Calm digital workspace showing secure information handling, organised review documents and business systems oversight.

Privacy notice

Privacy Notice

This notice explains how INTELIXA LIMITED trading as Intelixa collects, uses, stores and shares personal data when you visit our website, contact us, enquire about services, work with us, or take part in a Digital Health Check or other client project.

Last updated 27 August 2026

1. About this Privacy Notice

This Privacy Notice explains how INTELIXA LIMITED trading as Intelixa collects, uses, stores and shares personal data.

It applies when you:

  • visit the Intelixa website
  • contact Intelixa by email, form, telephone, social media or another communication route
  • make an enquiry about Intelixa services or take steps before entering into a contract
  • become a client, supplier, contractor, partner, contact or business prospect
  • take part in a Digital Health Check or other Intelixa client project
  • provide information, screenshots, exports, sample records or documents to Intelixa
  • receive relevant business marketing or ask Intelixa not to contact you for marketing
  • exercise a data protection right, make a complaint, or are involved in a data protection or security incident record
  • use or enquire about Intelixa products, templates, resources or services

This Privacy Notice may be updated from time to time. The latest version will be published on the Intelixa website.

2. Who is responsible for your personal data?

INTELIXA LIMITED trading as Intelixa is responsible for the personal data it collects and uses for its own business purposes.

For the purposes of UK data protection law, Intelixa will usually act as a data controller for personal data relating to its own website visitors, contacts, prospects, clients, suppliers, contractors and business administration.

In some client project situations, including some Digital Health Check work, a client may provide Intelixa with personal data relating to the client’s own customers, staff, suppliers, prospects or other contacts. Depending on the nature of the work and the decisions being made about that information, Intelixa may act as a data processor on the client’s instructions, an independent controller for some purposes, or both in different respects. Where appropriate, Intelixa may require a separate data processing agreement or additional data handling terms.

3. Personal data Intelixa may collect

Intelixa may collect and use different types of personal data depending on how you interact with us.

This may include:

  • name
  • business name
  • job title or role
  • email address
  • telephone number
  • postal or billing address
  • website address
  • social media profile or business page details
  • enquiry details and pre-contract communications
  • communication history
  • proposal, project, payment and invoicing information
  • meeting notes, call notes and project notes
  • marketing preferences and suppression or do-not-contact records
  • data protection rights, complaint and incident records where relevant
  • information supplied through website forms, Zoho Mail or another agreed communication route
  • technical information such as IP address, device type, browser type, approximate location and website usage data where analytics is enabled with consent
  • information about the client’s business systems, enquiry routes, CRM, website, workflow, tools, subscriptions and processes
  • information contained in client-provided screenshots, exports, sample records, documents, process notes, communications and other materials

Intelixa may also create working notes, analysis, reports, recommendations, task records and internal project records while providing services. Intelixa does not receive or hold purchaser or subscriber identities from Apple or equivalent app stores for ordinary Quotelixa or other app-store purchases where the store handles the customer relationship and does not provide that identity to Intelixa.

4. Digital Health Check, client project and sensitive data

During a Digital Health Check or other client project, Intelixa may receive, review or create materials such as website screenshots; enquiry examples; CRM exports or sample records; spreadsheet extracts; form submissions; process notes; workflow documents; customer journey notes; analytics screenshots; email or message examples; supplier or software information; business tool and system information; and report drafts, working notes and final reports.

Clients should only provide information that is relevant to the agreed scope of work. Where possible, clients should remove, redact or anonymise unnecessary personal data, confidential third-party information and sensitive information before sending materials to Intelixa.

Intelixa does not intentionally require, seek or need special category personal data or criminal offence data in normal business operations. Clients should not send safeguarding information, detailed HR or medical records, financial account data, passwords, authentication credentials or other highly sensitive information unless Intelixa has specifically requested it and agreed appropriate handling arrangements in writing.

If unnecessary sensitive or criminal offence information is received incidentally, Intelixa will aim to minimise access to it and delete, return, restrict or replace it as soon as it is no longer genuinely necessary. Any deliberate future processing of special category or criminal offence data requires separate Legal/Compliance review before it begins.

Special category personal data includes information about health, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for identification, sex life or sexual orientation.

