Skip to main content
Home > Privacy & Cookie Policy

Version 2.2 | Last updated: 11th August 2026

1. About this notice

This notice explains how Intercede Group plc (“Intercede”, “we”, “us” or “our”) collects and uses personal data when you visit www.intercede.com and related sub-domains, including any customer portals or forums that link to this notice (the “Website”), contact us, subscribe to our newsletters or events, use our customer portal or forums, or purchase or enquire about our products and services.

Intercede Group plc is the controller of personal data for the purposes of the UK General Data Protection Regulation (UK GDPR). We are the controller of all personal data collected through the Website and related business interactions, except where another Intercede group company or customer is identified as controller in a separate notice, contract or data-processing agreement.

Where a Website function, customer portal, forum, support service or product-related interaction is provided by another Intercede group company, that group company may also act as controller or processor depending on the circumstances.

If you have any questions about this policy or wish to raise a complaint, please contact us. Our contact details are:

  • Registered office: Lutterworth Hall, St Mary’s Road, Lutterworth, Leicestershire LE17 4PS, United Kingdom.
  • Companies House number: 04101977.
  • Privacy contact: privacy@intercede.com.

We are not required to appoint a statutory Data Protection Officer under Article 37 UK GDPR. Data protection queries should be sent to privacy@intercede.com. Internal responsibility for privacy compliance is allocated under our governance arrangements.

2. Legal framework

We process personal data in accordance with applicable UK data protection and privacy laws, including the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (PECR), as amended, and the Data (Use and Access) Act 2025 (DUAA), where applicable.

Personal data means any information about an individual from which a person can be identified.

3. Personal data we collect and why

The table below summarises the main categories of personal data we may process in connection with the Website and related business interactions. We may process additional or different information where we have a legal basis to do so. Additional information may be necessary for a specific interaction, contract, legal obligation, security matter or customer-support request.

Category of data Where we get it Purpose of use Lawful basis Retention
Contact details such as name, business email, job title, employer and phone number You, via enquiry, newsletter, event or resource-download forms Respond to enquiries, send requested materials, perform the contract, and manage B2B relationships Legitimate interests, consent where required, or contract where you have requested a service 24 months after last interaction, unless a longer period is required
Marketing preferences and consent records You, via opt-in tick-box, preference centre or unsubscribe link Send product updates, event invitations and industry news, and maintain suppression records Consent or soft opt-in under PECR where available (legitimate interests) Until withdrawn, plus limited suppression records
Customer portal login details and support tickets You and your organisation, via customer portal registration and support requests Provide customer support, account administration and contract management Contract, legitimate interests and legal obligation where applicable Duration of contract plus 6 years, unless a longer period is required
Forum posts and user-generated content on forums.www.intercede.com You, when you post or interact with forum content Operate, moderate and secure the customer forum Legitimate interests Duration of account plus 12 months, unless required for security, dispute or legal reasons
Website usage data, including IP address, browser, pages viewed and referrer Automatically, through cookies, similar technologies and server logs Security, troubleshooting, fraud prevention, service improvement, Website administration and analytics subject to cookie choices Legitimate interests for security and essential operation, consent for non-essential cookies unless exempt and legal obligation where applicable Analytics up to 26 months; security logs generally up to 12 months
Communication data, including any Website enquiries or other correspondence when you contact us You To manage our relationship with you and respond to enquiries Legitimate interests Kept indefinitely
Applicant CVs and recruitment data You, recruitment agencies or referees Manage recruitment, assess suitability and comply with employment-related obligations Legitimate interests, legal obligation and consent where applicable 12 months after application unless a longer retention period is agreed or required

Fields marked as required on our forms must be provided for us to respond or provide the relevant service. Other fields are optional. If you do not provide certain required information, we may not be able to perform the contract entered into with you.

We do not intentionally collect special category data through the Website unless you choose to provide it or it is necessary for a specific legal, recruitment, accessibility or support-related purpose.

4. Our legitimate interests

Where we rely on legitimate interests, we do so only where we have assessed that our interests are not overridden by your rights, freedoms and interests.

Our legitimate interests may include responding to business enquiries, administering customer and supplier relationships, providing customer support, operating and securing the Website, preventing fraud and misuse, maintaining audit and compliance records, sending limited B2B marketing where permitted by law, carrying out intra-group administration, supporting corporate transactions, and establishing, exercising or defending legal claims.

