What personal information we collect, why, how long we keep it, and the rights you have under UK GDPR.
Who we are
OpenKit Ltd is the controller of the personal information described in this policy. We provide artificial intelligence consultancy, bespoke software development and related engineering services to organisations across a range of sectors.
We are registered in England and Wales, company number 13030838, and our registered office is Cambridge Guildhall, Market Square, Cambridge CB2 3QJ. We handle personal information in accordance with UK GDPR and the Data Protection Act 2018.
Information we collect
We collect different types of information depending on how you interact with our services. Here’s what we gather and why:
When you contact us or enquire about services
When you reach out through our website, email, or phone, we collect your name, email address, phone number, and company details. We use this information to respond to your enquiries, discuss potential projects, and scope work. We store enquiry details and our communications in our customer relationship management (CRM) system so that we can provide consistent service, pick up conversations where they left off, and meet our professional obligations.
Newsletter subscribers
If you sign up for our newsletter, we collect your email address and, optionally, your name and company information. We use this to send you updates about our services, industry insights, and company news. You can unsubscribe at any time using the link in every email we send.
Client information
For our client engagements, we collect contact and project information including names, email addresses, phone numbers, company details, project requirements, and billing information. This allows us to deliver our services, manage projects, handle invoicing, and maintain ongoing client relationships.
Website analytics and usage data
We use PostHog and Google Analytics 4 to understand how visitors use our website. Two different things sit under that heading and they are governed differently. Aggregate counting, described under statistical information about site use, runs by default and stores nothing on your device. Google Analytics 4, PostHog keeping an id on your device, and session recording all wait until you accept analytics cookies.
Between them they collect information about your visit including pages viewed, time spent on the site, your approximate location at country or city level, device type, and browser information. Google states that Analytics 4 uses your IP address to derive that approximate location and does not log or store the address itself.
This data helps us see which content is worth keeping, which pages need work, and where visitors give up.
Our Cookie Policy lists every cookie the site sets, and the same table appears in the cookie settings panel you can open from the footer of any page.
Technical information
When you use our website or services, we automatically collect certain technical information such as your IP address, browser type, operating system, and referring website. This information helps us maintain security, troubleshoot technical issues, and ensure our services work properly across different devices and browsers.
Statistical information about site use
We count how this website is used, in aggregate, and that counting runs by default. It sets no cookies and stores nothing on your device, apart from a record of your own decision if you use the switch described below. It exists for one purpose, which is seeing which pages help a reader and which ones need work, so that we can improve the site.
What it collects: pages visited and how often, the referring site or campaign link a visit arrived from, interactions with the page such as scroll depth and which links and buttons were used, an approximate location no more precise than a city, and the type of device and browser. The visitor id is held in memory for a single page and then discarded, so visits are not linked to one another and no profile of any visitor is built. Nothing is taken from what you type into a form. None of it feeds advertising, and none of it is sold or shared for marketing. The service is PostHog on its EU instance, so this data is held in the European Union.
Our lawful basis under UK GDPR is legitimate interests: understanding how our own site is used so we can improve it, set against a form of measurement that neither identifies you nor follows you between visits. Under PECR, measurement that stores nothing on your device and is used solely for statistical purposes to improve the service does not require consent, provided we tell you plainly what it does and give you a free and simple way to object at any time.
That objection is a single switch. Select Cookie settings in the footer of any page and turn Statistical purposes off. It stops immediately and stays off on later visits. You do not need to give a reason, and nothing on the site behaves differently afterwards.
Analytics that does need your consent is separate, and none of it starts until you accept it: Google Analytics 4, PostHog keeping an id on your device so a return visit is recognised as the same browser, and session recording, which captures a playback of how a page was used with everything typed into a field masked before it leaves your browser. Marketing measurement is a third, separately answered question: with your consent we load LinkedIn’s Insight Tag, which tells LinkedIn when a visit here follows one of our LinkedIn adverts so we can see which adverts lead to enquiries, and that visit data is held on LinkedIn’s systems under LinkedIn’s own privacy policy. Our Cookie Policy sets out all of it in full.
Our legal basis for processing
We process your personal data on several legal grounds under UK GDPR:
Contract Performance: When we process data to deliver our services, respond to your enquiries, or fulfil our agreements with you.
Legitimate Interests: For business communications, improving our services, website analytics, security monitoring, and maintaining client relationships. We’ve assessed that these uses don’t override your privacy rights.
Consent: For newsletter subscriptions, analytics cookies, the LinkedIn marketing tag, and certain marketing communications. You can withdraw this consent at any time.
Legal Obligations: When we need to keep records for tax, accounting, or other legal requirements.
How we use your information
We use your personal information for several specific purposes:
Service Delivery: Managing projects, communicating with clients, providing technical support, and delivering the systems you’ve commissioned.
Business Communications: Sending project updates, invoices, important notices, and responding to your questions or requests.
