Home/Privacy Notice
Privacy Notice
This notice explains what personal data AleCodex Software Solutions collects, why it is collected, how long it is kept and what rights you have over it. It is written to be read, not to be skimmed past.
Last updated
1. Who we are
AleCodex Software Solutions is a sole trader business operated by Alexander Fountain in the United Kingdom. AleCodex provides software development, web development, eCommerce development, automation, AI integration and related digital services.
For the purposes of the UK GDPR and the Data Protection Act 2018, Alexander Fountain trading as AleCodex Software Solutions is the data controller for the personal data described in this notice.
- Controller
- Alexander Fountain, trading as AleCodex Software Solutions
- alex@alecodex.com
- Website
- https://alecodex.com
- Location
- United Kingdom
There is no separate Data Protection Officer. AleCodex is a one-person business and Alexander Fountain handles all data protection matters directly.
2. What this notice covers
AleCodex handles personal data in two distinct roles, and it matters which one applies to you.
As a controller — this notice applies
When you visit this website, send an enquiry, book a discovery call, become a client or receive an invoice, AleCodex decides why and how your data is used. That is the relationship this notice describes.
As a processor — the client's own notice applies
When AleCodex builds, hosts, maintains or supports a system for a client, that system may contain personal data belonging to the client's own customers, staff or users. In that situation AleCodex acts as a processor on the client's written instructions, and the client remains the controller.
That work is governed by a written agreement meeting the requirements of Article 28 of the UK GDPR, and AleCodex will not use that data for its own purposes. If you are an end user of a system AleCodex built for someone else, you should read that organisation's privacy notice, not this one.
3. Information we collect
Information you give us
- Name
- Email address
- Telephone number
- Company or business name
- Website address
- Project enquiry details, including any information you choose to put in a message
- Billing details and payment information
Information collected automatically
- Standard server log data recorded by our hosting provider, including IP address, browser type, referring page and the time of the request. This is generated automatically whenever any website is loaded and is used for security and reliability.
- Aggregated website usage statistics, if and when analytics is enabled. See the Cookie Notice for the current position.
Information we do not collect
We do not ask for, and do not want, special category data — such as health information, racial or ethnic origin, political opinions, religious beliefs, biometric data, or details of criminal convictions. Please do not include information of that kind in an enquiry form or email. If you send it anyway, it will be deleted once the enquiry has been dealt with.
4. Where we get it from
Personal data reaches us in a small number of ways:
- Directly from you, through the enquiry form, email, telephone or a discovery call
- Automatically, through server logs when you load a page
- From publicly available business sources, such as a company website or a public LinkedIn profile, where you have asked us to look at your existing setup
- From a referral, where an existing client or contact has introduced you
5. How we use it, and our legal basis
Under the UK GDPR we must have a lawful basis for every use of personal data. The table below sets out what we do and which basis applies.
| What we do | Data used | Lawful basis |
|---|---|---|
| Reply to your enquiry and arrange a discovery call | Name, email, phone, company, enquiry details | Legitimate interests — responding to someone who has approached us about work |
| Prepare quotations and written proposals | Name, contact details, company, project requirements | Steps taken at your request before entering a contract |
| Deliver the services you have engaged us for | Contact details, project and account information | Performance of a contract |
| Provide support, maintenance and care plan work | Contact details, system and support ticket information | Performance of a contract |
| Issue invoices and take payment | Name, billing address, company, payment details | Performance of a contract |
| Keep accounting and tax records | Invoices, payment records, correspondence | Compliance with a legal obligation |
| Keep the website secure and available | Server log data including IP address | Legitimate interests — protecting our systems and visitors |
| Understand how the website is used | Aggregated, non-identifying usage statistics | Consent, where analytics cookies or similar technologies are used |
| Send occasional updates about our services | Name and email address | Consent, which you can withdraw at any time |
| Establish, exercise or defend a legal claim | Whatever is relevant to the matter | Legitimate interests — protecting our legal position |
6. Our legitimate interests
Where we rely on legitimate interests, the UK GDPR requires us to say what those interests are and to balance them against your rights. Ours are:
- Being able to answer someone who has contacted us about a potential project
- Running the business efficiently and keeping accurate records of our work
- Keeping our website and our clients' systems secure and available
- Protecting our legal position if a dispute arises
In each case the processing is limited to what is necessary, involves ordinary business contact details rather than sensitive information, and is what a person contacting a software business would reasonably expect. You can object to processing based on legitimate interests at any time — see Your rights.
