We keep this policy deliberately specific. Rather than listing every technology we might one day use, it describes what this website actually does today. This website is, by design, a low-data property: it runs no analytics, sets no tracking cookies, and has no forms. If that changes, we will update this page and the date above.
Before publishing: the highlighted passages need confirmation from the business — principally the registered legal entity, retention periods, and which privacy regimes you are subject to. A qualified privacy adviser should review this page. Nothing here is legal advice.
1. Introduction
This Privacy Policy explains how [BUSINESS TO CONFIRM: full registered legal entity name and registered office address], trading as AppAgentix (“we”, “us” or “our”), handles personal information in connection with this website.
It covers visitors to this website and people who contact us about our services. It does not cover:
- personal data we process on behalf of a client while delivering a project — that is governed by the data processing terms in the relevant agreement, where the client is the controller and we act as a processor;
- third-party websites you reach through a link from here, each of which has its own policy; or
- applications we build for clients, which are operated by those clients under their own policies.
We are the controller of the personal information described in this policy. Please read it alongside our Cookie Policy and Terms and Conditions.
2. Information We Collect
We collect a limited amount of information, in two ways: information you actively give us, and a small amount of technical information collected automatically when any web server responds to a request.
We do not collect or use any of the following through this website:
- special category data such as health, biometric, racial or ethnic origin, religious belief, political opinion, trade union membership or sexual orientation;
- government identifiers such as passport or social security numbers;
- payment card or bank account details — there is no checkout or payment facility on this website;
- precise geolocation data from your device; or
- behavioural profiles built for advertising purposes.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
3. Information You Provide
This website currently has no contact form, newsletter sign-up, account registration, download gate or live chat widget. That means there is no mechanism on this site through which you can submit information to us directly.
You can, however, contact us through the channels published on the site, and if you do, we will hold what you send us:
- Email. If you email the address published in our footer, we receive your email address, your name if you include it, the content of your message and any attachments, together with the technical headers your mail client attaches.
- Telephone. If you call the number published in our footer, we receive your telephone number and whatever you tell us during the call. [BUSINESS TO CONFIRM: whether calls are recorded. If they are, say so here, explain why, and describe how callers are notified.]
- Post. If you write to our postal address, we receive the contents of your letter and your return address.
- Business correspondence. If we enter into discussions about a project, we will hold the contact details of the people involved, the correspondence itself, and any documents shared in the course of that discussion.
Please do not send us sensitive personal information, or personal data about other people, unless it is genuinely necessary and you have a lawful basis for sharing it.
4. Information Collected Automatically
4.1 Server logs
Like every website, this site runs on a web server that records requests it receives. A typical log entry contains your IP address, the date and time, the page or file requested, the HTTP status returned, the referring page where one is sent, and your browser’s user agent string.
These logs are generated by the hosting infrastructure rather than by any tracking code we have added. We use them only to keep the site running, to investigate errors, and to detect and prevent abuse such as automated scraping or intrusion attempts.
[BUSINESS TO CONFIRM: your hosting provider, where the server is physically located, and how long raw access logs are kept before rotation or deletion. Add the provider to the Third-Party Services table below.]
4.2 What we do not collect automatically
We want to be precise here, because many privacy policies claim more than the site actually does. On this website there is:
- no Google Analytics, and no analytics package of any kind;
- no Google Tag Manager or other tag management container;
- no Meta, LinkedIn, TikTok or other advertising pixel;
- no session-recording or heatmap tool such as Hotjar or Microsoft Clarity;
- no A/B testing or personalisation engine;
- no fingerprinting, device identification or cross-site tracking; and
- no use of browser storage — the site sets nothing in
localStorageorsessionStorage.
5. How We Use Information
We use personal information for the following purposes, and no others:
- To respond to you. To answer questions, provide the information you asked for, and correspond about a possible or ongoing engagement.
- To provide our services. To scope, quote, deliver, support and invoice work under an agreement.
- To operate and secure the website. To serve pages correctly, diagnose faults, monitor for abuse and protect against unauthorised access.
- To keep records. To maintain accurate business records of the enquiries we receive and the contracts we enter into.
- To meet legal obligations. To comply with tax, accounting, regulatory and other legal requirements, and to establish, exercise or defend legal claims.
We do not use personal information to make decisions about you by automated means alone, and we do not carry out profiling that produces legal or similarly significant effects.
