Privacy Policy
How we collect, use, store and share personal data, and how you can exercise your rights under the UK GDPR and the Data Protection Act 2018.
01 Who we are
Scalixs builds and operates cold email systems for UK business-to-business companies. In this policy, "we", "us" and "our" mean Scalixs.
Scalixs is an unincorporated business operating from the United States, providing services to companies in the United Kingdom.
Contact: team@scalixs.com
For most of the activities described here we are the data controller. Where we send outreach on behalf of a client, our client is the controller and we act as their processor — see section 5.
Scalixs is based in the United States, and offers services to people in the United Kingdom and monitors their behaviour there. The UK GDPR therefore applies to us under Article 3(2), and we comply with it. Where Article 27 requires us to appoint a UK representative, we will appoint one and name them in this policy.
Questions about this policy, or about any personal data we hold, go to team@scalixs.com.
02 Personal data we collect
Website visitors
This website does not use analytics, advertising or tracking cookies. Our hosting provider may record standard server log data — IP address, browser type, pages requested and the time of the request — for security and to keep the site running, under its own retention policy. Web fonts are loaded from Google Fonts, which receives your IP address when a page loads. See our cookie policy for detail.
Enquiries and the contact form
If you contact us we collect your name, email address, and any company name, website and message content you choose to give us, together with the correspondence that follows.
Clients and client contacts
If you become a client we collect business contact details for the people we work with, billing and invoicing information, records of the services we deliver, and the campaign data needed to run and report on your system.
Prospect data used in outreach
To build target lists for our clients we collect business contact data — name, job title, employer, business email address and public profile information — relating to people in their professional capacity at corporate subscribers. This comes from public sources, licensed business data providers and email verification services.
We do not knowingly collect special category data, criminal offence data, or data relating to children. We do not use automated decision-making that produces legal or similarly significant effects.
03 Lawful bases
| Activity | Lawful basis |
|---|---|
| Responding to your enquiry | Consent — you chose to contact us. You can withdraw it at any time. |
| Providing services to clients | Performance of a contract, and legitimate interests in managing the relationship. |
| B2B outreach to corporate subscribers | Legitimate interests (Article 6(1)(f)). We complete a legitimate interests assessment for a campaign before it runs. Under PECR Regulation 22, prior consent is not required to send marketing email to corporate subscribers. |
| Invoicing, accounting and tax records | Legal obligation. |
| Site security and server logs | Legitimate interests in protecting our systems. |
Where we rely on legitimate interests, we balance those interests against the rights and freedoms of the individuals concerned and document that assessment before the campaign runs. You can request a summary of it.
04 What we do with it
- Reply to enquiries and arrange calls.
- Deliver, operate and support the services set out in our contract with a client.
- Build and verify target lists, send campaigns, and handle replies on a client's behalf.
- Monitor deliverability and produce reporting.
- Raise invoices and keep accounting records.
- Maintain suppression lists so that opt-out requests are honoured.
- Protect our systems and meet our legal obligations.
We do not sell personal data. We do not share it for anyone else's marketing purposes. We do not add enquiry details to a marketing list.
05 Outreach we send for clients
When we run campaigns for a client, that client is the data controller and we act as their processor under a written agreement that meets Article 28 of the UK GDPR. We process the data only on their documented instructions.
We email corporate subscribers only — limited companies, limited liability partnerships, Scottish partnerships and public bodies. We do not email sole traders or unincorporated partnerships. Every message identifies the sender, gives a valid business address and carries a working opt-out that we action promptly.
If you have received an email sent by us on a client's behalf and want it stopped, reply to the message with "unsubscribe", or write to team@scalixs.com with the sending address. We will suppress the address across our client's campaigns and pass the request to the controller.
