Privacy Policy

Information controller

Oplex Works functions as the data controller from its base in North Josephfort, steering all decisions about your information. We act as your primary response point for concerns and complaints. Correspondence to info@oplexworks.co.uk reaches the controller and our data protection manager. Only staff with a defined purpose read submissions at this address; each communication is archived with full traceability to its response. Identity checks, if needed, require only the core identifying information.

Retention periods

Non-client inquiries are deleted one year after final correspondence, allowing enough time to recognise a returning contact without building a permanent record. Client records are retained six years following closeout, consistent with the contractual and accounting limitation timelines that ordinarily apply. Consent statements and analytics data, where analytics have been accepted, are kept twelve months before auto-deletion. Legal holds, unresolved complaints, and pending data requests bypass scheduled deletion entirely; affected data enters restricted-access storage until resolution, after which standard periods resume and run their course.

Information you provide

Our data collection and processing activities are restricted exclusively to your form submission information: your name, email, an optional phone number, and your message. The form is wholly and completely transparent—no covert optional fields or hidden data harvesting exists. Our technical security logs contain exclusively operational metadata—your IP address, the time, your browser type—and are kept completely separate from submissions. We absolutely reject purchasing external lists, merging third-party records with ours, and inferring your interests or income levels. Attached documents in email replies are protected with equal care and security.

International transfers

Our services operate from the EEA, so your information typically remains within EEA boundaries and does not normally leave. Processor backup systems located beyond the EEA necessitate Chapter V GDPR legal protections before any transfer proceeds: a European Commission adequacy decision, or standard contractual clauses accompanied by a documented transfer impact assessment. Processor locations and the applicable safeguards are supplied from info@oplexworks.co.uk upon request. Service modifications requiring an unprotected international transfer are declined outright; your consent does not authorise transfer by itself, and form use does not imply transfer agreement.

Encryption and access controls

The site operates over HTTPS exclusively; submissions are encrypted in transit and at rest within the database. Personnel access is role-based, limited to the small number who actually answer enquiries, each with an individual account, strong authentication, and a logged audit trail. Encrypted backups are maintained remotely, in a location separate from the primary systems, and tested regularly on a schedule. Security patches are applied promptly upon release; the same activity logs are monitored for irregularities; a written breach procedure addresses risk assessment and notification of the supervisory authority and affected persons within the legal seventy-two-hour timeframe where required.

Your data subject rights

You hold comprehensive GDPR rights under Articles 15 to 22. Access your information, correct factual errors, and demand deletion once no legal basis for processing remains. Pause processing during accuracy resolution while the dispute is being worked out, obtain the data you gave us in portable, machine-readable format, and oppose legitimate-interest processing at any time, indefinitely if you wish. Send requests to info@oplexworks.co.uk using plain language to exercise any of these rights; no formal template is necessary, and a plain message is enough. One-month response timeframe applies, extendable by two further months if the matter is complex, with advance notification given whenever an extension is used. Denials provide the explanations behind them.

Recipients and processors

We do not trade or lease your information to advertising platforms or third parties. Data is shared exclusively with infrastructure providers: the hosting service managing the website and database, and the mail delivery service reaching info@oplexworks.co.uk. These are GDPR-regulated processors under binding contracts, limited to our instructions, and required to maintain security. Tax and bank authorities receive payment information only when invoiced and legally required. All processor access is restricted to their operational scope, with annual reviews.

Our use of your information

The information serves to answer the question you raised, develop proposals if you seek one, and create a candid record supporting responsible practice administration. Where that exchange turns into client work, this same record backs delivery, billing, and the closeout handoff described elsewhere on this site. Form data is never used for marketing lists, advertising, profiling, newsletters, or automated decisions of any kind. No inquiry is scored, ranked, or fed into a growth tool, and none is analysed algorithmically behind the scenes. Once communication has clearly ended, its messages follow the deletion schedules set out below rather than indefinite storage.

GDPR foundations

Our processing finds justification in two GDPR grounds. Article 6(1)(a) GDPR authorises processing your contact form submission as consensual: you knowingly submit data to receive a response, and you may revoke consent at info@oplexworks.co.uk. Article 6(1)(f) GDPR authorises processing of messages tied to existing engagements or legal documentation: our legitimate interests in professional response and defensible records apply. Withdrawing consent terminates further processing; legally-mandated records remain restricted, not erased.

How to complain

You have the right to lodge complaints with a supervisory authority regarding how your data has been handled, in your EU state of habitual residence or wherever the alleged breach occurred. ICO serves as our regulatory authority for these matters, with a free, independent complaints procedure that charges no fee. Authority contact requires no prior notice to us, preserves every other legal option available to you, and carries no disadvantage in any ongoing exchange. We nevertheless ask you to contact info@oplexworks.co.uk first as well, because most concerns resolve quickly and directly once we understand them.