Privacy Policy – Exelyxis Ltd

Privacy Policy – Exelyxis Ltd

Implementing the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 is a priority for Exelyxis Ltd.

Data Controller

  • Official Company Name: Exelyxis Ltd
  • Email: info@exelyxis.gr

Exelyxis Ltd considers personal data any information relating to an identified or identifiable living individual. This includes, for example, name, address, ID number, IP address, employment, health data, or other personal information.

Special categories of data, such as health, racial or ethnic origin, political or religious beliefs, and trade union membership, receive additional protection.

This policy applies to personal data collected, stored, or processed digitally or in hard copy through any structured filing system and is issued in accordance with UK GDPR and guidance from the Information Commissioner’s Office (ICO).


Terms and Definitions

  • Personal Data: Any information relating to an identified or identifiable individual (“data subject”).
  • Processing: Any operation performed on personal data, including collection, storage, use, disclosure, adaptation, retrieval, or erasure.
  • Restriction of Processing: Marking stored personal data to limit future processing.
  • Filing System: Any structured set of personal data accessible according to specific criteria.
  • Controller: The entity determining the purposes and means of processing personal data.
  • Processor: Any person or entity processing personal data on behalf of the controller.
  • Recipient: Any person or entity receiving personal data.
  • Third Party: Any person or entity other than the data subject, controller, or processor.
  • Consent: Freely given, specific, informed, and unambiguous agreement to process personal data.
  • Personal Data Breach: Accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of personal data.
  • Special Categories of Data: Sensitive personal data such as health, racial or ethnic origin, political, religious or philosophical beliefs, trade union membership, genetic or biometric data, or sexual orientation.

Categories of Personal Data Collected

Data SubjectCategories of Data
Clients
  • Identity and demographics
  • Contact information (address, phone, email)
  • Business information
  • Contracts and account balances
  • Bank account information
  • CCTV data on premises
  • Other relevant information
Suppliers / Contractors
  • Identity and demographics
  • Contact and business information
  • Contracts and account balances
  • Bank account information
  • CCTV data on premises
  • Other relevant information
Employees / Candidates
  • Identity and demographics
  • Contact details
  • CVs and employment records
  • Health and insurance data
  • Financial and marital information
  • CCTV data on premises
Other IndividualsVisitors or collaborators interacting with the company

Purposes and Legal Basis of Processing

PurposeLegal Basis
Employment or cooperationContract performance, legal obligation, legitimate interests (UK GDPR Articles 6(1)(b), 6(1)(c), 6(1)(f))
Provision of products/servicesContract performance, legal obligation, legitimate interests
Commercial agreements / company interestsLegitimate interests
Legal and regulatory complianceCompliance with legal obligations
Video surveillanceProtection of people and property

Data Sharing

Personal data may be shared with third parties only when required to fulfil legal obligations or perform services. Service providers receive only the data necessary and are bound by confidentiality and secure processing requirements. Transfers outside the UK comply with UK GDPR adequacy or Standard Contractual Clauses.


Data Retention

Personal data are retained for as long as necessary for processing purposes, legal obligations, contractual duties, or potential claims.


Rights of Data Subjects

  • Be informed about processing
  • Access personal data
  • Request correction of inaccurate/incomplete data
  • Request erasure where data is no longer necessary or processing is unlawful
  • Object to processing based on legitimate interests
  • Request restriction of processing
  • Request data portability
  • Withdraw consent if processing is based on consent
  • Lodge a complaint with the ICO or relevant supervisory authority

Requests can be submitted in writing or via dpo@exelyxis.com.


Processing Principles

  • Processed lawfully, fairly, and transparently
  • Collected for explicit, legitimate purposes only
  • Adequate, relevant, and limited to necessity
  • Accurate and up to date
  • Retained only as long as necessary
  • Secured with appropriate technical and organizational measures

Records of Processing Activities

Exelyxis Ltd maintains records including:

  • Controller and DPO contact details
  • Purposes of processing
  • Categories of data subjects and personal data
  • Recipients, including transfers outside the UK
  • Retention periods and security measures

Protection of Personal Data

Exelyxis Ltd implements technical and organizational measures to ensure GDPR-compliant processing and prevent unauthorized access, loss, or breaches. Staff are trained in data protection.


Social Media

Exelyxis Ltd maintains accounts on Facebook, Instagram, LinkedIn, TikTok, and YouTube. The company is not responsible for data collected by these platforms. Users should consult the privacy policies of each platform.


Changes to this Privacy Policy

This policy may be updated to reflect changes in processing practices. Updated versions will be made publicly available.

AuBonBroth_Logo-Long_gold png

© Copyright 2025 Exelyxis Ltd™. All Rights Reserved.
5 South Charlotte Street,
Edinburgh, Scotland, EH2 4AN