5. How Intelixa collects personal data

Intelixa may collect personal data:

  • directly from you when you contact Intelixa
  • through website forms, including Zoho Forms, or through Zoho Mail and other agreed communication routes
  • during calls, meetings and project discussions
  • through documents, screenshots, exports or materials provided by a client, including information about the client’s own customers, staff, suppliers, prospects or other contacts where relevant to the agreed work
  • through business cards, networking, referrals or introductions
  • through public and business sources such as company websites, directories, social media and Companies House
  • through website analytics and related cookies after the required analytics consent has been given
  • from service providers used to operate the website, email, CRM, file storage, accounting, project, productivity or communication tools

Where Intelixa obtains personal data indirectly, for example from public business sources or from a client, Intelixa will handle transparency obligations according to the circumstances and any applicable exception under data protection law.

6. Why Intelixa uses personal data

Intelixa may use personal data to:

  • respond to enquiries and manage pre-contract contact
  • provide information about Intelixa services
  • prepare proposals, quotations and statements of work
  • deliver Digital Health Checks and client projects
  • review client-provided materials
  • create reports, recommendations and project outputs
  • manage prospects, CRM records and client relationships
  • arrange meetings, calls, follow-up and next actions
  • issue invoices and manage payments
  • keep accounting, tax and business records
  • manage suppliers, contractors and other business contacts
  • manage direct marketing preferences and suppression or do-not-contact records
  • measure and improve website use where analytics consent has been given
  • improve Intelixa services, templates, processes and website content
  • maintain security and prevent misuse
  • respond to data protection rights requests, complaints and incidents
  • comply with legal, regulatory, accounting and tax obligations
  • establish, exercise or defend legal rights
  • send relevant service updates, where lawful
  • send business marketing communications where permitted by law or where consent has been obtained

7. Lawful bases for using personal data

Intelixa will only use personal data where there is a lawful basis to do so. The lawful basis depends on the activity and the facts. Intelixa’s current working framework includes:

Pre-sales and enquiries: legitimate interests and/or taking steps at your request before entering into a contract, depending on the circumstances.

Client service delivery: contract where processing is necessary to deliver the agreed service; legitimate interests may also apply to administration involving business contacts who are not personally party to the contract.

Invoicing and accounting: legal obligation and/or contract as applicable.

CRM and business relationship management: normally legitimate interests.

Direct marketing: legitimate interests and/or consent as applicable. Separate Privacy and Electronic Communications Regulations (PECR) requirements are considered where they apply. The PECR soft opt-in is not itself a UK GDPR lawful basis.

Website analytics: consent.

Marketing suppression and do-not-contact records: legitimate interests and compliance with objection rights.

Data protection rights, complaints and breach or incident records: legal obligation and/or legitimate interests as appropriate.

Supplier, contractor and other business contacts: legitimate interests and/or contract depending on the facts.

Intelixa may also rely on legal obligation where processing is required by law. Vital interests is not expected to be a normal basis for Intelixa processing but may apply in a genuine emergency where necessary to protect someone’s life.

8. Artificial intelligence, automation and digital tools

Intelixa uses software, automation and AI-assisted tools where they support a defined business or client task. This can include OpenAI or ChatGPT where Intelixa deliberately submits information for an authorised purpose.

AI-assisted use may include organising or summarising information, research organisation, report structure, workflow analysis, checking, draft wording, document comparison, task management or other controlled assistance.

Intelixa does not use AI tools to make solely automated decisions about individuals that produce legal or similarly significant effects. Intelixa remains responsible for reviewing final client-facing outputs before release.

Intelixa aims to minimise personal data submitted to AI tools and not to submit unnecessary personal data, special category personal data, criminal offence data, passwords, authentication credentials or highly sensitive client information. Where personal information is deliberately submitted, Intelixa treats the AI provider as part of the relevant processing and supplier/transfer review.

Clients should avoid sending unnecessary personal data and should redact or anonymise information where possible before supplying it to Intelixa.

