About Us
Privacy Policy & GDPR Compliance
Get To Know Akendi Close

Privacy Policy & GDPR Compliance

Akendi UK - Last updated: 21 October 2025
- Exercise your data rights
Introduction

Welcome to Akendi UK's comprehensive privacy policy. We are committed to protecting your personal data and respecting your privacy rights in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and all applicable UK data protection laws. This policy explains how we collect, use, store, and protect your personal information when you visit our website or engage with our services.

Akendi operates as a data controller for the personal information we collect about you. We are registered with the Information Commissioner's Office (ICO) and comply with all relevant UK data protection regulations.

Your Data Protection Rights Under UK GDPR

As a UK resident, you have specific rights regarding your personal data:

  • Right to be informed: You have the right to clear information about how we use your personal data
  • Right of access: You can request a copy of the personal data we hold about you
  • Right to rectification: You can ask us to correct inaccurate or incomplete data
  • Right to erasure: You can request deletion of your personal data in certain circumstances
  • Right to restrict processing: You can ask us to limit how we process your data
  • Right to data portability: You can request your data in a portable format
  • Right to object: You can object to certain types of processing
  • Rights related to automated decision making: You have rights regarding automated decision-making and profiling
What Personal Data We Collect

We collect and process the following categories of personal data:

  • Contact Information: Name, email address, postal address, telephone number
  • Professional Information: Job title, company name, professional interests
  • Communication Data: Records of your communications with us, including emails and enquiries
  • Technical Data: IP address, browser type, device information, cookies, and website usage data
  • Marketing Data: Your preferences for receiving marketing communications and event invitations
Legal Basis for Processing

We process your personal data under the following legal bases as defined by UK GDPR:

  • Consent: For marketing communications and non-essential cookies
  • Contract: To deliver our services and fulfil contractual obligations
  • Legitimate Interest: For business development, website analytics, and security
  • Legal Obligation: To comply with UK legal and regulatory requirements
How We Use Your Personal Data

We process your personal data for the following purposes:

  • Delivering our UX design and consultancy services
  • Responding to your enquiries and providing customer support
  • Sending marketing communications (with your consent)
  • Improving our website and services through analytics
  • Ensuring website security and preventing fraud
  • Complying with legal and regulatory obligations
  • Managing our business relationships and conducting business development
Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your website experience. Our cookies fall into these categories:

  • Essential Cookies: Necessary for website functionality (no consent required)
  • Analytics Cookies: Help us understand website usage (consent required)
  • Marketing Cookies: Used for advertising and personalisation (consent required)

You can manage your cookie preferences through our cookie banner or by contacting us. Withdrawing consent for non-essential cookies may affect website functionality.

Data Sharing and International Transfers

We may share your personal data with:

  • Trusted service providers who assist with our operations
  • Professional advisers including lawyers and accountants
  • Government authorities where legally required
  • Other Akendi entities (Canada and USA) for business operations

Post-Brexit Data Transfers: For international data transfers, we implement appropriate safeguards including Standard Contractual Clauses (SCCs) approved by the UK authorities or rely on adequacy decisions. We ensure all transfers comply with UK data protection requirements.

Data Retention

We retain your personal data only for as long as necessary:

  • Client records: 7 years after project completion (legal requirement)
  • Marketing data: Until you withdraw consent or we determine it's no longer relevant
  • Website analytics: 26 months from collection
  • Communication records: 3 years from last contact
  • Financial records: 7 years (HMRC requirement)
Data Security

We implement robust technical and organisational measures to protect your personal data, including:

  • Encryption of data in transit and at rest
  • Regular security assessments and updates
  • Access controls and staff training
  • Incident response procedures
  • Regular backups and disaster recovery plans
Data Breach Notification

In accordance with UK GDPR requirements, we will report any personal data breach to the ICO within 72 hours of becoming aware of it, where feasible. We will also inform affected individuals without undue delay where the breach is likely to result in high risk to their rights and freedoms.

Children's Privacy

Our services are not directed at children under 16 years of age. We do not knowingly collect personal data from children under 16. If we become aware that we have collected such data, we will take immediate steps to delete it.

