Skip to content
Systems Horizon
  • Home
  • AI Solutions
  • Software Development
  • Services
  • Industries
  • Contact
Start a Project
Systems Horizon
Home AI Services Contact
Navigation
Home AI Solutions Software Development Services Industries Contact
Legal
Privacy Policy Cookie Policy Terms & Conditions
Start Your Digital Transformation
Legal

Privacy Policy

How Systems Horizon collects, uses and protects your personal data under UK GDPR and the Data Protection Act 2018.

On this page

  • 1. Introduction & Who We Are
  • 2. The Personal Data We Collect
  • 3. How We Collect Your Data
  • 4. How and Why We Use Your Data
  • 5. Marketing Communications
  • 6. Who We Share Your Data With
  • 7. International Transfers
  • 8. Data Retention
  • 9. Data Security
  • 10. Your Rights Under UK GDPR
  • 11. Cookies
  • 12. Children's Privacy
  • 13. Third-Party Links
  • 14. Changes to This Policy
  • 15. Complaints
  • 16. Contact Us

Last updated: 2 August 2026

1. Introduction & Who We Are

Systems Horizon ("Systems Horizon", "we", "us", "our") is a UK-focused IT services and software technology company providing software development, website and web application development, mobile applications, AI and machine learning solutions, automation services, SaaS product development, enterprise applications and technology consulting to clients ranging from startups to enterprises, in the UK and internationally.

We are committed to protecting your privacy and handling your personal data responsibly, lawfully and transparently. This Privacy Policy explains what personal data we collect when you visit our website, make an enquiry, book a consultation or otherwise interact with us; how and why we use it; who we share it with; and the rights you have under the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018.

For the purposes of data protection law, Systems Horizon is the data controller of personal data relating to visitors to this website and prospective clients. Where we process personal data on behalf of a client in the course of delivering services (for example, data contained in systems we build or maintain), we generally act as a data processor, and that processing is governed by our contract with the client rather than this policy.

If you have any questions about this policy or our data practices, please contact us at info@systemshorizon.com.

2. The Personal Data We Collect

Depending on how you interact with us, we may collect the following categories of personal data:

  • Contact and enquiry data — information you provide through our contact form or by email, including your name, email address, company name, telephone number (if provided) and details of your project or enquiry.
  • Consultation booking details — information you provide when arranging a consultation, such as your name, contact details, organisation, preferred dates and times, and a summary of the matters you would like to discuss.
  • Technical and usage data — information collected automatically when you browse our website, such as your IP address, browser type and version, device type, operating system, referring pages, pages visited and general interaction with the site. Analytics data of this kind is collected only where you have consented to analytics cookies (see our Cookie Policy).
  • Communications data — records of correspondence between you and us, including emails, messages, meeting notes and call records.
  • Business contact data — where you or your organisation become a client, we hold the business contact details of relevant personnel (names, job titles, work email addresses and phone numbers) needed to manage the engagement.

We do not ask for, and you should not submit through our website, any special category data (such as information about health, religion or political opinions) or financial account details. Our contact form is intended for business enquiries only.

3. How We Collect Your Data

We collect personal data in three main ways:

  • Directly from you — when you complete our contact form, email us, book a consultation, speak with us by phone or video call, attend a meeting, or enter into a contract with us.
  • Automatically, with your consent — through cookies and similar technologies when you browse our website. Non-essential cookies (analytics, functional and marketing) are set only after you opt in. You can learn more, and change your choices at any time, in our Cookie Policy.
  • From third parties — occasionally we receive business contact information from referrals, from your colleagues in the course of an engagement, or from publicly available sources such as your organisation's website, Companies House or professional networking platforms, where it is relevant to a business relationship.

