Governance & policy centre
Data & security

Data Protection and UK GDPR Policy

The governance principles Intelex Systems follows when processing personal data as controller or processor.

Intelex Systems processes personal data in accordance with applicable data-protection law, including the UK GDPR and Data Protection Act 2018. This public policy summarises our governance approach. Product- or service-specific privacy information may provide additional detail for a particular processing activity.

Personal data must be used lawfully, fairly, transparently and only to the extent necessary for a defined purpose.

Data-protection principles

  • Lawfulness, fairness and transparency
  • Purpose limitation
  • Data minimisation
  • Accuracy
  • Storage limitation
  • Integrity and confidentiality
  • Accountability

Controller and processor responsibilities

Intelex acts as a controller for its corporate, workforce, sales, supplier and website activities. When delivering services on a customer’s documented instructions, Intelex may act as a processor. Roles, instructions, confidentiality, security, sub-processing, assistance, return or deletion and audit arrangements are defined contractually.

Privacy by design and risk assessment

New products, changes and processing activities should identify the purpose, lawful basis, data categories, users, retention, sharing, transfers and security requirements before implementation. A Data Protection Impact Assessment is completed where processing is likely to result in high risk to individuals.

Individual rights

  • Be informed about processing
  • Request access and correction
  • Request erasure or restriction where applicable
  • Object to certain processing
  • Request portability where applicable
  • Withdraw consent where consent is relied upon
  • Ask for review of qualifying automated decisions

Security, incidents and suppliers

Personal data is protected through proportionate technical and organisational measures. Suspected incidents are assessed promptly, documented and notified to customers, individuals or the Information Commissioner’s Office when legally required. Processors and sub-processors are subject to proportionate due diligence and written terms.

International transfers

Where personal data is transferred outside the United Kingdom, Intelex uses an applicable adequacy regulation or appropriate safeguard, such as the UK International Data Transfer Agreement or approved UK Addendum, together with supplementary measures where needed.

Contact

Questions or rights requests may be sent to uk@intelexsystems.com with the subject ‘Data Protection Request’. We may need to verify identity before acting on a request.

Official references