Skip to main content

Privacy & Security at Pixcell

At Pixcell, trust and transparency matter. As a HubSpot Platinum Partner, we work with sensitive systems every day — and we take that responsibility seriously. Below is an overview of how we protect your data, ensure business continuity, and respond to incidents.

Who We Are

Pixcell.io Ltd is a private limited company registered in England and Wales.

Pixcell is registered with the Information Commissioner's Office and handles personal data in line with applicable UK data protection law, including the UK GDPR and Data Protection Act 2018.

Our Role

Depending on the situation, Pixcell may act as either a Data Controller or a Data Processor.

When Pixcell is a Data Controller

We act as a Data Controller when we decide how and why personal data is used for our own business activities.

This can include information relating to:

  • Website Visitors
  • Prospective Clients
  • Client Contacts
  • Suppliers
  • Partners
  • Business Enquiries
  • Contracts
  • Billing
  • Sales and Marketing
  • Our Own Business Operations

When Pixcell is a Data Processor

When a client gives Pixcell access to HubSpot or another business system so that we can carry out work on their behalf, the client will normally remain the Data Controller and Pixcell will act as the Data Processor.

This can include work involving:

  • HubSpot Administration
  • CRM Configuration
  • Data Management
  • Data Migration
  • Reporting
  • Automation
  • Integrations
  • Marketing Operations
  • Sales Operations
  • Customer Success Operations
  • Training
  • Technical Support
  • Ongoing HubSpot Support

When we act as a Data Processor, our responsibilities are also covered by our Standard Data Processing Addendum.

View Pixcell's Standard Data Processing Addendum

Our Approach to Data Protection

Our approach is simple.

  • Collect Only What Is Needed: We do not intentionally collect or access information that is not required for our business or the services we provide.
  • Do Not Sell Client Data: Client data is never sold.
  • Limit Data Sharing: Information is only shared with authorised service providers, professional advisers or delivery partners where needed to operate our business or deliver an agreed service.
  • Use Approved Access: Client systems are only accessed with client permission and through authorised access methods.
  • Limit Access: Only people who need access to complete assigned work receive it.
  • Protect Credentials: We avoid storing client passwords or credentials where delegated access is available.
  • Remove Access: Access is removed when it is no longer required.

Trust starts with knowing who has access to your information, why they have access and what they can do with it.

Information We May Collect

The information we process depends on how you interact with Pixcell.

Contact and Business Information

This may include:

  • Name
  • Business Email Address
  • Telephone Number
  • Job Title
  • Company
  • Business Address
  • Professional Information

Client Information

This may include:

  • Services Purchased
  • Contracts
  • Proposals
  • Project Information
  • Meeting Notes
  • Support Requests
  • Account Information
  • Invoices
  • Payment Records
  • Client Preferences
  • Communication History

Website Information

When you visit our website, we may collect information such as:

  • IP Address
  • Browser Information
  • Device Information
  • Pages Viewed
  • Website Interactions
  • Referral Source
  • Cookie Preferences

Client System Information

When a client gives us access to HubSpot or another platform, we may come into contact with information stored within that system.

Depending on the client and the work being carried out, this can include:

  • Contact Records
  • Company Records
  • Lead Information
  • Deal Information
  • Customer Records
  • Email Activity
  • Meeting Activity
  • Marketing Activity
  • Form Submissions
  • Reporting Information
  • CRM Notes
  • Support Information

Where we access this information solely to complete work for a client, Pixcell normally acts as a Data Processor.

How We Receive Information

We may receive personal data:

  • Directly From You when you contact us, submit a form, book a meeting or communicate with our team
  • From Your Organisation when your employer or organisation appoints you as a contact
  • Through Our Website when you interact with our forms or website
  • Through Referrals from clients, partners or other business contacts
  • From Public Business Sources where appropriate for business development
  • From Client Systems when we are given authorised access to complete agreed work
  • From Connected Platforms used as part of an agreed client project

How We Use Personal Data

We use personal data where we have a valid business or legal reason to do so.

Delivering Our Services

We may use information to:

  • Provide Consulting Services
  • Deliver HubSpot Support
  • Manage Projects
  • Configure Client Systems
  • Provide Training
  • Respond To Requests
  • Troubleshoot Issues
  • Manage Integrations
  • Carry Out Data Work
  • Create Reporting
  • Communicate With Client Teams

We normally rely on performance of a contract or legitimate interests for this activity.

Managing Client Relationships

We may use information to:

  • Manage Client Accounts
  • Schedule Meetings
  • Maintain Project Roadmaps
  • Provide Service Updates
  • Manage Renewals
  • Respond To Questions
  • Monitor Service Delivery

Sales and Marketing

We may use business contact information to:

  • Respond To Enquiries
  • Follow Up On Conversations
  • Introduce Relevant Pixcell Services
  • Manage Prospective Client Relationships
  • Maintain Our CRM
  • Send Relevant Business Communications

We use legitimate interests where appropriate and consent where required.

