Privacy Policy
E-Lucid Solutions Ltd | Last updated: 13 May 2026
For the purposes of the UK General Data Protection Regulation (“UK GDPR“), the Data Protection Act 2018 (“DPA 2018“) and the Privacy and Electronic Communications Regulations 2003 (“PECR“), E-Lucid Solutions Ltd (“E-LUCID“, “our“, “us“, “we“), with its registered office at Floor 3A, Maple House, 149 Tottenham Court Road, London, W1T 7NF, is the “Controller” of the Personal Data described in this Privacy Policy (“Policy“).
Protecting your privacy matters to us. This Policy explains what Personal Data we collect, how we use and manage it, the legal bases on which we rely, who we share it with, how long we keep it and the rights you have. Please read it carefully before providing us with any Personal Data or continuing to use our website at www.e-lucid.com (the “Website“).
Our Website may link to third-party sites. Those sites are not covered by this Policy. We recommend you review the privacy notice of each site you visit.
Defined terms are explained in the Glossary at the end of this Policy.
1. Whose Personal Data we collect
We collect Personal Data about a range of individuals in the context of our business, including:
- representatives of our customers, suppliers and other business contacts;
- consultants and contractors;
- visitors to and users of our Website;
- individuals who contact us by any means;
- job applicants.
2. How we collect your Personal Data
We collect Personal Data:
- Directly from you — when you visit our Website or complete one of our web forms, communicate with us, complete surveys, attend our events or visit our premises.
- Automatically from your device — using cookies and similar technologies as described in our Cookie Policy.
- From third parties — including your interactions with our social-media profiles on LinkedIn and X (formerly Twitter); other websites we operate; our group companies; recruitment agencies; and our sub-contractors and service providers.
3. What Personal Data we collect
The Personal Data we collect about you in a business context may include:
- identity and contact data (name, job title, employer, nationality, photographic identification, business email and address, telephone number);
- professional information (your role, areas of interest, communications with us, notes from meetings);
- financial and payment information held in connection with a contract;
- technical information collected automatically when you use the Website (IP address, browser type, operating system, language, time zone, access times, referring URLs).
Special category data. We may process Special Category Data (revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, health, genetic or biometric data, sexual orientation or sex life) and criminal-offence data only where (i) you have given us your explicit consent, (ii) we are required or permitted to do so under UK GDPR Article 9, the DPA 2018 or other applicable law, or (iii) it is necessary to establish, exercise or defend legal claims. An example is information you may voluntarily provide on an Equal Opportunities Classification Form.
3.1 Recruitment
If you apply for a role with us we will collect additional information, including qualifications, career history, third-party references and interview notes. We may, with your consent, collect data about your race, ethnicity, health or disability for equal-opportunities monitoring. Personal Data submitted in connection with a job application is processed in accordance with our Recruitment Notice (provided to applicants at the point of application).
4. Purposes and lawful bases for processing
The lawful bases on which we rely (UK GDPR Article 6) are:
- Contract — processing necessary for performing a contract with you or to take steps at your request before entering into a contract;
- Legitimate interests — pursuit of our legitimate interests, balanced against your rights and freedoms;
- Consent — where you have given clear, freely given, specific and informed consent;
- Legal obligation — where we are required to process the data to comply with a legal duty.
We may rely on more than one lawful basis depending on the specific purpose. The purposes for which we process Personal Data, and the lawful bases we rely on, are as follows:
- Providing the information, products and services you have ordered. Performance of a contract with you.
- Improving our products, services and the events we host. Legitimate interests — developing our products and services and growing our business.
- Administering, maintaining and improving the Website; carrying out analytics; notifying you of changes; ensuring network security. Legitimate interests — keeping the Website current, secure and useful, and understanding how customers use our services. Analytics cookies are set only with your consent (see our Cookie Policy).
- Embedding or playing third-party video content. Legitimate interests — informing customers about our business. Where third-party cookies are involved, your consent under PECR.
- Managing our internal recruitment processes. Steps taken at your request prior to entering into a contract of employment, and legitimate interests in managing and improving recruitment practices.
- Monitoring the implementation and impact of our equal-opportunities policy. Consent (UK GDPR Article 9(2)(a)), and legitimate interests in studying how individuals engage with us and informing our corporate-social-responsibility strategy.
- Direct marketing by email to existing or prospective business contacts. Consent (where required by PECR Regulation 22), or legitimate interests where the soft opt-in conditions of PECR are met or where the recipient is a corporate subscriber. You can opt out at any time.
- Complying with applicable law, regulation and lawful requests from public authorities. Compliance with a legal obligation.
- Negotiating, concluding and performing contracts; administering payments and accounts; corporate-social-responsibility activities; legal, regulatory and internal investigations; debt administration. Performance of a contract with you, legitimate interests in running our business, and compliance with a legal obligation.
5. Marketing
Where you have consented (or where the PECR soft opt-in or B2B corporate-subscriber rules apply), we may send you marketing communications by email about our products, services and events. You can opt out at any time by:
- clicking the “unsubscribe” link in any marketing email; or
- contacting us via our Contact Form.
Opting out of marketing will not affect service communications relating to a contract you have with us.
6. Automated decision-making and profiling
We do not make decisions about you that produce legal or similarly significant effects based solely on automated processing (including profiling). Should that change, we will update this Policy and, where required, obtain your consent or provide the additional information required under UK GDPR Article 22.
7. Who we share your Personal Data with
We share your Personal Data internally with personnel who have a need to know it for legitimate business or legal reasons (for example, processing an invoice or routing a query).
