Website, business relationships and digital services
1. About this Privacy Notice
This Privacy Notice explains how the companies identified above collect, use, disclose, retain and protect personal information. It also explains the rights available to individuals under applicable data protection law.
It applies when you interact with any of the three companies through the Argyll website, digital platforms, software, APIs, hosted services, email, telephone, meetings, events, contractual relationships, recruitment, site visits, investment or partnership discussions, and other business activities.
This notice should be read together with any service-specific privacy information, contractual terms, cookie notice or fair-processing information provided at the point personal information is collected.
1. The companies covered by this notice
The companies covered by this notice are:
- Argyll Development Holdings Ltd (ADH), the group holding and development company;
- Argyll Energy Development Ltd (AED), which undertakes energy, power and related infrastructure activities; and
- Argyll Data Development Ltd (ADD), which undertakes artificial intelligence, digital infrastructure, software, compute, hosting and related technology activities.
In this notice, “Argyll Group”, “we”, “us” and “our” refer to one or more of these companies, as the context requires.
1. Who is responsible for your personal information?
The company with which you interact will normally be the data controller of your personal information. For example, AED will generally be the controller for information collected in connection with an AED energy project, while ADD will generally be the controller for information collected in connection with an ADD platform or digital service.
Some activities are administered jointly or through shared group functions. Depending on the circumstances, the companies may act as separate controllers, joint controllers, or one company may process information on behalf of another. Shared functions may include website administration, information technology, cyber-security, finance, legal, governance, marketing, communications, record keeping and business administration.
Argyll Data Development Ltd provides technical hosting, administration, maintenance, security and management of the Argyll website. In doing so, ADD may process limited technical, operational and enquiry information for ADH and AED. ADD is also a controller in its own right for information it processes for its own business, platforms and services.
Peter Griffiths, a director of all three companies, has responsibility for data-protection governance and oversight across the Argyll Group in the United Kingdom. He is the principal contact for privacy enquiries and the exercise of individual rights on behalf of each relevant company. You may contact him using the details in section 25 if you are uncertain which company is responsible for your information.
4. Data protection law
We process personal information in accordance with applicable data protection and privacy law, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and, where applicable, the European Union General Data Protection Regulation (EU GDPR).
We have not appointed a formal Data Protection Officer because the group companies do not currently consider that they fall within the categories of organisations required to appoint one. Peter Griffiths acts as the Group Data Protection Lead and principal UK privacy contact, as identified in section 25.
5. Personal information we may collect
The information we collect depends on your relationship with us and the way in which you interact with our website, personnel, projects, platforms and services.
5.1 Identity and contact information
a) name and title;
b) business or organisation name;
c) job title or role;
d) postal address;
e) email address;
f) telephone number;
g) professional profile and contact preferences.
5.2 Business and relationship information
a) enquiries, correspondence and meeting records;
b) information about your organisation, requirements, proposals or projects;
c) contract, order, account and service information;
d) supplier, partner, adviser, investor or stakeholder information;
e) due-diligence and onboarding information;
f) event attendance, networking and relationship-management records;
g) complaints, feedback and support records.
5.3 Financial and transaction information
a) billing and payment contact details;
b) banking or payment information where necessary;
c) transaction, invoice and account records;
d) tax, compliance and financial due-diligence information.
5.4 Technical, usage and security information
a) IP address and approximate location derived from it;
b) browser, device, operating-system and software information;
c) authentication, account and session information;
d) pages, content, links, resources and features accessed;
e) API, platform and service usage information;
f) performance, diagnostic, telemetry and server-log information;
g) security, access-control, fraud-prevention and incident information;
h) cookie identifiers and preference information.
5.5 Recruitment information
a) curriculum vitae and employment history;
b) qualifications, skills and professional memberships;
c) interview, assessment and reference information;
d) right-to-work and identity information;
e) salary expectations and availability;
f) information required to make reasonable adjustments.
5.6 Site, facility and physical-security information
a) visitor records;
b) access-control records;
c) CCTV images where used;
d) vehicle and attendance information;
e) health and safety, incident and emergency information.
5.7 Content and service information
Where you use ADD digital services, we may process prompts, inputs, files, datasets, configurations, support material and generated outputs as necessary to provide, secure and support the relevant service. Service-specific terms or privacy information may provide additional detail.
Unless expressly agreed otherwise in writing, customer prompts, submitted content and AI-generated outputs processed through ADD inference services are not used to train foundation models.
