Legal
Privacy notice
1. About this notice
Cubixio Limited (“Cubixio”, “we”, “us”) is a data analytics practice registered in England and Wales, company number 17159605, with its registered office at Collingwood Buildings, 38 Collingwood Street, Newcastle upon Tyne, NE1 1JF. We are registered with the Information Commissioner’s Office under reference ZC220575.
This notice explains what personal data we handle in running our business and delivering our services, why we handle it, and what rights you have.
It covers Cubixio’s own business: this website, enquiries made to us, our client and supplier relationships, and the delivery of our services. It does not cover services, platforms or projects that Cubixio operates separately, each of which publishes its own privacy notice and terms. If you are using one of those, the notice published there governs that processing, not this one.
This notice is written for UK data protection law: the UK GDPR and the Data Protection Act 2018. Where we work in other jurisdictions, local data protection law may apply in addition, and the arrangements for a particular engagement are set out in its contract.
Questions, requests and complaints about data protection should go to [email protected], or by post to Cubixio Limited, Collingwood Buildings, 38 Collingwood Street, Newcastle upon Tyne, NE1 1JF.
2. Our role: controller and processor
Data protection law distinguishes between a controller, who decides why and how personal data is processed, and a processor, who processes it on a controller’s instructions. Cubixio acts in both roles depending on the work, and the distinction determines who you should contact about your data.
| You visit this website | Controller: Cubixio |
| You make an enquiry or ask for a proposal | Controller: Cubixio |
| You are a client, supplier or other business contact | Controller: Cubixio |
| We collect and analyse public content as part of a media analytics engagement | Controller: Cubixio |
| We handle data from a client’s own systems during an engineering or governance engagement | Processor: contact the client |
Where we act as a processor we handle data only on the client’s documented instructions under a written contract, and the client remains responsible for telling you how your data is used. If you contact us about data we hold as a processor, we will pass your request to the relevant client and tell you we have done so.
Occasionally an engagement is structured so that Cubixio and a client jointly determine the purposes and means of processing. Where that applies we put a joint controller arrangement in place under Article 26 of the UK GDPR, and the essence of it is made available to affected individuals on request.
3. Personal data we handle as a controller
3.1 Website visitors
We record IP address, browser and device type, pages visited, referring page, and the date and time of the visit, in standard server logs. We do this to keep the site available and secure and to diagnose faults. Our lawful basis is legitimate interests, being the secure operation of our website. These records are retained for 12 months.
3.2 Enquiries and prospective clients
We collect your name, email address, organisation, role, country focus, and whatever you choose to tell us in your message. We use this to respond to you, to assess whether we can help, and to prepare a proposal if you ask for one. Our lawful basis is legitimate interests, being responding to someone who has contacted us about our services; where a proposal moves towards a contract, we rely on steps taken at your request before entering into a contract.
Providing your details is voluntary. There is no statutory or contractual requirement to give them, and the only consequence of not doing so is that we will not be able to respond to you. Enquiries submitted through the contact form are delivered to our email system; the form does not retain a separate copy on this website. We keep enquiry records for 24 months from our last contact with you and then delete them. If you become a client, your records are governed by the following section.
3.3 Clients, suppliers and business contacts
We hold contact details, role, correspondence, contract and engagement records, invoices and payment details, and records of access to any systems we provide. We use these to deliver our services, manage the relationship, invoice and get paid, and meet our legal and accounting obligations. Our lawful bases are performance of a contract, legitimate interests in managing our business relationships, and legal obligation for accounting and tax records. We retain these records for the duration of the engagement and six years afterwards, to meet UK accounting requirements and the limitation period for contractual claims.
3.4 Personal data within public content, in media analytics work
Where we are engaged to analyse media coverage, we collect content from publicly available sources: broadcast television and radio, online radio streams, online news outlets, and public social media pages and posts. That content sometimes contains personal data. The categories we may hold from these sources are the names, roles and organisational affiliations of people appearing in public coverage; statements, quotations and posts attributed to a person; the outlet, platform or channel on which the content appeared and the date and time of publication; and, where content includes images, video or audio of identifiable people, those recordings as part of the source record.
We process this data to identify and measure themes, coverage patterns, tone and how narratives develop, and to report those findings to the client who commissioned the work. Our lawful basis is legitimate interests, being the provision of media analytics and research services to lawful clients. We have carried out and documented a legitimate interests assessment weighing this against the rights and freedoms of the people concerned; it is available to the ICO on request, and to clients as part of engagement documentation.
This personal data is not collected from you directly. It comes from publicly accessible broadcast, news and social media sources, and we record the source of every item we hold. Data protection law requires us to inform people whose data we obtain indirectly, unless doing so would involve disproportionate effort. Contacting every individual named across an entire monitoring programme would involve disproportionate effort within the meaning of Article 14(5)(b), so we rely on this notice as the public statement of that processing. Where anyone asks us directly, we will tell them what we hold about them.
In this work we do not access private accounts, private messages or closed groups. We do not build profiles of private individuals. We do not conduct covert collection of any kind. We do not attempt to identify people who have chosen to remain anonymous. We do not sell, rent or trade personal data. We do not use this data to make any decision about an individual.
We collect only what the agreed analytical method requires, and we record why each source is in scope. Raw source content is retained for the duration of the engagement and for no more than 12 months after it ends, or a shorter period where the client contract specifies one, after which it is deleted. Aggregated analytical output, which does not generally identify individuals, is retained for the engagement and any archival period agreed in the contract.
