UK Privacy Policy

Version: CRX_LEGA_PRVN_UK_V03

Your Privacy Rights

This privacy notice sets out your rights and answers any queries you may have about how Crux Product Design Ltd (hereinafter referred to as “Crux”) collects, uses and protects your personal information. If you have any questions or concerns about our notice, or our practices with regards to your personal information, please contact us at privacy@cruxproductdesign.com.

Please ensure that you read this notice, and any other notices you may be provided with when we collect or process your personal information. Doing so will help you make informed decisions about sharing your personal information with us.

Crux reviews and updates this privacy notice. We recommend checking periodically to ensure that you are happy with any changes.

This privacy notice applies to all personal information collected through our website, and/or any related services, sales, marketing or events (hereinafter referred to as our “Services“).

Crux offers a range of consultancy services to support a diverse array of product development projects. This includes human factors research and usability testing, methodology used to evaluate user interaction with products. To authorise this testing, Crux is registered as a data controller with the Information Commissioner’s Office (ICO) under number ZA558972. A data controller determines the purposes and means of the processing of personal information.

Notice At Collection

This Notice at Collection describes how we collect, use and disclose personal information.

2.1        Collection of Personal Information

This privacy notice explains what personal information we will collect when you are:

  1. Visiting our website or engaging on social platforms
  2. Visiting our office
  3. Applying for a job
  4. Using our services
  5. Supplying to us
  6. Participating in research

This notice also includes:

  • How we keep your personal information secure
  • Where your personal information is stored
  • What your rights are in relation to your personal information
  • How to find out more information on how Crux handles your personal information
2.1.1    Personal Information You Provide to Us

We collect personal information you provide directly to us. For example, we collect personal information directly from you when you visit our website or engage with us on social platforms; visit our office; use our Services; supply to us; participate in research studies; express an interest in obtaining information about us or our Services; participate in activities related to our Services; contact us or conduct business dealings with us. The types of personal information that we may collect directly from you include the following:

  • Name
  • Phone number(s)
  • Email
  • Business address
  • Social media
  • Other similar data

Data is stored on our secure customer relationship management (CRM) platform (see Section 2.3).

2.1.2    Personal Information Automatically Collected When Visiting Our Services

Some personal information is collected automatically when you visit our Services. This data is required to maintain the security and operation of our Services, and for our internal analytics and reporting purposes.

This personal information does not reveal your specific identity (for example, your name or contact information) but may can include device and usage information such as:

  • IP addresses
  • Browser and device characteristics
  • Operating system
  • Language preferences
  • Referring URLs
  • Information about how and when you use our Services
  • Device name
  • Device geolocation

Information collected by Cookies and similar tracking technologies: We use cookies and similar tracking technologies (like web beacons and pixels) to access or store personal information. Where this involves cookies that are not strictly functional for the operation of our website, we will ask you for your consent prior to those cookies being placed on your device.

We use Google Analytics to collect personal information about how people use our website. Google Analytics stores information about behaviour on our website, such as referrals, pages you visit and what you click on. We do not allow Google to share our analytics data. We do this to understand how we can improve our website and make sure we are meeting the needs of our users.

2.1.3    Personal Information We Collect from Other Sources

We obtain personal information directly from you or other members of your organisation. We may also acquire personal information from your public profiles available online, primarily LinkedIn or company websites. Where this is the case, we will be transparent about our collection of your personal data, and we only contact people who we believe will have an interest in our products and services.

2.2        Purpose and Use of Personal Information

We process your personal information for purposes based on legitimate business interests, the fulfilment of our contract with you, compliance with our legal obligations, and/or your consent.

