Legal centre
Privacy notice
This notice explains how BlueIxia handles personal data in connection with this website, its commercial services and the BlueIxia Intelligence client environment.
Last updated 11 September 2026
Who we are
BLUEIXIA LIMITED, company number 17298071, registered in england and wales, is responsible for the personal data processed in connection with this website and with services provided by the United Kingdom business.
BLUEIXIA SH.P.K, incorporated in the Republic of Kosovo, is responsible for the personal data processed in connection with services provided by the Kosovo business.
Each company determines the purposes and means of the processing it carries out for its own services, and each is a controller in respect of that processing. Where a specific activity is carried out jointly, or where one company processes personal data on behalf of the other, the arrangement applicable to that activity is described on request.
How to contact us
Privacy enquiries, data-subject requests and objections may be submitted through the contact page on this website, marking the message as a privacy request, or in writing to the relevant company.
We do not require the use of a web form. A written request through any reasonable channel is accepted.
What personal data we collect
The categories of personal data we process depend on your relationship with us:
- Identity and contact data: name, business email address, telephone number, organisation, role and country.
- Enquiry data: the content of contact, partnership and merchant enquiries and subsequent correspondence.
- Merchant and diagnostic data: business and transaction information entered into the payment diagnostic, and information contained in merchant statements supplied for review.
- Account data: credentials, authentication events, permissions and organisation membership for BlueIxia Intelligence.
- Q conversation data: prompts, requests and outputs generated within the client environment.
- Art and transaction data: artwork, transaction and counterparty information entered by a client.
- Recruitment data: contact details, location, professional background, languages, motivation and any CV supplied.
- Professional contact and event data: business contact information relating to professional relationships and events.
- Marketing data: preferences, subscription status and engagement records.
- Technical and log data: IP address, device and browser information, pages viewed, and security and audit records.
- Cookie data: as described in the Cookie Policy.
Merchant statements and business records may contain personal data relating to individuals other than the person submitting them. Only information relevant to the analysis requested should be supplied.
Sources of personal data
We obtain personal data from the following sources:
- directly from you, when you contact us, submit an enquiry, use a public tool, apply for a role or use BlueIxia Intelligence
- from your organisation, where a colleague provides your business contact details
- from payment providers, banks and technology providers in connection with an introduction or an account
- from publicly available business sources and professional networks
- automatically, through cookies, server logs and security monitoring
Why we use personal data and our lawful basis
We rely on a specific lawful basis for each purpose. We do not treat legitimate interests as a universal basis.
| Purpose | Data categories | Lawful basis | Legitimate interest, where relied upon | Retention logic |
|---|---|---|---|---|
| Operating and securing the website | Technical and log data, strictly necessary cookies | Legitimate interests | Operating a secure, functioning website and preventing misuse | Retained for the period necessary for security and integrity monitoring |
| Responding to enquiries | Identity, contact and enquiry data | Legitimate interests; steps at your request prior to a contract | Responding to business enquiries directed to us | Retained for the period needed to handle the enquiry and any resulting relationship |
| Providing the payment diagnostic | Merchant and diagnostic data, contact data | Legitimate interests; steps at your request prior to a contract | Providing a requested commercial analysis to a business user | Retained for the period needed to deliver and evidence the analysis |
| Providing BlueIxia Intelligence and Q | Account data, merchant data, Q conversation data, art and transaction data | Performance of a contract; legitimate interests of the client organisation | Administering client access on behalf of the contracting organisation | Retained for the duration of the client relationship and any applicable record-keeping period |
| Reviewing uploaded merchant statements | Merchant statements and the personal data within them | Performance of a contract; legitimate interests | Delivering the analysis the business has requested | Retained for the period needed to deliver the analysis and evidence the advice given |
| Introducing a merchant to a provider | Identity, contact, merchant and business data | Performance of a contract; legitimate interests | Arranging the introduction the business has asked for | Retained for the period needed to evidence the introduction and any remuneration due |
| Managing partnership and referral relationships | Identity, contact and enquiry data | Legitimate interests; steps prior to a contract | Establishing and managing commercial relationships | Retained for the duration of the relationship and a reasonable period afterwards |
| Assessing applications for roles and agent opportunities | Recruitment data, including CVs | Legitimate interests; steps at your request prior to a contract | Assessing suitability for an opportunity | Retained for the applicable recruitment period, then deleted or anonymised |
| Direct marketing to business contacts | Identity, contact and marketing data | Legitimate interests, or consent where required by electronic-marketing rules | Promoting relevant services to business contacts | Retained until objection or withdrawal, subject to a suppression record |
| Non-essential cookies and analytics | Cookie and technical data | Consent | Not applicable | Retained for the cookie lifetime disclosed in the Cookie Policy |
| Meeting legal and regulatory obligations | Any relevant category | Legal obligation | Not applicable | Retained for the period required by the applicable obligation |
| Establishing, exercising or defending legal claims | Any relevant category | Legitimate interests; legal obligation where applicable | Protecting our legal position | Retained for the applicable limitation period |
| Corporate transactions | Identity, contact and relationship data | Legitimate interests | Evaluating or completing a reorganisation, sale or merger | Retained for the period necessary for the transaction and any resulting obligations |
Where we rely on consent, you may withdraw it at any time, and withdrawal does not affect processing carried out before withdrawal. Where we rely on contract, we do so only where the processing is genuinely necessary for a contract with you or to take steps at your request before entering into one.
