Privacy Policy

Data controller

Maxon Partners in Shirleytown is your data controller, responsible for processing decisions and purposes. Direct all questions, objections, and complaints to the controller at info@maxonpartne.co.uk, who also handles data protection matters. The controller determines both the reason for and the method of every processing activity performed on this site, and serves as the first point of contact for any concern raised under this notice. Employees with relevant responsibilities access incoming messages, which are fully documented for request-to-response tracking, so every enquiry can be traced through to the reply it received. When verifying your identity, we request only the required identifying information, never more than what confirming you demands.

Legal basis

Processing finds legal authority in two GDPR articles. Article 6(1)(a) GDPR authorises form-based consent: you knowingly submit data expecting nothing more than a response, and you are able to withdraw that consent at any time by writing to info@maxonpartne.co.uk. Article 6(1)(f) GDPR authorises processing of messages tied to a professional engagement or a legal documentation requirement: our legitimate interests in responding professionally and keeping defensible records apply on this second, independent basis. Withdrawing consent stops all further processing that relies on it; legally-required records remain restricted to storage rather than being deleted.

Who has access to your data

Your information is never sold, leased, or given to advertising services. It is shared solely with essential infrastructure operators: the web host storing the website and database, and the email service connecting to info@maxonpartne.co.uk. These are contractual GDPR processors with restricted use rights, appropriate security obligations, and annual compliance verification. Tax and banking authorities receive payment data only upon invoice and legal mandate. Processor access is confined strictly to functional requirements.

Your legal protections

GDPR Articles 15 to 22 establish your rights. Access your data, correct errors, and request erasure once no legal basis for processing remains. Restrict processing during accuracy disputes while the question is being resolved, obtain the submitted data in portable, machine-readable format, and object at any time to processing based on legitimate interest. Write to info@maxonpartne.co.uk plainly to exercise any of these rights; no formal documents are needed, and a plain request is enough. One-month response window applies, extendable by two further months for complexity, with advance notice given if extended. Refusals include the explanations behind them.

How long we keep your data

Non-client inquiries are erased one year after the last message, allowing enough time to recognise a returning contact without building a permanent filing. Client records are kept six years past engagement closeout, aligned with the standard commercial and tax limitation periods that ordinarily apply. Consent statements and analytics data, where analytics have been accepted, are stored for twelve months then automatically purged. Legal holds, ongoing complaints, and active data requests exempt affected data from scheduled deletion entirely; such records enter restricted storage until the legal matter, complaint, or request closes, after which normal periods apply and run their course.

Moving data internationally

Our infrastructure is EEA-resident; your enquiry data ordinarily remains within EEA jurisdiction and does not normally cross its borders. External processor systems maintaining capacity beyond the EEA—including backup facilities—require Chapter V GDPR safeguards before any transfer proceeds: a Commission adequacy decision, or standard contractual clauses paired with a documented transfer impact assessment. Details on processors, their locations, and the applicable protections are available from info@maxonpartne.co.uk on request. Unprotected international transfers are simply not undertaken; form use does not authorise or imply transfer, and none rests on consent alone.

Security measures

All site traffic uses HTTPS encryption; form submissions are encrypted both in flight and at rest in the database. Personnel accessing enquiries are limited by role to the small number who actually answer them, each with individual credentials, strong authentication, and recorded access. Backups are encrypted, kept geographically separate from the primary systems, and periodically tested on a schedule. Security updates are deployed promptly; the same activity logs are scanned for anomalies; a written breach response includes risk assessment and mandatory notification of the supervisory authority and affected persons within the legal seventy-two-hour deadline where required.

What information we collect

All personal data that we handle comes exclusively and solely from your form input: your name, email address, phone number (optional), and your message. Our form transparency is complete and absolute; no covert or optional fields are designed to harvest additional data. Security logs maintained completely separately record exclusively technical details—your IP address, precise timestamp, browser type. External contact lists are absolutely not purchased from any source, profiles are not enriched from other data sources, and personal attributes are not inferred. Attachments sent by email follow the same protection standards and receive equivalent treatment.

Our use of your information

Purpose is to answer your inquiry, develop proposals as you ask, and keep correspondence records needed for accountable administration of the practice. Client engagements rely on this same documentation for delivery, payment, and the closing handoff described elsewhere on this site. Form data is not used for marketing, advertising, customer profiling, newsletters, or machine decisions of any kind. No inquiry is scored, ranked, analysed algorithmically, or fed into a growth tool. Once a communication has clearly concluded, it transitions to the deletion schedules set out below rather than permanent retention.

How to complain

Your right permits filing complaints with a supervisory authority about how your data has been handled, particularly in your EU state of habitual residence or wherever the alleged breach occurred. ICO is our regulatory authority for these matters, operating a free, independent complaints mechanism that charges no fee. Authority contact requires no prior notification to us, does not eliminate any other legal option available to you, and causes no disadvantage in any ongoing exchange. We nevertheless encourage contacting info@maxonpartne.co.uk initially as well, because most concerns resolve quickly and directly once we understand them.