Last updated: 7 September 2026
This website does not run analytics, advertising trackers or profiling of any kind. The personal data it handles is what you choose to send us through the contact forms, plus the standard server logs every website generates. We also receive business contact details from people who introduce us to a business through our referral programme, which is covered in its own section below. This policy sets out the detail: what we hold, why we hold it, how long we keep it, and the rights you have over it.
Who we are
Novix IT Ltd is a managed IT and security partner for UK wealth management and chartered accountancy firms, operating from Edinburgh and London. For the personal data described in this policy, Novix IT Ltd is the data controller.
Novix IT Ltd is registered in Scotland under company number SC740691, with its registered office at 4 Redheughs Rigg, South Gyle, Edinburgh, Midlothian, EH12 9DQ, United Kingdom.
For anything in this policy, contact privacy@novixit.co.uk or call +44 (0) 333 358 0560.
The personal data we collect
- Contact forms. When you use a form on this site we collect your name, email address, subject and message. The submission is delivered to the relevant Novix IT inbox by email, and a copy is written to a log on our server first, so that a message cannot be lost if the email fails to send. That log is not published and is not a database you can be looked up in; it is covered by the How long we keep it section below.
- Direct correspondence. If you email or call us, we hold the contact details and content of that correspondence for as long as the matter needs it.
- Server logs. Our hosting infrastructure records standard technical logs: IP address, browser and device type, the pages requested and when. We use these for security monitoring and fault diagnosis, nothing else.
- Referrals. Someone may give us business contact details for a person at a business they think we should speak to. That information comes to us from them rather than from you, so it has its own section: Information we receive from referrals.
How we use it, and the lawful basis for each use
- Responding to your enquiry and any follow-up you ask for. Lawful basis: our legitimate interest in answering the people who contact us.
- Delivering services you or your firm have engaged us for. Lawful basis: performance of a contract.
- Keeping records that company, tax and regulatory law require us to keep. Lawful basis: legal obligation.
- Protecting our systems, including this website, through the server logs described above. Lawful basis: our legitimate interest in running secure infrastructure.
Contacting us does not put you on a marketing list. We do not run marketing campaigns, we do not buy or rent contact lists, and we do not use your data to profile you.
There is one exception to unsolicited contact, and we would rather be straightforward about it. We operate a referral programme, and if someone introduces your business to us we may contact you once to introduce ourselves. We will tell you who referred you when we do. The section Information we receive from referrals explains how that works, what we hold, and how to stop it.
Information we receive from referrals
Where this information comes from
We operate a referral programme. Under it, clients, partners, suppliers and other businesses can introduce us to a business they think would benefit from our services. When they do, they give us contact details for a person at that business.
This means we sometimes hold information about you that we received from someone else rather than from you. If that has happened, we will tell you when we first contact you, and we will tell you who referred you. You can also ask us at any time.
What we hold
Only business contact details: your name, your job title, the name of your business, and a business email address or business telephone number. Our referral terms prohibit referrers from sending us anything more than that, and we do not ask for or accept sensitive personal information through a referral.
Why we use it and our lawful basis
We use it for one purpose: to contact you once to introduce ourselves and ask whether you would like to discuss your IT and cyber security arrangements.
Our lawful basis is our legitimate interests, and specifically our interest in growing our business through introductions from people who already know our work. We have assessed this against your interests and rights, and we consider a single business-to-business approach, using business contact details, with a clear route to say no, to be proportionate. You can ask us for a summary of that assessment.
How long we keep it
If you tell us you are not interested, or you ask us to stop contacting you, we will stop immediately and keep only the minimum record needed to make sure we do not contact you again.
If we do not hear from you and no engagement follows, we delete or anonymise the referral within twelve months of the referral lapsing.
If you become a client, the rest of this Privacy Policy governs how we handle your information from that point.
Marketing by email and telephone
We will not send you marketing emails or text messages without your consent where the law requires that consent. Before we contact you for the first time, we check whether your business is a registered company or limited liability partnership, or whether you are a sole trader or a partnership, because different rules apply. Where we contact you by telephone, we check your number against the Telephone Preference Service and the Corporate Telephone Preference Service first.
Wherever we can, we ask the person referring you to introduce us by email with you copied in, so that our first contact with you is part of a conversation you are already part of.
Your rights
You have the same rights over information we receive through a referral as over any other personal data we hold about you. You can ask us what we hold, ask us to correct or delete it, object to us using it, and ask us to restrict how we use it. Because we rely on legitimate interests, you have an absolute right to object to us using your details for direct marketing, and we will stop.
To exercise any of these rights, contact us using the details in the Who we are section of this policy. You can also complain to the Information Commissioner’s Office at ico.org.uk.
Cookies and local storage
This site sets no advertising, analytics or tracking cookies. The one thing it stores in your browser is your light or dark theme preference, kept in your browser's local storage. That preference stays on your device and is never transmitted to us. You can remove it at any time by clearing this site's data in your browser settings.
That is why there is no cookie banner on this site: nothing here requires one.
Who we share it with
The suppliers who run our email and website hosting process data on our behalf as processors, under contract terms that restrict what they can do with it. We disclose personal data to authorities where the law requires it. We do not sell personal data, and we do not pass it to third parties for their own marketing.
International transfers
Where a supplier processes data outside the UK, the transfer is covered by UK adequacy regulations or the UK International Data Transfer Agreement or Addendum, so the data carries equivalent protection wherever it sits.
How long we keep it
Correspondence is kept for as long as the enquiry or relationship needs it, then for any further period a legal or regulatory obligation requires. Server logs rotate on our hosting provider's standard schedule. When data is no longer needed, it is deleted.
Contact details that reached us through a referral have their own retention rule, set out under Information we receive from referrals above: twelve months from the date the referral lapses.
Your rights
Under UK data protection law you have the right to:
- access the personal data we hold about you
- have inaccurate data corrected
- have data erased where there is no longer a reason for us to hold it
- restrict or object to how we process it
- receive the data you gave us in a portable format
To exercise any of these, email privacy@novixit.co.uk. We respond within one calendar month. If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office at ico.org.uk. We would value the chance to put it right first.
Data we process for client firms
When we deliver services to a client firm, we act as a processor on that firm's instructions, under the agreement that governs the engagement. This policy does not cover that data. If your personal data is held by one of our clients, the client firm is the controller, and questions about it should go to them. We will support the client in answering.
How we secure it
Novix IT holds current Cyber Essentials Plus certification, and access to the inboxes that receive your data is limited to the people who need it to deal with your enquiry.
Links to other sites
Pages on this site link to external sites, such as the Information Commissioner's Office and the suppliers whose services we discuss. Those sites set their own privacy practices, which this policy does not cover. Review their policies directly.
Changes to this policy
When this policy changes, the new version is published on this page with a revised date at the top. Significant changes will be flagged clearly rather than slipped in quietly.