Special-category and criminal-offence data
We do not seek special-category personal data, and our services are not designed to process it. Applicants and clients should not include such information unless we have specifically requested it, for example to make an adjustment during a recruitment process.
We do not routinely process criminal-offence data. Where processing of such data becomes necessary, it is carried out only where a lawful basis and an applicable condition are satisfied.
Children
This website and our services are directed at businesses and professional users. They are not directed at children, and we do not knowingly collect personal data relating to children.
International data transfers
BlueIxia operates across the United Kingdom and the Republic of Kosovo. Personal data provided to the United Kingdom business may be accessible to the Kosovo business, and personal data provided to the Kosovo business may be accessible to the United Kingdom business, where that is necessary for the service concerned.
Service providers engaged to host, store, secure and operate our systems may process personal data outside the United Kingdom or outside Kosovo.
Where personal data is transferred to a jurisdiction that does not benefit from a relevant adequacy decision, we put in place a transfer mechanism recognised under the applicable law, such as approved standard contractual clauses together with a transfer risk assessment where required.
You may request information about the safeguards applicable to a particular transfer by contacting us as described above.
Retention
We retain personal data only for as long as necessary for the purpose for which it was collected, and for any period required to meet legal, regulatory, accounting, evidential or limitation requirements. Retention is set by data category, and the retention logic for each purpose is shown in the table above.
Categories with their own retention treatment include general enquiries, prospective merchant records, active client records, payment diagnostics, merchant statements, BlueIxia Intelligence accounts, Q conversations, partnership enquiries, recruitment records and CVs, marketing contacts, security logs, cookie consent records, complaints and records relating to legal claims.
Where personal data is no longer required, it is deleted or anonymised. Recruitment records are deleted or anonymised at the end of the applicable recruitment period, and an applicant may ask for their information to be removed at any time.
Security
We apply technical and organisational measures appropriate to the risk, including access control, least-privilege permissions, restricted document storage, encrypted transport, monitoring, audit logging and incident-management procedures. These are described further in the Security Statement.
No internet-connected system can be guaranteed to be absolutely secure, and we do not represent that ours is.
Automated processing and profiling
Our tools produce calculations, estimates and analysis using automated processing. Those outputs support human commercial judgement, and merchant underwriting and provider approval decisions are made by the relevant provider rather than by BlueIxia.
We do not make decisions producing legal effects concerning an individual, or similarly significantly affecting an individual, based solely on automated processing.
Your rights
Subject to the conditions and exemptions in the applicable law, individuals may have the right to:
- request access to their personal data
- request rectification of inaccurate or incomplete data
- request erasure in certain circumstances
- request restriction of processing in certain circumstances
- object to processing carried out on the basis of legitimate interests
- object at any time to direct marketing
- request portability of data provided to us, where processing is based on consent or contract and carried out by automated means
- withdraw consent, where processing is based on consent
- rights in relation to certain decisions based solely on automated processing
Not every right applies in every circumstance. We will explain the position where a right does not apply to a particular request.
Requests may be made through the contact page or in writing. We may ask for information to verify identity, and we respond within the period required by applicable law.
Direct marketing
Marketing to corporate business contacts is carried out on the basis of legitimate interests, where permitted. Individuals, sole traders and certain other recipients receive greater protection under applicable electronic-marketing rules, and we obtain consent where consent is required.
Publication of a business email address does not, by itself, constitute consent to receive marketing.
Every marketing message includes an effective opt-out, and objections are recorded and applied across our systems.
Complaints to a supervisory authority
If you are dissatisfied with how we have handled your personal data, please raise it with us first so that we can address it.
For processing carried out by the United Kingdom business, you may complain to the Information Commissioner's Office.
For processing carried out by the Kosovo business, you may complain to the Information and Privacy Agency of the Republic of Kosovo.
These authorities supervise data protection. Complaints about a regulated payment service are handled separately, as described in the Complaints Procedure.
Changes to this notice
We update this notice as our processing changes. The revision date at the top of this page records the current version, and material changes are notified where required.
BLUEIXIA LIMITED. Company No. 17298071. Registered in England and Wales.
These documents are published by BlueIxia. They are not stated to have been prepared, reviewed or approved by any external adviser or regulator.
