Xeniflow Ltd respects your privacy. This policy explains what personal data we collect, why we collect it, how we use it, and the rights you have under UK GDPR and the Data Protection Act 2018.
1. Who we are
Xeniflow Ltd ("Xeniflow", "we", "us", "our") is a workflow automation and systems integration consultancy based in Rotherham, United Kingdom. We are the data controller for personal information collected through this website and in the course of providing our services.
2. What information we collect
We may collect and process the following categories of personal data:
- Contact details you provide when you fill out our contact form, email us, or call us — typically your name, company, email address, and phone number.
- Enquiry details — the information you share about your business, workflows, or project when you get in touch.
- Technical data — such as your IP address, browser type, device information, and pages visited, collected automatically when you use our website.
- Cookie data — small text files placed on your device to help the site function correctly. See section 8 below.
- Client project data — information you share with us during a project that may incidentally contain personal data (for example, contact names inside a CRM we are integrating).
3. How we use your information
We use your personal information for the following purposes:
- To respond to your enquiry and communicate with you about potential or ongoing projects.
- To deliver our services — designing, building, and supporting workflow automations for your business.
- To send you invoices and manage our commercial relationship.
- To improve our website, services, and internal processes.
- To comply with legal, tax, and regulatory obligations.
- To send you occasional marketing emails — only if you've explicitly opted in, and always with a one-click unsubscribe.
4. Legal basis for processing
Under UK GDPR, we rely on the following legal bases:
- Contract — to deliver services you've engaged us for, and to communicate with you about your project.
- Legitimate interests — to respond to enquiries, improve our services, and prevent fraud.
- Consent — for marketing emails and non-essential cookies. You can withdraw consent at any time.
- Legal obligation — to keep financial records as required by HMRC and Companies House.
5. How long we keep your data
We keep personal data only as long as necessary:
- Enquiries that don't become projects — up to 12 months, then deleted.
- Active client records — for the duration of the engagement plus 6 years, to meet accounting and legal requirements.
- Marketing subscribers — until you unsubscribe, plus 30 days.
- Website analytics — typically 14 months.
6. Who we share your data with
We do not sell your personal data. We may share it with trusted third parties strictly to run our business and deliver services:
- Cloud providers — such as Google Workspace, Microsoft 365, and secure file storage used for email and documents.
- Accounting software — for invoicing and compliance.
- Website infrastructure — hosting, analytics, and email delivery providers.
- Professional advisers — accountants, solicitors, or insurers when required.
- Legal authorities — where we are legally required to do so.
Where data is transferred outside the UK (for example, to US-based cloud providers), we ensure appropriate safeguards are in place, such as the UK International Data Transfer Addendum or equivalent standard contractual clauses.
7. Your rights
Under UK GDPR you have the right to:
- Access a copy of the personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request erasure of your data ("right to be forgotten"), subject to legal retention obligations.
- Restrict or object to certain processing activities.
- Request data portability — receive your data in a structured, machine-readable format.
- Withdraw consent at any time where processing is based on consent.
- Lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
To exercise any of these rights, email luqman@xeniflowltd.uk. We'll respond within 30 days.
8. Cookies
Our website uses a small number of cookies:
- Essential cookies — required for the site to function (for example, remembering your cookie preference).
- Analytics cookies — anonymised data about which pages are visited, so we can improve the site. No personal identifiers are stored.
You can control cookies through your browser settings. Blocking all cookies may affect how the site works.
9. Security
We take reasonable technical and organisational measures to protect personal data against unauthorised access, loss, or misuse. These include encrypted connections (HTTPS), access controls, and secure credential management. No system is completely secure — if we ever become aware of a breach affecting your data, we'll notify you and the ICO where required.
10. Changes to this policy
We may update this policy occasionally. The "Last updated" date at the top of this page tells you when. Significant changes will be communicated to active clients by email.
11. Contact us
If you have any questions about this policy or how we handle your data, contact us: