Last updated: 7 August 2026
CSITEX Ltd, trading as CSITEX, is the data controller for the information described here.
| What | Why | Lawful basis |
|---|---|---|
| Name, email, company and role from event registrations, plus your questions, chat messages and, if you take part, your voice and image in the recording | To run our events, send joining details and share the recording afterwards | Legitimate interests: delivering the event you registered for |
| Name and email, where you've opted in | To send you our newsletter | Consent |
| Name, email, company, role and notes on our conversations | To respond to enquiries and manage our contact records | Legitimate interests: running a business and following up with people who approach us |
| Responses to the IT Readiness Assessment | To generate your score and discuss it with you | Legitimate interests: providing the assessment you asked for |
| Contact details, business information, notes, documents and deliverables | To deliver our services | Performance of a contract |
| Billing details, invoices and payment records | To invoice you and keep proper accounts | Legal obligation |
Where we rely on legitimate interests, our interest is in running a small consultancy and delivering what people have asked us for. The information involved is business contact information, used in a way you'd reasonably expect. If you disagree in your case, tell us and we'll look at it again.
We don't collect special category data such as health or ethnicity, and we ask you not to send it to us.
Usually from you: a registration form, an enquiry, a conversation, or the work we do together.
If we approach you first, we'll typically have found your details from your public LinkedIn profile, your company website, Companies House, or an introduction. Where someone introduced us, we'll tell you who when we make contact.
Our events run on Microsoft Teams, and we record them. We tell you when you register, and Teams displays a notification to everyone in the session when recording starts.
Attendee cameras and microphones are switched off, so the recording captures the presentation rather than the people watching it.
We share the recording with everyone who registered, including people who don't attend on the day.
Teams also produces an attendance report showing who joined and for how long. We use it to judge whether an event was worth running, and nothing else.
We only send marketing emails to people who have asked for them. Every email has an unsubscribe link and it works immediately. You can also just reply and ask.
When you unsubscribe we keep your email address on a suppression list indefinitely, because that's the only way to be sure we don't add you back by accident. We don't use it for anything else.
We don't share our list with anyone.
We don't sell your information and we don't share it for anyone else's marketing.
We use established business suppliers to run our operation, who process information on our behalf under contract. They fall into these categories:
We'll tell you which specific supplier handles your information if you ask.
On AI: we use Claude, made by Anthropic, as a drafting and analysis aid. Where personal information enters it, we use a paid account with model training switched off, so your information is not used to train Anthropic's models, and Anthropic holds those conversations for a limited period, currently around 30 days, before deleting them. No decision affecting you is made by an AI tool. Everything we produce is reviewed and signed off by a person before it reaches you. If you'd prefer we didn't use AI on your work at all, tell us and we won't.
We'll also disclose information where we're legally required to, for example to HMRC or under a court order.
Most of our suppliers hold information in the UK or the European Economic Area. Some are based in the United States or hold data there.
Where information goes outside the UK, we rely on UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework, or the International Data Transfer Addendum to the standard contractual clauses, depending on the supplier.
When a retention period ends we delete the information or anonymise it.
Multi-factor authentication on every account that supports it, encrypted storage and devices, no shared logins, and access limited to the people working on your engagement, all of whom are bound by the same confidentiality terms.
If a breach happens that puts your rights at risk, we'll report it to the ICO within 72 hours and tell you without undue delay.
You have the right to get a copy of what we hold about you, have it corrected, have it deleted where we don't have a good reason to keep it, restrict what we do with it while a question is sorted out, object to us using it on the basis of legitimate interests, and receive it in a portable format where we hold it under consent or a contract.
Where we rely on consent, you can withdraw it at any time. That doesn't undo what we did before you withdrew it.
If you object to marketing we'll stop, no questions asked.
To use any of these, email privacy@csitex.co.uk. We'll respond within one month. It's free, and we won't ask you to justify the request.
Come to us first. Email privacy@csitex.co.uk or write to us at the registered office above. You can complain in whatever way suits you, including by replying to one of our emails. We'll acknowledge within 30 days and respond as quickly as we can after that.
You can also complain to the Information Commissioner's Office at any point, whether or not you've come to us first.
Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. 0303 123 1113. ico.org.uk/make-a-complaint
We update this statement from time to time. The date at the top tells you when it last changed.