Privacy Policy
Privacy Policy
Last updated: 14th April 2026
EPX Limited is committed to protecting your privacy. This policy explains how we collect, use, store, and share your personal information, in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
- Who We Are
EPX Limited is the data controller for your personal data. You can contact us at:
Address: EPX IT, Stafford Enterprise Park, Weston Road, Stafford, Staffordshire. ST18 0BF
Email: MPennington@epx.co.uk
Phone: 01785 878 311
Our privacy lead, Mark Pennington , is responsible for overseeing data protection matters and is your point of contact for any privacy questions.
- What Information We Collect
We may collect your name, email address, phone number, company name, job title, and any details you share when contacting us or using our services. When you visit our website we also collect your IP address, browser type, and usage data through cookies. If you are a client, we process information generated through the delivery of our services, such as support tickets and system logs.
- How We Use Your Information
We use your information for the following purposes, relying on the lawful basis shown in brackets:
- Responding to enquiries and preparing quotes (contractual necessity or pre-contractual steps).
- Delivering IT services and support to clients (performance of a contract).
- Sending marketing communications where you have opted in (consent), or to existing business contacts (legitimate interests).
- Improving our website and services (legitimate interests).
- Meeting our legal and regulatory obligations (legal obligation).
- Use of AI Tools
We use approved AI powered tools (including Microsoft 365 Copilot and Anthropic's Claude) to support service delivery and improve operational efficiency. Our use of these tools is governed by our internal Responsible AI Use Policy. Sensitive personal data is not processed through AI tools, and all AI providers act as our data processors under appropriate contracts.
We do not use AI or any automated system to make decisions about you that have a legal or similarly significant effect without human involvement.
- Who We Share Your Information With
We share your information only where necessary, with:
- Trusted technology providers and sub-processors who help us deliver our services (including cloud providers and the AI tool providers referenced above).
- Professional advisers such as accountants and lawyers.
- Regulators or law enforcement where we are legally required to do so.
Where data is transferred outside the UK, we rely on UK adequacy decisions or use the UK approved International Data Transfer Agreement (IDTA) or Addendum to ensure your data remains protected. We never sell your personal data.
- How Long We Keep Your Information
We keep enquiry data for up to 2 years from last contact, client data for 6 years after the end of our contract, and marketing data until you unsubscribe. Website analytics data is retained for up to 26 months. Data is securely deleted or anonymised when no longer needed.
- Your Rights
Under UK GDPR you have the right to access your data, to have it corrected or deleted, to restrict or object to our processing, to receive your data in a portable format, and to withdraw consent at any time where processing is based on it. You also have the right not to be subject to decisions made solely by automated processing.
To exercise any of these rights please contact us at MPennington@epx.co.uk. We will respond within one month.
If you are unhappy with how we handle your data, you can complain to the Information Commissioner's Office (ICO) at ico.org.uk, by calling 0303 123 1113, or by writing to Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
- Cookies
Our website uses cookies to help it function and to understand how visitors use the site. Essential cookies are used for security and basic functionality. Non-essential cookies (such as analytics) are only used with your consent, which you can give or withdraw through our cookie banner or your browser settings.
- Embedded Content
Our website may include embedded content from other sites (such as videos or maps). These third parties may collect data about you and use cookies in the same way they would if you visited their site directly.
- Changes to This Policy
We may update this policy from time to time to reflect changes to our services, technology, or legal obligations. The date at the top of this policy shows when it was last revised.
Document reference: POL-PRIV-001 | Version 2.0 | [14.04.26]