Privacy Policy.
How Linox Ltd collects, uses, shares, and protects personal data — written for the individuals whose data we handle.
// last updated 5 may 2026 · contact hello@linox.co.uk
We are committed to protecting personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), the Privacy and Electronic Communications Regulations 2003 (PECR) where applicable, and, to the extent applicable, the EU GDPR.
1 · Who we are
Linox Ltd is a company registered in England and Wales under company number 12796381, with its registered office at Lytchett House, 13 Freeland Park, Wareham Road, Poole, England, BH16 6FA.
Linox builds Darkfield, an AI vision platform that runs perception on the cameras an organisation already operates — turning video into events, detections, alerts, analytics, and reports.
For any question about this policy or about how we handle personal data, contact us at hello@linox.co.uk or write to the registered address above.
2 · How this policy fits with our other documents
| Document | What it covers | Who it is mainly for |
|---|---|---|
| This Privacy Policy | Who we are, the personal data we handle and why, the lawful bases we rely on, who we share data with, your rights, and how to complain. | Individuals (website visitors, customer contacts, platform users, the public) |
| Data Processing Agreement (DPA) | The contractual terms that govern Linox's processing of customer data as a processor, including the authoritative details of the processing (Annex 1), technical and organisational security measures (Annex 2), and list of subprocessors (Annex 3). | Our business customers (controllers) |
| Security Whitepaper | The detailed technical and organisational security controls that protect the Darkfield platform. | Security, IT, and data-protection teams |
Where this policy touches on something covered in depth elsewhere — the subprocessor list, the security measures, or the precise processing details — it gives a summary and points you to the relevant document rather than reproducing it. If you are a customer, the DPA governs our processing of your data and prevails over this policy in the event of any conflict about that processing.
3 · Our roles: controller and processor
Linox as a controller. We decide why and how personal data is processed for the people we deal with directly: visitors to our website, prospective customers and enquirers, and the administrators and users our customers register on the platform (their account and contact details). Sections 4 to 11 explain how we handle that data.
Linox as a processor. When we operate the Darkfield platform for a customer, the customer is the controller for the video, images, and other personal data captured by their cameras, and Linox acts as their processor under our Data Processing Agreement. We process that data only on the customer's documented instructions. If you are an individual captured by a customer's cameras (an employee, visitor, driver, or member of the public), the organisation operating those cameras is responsible for telling you how your data is used and for handling your rights requests — please contact that organisation first. Section 12 summarises this processing; the full detail is in Annex 1 of the DPA.
4 · The personal data we collect as a controller
Depending on how you interact with us, we may collect:
- Identity and contact data — your name, job title, employer, business email address, business telephone number, and postal address.
- Account and user data — the names, email addresses, and role assignments of the administrators and users a customer registers on the platform, together with authentication and access settings.
- Enquiry and communications data — the content of your messages, support tickets, and correspondence, and records of demonstrations, meetings, and calls.
- Transaction and contract data — details of the services you have purchased or enquired about, billing contact details, and contractual records. We do not take payment online; customer payments are made by business-to-business bank transfer, so we do not collect or process payment-card data.
- Technical and usage data — IP address, browser type and version, device information, and server log data recorded when you visit our website.
- Marketing and preferences data — your marketing and communication preferences.
We collect this information when you contact us, request a demonstration or quote, enter into a contract, are registered as a platform user, or visit our website. Our website does not use cookies or similar tracking technologies.
5 · How we use personal data, and our lawful bases
| Purpose | Lawful basis |
|---|---|
| Responding to enquiries and providing demonstrations, quotes, and information | Legitimate interests; steps prior to entering a contract |
| Providing, administering, and supporting the Services and customer accounts | Performance of a contract |
| Managing user access, authentication, and platform security | Performance of a contract; legitimate interests |
| Billing, invoicing, and financial records | Performance of a contract; legal obligation |
| Service and administrative communications | Performance of a contract; legitimate interests |
| Marketing communications about our products and services | Consent, where required; otherwise legitimate interests (see section 7) |
| Improving and securing our website, products, and services | Legitimate interests |
| Complying with legal obligations and handling legal claims | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we have weighed the impact on your rights and do not use your data where those interests are overridden. We do not use the personal data we hold as a controller to make solely automated decisions producing legal or similarly significant effects about you.
6 · Special category data
Darkfield is not intended to process special category data (such as health, racial or ethnic origin, or biometric data) or data on criminal convictions. Depending on a customer's configuration, footage may nonetheless reveal such information. Where Linox acts as a processor, the customer is responsible for determining whether this occurs, ensuring an Article 9 (and, where relevant, Article 10) UK GDPR condition applies, and carrying out any required Data Protection Impact Assessment, as set out in the DPA. We support customers with DPIAs and with minimising what is captured (see section 12).
7 · Marketing communications
From time to time we may send you marketing communications about our products and services — for example by email — where you have asked to hear from us or where we are otherwise permitted to contact you, such as where you are an existing customer or business contact (the "soft opt-in"). We rely on your consent, or on our legitimate interests, in accordance with PECR and the UK GDPR, and we send only communications relevant to your business relationship with us.
You can opt out at any time using the unsubscribe link in our emails or by contacting hello@linox.co.uk. Opting out will not affect service or administrative messages we need to send in connection with the Services.
8 · Who we share personal data with
We do not sell personal data. We share it only as described below.
Service providers (subprocessors). We use selected third parties to help deliver the Services — including cloud infrastructure and storage providers, LLM service providers, vehicle-data sources (DVLA and DVSA), and collaboration and support tools. When they process personal data on our behalf they do so under written agreements no less protective than our own commitments, and only on our instructions. The current, authoritative list of subprocessors is maintained in Annex 3 of our DPA.
