Privacy Notice

This privacy notice will help you understand how Optellum uses and protects your personal data.

We are Optellum Ltd, registered in England and Wales at 5 Kings Meadow, Osney Mead, Ferry Hinksey Road, Oxford, Oxfordshire, England, OX2 0DP with company number 09846477.

You can contact our voluntarily appointed Data Protection Officer at if you have any concerns or wish to exercise your rights at simon.ghent@optellum.com.

Our Promises

We’re committed to your data privacy and security. As such we give you these promises:

  • We will only collect data about you that is relevant and necessary;
  • Your data will only be held on systems that meet compliance standards;
  • Your data will only be accessed by those who need it and we will minimise the amount of data that is processed, wherever possible;
  • We won’t share or sell your data to any third party, except for the marketing of our own services to you, unless either you have agreed, we are required to share it by law or we need to fulfill our service commitments to you through a third party that meets our own privacy standards;
  • We will always remember that it is your personal data, not ours. As such we will ensure complete transparency and openness with you wherever possible.
  • We respect your rights as outlined in the next section and will respond to all requests promptly.

Your Rights

You have the following rights over any data we hold about you:

  • Your right of access – You have the right to ask us for copies of your personal information.
  • Your right to rectification – You have the right to ask us to rectify personal information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete.
  • Your right to erasure – You have the right to ask us to erase your personal information in certaincircumstances.
  • Your right to restriction of processing – You have the right to ask us to restrict the processing of yourpersonal information in certain circumstances.
  • Your right to object to processing – You have the the right to object to the processing of your personalinformation in certain circumstances.
  • Your right to data portability – You have the right to ask that we transfer the personal information you gave us to another organisation, or to you, in certain circumstances.

You can read more about your rights here.

If you would like to uphold your rights then please contact our Data Protection Officer at simon.ghent@optellum.com.

If you are in dissatisfied with our response you also have the right to lodge a complaint with the Data Protection Authority. This can be done at https://ico.org.uk/concerns/

How we Collect your Data

We collect information about you in two key ways:

  • Passive – you give us information on our website, email us, call us, post a comment on our blog, send us a CV, meet one of us at events or meetings or approach us on social media
  • Proactive – this is data about you that we may hold from referrals, resellers or proactive marketing activity.

What Data we Collect

We try and minimise the data held and the exact data elements we hold will be dependent on your journey with us. Typically, data elements we collect include:

  • Name
  • Telephone Number
  • Email Address
  • Company Details
  • Business Social Media Page

We may record and transcribe calls, specifically on Teams. This captures your image if shown and what you say. We use this information to help us summarise actions, gain insights and for quality and training purposes.

Legal Basis for Processing

The lawful basis we use for most B2B processing is “Legitimate Interest”. The ICO recommend that companies using this basis conduct a “Legitimate Interests Assessment” (LIA) and this has been completed and is reviewed annually. For B2C marketing we rely on consent mechanisms. In some cases we may process your data as part of contractual obligation.

How we Process your Data

Data is processed/stored mainly on encrypted cloud services such Microsoft 365, Azure, and other SaaS platforms including for marketing.

We may make use of Large Language Models (LLM’s) commonly referred to as AI to help us gain insights. Your data will not be processed for the purposes of machine learning, and the data will be encrypted in transit and at rest. A full list of these systems can be provided on request. These services all have strong data security at the heart of their systems including ISO27001 and SOC2 certification.

We ensure that access to these services is strictly controlled and include strong authentication processes like Multi Factor Authentication.

Data will be processed in either the UK, EEA/EU data centres or on US based servers that have demonstrated strong Data Security. We may also process your data in countries outside the UK or European Union from time to time in other aspects of our business.

Further to Section 119A of the Data Protection Act 2018 and noting Case C-311/18 in the European Court of Justice, if your data is transferred or processed outside of the UK or EEA we ensure the safeguards of International Data Transfer Agreements (IDTAs) or Addendums are enforced. Where this is not possible, we ensure that European Standard Contractual Clauses are entered. For data transfer between the USA, we may rely on the Data Privacy Framework or the UK Extension Data Bridge.

