Skip to content
BlueIxia

Legal centre

Privacy notice

This notice explains how BlueIxia handles personal data in connection with this website, its commercial services and the BlueIxia Intelligence client environment.

Who we are

BLUEIXIA LIMITED, company number 17298071, registered in england and wales, is responsible for the personal data processed in connection with this website and with services provided by the United Kingdom business.

BLUEIXIA SH.P.K, incorporated in the Republic of Kosovo, is responsible for the personal data processed in connection with services provided by the Kosovo business.

Each company determines the purposes and means of the processing it carries out for its own services, and each is a controller in respect of that processing. Where a specific activity is carried out jointly, or where one company processes personal data on behalf of the other, the arrangement applicable to that activity is described on request.

How to contact us

Privacy enquiries, data-subject requests and objections may be submitted through the contact page on this website, marking the message as a privacy request, or in writing to the relevant company.

We do not require the use of a web form. A written request through any reasonable channel is accepted.

What personal data we collect

The categories of personal data we process depend on your relationship with us:

  • Identity and contact data: name, business email address, telephone number, organisation, role and country.
  • Enquiry data: the content of contact, partnership and merchant enquiries and subsequent correspondence.
  • Merchant and diagnostic data: business and transaction information entered into the payment diagnostic, and information contained in merchant statements supplied for review.
  • Account data: credentials, authentication events, permissions and organisation membership for BlueIxia Intelligence.
  • Q conversation data: prompts, requests and outputs generated within the client environment.
  • Art and transaction data: artwork, transaction and counterparty information entered by a client.
  • Recruitment data: contact details, location, professional background, languages, motivation and any CV supplied.
  • Professional contact and event data: business contact information relating to professional relationships and events.
  • Marketing data: preferences, subscription status and engagement records.
  • Technical and log data: IP address, device and browser information, pages viewed, and security and audit records.
  • Cookie data: as described in the Cookie Policy.

Merchant statements and business records may contain personal data relating to individuals other than the person submitting them. Only information relevant to the analysis requested should be supplied.

Sources of personal data

We obtain personal data from the following sources:

  • directly from you, when you contact us, submit an enquiry, use a public tool, apply for a role or use BlueIxia Intelligence
  • from your organisation, where a colleague provides your business contact details
  • from payment providers, banks and technology providers in connection with an introduction or an account
  • from publicly available business sources and professional networks
  • automatically, through cookies, server logs and security monitoring

Why we use personal data and our lawful basis

We rely on a specific lawful basis for each purpose. We do not treat legitimate interests as a universal basis.

PurposeData categoriesLawful basisLegitimate interest, where relied uponRetention logic
Operating and securing the websiteTechnical and log data, strictly necessary cookiesLegitimate interestsOperating a secure, functioning website and preventing misuseRetained for the period necessary for security and integrity monitoring
Responding to enquiriesIdentity, contact and enquiry dataLegitimate interests; steps at your request prior to a contractResponding to business enquiries directed to usRetained for the period needed to handle the enquiry and any resulting relationship
Providing the payment diagnosticMerchant and diagnostic data, contact dataLegitimate interests; steps at your request prior to a contractProviding a requested commercial analysis to a business userRetained for the period needed to deliver and evidence the analysis
Providing BlueIxia Intelligence and QAccount data, merchant data, Q conversation data, art and transaction dataPerformance of a contract; legitimate interests of the client organisationAdministering client access on behalf of the contracting organisationRetained for the duration of the client relationship and any applicable record-keeping period
Reviewing uploaded merchant statementsMerchant statements and the personal data within themPerformance of a contract; legitimate interestsDelivering the analysis the business has requestedRetained for the period needed to deliver the analysis and evidence the advice given
Introducing a merchant to a providerIdentity, contact, merchant and business dataPerformance of a contract; legitimate interestsArranging the introduction the business has asked forRetained for the period needed to evidence the introduction and any remuneration due
Managing partnership and referral relationshipsIdentity, contact and enquiry dataLegitimate interests; steps prior to a contractEstablishing and managing commercial relationshipsRetained for the duration of the relationship and a reasonable period afterwards
Assessing applications for roles and agent opportunitiesRecruitment data, including CVsLegitimate interests; steps at your request prior to a contractAssessing suitability for an opportunityRetained for the applicable recruitment period, then deleted or anonymised
Direct marketing to business contactsIdentity, contact and marketing dataLegitimate interests, or consent where required by electronic-marketing rulesPromoting relevant services to business contactsRetained until objection or withdrawal, subject to a suppression record
Non-essential cookies and analyticsCookie and technical dataConsentNot applicableRetained for the cookie lifetime disclosed in the Cookie Policy
Meeting legal and regulatory obligationsAny relevant categoryLegal obligationNot applicableRetained for the period required by the applicable obligation
Establishing, exercising or defending legal claimsAny relevant categoryLegitimate interests; legal obligation where applicableProtecting our legal positionRetained for the applicable limitation period
Corporate transactionsIdentity, contact and relationship dataLegitimate interestsEvaluating or completing a reorganisation, sale or mergerRetained for the period necessary for the transaction and any resulting obligations

Where we rely on consent, you may withdraw it at any time, and withdrawal does not affect processing carried out before withdrawal. Where we rely on contract, we do so only where the processing is genuinely necessary for a contract with you or to take steps at your request before entering into one.