9. Sharing personal data and current service providers

Intelixa may share or make personal data available where reasonably necessary to service providers and recipients that support the relevant activity. Current examples include:

  • Zoho services, including Zoho Mail for business email, Zoho CRM for relationship management, and Zoho Forms for website or business forms
  • Microsoft OneDrive for controlled document and file storage
  • GitHub where personal information is deliberately recorded as part of authorised project, governance or development evidence
  • OpenAI or ChatGPT where Intelixa deliberately submits personal information for an authorised AI-assisted task
  • Cloudflare for website infrastructure, delivery and security-related services
  • Google Analytics 4 after analytics consent has been given
  • banking, payment, invoicing and accounting systems where needed for payments, invoicing and financial administration
  • professional advisers, such as accountants, insurers, lawyers or consultants
  • subcontractors or specialist suppliers, where agreed or reasonably necessary for the service
  • regulators, public authorities, courts or law enforcement where required by law
  • another organisation if Intelixa is involved in a business transfer, restructuring, merger or sale

The provider list may change as Intelixa’s systems change. Material new processing is subject to change-triggered governance before it is treated as current practice. Intelixa will not sell personal data. Intelixa will not use a client’s name, logo or identifiable project details in public case studies or marketing without permission.

10. International transfers

Some service providers used by Intelixa may process or store personal data outside the United Kingdom.

Where personal data is transferred internationally, Intelixa will use the transfer mechanism appropriate to the relevant provider and processing. Depending on the circumstances, this may include UK adequacy regulations, an applicable data-privacy framework route, approved contractual safeguards such as standard contractual clauses together with a UK addendum or other lawful transfer mechanisms.

The exact transfer position depends on the provider, service and data involved, and Intelixa reviews material provider and transfer arrangements as part of its data-protection governance.

11. How long Intelixa keeps personal data

Intelixa keeps personal data only for as long as it is needed for the relevant purpose, legal or contractual requirements, or another documented reason. Current working retention baselines include:

  • general enquiries that do not become customers: 24 months after the last meaningful contact
  • prospect and CRM records: 24 months after the last meaningful contact, then review and delete unless an active business, legal or suppression reason remains
  • material client service and project records, including relevant Digital Health Check records: for the client relationship and up to six years afterwards where needed for contractual, evidential, insurance, dispute or legal purposes
  • contracts, invoices, accounting and payment records: generally six years from the end of the relevant company financial year, subject to applicable legal and tax requirements
  • supplier and contractor records: for the relationship plus six years where the record is contractual or financial; otherwise generally 24 months after the last meaningful contact
  • routine support correspondence: 24 months after closure unless it forms part of a longer client, contractual or legal record
  • data protection rights, complaint and breach or incident governance records: six years after closure as the current working baseline
  • marketing suppression and do-not-contact records: a minimal record may be retained for as long as needed to honour the objection or suppression
  • unnecessary incidental sensitive or criminal offence data: delete as soon as it is no longer genuinely necessary
  • Google Analytics event-level data: two months under the approved analytics retention baseline; analytics cookies and the Intelixa consent-preference cookie have their own browser lifetimes described below

Intelixa may retain anonymised or aggregated information that no longer identifies individuals. Retention can be extended where a legal hold, active dispute, regulatory requirement or other documented reason makes that necessary.

12. Security

Intelixa takes reasonable and proportionate steps to protect personal data against unauthorised access, loss, misuse, alteration or disclosure.

Measures may include access controls, password and authentication controls, secure storage, device security, supplier review, limited access to project materials, backup and recovery controls where applicable, and deletion or archiving according to the relevant retention requirement.

No internet, email, cloud or electronic storage system can be guaranteed completely secure. Clients should avoid sending passwords, authentication credentials, unnecessary sensitive information or excessive personal data to Intelixa.

13. Cookies and analytics

Intelixa uses Google Analytics 4, provided by Google, to measure and improve how this website is used.

Google Analytics operates only after you give affirmative analytics consent. Until you choose to allow analytics, Intelixa does not load the Google Analytics tag, does not send analytics requests to Google, and does not set Google Analytics cookies.

Analytics data is used for website-performance and usage measurement. It is pseudonymous rather than fully anonymous.

