1. Introduction
Oinio Ltd (registered in England and Wales, with its principal place of business at Kent, United Kingdom) is committed to protecting the privacy and security of your personal data.
This Privacy Policy explains how we collect, use, store, and share your personal data when you visit our website (https://oinio.io), use our services, or otherwise interact with us.
We act as a Data Controller for the personal data we process. This policy applies in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the EU General Data Protection Regulation (EU GDPR) where applicable.
2. Personal Data We Collect
We may collect and process the following categories of personal data:
2.1 Information You Provide to Us
- Full name, email address, phone number, and postal address
- Job title, company name, and professional details
- CV, cover letter, and employment history (where applicable)
- Account credentials and authentication data
- Payment and billing information
- Any other information you voluntarily provide through forms, emails, or correspondence
2.2 Information We Collect Automatically
- IP address, browser type, device identifiers, and operating system
- Pages visited, time spent on pages, and navigation paths
- Cookies and similar tracking technologies (see Section 8)
- Referral source and search terms used to find our website
2.3 Information from Third Parties
- Data from business partners, clients, or publicly available sources
- Information from identity verification or background check providers
- Data from integrated third-party platforms (e.g. calendar, communication, or CRM tools)
3. Lawful Basis for Processing
We process your personal data on one or more of the following legal bases under Article 6 of the UK/EU GDPR:
- Consent: Where you have given clear consent for us to process your personal data for a specific purpose.
- Contract: Where processing is necessary for the performance of a contract with you, or to take steps at your request prior to entering a contract.
- Legal Obligation: Where processing is necessary for compliance with a legal obligation to which we are subject.
- Legitimate Interests: Where processing is necessary for our legitimate interests (or those of a third party), provided your rights do not override those interests. Our legitimate interests include operating and improving our services, fraud prevention, and direct marketing to existing clients.
4. How We Use Your Personal Data
We use your personal data for the following purposes:
- To provide, maintain, and improve our IT consulting, automation, and AI integration services
- To manage your account and provide customer support
- To communicate with you about our services, updates, and promotional offers
- To process payments and manage billing
- To comply with legal and regulatory obligations
- To protect our rights, property, and safety, and that of our users
- To analyse website usage and improve user experience
- To facilitate recruitment processes where applicable
5. Who We Share Your Data With
We may share your personal data with the following categories of recipients:
- Service providers and sub-processors who assist in delivering our services (e.g. cloud hosting, payment processing, email delivery)
- Professional advisers including lawyers, auditors, and accountants
- Regulatory authorities, law enforcement, or other bodies where required by law
- Business partners and clients, where necessary for the performance of our services
We require all third parties to respect the security of your personal data and to treat it in accordance with applicable data protection laws. We do not sell your personal data to any third party.
6. International Data Transfers
Oinio Ltd is headquartered in the United Kingdom with a presence in South Africa. Where we transfer personal data outside the UK or the European Economic Area (EEA), we ensure appropriate safeguards are in place, including:
- Transfers to countries with an adequacy decision from the UK Government or the European Commission
- Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner’s Office (ICO) or the European Commission
- The UK International Data Transfer Agreement (IDTA) where applicable
- Other valid transfer mechanisms under the UK GDPR or EU GDPR
7. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements.
The retention period depends on the nature of the data and the purpose of processing:
- Client and contract data: retained for 6 years after the end of the business relationship
- Marketing data: retained until you withdraw consent or opt out
- Website analytics data: retained for up to 26 months
- Recruitment data: retained for up to 12 months after a recruitment process concludes, unless you consent to longer retention
When personal data is no longer required, we will securely delete or anonymise it.
8. Cookies and Tracking Technologies
Our website uses cookies and similar technologies to enhance your browsing experience, analyse site traffic, and understand user behaviour.
We use the following types of cookies:
- Strictly Necessary Cookies: Required for the website to function and cannot be switched off.
- Analytics Cookies: Help us understand how visitors interact with our website (e.g. Google Analytics).
- Functional Cookies: Enable enhanced functionality and personalisation.
- Marketing Cookies: Used to deliver relevant advertisements and track campaign effectiveness.
You can manage your cookie preferences through your browser settings or through our cookie consent banner. Disabling certain cookies may affect website functionality.
9. Your Rights
Under the UK GDPR and EU GDPR, you have the following rights in relation to your personal data:
- Right of Access: You have the right to request a copy of the personal data we hold about you.
- Right to Rectification: You can request that we correct inaccurate or incomplete personal data.
- Right to Erasure: You can request the deletion of your personal data in certain circumstances.
- Right to Restriction: You can request that we restrict the processing of your personal data.
- Right to Data Portability: You can request to receive your personal data in a structured, commonly used, and machine-readable format.
- Right to Object: You can object to processing based on legitimate interests or direct marketing.
- Rights related to Automated Decision-Making: You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal or similarly significant effects.
To exercise any of these rights, please contact us at hello@oinio.io. We will respond to your request within one month, as required by law. There is no fee for making a request, unless the request is manifestly unfounded or excessive.
10. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or alteration. These measures include:
- Encryption of data in transit (TLS/SSL) and at rest
- Access controls and role-based permissions
- Regular security assessments and vulnerability testing
- Staff training on data protection and information security
- Incident response procedures for data breaches
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform affected individuals without undue delay.
11. Children’s Privacy
Our services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected personal data from a child, we will take steps to delete it promptly.
12. Third-Party Links
Our website may contain links to third-party websites or services. We are not responsible for the privacy practices or content of these third-party sites. We encourage you to review the privacy policies of any third-party services you access.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational reasons. The “Last updated” date at the top of this policy indicates when it was most recently revised.
We encourage you to review this policy periodically. Where changes are significant, we will notify you by email or through a prominent notice on our website.
14. Complaints
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with a supervisory authority:
- UK: Information Commissioner’s Office (ICO) — www.ico.org.uk
- EU: Your local Data Protection Authority in the relevant EU Member State
We would, however, appreciate the opportunity to address your concerns before you approach a supervisory authority, so please contact us in the first instance.
15. Contact Us
If you have any questions about this Privacy Policy or our data protection practices, please contact us:
Oinio Ltd
Address: First Floor, Unit 4, Markerstudy Business Park, Whitstable, Kent, England, CT5 3FE
Email: info@oinio.io
Website: https://oinio.io