Privacy Statement
Introduction
We respect your privacy and understand your personal information is important to you. This Privacy Statement outlines ePAQ® Systems Limited’s practices with respect to information collected from those accessing our website at www.epaq.co.uk.
Grounds for data collection
Processing of your personal information such as name or phone number is necessary for us to provide you with the follow-up information that you request about our products and services.
We will not collect, share or use your personal information for purposes other than those described in this Privacy Statement. We encourage users of our website to carefully read the Privacy Statement and use it to make informed decisions.
Lawful basis for processing
Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we must identify a lawful basis for processing personal data. ePAQ® Systems Ltd relies on the following bases:
Consent – where you have provided your details via our website (e.g. contact form or demo request), we will process your information on the basis of your consent. You can withdraw consent at any time by contacting us at support@epaq.co.uk.
Legitimate interests – where we communicate with you about our products and services, provided this does not override your rights and freedoms.
Legal obligation – where we are required to retain information to comply with applicable law or regulation.
Contract – where processing is necessary in order to take steps at your request prior to entering into a contract with us, or to perform a contract with you.
Special category data (health information)
Where ePAQ® questionnaires are used within NHS services, health information is collected as part of clinical care. This is classed as special category data under UK GDPR. The lawful basis for processing this data is:
Article 9(2)(h) – processing is necessary for the purposes of the provision of health or social care or treatment, or the management of health or social care systems and services.
This means health data collected through ePAQ® is processed only in partnership with the relevant NHS Trust or healthcare provider, in line with their role as data controller. ePAQ® Systems Ltd acts as a data processor in this context, ensuring data is handled securely and in compliance with NHS information governance standards.
What data do we collect from you?
We collect two types of data and information from users of our website.
Non-personal information
Un-identified and non-identifiable information pertaining to a user(s), which may be made available or gathered via your use of the site. This may include aggregated usage data and technical information transmitted by your device (e.g. browser type, operating system, language preference, access time) in order to enhance functionality of our site. It may also include information on your activity on the site (e.g. pages viewed, browsing, clicks, actions).
Personal information
Individually identifiable information, namely information that identifies an individual or may with reasonable effort identify an individual. Such information includes:
Registration information: When you register to our site you will be asked to provide us with certain details such as: full name; e-mail or physical address; and other contact details.
How do we receive information about you?
We receive your personal information from various sources:
When you voluntarily provide us with your details (e.g. when registering for a demo or requesting further information).
From third-party providers, services and public registers (for example, traffic analytics).
How do we use your information?
We do not rent, sell or share users’ information with third parties except as described in this Privacy Statement.
We may use the information for the following:
Communicating with you – providing you with technical information and responding to customer service issues.
Keeping you informed of updates and services.
Marketing our products and services (see Marketing section).
Reviewing statistics and conducting analysis to improve the site.
We may also share personal information with affiliated companies and subcontractors or trusted third-party providers (hosting, processing, analytics, marketing, research) strictly for the purposes listed above.
We may also disclose information if required to comply with law, regulation, legal process, to enforce our policies, investigate potential violations, prevent fraud/security issues, defend against claims, or to protect rights, property, or safety.
Where your information is processed?
Your information is currently processed only in the UK. If in future data is transferred outside the UK, we will ensure appropriate safeguards are in place (e.g. adequacy decisions or Standard Contractual Clauses).
Google Analytics
We use Google Analytics (including advertiser features) to understand site visitors via anonymised data. This may include demographics, interest reporting, and remarketing. Data is collected via Google cookies and anonymous identifiers.
User Rights
You may request to:
Confirm whether your personal data is being processed and access a copy.
Receive a copy of personal data you provided, in a portable format.
Rectify inaccurate data.
Request erasure of personal data.
Object to or restrict processing of personal data.
Lodge a complaint with the ICO.
Requests can be made by contacting our Data Protection Officer at support@epaq.co.uk.
Retention
We will retain personal data for as long as necessary to provide services, comply with legal obligations, resolve disputes, and enforce policies. Retention periods are determined by the type of information collected and its purpose, with outdated or unused information destroyed at the earliest reasonable time.
Cookies
We and our partners use cookies to enhance your experience, including session cookies, persistent cookies, and third-party cookies (e.g. analytics). You may disable cookies in your device preferences, but some features of the site may not function properly.
Marketing
We may use your personal information to provide promotional materials about our services that we believe may interest you. Marketing communications will only be sent where you have opted in, and you may unsubscribe at any time. Even if you unsubscribe, we may still send essential communications such as service or security notices.
How we protect your information
We use industry-standard technical and organisational measures to protect personal data, including secure hosting, encryption, and strict access controls. All staff complete annual data protection training. While we take reasonable steps to safeguard information, no system is completely secure, we cannot be responsible for the acts of those who gain unauthorised access or abuse our site, and we make no warranty, express, implied or otherwise, that we will prevent such access.
Data breaches
In the event of a serious personal data breach, we will notify the Information Commissioner’s Office (ICO) within 72 hours where required, and affected customers without undue delay. A Security Incident Form will be completed internally, documenting resolution and any notifications made.
Minors
Our website is not directed at children. We do not knowingly collect personal data from minors without parental consent. If a parent or guardian believes their child has provided data without consent, they should contact us at support@epaq.co.uk.
Updates or amendments
We may amend this Privacy Statement from time to time. Material changes will take effect immediately when displayed on our website. The date of the last revision will be shown below. Continued use of the site after changes constitutes acceptance.
Contact us
If you have questions about this Privacy Statement or the information we hold, please contact: support@epaq.co.uk
Last modified: 25/08/2025