We use the personal information we collect or receive:

  • To send you focused marketing communications: We will send you select material we believe will be of interest. You can opt-out of our marketing emails at any time.
  • To send administrative information to you: We will use your personal information to send you product, service and new feature information and/or information about changes to our terms, conditions, and policies.
  • To protect our Services: We will use your personal information as part of our efforts to keep our Services safe and secure (for example, for fraud monitoring and prevention).
  • For analysis and improvement: We will use your personal information for data analysis, identifying usage trends, determining the effectiveness of our promotional campaigns and to evaluate and improve our products, Services and your experience. We will use and store personal information in aggregated and anonymised form so that it is not associated with individual end users. We will not use identifiable personal information without a specific lawful basis in place.
2.3        Disclosure of Personal Information

We use other companies to provide us with telephony, email and other IT services. We have put agreements in place with these companies to ensure that they will only process your personal information as requested by us and in accordance with data protection law.

We only share and disclose your personal information with the following third parties. If we have processed your data based on your consent and you wish to revoke your consent, please contact us (refer to Section 11).

  • SAP – an enterprise resource planning (ERP) system
  • HubSpot – a CRM platform
  • Retargeting Platforms – LinkedIn website retargeting
  • Office365 – for email correspondence and communication
2.4        Retention of Personal Information

Crux will retain your personal information for as long as it is required to fulfil the purposes for which the personal information was collected (including for the purpose of meeting any legal or other reporting requirements or obligations).

We will retain your personal information for no longer than 2 years after our relationship with you has ended. If you do use our Services, we will need to retain certain personal information for a longer period to meet our legal obligations (for example for financial records).

When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymise it, or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.

Visiting Our Office

For security purposes and emergency preparedness we may request personal information if you visit our office. This could include your name, business and vehicle details (if required). We use CCTV at our offices for security and the personal safety of our staff and visitors. Signage is in place to inform all visitors that we have CCTV. Any captured data is only accessible to limited members of staff within Crux and is stored for 30 days before being automatically deleted.

Applying For A Job

When you apply for a job with us, Crux will collect and process personal information about you.

4.1        Collection and Processing of Personal Information

The personal information we process, where provided, includes:

  • Your name, home address, email address and/or phone numbers
  • Your date of birth, marital status, nationality and National Insurance number
  • Your educational and employment history
  • Further information contained within your CV or other documents you submit to us
  • Information from the selection process
  • References and assessments relating to your work for previous employers
  • Information to confirm your identity and right to work, such as a copy of your passport
  • Any access or support requirements you may have in attending an interview
  • Details of any unspent criminal convictions
  • Information relating to your feedback on our organisation

Crux does not collect personal information relating to your ethnicity, gender, disability, religion, sexual orientation and other diversity-related information as part of our recruitment process.

4.2        Sources of Personal Information

We obtain personal information directly from you, as well as from third parties such as recruitment agencies, background checking companies or former employers where seeking a reference. We may also check any publicly available social media profiles (primarily LinkedIn), where this is relevant, as part of our recruitment process e.g. for checking employment history.

4.3        Purpose and Use of Personal Information

We process the personal information listed in Section 4.1 above for the following purposes only in accordance with our legitimate business interests and legal obligations as an employer:

  • To make recruitment decisions
  • To meet our accessibility and support requirements
  • To prevent and detect fraud and other wrongdoing
4.4        Disclosure of Personal Information

Your personal information will only be shared with Crux employees involved in the recruitment process.

This includes the People team, interviewers involved in the recruitment process and managers in the business area, including Operations and IT staff (including contractors), if access to the data is necessary for the performance of their roles.

We use other companies to provide us with telephony, email and other IT services. We have put agreements in place with these companies to ensure that they will only process your personal information as requested by us and in accordance with data protection law.

Crux will not share your data with third parties unless your application is successful, and it makes you an offer of employment. Crux may then share data with former employers to obtain references.

4.5        Retention of Personal Information

We will not keep your personal information for longer than is necessary. We will keep the personal information connected to your job application (including any interview records) for 6 months from the end of the recruitment process.

In some instances, we may ask for your consent to retain your data for a longer period if a suitable position is not immediately available. If your application is successful and you become a member of staff, we will provide you with a copy of the Employee Privacy Notice. The retention periods referred to therein will apply to your personal information during your employment.

Using Our Services

When using Crux for your project, we need to collect and process personal information about you to fulfil our contractual obligations to you as a client.

