CEDX Systemscedxsystems.com
Legal

Privacy notice

This notice describes the personal data CEDX Systems Limited handles as a controller, about visitors to this site, people at customer and prospective customer organisations, candidates and suppliers. It does not describe the data we process on a customer's behalf inside their tenant; that is governed by the data processing agreement.

Version
6.4
Last updated
2 April 2026
Effective from
2 April 2026
Contents

1.About this notice

  1. 1.1This notice explains how CEDX Systems Limited handles personal data where it decides why and how that data is used. In data protection law that role is called the controller.
  2. 1.2Where CEDX handles personal data on behalf of a customer (everything inside a customer's tenant, including records about that customer's own employees and clients) CEDX acts as a processor. That relationship is governed by the data processing agreement rather than by this notice, and the customer, not CEDX, decides what happens to the data.
  3. 1.3This notice is written to meet the requirements of the UK General Data Protection Regulation and the Data Protection Act 2018, and of Regulation (EU) 2016/679 where it applies.
  4. 1.4Where a local notice has been issued for a particular country and it conflicts with this document, the local notice prevails for people in that country.

2.Who we are and how to reach us

  1. 2.1The controller is CEDX Systems Limited, registered in England and Wales under company number 07648321, whose registered office is at Sixth Floor, 40 Bishopsgate, London EC2N 4AJ, United Kingdom.
  2. 2.2The Data Protection Officer can be reached at privacy@cedxsystems.com, or by post at the registered office marked for the attention of the Data Protection Officer.
  3. 2.3CEDX Systems GmbH, Neue Mainzer Straße 52, 60311 Frankfurt am Main, is the appointed representative in the European Union for the purposes of Article 27 of Regulation (EU) 2016/679.
  4. 2.4Every request received at the address in clause 2.2 is logged on the day it arrives and acknowledged within five Working Days, whatever route it came by.

3.The personal data we collect

We collect different categories of data depending on the relationship. We do not collect more than we need for the purpose, and we do not collect special category data about visitors, customers or suppliers at all.

Site visitors
pages requested, referring page, approximate location derived from a truncated IP address, browser and device type, and any preference recorded in a cookie. We do not build a behavioural profile and we do not sell any of it.
Enquirers
name, work email address, telephone number where given, employer, job title, and the content of the enquiry itself.
Customer contacts
name, work contact details, role, the products the person administers, and a record of support tickets, service reviews and correspondence.
Users
authentication events, administrative actions and security telemetry, held as controller only for the purposes of securing the platform. Everything else a user does is customer data.
Candidates
application, curriculum vitae, right-to-work evidence, interview notes, assessment outcomes and, where offered a role, references.
Suppliers and partners
contact details for individuals at the organisation, due diligence responses, and payment details where the supplier is an individual or a sole trader.

4.Where the data comes from

  1. 4.1Most of the personal data we hold is given to us directly by the person it is about, or by their employer in the course of a commercial relationship.
  2. 4.2We receive some data from a customer organisation about its own staff, for example when it nominates administrators or names attendees for training.
  3. 4.3We collect technical data automatically when a person uses this site or the Services, as described in clause 7.
  4. 4.4We obtain a limited amount of business contact data from professional networks and from published company information, for the purpose described in clause 5.5. We tell recipients where we obtained their details in the first message we send.

5.Why we use it, and our lawful basis

We use personal data only for the purposes set out below, and each purpose has a stated lawful basis. Where the basis is legitimate interests, we have carried out and recorded a balancing assessment, a summary of which is available on request.

  1. 5.1To provide, support and administer the Services to a customer organisation, including managing accounts, entitlements and support tickets. Basis: performance of a contract, or legitimate interests where the individual is not themselves the contracting party.
  2. 5.2To secure the platform: detecting and investigating unauthorised access, abuse and fraud, and maintaining the audit trail. Basis: legitimate interests in protecting our systems and our customers' data, and legal obligation where a breach must be reported.
  3. 5.3To respond to an enquiry and to conduct the resulting sales process. Basis: steps taken at the request of the individual before entering into a contract, and legitimate interests.
  4. 5.4To invoice, collect payment, and keep accounting and tax records. Basis: performance of a contract and legal obligation.
  5. 5.5To send relevant business communications to a professional contact about products related to those their organisation already uses. Basis: legitimate interests. Every message carries a working unsubscribe link and honours it within two Working Days.
  6. 5.6To run recruitment, including assessing applications, arranging interviews and making offers. Basis: steps taken before entering into a contract, and legitimate interests in maintaining a record of hiring decisions.
  7. 5.7To meet our legal and regulatory obligations, to establish or defend legal claims, and to comply with a lawful request from a court or a regulator. Basis: legal obligation and legitimate interests.
  8. 5.8To improve the Services by analysing aggregate usage. This is done on data that has been aggregated so that it no longer identifies anyone; where it cannot be, the basis is legitimate interests and the analysis is limited to operational metrics.

