Privacy & Cookie Policy

    Last updated: 16 September 2026

    SmartIR Limited ("SmartIR", "we", "us") respects your privacy. This policy explains what personal data we collect when you visit www.smartir.co.uk or contact us, how we use it, and the rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

    1. Who we are

    SmartIR Limited is the controller responsible for your personal data.

    • Registered in England and Wales, company number 12473467
    • Registered office: Marsland Chambers, 1a Marsland Road, Sale Moor, Cheshire, M33 3HP
    • Office: Graphene Engineering Innovation Centre (GEIC), Sackville Street, Manchester M1 3BB
    • Email: info@smartir.co.uk

    We are not required to appoint a Data Protection Officer. If you have any questions about this policy or about your personal data, please email us at info@smartir.co.uk.

    2. The personal data we collect

    Visiting our website

    Our website has no contact forms, user accounts, analytics or advertising. As with any website, when you visit it your browser sends technical information to our hosting provider, GitHub Pages, so that the pages can be delivered: your IP address, browser and device type, the page requested, the referring page, and the date and time of the request. GitHub records this information in its server logs to operate and secure its service. We do not have access to these logs and we do not use them to identify visitors.

    Contacting us by email

    If you email us, for example to make an enquiry or to request a demo or a quote, we receive your name, email address and any other information you choose to include, such as your organisation, job title, phone number, the content of your message and any attachments.

    Applying for a job

    If you send us your CV or a job application, we process the information it contains, such as your contact details, education, employment history and qualifications. Please do not include sensitive information, such as details about your health, unless we ask for it.

    3. How we use your personal data and our lawful basis

    PurposePersonal dataLawful basis
    Delivering our website and keeping it secureTechnical data (IP address, browser and device type, pages requested, date and time)Legitimate interests: operating a secure and functioning website
    Responding to your enquiries, demo and quote requestsContact details and the content of your messageLegitimate interests: responding to people who contact us; or taking steps at your request before entering into a contract
    Managing our relationships with customers, suppliers and partnersContact details and correspondencePerformance of a contract; legitimate interests: running our business
    Assessing job applicationsContact details, CV and application informationTaking steps at your request before entering into an employment contract; legitimate interests: recruiting suitable staff
    Complying with the law and establishing or defending legal claimsAny of the above, where relevantLegal obligation; legitimate interests: protecting our legal rights

    Where we rely on legitimate interests, we have balanced them against your rights and interests, and you can object at any time (see Your rights).

    You are not required by law or contract to give us your personal data, but if you do not, we may not be able to respond to your enquiry or consider your application. We do not make decisions about you based solely on automated processing, we do not profile you, and we never sell your personal data.

    4. Who we share your personal data with

    We only share personal data where necessary, with:

    • GitHub, Inc., which hosts our website (GitHub Privacy Statement);
    • Microsoft Corporation, which provides our email and business productivity services through Microsoft 365 (Microsoft Privacy Statement);
    • professional advisers, such as lawyers and accountants, where needed;
    • law enforcement bodies, regulators and other authorities, where the law requires us to.

    5. International transfers

    GitHub and Microsoft are based in the United States and may process personal data outside the UK. These transfers are protected by safeguards recognised under UK data protection law. Both companies are certified under the UK Extension to the EU-US Data Privacy Framework (the "UK-US data bridge"). Where that does not apply, we rely on the International Data Transfer Agreement or Addendum approved for use in the UK.

    6. How long we keep your personal data

    • Enquiries and correspondence: up to 2 years after our last contact with you, unless a business relationship follows.
    • Business relationship records: for the duration of the relationship and up to 6 years afterwards, to meet our legal, tax and accounting obligations.
    • Unsuccessful job applications: 6 months after the end of the recruitment process, unless you agree that we may keep your details for future vacancies.
    • Website server logs: kept by GitHub in line with its own privacy statement.

    7. Your rights

    Under UK data protection law you have the right to:

    • Access: ask for a copy of the personal data we hold about you;
    • Rectification: ask us to correct inaccurate or incomplete data;
    • Erasure: ask us to delete your data;
    • Restriction: ask us to limit how we use your data;
    • Objection: object to our use of your data where we rely on legitimate interests;
    • Portability: receive the data you gave us in a machine-readable format, or have it sent to another organisation;
    • Withdraw consent: where we rely on your consent, withdraw it at any time.

    Some of these rights apply only in certain circumstances. To exercise any of them, email us at info@smartir.co.uk. There is no charge. We may ask you to confirm your identity, and we will respond within one month. For complex requests this can be extended by up to two further months, in which case we will let you know.

    8. Complaints

    If you are unhappy with how we have handled your personal data, please contact us first at info@smartir.co.uk. We will acknowledge your complaint within 30 days, investigate it without undue delay and tell you the outcome.

    You also have the right to complain to the UK data protection regulator, the Information Commissioner's Office (ICO), which becomes the Information Commission on 30 September 2026:

    9. Cookies and similar technologies

    Our website does not use cookies or similar technologies, such as local storage, tracking pixels or device fingerprinting, and we do not use analytics or advertising tools. We do not store or access any information on your device, so we do not need your consent and you will not see a cookie banner.

    Fonts, images and scripts are all served from our own website, so your browser does not contact third-party services when you view our pages.

    If we introduce cookies or similar technologies in the future, we will update this policy and, where the Privacy and Electronic Communications Regulations (PECR) require it, ask for your consent first.

    10. Links to other websites

    Our website links to other websites, such as LinkedIn. When you follow these links, the other website's own privacy policy applies. We are not responsible for how those websites handle your personal data.

    11. Security

    We use appropriate technical and organisational measures to protect your personal data, including encrypted (HTTPS) connections to our website and access controls on our email systems.

    12. Changes to this policy

    We may update this policy from time to time. The latest version will always be available on this page, with the date of the last update shown at the top.