Legal

Privacy Policy

Last updated: 24 September 2026

1. Who we are

This website, vidgyst.co.uk, is operated by VIDGYST LTD, a company registered in England and Wales under company number 17298081, with its registered office at 128 City Road, London, United Kingdom, EC1V 2NX ("Vidgyst", "we", "us").

We provide IT services to logistics and supply chain businesses: implementation and support of ERP, TMS and WMS, system integrations, real-time tracking, warehouse automation and analytics.

For personal data we collect about our own contacts and website visitors we act as the controller under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. For personal data held in our clients' systems we act as a processor, as explained in section 3.

Questions about this policy or your data: [email protected], +44 7418 623957, or by post to the address above.

2. Data we collect

We collect only what we need to answer an enquiry and to run a project with you.

When you contact us

This website has no forms. Enquiry buttons open your own email client, so we receive whatever you choose to send, typically:

  • your name, email address and phone number;
  • your job title, company name and company website;
  • details of your operation, sites and systems that you include in the message.

When we work together

  • contact and business details of your staff involved in the project;
  • contract, billing and payment records for your company;
  • meeting notes, support tickets and correspondence;
  • user account details we create for you in project or support tools.

Special category data

We do not ask for special category data (for example health, ethnicity, religious beliefs or biometric data) or criminal offence data. Please do not send it to us.

3. Data in client systems

During implementation, integration and support work we are given access to our clients' systems, such as ERP, TMS, WMS, carrier connections and customer portals. These systems contain personal data about third parties, including:

  • shipment recipients: name, delivery address and phone number;
  • drivers and warehouse staff: names, user IDs and operational records;
  • vehicle geolocation data and scan events linked to individual users or devices.

For this data our client is the controller and we act as a processor under a written agreement meeting Article 28 UK GDPR. Under that agreement we:

  • process the data only on the client's documented instructions;
  • ensure everyone working on the data is bound by confidentiality;
  • engage sub-processors only with the client's prior authorisation;
  • apply appropriate technical and organisational security measures;
  • help the client respond to data subject requests and meet its security and impact assessment obligations;
  • notify the client without undue delay after becoming aware of a personal data breach;
  • return or delete the data at the end of the work, as the client chooses, unless the law requires us to keep it;
  • make available the information needed to demonstrate compliance and allow audits.

Wherever possible we use anonymised or synthetic data for testing rather than live records.

If you are a recipient, driver or employee whose data sits in one of our clients' systems, please contact that company first. If you contact us, we will pass your request to the relevant client.

4. Purposes and legal bases

PurposeLegal basis
Replying to your enquiry and preparing a proposal or quoteLegitimate interests in responding to business enquiries; steps prior to a contract
Delivering projects, integration work and supportPerformance of a contract
Processing client system data on the client's instructionsThe client's legal basis as controller; our Article 28 agreement
Invoicing, accounting and tax recordsLegal obligation
Keeping our systems and client access secureLegitimate interests
Occasional updates about our services, where you have opted inConsent
Establishing or defending legal claimsLegitimate interests

Where we rely on legitimate interests, we have balanced them against your rights and you can object at any time (see section 10).

5. Sharing with third parties

We do not sell personal data. We share it only where needed, with:

  • hosting, email, file storage and ticketing providers that run our business tools;
  • software vendors and platform providers of the systems we implement, where their involvement is needed for the project and approved by the client;
  • sub-contractors who work on a project under confidentiality terms, with client authorisation where client data is involved;
  • our accountants, legal and insurance advisers;
  • HMRC, regulators, courts or law enforcement where the law requires it.

Each recipient is bound by a contract that limits how they may use the data.

6. International transfers

We aim to keep data in the United Kingdom. Where infrastructure or sub-processors outside the UK are used, we rely on appropriate safeguards: UK adequacy regulations, the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment. For client data, such transfers happen only with the client's approval. You can ask us for details of the safeguards used.

7. How long we keep data

  • Enquiries that do not lead to a project: up to 24 months after the last contact.
  • Client contract and project records: 6 years after the contract ends, to cover limitation periods.
  • Accounting and tax records: 6 years from the end of the financial year, as required by law.
  • Client system data processed on instructions: only for the duration of the work, then returned or deleted as the client instructs.
  • Marketing preferences: until you withdraw consent.

8. Security

We use access controls with multi-factor authentication, least-privilege accounts for client systems, encryption in transit and at rest, secure credential storage, logging of administrative access and staff confidentiality commitments. Access to client environments is removed when a project or support contract ends. No system is completely secure, but we review these measures regularly and act promptly on any incident.

9. Cookies

This website does not set cookies and does not use analytics or advertising trackers. Fonts are loaded from Google Fonts, which means your browser sends your IP address to Google to fetch them; Google does not set cookies for this service. If we add cookies in future, we will update this policy and ask for your consent where required.

10. Your rights

Under UK GDPR you have the right to:

  • access the personal data we hold about you;
  • rectification of inaccurate or incomplete data;
  • erasure of your data in certain circumstances;
  • restriction of processing in certain circumstances;
  • data portability for data you provided, where processing is based on consent or contract;
  • object to processing based on legitimate interests, and to direct marketing at any time;
  • withdraw consent where processing is based on consent.

To exercise any right, email [email protected]. We will reply within one month and may ask you to confirm your identity. There is normally no fee.

12. Complaints

If you are unhappy with how we handle your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority: ico.org.uk, telephone 0303 123 1113.

13. Children

Our services are for businesses and are not directed at anyone under 18. We do not knowingly collect personal data from children. If you believe a child has sent us data, contact us and we will delete it.

14. Changes to this policy

We may update this policy when our services or the law change. The current version is always on this page, with the date it was last updated shown at the top. Significant changes affecting clients will also be communicated directly.

Last updated: 24 September 2026.