We regularly review suppliers for data security compliance to ensure your data is safe and track where your data is held.

All our processes are subject to various internal policies to ensure that your data privacy and security is upheld. You can receive a list of all processors on request.

Who we share your data with

Your data will be shared internally, including with members of external teams (including external payroll), your line manager, managers in the business area in which you work and IT staff if access to the data is necessary for performance of their roles.

The Company shares your data with third parties to obtain pre-employment references from other employers, obtain employment background checks from third-party providers and obtain necessary criminal records checks from the Disclosure and Barring Service.

We may also share your data with third parties in the context of funding or a sale of some or all its business. In those circumstances the data will be subject to confidentiality arrangements.

The Company also shares your data with third parties that process data on its behalf, in connection with payroll, data protection, the provision of benefits and the provision of HR services.

What we use your Data for

We process your data for several reasons:

  • To better understand your needs.
  • To deliver our services and products.
  • To send invitations to events and follow these up if you have signed up to them.
  • To send you promotional emails containing the information we think you will find interesting.
  • To contact you to fill out surveys and participate in other types of market research.
  • To customize our website according to your online behaviour and personal preferences.

We ensure we have a “legal basis” to use your data for the purpose we have collected it for.

Third Parties

We use re-marketing services from third parties. These may rely on the use of cookies. You can read more about these in our Cookies Policy.

We also share information where agents, resellers or suppliers are involved in the delivery of your service.

Our website and other materials sent to you may contain links to other third-party websites. We may also offer buttons to social media that link to third party services. We’re not responsible for the content or your data privacy these sites provide through their tools or sites.

Data Retention

Dependant on the data you provide us and for what purpose it is provided we may need to retain your data based on your journey with us. Typically, we will retain your data for up to 6 years from the point we no longer engage with you.

If you wish to fi nd out more about your specifi c data retention, please contact us.

Data Permissions

Every marketing email sent from Us allows you to opt out of receiving emails from us, except for the purposes of fulfilling any contractual arrangements.

You can also contact us at the email address above and request to opt out, view, export or delete your data.

If you request for your data to be deleted, your name and email address will be added to an exceptions list and allother data removed to the extent possible.

Data Protection Complaints

We always try to meet the highest standards of Data Privacy when collecting and using personal information. For this reason, we take any complaints we receive very seriously. We encourage people to bring it to our attention if they think that our collection or use of information is unfair, misleading or inappropriate.

You have the right to complain about how we use your personal data. If you are unhappy or have concerns, please contact us first using the details in the “Our Contact Details” section above, so we can try to resolve the issue.

You also have the right to make a complaint to the UK Information Commission (IC). However, the law now requires you to raise your complaint with us before complaining to the IC. If you do complain to us, we will acknowledge your complaint within 30 days, investigate it fairly and promptly, and write to you with our response.

You have the right to complain to the UK IC at any time, using the contact information below:

Please ensure that you state ‘Data Protection Complaint’ in the subject field.

The Information Commission’s address:

Information Commission
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline number: 0303 123 1113
ICO website: https://www.ico.org.uk

Under the UK Data (Use and Access) Act 2025, the IC typically requires you to have completed our internalcomplaints process, before they will investigate.

Legal compliance

We seek to uphold our legal obligations as covered by the Data Protection Act 2018, Data Use and Access Act 2025 and the General Data Protection Regulation 2016. Our Data Protection Authority is designated as the Information Commission (IC) formally the Information Commissioners Office (ICO). This Privacy Policy is reviewed on a regular basis and was last reviewed in May 2026.

We retain the right to update this notice at any time. We will always document any changes and will publish the latest version on the company’s website.

Where Data is processed in any other jurisdictions, and you believe we may be infringing on legal or regulatory obligation please contact us at the above address immediately.