5.1        Collection and Processing of Personal Information

The personal information we process includes:

  • Your name
  • Your job title
  • Your company and department
  • Your business address
  • Your business email address
  • The phone numbers provided to us
5.2        Sources of Personal Information

We obtain this personal information directly from you or other members of your organisation. We may also acquire this personal information from your public profiles available online, primarily LinkedIn. Where this is the case, we will be transparent about our collection of your personal information.

5.3        Purpose and Use of Personal Information

We process the personal information listed in Section 5.1 above to fulfil our contractual obligations to you as a client in accordance with our legitimate business interests. This data is used by Crux to:

  • Provide you with quotations
  • Send and agree contractual information
  • Enable project communication
  • Send project deliverables
  • Provide service updates
5.4        Disclosure of Personal Information

Your personal information will only be shared within Crux, including Crux Directors, Heads of Function, project and senior team members, and Finance team members, if relevant, for invoicing purposes.

We use other companies to provide us with telephony, email and other IT services. We have put agreements in place with these companies to ensure that they will only process your personal information as requested by us and in accordance with data protection law.

5.5        Retention of Personal Information

Crux will retain your personal information for as long as is necessary to provide our services to you and for our own purpose in meeting legal and business obligations after completion of a project (including for the purpose of meeting any legal, accounting or other reporting requirements or obligations).

This means Crux may retain your personal information after the project ends for a minimum of 7 subsequent tax years.

Supplying To Us

We collect and process personal information about you when you are a Crux Product Design supplier.

6.1        Collection and Processing of Personal Information

The personal information we process includes:

  • Contact names and job titles
  • Your business address
  • Your business email addresses and phone numbers
  • Your organisations bank details
  • Data to allow us to qualify you as an approved supplier
6.2        Sources of Personal Information

We obtain this personal information directly from you or other members of your organisation. We may also acquire personal information from your public profiles available online, for example on your company’s website or Companies House.

6.3        Purpose and Use of Personal Information

We process the personal information listed in Section 6.1 above to fulfil our contractual obligations to you as a supplier in accordance with our legitimate business interests.

This data is used by Crux to:

  • Discuss requirements
  • Send and agree contractual information
  • Enable project communication
  • Process payments
  • Send you requests for quotations
  • Receive project and business deliverables
6.4        Disclosure of Personal Information

Your personal information will only be available to the relevant teams within Crux, for example Finance and Operations teams.

We use other companies to provide us with telephony, email and other IT services. We have put agreements in place with these companies to ensure that they will only process your personal information as requested by us and in accordance with data protection law.

6.5        Retention of Personal Information

Crux will retain your personal information for as long as our business relationship is active and for our own purpose in meeting legal and business obligations after completion of a project (including for the purpose of meeting any legal, accounting or other reporting requirements or obligations).

This means Crux may retain your personal information after the project ends for a minimum of 7 subsequent tax years.

Participating In Research

As part of our service offering Crux undertakes User Research. In order to recruit people to take part in studies we collect personal information to allow us to assess suitability of participants.

If you are selected to participate in a user study, you will be provided with a specific Privacy Notice relating to that study prior to taking part.

If you would like another copy of any Privacy Notices, or any other documentation provided, please request this via the contact details above.

7.1        Collection and Processing of Personal Information

The personal information we process includes:

  • Your name, age, identity and contact details
  • Your answers to any questions that you have been asked to assess whether you meet the eligibility criteria to take part in a study
  • Depending on the nature of the product, you may be asked to provide sensitive personal information about health and medical conditions
  • If you have responded to one of our own campaigns, through our website or any other online form, our servers will collect the IP address assigned to you or the person that provides you with internet access
7.2        Sources of Personal Information

We obtain personal information directly from you or from one of our recruitment partners in response to a recruitment campaign. Those recruitment campaigns may take place through social media platforms, such as Facebook. We do not use Facebook to collect personal information about potential participants in our research – an email link is provided within our adverts to register your interest.

