Privacy Policy

How SoftExponent handles personal information.

This privacy policy explains what personal information SoftExponent collects, why we use it, who we may share it with, and the choices and rights available to you.

Last updated: 17 August 2026

1. Who we are

SoftExponent Ltd is a company registered in England and Wales under company number 17246625. Our registered office is 3rd Floor, 45 Albemarle Street, Mayfair, London W1S 4JL, United Kingdom.

SoftExponent provides IT support, cybersecurity, cloud, technology consulting and digital transformation services. For applicable data protection law, SoftExponent Ltd is the controller of the personal information described in this policy.

Contact point

For privacy enquiries, contact us at [email protected].

2. Information we collect

We may collect and use the following types of personal information, depending on how you interact with us:

  • Contact details, such as name, business email address, phone number, company name and job role.
  • Enquiry information, such as messages submitted through forms, consultation requests, service interests and project details.
  • Client service information, such as account contact details, support requests, onboarding information, service notes and operational communications.
  • Billing, order and transaction information, such as billing contact details, selected services, order and subscription information, payment status, invoices and transaction references. Payment card details are entered directly into the payment provider’s secure systems and are not stored by SoftExponent.
  • Account information, where an online customer account is created, including login identifiers, order history, subscription status and account preferences.
  • Website and technical information, such as IP address, browser type, device information, pages visited, referral source and cookie preferences.
  • Security and fraud prevention information, such as log data, access records, suspicious activity indicators and information needed to protect our website, systems and services.

3. How we use your information

We use personal information for legitimate business, service and compliance purposes, including to:

  • Respond to enquiries, consultation requests and support requests.
  • Provide IT support, cybersecurity, cloud, consulting and related services.
  • Create and manage client accounts, onboarding steps, plans, service records and communications.
  • Process orders, payments and recurring subscription arrangements.
  • Administer customer accounts, order history and subscription status.
  • Send transactional messages such as enquiry acknowledgements, order confirmations, payment information and service notices.
  • Prepare proposals, quotes, contracts, invoices and service updates.
  • Operate, maintain and improve our website, forms, client portal and digital services.
  • Protect our website, systems, clients and services from security threats, misuse and fraud.
  • Meet legal, accounting, regulatory, tax and record keeping obligations.
  • Send relevant service, administrative or business communications.

4. Lawful basis for processing

Where UK data protection law applies, we rely on one or more lawful bases depending on the purpose of processing.

  • Contract: where processing is needed to provide a service, respond to pre-contract enquiries, manage a client relationship, or take steps requested before entering into a contract.
  • Legitimate interests: where processing supports normal business operations, service improvement, client communication, website security, fraud prevention, business development or administration, provided those interests are not overridden by your rights and interests.
  • Legal obligation: where processing is required for tax, accounting, regulatory, legal or compliance reasons.
  • Consent: where we ask for permission, such as for certain cookies or optional marketing communications. Where consent is used, you can withdraw it at any time.

We do not intend to collect special category data through general website forms. Please avoid sending sensitive personal information unless it is necessary for the service or support request.

5. Who we share information with

We may share personal information with trusted providers where reasonably necessary to operate the website, process transactions, communicate with clients or deliver services. These may include:

  • WordPress, WooCommerce and WooCommerce Subscriptions for website, order, account and subscription functionality.
  • WooPayments, Stripe and associated payment infrastructure for secure payment processing, fraud prevention and transaction management.
  • WPForms for website enquiry handling.
  • Elementor Site Mailer and its email-delivery infrastructure for transactional website emails.
  • Microsoft 365 for business email, documents and communications.
  • Hosting, security, backup, analytics and website-support providers.
  • Technology vendors, subcontractors or specialist service partners involved in delivering an agreed client service.
  • Banks, accountants, insurers, professional advisers, regulators, courts or public authorities where reasonably necessary or legally required.

We do not sell personal information.

6. How long we keep information

We keep personal information only for as long as reasonably necessary for the purpose for which it was collected.

Enquiry and prospective-client information is retained while needed to respond, follow up and assess a potential engagement, and may be removed or anonymised when it is no longer reasonably required.

Order, subscription, contractual, billing and accounting records may normally be retained for up to six years after the end of the financial year to which they relate, or longer where required for an ongoing contract, legal obligation, dispute, regulatory enquiry or legal claim.

Account, technical, security and fraud-prevention information is retained according to the nature of the information, operational need, security risk and any applicable legal requirement. Information may be deleted or anonymised when it is no longer required.

7. How we protect information

We use appropriate technical and organisational measures to help protect personal information against unauthorised access, loss, misuse, disclosure or alteration.

  • Access controls and account protection.
  • Security monitoring and system hardening where appropriate.
  • Supplier selection and service management controls.
  • Secure handling of support, enquiry and client information.

No online service can be guaranteed completely secure, but we work to protect information in a proportionate and commercially responsible way.

8. Your data protection rights

Depending on the circumstances, you may have rights under UK data protection law, including the right to:

  • Request access to your personal information.
  • Ask for inaccurate information to be corrected.
  • Ask for information to be erased in certain circumstances.
  • Ask us to restrict or object to certain processing.
  • Request data portability in certain circumstances.
  • Withdraw consent where processing is based on consent.
  • You also have the right to complain to the Information Commissioner’s Office. Further information is available at https://ico.org.uk/.

To exercise your rights, contact us at [email protected]. We may need to verify your identity before responding.

9. Cookies and website analytics

Our website may use cookies and similar technologies to operate the site, improve performance, remember preferences, understand how visitors use the site, and support relevant website functionality.

Essential cookies may be needed for the website to work. Non-essential cookies, such as analytics or marketing cookies, should only be used where permitted and where the appropriate consent or preference mechanism is in place.

Cookie Policy

Further details about the cookies used on this website and the available choices are provided in our Cookie Policy.

10. International transfers

Some website, cloud, payment, email, security or technology providers may process information outside the United Kingdom. Where UK data protection law requires safeguards, we expect the relevant provider or transfer arrangement to use an applicable adequacy regulation, recognised contractual protection or another lawful transfer mechanism.

11. Changes to this policy

We may update this privacy policy from time to time to reflect changes to our services, website, legal requirements, suppliers or business operations. The latest version will be published on this page.

Privacy contact

Questions about this privacy policy?

Contact SoftExponent using the details below. We will review your request and respond as appropriate.