Privacy Policy
Last updated: 10 April 2026
1. Introduction
SpectrumX Direct Limited(“SpectrumX”, “we”, “us” or “our”) is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store and protect your personal data when you visit our website at www.spectrumx.com or interact with our business.
This policy is provided in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR). Please read this policy carefully to understand our practices regarding your personal data.
2. Data Controller
The data controller responsible for your personal data is:
SpectrumX Direct LimitedParkgate Industrial Estate
Knutsford, Cheshire
United Kingdom
If you have any questions about this Privacy Policy or our data protection practices, please contact us using the details on our Contact Us page.
3. Personal Data We Collect
We may collect and process the following categories of personal data:
3.1 Information You Provide to Us
- Contact information: Your name, email address, telephone number and company name when you submit a contact form, send us an email or make a telephone enquiry.
- Business enquiry details: Information about your manufacturing requirements, project specifications or other business needs that you share with us.
- Correspondence: Records of any correspondence between you and SpectrumX, including emails, letters and notes of telephone conversations.
3.2 Information Collected Automatically
- Technical data: Your IP address, browser type and version, operating system, time zone setting, referring URL and other technical information collected through cookies and similar technologies.
- Usage data: Information about how you use our website, including pages visited, time spent on pages, navigation paths and interaction data, collected through Google Analytics 4 (GA4).
For more information about cookies and analytics, please see our Cookie Policy.
4. Lawful Bases for Processing
We process your personal data on the following lawful bases under the UK GDPR:
- Consent (Article 6(1)(a)): Where you have given clear consent for us to process your personal data for a specific purpose, such as receiving marketing communications or the use of non-essential cookies.
- Contract (Article 6(1)(b)): Where processing is necessary for the performance of a contract with you or to take steps at your request prior to entering into a contract, such as responding to a manufacturing enquiry.
- Legitimate interests (Article 6(1)(f)): Where processing is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. This includes website analytics to improve our services, responding to general enquiries and maintaining business records.
- Legal obligation (Article 6(1)(c)): Where processing is necessary to comply with a legal obligation, such as maintaining records required by pharmaceutical regulations or responding to regulatory requests.
5. How We Use Your Personal Data
We use your personal data for the following purposes:
- To respond to your enquiries and provide information about our services, products and capabilities.
- To process and manage manufacturing contracts and business relationships.
- To administer and improve our website, including analysing usage patterns to enhance user experience.
- To comply with legal and regulatory obligations applicable to pharmaceutical manufacturing and distribution.
- To protect our legitimate business interests, including maintaining records and managing business risks.
6. Data Sharing and Transfers
We do not sell, rent or trade your personal data to third parties. We may share your personal data with:
- Service providers: Third-party providers who assist us with website hosting, analytics (Google Analytics 4), email services and IT support. These providers process data on our behalf under appropriate data processing agreements.
- Professional advisers: Our legal, accounting and other professional advisers where necessary for the management of our business.
- Regulatory bodies: The MHRA and other regulatory authorities where required by law or regulation.
Where personal data is transferred outside the United Kingdom, we ensure that appropriate safeguards are in place in accordance with the UK GDPR, such as Standard Contractual Clauses or an adequacy decision by the Secretary of State.
7. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Our retention periods are:
- Contact form submissions: Retained for two years from the date of submission, unless a business relationship is established, in which case retention periods applicable to business records apply.
- Business and contract records: Retained for the duration of the business relationship and for a period of six years thereafter, in accordance with statutory limitation periods and regulatory requirements.
- Website analytics data: Retained in accordance with our Google Analytics 4 configuration, which anonymises data after 14 months.
8. Your Rights
Under the UK GDPR and Data Protection Act 2018, you have the following rights in relation to your personal data:
- Right of access: The right to request a copy of the personal data we hold about you.
- Right to rectification: The right to request correction of inaccurate or incomplete personal data.
- Right to erasure: The right to request deletion of your personal data in certain circumstances.
- Right to restriction of processing: The right to request that we restrict the processing of your personal data in certain circumstances.
- Right to data portability: The right to receive your personal data in a structured, commonly used and machine-readable format.
- Right to object: The right to object to processing based on legitimate interests or for direct marketing purposes.
- Rights related to automated decision-making: The right not to be subject to a decision based solely on automated processing, including profiling.
To exercise any of these rights, please contact us using the details on our Contact Us page. We will respond to your request within one month, as required by the UK GDPR. If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure or destruction. These measures include encrypted data transmission (SSL/TLS), access controls, regular security assessments and staff training on data protection. While no method of transmission over the internet is completely secure, we take all reasonable steps to protect the personal data entrusted to us.
10. Children’s Privacy
Our website and services are directed at businesses and professionals. We do not knowingly collect personal data from children under the age of 16. If we become aware that we have collected personal data from a child under 16 without appropriate parental consent, we will take steps to delete that information promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology or legal requirements. Any changes will be posted on this page with an updated “Last updated” date. We encourage you to review this policy periodically to stay informed about how we protect your personal data.
12. Governing Law
This Privacy Policy is governed by and construed in accordance with the laws of England and Wales. Any disputes arising from or in connection with this policy shall be subject to the exclusive jurisdiction of the courts of England and Wales.