In addition, in some cases the law says, we may rely on “recognised legitimate interests” lawful basis under Article 6(1)(ea) UK GDPR (as inserted by the DUAA). This includes specified purposes such as safeguarding, crime prevention, and disclosures to competent public authorities.

You have the right to object to processing based on legitimate interests, as described in section 8.

5. Who we share personal data with

We will only share your personal data where it is permitted by data protection law. We require all our third-party service providers to protect your personal data and only use it in accordance with data protection law.

We may share personal data with the following categories of recipients where necessary for the purposes described in this notice.

Recipient category Purpose Location / safeguards
Microsoft and cloud-hosting providers Corporate email, storage, hosting, authentication and security UK, EEA and other locations subject to appropriate safeguards
CRM, marketing automation and email-service providers Customer relationship management, marketing communications and preference management UK, EEA and/or US subject to appropriate safeguards
Website analytics and consent-management providers Analytics, cookie preference management and website performance UK, EEA and/or US subject to appropriate safeguards
Forum, customer portal and support providers Operate customer forum, customer portal and support services UK, EEA and/or other locations subject to appropriate safeguards
Professional advisers Legal, audit, tax, accounting and other professional advice UK and EEA
Regulators, law enforcement, courts and public authorities Compliance with legal obligations, regulatory requests and dispute resolution UK, EEA, US or other relevant jurisdictions
Prospective or actual purchasers, investors or advisers in a corporate transaction Due diligence, transaction planning, restructuring or transfer of business/assets UK, EEA and/or other locations subject to appropriate safeguards

We do not sell personal data to third parties for their own marketing purposes.

6. International data transfers

Some recipients may be located outside the UK or EEA. Where we make a restricted transfer of personal data outside the UK, we use an appropriate transfer mechanism where required, such as UK adequacy regulations, the UK-US Data Bridge where the recipient is appropriately certified for the relevant processing, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, binding corporate rules or another safeguard or exception permitted by UK GDPR.

We rely on the UK-US Data Bridge (the UK Extension to the EU-US Data Privacy Framework) only where the recipient US organisation holds an active DPF certification covering the categories of data being transferred.

Where required, we assess whether the transfer mechanism provides appropriate protection for the personal data being transferred, including by carrying out a transfer risk assessment.

You can request information about the relevant safeguard by contacting privacy@intercede.com. We may redact or withhold information where necessary to protect confidentiality, security, commercial interests or legal privilege.

7. How long we keep personal data

We keep personal data for as long as reasonably necessary for the purposes described in this notice, using retention periods and criteria set by our internal retention arrangements.

The retention periods in this notice describe our normal practice and may vary depending on the context. We may retain personal data for longer where necessary to establish, exercise or defend legal claims; comply with legal, tax, accounting, audit or regulatory obligations; resolve disputes; investigate security incidents; maintain business-continuity or backup records; enforce contracts or policies; or maintain suppression records for marketing opt-outs.

Where we no longer need personal data, we delete, anonymise or restrict access to it in accordance with our retention processes, unless continued retention is permitted or required by law.

8. Your rights

Under the UK GDPR, you may have the right to be informed about how we use your data, access your personal data, have inaccurate data rectified, request erasure in certain circumstances, restrict processing, object to processing based on legitimate interests or for direct marketing, receive your data in a portable format, withdraw consent where consent is our lawful basis, and not be subject to solely automated decision-making with legal or similarly significant effects.

These rights are subject to conditions, limitations and exemptions under applicable law. We do not carry out solely automated decision-making with legal or similarly significant effects on Website visitors.

To exercise your rights, email privacy@intercede.com. We will respond within one calendar month unless the law permits an extension. We do not usually charge a fee, but we may charge a reasonable fee or refuse to act where permitted by law, for example if a request is manifestly unfounded or excessive. We may need to verify your identity before responding. We may also contact you for further information, where necessary, to assist us in providing a response.

9. How to complain

You have the right to complain to Intercede about how we process your personal data (section 164A of the Data Protection Act 2018).