You can ask us to stop marketing communications at any time.

Client Data and Confidentiality

All client information and confidential information received during an engagement is treated as confidential.

Pixcell personnel with access to client information are subject to confidentiality obligations.

Client information is only used for the purpose for which access was provided unless:

  • The Client Gives Permission
  • The Information Is Already Public
  • Disclosure Is Required By Law

Our confidentiality obligations continue after a client engagement ends. This reflects the confidentiality commitments contained within our standard client agreements.

Client Ownership and Intellectual Property

Information, materials and intellectual property supplied to Pixcell by a client remain the property of that client. Pixcell does not claim ownership over client data, confidential information or intellectual property provided to us for the purpose of delivering our services. Where we create deliverables for a client, ownership is governed by the applicable client agreement. Our standard contractual position is that deliverables created for a client become the client's property once full payment has been received.

Secure Systems and Access Controls

We maintain controls around who can access client systems and how that access is provided.

These include:

  • Least Privilege Access: Access is limited to people assigned to the relevant work.
  • HubSpot Partner Access: Official HubSpot Partner Access is used where available and appropriate.
  • Client Approved Access: Other systems are accessed using methods approved by the client.
  • Individual Accounts: Individual user accounts are used where supported.
  • Multi Factor Authentication: MFA or 2FA is enabled where supported.
  • Single Sign On: SSO is used where appropriate.
  • Credential Protection: Client passwords and credentials are not intentionally stored where delegated access is available.
  • Revocable Access: Clients remain able to revoke access through the relevant platform.
  • Access Removal: Access is removed once it is no longer required.

Where a client requires access through systems such as Okta or another identity provider, Pixcell will work with the client to follow their approved access process.

Access and Delivery

Pixcell operates with a distributed team of consultants working from the United Kingdom and Pakistan. Access to client systems is provided on a least privilege basis. Only consultants assigned to a client or project receive access to the systems and information required to complete their work.

Team members who access client systems:

  • Are Bound By Confidentiality Obligations
  • Follow Pixcell Security Requirements
  • Use Approved Access Methods
  • Use MFA Where Supported
  • Use Individual Accounts Where Available
  • Only Access Information Required For Their Work
  • Have Access Removed When It Is No Longer Required

Our location does not change the security requirements applied to client information.

International Data Access

Our distributed team and use of cloud based technology means personal data may in some circumstances be accessed from outside the United Kingdom. Where international access constitutes a restricted transfer under applicable data protection law, Pixcell puts appropriate safeguards in place.

Depending on the circumstances, these may include:

  • UK Adequacy Regulations
  • International Data Transfer Agreements
  • The UK International Data Transfer Addendum
  • Standard Contractual Clauses Where Applicable
  • Contractual Confidentiality Requirements
  • Access Restrictions
  • Technical Safeguards
  • Organisational Safeguards

The appropriate safeguards depend on the client, system and type of processing involved.

Clients can contact us for more information about the arrangements applying to their engagement.

Service Providers and Sub Processors

We use a number of established technology providers to run our business and deliver our services.

Our core systems include:

Service Purpose
Google Workspace Email, documents, file storage and collaboration
Slack Internal and client communication
ManyRequests Customer Portal and project management
HubSpot CRM, customer management and service delivery
Read.ai Meeting transcription, summaries and meeting notes


We may also use professional advisers, banking providers, insurers and specialist technology providers where required.
When a provider processes client data on our behalf, we put appropriate arrangements in place as required by applicable data protection law. Our Standard Data Processing Addendum contains further information about our approach to Sub Processors.

Client Controlled Systems

Clients often ask Pixcell to work within software they have selected and licensed themselves.

This may include:

  • CRM Systems
  • Sales Platforms
  • Marketing Platforms
  • Data Enrichment Platforms
  • Finance Systems
  • Customer Support Platforms
  • Integration Platforms

A provider does not become a Pixcell Sub Processor simply because a client gives Pixcell authorised access to its account.

Marketing and Publicity

Our standard client agreement allows Pixcell to reference a client's name, logo and company as a Pixcell client in our website, proposals, presentations and other marketing materials. We may also produce case studies relating to work delivered for a client. We do not publish confidential information, commercially sensitive information or private client data as part of this activity. Customer specific performance figures, financial information or other identifiable confidential information are only published with the client's prior written approval.

Clients may ask us to stop using their name or logo for future marketing by contacting us in writing. Any specific contractual terms agreed with a client will take priority over this general position.