6. How we collect personal information
We may collect personal information:
a) directly from you through forms, emails, telephone calls, meetings, accounts, applications, contracts, events and other interactions;
b) from your employer, organisation, authorised representative, adviser or business contact;
c) from public sources, including corporate websites, professional networks, public registers, Companies House, regulatory sources and media;
d) from group companies, service providers, partners, advisers and counterparties where lawful;
e) automatically through cookies, logs, analytics, authentication systems and monitoring technologies;
f) from security systems and access-control arrangements at sites or facilities.
6.1 Website and customer enquiries
When you submit an enquiry through the Argyll website, the information may currently be routed into a Salesforce environment owned and administered by SambaNova Systems. SambaNova personnel may review the enquiry, contact you, assess or qualify your requirements, add notes and decide whether the enquiry should be passed to Argyll. Selected enquiry information and associated notes may then be made available to Argyll through a shared Google Workspace record for follow-up by Argyll Sales and Development.
The information involved may include your name, company or organisation, job title, email address, telephone number, country, message, product or service interest, IP address and information generated through subsequent communications or qualification activity.
For this activity, the precise legal role of each organisation depends on the decisions each makes about the purposes and means of processing. SambaNova may act as a separate controller, joint controller or processor for particular stages of the enquiry journey. Argyll is reviewing and documenting those responsibilities and the associated contractual, governance, retention, security and international-transfer arrangements.
If the enquiry concerns an ADH or AED activity, ADD may receive or process the enquiry as the technical host and manager of the website before it is passed to the relevant group company. The relevant Argyll company will then use the information for its own enquiry handling, relationship management, due diligence, project development and, where applicable, contracting purposes.
7. How we use personal information
a) responding to enquiries and communications;
b) developing and administering business relationships;
c) taking steps before entering into a contract and performing contracts;
d) providing, operating and supporting websites, platforms, software, APIs, infrastructure and related services;
e) creating and administering accounts, access rights and authentication;
f) customer, supplier, partner, investor and stakeholder management;
g) project planning, delivery, due diligence and governance;
h) billing, payments, accounting, tax and financial administration;
i) recruitment and workforce administration;
j) website and service analytics, diagnostics and improvement;
k) capacity, performance and operational management;
l) cyber-security, physical security, fraud prevention and abuse detection;
m) investigating incidents, complaints and disputes;
n) complying with legal, regulatory, sanctions, export-control and governance requirements;
o) establishing, exercising or defending legal rights;
p) business continuity, resilience, audit and record keeping;
q) corporate transactions, financing, restructuring or investment activities.
8. Lawful bases for processing
We use one or more lawful bases depending on the purpose and circumstances of the processing.
8.1 Contract
We process personal information where necessary to take steps at your request before entering into a contract or to perform a contract with you. This may include responding to a service request, onboarding, account administration, project delivery, support and billing.
8.2 Legitimate interests
We process personal information where necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your rights and freedoms. These interests may include operating and developing our businesses, managing relationships, administering the group, protecting systems and facilities, preventing fraud and abuse, improving services, maintaining records and protecting legal rights.
8.3 Legal obligation
We process information where necessary to comply with law, regulation, court orders, lawful requests, taxation, accounting, health and safety, sanctions, export control, corporate governance and other legal obligations.
8.4 Consent
We rely on consent where required, including for certain non-essential cookies, optional marketing communications or particular uses of information. You may withdraw consent at any time. Withdrawal does not affect processing carried out before consent was withdrawn.
8.5 Vital interests and public interest
In limited circumstances, we may process information to protect someone’s vital interests or where processing is necessary for a task carried out in the public interest and a lawful basis applies.
9. If you do not provide requested information
Where information is required by law or under a contract, or is necessary to provide a requested service, failure to provide it may prevent us from responding to an enquiry, entering into or performing a contract, creating an account, granting access, making a payment, completing due diligence or progressing a project or application.
10. Special category and criminal-offence information
We do not routinely seek special category personal information. We may process it where necessary and lawful, for example in connection with health and safety, accessibility adjustments, employment, equality monitoring, site incidents, insurance or legal claims. Where required, we will identify an additional condition for processing under applicable law.
We may process criminal-offence information where necessary and lawful for security, fraud prevention, due diligence, sanctions compliance, recruitment, legal claims or regulatory obligations, subject to appropriate safeguards.
