to touch personal data on this company's behalf, subcontractors included, is under a written confidentiality obligation before they touch it.

Measures reduce the probability of failure without reaching zero, and a specification that stops here would be incomplete. Section 16 is the failure path.

Section 16

The failure path: personal data breaches

Role: controller and processor

The statutory definition is broader than most people assume. A breach is any security failure that destroys, loses, alters, discloses or opens access to personal data without authorisation, whether or not anyone intended it. A message sent to the wrong recipient qualifies. So does a mislaid laptop, and so does a deletion nobody meant to run.

16.1 Reporting a suspected failure

Write to [email protected] with "Security" at the front of the subject. A report that turns out to be a false alarm costs this company very little and is welcome on that basis. Once the company is aware, the first steps are containment, then establishing which records and how many people are involved, then recording the moment awareness began, because the Article 33 clock runs from awareness and not from the incident.

16.2 Reporting to the regulator, Article 33

Where VEXBE is the deciding party and the failure is likely to put people's rights at risk, the Information Commissioner is told within 72 hours of awareness where that is achievable, and a report filed later carries its own explanation for the delay, as Article 33(1) demands. The report covers the nature of the failure, the categories and rough numbers of people and records involved, the likely consequence, and what has been done or is proposed. Where the picture is still incomplete at the deadline, Article 33(4) permits reporting what is known and supplying the balance in stages, and that is what happens rather than a silent wait for a finished investigation.

16.3 Telling the people affected, Article 34

Where the likely risk to individuals is high, those individuals are told promptly, in plain language, with a point of contact, an account of the likely consequence, the measures taken, and any step worth their taking themselves. Article 34(3) supplies three circumstances relieving a controller of individual notice: the payload had been rendered unintelligible, by strong encryption for instance; later steps have brought the risk back down; or contacting each person separately would demand effort out of all proportion, and a public announcement stands in its place. This company treats the third of those as a genuinely exceptional route rather than a convenient one.

16.4 Failures on the processor side

Article 33(2) requires a processor to alert the deciding party promptly. The undertaking given to clients is tighter than the statutory floor: the client's named contact hears within 24 hours of awareness, with whatever is known at that point, and updates follow as the picture fills in. Whether the regulator and the affected individuals are told is the client's call, and VEXBE supplies what that decision needs rather than making it.

16.5 The internal record

Article 33(5) requires every failure to be documented, including the ones that never become reportable, capturing the facts, the effect and the remedial action. Those entries are kept for six years, as section 14 sets out.

Section 17

IF-06, your request to the controller

IF-06 · Individual → VEXBE LTD, exercising a right

Endpoints: you, and the company acting as controller.
Direction: inbound request, outbound written answer.
Payload inbound: enough detail to locate the records, plus identity evidence only where genuine doubt exists.
Payload outbound: the data, or the action taken, or a refusal naming its statutory ground.
Guarantee: every request receives a written outcome. A refusal states which part is refused and under which provision.
Expiry: the file created by the request is destroyed after 3 years.

Role: controller

The rights below attach to records for which this company decides the purpose. Section 9.4 governs the processor situation. For each right, what follows says what it lets you compel, and where the law permits a refusal it says so rather than leaving you to discover it.

17.1 Article 13 and Article 14, being informed

A clear account of how your data gets handled is owed to you, and this document is the discharge of that duty. Nothing has to be requested to obtain it. Where a passage here is unclear or turns out to be wrong, say so; it gets explained or corrected, and a correction is logged in section 22.

17.2 Article 15, access

Confirmation of whether records about you exist may be required, together with a copy of them and the supplementary detail Article 15(1) lists: purposes, categories, recipients, the period or the criteria setting it, your rights, the source where the data did not come from you, and whether automated decisions are taken. Write in and describe what you want; no particular form of words is needed and no Article has to be cited. A fee is possible only where Article 12(5) applies, meaning a request that is manifestly unfounded or excessive, and any such decision comes with reasons and a route to challenge it. Where a copy would expose someone else's data or a third party's confidential material, that portion is redacted, the rest is supplied, and you are told redaction has occurred.

