Corporate Data Protection Policy

Agilysis is fully committed to transparency in how it handles personal data and the purposes for which it processes personal data. The company takes all the essential measures to ensure that information it holds remains private and secure and is processed fairly and lawfully.

The lawful basis upon which Agilysis handles personal data will vary depending on the specific purpose. Our main activities will be based on the research provisions within the Data Protection Act 2018 (DPA) and the UK GDPR. Other activities will be based on either consent or Legitimate Interest as defined under the Data Protection Act 2018 (DPA). The company has completed a Legitimate Interest Assessment to support this basis.

The type of information Agilysis processes will fall into one of the following categories:

Customer / client / staff contact and associated information

Personal information held by Agilysis will most commonly relate to our customers, clients or staff. In these cases, we will be the data controller.

For our customers / clients we only hold data with minimal privacy impact which is used in the manner our clients and other contacts would reasonably expect. We respect all individual rights with respect to their personal data and offer the right to opt out to everyone whose data we hold.

Agilysis only holds personal information supplied to it directly by the person concerned or, in the case of organisations with which Agilysis has an existing commercial relationship, by professional colleagues of the person concerned.

Agilysis’ general purpose in storing personal information is to facilitate professional contact with persons and organisations who use Agilysis products or otherwise engage in a commercial relationship with the company. We only collect and store information that is necessary and relevant to this purpose. We make every reasonable effort to ensure that it is accurate, correcting or deleting data if necessary.

Project data (scientific research)

During our project work, in some cases, we may collect personal data ourselves or be provided with personal data by a client for us to process. This will usually be for the purposes of scientific research. In these cases, Agilysis may be the controller, a joint controller or a processor of the data, dependent on the specific project and nature of the tasks.

Processes for the appropriate handling of this personal data are assessed on a case-by-case basis prior to any personal data being collected by and/or provided to Agilysis. Where it is practical within the data collection process, consent from data subjects will be sought and information provided regarding how they can opt out or ask for their information to be withdrawn. As we seek to anonymise data as soon as possible within our research processes, it may be that their anonymised data will remain in use as we will no longer be able to identify a specific data subject in the anonymised dataset.

Where personal data is collected or provided to us as part of a project, access to it is restricted to key staff identified by the Executive Team as having an objective requirement. The assessment at the outset of the project will identify the necessary retention period for the data collected and processes for secure disposal once it is no longer needed.

Product data (statistical)

The development of Agilysis’ products, in some cases, includes the use of personal data or combinations of data that could be used to identify an individual. In these cases, Agilysis will most likely be the controller or joint controller for the data.

Agilysis anonymises this data at the earliest opportunity in the development process so that individuals are not identifiable in the statistics provided in the products.

Personal data held by Agilysis for this purpose will be stored and disposed of securely in accordance with our data sharing agreement(s) with the source provider(s).

Other principles

If Agilysis ever needs to collect personal information for any other specific purpose, we will undertake an assessment of the basis and processes prior to any data collection or receipt of personal data from a third-party. If necessary, a Legitimate Interest Assessment will be undertaken.

Agilysis do not store any information about persons under the age of 16 unless specifically required for legitimate purposes. Once information is no longer required (e.g., after an event has finished), data is securely disposed of.

Agilysis do not supply personal data to any third parties.

These principles are enshrined in a series of related procedures which document the flow of personal data and who is responsible for implementing each step.

Personnel

Agilysis has no requirement for a Data Protection Officer, as the company does not hold or process substantial volumes of personal data, conduct extensive direct marketing activities or process special categories of personal data on a large scale.

An Agilysis Director is designated as the company’s Data Process Auditor. The Data Process Auditor is in overall charge of implementing this policy and related procedures and administers the Data Protection Archive.

Systems

Agilysis uses the following systems which may be used for processing personal data:

  • HubSpot holds contact information for people who are or have been users of Agilysis online services and/or are legitimate business contacts of Agilysis. Where paper records are also held and referenced in HubSpot, including User Licences for Agilysis products, these are held securely on the company’s server which is password protected.
  • Sage holds contact information for people who have conducted financial transactions with Agilysis, including paper records referenced in Sage, such as invoices and purchase orders.
  • Personnel data includes personal information about persons under contract to Agilysis only, stored electronically in TimeTac and a MS SharePoint folder; access to both these is restricted to directors, managers, and key staff identified by the Executive Team as having an objective requirement.
  • Project folders on MS SharePoint may contain contractual or project documents which refer to individuals, where personal data is collected as part of the project access to these folders is restricted to key staff identified by the Executive Team as having an objective requirement.
  • Data provided online to apps accessed via smartphones and websites which may include personal information about persons who purchase, subscribe to, or use apps published by Agilysis which are maintained on secure servers, protected by industry standard security protocols in accordance with UK GDPR / DPA requirements and the Security section of the company’s IT Management Policy.
  • Secure PostgeSQL instances are used for processing product and project data. Data ingested into these databases is anonymised before use.

Training

Data Protection training will be provided for all staff involved in handling personal data for:

  • Users of online assets
  • Suppliers of services to Agilysis
  • Agilysis employees
  • Clients with whom Agilysis has a contractual relationship, and/or
  • Marketing to existing or potential clients.

This training will be included during induction for new starters and will also incorporate the Privacy Notice issued to all clients. The Data Process Auditor is responsible for ensuring training is delivered.

Annual Audit

The Data Process Auditor will conduct an annual audit of Agilysis’ Data Protection structures. This audit will:

  • Review the contents of Agilysis’ data systems and the Data Protection Archive and destroy any information held therein which is no longer required for legal, compliance, statistical or research purposes.
  • Consider information about projects or clients which have been dormant throughout the previous year and destroy or archive any personal information held which is no longer required for legal, contractual, compliance, accounting, statistical or research purposes.
  • Consider financial records in or related to Sage which are no longer required for legal, contractual, compliance, or accounting purposes, and, where possible destroy or archive any personal information held which is no longer required for legal, contractual, compliance or accounting purposes.
  • Check personnel data for information held on past employees and destroy or archive any personal information held which is no longer required for legal, contractual, compliance or accounting purposesGDPR compliance regulations do not set out any minimum or maximum time limits for keeping staff data. However statutory regulations suggest that personal data, performance appraisals and employment contracts should be kept for six years after termination of an employee’s contract. Agilysis’ policy is to keep relevant and required data on former colleagues for up to seven years, as outlined in the employee handbook.
  • Review the contents of this policy and related procedures, including any changes to the purposes for which Agilysis collects or stores personal data and whether they are compatible with the original purpose, and make recommendations to the Board on any revisions which may be necessary.

Policy updated: 09/07/2025