How to complain. You can complain by:

  • emailing privacy@intercede.com;
  • writing to the Privacy Lead, Intercede Group plc, Lutterworth Hall, St Mary’s Road, Lutterworth, Leicestershire LE17 4PS.

What we will do.

  • We will acknowledge your complaint within 30 days of receipt.
  • We will take appropriate steps to investigate without undue delay and keep you informed.
  • We will provide our substantive response and outcome within three months, or explain any delay.
  • We will tell you about your right to escalate to the Information Commissioner (or, following the DUAA transition, the Information Commission).

Escalation to the ICO. If you remain unhappy, you have the right to complain to the Information Commissioner’s Office: Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF; helpline 0303 123 1113; website ico.org.uk. The ICO may ask you to raise your complaint with us first.

10. Cookies and similar technologies

10.1 What we use them for

Cookies are text files containing letters and numbers which are stored on your browser or computer. We use cookies to distinguish you from other Website users. They help us improve our Website and provide a better browsing experience.

We use cookies and similar technologies (pixels, local storage, tags, scripts and comparable tools) for: (i) strictly necessary purposes (for the operation of the Website such as session management, load balancing, security, authentication, remembering cookie choices); (ii) statistical / first-party analytics purposes, to understand aggregate use of the Website and improve it; (iii) functional / appearance purposes (to recognise you, accessibility, display preferences, language); (iv) security purposes; and (v) marketing / advertising purposes, including retargeting and campaign measurement (where used).

10.2 Consent and controls (post-DUAA PECR)

Following amendments to the PECR made by the DUAA and in force from 5 February 2026, cookies in categories (i) to (iv) above may be placed without prior consent, provided we give you clear information and a straightforward means to opt out. For category (v) marketing/advertising cookies, we will continue to obtain your consent before placing them.

You can accept, reject or manage cookies at any time using the Cookie Preferences link on the Website.

10.3 Cookie list and reviews

We maintain information about the cookies and similar technologies used on the Website, including their provider, purpose, category and expiry where applicable. The current cookie list is made available through our consent-management platform or cookie preference tool and is reviewed periodically and when Website technologies materially change.

Please note that third parties may also use cookies. We do not have control over third-party cookies. Please refer to the relevant privacy and cookie information provided by third parties for further details on how cookies are used on their websites. We are not responsible for the privacy or cookie practices of those third party websites.

11. Marketing communications

Where you have opted in, or where you are an existing customer or business contact receiving communications about similar products and services under PECR or other applicable rules, we may send you marketing emails about our products, events and industry news.

Every marketing email includes an unsubscribe link. You can also email privacy@intercede.com at any time to stop marketing communications. We may retain limited suppression information to ensure that we respect your marketing preferences.

12. Security

We maintain a risk-based information security programme designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure.

Measures may include access controls, encryption, logging and monitoring, vulnerability management, supplier controls, staff training, incident-response procedures, role-based access and other technical and organisational measures appropriate to the nature of the data and processing risks.

No system can be guaranteed to be completely secure. We have put in place procedures to deal with a personal data breach. Where a personal data breach is notifiable under applicable law, we will notify the ICO and/or affected individuals in accordance with the relevant legal requirements, including the 72-hour notification timeframe where required and feasible.

13. Children

The Website is not directed to children under 13 and we do not knowingly collect personal data from children through the Website. If you believe a child has provided personal data to us through the Website, please contact privacy@intercede.com.

If you provide services to children on Intercede’s behalf, or ask Intercede to process personal data relating to children, the relevant customer agreement and data-processing terms will apply and appropriate safeguards should be assessed before processing begins.

14. MyID processing on behalf of customers

This notice applies to personal data processed by Intercede as controller in connection with the Website and related business interactions.

It does not govern personal data processed within MyID deployments on behalf of customers, where the customer is usually the controller and Intercede acts as processor or sub-processor under the applicable customer agreement and Data Processing Agreement.

Customer agreements, product terms, support terms and data-processing agreements prevail over this notice for customer-controlled deployments, support activities and services to the extent they apply to that processing.

15. Changes to this notice

We may update this notice from time to time as our processing activities, Website technologies, legal requirements or regulatory guidance change.

Material changes may be highlighted at the top of the relevant page for an appropriate period. The latest version of this notice will be published on the Website.

This version was last updated on 11th August 2026.