Data Processing Addendum

Where Pixcell processes personal data on behalf of a client, our Standard Data Processing Addendum sets out the responsibilities of both parties.

It covers:

  • Processing Instructions
  • Confidentiality
  • Security Measures
  • Access Controls
  • Sub Processors
  • International Data Transfers
  • Data Subject Requests
  • Security Incidents
  • Data Return and Deletion
  • Audit and Compliance

View Pixcell's Standard Data Processing Addendum

The DPA can be incorporated into a client agreement or signed separately where required.

If your organisation requires a DPA, supplier questionnaire, security assessment or other vendor due diligence information, contact us and we will provide what is required.

Incident Awareness and Response

We work to reduce the risk of security incidents, but we also maintain a clear process for responding when something happens.

Where an incident affects client data, we will:

  • Identify what has happened
  • Restrict affected access where appropriate
  • Contain the issue
  • Investigate the cause and potential impact
  • Document what has happened
  • Notify the affected client without undue delay and, where reasonably practicable, within 24 hours of becoming aware of the incident
  • Provide further information as our investigation develops
  • Resolve identified security issues
  • Review the incident after resolution where appropriate

Where Pixcell acts as a Data Processor, any additional notification obligations are covered by the relevant client agreement and our DPA.

Business Continuity

Pixcell is a remote first consultancy and our systems are designed to allow our team to continue working during most operational disruptions.

Our business operations are supported by:

  • Cloud Based Platforms including HubSpot, Google Workspace, Slack and ManyRequests
  • Platform Backup Features provided by our core technology providers
  • Alternative Communication Methods if a primary system becomes unavailable
  • Distributed Delivery across our team
  • Defined Responsibilities for client communication and service delivery

Our aim is to maintain consistent client support while protecting access to client information.

Business Insurance

Pixcell maintains business insurance appropriate to our consultancy services.

Our cover includes:

  • Professional Indemnity
  • Public Liability
  • Legal Expenses

We also work with external legal, compliance and insurance specialists where needed.

How Long We Keep Personal Data

We keep personal data only for as long as we reasonably need it.

The appropriate period depends on:

  • Why The Information Was Collected
  • Whether We Have An Active Relationship With You
  • Contractual Requirements
  • Legal Requirements
  • Accounting Requirements
  • Potential Disputes Or Claims
  • Security Requirements

When information is no longer required, we delete it, anonymise it or securely dispose of it where appropriate. Where we process personal data on behalf of a client, return and deletion of that information is also governed by the applicable client agreement and our DPA.

Your Data Protection Rights

Depending on the circumstances, you may have the right to:

  • Access personal data we hold about you
  • Correct inaccurate or incomplete information
  • Request Deletion in certain circumstances
  • Restrict Processing in certain circumstances
  • Object To Processing in certain circumstances
  • Receive Certain Data in a portable format
  • Withdraw Consent where we rely on consent
  • Object To Direct Marketing at any time
  • Make A Complaint to the Information Commissioner's Office

Not every right applies in every situation.

To make a request, contact:

Fawwad Mirza
fawwad@pixcell.io

We may need to confirm your identity before completing a request.

If the information is held by Pixcell solely on behalf of one of our clients, we may refer the request to that client as the Data Controller.

Cookies

Our website may use cookies and similar technologies to operate the website, remember preferences and understand how visitors use it.

These may include:

  • Necessary Cookies
  • Preference Cookies
  • Analytics Cookies
  • Marketing Cookies Where Applicable

Where consent is required for a non essential cookie, we will ask for that consent before using it. You can manage your preferences through the cookie controls available on our website.

Complaints

If you have concerns about how Pixcell has handled your personal data, please contact us first so we can investigate.

Data Protection Contact: Fawwad Mirza
Email: fawwad@pixcell.io

You also have the right to contact the Information Commissioner's Office.

ICO Registration Reference: ZB738819

View Pixcell's ICO Registration

Transparency and Accountability

We want clients to know who is working with them, how their systems are accessed and what protections are in place.

That means being clear about:

  • Who delivers the work
  • Where our team operates
  • How access is provided
  • Why access is needed
  • Which systems we use
  • How information is protected
  • What happens if something goes wrong

Clients carrying out supplier onboarding, vendor due diligence, security reviews or data protection assessments can contact us for further information.

Contact

For privacy, security, data protection or supplier due diligence enquiries:

Pixcell.io Ltd

Company Number: 14423454

Registered Office: Flat 8, 1 Durham Road, Raynes Park, London, England, SW20 0QH

Data Protection Contact: Fawwad Mirza

Email: fawwad@pixcell.io

Companies House: View our company profile

ICO: View registration ZB738819

Standard Data Processing Addendum: View our DPA