Skip to main content

Privacy policy

Last updated

InfraLayer Ltd ("InfraLayer", "we", "us") is the controller of the personal data described in this policy. We are a company registered in England and Wales, company number 17345513, with our registered office at 20 Wenlock Road, London N1 7GU. Our operating location is Cape Town, South Africa.

This policy explains what we collect, why, how long we keep it, and the rights you have. It covers both the UK General Data Protection Regulation together with the Data Protection Act 2018, and the Protection of Personal Information Act 2013 of South Africa (POPIA), because InfraLayer is a UK company whose operations are in South Africa.

Contact for any privacy question or request: hello@infra-layer.com, or by post to InfraLayer Ltd at the registered office above.

Our Information Officer for the purposes of POPIA is John Huskinson, who can be reached at the same address.

What we collect

When you use the enquiry form. Your name, your work email address, your company name, and whatever you choose to write in the message and in the fields describing the roles and the function you are considering. These fields are the ones on the form itself and nothing more. We do not ask for special category data and you should not send any.

When you email us. The content of your message and anything in it, together with your email address and any signature block.

When you visit the site. Our hosting provider records standard server information including IP address, the pages requested, timestamps, and the browser and device reported by your software. This is created by the act of requesting a page and cannot be avoided while still serving the site.

Spam prevention. We use Cloudflare Turnstile on the enquiry form. It performs a check in your browser to distinguish a person from an automated submission. Turnstile is designed to do this without profiling you across sites and without advertising cookies.

Website statistics. We use Plausible Analytics to count how many people read which pages. It is chosen because of what it does not do. It sets no cookies, it stores no IP addresses, and it builds no profile of you. To tell one visit from another within a day it creates a one way hash of your IP address and browser, using a secret that is discarded and replaced every 24 hours, so the same visitor cannot be recognised the following day and cannot be recognised on any other website. The data we see is counts: pages, referring sites, country, and device type. Plausible processes it in the European Union.

We do not use advertising cookies, we do not track you across other websites, and we do not buy or enrich contact data.

Why we use it, and our lawful basis

Enquiry form and email. To answer you and to discuss whether we can help. Under UK GDPR this is Article 6(1)(b), steps taken at your request before a contract, together with Article 6(1)(f), our legitimate interests in responding to business enquiries. Under POPIA it is section 11(1)(b) and section 11(1)(f).

Server logs. To keep the site available, and to investigate faults and abuse. Article 6(1)(f) legitimate interests in security and reliability, and POPIA section 11(1)(f).

Spam prevention. To stop automated abuse of the form. Article 6(1)(f) legitimate interests in protecting our systems, and POPIA section 11(1)(f).

Website statistics. To understand which pages are read and improve them. Article 6(1)(f) legitimate interests in understanding how our own site is used, and POPIA section 11(1)(f). No cookie is set and no profile is built, so no consent is required for it.

Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and we have concluded it is not, because the data is business contact data you have chosen to send us for a purpose you initiated, or aggregate counts that do not identify you. You can object at any time and we will stop unless we have compelling grounds to continue.

We do not use your enquiry to send marketing. If that ever changes we will ask for your consent first, separately, and you will be able to withdraw it as easily as you gave it.

Who else handles it

We use a small number of service providers, each processing on our instructions under a written agreement:

Vercel. Hosts and serves the website. United States, with UK and EU regions.

Resend. Delivers the enquiry form email to us. United States.

Microsoft. Our email is Microsoft 365, so an enquiry you send arrives in a mailbox Microsoft operates, and stays there as long as any email does. United Kingdom and European Union.

Sanity. Stores the site's content. Enquiry data never reaches it. European Union.

Cloudflare. Turnstile spam prevention on the form. Global network.

Plausible. Website statistics, as described above. European Union.

We share personal data with our South African employer of record partner only where it is necessary to deliver a service you have engaged us for. Nothing you send through this website reaches them at the enquiry stage. We do not sell personal data and we do not share it for anyone else's marketing.

Sending data between the UK, the EU and South Africa

Our providers are in the United States and the European Union, and our operations are in South Africa, so personal data moves across borders.

For transfers out of the United Kingdom we rely on the UK International Data Transfer Addendum to the European Commission's standard contractual clauses, or on the UK Extension to the EU-US Data Privacy Framework where a provider is certified under it. For transfers of personal information out of South Africa we rely on section 72 of POPIA, on the basis that the recipient is subject to binding agreements providing an adequate level of protection.

You can ask us for details of the safeguards that apply to a particular transfer.

How long we keep it

Enquiries that do not become a client relationship. 24 months from your last contact with us, then deleted.

Enquiries that become a client relationship. For the life of the relationship and 6 years after it ends, which is the ordinary limitation period for contract claims in England and Wales.

Server logs. As retained by our hosting provider in the ordinary course, and not used by us beyond security and fault investigation.

Website statistics. Aggregate counts only, with nothing in them that identifies you.

Your rights

Under UK GDPR you have the right to be informed, to access a copy of your data, to have inaccurate data corrected, to have data erased, to restrict processing, to data portability, and to object to processing based on legitimate interests. You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make any such decisions.

Under POPIA you have the right to be notified that your information is being collected, to request access to it, to request correction or deletion of information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained, to object to processing, and to complain to the Information Regulator.

To exercise any of these, email hello@infra-layer.com. We will respond within one month under UK GDPR, and within the period POPIA prescribes for a request made on Form 2. We do not charge a fee unless a request is manifestly unfounded or excessive.

Complaints

If you are not satisfied with how we have handled your data, you can complain to a regulator. In the United Kingdom this is the Information Commissioner's Office, at ico.org.uk. In South Africa it is the Information Regulator, at inforegulator.org.za. We would rather you came to us first so that we have a chance to put it right.

Cookies

We use only cookies that are strictly necessary for the site to function and for spam prevention on the enquiry form. Our website statistics are collected without cookies, and we use no advertising or profiling cookies at all. That is why you are not asked to accept anything when you arrive: there is nothing to consent to.

Security

The site is served over HTTPS. Enquiry data is validated and spam checked on our server rather than in your browser, and the credentials that send our email are held server side and are never exposed to it. Access to enquiry data is limited to the people at InfraLayer who need it to respond to you.

No system is perfectly secure, and we do not claim otherwise. If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the Information Commissioner's Office within 72 hours where required, notify the Information Regulator where POPIA applies, and tell you directly where the risk is high.

Changes

If we change this policy we will update the date at the top. Where a change materially affects how we use data you have already given us, we will tell you directly.