7.3        Purpose and Use of Personal Information

We will only use your personal information:

  • To assess whether you are eligible to take part in a study
  • To contact you in relation with other studies that may be applicable
  • To make arrangements with you to take part in a study
  • If necessary, to defend any legal claims brought against us or our client in relation to the recruitment of participants to take part in a study

There are six lawful grounds for using your personal information and we need to satisfy one for each separate purpose we intend to use your personal information for.

For all of the purposes described above, we will rely on our legitimate interests. We have undertaken an assessment of our legitimate interests and how we balance those with your rights and freedoms.

Where we collect any sensitive personal information, such as information about health or medical conditions, we also have to satisfy one additional condition. The conditions that we will rely on will be:

  • If the product is a regulated medical device or the purpose of the study is to support a client’s application for regulatory approval for a medical device, ensuring high standards of quality and safety in relation to the use of such product
  • If the product is not a medical device, for scientific research purposes
7.4        Disclosure of Personal Information

We will keep your personal information separate from the information we hold about our general business activities. Access to your personal information will be limited to those who need access to it for the purposes described above, i.e., Crux employees who are either recruiting for or running the study you are participating in.

We use other companies to provide us with telephony, email and other IT services. We have put agreements in place with these companies to ensure that they will only process your personal information as requested by us and in accordance with data protection law.

In very rare circumstances, we may have to share your personal information with a court or other regulatory authority in response to an order or other legal request. Where we are allowed to do so, we will notify you of this.

7.5        Retention of Personal Information

If you have taken part in a research study your personal information and our results will be retained for 7 years from the date that we deliver our report to the client, unless stated otherwise in the study terms you agree to.

If you do not meet the eligibility criteria for a study, then we will delete your personal information unless you agree that we may keep your details on record for any future studies, which you may be eligible for. If such opportunities do not arise within 2 years, we will delete your personal information. For some potential participants with specific medical or heath conditions, we may retain your personal information for a longer period as studies in certain areas occur less frequently and it is important that we have enough participants for a study to be viable. Where this is the case, we will seek your consent prior to retaining your personal information for a longer period, in line with the above purpose.

Personal Information Security

Crux have put in place a number of measures to protect your personal information from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. These measures include:

  • Cyber security protocols
  • Requiring everyone who works with us to agree to legally binding confidentiality obligations
  • Using strong passwords and encryption for our users, servers and communications channels
  • Access to personal information is limited by specific roles
  • Ensuring that all staff are properly trained on how to handle your personal information as required by law
  • Adherence to policies and procedures to ensure we can deal with any security breaches involving your personal information quickly and effectively and respond to any requests by you to exercise your rights
  • Contractual arrangements with third party service providers

Storage Of Personal Information

The personal information that we collect from you is stored within the United Kingdom or European Economic Area (“EEA”). In some cases, we may transfer your personal information to countries outside the United Kingdom and European Economic Area. Where we do so we will ensure that you are made aware that such transfers are compliant with the Data Protection Act 2018 or UK General Data Protection Regulation and that appropriate measures are put in place to keep your personal information secure. The only exception to this is HubSpot (a CRM Platform).

Customer data is processed and secured in the EU before being transmitted and stored in the US to provide additional redundancy for critical components of our system. HubSpot act as our data processor for this purpose and are compliant with the EU-US Privacy Shield. We also have a written agreement in place with HubSpot in relation to the service they provide and how they must handle the data.

Further Information

You have several rights in relation to the personal information we hold about you, including the right to request a copy of your personal information (commonly known as a “subject access request”) and the right to have any inaccurate or incomplete personal information about you corrected. In certain circumstances, you have the right to request deletion of the personal information we hold about you, ask us to restrict how we use it or object to us holding it.

Please note that there are some limited circumstances and exemptions where these rights may not apply. For further information about your rights, visit the ICO’s website.

You also have the right to make a complaint to the ICO through their website about how we have used your personal information.

Contact Us

Should you have any queries regarding this privacy notice, Crux’s processing of your personal information or wish to exercise your rights you can contact Crux’s Privacy Team using this email address: privacy@cruxproductdesign.com.