11. AI-assisted processing and automated decisions
We may use artificial intelligence and automated tools to assist with activities such as document analysis, information retrieval, cyber-security, service monitoring, technical support, workflow management, drafting and operational analysis. These tools may support personnel but do not replace accountability for decisions.
We do not currently make decisions based solely on automated processing that produce legal effects, or similarly significant effects, for individuals unless we have a lawful basis and provide specific information about the processing and applicable safeguards.
12. Sharing information within the Argyll Group
Personal information may be shared between ADH, AED and ADD where reasonably necessary for the purposes described in this notice. This may include shared management, governance, finance, legal, IT, cyber-security, website, communications, business-development, project and administrative functions.
Access is limited to personnel and service providers who require the information for authorised purposes and who are subject to appropriate confidentiality and security obligations.
13. Sharing information with other organisations
We may share personal information with appropriate recipients, including:
a) website, hosting, cloud, data-centre and infrastructure providers;
b) cyber-security, authentication, monitoring and technical-support providers;
c) payment processors, banks, accountants, auditors and insurers;
d) legal advisers, consultants, engineers and other professional advisers;
e) communications, event, marketing and customer-management providers;
f) project partners, suppliers, subcontractors, customers and counterparties where necessary;
g) regulators, courts, law-enforcement bodies, government departments and public authorities;
h) potential or actual investors, funders, purchasers or transaction counterparties;
i) other recipients where you direct us or provide consent.
The website currently uses Squarespace for website services and may use Google Analytics or related analytics technologies, subject to cookie choices and applicable law. The current customer-enquiry workflow may also involve SambaNova Systems, Salesforce and Google Workspace, as described in section 6.1.
These providers may process information as service providers, processors, separate controllers or joint controllers depending on the activity and the decisions they make. Providers and technologies may change over time, and material changes will be reflected in this notice where required.
We do not sell personal information.
14. Corporate transactions
We may disclose personal information in connection with a proposed or actual financing, investment, merger, acquisition, reorganisation, sale, transfer or other corporate transaction. Any disclosure will be limited to information reasonably necessary for the transaction and recipients will be subject to appropriate confidentiality and data-protection obligations.
We do not ordinarily advertise, publish or otherwise disclose the identity of our clients, prospective clients or commercial partners, or details of their relationship with us, without their prior consent. Client information will not be used in publicity, marketing materials, case studies, announcements or promotional communications unless expressly agreed.
This does not prevent confidential disclosure where reasonably necessary for due diligence, professional advice, regulatory compliance, legal obligations or the completion of a corporate transaction, provided that appropriate confidentiality and data-protection safeguards are in place.
15. International transfers
Some group companies, service providers, infrastructure providers, professional advisers or counterparties may process or access personal information outside the United Kingdom. In particular, website enquiry information routed through SambaNova-operated systems may be accessible to SambaNova personnel and systems in the United States before Argyll receives or follows up the enquiry. International processing may also occur where technology, cloud, support, communications, analytics or professional services operate across borders.
Where an Argyll company initiates a restricted transfer, it will identify and document an applicable lawful transfer mechanism. This may include UK adequacy regulations, including the UK Extension to the EU-US Data Privacy Framework where the recipient and relevant data are covered, an appropriate safeguard such as the UK International Data Transfer Agreement or the UK Addendum to approved standard contractual clauses, or a permitted exception. Where required, we will also complete an appropriate transfer-risk or data-protection assessment and apply supplementary safeguards.
Further information about relevant transfer safeguards may be requested using the contact details in section 25, although we may redact commercially confidential or security-sensitive information.
16. Security
We implement technical and organisational measures designed to protect personal information from unauthorised access, unlawful processing, accidental loss, destruction, alteration, disclosure or damage.
Measures may include encryption in transit and at rest where appropriate, authentication, access controls, least-privilege arrangements, network and infrastructure security, monitoring and logging, secure backups, vulnerability management, physical security, incident response, business continuity and confidentiality obligations.
No internet transmission, storage system or technical environment can be guaranteed to be completely secure. You should use appropriate security measures when communicating with us and should not submit confidential, classified or security-sensitive material through ordinary website forms unless expressly requested.
17. Retention
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, including legal, regulatory, tax, accounting, contractual, security, dispute-resolution and record-keeping requirements.
Information category
Typical retention approach
General enquiries
Normally retained for up to three years after the last meaningful contact, unless a longer period is justified.
