Privacy & Cookie Policy
Last updated: 16 September 2026
SmartIR Limited ("SmartIR", "we", "us") respects your privacy. This policy explains what personal data we collect when you visit www.smartir.co.uk or contact us, how we use it, and the rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are
SmartIR Limited is the controller responsible for your personal data.
- Registered in England and Wales, company number 12473467
- Registered office: Marsland Chambers, 1a Marsland Road, Sale Moor, Cheshire, M33 3HP
- Office: Graphene Engineering Innovation Centre (GEIC), Sackville Street, Manchester M1 3BB
- Email: info@smartir.co.uk
We are not required to appoint a Data Protection Officer. If you have any questions about this policy or about your personal data, please email us at info@smartir.co.uk.
2. The personal data we collect
Visiting our website
Our website has no contact forms, user accounts, analytics or advertising. As with any website, when you visit it your browser sends technical information to our hosting provider, GitHub Pages, so that the pages can be delivered: your IP address, browser and device type, the page requested, the referring page, and the date and time of the request. GitHub records this information in its server logs to operate and secure its service. We do not have access to these logs and we do not use them to identify visitors.
Contacting us by email
If you email us, for example to make an enquiry or to request a demo or a quote, we receive your name, email address and any other information you choose to include, such as your organisation, job title, phone number, the content of your message and any attachments.
Applying for a job
If you send us your CV or a job application, we process the information it contains, such as your contact details, education, employment history and qualifications. Please do not include sensitive information, such as details about your health, unless we ask for it.
3. How we use your personal data and our lawful basis
| Purpose | Personal data | Lawful basis |
|---|---|---|
| Delivering our website and keeping it secure | Technical data (IP address, browser and device type, pages requested, date and time) | Legitimate interests: operating a secure and functioning website |
| Responding to your enquiries, demo and quote requests | Contact details and the content of your message | Legitimate interests: responding to people who contact us; or taking steps at your request before entering into a contract |
| Managing our relationships with customers, suppliers and partners | Contact details and correspondence | Performance of a contract; legitimate interests: running our business |
| Assessing job applications | Contact details, CV and application information | Taking steps at your request before entering into an employment contract; legitimate interests: recruiting suitable staff |
| Complying with the law and establishing or defending legal claims | Any of the above, where relevant | Legal obligation; legitimate interests: protecting our legal rights |
Where we rely on legitimate interests, we have balanced them against your rights and interests, and you can object at any time (see Your rights).
You are not required by law or contract to give us your personal data, but if you do not, we may not be able to respond to your enquiry or consider your application. We do not make decisions about you based solely on automated processing, we do not profile you, and we never sell your personal data.
5. International transfers
GitHub and Microsoft are based in the United States and may process personal data outside the UK. These transfers are protected by safeguards recognised under UK data protection law. Both companies are certified under the UK Extension to the EU-US Data Privacy Framework (the "UK-US data bridge"). Where that does not apply, we rely on the International Data Transfer Agreement or Addendum approved for use in the UK.
6. How long we keep your personal data
- Enquiries and correspondence: up to 2 years after our last contact with you, unless a business relationship follows.
- Business relationship records: for the duration of the relationship and up to 6 years afterwards, to meet our legal, tax and accounting obligations.
- Unsuccessful job applications: 6 months after the end of the recruitment process, unless you agree that we may keep your details for future vacancies.
- Website server logs: kept by GitHub in line with its own privacy statement.
7. Your rights
Under UK data protection law you have the right to:
- Access: ask for a copy of the personal data we hold about you;
- Rectification: ask us to correct inaccurate or incomplete data;
- Erasure: ask us to delete your data;
- Restriction: ask us to limit how we use your data;
- Objection: object to our use of your data where we rely on legitimate interests;
- Portability: receive the data you gave us in a machine-readable format, or have it sent to another organisation;
- Withdraw consent: where we rely on your consent, withdraw it at any time.
Some of these rights apply only in certain circumstances. To exercise any of them, email us at info@smartir.co.uk. There is no charge. We may ask you to confirm your identity, and we will respond within one month. For complex requests this can be extended by up to two further months, in which case we will let you know.
8. Complaints
If you are unhappy with how we have handled your personal data, please contact us first at info@smartir.co.uk. We will acknowledge your complaint within 30 days, investigate it without undue delay and tell you the outcome.
You also have the right to complain to the UK data protection regulator, the Information Commissioner's Office (ICO), which becomes the Information Commission on 30 September 2026:
- Online: ico.org.uk/make-a-complaint
- Helpline: 0303 123 1113
- Post: Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
10. Links to other websites
Our website links to other websites, such as LinkedIn. When you follow these links, the other website's own privacy policy applies. We are not responsible for how those websites handle your personal data.
11. Security
We use appropriate technical and organisational measures to protect your personal data, including encrypted (HTTPS) connections to our website and access controls on our email systems.
12. Changes to this policy
We may update this policy from time to time. The latest version will always be available on this page, with the date of the last update shown at the top.