6. Legal Bases for Processing
Where the UK GDPR, the EU GDPR or an equivalent regime applies to our processing, we rely on the following legal bases.
| Purpose | Legal basis |
|---|---|
| Responding to an enquiry you sent us | Legitimate interests — replying to someone who has contacted us. Where the enquiry concerns a contract, steps taken at your request prior to entering into it. |
| Delivering services under an agreement | Performance of a contract. |
| Operating, maintaining and securing the website | Legitimate interests — keeping our site available, correct and secure. |
| Serving web fonts from Google Fonts | Legitimate interests — presenting the site as designed. See section 10. |
| Keeping business and financial records | Legal obligation, and legitimate interests in maintaining accurate records. |
| Establishing or defending legal claims | Legitimate interests, and legal obligation where applicable. |
Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights and freedoms, and concluded that they are not, given the limited and expected nature of the processing. You may object to processing based on legitimate interests — see section 15.
7. Cookies and Similar Technologies
This website sets no analytics, advertising or tracking cookies. It does not run a consent banner, because there is nothing requiring consent to run.
The only cookies that can be set are strictly necessary cookies placed by WordPress itself, and only in specific circumstances — for example if someone logs in to the site’s administration area, or leaves a comment where commenting is enabled. An ordinary visitor reading these pages will normally not receive any cookie at all.
Our Cookie Policy lists each cookie, what it does, how long it lasts, and how to control cookies in your browser.
8. Analytics
We do not use analytics on this website. There is no Google Analytics property, no self-hosted analytics such as Matomo or Plausible, and no server-side analytics pipeline. We do not measure page views, sessions, conversions, scroll depth, click events or user journeys.
The only visibility we have into traffic is the raw server log described in section 4.1, which we consult reactively when investigating an error or a security concern, not as an audience measurement tool.
If analytics is added later: this section, the Cookie Policy, and section 11 must be updated before the tracking code goes live, and a consent mechanism will be required for visitors in the EU, the UK and other jurisdictions with equivalent rules. [BUSINESS TO CONFIRM: whether analytics is planned, and if so which provider.]
9. Communication and Marketing
There is no newsletter sign-up, mailing list subscription or marketing automation platform connected to this website. We do not build marketing audiences from site visitors, and we do not run retargeting campaigns based on your visit here.
If you contact us about a project, we will reply to you and may follow up about that enquiry. That is correspondence about a matter you raised, not marketing.
If we ever send you genuine marketing communications, we will do so only where we have the consent or the lawful basis required in your jurisdiction, every message will carry a clear unsubscribe mechanism, and we will act on an opt-out promptly. You can ask us at any time to stop contacting you for marketing purposes by emailing the address in section 19.
[BUSINESS TO CONFIRM: whether you operate any outbound email or CRM system outside this website, such as HubSpot, Salesforce, Mailchimp or Apollo. If you do, it must be named here and in section 11, even though it is not embedded in the site.]
10. Form Submissions
Our project enquiry forms collect your name, email address, phone number and project requirements, plus any optional choices you submit. The form is sent to us for the purpose of responding to your enquiry. Submissions may be stored in the website database and sent to our email and CRM systems for handling your request.
The phone country code is preselected using country-level IP geolocation when the form loads, unless the country is already known from the website host. For this lookup, your browser requests api.country.is directly. The provider receives your IP address to return a country code; your name, phone number, email address and form message are not sent to it. The provider says it does not log requests. You can change the preselected country code before submitting the form.
The country estimate is not precise GPS location, and the form does not request access to your device's location. If the lookup is unavailable, the form falls back to the device time zone, browser language and configured default.
- required fields are marked in the form; phone and project requirements are required to submit an enquiry;
- we use the information to respond to and manage the enquiry;
- submissions are handled by our website and may be processed by our email and CRM providers;
- submissions are retained only as long as needed for the enquiry and related business/legal requirements; and
- automated spam and validity checks may be applied to submissions.
11. Third-Party Services
We have audited what this website loads. The table below is the complete list of third parties involved in serving it.
| Service | Provider | What it does and what it receives |
|---|---|---|
| Google Fonts | Google LLC / Google Ireland Limited | Serves the Poppins typeface used across the site. Your browser requests the stylesheet and font files from fonts.googleapis.com and fonts.gstatic.com, so Google receives your IP address, user agent and the referring page. Google states that it does not set cookies for Google Fonts and does not use these requests to create user profiles. |
| IP country lookup | Country (country.is), operated by Line of Flight | When a project enquiry form needs to detect the visitor's country, the browser requests api.country.is over HTTPS. The service uses the visitor's IP address to return a country code and states that it does not log requests. Form fields are not sent to this service. See the service documentation. |
| Web hosting | [BUSINESS TO CONFIRM: hosting provider and region] | Stores the website files and database and serves pages to visitors. Processes the server log data described in section 4.1. |
| Business email | [BUSINESS TO CONFIRM: email provider, for example Google Workspace or Microsoft 365] | Receives, stores and transmits correspondence sent to our published email address. |
11.1 Avoiding the Google Fonts request
If you would prefer your browser not to contact Google, the fonts can be self-hosted. We have noted this as an improvement, and the theme is already structured to make the change straightforward. In the meantime, browser extensions that block third-party font requests will prevent it; the site remains fully readable in a fallback typeface.
