1. The organisation behind this site
MyInfoCentre is a trading name of Prophoenix Solutions Tech, a company registered in England and Wales under number 17064165. Our registered office sits at 27 Old Gloucester Street, London, England, WC1N 3AX. For everything described below, Prophoenix Solutions Tech acts as the data controller, meaning we decide why your information is processed and how.
We are entered on the register kept by the Information Commissioner’s Office under reference ZA786198. Data protection questions should go to hello@myinfocentre.co.uk, or by post to the registered office above, marked for the attention of the data protection contact.
2. Where your information comes from
2.1 Details you type into our forms
Our enquiry and opt-in forms ask for a name, an email address, a telephone number, the organisation you work for, the web address of the site you want reviewed, an indication of current monthly spend, the area of work you want help with and a free-text note about the problem. Whatever you choose to write in that note reaches us as well.
2.2 Details your browser sends
Every request to myinfocentre.co.uk is logged by our hosting layer. Those logs record an IP address, the requested URL, a timestamp, the browser and operating system string, and the page that referred you. Logs exist so we can spot outages, block abuse and keep the site online.
2.3 Measurement data, only with permission
If you agree to non-essential cookies we receive aggregated statistics about which pages get read, how long visits last, and which channel brought you here. Nothing in that set identifies you by name. Refuse, and no measurement tags load at all.
2.4 Records created while we work together
Clients also give us business contact details, platform access, briefing material and the commercial paperwork attached to an engagement.
None of our forms ask for special category information such as health, beliefs, ethnicity or criminal history. Please leave that sort of detail out of any message you send us.
3. Legal grounds for each use
UK GDPR requires a named ground for every processing activity. Ours are set out below.
| What we do with it | Ground relied on |
|---|---|
| Reply to an enquiry, scope the work and put a proposal together | Pre-contractual steps you asked for, plus our legitimate interest in winning work |
| Run campaigns, sites and reporting for a client under a signed brief | Necessary to perform the contract |
| Keep the site available and screen out bots and form abuse | Legitimate interest in a secure, working service |
| Load analytics and any advertising measurement tags | Your consent, which you may take back whenever you like |
| Send occasional marketing about what we do | Your consent, or the soft opt-in permitted for existing customers |
| Keep books, invoices and records regulators may ask to see | Compliance with a legal obligation |
| Handle a dispute or take advice on one | Legitimate interest in defending our position |
4. What happens after you press send
Form data travels over an encrypted connection to a small serverless endpoint. That endpoint emails the submission to our own inbox and sends you a copy for your records. Two anti-abuse measures run at that point: a hidden field that only automated scripts fill in, and a limit on how many submissions one address may make in a short window. The address used for that limit is held only briefly and never feeds any profile of you.
5. Other organisations involved
Your information is never sold, rented or swapped. A short list of suppliers process it on our instructions, each under a written data processing agreement and each restricted to what their job requires:
- a hosting and content delivery provider, which serves the site and filters malicious traffic;
- an email delivery provider, which puts notifications and confirmations in the right inbox;
- a website analytics provider, engaged only once you have consented to measurement cookies;
- a customer relationship and productivity platform, where enquiries and client files live;
- advertising platforms, where a campaign we run for you needs conversion measurement;
- our accountants, insurers and legal advisers, in the narrow circumstances where they need to know.
We will also release information where a court order, statutory duty or regulatory request obliges us to.
6. Sending data outside the UK
A number of the suppliers above operate infrastructure abroad, so some information leaves the United Kingdom. When it does we rely either on UK adequacy regulations covering that country, or on the International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses) supported by a transfer risk assessment and, where sensible, added technical measures such as encryption.
7. Retention
Nothing is kept indefinitely. Once the period below runs out the record is deleted or anonymised.
| Record | Kept for |
|---|---|
| Enquiries that never became an engagement | Two years from the last exchange between us |
| Client files, contracts and invoices | Six years after the engagement ends, as tax and contract rules require |
| Marketing permissions and unsubscribe entries | While the permission stands; a minimal suppression entry is kept afterwards so we do not contact you again by mistake |
| Web server and security logs | Up to twelve months |
| Cookie consent choices | Twelve months, then you are asked again |
8. What you are entitled to ask for
The law gives you the following rights over information we hold about you:
- a copy of it, together with an explanation of how it is being used;
- correction of anything recorded wrongly or incompletely;
- deletion, where we have no continuing reason to keep it;
- a pause on processing while an accuracy or objection point is looked into;
- an objection to any use we justify by legitimate interests, marketing included;
- a machine-readable export of information you supplied under consent or a contract;
- withdrawal of consent, effective from the moment you tell us, without affecting what was lawful beforehand.
Email hello@myinfocentre.co.uk to use any of these. We reply inside one calendar month and there is no charge. If a request is unusually broad we may take up to two further months, and we will explain why before doing so. Occasionally we need to confirm who you are before releasing anything.
9. Raising a complaint
Tell us first if you think we have mishandled your information, since most problems are quicker to fix directly. You are also free to go straight to the regulator. The Information Commissioner’s Office takes complaints at ico.org.uk and on 0303 123 1113. Contacting the ICO costs nothing and does not remove any other legal route open to you.
10. Keeping information safe
Traffic to and from this site is encrypted. Internal accounts are granted the narrowest access that lets someone do their job, administrative logins require a second factor, and we review supplier access on a regular cycle. No system connected to the internet is beyond risk, so we make no absolute promise of security, but we do notify the ICO and affected people where a breach meets the reporting threshold.
11. Age
We market to organisations, not to consumers, and we have no reason to collect information about children. If a person under 18 has sent us something, write to us and it will be removed.
12. Cookies
Cookies, tags and local storage are dealt with separately in our Cookie Policy, which lists each category, its purpose and how to change your answer.
13. Revisions
This policy is reviewed once a year as a minimum, and sooner if our suppliers or the law change. Any new version is published on this page with a fresh date at the top. Where a change materially affects you and we hold your contact details, we will tell you rather than rely on you noticing.