Legal
Privacy Notice
Last updated: 27 August 2026
1. Who we are
Axiom Inc Limited is a company registered in England and Wales under company number 16989885. Our registered office is 51 Borough High Street, London, SE1 1NB.
For the purposes of applicable data-protection law, including the UK General Data Protection Regulation and the Data Protection Act 2018, Axiom Inc Limited is the controller of personal data described in this Privacy Notice where we determine the purposes and means of processing.
Contact details: email hello@axiom-inc.ltd; telephone 0333 880 0603; post Axiom Inc Limited, 51 Borough High Street, London, SE1 1NB.
If we appoint a data protection officer, we will publish the relevant contact details here.
2. When this notice applies
This notice applies to personal information we process when you:
- Visit or interact with our website
- Contact us with an enquiry
- Request a quote, meeting or information
- Represent a prospective, current or former client, supplier or other business contact
- Subscribe to communications where this service is offered
- Attend an event or otherwise interact with us in a business context
When we provide payroll services to a client, we will often process employee and worker data on that client’s documented instructions. In that scenario, the client is generally the controller and we are generally the processor. The relevant client privacy notice and our signed Data Processing Addendum govern that processing; this public Privacy Notice does not replace them.
3. Personal data we collect
Depending on the context, we may collect:
- Identity and business-contact information, such as name, job title, employer, work address, email address and telephone number
- Enquiry, meeting and correspondence records
- Commercial information, such as payroll requirements, employee-count bands, service interests and proposal history
- Website technical information, including IP address, device/browser information, referral source, pages visited and cookie preferences
- Marketing preferences and consent records
- Information required for supplier, client or professional relationship management
Do not use website forms to submit employee bank details, National Insurance numbers, copies of identification, health data or other sensitive personal data.
4. How we receive personal data
We collect personal data directly from you when you contact us, submit a form, communicate with us or enter into a business relationship with us. We may also receive business-contact information from clients, colleagues, publicly available professional sources, service providers and referral partners.
5. Why we use personal data and our lawful bases
| Purpose | Typical personal data | Lawful basis |
|---|---|---|
| Responding to an enquiry or quote request | Contact and enquiry details | Taking steps at your request before entering a contract; legitimate interests in responding to business enquiries |
| Delivering and administering contracted services | Client-contact and service-delivery records | Performance of a contract; legal obligations; legitimate interests |
| Managing client, supplier and professional relationships | Contact, correspondence and contractual records | Performance of a contract; legitimate interests |
| Sending business communications or marketing where permitted | Contact details and preferences | Consent where required; legitimate interests where permitted by law |
| Running, securing and improving our website and systems | Technical, security and usage information | Legitimate interests; consent for non-essential cookies where required |
| Meeting legal, accounting, regulatory and record-keeping requirements | Relevant records | Legal obligation; legitimate interests |
| Establishing, exercising or defending legal claims | Relevant correspondence and records | Legitimate interests; legal claims |
Where we rely on legitimate interests, our interests include operating and developing our business responsibly, responding to prospective clients, protecting systems, preventing fraud, maintaining business records and defending legal rights. We will balance these interests against the individual’s rights and interests.
6. Payroll-service data
For payroll services, the client remains responsible for ensuring it has an appropriate lawful basis, has provided employees and workers with appropriate privacy information, and has given us documented instructions.
The relevant signed service agreement and DPA will define, among other things:
- The subject matter and duration of processing
- The nature and purpose of processing
- The categories of data subjects and personal data
- The controller’s instructions and rights
- Confidentiality commitments
- Security measures
- Subprocessor arrangements
- Assistance with data-subject requests, security incidents, DPIAs and regulatory engagement
- Return/deletion arrangements at the end of the service
- Audit and information rights
8. International transfers
Some technology and service providers may process personal data outside the United Kingdom. Where this happens, we will use an appropriate UK data-transfer mechanism and implement supplementary safeguards where required. Before publication, confirm the locations, transfer mechanisms and safeguards for each relevant supplier.
9. Security
We use appropriate technical and organisational measures designed to protect personal data. Measures may include access controls, least-privilege access, multi-factor authentication, encryption where appropriate, secure transfer processes, logging, backup arrangements, staff confidentiality requirements and supplier due diligence.
No transmission or system can be guaranteed to be completely secure. Please do not send sensitive payroll or employee information through public website forms or unencrypted email unless we have agreed a secure transfer method.
10. Retention
We keep personal data for no longer than necessary for the purpose for which it was collected, taking account of legal, regulatory, contractual, accounting, dispute-resolution and operational requirements.
We apply retention periods that are appropriate to the type of information and purpose of processing. We review these periods periodically and securely delete or anonymise information when it is no longer required, unless law requires us to retain it.
Clients remain responsible for their own statutory records-retention obligations. HMRC guidance indicates PAYE records generally need to be retained for at least three years after the end of the relevant tax year.
11. Your rights
Subject to the conditions and exceptions in data-protection law, you may have the right to:
- Request access to your personal data
- Request correction of inaccurate or incomplete data
- Request erasure in certain circumstances
- Request restriction of processing in certain circumstances
- Object to processing based on legitimate interests or direct marketing
- Request data portability where applicable
- Withdraw consent where processing depends on consent
- Complain to the Information Commissioner’s Office
To exercise rights relating to personal data for which Axiom is controller, contact hello@axiom-inc.ltd.
If your data is processed by us for a payroll client, contact your employer or the relevant client first. We will assist the client as required under our DPA.
12. Direct marketing
We may send business-to-business marketing communications where permitted by law. You can opt out at any time using the unsubscribe link or by contacting hello@axiom-inc.ltd. We will continue to send non-marketing service, legal or administrative messages where necessary.
13. Automated decision-making
We do not make decisions about individuals based solely on automated processing that produce legal or similarly significant effects, unless we tell you otherwise and provide the information required by law.
14. Complaints
Please contact us first if you have a concern. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk.
15. Changes to this notice
We may update this Privacy Notice from time to time. The current version will be published on this page with its “Last updated” date.