Our privacy policy

Who we are and scope

Graph Aware Limited, a UK-based international software company with entities in the EU (Italy and the Czech Republic) and Australia, acts as the controller for personal data processed through our website, client services, recruitment activities, events, and related operations.

This policy complies with UK GDPR and EU GDPR, covers customers, prospects, website users, job applicants, and candidates (not intended for children), and explains how personal data is collected, used, shared, protected, transferred, and what rights individuals have under applicable data protection laws; where relevant, specific controllers are identified at the point of collection.

Our compliance team oversees data protection matters and can be contacted at gdpr@graphaware.com for all privacy-related queries, including requests to exercise data subject rights or obtain further information about this notice.

Personal data we collect

We may collect the following categories of personal data, depending on how you interact with us:

  • Identity: name, username, title, date of birth, gender, pronouns.
  • Contact: corporate/personal email address, phone number, postal address, company/employer details.
  • Financial/transaction: payment details, invoicing information, transaction history in relation to our products and services.
  • Technical: IP address, browser type and version, operating system, device identifiers, cookie identifiers, time zone, approximate location, and other information from server logs.
  • Profile/usage: interests, interaction history with our website, services, and communications, feedback, employment details, job title, project information, education history, references, and communication preferences.
  • Marketing data: marketing preferences, subscription and unsubscribe information, engagement metrics, and campaign interaction data.
  • Special categories and criminal data (recruitment/compliance only): information relating to criminal convictions, security clearances, right-to-work documentation, and related vetting information where required by law or our legitimate interests in protecting our business (e.g., fraud and IP protection), subject to appropriate safeguards and data minimisation.

We also generate aggregated or anonymised statistics for analytics and reporting, which do not identify individuals; such data is not treated as personal data where irreversibly anonymised. No special category data is intentionally collected for general marketing purposes.

How we collect data

We collect personal data from a range of sources:

Directly from you:

Forms on our website or landing pages (including mandatory marketing consent checkboxes where required), emails and correspondence, business cards, event badge scans or attendee lists when you register for or attend our events, job applications (including CVs, cover letters, references), account registrations, support tickets, meetings, interviews, and calls (which may be recorded for training, quality, or evidential purposes).

Automatically:

Cookies and similar technologies, server and application logs, usage data from our website and online services, and tracking pixels within emails or web pages that help measure engagement and performance.

Third parties:

Advertising and analytics providers (such as Google, LinkedIn, Microsoft Advertising and Reddit Advertising) for clicks, conversions, and campaign performance; partners; event badge scans or attendee lists when you register for or attend an event we have organised or participated in, public and professional sources (including prior employers and online professional profiles); regulators and public authorities where legally permitted or required; recruitment vendors and background-check providers (such as DBS and Access NI checks); processors used for HR, timesheets, CRM and marketing (including BambooHR, Harvest, HubSpot); and reputable marketing lists or data aggregators, always in line with applicable law and contractual assurances.

In many cases, data from these sources is synchronised into HubSpot or other systems we use for centralised management and analysis.

Cookies

Cookies and similar technologies are used to support site functionality, analytics, marketing, and security.

These technologies allow us to recognise your browser or device, understand how our services are used, improve the user experience, and measure the effectiveness of our communications. Cookie use is managed via a Cookiebot banner that enables granular consent by category.

Cookie categories

Category Purpose Examples/vendors Typical duration
Strictly necessary Security, load balancing, login, form submissions, captcha validation, and core performance Cloudflare, Google reCAPTCHA, HubSpot Session to 1 year
Statistics/performance Usage analytics, service improvement, performance measurement HubSpot tracking cookies, Google Analytics Up to 14 months
Marketing Measuring advertising effectiveness, lead scoring and profiling HubSpot, Google Ads, Microsoft Ads Until opt-out plus 30 days
Functional/preferences Remembering consent settings, preferences Cookiebot Up to 12 months

Purposes, legal basis, and retention

Purpose Data types Legal basis (UK/EU GDPR) Legitimate interests (where applicable) Retention period
Provide and improve products and services Identity, contact, financial Contract; Consent; Legal obligation Ensuring service quality 6 years (tax/legal)
Recruitment Identity, contact, CV Contract; Legal obligation; Consent Conducting fair recruitment Up to 6 months
Operate accounts Identity, contact, financial Contract; Legal obligation Maintaining accurate records 6 years
Marketing, newsletters, and updates Identity, contact Consent; Legitimate interests Business growth Until opt-out plus 30 days
Crime prevention, security Identity, technical Legitimate interests; Legal obligation Ensuring network and information security Up to 14 months
Research, product development Identity, contact, usage Consent; Legitimate interests Developing and improving products Typically 12 months

Sharing your data

We share personal data only as necessary for the purposes described above, subject to appropriate contractual and security safeguards.

International transfers

Because GraphAware operates internationally, personal data may be transferred and accessed across borders.

Transfers within the EEA/UK:

Transfers under UK adequacy regulations.

Transfers to other countries:

Appropriate safeguards under UK GDPR and EU GDPR Chapter V are relied upon.

Data security

We take the security of personal data seriously and implement appropriate measures designed to protect it against unauthorised access or loss.

Your rights

Data subjects have the following rights under UK GDPR and EU GDPR:

  • Right of access (SAR): Confirm whether we process your data and access a copy.
  • Rectification, erasure, restriction, portability: Correct inaccurate data, delete or restrict personal data.
  • Right to object: Object to processing based on legitimate interests, profiling, or direct marketing.
  • Right to withdraw consent: Withdraw consent at any time.

Complaints and changes

If you have concerns about data handling, contact our compliance team at gdpr@graphaware.com. You also have the right to lodge a complaint with your local supervisory authority.