GEMBEX LIMITED PRIVACY POLICY
Type of website: Service-based consultancy website showcasing GEMBEX’s offerings, client recommendations, case studies, and contact forms. Effective date: 11th November 2025.
www.gembex.co.uk (the "Site") is owned and operated by Gembex Limited. Gembex Limited is the data controller and can be contacted at:
cj@gembex.co.uk
PURPOSE
The purpose of this privacy policy (this "Privacy Policy") is to inform users of our Site of the following:
The personal data we will collect;
Use of collected data;
Who has access to the data collected; and
The rights of Site users.
This Privacy Policy applies in addition to the terms and conditions of our Site.
GDPR
For users in the European Union, we adhere to the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, known as the General Data Protection Regulation (the "GDPR"). For users in the United Kingdom, we adhere to the GDPR as enshrined in the Data Protection Act 2018.
We have not appointed a Data Protection Officer as we do not fall within the categories of controllers and processors required to appoint a Data Protection Officer under Article 37 of the GDPR.
CONSENT
By using our Site users agree that they consent to:
The conditions set out in this Privacy Policy.
When the legal basis for us processing your personal data is that you have provided your consent to that processing, you may withdraw your consent at any time. If you withdraw your consent, it will not make processing which we completed before you withdrew your consent unlawful.
You can withdraw your consent by: - By contacting Gembex Limited at cj@gembex.co.uk or using the opt-out link provided in communications.
LEGAL BASIS FOR PROCESSING
We collect and process personal data about users in the UK only when we have a legal basis for doing so under Article 6 of the GDPR.
We rely on the following legal bases to collect and process the personal data of users in the UK:
Users have provided their consent to the processing of their data for one or more specific purposes;
Processing of user personal data is necessary for us or a third pary to pursue a legitimate interest. Our legitimate interest is not overriden by the interests or fundamenal rights and freedoms of users. Our legitimate interest(s) are: Providing professional services, improving user experience, protecting intellectual property, and maintaining website functionality.; and
Processing of user personal data is necessary for us to take, at the request of a user, steps before entering a contract or for the performance of a contract to which a user is a party. If a user does not provide the the personal data necessary to perform a contract the consequences are as follows: - GEMBEX may be unable to respond to enquiries, deliver services, or complete onboarding processes..
PERSONAL DATA WE COLLECT
We only collect data that helps us achieve the purpose set out in this Privacy Policy. We will not collect any additional data beyond the data listed below without notifying you first.
DATA COLLECTED AUTOMATICALLY
When you visit and use our Site, we may automatically collect and store the following information:
IP address;
Location;
Hardware and software details;
Clicked links;
Content viewed; and
Session duration, referral source (e.g. Google, LinkedIn).
DATA COLLECTED IN A NON-AUTOMATIC WAY
We may also collect the following data when you perform certain functions on our Site:
First and last name;
Email address;
Phone number; and
Project details, company name, service preferences, and any information voluntarily submitted via contact or onboarding forms.
This data may be collected using the following methods:
Through contact forms, onboarding forms, and direct email communication initiated by the user..
HOW WE USE PERSONAL DATA
Data collected on our Site will only be used for the purposes specified in this Privacy Policy or indicated on the relevant pages of our Site. We will not use your data beyond what we disclose in this Privacy Policy.
The data we collect automatically is used for the following purposes:
1. Understand how visitors use our website (e.g. which pages are most visited, how users navigate);
2. Improve site performance and content (e.g. refining layout, fixing broken links, optimising for devices) - Maintain website security and prevent misuse (e.g. detecting suspicious activity or unauthorised access;
3. Maintain website security and prevent misuse (e.g. detecting suspicious activity or unauthorised access attempts);
4. Analyse referral sources and session patterns (e.g. seeing whether users arrive via LinkedIn, Google, or direct links); and
5. Support internal reporting and business planning (e.g. identifying service interest trends or peak traffic times) Let me know if you’d like this phrased in GEMBEX’s brand tone or added to your full.
The data we collect when the user performs certain functions may be used for the following purposes:
Through contact forms, onboarding forms, and direct email communication initiated by the user..
WHO WE SHARE PERSONAL DATA WITH
Employees
We may disclose user data to any member of our organisation who reasonably needs access to user data to achieve the purposes set out in this Privacy Policy.
THIRD PARTIES
We may share user data with the following third parties:
1. LinkedIn → May collect data if users arrive via LinkedIn or interact with embedded content;
2. Microsoft Outlook or email hosting provider → Stores contact form submissions and client communications; and
3. Web hosting provider (e.g. SiteGround, GoDaddy, etc.) → May log IP addresses and basic access data for security and performance.