7. Marketing
We do not add enquiry details to a marketing mailing list. If you contact us about a project, your details are used to answer you and to deliver the work — nothing else.
If we ever send service updates or similar messages, it will be because you asked to receive them, and every message will carry a one-click unsubscribe. Withdrawing consent is as easy as giving it, and it will not affect any work we are doing for you.
We do not sell personal data, and we never will.
9. Transfers outside the UK
Some of the providers listed above are based outside the United Kingdom, or store data outside it. Our website hosting is provided by Netlify, Inc., a company based in the United States.
Where personal data is transferred outside the UK, we make sure at least one of the following applies:
- The country has UK adequacy regulations, meaning the UK government has decided it offers an equivalent standard of protection
- The transfer is covered by an International Data Transfer Agreement, or the UK Addendum to the European Commission's Standard Contractual Clauses
- The provider participates in the UK Extension to the EU–US Data Privacy Framework
You can ask us for more detail about the safeguards applying to a particular transfer by emailing alex@alecodex.com.
10. How long we keep it
We keep personal data only for as long as there is a reason to, then delete it.
| Record | Retention period | Why |
|---|---|---|
| Enquiries that do not become projects | 12 months from the last contact | To pick up the thread if you come back, and to show what was said |
| Client project records and correspondence | 6 years after the engagement ends | Contractual limitation periods and professional record keeping |
| Invoices, payments and accounting records | 6 years after the end of the relevant tax year | HMRC and statutory accounting requirements |
| Website server logs | Up to 30 days, as retained by the hosting provider | Security monitoring and fault diagnosis |
| Marketing consent records | Until consent is withdrawn, then a minimal record of the withdrawal | To honour your choice and evidence that we did |
Where data no longer needs to be identifiable, we may anonymise it and keep the aggregate figures instead. Anonymised data is no longer personal data.
11. How we protect it
We take appropriate technical and organisational measures to keep personal data secure, including:
- Encryption in transit — this website is served over HTTPS with HSTS enabled
- Multi-factor authentication on business accounts wherever it is offered
- A password manager, with unique credentials for every service
- Access limited to the people who genuinely need it, which is normally one person
- Encrypted device storage and regular security updates
- Reputable providers chosen with their security posture in mind
No system is completely secure, and we cannot guarantee the security of data sent to us over the internet. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it, and tell you directly where the risk to you is high.
12. Your rights
Under the UK GDPR you have the following rights over your personal data:
| Right | What it means |
|---|---|
| Access | Ask for a copy of the personal data we hold about you |
| Rectification | Have inaccurate data corrected, or incomplete data completed |
| Erasure | Ask us to delete data where there is no longer a good reason to keep it |
| Restriction | Ask us to pause using your data while a concern is resolved |
| Objection | Object to processing we carry out on the basis of legitimate interests |
| Portability | Receive data you gave us in a structured, machine-readable format |
| Withdraw consent | Withdraw consent at any time, where consent is the basis we rely on |
| Automated decisions | Not be subject to a decision made solely by automated means |
How to exercise them
Email alex@alecodex.com. You do not need to use a particular form of words, and there is no charge.
We will respond within one month. If a request is complex, or you have made several, we may extend that by up to two further months — we will tell you within the first month if that happens and explain why. We may need to confirm your identity before releasing personal data, which is a safeguard for you rather than an obstacle.
Some rights are qualified rather than absolute. For example, we cannot delete invoices we are legally required to keep for tax purposes. Where we cannot do what you have asked, we will explain why.
13. Complaints
If you are unhappy with how we have handled your personal data, please tell us first at alex@alecodex.com — most issues are quicker to fix directly.
You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority for data protection. Contacting us first is not a precondition.
- Website
- ico.org.uk
- Helpline
- 0303 123 1113
- Post
- Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
15. Automated decisions
We do not make decisions about you using solely automated means, and we do not carry out profiling that produces legal effects or similarly significant effects for you. Quotes, proposals and project decisions are made by a person.
16. Children
Our services are aimed at businesses and are not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, email alex@alecodex.com and we will delete it.
17. Changes to this notice
We may update this Privacy Notice from time to time — for example if we start using a new service provider or offer a new service. The current version is always published at alecodex.com/privacy.html and the date at the top shows when it last changed.
If a change materially affects how we use your data, we will take reasonable steps to tell you directly.
18. Contact
Any question about this notice, or about how your data is handled, goes to the same place:
- Name
- Alexander Fountain
- Business
- AleCodex Software Solutions
- alex@alecodex.com
- Phone
- +44 7935 279674
- Website
- https://alecodex.com