1. Who we are
This website, vidgyst.co.uk, is operated by VIDGYST LTD, a company registered in England and Wales under company number 17298081, with its registered office at 128 City Road, London, United Kingdom, EC1V 2NX ("Vidgyst", "we", "us").
We provide IT services to logistics and supply chain businesses: implementation and support of ERP, TMS and WMS, system integrations, real-time tracking, warehouse automation and analytics.
For personal data we collect about our own contacts and website visitors we act as the controller under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. For personal data held in our clients' systems we act as a processor, as explained in section 3.
Questions about this policy or your data: [email protected], +44 7418 623957, or by post to the address above.
2. Data we collect
We collect only what we need to answer an enquiry and to run a project with you.
When you contact us
This website has no forms. Enquiry buttons open your own email client, so we receive whatever you choose to send, typically:
- your name, email address and phone number;
- your job title, company name and company website;
- details of your operation, sites and systems that you include in the message.
When we work together
- contact and business details of your staff involved in the project;
- contract, billing and payment records for your company;
- meeting notes, support tickets and correspondence;
- user account details we create for you in project or support tools.
Special category data
We do not ask for special category data (for example health, ethnicity, religious beliefs or biometric data) or criminal offence data. Please do not send it to us.
3. Data in client systems
During implementation, integration and support work we are given access to our clients' systems, such as ERP, TMS, WMS, carrier connections and customer portals. These systems contain personal data about third parties, including:
- shipment recipients: name, delivery address and phone number;
- drivers and warehouse staff: names, user IDs and operational records;
- vehicle geolocation data and scan events linked to individual users or devices.
For this data our client is the controller and we act as a processor under a written agreement meeting Article 28 UK GDPR. Under that agreement we:
- process the data only on the client's documented instructions;
- ensure everyone working on the data is bound by confidentiality;
- engage sub-processors only with the client's prior authorisation;
- apply appropriate technical and organisational security measures;
- help the client respond to data subject requests and meet its security and impact assessment obligations;
- notify the client without undue delay after becoming aware of a personal data breach;
- return or delete the data at the end of the work, as the client chooses, unless the law requires us to keep it;
- make available the information needed to demonstrate compliance and allow audits.
Wherever possible we use anonymised or synthetic data for testing rather than live records.
If you are a recipient, driver or employee whose data sits in one of our clients' systems, please contact that company first. If you contact us, we will pass your request to the relevant client.
4. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Replying to your enquiry and preparing a proposal or quote | Legitimate interests in responding to business enquiries; steps prior to a contract |
| Delivering projects, integration work and support | Performance of a contract |
| Processing client system data on the client's instructions | The client's legal basis as controller; our Article 28 agreement |
| Invoicing, accounting and tax records | Legal obligation |
| Keeping our systems and client access secure | Legitimate interests |
| Occasional updates about our services, where you have opted in | Consent |
| Establishing or defending legal claims | Legitimate interests |
Where we rely on legitimate interests, we have balanced them against your rights and you can object at any time (see section 10).
6. International transfers
We aim to keep data in the United Kingdom. Where infrastructure or sub-processors outside the UK are used, we rely on appropriate safeguards: UK adequacy regulations, the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment. For client data, such transfers happen only with the client's approval. You can ask us for details of the safeguards used.
7. How long we keep data
- Enquiries that do not lead to a project: up to 24 months after the last contact.
- Client contract and project records: 6 years after the contract ends, to cover limitation periods.
- Accounting and tax records: 6 years from the end of the financial year, as required by law.
- Client system data processed on instructions: only for the duration of the work, then returned or deleted as the client instructs.
- Marketing preferences: until you withdraw consent.
8. Security
We use access controls with multi-factor authentication, least-privilege accounts for client systems, encryption in transit and at rest, secure credential storage, logging of administrative access and staff confidentiality commitments. Access to client environments is removed when a project or support contract ends. No system is completely secure, but we review these measures regularly and act promptly on any incident.
10. Your rights
Under UK GDPR you have the right to:
- access the personal data we hold about you;
- rectification of inaccurate or incomplete data;
- erasure of your data in certain circumstances;
- restriction of processing in certain circumstances;
- data portability for data you provided, where processing is based on consent or contract;
- object to processing based on legitimate interests, and to direct marketing at any time;
- withdraw consent where processing is based on consent.
To exercise any right, email [email protected]. We will reply within one month and may ask you to confirm your identity. There is normally no fee.
11. Withdrawing consent
Where we rely on your consent, you can withdraw it at any time by emailing [email protected] or using the unsubscribe link in any update we send. Withdrawal does not affect processing carried out before it.
12. Complaints
If you are unhappy with how we handle your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority: ico.org.uk, telephone 0303 123 1113.
13. Children
Our services are for businesses and are not directed at anyone under 18. We do not knowingly collect personal data from children. If you believe a child has sent us data, contact us and we will delete it.
14. Changes to this policy
We may update this policy when our services or the law change. The current version is always on this page, with the date it was last updated shown at the top. Significant changes affecting clients will also be communicated directly.
Last updated: 24 September 2026.