How information is handled
The operational context
This notice covers enquiries to Vertex about automotive workflow software and visits to its corporate pages. The company identified below is the controller for those activities. A description of a service workflow is usually sufficient at the enquiry stage; driver details, vehicle-linked personal records and customer databases should stay out of introductory correspondence.
Connection and enquiry information
Cloudflare serves the website and receives connection data such as an IP address, requested resource and browser information. This helps deliver pages and assess security threats. If you contact Vertex, your contact information and the explanation you provide are used to understand and handle that request.
Purposes and lawful bases
Website delivery, service security and relevant business correspondence are pursued as legitimate interests under Article 6(1)(f), balanced against individual rights. A request for steps towards a contract may fall under Article 6(1)(b). Legal record-keeping duties provide a separate basis where Article 6(1)(c) applies. Information is not repurposed merely because it is technically available.
Project boundaries
An automotive software engagement may involve different categories of information from a corporate enquiry. Where Vertex is a processor, customer instructions and a written processing arrangement must govern the project data. The arrangement should identify access, providers, safeguards and how information is returned or removed.
Retention and international transfers
Retention is assessed against the enquiry’s purpose, the resulting business relationship and any record-keeping or dispute requirement. Records without a continuing justification should be removed or anonymised. Global hosting may involve international transfers; adequacy provisions or approved contractual safeguards must support transfers that require them.
Requests and incidents
You may seek access, correction, restriction or deletion of data by writing to Vertex at the registered office. Objection and portability rights apply in relevant circumstances. Describe the correspondence involved; proportionate identity confirmation may be needed. The usual response period is one month. A personal data breach is assessed and notified to the ICO and affected people where the applicable risk thresholds are met, including the 72-hour regulatory deadline. Concerns can also be raised with the ICO. These pages address business users, rather than children.