6.Marketing and communications

  1. 6.1We send marketing only to business contacts, only about products and services related to our existing relationship or enquiry, and only to a work email address.
  2. 6.2We do not sell, rent or share personal data with a third party for that third party's own marketing purposes, and we do not participate in any advertising exchange.
  3. 6.3Every marketing message identifies who sent it and includes an unsubscribe link that works without requiring the recipient to log in or to give a reason.
  4. 6.4Unsubscribing from marketing does not stop operational messages about a service a person's organisation uses, such as incident notifications, release notices and invoices.
  5. 6.5A person may object to marketing at any time by writing to privacy@cedxsystems.com, and we will act on that objection across every list we hold.

7.Cookies and similar technologies

  1. 7.1This site sets a small number of cookies. Strictly necessary cookies maintain session state, remember a cookie preference and protect submitted forms; these are set without consent because the site cannot function without them.
  2. 7.2Analytics cookies are set only where the visitor has consented. Analytics are collected in aggregate, with IP addresses truncated before storage, and are retained for fourteen months.
  3. 7.3We do not set advertising cookies, we do not embed third-party tracking pixels, and we do not use fingerprinting techniques to identify a device across sites.
  4. 7.4A visitor may withdraw consent at any time through the cookie preference control in the site footer, or by clearing cookies in their browser. Withdrawal takes effect immediately and does not affect anything already collected lawfully.
  5. 7.5Inside the Services, cookies are used for authentication and session integrity. These are strictly necessary and cannot be disabled while a user is signed in.

8.Who we share it with

  1. 8.1We share personal data with service providers that process it on our behalf under a written contract that restricts them to our instructions. The current list of sub-processors is published and maintained on the sub-processors page.
  2. 8.2We share data with professional advisers (lawyers, auditors, insurers and accountants) where necessary and under a duty of confidence.
  3. 8.3We share data with a regulator, a court or a law enforcement authority where we are legally required to. We assess every request, we refuse those that are not valid, and we notify the affected customer unless we are legally prohibited from doing so.
  4. 8.4We may share data with an acquirer in connection with a merger, acquisition or sale of assets, subject to confidentiality obligations and to that acquirer being bound by this notice until it issues its own.
  5. 8.5We do not share personal data with any other third party for any other purpose.

9.International transfers

  1. 9.1Customer data stays in the region a customer has selected. Nothing in this clause changes that.
  2. 9.2The personal data we hold as controller is stored in the United Kingdom and in the European Union. A limited number of our sub-processors are established outside those territories, as identified on the sub-processors page.
  3. 9.3Where a transfer is made to a country without an adequacy decision, it is made under the International Data Transfer Agreement, or under the UK Addendum to the European Commission's standard contractual clauses, together with a documented transfer risk assessment.
  4. 9.4Supplementary measures applied to those transfers include encryption in transit and at rest with keys held in the originating region, pseudonymisation where the purpose allows it, and a contractual commitment from the recipient to challenge any unlawful access request and to notify us of it where the law permits.
  5. 9.5A copy of the relevant transfer mechanism, with commercial terms redacted, is available on request to privacy@cedxsystems.com.

10.How long we keep it

We keep personal data only for as long as the purpose requires, and then delete it or irreversibly anonymise it. The periods below are the defaults; a longer period applies only where a legal obligation or an active legal claim requires it.

Default retention periods for personal data held by CEDX Systems Limited as controller.
CategoryRetention periodTrigger
Site analytics14 monthsFrom collection
Enquiries that do not become customers24 monthsFrom last contact
Customer contact records6 yearsFrom the end of the contract
Contracts, invoices and tax records7 yearsFrom the end of the financial year
Security and audit logs held as controller13 monthsFrom the event
Unsuccessful job applications12 monthsFrom the decision, unless the candidate asks us to keep it longer
Employee records6 yearsFrom the end of employment
Records of data subject requests3 yearsFrom closure of the request
Default retention periods for personal data held by CEDX Systems Limited as controller.

