Privacy Policy

How Agile Spiral Limited handles personal data from website visitors, contact form enquiries, clients, suppliers and business contacts under UK data protection law.

Controller
Agile Spiral Limited
Company number
10626269
Last updated
29 June 2026
Privacy contact
info@agilespiral.com

Who We Are

Agile Spiral Limited is a UK public-sector digital delivery consultancy.

Company name Agile Spiral Limited
Company number 10626269
Registered office 11 Madison Way, London, E20 1PD, United Kingdom
Privacy contact info@agilespiral.com

This policy explains how we use personal data under the UK GDPR, the Data Protection Act 2018 and, where it applies, the EU GDPR. Agile Spiral Limited is the data controller for the personal data described in this policy.

Personal Data We Collect

We collect a small amount of personal data when you use this website, contact us, work with us, supply services to us, or communicate with us about a business opportunity.

  • Contact form details, including your first name, last name, email address, subject and message.
  • Business contact details, including name, role, organisation, email address, phone number and correspondence.
  • Client, supplier and procurement information needed to discuss, agree, deliver and manage work.
  • Payment, invoicing, tax and accounting records where we have a client or supplier relationship.
  • Information you choose to send us about your background when contacting us about work.
  • Basic technical data, such as server logs, IP address, browser type, device information and pages visited.

Please do not send sensitive personal data through the website contact form unless it is necessary for your enquiry.

How We Use Personal Data

We use personal data for the purposes below. We only use it where we have a lawful basis under the UK GDPR or GDPR.

Purpose Lawful basis
Responding to contact form messages and other enquiries Legitimate interests, and steps before entering into a contract where relevant
Discussing services, procurement routes, proposals, bids and delivery needs Contract, legitimate interests and legal obligation where applicable
Managing client, supplier and professional adviser relationships Contract, legitimate interests and legal obligation where relevant
Keeping finance, accounting, tax, audit and legal records Legal obligation and legitimate interests
Operating, securing and troubleshooting the website Legitimate interests
Considering work-related enquiries sent to us directly Legitimate interests, and steps before entering into a contract where relevant

We do not sell personal data.

Cookies and Website Data

This website uses a Netlify contact form so visitors can send enquiries to Agile Spiral. When you submit the form, the details you provide are processed so we can receive and respond to your message.

We do not currently use analytics, advertising cookies or tracking pixels on this website. The website host may collect basic technical logs needed to operate, secure and troubleshoot the site.

If we introduce analytics in future, then we will update this policy and use cookie controls where required.

Sharing Personal Data

We share personal data only where it is necessary for the purposes set out in this policy.

  • Website hosting and contact form providers.
  • Email, cloud storage and business administration providers.
  • Accountants, legal advisers, insurers and other professional advisers.
  • Public-sector clients, framework authorities and procurement platforms where needed for bids, contracts or delivery.
  • Service providers where needed to provide services or manage a business relationship.
  • Regulators, courts, law enforcement or public authorities where required by law.

Some service providers may process data outside the UK. Where this happens, we rely on appropriate safeguards, such as UK adequacy regulations, the UK International Data Transfer Agreement or an approved transfer addendum.

How Long We Keep Personal Data

We keep personal data only for as long as needed for the purpose it was collected.

The retention period depends on the type of data, the nature of the relationship, whether the information is still needed for business records, and whether we need to keep it for legal, accounting, tax, procurement, security or dispute-resolution reasons.

When personal data is no longer needed, we will delete it, anonymise it, or keep it only where the law requires or permits us to do so.

Your Rights

Under the UK GDPR and GDPR, you may have the right to ask us to:

  • provide a copy of the personal data we hold about you;
  • correct inaccurate or incomplete personal data;
  • delete personal data in certain circumstances;
  • restrict or object to how we use personal data;
  • provide personal data in a portable format where applicable;
  • withdraw consent where processing is based on consent.

To exercise your rights, contact info@agilespiral.com. We may need to confirm your identity before responding.

You also have the right to complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint.

Updates to This Policy

We may update this policy from time to time, including when we change website tools, introduce analytics, or change how we handle personal data. The latest version will be published on this page.