Legal

Privacy policy

Effective 30 July 2026

Who controls your data

VyrexCode is the controller for enquiries, sales and account administration. For client website analytics and campaign data, VyrexCode acts as a processor on the client's documented instructions.

What we collect

We process contact and account details, support and sales correspondence, transaction references, campaign performance data, website SEO elements, service logs, security records and client-supplied brand assets. The Vyrex Tag is designed not to collect visitor names, email addresses, form values, cookies or persistent identifiers.

Why we process it

We use data to provide contracted services, secure accounts, process payments, respond to enquiries, measure service performance, meet legal obligations and pursue legitimate interests in operating and improving the platform. Marketing messages are sent only where permitted and can be declined.

Sharing and international transfers

We use vetted service providers listed in our subprocessor register. Where data leaves the UK, we rely on an applicable adequacy decision or contractual safeguards.

Retention

Enquiries are retained for up to 24 months; account and campaign data for the contract plus 90 days unless another period is agreed; security logs for 12 months; and financial records for the legally required period. Backups expire on their normal rotation. A legal hold may extend these periods.

Your rights

You can request access, correction, deletion, restriction, portability or object to processing. You may complain to the UK Information Commissioner's Office. Send requests to [email protected]; identity verification may be required.

Security and deletion

We use access controls, encryption, audit logs, least-privilege database credentials and protected backups. Client offboarding disables access and integrations immediately, then schedules deletion according to the contract and retention schedule.