11.2 Media and external links
Images, video and other media used on the site are served from our own infrastructure, not from third-party embeds. There are no YouTube, Vimeo, Google Maps, or social media embeds on this website, so no such provider receives data about your visit. Links to external websites, including our social media profiles, are ordinary links — those sites receive data about you only if you choose to follow the link.
12. Data Sharing
We do not sell, rent or trade personal information. We share it only in the following circumstances:
- Service providers. With the processors listed in section 11, which act on our instructions and are bound by contract to protect the information and to use it only for the purposes we specify.
- Professional advisers. With our accountants, auditors, insurers and lawyers, where necessary and subject to professional duties of confidentiality.
- Corporate transactions. With a prospective buyer or their advisers if we sell or reorganise all or part of our business, subject to appropriate confidentiality protections. You would be informed if your information became subject to a different privacy policy as a result.
- Legal requirements. Where we are required to disclose by law, court order, or a valid request from a regulator or law enforcement agency, or where disclosure is necessary to establish, exercise or defend legal claims, or to protect the rights, property or safety of any person.
Where we receive a government or law enforcement request for data, we will satisfy ourselves that it is lawful and properly served, disclose no more than is required, and notify the individual concerned unless we are legally prohibited from doing so.
13. Data Retention
We keep personal information only for as long as we need it for the purpose it was collected for, and to meet our legal, accounting and reporting obligations.
When deciding how long to keep information we consider its nature and sensitivity, the potential risk of harm from unauthorised use or disclosure, the purposes we are processing it for, and whether we can achieve those purposes by other means. When it is no longer needed, we delete it or irreversibly anonymise it.
[BUSINESS TO CONFIRM: concrete retention periods, which should replace the general statement above. Typical starting points are: unsuccessful enquiries deleted after 12–24 months; client correspondence retained for the life of the relationship plus the limitation period; financial records retained for the period required by tax law in your jurisdiction; server access logs rotated after 30–90 days. These are illustrative only and must be set by the business.]
You can ask us to delete information we hold about you at any time — see section 15.
14. Data Security
We maintain appropriate technical and organisational measures to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These include:
- encryption of data in transit using HTTPS/TLS across the website;
- access controls that limit personal information to the people who need it to do their job;
- authentication requirements for administrative access to the website and our business systems;
- keeping the WordPress core, theme and plugins up to date, and applying security patches promptly;
- maintained backups of the website and its database; and
- confidentiality obligations on our staff and contractors.
No method of transmission over the internet or of electronic storage is completely secure, so while we work to protect your information we cannot guarantee absolute security. Email in particular is not a secure medium; please do not send us confidential or sensitive material by unencrypted email.
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required, the affected individuals, within the timescales the applicable law sets.
[BUSINESS TO CONFIRM: your certifications. The site footer displays SOC 2 Type II, ISO 27001 and ISO 42001 badges. If those certifications are current, reference them here with their scope and certifying body. If they are aspirational, they should be removed from the footer as well as from this page.]
15. Your Rights
Depending on where you live, you may have some or all of the following rights over the personal information we hold about you.
15.1 Rights under the UK and EU GDPR
- Access. Obtain confirmation that we process your data, and a copy of it.
- Rectification. Have inaccurate data corrected and incomplete data completed.
- Erasure. Ask us to delete your data where there is no good reason for us to continue processing it.
- Restriction. Ask us to suspend processing in certain circumstances, for example while we verify the accuracy of data you have challenged.
- Portability. Receive data you provided to us in a structured, commonly used, machine-readable format, or have it transmitted to another controller.
- Objection. Object to processing based on legitimate interests, and object at any time to processing for direct marketing.
- Withdraw consent. Where we rely on consent, withdraw it at any time, without affecting the lawfulness of processing before withdrawal.
- Complain. Lodge a complaint with your supervisory authority. In the UK this is the Information Commissioner’s Office; in the EU it is the authority in your country of residence, work or the alleged infringement.
15.2 Rights under Indian law
We operate from India, where the Digital Personal Data Protection Act, 2023 applies to the processing of digital personal data. Where that Act applies to our processing, you have the right to access a summary of the personal data we process and the processing activities undertaken; to correction, completion, updating and erasure of your personal data; to nominate another person to exercise your rights in the event of your death or incapacity; and to a readily available grievance redressal mechanism.
