NEWRecognition module — recognise hard work and the people going above and beyond
WasteOptixWaste management software

Legal

Privacy Policy

How WasteOptix collects, uses and protects personal data — and which of the two roles we are playing when we do.

Version 1.0 · Last updated 23 September 2026

1. Who we are

WasteOptix is operated by Optix Compliance, a business operating in England and Wales ("we", "us", "our").

This policy covers wasteoptix.co.uk and the WasteOptix application.

Contact for data protection matters: privacy@optixgroup.co.uk

2. The two roles we play

This is the most important thing to understand about how we handle data, and it determines which parts of this policy apply to you.

When we are the controller

We decide how and why data is used when we handle:

  • data about visitors to our websites
  • data about prospective customers and enquiries
  • data about the individuals who administer a customer account with us
  • billing and account data
  • support correspondence

Sections 3 to 10 of this policy apply to that data.

When we are the processor

Our customers upload records about their own staff, workers, clients, tenants, candidates and service users into our software. For that data, our customer is the controller — they decide what is collected, why, and how long it is kept — and we are the processor, handling it only on their documented instructions.

If you are an employee, worker, candidate, tenant, resident or service user of one of our customers, and you want to exercise your rights over your data, you should contact that organisation rather than us. They are responsible for responding. We will assist them, and if you contact us we will point you to the right organisation where we can.

Our obligations as a processor are set out in our Data Processing Agreement, which forms part of our contract with every customer. Section 11 summarises it.

3. Personal data we collect as controller

CategoryExamplesWhere we get it
Identity dataName, job title, employerYou, directly
Contact dataEmail address, phone number, business addressYou, directly
Account dataUsername, hashed password, account preferencesYou, directly
Billing dataBilling contact, billing address, VAT number, subscription and invoice history, card type and last four digitsYou, via Stripe
Usage dataPages viewed, features used, login timesAutomatically
Technical dataIP address, browser type and version, device type, operating systemAutomatically
Support dataThe content of emails and any attachments you send usYou, directly

We do not collect or store your full payment card details. Card payments are processed directly by Stripe; we receive only a payment reference and limited card metadata.

4. Why we use it, and our lawful basis

PurposeLawful basis
Creating and administering your accountPerformance of a contract
Providing the software you subscribe toPerformance of a contract
Taking payment and issuing invoicesPerformance of a contract
Providing customer supportPerformance of a contract
Sending service messages — security alerts, password resets, changes to terms, maintenance and renewal noticesPerformance of a contract, and our legitimate interest in operating the service securely
Keeping the service secure, and detecting and preventing fraud and abuseOur legitimate interest in protecting our service and our customers
Understanding how the service is used so we can improve itOur legitimate interest in developing our products
Responding to enquiries from prospective customersOur legitimate interest in responding to enquiries, and steps taken at your request before entering a contract
Keeping accounting and tax recordsLegal obligation
Establishing, exercising or defending legal claimsOur legitimate interest in protecting our legal position

Where we rely on legitimate interests, we have assessed that our interest does not override your rights and freedoms. You can ask us for details of that assessment at privacy@optixgroup.co.uk, and you have the right to object — see section 8.

Service messages are not marketing. You cannot opt out of security alerts, billing notices or notifications about changes to the service while you hold an account with us.

5. Marketing

We do not currently send marketing emails, and we operate no mailing list. If you complete an enquiry or demo request form, we use your details to respond to that enquiry.

Should we begin sending marketing in future, we will do so only where we have your consent or may rely on the soft opt-in, every message will carry an unsubscribe link, and this policy will be updated before we start. You can tell us at any time that you do not wish to be contacted, by emailing privacy@optixgroup.co.uk.

We do not sell your data, and we do not share it with third parties for their own marketing.

6. Who we share data with

We share personal data with the following providers. This is our full list, not a category summary.

ProviderPurposeWhat they receiveRegion
Vercel Inc.Application hosting and content deliveryAll Customer Personal Data in transit; technical request dataUK / EEA
Nile (Niledatabase, Inc.)Database hosting, uploaded files and backupsAll Customer Personal DataEEA (Frankfurt)
Stripe Payments Europe, Ltd.Payment processingBilling contact and card metadata only — no Customer Personal DataEEA, with onward transfer to the United States under the UK IDTA
Vercel Inc. (Web Analytics)Aggregate visitor measurement on our marketing sitesTechnical request data only — no cookie, no device identifierUK / EEA

We also share data with our professional advisers — accountants, solicitors and insurers — where necessary; with authorities, regulators and law enforcement where required by law; and with an acquirer or successor if we sell or restructure the business.