We may disclose your Personal Data outside E-Lucid to:
- public bodies, regulators, courts and law-enforcement authorities;
- our professional advisers (lawyers, auditors, insurers);
- suppliers of IT, hosting, payment-processing, security and analytics services who act as our processors;
- third parties engaged by us or with whom we otherwise have a business relationship, where necessary to (a) provide services you have requested, (b) enable you to view third-party video content, (c) protect intellectual property in materials available from the Website, (d) obtain legal or other professional advice, (e) respond to a legal request or comply with a legal obligation, (f) enforce our Rules of Website Use, and (g) where otherwise necessary for the purposes set out in this Policy;
- any prospective seller or buyer (and their advisers) in connection with a sale, merger or restructure of our business or assets.
We share Personal Data with our parent company, UCL Business Ltd (“UCLB”). UCLB is required to maintain the confidentiality of your data and is restricted from using it for purposes other than those set out in this Policy.
Where the Website permits user-generated content (comments, posts, testimonials), anything you submit may be visible to other users and the wider public. Please do not include Personal Data you do not wish to be public.
We may share aggregated or de-identified information (which cannot reasonably be linked to you) with third parties for analytics and business-development purposes.
8. International transfers
We may transfer Personal Data outside the United Kingdom, including to the European Economic Area and to other jurisdictions, to operate our business and provide our services. Where we do so:
- where the destination is covered by UK “adequacy regulations”, the transfer relies on that adequacy decision;
- otherwise, we put in place an appropriate safeguard required by UK GDPR Article 46 — typically the UK International Data Transfer Agreement (IDTA) or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, supplemented (where required) by a transfer-risk assessment.
You can request a copy of the safeguards we use by contacting us using the details in section 13.
9. Security
We take appropriate technical and organisational measures to protect Personal Data from accidental or unlawful destruction, accidental loss and unauthorised access, alteration, disclosure or misuse. These include access controls, encryption in transit and at rest, network segmentation, logging and regular security testing. Despite our efforts, no method of transmission over the internet is completely secure, and we cannot guarantee absolute security; any transmission of data to us is at your own risk.
Access to your Personal Data is limited to employees, contractors and other third parties who have a legitimate need to know. They process it only on our instructions and are subject to a duty of confidentiality.
Where you hold a password to access secure areas of the Website, you are responsible for keeping it confidential.
10. Cookies
Our Website uses cookies and similar technologies to make it work, to remember your preferences and (with your consent) to help us understand how visitors use the site. Full details — including the cookies set, their purpose and duration, and how to manage your preferences — are in our Cookie Policy.
11. Records retention
We retain your Personal Data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting, regulatory or reporting requirements. The criteria we apply to determine retention periods include:
- the duration of any contractual relationship with you or your organisation;
- statutory limitation periods relevant to potential legal claims (typically up to six years from the end of the relationship under English law);
- specific retention obligations imposed by law or regulation (for example, tax, accounting and anti-money-laundering rules);
- the sensitivity of the data and the risks of harm from unauthorised use or disclosure.
Where Personal Data is no longer needed, we securely delete or anonymise it.
12. Your rights
Under the UK GDPR and DPA 2018 you have the following rights in relation to your Personal Data:
- Access — to request a copy of the Personal Data we hold about you;
- Rectification — to ask us to correct inaccurate or incomplete data;
- Erasure — to ask us to delete your data in certain circumstances;
- Restriction — to ask us to restrict our processing in certain circumstances;
- Portability — to receive your Personal Data, where processed by automated means on the basis of consent or contract, in a structured, commonly used and machine-readable format;
- Objection — to object to processing based on our legitimate interests and to object at any time to direct marketing;
- Withdrawal of consent — where we rely on consent, to withdraw it at any time (this does not affect the lawfulness of processing before withdrawal);
- Rights relating to automated decision-making — see section 6;
- Complaint to a supervisory authority — to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk, the UK supervisory authority for data-protection matters. We would, however, appreciate the opportunity to address your concerns first.
To exercise any of your rights, please contact our Data Protection Representative using the details in section 13. You will not be charged a fee for most requests. We may ask you to verify your identity before responding.
Please keep us informed of changes to your Personal Data so that we can keep our records accurate.
13. Contact us
Data Protection Representative
E-Lucid Solutions Ltd
Floor 3A, Maple House
149 Tottenham Court Road
London, W1T 7NF
United Kingdom
14. Changes to this Policy
We may modify or amend this Policy from time to time. The current version is always available on our Website and the “Last updated” date is shown at the top. Where changes are material we will take reasonable steps to bring them to your attention (for example, by notice on the Website or by email if we hold a current email address for you).
Glossary
- Controller — the party that determines the purposes and means of processing Personal Data.
- Personal Data — any information relating to an identified or identifiable living individual, including names, contact details, IP addresses, online identifiers and other information capable of identifying an individual.
- Processing — any operation performed on Personal Data, including collecting, storing, accessing, combining, sharing or deleting it.
- Processor — a third party that processes Personal Data on our behalf and on our instructions.
- Special Category Data — categories of Personal Data given heightened protection under UK GDPR Article 9 (for example, health, racial or ethnic origin, sexual orientation).
- UK GDPR — the UK General Data Protection Regulation, being Regulation (EU) 2016/679 as retained in UK law.
- DPA 2018 — the UK Data Protection Act 2018.
- PECR — the Privacy and Electronic Communications (EC Directive) Regulations 2003 (as amended).
- ICO — the UK Information Commissioner’s Office, the UK supervisory authority for data protection.