Privacy statement
Version 1.0 · Effective [DD Month YYYY] · Last reviewed [DD Month YYYY]
1. Who we are
Scicon Systems Limited ("Scicon", "we", "us") is a company registered in Scotland, company number [SC000000], with its registered office at [Address line 1, Town], Aberdeenshire, [Postcode], Scotland. We are the data controller for the personal data described in section 4 of this notice.
We are registered with the Information Commissioner's Office under registration number [ZA000000]. For anything relating to this notice or to your personal data, contact privacy@sciconsystems.com, or write to the Data Protection Lead at the registered office above.
Our two different roles
Scicon acts in two capacities, and it matters which one applies to you.
As a controller — for our website visitors, our partner and prospective partner contacts, job applicants, and supplier contacts. We decide why and how that data is used, and this notice explains it.
As a processor — for personal data held inside our products on behalf of the organisation that licenses them, such as user accounts, authentication events, shared content and activity records. In those cases that organisation (or, where a partner has deployed on their behalf, their client) is the controller, they decide what is collected and how long it is kept, and their own privacy notice governs it. We process that data only on their documented instructions under a written data processing agreement. If you use a Scicon product through your employer or an IT provider and want to exercise your rights, contact them; we will support them in responding.
Content we cannot read
Two of our products are built so that we are not able to access what passes through them. In PushItPro, content is encrypted before it reaches us and we hold only ciphertext we cannot decrypt. In Volarian, documents are shared encrypted and view-only. Where that is the case we cannot produce the content in response to any request — yours, a controller's, or a lawful authority's — because we do not hold it in readable form. We can still act on the account and metadata described in section 4.
2. Scope
This notice covers sciconsystems.com, our sales and marketing activity, our partner relationships, recruitment, and our supplier relationships. It does not cover third-party websites we link to, or the privacy practices of our partners.
3. Changes to this notice
We review this notice at least annually and whenever our processing changes materially. The version number and effective date at the top of this page tell you which version you are reading. Where a change materially affects you, we will tell you directly if we hold your contact details.
4. Personal data we collect
Website visitors. IP address (truncated where our analytics configuration allows), device and browser type, pages viewed, referring source, and the date and time of your visit. See section 10 on cookies.
Enquiries and partner prospects. Name, business email address, telephone number, employer, job title, and the content of your enquiry or our correspondence. Where we identify a prospective partner from public sources, this may also include publicly listed business contact details and information about the organisation's market and size.
Partner and customer contacts. Contact and role details, records of meetings, support tickets, training and certification records, and the commercial correspondence necessary to run the relationship.
Product users. Account name, business email, role and permissions, authentication events, and a record of actions taken in the product — for example that a secret was created, opened or expired, or that a document was viewed. Where the product is zero-knowledge, this metadata is what we hold; the content itself is not readable by us. As set out in section 1, we hold all of this as a processor.
Job applicants. The information in your application, right-to-work evidence, interview notes and references.
Supplier contacts. Name, business contact details and payment details where the supplier is an individual or sole trader.
We do not seek special category data (such as health or biometric data), and we ask that you do not send it to us. We do not knowingly collect data about children; our services are business-to-business.
5. Where we get it
Directly from you, when you contact us, apply for a partnership, attend an event, subscribe to updates, or use a system we support. From our partners, where they introduce you as a contact for a deployment. From publicly available sources such as company websites, Companies House and professional networking sites, when we research prospective partners. Automatically, from your device when you visit our website.
6. Why we use it, and our lawful basis
| Purpose | Data used | Lawful basis |
|---|---|---|
| Responding to enquiries and providing quotations | Enquiry and contact data | Legitimate interests — responding to a request made of us; or steps prior to entering a contract |
| Business-to-business marketing to relevant organisations | Business contact data | Legitimate interests, balanced against your rights, with an objection route in every message. Consent where required by PECR |
| Managing the partner relationship, licensing and support | Partner contact and account data | Performance of a contract |
| Providing and securing the products, including logging and monitoring | Product account and activity data | Processed on behalf of the controlling organisation under a data processing agreement |
| Understanding how the website is used and improving it | Website analytics data | Consent, where non-essential cookies or similar technologies are used |
| Recruitment | Application data | Steps prior to entering a contract; legal obligation for right-to-work checks |
| Accounting, tax and statutory record-keeping | Transaction and contact data | Legal obligation |
| Establishing, exercising or defending legal claims | As relevant | Legitimate interests |
Where we rely on legitimate interests, we have carried out a balancing assessment and you can ask us for a summary of it. Where we rely on consent, you can withdraw it at any time without affecting processing carried out before withdrawal.