Marketing: With your permission, we send newsletters and information about our services that might interest you. We also use analytics to understand how our marketing performs.
Improving Our Services: Analysing how our website and services are used to make improvements, develop new offerings, and enhance user experience.
Legal and Security: Protecting our business and clients from fraud, ensuring compliance with our legal obligations, and maintaining the security of our systems.
Sharing your information
We don’t sell your personal information to anyone. However, we do share it with trusted partners in specific circumstances:
Service Providers: We work with hosting providers, email services, payment processors, and other technical partners who help us deliver our services. These companies can only use your data to provide services to us and must protect it according to our instructions.
Professional Advisors: Our accountants, lawyers, and business consultants may access your information when they’re helping us with legitimate business matters.
Legal Requirements: We’ll disclose information if required by law, court orders, or to protect our legal rights and those of our clients.
Business Transfers: If we sell or transfer part of our business, client information may be included in that transfer, but the new owner must continue to protect your data according to this policy.
International data transfers
Some of our service providers are located outside the UK. When we transfer your data internationally, we rely on the transfer mechanisms UK data protection law recognises, which include standard contractual clauses, transfers to countries covered by UK adequacy regulations, and other appropriate safeguards.
For the two analytics services named in this policy, the position is as follows. We use PostHog on its EU Cloud instance, so those analytics events are stored in the European Union. Google Analytics data may be processed outside the UK, and Google processes it under its own data processing terms, which incorporate the standard contractual clauses approved for international transfers.
Data security and ISO 27001
ISO 27001 certifies our management system: our controls are designed to the standard and independently assessed by an external body. In practice that management system governs how client data is classified, who can access it, where it may be stored, and how we respond when something goes wrong. Our security measures include:
Technical Safeguards: Encryption of data both when stored and transmitted, secure hosting infrastructure, regular security updates, and access controls that limit who can see your information.
Organisational Measures: Staff training on data protection, clear policies and procedures, regular security assessments, and incident response plans.
Physical Security: Secure facilities and equipment, with appropriate access controls and environmental protections.
The management system is reviewed on the cycle the standard requires, and audited by our certification body.
Your rights
Under UK GDPR you have several important rights regarding your personal information:
Access: You can request a copy of the personal information we hold about you, along with details about how we use it.
Correction: If any information we have is inaccurate or incomplete, you can ask us to correct it.
Erasure: In certain circumstances, you can request that we delete your personal information.
Restriction: You can ask us to limit how we use your information in specific situations.
Objection: You can object to certain uses of your data, particularly for marketing purposes or when we rely on legitimate interests. For the aggregate site counting, you do not need to write to us: the Statistical purposes switch in the cookie settings panel is the objection, and it works immediately.
Portability: You can request your data in a portable format to transfer to another service provider.
Withdraw Consent: Where we rely on your consent, you can withdraw it at any time. For analytics cookies, the quickest route is the Cookie settings control in the footer of any page.
To exercise any of these rights, contact us at [email protected]. We’ll respond within one month and won’t charge a fee unless your request is clearly unfounded or excessive.
Data retention
We keep your personal information only as long as necessary for the purposes for which we collected it. Our retention periods vary depending on the type of information:
Client Project Data: We typically retain this for seven years after project completion to meet our professional and legal obligations.
Marketing and Newsletter Data: We keep this until you unsubscribe or ask us to delete it.
Website Analytics: Google and PostHog each hold this data under a retention period set in our account with that provider. The two use different retention models, so a single figure would misdescribe one of them. Email [email protected] and we will tell you the current setting for either.
Financial Records: We retain these for seven years to comply with accounting and tax requirements.
When we no longer need your information, we securely delete or anonymise it.
Cookies and tracking
Our website uses cookies and similar technologies, in the three categories our Cookie Policy sets out:
Essential: One cookie, which records the cookie choices you make. It cannot be switched off, because it is what remembers that you switched something off.
Analytics: Google Analytics 4, PostHog keeping an id on your device, and session recording. None of it starts until you accept this category, and rejecting it changes nothing about what you can read or do here. The cookieless counting described under statistical information about site use is a separate matter, runs by default, and has its own switch in the same panel.
Functional: We set no functional cookies. A few features remember a preference in your browser’s local storage instead, which stays on your device.
You can change your cookie choices at any time using the Cookie settings control in the footer of any page, or through your browser’s own privacy settings.
Children’s privacy
Our services are designed for businesses and professional users. We don’t knowingly collect personal information from children under 16. If we discover we’ve inadvertently collected such information, we’ll delete it promptly.
Changes to this policy
We review this policy when our practices or the law change, and the date at the top of this page is the date of the last review. When we make significant changes, we’ll notify you by:
- Sending an email to our newsletter subscribers and clients
- Posting a notice on our website
- Including information in our service communications
Want a copy of your data, a correction, or to raise a concern? Write to [email protected] and we’ll respond within one month.