17.3 Article 16, rectification

Correction of an inaccurate record may be required, as may completion of a partial one, including by adding a statement of your own. Tell the company what is wrong and what the correct position is. Where the correction can be verified it is made. Where accuracy is genuinely contested, typically because the entry records a view held at a particular moment, your account is stored beside the entry rather than replacing it, and you are told that is what happened. Article 19 requires a correction to be passed to each recipient unless doing so proves impossible or disproportionate, and the recipients are identified to you on request.

17.4 Article 17, erasure

Any of the grounds listed at Article 17(1) supports a demand for erasure: the purpose is spent, consent has been withdrawn with no alternative basis available, an objection under Article 21(1) succeeds, the processing was unlawful, or another law compels deletion. The right has limits set by Article 17(3), which obliges a controller to keep what a legal obligation or a legal claim requires. This is precisely why an invoice survives an erasure request: section 388 of the Companies Act 2006 and tax law require it for six years, and that requirement outranks the request. A partial refusal names the surviving records and the ground for each, and everything outside that survives nothing.

17.5 Article 18, restriction

Records can be frozen, held but put beyond use, in four situations: you dispute accuracy and verification is pending; the processing is unlawful but you would rather it were frozen than erased; the company no longer needs the data but you need it for a claim; or an Article 21(1) objection is being weighed. While frozen, nothing is done with the records beyond storage, except with your agreement, for a legal claim, to protect another person, or for a substantial public interest. You are told before the freeze is lifted.

17.6 Article 21, objection

An operation running on Article 6(1)(f) can be objected to by reference to your particular circumstances, and it must stop unless the company can show compelling grounds that override your interests, or the processing serves a legal claim. Since most controller-side activity here rests on that basis, the right has real purchase, and an objection is reconsidered on its merits rather than acknowledged and filed. Article 21(2) makes an objection to direct marketing absolute and immediate, with no balancing at all.

17.7 Article 20, portability

This right engages when an automated operation runs on either consent or contract. It lets you take away whatever you supplied, in a structured form that is commonly used and readable by machine, and have it sent on to another controller wherever that is technically achievable. In practice, at this company, that means the correspondence you sent, supplied as plain text or an ordinary document format. It does not reach material the company derived or inferred, nor anything running on legitimate interests or legal obligation.

17.8 Article 7(3), withdrawing consent

Consent is withdrawable at any time and the withdrawal must be as easy as the giving was, without unsettling anything lawfully done beforehand. The authorisation register in section 8 shows no operation currently running on consent. Should one ever be introduced, the withdrawal route will be stated where the consent is asked for, and a single reply will be enough to exercise it.

17.9 Article 22, automated decisions

No decision carrying a legal effect, or an effect of comparable weight, may be reached about you by machinery alone, profiling included. No such decision is taken here: whether to take on an enquiry, what to quote, and how an engagement runs are all human judgements. Introducing one would require this notice to be revised first, with the Article 22(3) safeguards in place from the start, meaning human review, a route to put your side, and a route to contest.

17.10 Article 77, complaint

A complaint may go to the Information Commissioner whenever you wish, and approaching this company first is no precondition, though being given the opportunity to fix an error is naturally preferred here. Section 19 has the details.

Section 18

Handling contract for an IF-06 request

Role: controller

18.1 Submitting one

Send it to [email protected] with "Data protection request" at the front of the subject. Name the right you are using, or simply describe the outcome you want, and give enough to locate the records, which usually means the address you corresponded from and an approximate date range. A request is valid whether spoken or written, whether or not it uses legal vocabulary, and whichever part of the company receives it; the subject line only speeds the routing. Somebody may act for you, in which case evidence of their authority is requested.

18.2 Establishing who you are

Article 12(6) permits further information to be sought where identity is genuinely in doubt, and this company treats that as a narrow permission rather than a delaying tactic. A request arriving from an address already sitting in the correspondence is normally answered on that basis alone. Where the request reaches records not linked to a known address, or doubt is otherwise real, the smallest evidence that resolves it is requested and the reason is explained. Anything supplied for verification is used to verify and then destroyed. The clock in 18.3 starts once what is reasonably needed is in hand.

18.3 Timing

The statutory obligation under Article 12(3) is to respond promptly and at the latest one month after receipt, running from receipt or from verification where verification was needed, and ending on the corresponding date of the following month. A complex request, or several from the same person, permits an extension of up to two further months, and where that applies you are told inside the first month, with the reason. Beyond the statutory position, this company undertakes to confirm receipt within two working days so that you are not left wondering whether a message arrived at all.