To raise a grievance, contact us using the details in section 19. [BUSINESS TO CONFIRM: the DPDP Act requires a published point of contact for grievances, and a Data Protection Officer if you are classified as a Significant Data Fiduciary. Confirm who that contact is and publish their details here. Note that provisions of the Act and its rules are being brought into force in phases, so confirm the current compliance position.]
15.3 Rights under California law
If you are a California resident, the California Consumer Privacy Act as amended may give you the right to know what personal information we collect, use, disclose and sell; to request deletion; to request correction; to opt out of sale or sharing for cross-context behavioural advertising; to limit the use of sensitive personal information; and not to be discriminated against for exercising these rights.
As set out in this policy, we do not sell or share personal information for cross-context behavioural advertising, and we do not collect sensitive personal information through this website, so there is nothing for you to opt out of. Your other rights are exercised in the same way as described below.
[BUSINESS TO CONFIRM: the CCPA only applies to businesses meeting its thresholds for revenue, volume of California consumer data, or share of revenue from selling data. Confirm whether you meet any of them; if not, this subsection can be removed.]
15.4 How to exercise your rights
Email us at info@appagentix.com, marking your message for the attention of the privacy team, or write to the postal address at the end of this page. Please describe the right you wish to exercise and give us enough information to locate your data.
We may need to verify your identity before acting, to make sure we do not disclose data to the wrong person. We will respond within the period required by the applicable law — one month under the UK and EU GDPR, which may be extended by two further months for complex requests, and 45 days under California law, extendable once. Exercising these rights is free, though we may charge a reasonable fee or decline to act if a request is manifestly unfounded or excessive, and we will explain our reasoning if we do.
You may use an authorised agent to make a request on your behalf where the applicable law allows it; we will ask for proof of that authorisation.
[BUSINESS TO CONFIRM: whether a dedicated privacy mailbox such as privacy@appagentix.com should be used instead of the general enquiries address, and whether you are required to appoint a Data Protection Officer or an EU/UK representative. If a DPO or representative is appointed, their details must be published here.]
16. International Data Transfers
We operate from India, and the third-party providers we rely on run global infrastructure. As a result, personal information may be transferred to, stored in, or accessed from countries outside your own, including countries whose data protection laws differ from those in your jurisdiction.
India has not been granted an adequacy decision by the European Commission or the UK government. Where personal data is transferred to us from the UK or the European Economic Area, we therefore rely on one of the following safeguards:
- the UK or EU Standard Contractual Clauses, together with the UK International Data Transfer Addendum where relevant, supported by a transfer risk assessment;
- your explicit consent to the transfer, having been informed of the risks; or
- the transfer being necessary for the performance of a contract with you, or for steps taken at your request before entering into one.
You can ask us for details of the safeguard applied to a particular transfer using the contact details below.
[BUSINESS TO CONFIRM: whether you actively market to or serve clients in the UK and EEA. If you do not, the GDPR may not apply to you and this section together with section 15.1 should be adjusted accordingly. If you do, confirm the specific transfer mechanism in place with each processor.]
17. Children’s Privacy
This website and our services are aimed at businesses and the professionals who work in them. They are not directed at children, and we do not knowingly collect personal information from children.
The age at which a person is treated as a child differs by jurisdiction: under India’s Digital Personal Data Protection Act, 2023 it is 18, and under the UK and EU GDPR it is generally 13 to 16 depending on the country. We apply the highest applicable standard, and we do not knowingly collect personal information from anyone under 18.
If you believe that a child has provided us with personal information, please contact us and we will delete it promptly. If we become aware that we hold such information without the appropriate verifiable parental consent, we will take steps to remove it.
18. Changes to This Policy
We may update this policy to reflect changes in our practices, the technologies the website uses, or legal requirements. The “Last updated” date at the top of this page shows when it was last revised.
We will always update this page before introducing a new technology that processes personal data — adding analytics, a form, a chat widget or an advertising pixel, for example — rather than afterwards. Where a change materially affects your rights, we will take reasonable steps to bring it to your attention, and where the law requires consent, we will obtain it before the change takes effect.
We encourage you to review this page periodically.
19. Contact Information
If you have questions about this policy, want to exercise a right, or wish to make a complaint about how we handle personal information, please contact us using the details below and mark your message for the attention of the privacy team.
We take privacy complaints seriously and will investigate and respond. If you are not satisfied with our response, you have the right to complain to your data protection supervisory authority, as described in section 15.1.