11.How we protect it

  1. 11.1Personal data is encrypted in transit using TLS 1.3 and at rest using AES-256, with keys managed in a hardware security module and rotated annually.
  2. 11.2Access is granted on the principle of least privilege, is reviewed quarterly, and requires multi-factor authentication. Administrative access to production is time-bound, requires a documented reason and is recorded in the audit trail.
  3. 11.3Our information security management system is certified to ISO/IEC 27001 and we obtain an annual SOC 2 Type II report. Both are described in the compliance statement.
  4. 11.4We test the platform through an independent penetration test at least annually and after any material architectural change, and we operate a coordinated disclosure process for externally reported vulnerabilities.
  5. 11.5Where a personal data breach affecting data we hold as controller is likely to result in a risk to individuals, we notify the Information Commissioner's Office within seventy-two hours and, where the risk is high, the affected individuals without undue delay.

12.Your rights

Anyone whose personal data we hold as controller may exercise the following rights, free of charge, by writing to privacy@cedxsystems.com. We will not ask why. We may ask for enough information to be satisfied of identity, and no more.

  • Access, to be told whether we hold data about you and to receive a copy of it.
  • Rectification, to have inaccurate data corrected and incomplete data completed.
  • Erasure, to have data deleted where we no longer have a valid reason to keep it.
  • Restriction, to have processing paused while an accuracy or objection dispute is resolved.
  • Objection, to object to processing based on legitimate interests, and an absolute right to object to direct marketing.
  • Portability, to receive data you gave us in a structured, machine-readable format, or to have it sent to another controller.
  • Withdrawal of consent, where we rely on consent, to withdraw it at any time without affecting prior processing.
  1. 12.1We respond within one calendar month. Where a request is complex we may extend this by up to two further months, and we will tell you within the first month if we do, along with the reason.
  2. 12.2Where a request concerns data held inside a customer's tenant, we are the processor rather than the controller. We will forward the request to that customer without undue delay and tell you that we have done so; the customer decides how to respond.
  3. 12.3We will refuse a request only where the law permits it, and we will explain which exemption we are relying on.

13.Automated decision-making

  1. 13.1We do not make any decision producing a legal or similarly significant effect about an individual on the basis of automated processing alone.
  2. 13.2Automated tools are used to flag suspected fraud, abuse and account compromise. A flag suspends nothing on its own; a person reviews every case before any account is restricted.
  3. 13.3Job applications are read by a person. We do not use automated screening, ranking or video assessment at any stage of recruitment.
  4. 13.4AI features within the Services operate on customer data under the customer's instructions and within the same entitlements as the user on whose behalf they act. They are not used to make decisions about individuals on our own behalf.

14.Children

  1. 14.1The Services are enterprise software sold to organisations and are not directed at children. We do not knowingly collect personal data about anyone under the age of sixteen as a controller.
  2. 14.2Where a customer's own use of the Services involves data about children, that customer is the controller and is responsible for the lawful basis and for any additional safeguards required.
  3. 14.3If we become aware that we have collected data about a child as controller without a lawful basis, we will delete it promptly.

15.Changes to this notice

  1. 15.1We review this notice at least annually and whenever we make a material change to how we handle personal data.
  2. 15.2Where a change is material we will give notice by email to customer contacts, and by a prominent notice on this site, at least thirty days before it takes effect.
  3. 15.3Previous versions are retained and a copy of any prior version can be requested from privacy@cedxsystems.com.

16.Complaints

  1. 16.1If you are unhappy with how we have handled your personal data, please tell the Data Protection Officer first. Most concerns are resolved quickly once someone has actually looked at the file.
  2. 16.2You also have the right to complain to a supervisory authority. In the United Kingdom that is the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
  3. 16.3In the European Union you may complain to the supervisory authority in the country where you live or work, or where the issue arose. Our lead authority in the European Union is the Hessian Commissioner for Data Protection and Freedom of Information.
  4. 16.4Complaining to a supervisory authority does not limit any other remedy available to you, and we will not treat you differently for having done so.
Related documents

Questions about any of these documents go to our legal and privacy contacts. Enterprise customers may request countersigned copies through their account team.