3.5 Special category data
Public commentary and news coverage frequently reveal information that data protection law treats as special category data: political opinions, religious or philosophical beliefs, racial or ethnic origin, trade union membership, health, sex life and sexual orientation. Where we analyse public content we may process such data incidentally, because it is present in the material being measured. We do not seek it out, we do not analyse or segment individuals by these characteristics, and we do not use it to make any decision about a person.
Where an individual has themselves deliberately made such information public, we rely on Article 9(2)(e) of the UK GDPR. We apply that condition narrowly: it covers information a person has actively chosen to publish about themselves, not information published about them by someone else. Where that condition does not apply, we rely on Article 9(2)(j), processing necessary for statistical purposes, subject to the safeguards in Article 89(1) and the corresponding condition in Schedule 1 of the Data Protection Act 2018. Those safeguards include collecting only what the method requires, and reporting results in aggregate rather than about identified individuals wherever the analytical purpose allows. The condition relied on is recorded in the documentation for each engagement, and where an engagement could not be delivered within these conditions we decline it.
3.6 Criminal offence data
News coverage often refers to allegations, investigations, proceedings and convictions. Where our analysis covers such material we may process personal data relating to criminal offences, which requires a condition under the Data Protection Act 2018 in addition to a lawful basis. We do not compile records of any individual’s criminal history. We do not provide screening, vetting, due diligence or background checking services of any kind, and we do not use this material to make or support decisions about individuals. Where an engagement would involve processing of this kind beyond what is incidental to measuring public coverage, we identify and record the applicable condition before work begins, and decline the engagement if none applies.
3.7 Children
Our services are not directed at children and we do not knowingly collect data about children through this website. Public coverage occasionally names or depicts people under 18. We do not analyse individuals by age, we do not target analysis at children, and we apply additional minimisation to material that plainly concerns a child.
4. Personal data we handle as a processor
During analytics engineering and governance engagements we frequently work inside a client’s own systems and data. Any personal data there belongs to the client, who is the controller. In that work we process the data only on the client’s documented written instructions. We do not use it for any purpose of our own, and we never reuse it across clients. We apply confidentiality obligations to everyone working on the engagement, and we engage no sub-processor without the client’s prior written authorisation. We return or delete the data at the end of the engagement, as the client directs, and we assist the client in responding to data subject requests and in meeting their own obligations, including breach notification. Where we hold data for more than one client, each client sees only their own, and separation is enforced at the database layer rather than in application logic.
If you believe a client of ours holds your data and we are processing it on their behalf, contact that organisation. If you contact us, we will forward your request to them.
5. Who we share data with
We do not sell, rent or trade personal data, and we do not share it for anyone else’s marketing. We use a small number of service providers who process data on our behalf under written contract, covering hosting, email, file storage, accounting and payments. A current list of these sub-processors is available on request from [email protected]. We disclose personal data otherwise only where we are legally required to, or to establish, exercise or defend legal claims.
6. International transfers
Our own business data is held within the UK or the European Economic Area wherever practicable. Where a service provider processes data outside the UK, we rely on UK adequacy regulations where they apply, and otherwise on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment. Where we work with clients or partner organisations outside the UK, the transfer arrangements are set out in the relevant engagement contract.
7. Security
We apply encryption in transit using TLS 1.2 or above, and encryption at rest. Access is granted on a least-privilege basis and reviewed. Access to client environments is logged. Devices used for client work are encrypted and access-controlled. We keep a record of security incidents. Where a personal data breach occurs we will notify the ICO within 72 hours where the breach is likely to result in a risk to people’s rights and freedoms, and notify affected individuals without undue delay where the risk is high. Where we are acting as a processor, we notify the client without undue delay.
8. Automated decision-making
We do not make decisions producing legal or similarly significant effects about individuals by automated means, and we do not carry out that kind of profiling. Some of our analytical work uses automated classification and text processing to sort, categorise and summarise content. That processing produces analysis about themes and coverage, not decisions about individuals.
9. Your rights
Under UK data protection law you have the right to ask what personal data we hold about you and get a copy of it; to have inaccurate data corrected; to ask for data to be erased in certain circumstances; to ask us to restrict how we use your data; to receive data you gave us in a portable format, where that right applies; and to withdraw consent at any time, where we rely on consent.
To exercise any of these, contact [email protected]. We will respond within one month. If a request is complex we may extend that by up to two further months, and we will tell you within the first month if we do, and why. We do not charge for responding, except where a request is manifestly unfounded or excessive.
You also have the right to object at any time to processing we carry out on the basis of legitimate interests. This includes our collection and analysis of public content described in section 3.4. If you object, we will stop that processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is for the establishment, exercise or defence of legal claims. To object, contact [email protected], telling us what you object to and, if you can, how we would identify the data concerned.
If you are unhappy with how we have handled your data, please tell us first so that we can put it right. You also have the right to complain to the Information Commissioner’s Office at any time, at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, on 0303 123 1113, or at ico.org.uk.
10. Cookies
This website uses only cookies that are strictly necessary for it to work, including those set by our hosting and caching provider and by the contact form. Strictly necessary cookies do not require your consent. We do not currently use analytics, advertising or tracking cookies. If that changes, we will update this notice and ask for your consent before any non-essential cookie is set.
11. Changes to this notice
We update this notice when our processing changes. The date at the top shows the current version. Where a change materially affects how we use your data, we will take reasonable steps to tell affected people directly.
Cubixio Limited · Company number 17159605 · ICO registration ZC220575
Collingwood Buildings, 38 Collingwood Street, Newcastle upon Tyne, NE1 1JF