18.4 What the answer looks like

It comes in writing, by email to the address you wrote from unless you ask for another route. It states what was found, what has been done, and, for any part refused, precisely which part and on which provision. The first copy carries no charge. Article 15(3) permits a reasonable administrative fee for further copies of the same material, calculated on what producing them actually costs.

18.5 The only grounds for refusal

A refusal has to rest on something the legislation provides. In practice that means one of four: Article 12(5), where the request is manifestly unfounded or excessive; an exemption drawn from Schedule 2 to the Data Protection Act 2018, privilege attaching to legal advice being the commonest, followed by the exemption covering negotiations with the person asking; Article 15(4), where a copy would harm another person's rights; or, on an erasure request, one of the Article 17(3) exceptions, most often the obligation behind the accounting records. Expense and inconvenience appear nowhere on that list. A refusal states its ground, tells you the regulator is available, and tells you Article 79 gives a route to court.

18.6 Disagreeing with the outcome

Reply and say so. The matter is reviewed by someone who did not decide it the first time. If that still leaves the question open, the regulator's process costs nothing and no right is surrendered by having tried the company first.

Section 19

Escalation endpoint: the ICO

Role: controller

Where you think VEXBE LTD has handled your personal data badly, the company would like to hear it first, at [email protected] with "Complaint" at the front of the subject. Receipt is confirmed inside three working days and a reasoned answer follows within twenty. Independently of that, Article 77 gives you a route to the supervisory authority, which in the United Kingdom is the Information Commissioner's Office.

Information Commissioner's Office

Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
United Kingdom

Helpline: 0303 123 1113
Website: ico.org.uk/make-a-complaint

The regulator prefers that an organisation be given a chance to answer before a complaint reaches it, but that preference is not a condition of being heard, and approaching it costs you nothing either way. Article 79 additionally provides a judicial remedy, and Article 82 provides compensation where an infringement has caused you damage, material or otherwise.

Section 20

Erasure and deletion of data held about you

Role: controller

This section specifies how to have the records this company holds about you erased, what erasure removes, how long it takes, and the narrow set of things that survive it with a stated reason attached to each.

20.1 Making the request

Write to [email protected] with "Data protection request" at the front of the subject and ask for erasure. The request runs under Article 17, and the limits bearing on it sit at section 17.4. The company identifies everything it holds about you, erases what it is free to erase, and tells you specifically what survives and under which obligation, which in practice means invoices and the contract documents underneath them.

20.2 What erasure removes, and how long it takes

Once a request is verified, removal from live systems completes inside 30 days. Backup sets are not edited individually, because pulling a single record out of an encrypted backup is not an operation anyone can perform reliably; those copies age out on the normal cycle, which does not run beyond 90 days, and no restored backup is ever used to bring erased records back. Completion is confirmed to you in writing.

20.3 What survives erasure

Three things, each for a stated reason. Invoices and the accounting entries behind them, for six years, under section 388 of the Companies Act 2006 and tax law. Contract documents and the correspondence recording what was agreed, for six years, under the Limitation Act 1980, so that a claim remains capable of being brought or answered. And a suppression entry consisting of an email address on its own, where you have asked not to be contacted, because honouring that instruction is impossible without remembering it. Nothing else survives, and none of the three is used for any other purpose.

Section 21

Device storage

Role: controller

Storage written to or read from your device is regulated separately by the Privacy and Electronic Communications (EC Directive) Regulations 2003, which sit alongside the UK GDPR rather than inside it. The full specification of what this site writes, why regulation 6 does not require a consent gate in front of it, and the one strictly necessary item the security layer may set, is in the cookie notice. That document and this one are maintained together, and a change to either is reflected in both.

Section 22

Change control

Role: controller

A specification without change control is a snapshot. This one carries an issue date and a revision number at the head, and both move whenever the substance moves, with a line added to the log below recording what changed.

A material revision means a new interface, a new payload class, a new authorisation or a new recipient. Any of those is published before the processing it describes begins, not after, and clients affected by one are told by email rather than left to notice a changed date on a web page.

Revision log

  • Revision 1.0, issued 15 August 2026. Specification issued.

The controlling copy is always the one published at vexbe.co.uk/privacy.html. A copy circulated as a document should be checked against that address before anyone relies on it.

Back to contents