Subprocessor changes. Where Linox acts as a processor, we give affected customers advance notice — for example by email and/or by publishing an updated subprocessor list — and an opportunity to object before a new or replacement subprocessor begins processing their data, as set out in the DPA. Providers that we use only for our own internal purposes, and that do not process customer data captured by the Services, are not subprocessors.
Group companies. We may share personal data within our corporate group to provide and administer the Services, subject to the protections in this policy and the DPA.
Professional advisers and authorities. We may share data with our advisers (lawyers, accountants, auditors) and with regulators, law enforcement, or other authorities where required or permitted by law.
Business transfers. If Linox is involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction, subject to appropriate confidentiality protections.
9 · International data transfers
Our default is UK data residency: where reasonably possible we process and store personal data within the United Kingdom, and this is the default for UK customers. Some service providers may process data outside the UK. Where we make such a restricted transfer, we put in place an appropriate safeguard — such as the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or the EU Standard Contractual Clauses — together with any supplementary measures required, unless a lawful exemption applies. You can ask us for more information about these safeguards using the contact details in section 15.
10 · How we keep personal data secure
Security and privacy are the starting point of the Darkfield architecture, not an afterthought. In line with Article 32 UK GDPR, we maintain appropriate technical and organisational measures, including encryption in transit (TLS 1.2 or higher) and at rest (AES-256), least-privilege role-based access control with multi-factor authentication, network segmentation and isolation, data minimisation (turning video into events and short evidence clips rather than retaining continuous footage), centralised audit logging and monitoring, and a documented incident response plan. These measures are described in full in our Security Whitepaper and in Annex 2 of the DPA.
Personal data breaches. Where Linox acts as a processor, we notify the affected customer without undue delay after becoming aware of a breach affecting their data, so they can meet their obligation to notify the ICO within 72 hours and inform affected individuals. Where Linox is the controller, we notify the ICO and affected individuals where required by law.
11 · How long we keep personal data
We keep personal data only as long as necessary for the purposes for which it was collected, including to meet legal, accounting, or reporting requirements.
For personal data we hold as a controller:
- Enquiry and prospect data: until 1 year after our last business engagement.
- Customer account and contract data: until 1 year after our last business engagement.
- Billing and financial records: for as long as required by applicable law (in the UK, generally six years for tax and accounting purposes).
- Marketing data: until 1 year after our last business engagement.
- Website and usage data: up to 1 year.
For data processed through the Darkfield platform, retention windows are configurable by the customer, a zero-retention option is available for sensitive deployments, and data is securely disposed of at the end of its retention period and when a customer leaves the service.
When personal data is no longer needed, we securely delete or anonymise it.
12 · The Darkfield platform: camera and vehicle data
This section summarises how the platform processes personal data. Where the platform is operated for a customer, the customer is the controller and Linox is the processor, governed by the DPA.
In short: the Services ingest video and image data from a customer's cameras and run AI inference to detect people, vehicles, events, and conditions, generating events, alerts, analytics, reports, and short evidence clips — and, where configured, lookups of number plates against DVLA and DVSA records. Customers choose where inference happens (on-site at the edge, in a dedicated UK cloud instance, or fully air-gapped), which determines whether raw video leaves their network. In all cases the platform retains events and short clips rather than continuous footage, and in-memory anonymisation can remove identifying detail from each frame before any clip is persisted. Detection is limited to what the customer defines, and customers can pause or override the system at any time.
If you believe you have been captured by a Darkfield-enabled camera and wish to exercise your rights, please contact the organisation that operates the camera (the controller). If you contact Linox, we will promptly refer your request to that organisation and, as required by the DPA, will not respond except on their documented instructions.
13 · Your data protection rights
Under the UK GDPR you have rights over your personal data. These rights apply against the relevant controller — so where Linox acts as a processor for a customer's camera data, please direct your request to that customer (see section 12).
Your rights are: to be informed; of access to your data; to rectification; to erasure; to restrict processing; to data portability; to object (including to direct marketing at any time); rights relating to automated decision-making; and to withdraw consent where we rely on it.
To exercise any of these rights for data where Linox is the controller, contact us using the details in section 15. We will respond within one month, extendable by two further months for complex or numerous requests (we will tell you if so). There is normally no charge, though we may charge a reasonable fee or decline where a request is manifestly unfounded or excessive. We may need to verify your identity first.
14 · Children's data
The Darkfield platform and our website are intended for business and organisational use and are not directed at children, and we do not knowingly collect children's data through our website. Camera footage processed on behalf of customers may incidentally capture children; the customer, as controller, is responsible for addressing this in its own privacy notice, lawful basis, and DPIA.
15 · How to contact us and how to complain
For any question, to exercise your rights, or to raise a concern about how we handle personal data:
- Email: hello@linox.co.uk
- Post: Linox Ltd, Lytchett House, 13 Freeland Park, Wareham Road, Poole, England, BH16 6FA
You also have the right to complain to the UK supervisory authority, the Information Commissioner's Office (ICO) — ico.org.uk, helpline 0303 123 1113, or Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. We would appreciate the chance to address your concerns first.
16 · Changes to this policy
We may update this policy to reflect changes in our practices, the Services, or the law. The version published on this page is the version in force, and the "Last updated" date shows when it was last revised. Where changes are significant, we will take reasonable steps to bring them to your attention.
This Privacy Policy works alongside the Linox Data Processing Agreement and the Linox Security Whitepaper, each of which is referenced above. For the processing of customer personal data by Linox as a processor, the Data Processing Agreement prevails in the event of any conflict.
// © 2026 linox ltd · united kingdom