Customers, suppliers and contracts
Normally retained for the relationship and up to seven years afterwards, subject to legal, tax and contractual requirements.
Financial and accounting records
Normally retained for at least six years after the relevant financial period, or longer where required.
Recruitment records
Unsuccessful applications are normally retained for up to twelve months, unless consent or another lawful basis supports longer retention.
Security and technical logs
Retained for periods proportionate to operational, security and investigative needs.
CCTV and access records
Normally retained for a limited period unless required for an incident, investigation, legal claim or statutory purpose.
Legal, compliance and due-diligence records
Retained for as long as necessary to meet applicable obligations and protect legal rights.
These periods are indicative. We may retain information for longer where required by law, where a dispute or investigation is anticipated or ongoing, or where deletion would compromise security or legal rights. When no longer required, information will be securely deleted, anonymised or otherwise disposed of.
18. Cookies and similar technologies
The website uses cookies and similar technologies for essential operation, security, preferences, analytics and embedded content. Non-essential cookies will be used only where permitted by law and, where required, after consent has been obtained.
You can manage available choices through the website cookie controls. Further information is provided in the separate Cookie Policy.
19. Marketing communications
We may send business-to-business communications where lawful and relevant to an existing or prospective professional relationship. Where consent is required, we will seek it. You can opt out of marketing at any time by using an unsubscribe facility or contacting us. We may retain limited suppression information to ensure your preference is respected.
20. Children
Our websites and business services are not directed at children under 16, and we do not knowingly collect their personal information through general website or business activities. If we become aware that information has been collected from a child without an appropriate lawful basis, we will take reasonable steps to delete or restrict it.
21. Links and third-party services
Our websites, platforms and communications may contain links to third-party websites or services. We do not control their privacy practices and are not responsible for their content, security or processing activities. You should review the privacy information provided by the relevant third party.
22. Your rights
Depending on the circumstances and applicable law, you may have the right to:
a) be informed about how your personal information is used;
b) request access to your personal information;
c) request correction of inaccurate or incomplete information;
d) request deletion in certain circumstances;
e) request restriction of processing in certain circumstances;
f) object to processing based on legitimate interests or for direct marketing;
g) receive certain information in a portable format;
h) withdraw consent where processing relies on consent;
i) request safeguards in relation to qualifying automated decision-making;
j) lodge a complaint with a supervisory authority.
These rights are not absolute. We may need to verify your identity and may refuse or limit a request where an exemption or overriding legal obligation applies. We will explain our decision where required.
23. Exercising your rights
Requests may be submitted using the contact details in section 25. Please identify the company or activity concerned where possible. We may request additional information to verify identity, locate relevant records or clarify the request.
We normally respond within one month, although the period may be extended where permitted for complex or multiple requests. We do not usually charge a fee, but applicable law permits a reasonable fee or refusal in certain circumstances involving manifestly unfounded or excessive requests.
24. Complaints
Please contact us first if you have concerns about how we use personal information. We will seek to investigate and resolve the matter.
You also have the right to complain to the Information Commissioner’s Office, the United Kingdom supervisory authority. Information about making a complaint is available from the ICO website. Where the EU GDPR applies, you may also have the right to complain to the supervisory authority in the relevant European Economic Area jurisdiction.
25. Contact details
Peter Griffiths Director and Group Data Protection Lead For and on behalf of: Argyll Development Holdings Ltd Argyll Energy Development Ltd Argyll Data Development Ltd Registered office for all three companies: Killellan Farm Toward Argyll PA23 7UJ United Kingdom Email: info@argylldev.com
26. Changes to this Privacy Notice
We may update this notice to reflect changes in law, regulation, technology, group structure, services, providers or business activities. The current version will be published on the website with its effective date. Where a change materially affects individuals, we may provide additional notice where appropriate.
27. Related documents
This Privacy Notice may operate alongside:
a) Website Terms of Use;
b) Cookie Policy;
c) Platform Terms of Service;
d) Software and Platform Licence Agreements;
e) Acceptable Use Policies;
f) Data Processing Addenda;
g) service-specific privacy information;
h) employment, recruitment or visitor privacy notices;
i) commercial agreements and project documentation.
Where a service-specific notice provides more detailed information about a particular processing activity, that information should be read together with this notice.
Questions about this policy? Email legal@argylldata.ai or get in touch.