4. How and Why We Use Your Data

Under the UK GDPR, we must have a lawful basis for each use of your personal data. The table below sets out our main purposes and the corresponding lawful bases:

PurposeData usedLawful basis
Responding to enquiries and arranging consultationsContact and enquiry data; consultation booking details; communications dataLegitimate interests (responding to business enquiries) and, where relevant, steps taken at your request prior to entering into a contract
Providing our services and managing client engagements, including invoicing and account administrationBusiness contact data; communications dataPerformance of a contract with you or your organisation
Understanding how our website is used and improving its content and performanceTechnical and usage dataConsent (analytics cookies load only after you opt in)
Sending marketing communications about our services, insights and updatesContact dataConsent — or, for existing clients, legitimate interests under the PECR soft opt-in (you may opt out at any time)
Maintaining the security of our website and systems, and preventing fraud or misuseTechnical and usage data; communications dataLegitimate interests (protecting our business and users)
Complying with legal and regulatory obligations, such as accounting, tax and record-keeping requirementsBusiness contact data; transaction recordsLegal obligation

Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms and are satisfied that our processing is proportionate and within your reasonable expectations. We do not use your personal data for automated decision-making that produces legal or similarly significant effects on you.

5. Marketing Communications

We send marketing emails — such as service updates, insights and offers — only where you have opted in to receive them, or where permitted under the "soft opt-in" rules in the Privacy and Electronic Communications Regulations (PECR) for existing clients, in which case you are always given a clear opportunity to opt out.

You can unsubscribe at any time by clicking the unsubscribe link included in every marketing email, or by contacting us at info@systemshorizon.com. Withdrawing from marketing does not affect service-related communications we need to send you as part of an active engagement (for example, project updates or invoices), and it does not affect the lawfulness of processing carried out before you withdrew.

6. Who We Share Your Data With

We do not sell your personal data to anyone. We share it only where necessary, with:

  • Service providers and subprocessors — trusted third parties who support our operations, such as website hosting providers, email and productivity platforms, customer relationship management tools, scheduling tools and, where you have consented, analytics providers. These providers act on our documented instructions under contracts that impose appropriate data protection and confidentiality obligations.
  • Professional advisers — accountants, auditors, insurers, bankers and lawyers, where reasonably necessary for the running of our business.
  • Authorities and regulators — courts, law enforcement, HMRC or other public bodies, where we are legally required to disclose information or where disclosure is necessary to protect our legal rights.
  • Business transfers — a prospective buyer or successor in the event of a merger, acquisition or reorganisation of our business, subject to appropriate safeguards.

7. International Transfers

Some of our service providers process data outside the United Kingdom, for example in the European Economic Area or the United States. Where we transfer personal data outside the UK, we ensure an equivalent level of protection by relying on one or more of the following safeguards:

  • UK adequacy regulations — transfers to countries the UK Government has determined provide adequate protection for personal data;
  • Appropriate safeguards — the UK International Data Transfer Agreement (IDTA), or the EU Standard Contractual Clauses supplemented by the UK International Data Transfer Addendum, together with supplementary technical and organisational measures where appropriate.

You can contact us at info@systemshorizon.com for further information about the safeguards applied to specific transfers.

8. Data Retention

We keep personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting and reporting requirements. Our standard retention periods are:

  • Enquiry and consultation data — retained for up to 24 months after our last contact with you, so we can respond to follow-up questions, unless the enquiry leads to an engagement;
  • Client and contract records — retained for the duration of the engagement and for 6 years afterwards, in line with limitation periods for contractual claims and UK tax and accounting requirements;
  • Marketing data — retained until you unsubscribe, after which we keep a minimal suppression record so we do not contact you again;
  • Cookie consent records — your cookie preferences are stored in your browser under the key sh_cookie_consent_v1 for up to 12 months, after which you will be asked for your preferences again;
  • Website analytics data — retained in accordance with the retention settings of the analytics tools described in our Cookie Policy, where you have consented to their use.

When personal data is no longer required, we securely delete or anonymise it.

