ValenPath Systems Logo
← Back to homepage

Customer Privacy Notice

Last updated: 11/09/2026

Version: 2

This privacy notice tells you what to expect us to do with your personal information.

Contact details

Email: [email protected]

Data Controller: ValenPath Systems Ltd is the data controller for the personal information described in this privacy notice. We decide what personal information we collect and how we use it, and we are responsible for ensuring that the processing complies with UK data protection law.

What information we collect, use, and why

To provide and improve products and services for clients

For information updates or marketing purposes

To comply with legal requirements

For recruitment purposes

For dealing with queries, complaints or claims

Data protection rights

Under UK data protection law, we must have a "lawful basis" for collecting and using your personal information. There is a list of possible lawful bases in the UK GDPR. You can find out more about lawful bases on the ICO's website.

Which lawful basis we rely on may affect your data protection rights. The rights listed below are set out in brief.

Read more about your data protection rights

For full details about any right listed above—including the legal basis, scope, and exemptions that may apply—please visit the Information Commissioner's Guide to Data Subject Rights.

If you make a request, we must respond to you without undue delay and in any event within one month.

To make a data protection rights request, please contact us using the contact details at the top of this privacy notice.

Our lawful bases for collecting or using personal information

To provide and improve products and services for clients

For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.

For information updates or marketing purposes

For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.

To comply with legal requirements

For recruitment purposes

For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.

For dealing with queries, complaints or claims

Where we get personal information from

How long we keep information

Category of Personal Information Examples Retention Period Reason / Notes Client account information Names, email addresses, organisation details, authentication data Duration of client relationship + 6 years Necessary to operate accounts and retain records for contractual and legal purposes (e.g. HMRC). Service usage data / technical metadata Logs, error reports, system events, usage analytics Up to 12 months Used for troubleshooting, security and improving services. Retained only as long as necessary. Project and consultancy records Documents, deliverables, correspondence, notes Duration of project + 6 years Required for contract management, audit and potential legal claims. General enquiries Emails, contact forms, messages Up to 12 months Retained to respond to enquiries and maintain business records. Deleted sooner if no longer needed. Complaints or claims Complaint details, investigation notes correspondence 6 years Standard limitation period for legal claims in the UK. Marketing information Email addresses, communication preferences Until consent is withdrawn or 24 months of inactivity Retained only while consent is valid or legitimate interest applies. Recruitment information CVs, cover letters, interview notes 12 months Retained for future opportunities and to manage recruitment processes. Financial records Invoices, payment records, transaction details 6 years Required under HMRC rules. Security and access logs Authentication logs, access attempts Up to 12 months Required for security monitoring and incident investigation. Backups System backups containing personal data Up to 90 days Rolling backup cycle for disaster recovery. Automatically overwritten.

Who we share information with

Data processor: Microsoft Corporation – Cloud services provider (email, productivity, and storage), Technology sector, headquartered in the United States with EU / UK data centres.

This data processor does the following activities for us: We use Microsoft Corporation as a cloud services provider for business email (Outlook), file storage (OneDrive) and productivity tools (Microsoft 365). Microsoft processes personal information only on our behalf and only under our instructions. They host and transmit the information we store within these services, such as client contact details, correspondence and project documents, and they do so in accordance with UK data protection law. Microsoft acts solely as a data processor for ValenPath Systems Ltd.

Sharing information outside the UK

Where necessary, we may transfer personal information outside of the UK. When doing so, we comply with the UK GDPR, making sure appropriate safeguards are in place.

Organisation name: Microsoft Corporation

Category of recipient: Cloud services provider (email, productivity, and storage) – Technology sector

Country the personal information is sent to: Most data is stored in UK or EU data centres, but limited processing may occur in the United States or other countries where Microsoft or its authorised subprocessors operate.

How the transfer complies with UK data protection law: Addendum to the EU Standard Contractual Clauses (SCCs)

How to complain

If you have any concerns about our use of your personal information, you can make a data protection complaint to us:

If you remain unhappy with how we've used your data after raising a complaint with us, you can also complain to the ICO:

Information Commissioner's Office

Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Helpline: 0303 123 1113

Website: ico.org.uk/make-a-complaint