We require every provider that handles personal data on our behalf to be bound by a written contract meeting the requirements of Article 28 UK GDPR.

7. International transfers

We host customer data in the United Kingdom or the European Economic Area.

Stripe processes billing data in the EEA with onward transfer to the United States. Where a transfer leaves the UK without an adequacy decision, we rely on the International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment.

You can ask us for details of the safeguards applying to a specific transfer at privacy@optixgroup.co.uk.

8. Your rights

Under UK GDPR you have the right to:

  • be informed about how we use your data — this policy
  • access your personal data and receive a copy
  • rectification of inaccurate or incomplete data
  • erasure, in certain circumstances
  • restrict processing, in certain circumstances
  • data portability for data you provided, where processing is by consent or contract and carried out by automated means
  • object to processing based on legitimate interests, and to direct marketing at any time
  • not be subject to solely automated decision-making producing legal or similarly significant effects
  • withdraw consent at any time where we rely on it, without affecting the lawfulness of processing before withdrawal

To exercise a right, email privacy@optixgroup.co.uk. We will respond within one month. We may extend that by up to two further months for complex requests and will tell you if we do. We may ask you to verify your identity. There is no charge unless a request is manifestly unfounded or excessive.

If your data is held in our software by one of our customers, contact that organisation instead — see section 2.

We would like the chance to resolve any concern first, but you have the right to complain to the Information Commissioner's Office at any time: Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF · 0303 123 1113 · ico.org.uk

9. How long we keep it

DataRetention
Account dataFor the life of the account, then 12 months
Customer data held in the softwareSee section 11 and the Data Processing Agreement
Billing, invoices and accounting records6 years from the end of the financial year, as required by tax law
Support correspondence3 years from the end of the matter
Enquiries that did not become customers12 months
Website analyticsAggregate counts only, retained by our analytics provider; no individual record is created

Where we need to keep data to establish, exercise or defend legal claims, we may retain it for the relevant limitation period.

10. Security

Our technical and organisational measures are published in full in Schedule 3 of our Data Processing Agreement, including the measures we have not yet built. We would rather state the gap than imply a control we do not have.

No system is completely secure, and we cannot guarantee the security of data transmitted to us over the internet.

Where a personal data breach is likely to result in a risk to individuals' rights and freedoms, we will report it to the ICO within 72 hours of becoming aware of it, and notify affected individuals without undue delay where the risk is high. Where we are a processor, we will notify the relevant customer without undue delay so they can meet their own obligations.

11. Data held in our software

As processor, we process the personal data that customer organisations choose to upload to WasteOptix. For this product that includes: name, contact details, driving licence and CPC details, round and collection records, vehicle assignment, customer site contacts and transfer note signatories.

WasteOptix may hold special category data: limited — driver medical fitness where recorded. It may also hold criminal offence data: limited — driving endorsements where recorded. Customer organisations are responsible for holding a valid condition under Article 9 and, where applicable, Article 10 UK GDPR.

For that data:

  • our customer determines what is collected and why
  • we process it only on their documented instructions
  • we do not use it for our own purposes
  • we do not use it to train, fine-tune or evaluate any artificial intelligence or machine learning model
  • we do not sell or disclose it, except to the providers listed in section 6 under contract, or where legally required
  • we delete or return it on termination, as set out in the Data Processing Agreement

If you believe an organisation using our software holds data about you, contact that organisation. If you do not know which organisation to contact, email privacy@optixgroup.co.uk and we will help where we are able to without breaching our confidentiality obligations to our customers.

12. Children

Our websites and products are business tools and are not directed at children. We do not knowingly collect personal data directly from children through our websites.

CareOptix contains records about children and young people. That data is uploaded by care providers acting as controller. We process it strictly as a processor under section 11 and under the Data Processing Agreement, and never for our own purposes.

13. Cookies

Our marketing sites set no cookies at all, and our visitor measurement is cookieless. Our applications set only the cookies strictly necessary to keep you signed in. Our Cookie Policy explains this in full.

14. Changes to this policy

We may update this policy. We will post the updated version here with a revised date. Where changes are material, we will notify account holders by email at least 30 days before they take effect.