We may share the following user data with third parties:
1. Contact form submissions → Name, email address, message content (processed by your email hosting provider, e.g. Outlook or Microsoft 365);
2. Basic technical data → IP address, browser type, device type (logged by your web hosting provider for security and performance monitoring); and
3. Referral source and session metadata → e.g. if a user arrives via LinkedIn or another external link (may be logged by your hosting provider or visible in server logs).
We may share user data with third parties for the following purposes:
1. Delivering and storing contact form submissions → So GEMBEX can respond to enquiries and manage client communications;
2. Maintaining website functionality and security → Hosting providers may log basic technical data to detect issues or prevent misuse; and
3. Ensuring reliable email delivery and record-keeping → Email platforms store submitted data for follow-up and documentation.
Third parties will not be able to access user data beyond what is reasonably necessary to achieve the given purpose.
OTHER DISCLOSURES
We will not sell or share your data with other third parties, except in the following cases:
1. If the law requires it;
2. If it is required for any legal proceeding;
3. To prove or protect our legal rights; and
4. To buyers or potential buyers of this company in the event that we seek to sell the company.
If you follow hyperlinks from our Site to another Site, please note that we are not responsible for and have no control over their privacy policies and practices.
HOW LONG WE STORE PERSONAL DATA
User data will be stored until the purpose the data was collected for has been achieved.
You will be notified if your data is kept for longer than this period.
HOW WE PROTECT YOUR PERSONAL DATA
We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, or alteration. These include:
- Secure hosting infrastructure with firewall protection and access controls
- Encrypted data transmission via HTTPS
- Restricted access to submitted data, limited to authorised personnel only
- Regular monitoring and updates to maintain website security and performance
- Data minimisation practices, ensuring only necessary information is collected and retained
While we take all reasonable precautions to ensure that user data is secure and that users are protected, there always remains the risk of harm. The Internet can be insecure at times and therefore we are unable to guarantee the security of user data beyond what is reasonably practical.
YOUR RIGHTS AS A USER
Under the GDPR, you have the following rights:
1. Right to be informed.
2. Right of access.
3. Right to rectification.
4. Right to erasure.
5. Right to restrict processing.
6. Right to data portability; and
7. Right to object.
CHILDREN
We do not knowingly collect or use personal data from children under 16 years of age. If we learn that we have collected personal data from a child under 16 years of age, the personal data will be deleted as soon as possible. If a child under 16 years of age has provided us with personal data their parent or guardian may contact our privacy officer.
HOW TO ACCESS, MODIFY, DELETE, OR CHALLENGE THE DATA COLLECTED
If you would like to know if we have collected your personal data, how we have used your personal data, if we have disclosed your personal data and to who we disclosed your personal data, if you would like your data to be deleted or modified in any way, or if you would like to exercise any of your other rights under the GDPR, please contact us at cj@gembex.co.uk
HOW TO OPT-OUT OF DATA COLLECTION, USE OR DISCLOSURE
In addition to the method(s) described in the How to Access, Modify, Delete, or Challenge the Data Collected section, we provide the following specific opt-out methods for the forms of collection, use, or disclosure of your personal data specified below:
1.Voluntary data submission
→ Users can choose not to submit contact forms or onboarding details
2. Third-party disclosure (limited)
→ Users may refer to the privacy policies of GEMBEX’s email and hosting providers for additional opt-out options. You can opt-out by - Choosing not to submit personal data via website forms
→ No data is collected unless voluntarily provided
3. Contacting GEMBEX directly
→ Users can request access, correction, or deletion of their data at any time
→ Contact method: [Insert email address or contact form link]
4. Reviewing third-party provider policies
→ For data processed by hosting or email services, users may refer to those providers’ privacy policies for additional opt-out options.
ADDITIONAL CLAUSES
International Data Transfers
- We operate within the UK and do not transfer personal data internationally. If this changes, we will ensure appropriate safeguards are in place.
Policy Updates
- We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date.
Third-Party Links Disclaimer
- Our website may contain links to third-party sites. We are not responsible for their privacy practices and encourage you to review their policies.
MODIFICATIONS
This Privacy Policy may be amended from time to time to maintain compliance with the law and to reflect any changes to our data collection process. When we amend this Privacy Policy, we will update the "Effective Date" at the top of this Privacy Policy. We recommend that our users periodically review our Privacy Policy to ensure that they are notified of any updates. If necessary, we may notify users by email of changes to this Privacy Policy.
COMPLAINTS
If you have any concerns or complaints about how we handle your personal data, please contact us using the details provided in the Contact Information section. We will do our best to resolve the issue promptly and fairly.
If you feel your concern has not been addressed satisfactorily, you have the right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner’s Office (ICO).
Website: www.ico.org.uk
CONTACT INFORMATION
If you have any questions, concerns or complaints, you can contact us at cj@gembex.co.uk