9. Data Security

We take the security of personal data seriously and apply technical and organisational measures appropriate to the risk, including:

  • encryption of data in transit using TLS across our website and communication channels;
  • access controls based on the principle of least privilege, with multi-factor authentication on key business systems;
  • secure software development practices, including code review and dependency management, reflecting our expertise as a software engineering business;
  • vetting of service providers and contractual data protection obligations on those who process data for us;
  • staff confidentiality obligations and data protection awareness; and
  • procedures for identifying, containing and responding to security incidents.

No system can be guaranteed to be completely secure, but in the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) without undue delay and, where required, within 72 hours, and will inform affected individuals where the risk is high.

10. Your Rights Under UK GDPR

Subject to certain conditions and exemptions, you have the following rights in relation to your personal data:

  • Access — to request a copy of the personal data we hold about you;
  • Rectification — to have inaccurate data corrected and incomplete data completed;
  • Erasure — to have your data deleted in certain circumstances, for example where it is no longer needed for the purpose it was collected;
  • Restriction — to limit how we use your data in certain circumstances, for example while a dispute about accuracy is resolved;
  • Data portability — to receive the data you provided to us in a structured, commonly used, machine-readable format where processing is based on consent or contract and carried out by automated means;
  • Objection — to object to processing based on legitimate interests, and to object at any time to direct marketing, in which case we will stop;
  • Withdrawal of consent — where processing is based on consent (such as analytics cookies or marketing emails), to withdraw that consent at any time, without affecting processing carried out beforehand.

To exercise any of these rights, contact us at info@systemshorizon.com. We do not normally charge a fee, and we will respond within one month of receiving your request. If a request is complex or we receive several from you, we may extend this by up to two further months, in which case we will tell you and explain why. We may ask you to verify your identity before acting on a request, to protect your data from unauthorised disclosure.

11. Cookies

Our website uses a small number of cookies and similar technologies. Strictly necessary storage — including your saved consent preferences, held in your browser under the key sh_cookie_consent_v1 — operates without consent, while analytics, functional and marketing tools load only after you opt in. Full details of each category, the technologies that may be set when enabled, and how long they last are set out in our Cookie Policy. You can change or withdraw your choices at any time via cookie settings, also available in the website footer.

12. Children's Privacy

Our website and services are directed at businesses and business professionals and are not intended for children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us at info@systemshorizon.com and we will delete it promptly.

13. Third-Party Links

Our website may contain links to third-party websites, such as client sites we have built, technology partners or professional profiles. Clicking those links may allow third parties to collect data about you. We do not control these websites and are not responsible for their privacy practices. We encourage you to read the privacy policy of every website you visit.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies or legal obligations. When we do, we will publish the revised version on this page and update the "Last updated" date at the top. Where a change materially affects how we use your personal data, we will take reasonable steps to bring it to your attention, for example by a notice on our website or, where appropriate, by email. Please review this page periodically to stay informed.

15. Complaints

If you are unhappy with how we have handled your personal data, please contact us first at info@systemshorizon.com so that we can try to resolve your concern directly. We take complaints seriously and will respond promptly.

You also have the right to lodge a complaint at any time with the UK supervisory authority for data protection, the Information Commissioner's Office (ICO):

  • Website: ico.org.uk
  • Helpline: 0303 123 1113
  • Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

16. Contact Us

If you have any questions about this Privacy Policy, our data practices, or your rights, you can reach us at:

  • Email: info@systemshorizon.com
  • Contact form: systemshorizon.com — contact

This policy should be read alongside our Terms & Conditions and our Cookie Policy.

Systems Horizon — Build · Design · Develop

AI-powered solutions, enterprise software and automation platforms — engineered for businesses that want to operate smarter.

Company

  • Home
  • AI Solutions
  • Software Development
  • Industries
  • Why Systems Horizon
  • Contact

Services

  • AI & Machine Learning
  • Custom Software
  • Web & Mobile Apps
  • Automation
  • SaaS Development
  • Consulting

Legal

  • Privacy Policy
  • Cookie Policy
  • Terms & Conditions

© 2026 Systems Horizon. All rights reserved.

Engineered for the future · Delivering worldwide