Special-category and criminal-offence data

We do not seek special-category personal data, and our services are not designed to process it. Applicants and clients should not include such information unless we have specifically requested it, for example to make an adjustment during a recruitment process.

We do not routinely process criminal-offence data. Where processing of such data becomes necessary, it is carried out only where a lawful basis and an applicable condition are satisfied.

Children

This website and our services are directed at businesses and professional users. They are not directed at children, and we do not knowingly collect personal data relating to children.

Sharing personal data

We may share personal data with:

  • payment providers, banks and acquirers, where you have asked to be introduced or where an account is being arranged
  • technology, hosting, storage, communications and security providers engaged to operate our services
  • professional advisers, including legal, accounting and insurance advisers
  • competent authorities and regulators, where required by law or where we are legally permitted to do so
  • a purchaser, investor or successor in connection with a corporate transaction, subject to appropriate confidentiality protections

Service providers act on documented instructions under written terms that impose confidentiality and security obligations. We do not sell personal data.

We do not publish uploaded merchant documents, and we do not disclose them other than as described in this notice.

International data transfers

BlueIxia operates across the United Kingdom and the Republic of Kosovo. Personal data provided to the United Kingdom business may be accessible to the Kosovo business, and personal data provided to the Kosovo business may be accessible to the United Kingdom business, where that is necessary for the service concerned.

Service providers engaged to host, store, secure and operate our systems may process personal data outside the United Kingdom or outside Kosovo.

Where personal data is transferred to a jurisdiction that does not benefit from a relevant adequacy decision, we put in place a transfer mechanism recognised under the applicable law, such as approved standard contractual clauses together with a transfer risk assessment where required.

You may request information about the safeguards applicable to a particular transfer by contacting us as described above.

Retention

We retain personal data only for as long as necessary for the purpose for which it was collected, and for any period required to meet legal, regulatory, accounting, evidential or limitation requirements. Retention is set by data category, and the retention logic for each purpose is shown in the table above.

Categories with their own retention treatment include general enquiries, prospective merchant records, active client records, payment diagnostics, merchant statements, BlueIxia Intelligence accounts, Q conversations, partnership enquiries, recruitment records and CVs, marketing contacts, security logs, cookie consent records, complaints and records relating to legal claims.

Where personal data is no longer required, it is deleted or anonymised. Recruitment records are deleted or anonymised at the end of the applicable recruitment period, and an applicant may ask for their information to be removed at any time.

Security

We apply technical and organisational measures appropriate to the risk, including access control, least-privilege permissions, restricted document storage, encrypted transport, monitoring, audit logging and incident-management procedures. These are described further in the Security Statement.

No internet-connected system can be guaranteed to be absolutely secure, and we do not represent that ours is.

Automated processing and profiling

Our tools produce calculations, estimates and analysis using automated processing. Those outputs support human commercial judgement, and merchant underwriting and provider approval decisions are made by the relevant provider rather than by BlueIxia.

We do not make decisions producing legal effects concerning an individual, or similarly significantly affecting an individual, based solely on automated processing.

Your rights

Subject to the conditions and exemptions in the applicable law, individuals may have the right to:

  • request access to their personal data
  • request rectification of inaccurate or incomplete data
  • request erasure in certain circumstances
  • request restriction of processing in certain circumstances
  • object to processing carried out on the basis of legitimate interests
  • object at any time to direct marketing
  • request portability of data provided to us, where processing is based on consent or contract and carried out by automated means
  • withdraw consent, where processing is based on consent
  • rights in relation to certain decisions based solely on automated processing

Not every right applies in every circumstance. We will explain the position where a right does not apply to a particular request.

Requests may be made through the contact page or in writing. We may ask for information to verify identity, and we respond within the period required by applicable law.

Direct marketing

Marketing to corporate business contacts is carried out on the basis of legitimate interests, where permitted. Individuals, sole traders and certain other recipients receive greater protection under applicable electronic-marketing rules, and we obtain consent where consent is required.

Publication of a business email address does not, by itself, constitute consent to receive marketing.

Every marketing message includes an effective opt-out, and objections are recorded and applied across our systems.

Complaints to a supervisory authority

If you are dissatisfied with how we have handled your personal data, please raise it with us first so that we can address it.

For processing carried out by the United Kingdom business, you may complain to the Information Commissioner's Office.

For processing carried out by the Kosovo business, you may complain to the Information and Privacy Agency of the Republic of Kosovo.

These authorities supervise data protection. Complaints about a regulated payment service are handled separately, as described in the Complaints Procedure.

Changes to this notice

We update this notice as our processing changes. The revision date at the top of this page records the current version, and material changes are notified where required.

BLUEIXIA LIMITED. Company No. 17298071. Registered in England and Wales.

These documents are published by BlueIxia. They are not stated to have been prepared, reviewed or approved by any external adviser or regulator.

Return to the legal centre