7. Who we share it with
We share personal data with service providers who act on our instructions — hosting and infrastructure, email and CRM, accounting, and professional advisers — each under a written contract that limits what they may do with it. We share partner contact details with a partner's own account team where that is necessary to run the relationship. We disclose data to regulators, law enforcement or courts where we are legally required to. If Scicon is involved in a merger, acquisition or sale of assets, data may transfer to the acquiring entity under the same protections.
We do not sell personal data, and we do not share it with advertising networks for their own purposes.
Our sub-processors
| Sub-processor | Purpose | Location of processing |
|---|---|---|
| Cloudflare, Inc. | Edge network, application hosting and R2 object storage | [Confirm — jurisdictional restriction available] |
| Clerk, Inc. | Identity, authentication and session management | [Confirm] |
| Neon, Inc. | Managed PostgreSQL database | [Confirm region] |
| [Email provider] | Transactional and marketing email | [Confirm] |
| [CRM provider] | Sales and partner relationship records | [Confirm] |
| [Accountant] | Bookkeeping and statutory accounts | United Kingdom |
We give [30] days' notice before adding a sub-processor, and a controller may object. This list is maintained because partners and procurement teams ask for it, and having it ready shortens their review.
8. International transfers
Our products and business data are hosted [state the region — confirm what your Cloudflare, Clerk and Neon configurations actually do, since each supports different regional options]. Where a supplier processes data outside the UK, we rely on UK adequacy regulations, or on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment. You can ask us which mechanism applies to a particular transfer.
9. How long we keep it
| Record | Retention |
|---|---|
| Website analytics | [14] months |
| Unconverted enquiries and prospect records | [24] months from last contact |
| Marketing subscription records | Until you unsubscribe, plus [24] months of suppression data |
| Partner and customer contract records | Contract term plus [6] years |
| Product account and audit logs | As instructed by the controlling organisation |
| Unsuccessful job applications | [6] months, or longer with consent |
| Accounting and tax records | 6 years from the end of the financial year |
At the end of a retention period we delete the data or irreversibly anonymise it. Suppression lists are the deliberate exception: we keep the minimum needed to make sure we do not contact you again.
10. Cookies and similar technologies
We use strictly necessary cookies to make the site work; these do not require consent. Any analytics, preference or marketing cookies are set only after you consent, and you can change or withdraw that choice at any time through the cookie settings link in the footer.
11. Marketing
We market to business contacts at organisations we believe have a relevant interest. Every message identifies Scicon Systems, explains where we found your details, and carries a one-click unsubscribe. You can opt out at any time by using that link or by emailing privacy@sciconsystems.com, and we will action it promptly and permanently.
12. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you by automated means, and we do not carry out profiling of that kind.
13. Security
We apply technical and organisational measures appropriate to the risk. Where the architecture allows it we go further and design ourselves out of access altogether, as described in section 1. Across the portfolio this includes encryption in transit and at rest, role-based access control, multi-factor authentication on administrative accounts, least-privilege access, logging and monitoring, supplier due diligence, staff training, and a documented incident response process. Where we are a processor and become aware of a personal data breach, we notify the relevant controller without undue delay so that they can meet their own obligations.
14. Your rights
Under the UK GDPR you have the right to be informed; to access a copy of your personal data; to have inaccurate data corrected; to have data erased in certain circumstances; to restrict processing; to data portability; to object to processing based on legitimate interests; and to object to direct marketing at any time, without exception.
To exercise any of these, email privacy@sciconsystems.com. We will respond within one month and will tell you promptly if we need to extend that for a complex request. We may ask for information to confirm your identity. There is no charge unless a request is manifestly unfounded or excessive.
If you use a Scicon product provided by your employer or an IT provider, please direct your request to that organisation, since they are the controller. Tell us if you are unsure who that is and we will point you to them.
15. Complaints
Please raise any concern with us first — we would rather fix it. You also have the right to complain to the Information Commissioner's Office at any time: ico.org.uk/make-a-complaint, helpline 0303 123 1113, or Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.