06 How long we keep it
| Data | Retention period |
|---|---|
| Enquiries that do not become clients | 24 months from the last contact, then deleted. |
| Client records and correspondence | 6 years from the end of the contract, to meet contractual, tax and limitation requirements. |
| Invoices and accounting records | 6 years from the end of the relevant financial year. |
| Prospect and campaign data held for a client | As instructed by that client. On termination it is returned or deleted within 30 days, unless we are required to keep it by law. The accounts holding it belong to the client. |
| Suppression and opt-out records | Retained indefinitely. We need to keep a record of an opt-out in order to honour it. |
| Server logs | Held by our hosting provider under its own retention policy. We do not keep a separate copy. |
07 Third parties who process data for us
We use a small number of suppliers to run our business. Each is bound by a written contract that restricts them to processing data on our instructions and requires appropriate security.
- Website and email hosting providers.
- Domain registrars and DNS providers.
- Email sending and sequencing platforms.
- Business data providers and email verification services.
- Calendar and scheduling tools.
- Cloud storage and document tools.
- Accounting software and our accountants.
- Google Fonts, which serves the typefaces used on this site.
Note that for clients, the sending platform, mailbox and domain accounts are registered in the client's own name and billed to the client. A current list of the named suppliers we use is available on request from team@scalixs.com.
We may also disclose personal data where we are required to by law, by a court, or by a regulator, and to professional advisers where necessary.
08 International transfers
Scalixs is based in the United States. Personal data relating to people in the United Kingdom is therefore transferred out of the UK to Scalixs as a matter of course, not only when a supplier is involved. Some of our suppliers are also based outside the UK, principally in the United States and the European Economic Area.
For every such transfer, including transfers to Scalixs, we put one of the following safeguards in place:
- The UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.
- The UK Extension to the EU–US Data Privacy Framework, where the receiving US organisation is certified under it.
- UK adequacy regulations, where the destination country has been formally recognised as providing an adequate level of protection.
Where a transfer relies on the IDTA or the Addendum, we carry out a transfer risk assessment first. Because United States law permits public authorities to access data in ways that differ from UK law, we apply additional measures — encryption in transit and at rest, access limited to named individuals, and a policy of challenging any access request that appears unlawful.
You can request details of the safeguards applied to a particular transfer at any time.
09 Security
We apply access controls, multi-factor authentication, encrypted connections and least-privilege access to the accounts and systems we work in. Access to a client's accounts is limited to the people who need it, and is removed when a contract ends.
No system is completely secure. If a personal data breach occurs that is likely to result in a risk to individuals, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it, and tell the affected individuals where the law requires.
10 Your rights
Under the UK GDPR you have the right to:
- Be informed about how your data is used — this policy is part of that.
- Access a copy of the personal data we hold about you.
- Rectification of data that is inaccurate or incomplete.
- Erasure of your data, where there is no overriding reason for us to keep it.
- Restrict processing in certain circumstances, for example while an accuracy dispute is resolved.
- Object to processing carried out on the basis of legitimate interests. Where you object to direct marketing, that right is absolute and we will stop.
- Data portability, where processing is based on consent or contract and carried out by automated means.
- Withdraw consent at any time, where we rely on consent.
Exercising these rights is free of charge. We can charge a reasonable fee, or refuse, only where a request is manifestly unfounded or excessive — and we will explain why if that ever applies.
11 How to make a request
Email team@scalixs.com with the words "data protection request" in the subject line, and tell us what you would like us to do. Include the email address the data relates to so we can find the right records.
We may ask for proof of identity where we cannot otherwise be confident who is making the request. We will respond within one month. If a request is complex, we may extend that by up to two further months and will tell you within the first month if we do.
If your request relates to outreach we sent on behalf of a client, we will action the suppression immediately and pass the request to that client as controller.
12 Complaints
If you are unhappy with how we have handled your personal data, tell us first — most issues are quicker to fix directly. You also have the right to complain to the UK supervisory authority at any time:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
ico.org.uk/make-a-complaint
13 Changes to this policy
We update this policy when our practices or the law change. The date at the top shows when it was last revised. Material changes affecting clients will be notified by email.