This Privacy Notice explains how Pixedi Ltd (“we”, “us”) collects, uses, stores, and discloses information submitted through the Pixedi Black vetting form and related communications.
Plain-English summary: We collect only what we need to evaluate your request. Access is tightly restricted. We do not sell your data. If we decline your request, we delete your submission quickly. If we engage, we retain project materials only as long as necessary and apply strict security controls.
1) Who we are
Controller / Business: Pixedi Ltd (United Kingdom) acts as the data controller (UK) and “business” (US state privacy terms) for information submitted via the Pixedi Black intake.
Contact: Use the communication channel provided on the site or the channel we initiate after vetting.
2) What we collect
When you submit the vetting form or communicate with us, we may collect:
- Identity & organisation details you provide (e.g., entity name, role/title)
- Commercial/engagement details (e.g., budget/capital allocation ranges, timelines)
- Objective/brief content you submit
- Contact details you provide (email/phone/secure handle)
- Technical metadata (e.g., IP address, timestamps, browser/device signals, basic security logs)
We do not request sensitive personal data. Please do not submit passports, national IDs, medical data, or other special-category/sensitive information unless we explicitly request it through a secure channel.
3) How we use your information
We use information for the following purposes:
- Vetting & eligibility assessment (to decide whether to engage)
- Secure communications (to contact you if your request qualifies)
- Service delivery (if engaged) (to plan, execute, and support the agreed scope)
- Security & fraud prevention (protecting systems, enforcing access controls)
- Legal compliance (meeting lawful obligations, responding to valid legal requests)
We do not use vetting submissions for advertising, lead reselling, or unrelated marketing.
4) Legal bases (UK)
For individuals in the UK/EEA-like regimes, we rely on:
- Legitimate interests (assessing inquiries, protecting confidentiality and security)
- Contract (where engagement proceeds and processing is necessary to perform it)
- Legal obligation (where required)
You may object to processing based on legitimate interests where applicable.
5) US privacy disclosures (high-level)
If you are a resident of a US state with privacy laws (e.g., California), this section applies in addition to the rest of the notice:
- No sale / no targeted advertising: We do not sell personal information and do not share it for cross-context behavioral advertising.
- Data minimization: We collect and use information for the purposes described above.
- Rights: Depending on your state, you may have rights to access, delete, correct, or obtain a copy of your information, and to opt out of certain processing categories (where applicable). We will verify requests before acting.
6) Operational security & access restrictions
Pixedi Black runs under a restricted-access model:
- Need-to-know access: Only authorized personnel may access Black Tier submissions.
- Operational isolation: Black Tier materials are segregated from general operations.
- Security controls: Encryption in transit, access controls, and monitoring designed to prevent unauthorized access.
No system can guarantee absolute security, but we apply controls appropriate to the sensitivity of Black Tier work.
7) Retention & deletion
We retain information only as long as necessary for the purposes above.
7.1 Vetting submissions
If declined: We delete the submission and identifying traces within 24 hours (or as soon as technically feasible).
If accepted / engagement begins: We retain intake materials as part of the engagement record.
7.2 Project materials (if engaged)
Upon project completion or contract termination, project assets and correspondence are retained for a maximum of 7 days, then securely destroyed, unless a longer retention period is required for:
- billing/financial recordkeeping,
- legal compliance,
- active dispute resolution, or
- explicit written instructions from the client.
Secure destruction may include cryptographic erasure, secure deletion, or key destruction depending on the storage medium.
8) Sharing & disclosures
We do not share client data with marketing partners.
We may disclose information only in limited circumstances:
- Service providers (rare, necessary, and controlled): If strictly required for operations (e.g., secure email/hosting), under contractual confidentiality and security obligations.
- Legal requirements: To comply with valid legal processes or protect rights, safety, and security.
- With your instruction: Where you direct us in writing.
9) International transfers
Because we operate in the UK and may engage with US-based clients, information may be processed in the UK and the US. Where UK law requires safeguards for cross-border transfers, we implement appropriate transfer mechanisms and security controls.
10) Your choices & rights
You can request:
- access to the information we hold about you,
- correction of inaccurate data,
- deletion (where applicable),
- restriction or objection (UK/EEA-like regimes),
- a copy/portability (where applicable).
We may ask for verification to protect confidentiality.
11) Cookies & analytics
If this page uses cookies or analytics, we will present a cookie notice/consent mechanism where required and limit analytics to what is necessary for security and basic site performance.
12) Changes to this notice
We may update this notice to reflect operational, legal, or security changes. The “Last Updated” date will change accordingly.