When you allow analytics, measurements may include:

  • page visits and navigation
  • broad device and browser information
  • broad geographic region
  • referrer and traffic-source information
  • campaign attribution using approved UTM campaign fields where those are intentionally present in a tagged link

Successful enquiry-completion events are not enabled in the current analytics release. They may be introduced later only through separate approved measurement and privacy governance.

Intelixa minimises the page location sent to Google Analytics to the Intelixa website origin and page path. The implementation does not send the page query string as page location and does not intentionally send names, email addresses, form contents or other direct identifiers to Google Analytics.

After you allow analytics, Google may create a _ga cookie and related _ga_* cookies on this website. Those cookies contain a Google Analytics identifier. Intelixa also stores a preference cookie named intelixa_analytics_consent so the site can remember whether you accepted or rejected analytics. That preference cookie contains only a consent-policy version and your accepted or rejected choice and is kept for about 180 days.

You can change or withdraw analytics consent at any time using Cookie settings in the website footer. When you withdraw consent, Intelixa stops future analytics collection from your browser and removes Google Analytics cookies where technically possible. Intelixa will also request deletion from Google Analytics of analytics information associated with that browser identifier where it can identify that information for deletion.

Intelixa does not currently use Google Analytics for advertising, remarketing, User-ID, personalised advertising, or demographic or interest profiling. Intelixa does not match Google Analytics identifiers to CRM or Zoho records and does not use analytics to identify you as a named individual.

Google is the analytics provider and relevant processing may involve international transfers. Intelixa’s approved working retention baseline for Google Analytics event-level data is two months.

14. Marketing communications

Intelixa may contact business contacts about relevant Intelixa services, products, updates or resources where permitted by law. Intelixa considers both UK data-protection law and applicable Privacy and Electronic Communications Regulations (PECR) requirements for electronic marketing.

Where consent is required, Intelixa will ask for consent before sending the relevant marketing communication. Where legitimate interests is relied on, Intelixa will consider the nature of the business relationship and the individual’s rights and reasonable expectations.

You can unsubscribe from marketing emails or ask Intelixa to stop sending marketing communications at any time. Intelixa may keep a minimal suppression record so that the request continues to be honoured. Intelixa may still send service, contractual or administrative messages where necessary.

15. Your data protection rights

Depending on the circumstances, you may have the right to:

  • request access to your personal data
  • ask for inaccurate personal data to be corrected
  • ask for personal data to be erased
  • ask Intelixa to restrict how personal data is used
  • object to certain uses of personal data, including direct marketing
  • request transfer of personal data in a portable format where the right applies
  • withdraw consent where Intelixa relies on consent
  • complain to the Information Commissioner’s Office

These rights are not absolute and may depend on the circumstances. To exercise your rights, contact Intelixa using the contact details on this page. Intelixa may need to verify your identity before responding and will correct inaccurate information and consider whether a correction needs to be reflected in other controlled records or recipients where applicable.

16. Complaints

If you have a concern about how Intelixa handles personal data, please contact Intelixa first so the issue can be reviewed.

You also have the right to complain to the Information Commissioner’s Office, the UK regulator for data protection.

ICO website: https://ico.org.uk ICO telephone: 0303 123 1113

17. Client responsibility when providing third-party personal data

Where a client provides Intelixa with personal data relating to the client’s own customers, staff, suppliers, prospects or other third parties, the client is responsible for ensuring that it has an appropriate lawful basis and authority to share that information with Intelixa.

The client is also responsible for providing any required privacy information to those individuals, unless otherwise agreed in writing. The client should only provide personal data that is relevant and necessary for the agreed work.

Intelixa may ask the client to redact, anonymise, reduce or replace information where appropriate. Where Intelixa acts as a processor, the relevant client instructions and data-processing terms also apply.

18. Digital Health Check terms

Where Intelixa provides a Digital Health Check, the Digital Health Check Terms and Conditions will also apply.

Those terms include further information about scope, client responsibilities, client-provided materials, report use, publication restrictions, AI-assisted tools, payment and liability.

Digital Health Check Terms and Conditions: /digital-health-check-terms/

19. Updates to this Privacy Notice

Intelixa may update this Privacy Notice when its processing, providers, products, legal obligations or operating controls change.

The latest version and last-updated date will be published on the Intelixa website.