Changes to This Privacy Policy

We may update this privacy policy periodically to reflect changes in our practices or applicable law. We will notify you of any material changes by posting the updated policy on our website and updating the "last updated" date. For significant changes, we may also provide additional notice via email.

ICO Registration and Complaints

We are registered with the Information Commissioner's Office (ICO). If you have concerns about our data processing practices, you can contact us directly. You also have the right to lodge a complaint with the ICO at any time:

  • ICO Website: ico.org.uk
  • ICO Helpline: 0303 123 1113
  • Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

Frequently Asked Questions

What are my rights under UK GDPR?

Under UK GDPR, you have several fundamental rights including the right to be informed, right of access, right to rectification, right to erasure ('right to be forgotten'), right to restrict processing, right to data portability, right to object, and rights related to automated decision making including profiling. These rights are designed to give you control over your personal data.

How do I request deletion of my personal data?

To request deletion of your personal data, please contact us at contact@akendi.com with 'Data Deletion Request' in the subject line. Include your full name, email address, and specify which data you'd like deleted. We will respond within one month and delete your data where legally permissible under UK GDPR. Note that we may need to retain some data for legal or legitimate business purposes.

How does Brexit affect data transfers?

Post-Brexit, the UK has its own data protection regime based on UK GDPR and the Data Protection Act 2018. For international transfers, we use appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by UK authorities or rely on adequacy decisions. We ensure all data transfers comply with both UK requirements and destination country laws, maintaining the same high level of protection.

Are you registered with the ICO?

Yes, we are registered with the Information Commissioner's Office (ICO) as required under UK data protection law. We comply with all ICO guidelines and would report any qualifying data breaches within 72 hours of becoming aware of them, as required by UK GDPR.

What cookies do you use and why?

We use three types of cookies: essential cookies for basic website functionality (these don't require consent), analytics cookies to understand user behaviour and improve our website (requires consent), and marketing cookies for advertising purposes (requires consent). You can manage your cookie preferences at any time through our cookie banner or by contacting us directly.

How long do you keep my personal data?

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected. Typically, client project data is kept for 7 years for legal and accounting purposes, marketing data until you withdraw consent or we determine it's no longer relevant, website analytics data for 26 months, and general communication records for 3 years. Specific retention periods depend on the type of data and legal requirements.

How do I withdraw consent for marketing communications?

You can withdraw consent for marketing communications at any time by clicking the 'unsubscribe' link in any marketing email, updating your preferences in your account settings, or contacting us directly at contact@akendi.com. Withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal.

What happens if there's a data breach?

In the unlikely event of a personal data breach, we follow UK GDPR requirements by reporting qualifying breaches to the ICO within 72 hours of becoming aware of them. If the breach is likely to result in high risk to your rights and freedoms, we will also notify you directly without undue delay. We have comprehensive incident response procedures to minimise any potential impact.

Can I access all the data you hold about me?

Yes, you have the right to request a copy of all personal data we hold about you. This is called a Subject Access Request (SAR). Contact us at contact@akendi.com with 'Subject Access Request' in the subject line. We'll provide this information free of charge within one month, along with details about how we process your data.

Do you use automated decision-making or profiling?

We do not use automated decision-making or profiling that would significantly affect you. Any analytics we conduct is for general website improvement and business purposes. If we were to implement automated decision-making in the future, we would update this policy and ensure compliance with UK GDPR requirements, including your right to human intervention.

Exercise Your Data Rights

Contact us at contact@akendi.com to exercise any of your data protection rights under UK GDPR.

Response Time: We aim to respond to all data protection requests within one month.

ICO Registration

We are registered with the Information Commissioner's Office (ICO) as required under UK data protection law.

Data Protection Officer

For data protection enquiries, please contact our team at contact@akendi.com

Akendi UK is the premier human experience research and UX design consultancy specialising in creating intentional, user-centred experiences. Based in Cambridge, we combine deep insights about user behaviour with inspired design whilst maintaining the highest standards of data protection and privacy.

How can we help_hand help you?