Privacy Policy

1. Introduction

Infoseny Ltd. ("we", "us", or "our") is committed to protecting and respecting your privacy.

This Privacy Policy explains how we collect, use, store, share, and protect personal data when you visit our website, contact us, engage us for custom software or AI services, or use our software products and related services, including Wealthseny, in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Who We Are

Company name: Infoseny Ltd.
Registered location: United Kingdom
Website: www.infoseny.com
Contact email: dataprotection@infoseny.com

For the purposes of data protection law, Infoseny is the data controller of your personal data unless we tell you otherwise for a specific service or processing activity.

3. Personal Data We Collect

We may collect and process the following categories of personal data depending on how you interact with us.

3.1 Information You Provide to Us

  • Name
  • Email address
  • Company name
  • Job title
  • Contact details and the contents of enquiries, meeting requests, support requests, or other communications
  • Information you provide during onboarding, discovery, project delivery, or service configuration
  • Billing, invoicing, and payment-related information processed in connection with our services

3.2 Account and Security Information

When you create, access, secure, or recover an account for one of our services or products, including Wealthseny, we may collect and use:

  • Email address
  • Optional full name
  • Invitation code or other account-eligibility details where applicable
  • Account registration details
  • Authentication and session data
  • Password reset and account recovery data
  • Login and security metadata, such as IP address, browser and device information, user agent, login timestamps, and security event data used to protect accounts and investigate access issues

3.3 Information We Collect Automatically

  • IP address
  • Browser type and version
  • Operating system
  • Device information
  • Pages visited and time spent on the website or service
  • Usage, diagnostic, and performance information
  • Cookies and similar technologies

3.4 Information from Third Parties

  • Payment processors
  • Business partners, referrers, or client representatives where relevant to service delivery
  • Analytics or advertising providers, where applicable
  • Identity, authentication, communications, or infrastructure providers where reasonably necessary to operate and secure our services

4. How We Use Your Personal Data

We only use your personal data where we have a lawful basis to do so. We may use your personal data to:

  • Provide, operate, and maintain our website, custom services, software products, and related services
  • Respond to enquiries, proposals, and support requests
  • Manage onboarding, service delivery, project communications, and account administration
  • Process payments, invoices, and related financial administration
  • Improve our products, services, operations, reliability, and user experience
  • Send service-related communications and administrative notices
  • Send marketing communications where consent is given or another lawful basis applies
  • Comply with legal, regulatory, accounting, and reporting obligations
  • Detect, prevent, and investigate fraud, abuse, misuse, and unauthorised access

4.1 How We Use Account and Security Information

We use account and security information to:

  • Create and manage user accounts
  • Authenticate users and maintain secure sessions
  • Provide password recovery and credential-change functionality
  • Detect, prevent, and investigate fraud, abuse, misuse, and unauthorised access
  • Monitor, secure, maintain, and improve the reliability of our authentication and account-security processes
  • Provide customer support and investigate account-access issues

Authenticated access is supported through first-party security and session controls designed to reduce browser-side exposure of authentication tokens.

5. Lawful Bases for Processing

Under UK GDPR, we rely on the following lawful bases depending on the processing activity:

  • Contract or steps prior to entering into a contract where processing is necessary to respond to service enquiries, prepare proposals, deliver our services, create accounts, authenticate users, maintain secure sessions, provide password reset functionality, and otherwise provide access to our services and products
  • Legitimate interests where processing is necessary to operate and improve our business, protect accounts, prevent abuse, apply rate limiting, detect fraud, investigate incidents, maintain service security, support account-access troubleshooting, and communicate with customers and prospective customers in a proportionate way
  • Consent where required for non-essential cookies, certain marketing communications, or other processing that legally requires consent
  • Legal obligation where we must retain, use, or disclose information to comply with applicable law, regulation, court order, or lawful request

6. Cookies and Similar Technologies

We use cookies and similar technologies for different purposes.

6.1 Strictly Necessary Authentication and Security Cookies

We use strictly necessary cookies to sign users in, maintain secure authenticated sessions, protect account actions, and support essential security features. These cookies are required for the operation and security of authenticated areas of our services and are not used for advertising purposes.

6.2 Optional Analytics or Marketing Cookies

Where we use analytics or marketing cookies, these are separate from authentication and security cookies and, where required by law, are used only with the appropriate consent mechanism.

If you disable strictly necessary authentication or security cookies, some account and login features may not function correctly.

7. Data Sharing and Third Parties

We may share personal data with service providers and partners that support the operation of our business and services, including:

  • Cloud hosting and edge delivery providers
  • Authentication and identity service providers
  • Transactional email and communications providers
  • Payment processors
  • Analytics providers, where applicable
  • Security, infrastructure, maintenance, and support providers
  • Professional advisers such as legal, accounting, audit, or insurance advisers
  • Regulatory authorities, courts, law enforcement, or other third parties where required by law or reasonably necessary to protect our rights or the rights of others

We do not publish a vendor list in this policy. We use third-party providers only where reasonably necessary to operate, secure, maintain, or support our services.

8. International Access and Processing

We primarily host and store personal data in the United Kingdom. In some circumstances, personal data may be accessed or processed outside the United Kingdom, including when users access our services from other countries or where our service providers support hosting, authentication, communications, security, maintenance, analytics, or other operational functions.

Where personal data is processed outside the United Kingdom, we use appropriate safeguards in accordance with applicable data protection law, which may include UK adequacy regulations, International Data Transfer Agreements (IDTAs), or other recognised transfer mechanisms where relevant.

9. Data Security

We implement appropriate technical and organisational measures to protect personal data, including:

  • Access controls and least-privilege practices
  • Encryption and secure transmission measures where appropriate
  • Secure hosting and infrastructure controls
  • Monitoring, logging, and security reviews designed to support the confidentiality, integrity, and availability of our systems

Despite these measures, no method of transmission over the internet or method of electronic storage is completely secure.

10. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes described in this policy, including to provide our services, manage customer relationships, maintain account security, comply with legal obligations, and resolve disputes.

In particular:

  • Enquiry, onboarding, and service-delivery records may be retained for as long as needed to manage the relationship and related legal, operational, or accounting matters
  • Session and authentication cookies are retained for the period needed to maintain secure access and are deleted or expire automatically in accordance with their security purpose
  • Password reset and account recovery data is retained only for the period needed to support recovery, protect accounts, and investigate misuse
  • Security and account-access logs may be retained for a limited period to detect abuse, investigate incidents, and support account-security operations
  • Dormant account data may be retained until the account is reactivated, deleted, or no longer needed for legitimate business or legal purposes
  • Following account deletion, some data may be retained for limited periods in backups, audit trails, legal records, accounting records, dispute handling, or security records where required or justified by applicable law or legitimate operational needs

11. Your Data Protection Rights

Under UK GDPR, you have the right to:

  • Access your personal data
  • Rectify inaccurate or incomplete data
  • Request erasure of your data in appropriate circumstances
  • Restrict processing
  • Object to processing
  • Data portability where applicable
  • Withdraw consent at any time where processing relies on consent
  • Lodge a complaint with the Information Commissioner's Office (ICO)

ICO contact: https://www.ico.org.uk

12. Children's Data

Our services are not intended for children under the age of 16, and we do not knowingly collect personal data from children.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated "Last updated" date.

14. Contact Us

If you have any questions about this Privacy Policy or how we handle your personal data, please contact us at dataprotection@infoseny.com.

Last updated: July 2026