Privacy Policy

Document Control

Exarlis Ltd Privacy Policy - Version 2.0. Last Updated: April 2026


1. Who we are

Exarlis Ltd (“Exarlis”, “we”, “us”, “our”) is a private limited company registered in England and Wales (company number 16981902). Our registered office is at 1259 London Road, C/O MCL Accountants, Leigh-on-Sea, Essex, SS9 2AF. We are registered with the Information Commissioner’s Office as a data controller (registration reference: ZC096677).

For any privacy-related queries, please contact us at contact@exarlis.com.

2. What this policy covers

This policy explains what personal data we collect when you visit our website, why we collect it, how we use it, how long we keep it, and what your rights are under UK law. It applies to data collected via this website only. It does not cover data collected under separate client engagement agreements, which are governed by those agreements.

3. The data we collect and how

We collect personal data in the following ways:

Contact form. When you submit an enquiry via our contact form, we collect your name, email address, and the content of your message. We use this information solely to respond to your enquiry. The lawful basis for this processing is legitimate interests (Article 6(1)(f) UK GDPR).

Google Analytics 4. With your consent, we use Google Analytics 4 to collect anonymised data about how visitors use our website, including pages visited, time on site, general location (country and city level), device type, traffic source, and browser type. No personally identifiable information is collected. The lawful basis for this processing is consent (Article 6(1)(a) UK GDPR).

Microsoft Clarity. With your consent, we use Microsoft Clarity to collect behavioural analytics data including mouse movements, clicks, scroll behaviour, and pages visited. Clarity generates session recordings and heatmaps to help us understand and improve the user experience. No form field content is ever recorded. The lawful basis for this processing is consent (Article 6(1)(a) UK GDPR).

Cookiebot by Usercentrics. We use Cookiebot to manage cookie consent on this website. When you make a consent decision, Cookiebot records your choice, the date of consent, and a unique consent ID. This data is retained solely to evidence compliance with our legal obligations under PECR and UK GDPR. The lawful basis for this processing is legal obligation and legitimate interests (Article 6(1)(c) and 6(1)(f) UK GDPR).

We do not collect special category data (such as health, ethnicity, or religious information) through this website.

We do not use personal data for automated decision-making or profiling.

4. Cookies and tracking technologies

We use cookies and similar tracking technologies on this website. Our cookie management platform (Cookiebot by Usercentrics) presents you with a consent banner on your first visit. Only strictly necessary cookies are placed without your consent.

Please see our separate Cookie Policy for full details of every cookie in use, their purpose, and how to manage your preferences.

5. How we use your data

Contact form enquiries are used solely to respond to you. We will not add you to any mailing list or share your contact details with third parties without your explicit consent.

Google Analytics data is used in aggregate to understand traffic and engagement patterns. No personally identifiable information is collected. IP addresses are anonymised.

Microsoft Clarity data is used to understand how visitors interact with pages (e.g. where they click, how far they scroll). Session recordings are used to identify usability issues. Sensitive content is masked by default and no form field content is recorded.

Cookiebot consent records are stored to evidence compliance with PECR and UK GDPR. They are not used for any other purpose.

6. Who we share your data with

We do not sell, rent, or trade personal data. We share data only with the following third-party processors, to the extent necessary to operate this website.

Google LLC (Google Analytics 4 and Google Tag Manager). We share website usage data with Google LLC, based in the USA, for the purposes of website analytics and tag management. Google Tag Manager controls when and how tracking scripts are deployed on our website. These transfers are governed by Google's Data Processing Terms and Standard Contractual Clauses with a UK Addendum.

Microsoft Corporation (Microsoft Clarity). We share behavioural analytics data with Microsoft Corporation, based in the USA, for the purpose of generating session recordings and heatmaps. This transfer is governed by Microsoft's Data Processing Agreement and Standard Contractual Clauses with a UK Addendum.

Usercentrics A/S (Cookiebot). We share consent records with Usercentrics A/S, based in Denmark, for the purpose of consent management and storing records of your consent decisions. Consent data is processed within the EU/EEA and is not transferred outside that region. This transfer is covered by EU/UK adequacy and a GDPR-compliant data processing agreement.

Website hosting provider. Your data passes through the servers of our website hosting provider as part of normal website operation. A data processing agreement is in place with our hosting provider. The country of processing is subject to the specific provider used.

We require all processors to handle your data securely and only for specified, documented purposes.

7. International data transfers

Google Analytics 4, Microsoft Clarity, and Google Tag Manager involve the transfer of personal data to the United States. These transfers are carried out under the Standard Contractual Clauses (SCCs) approved for use under UK GDPR, supplemented by a UK Addendum where required by the ICO. Cookiebot consent data is processed within the EU/EEA and is not transferred to the USA. We will not transfer personal data to countries outside the UK or EEA without ensuring adequate protections are in place.

8. How long we keep your data

Contact form enquiries are retained for 12 months from the date of last contact, to manage ongoing correspondence and for legitimate business record-keeping purposes.

Google Analytics data is retained for 2 years, in line with the standard Google Analytics 4 retention period.

Microsoft Clarity data, including session recordings and heatmaps, is retained for 1 year, in line with the standard Microsoft Clarity retention period.

Cookiebot consent records are retained for 6 months, as required to evidence consent decisions under PECR and UK GDPR.

After the relevant retention period, personal data is securely deleted or permanently anonymised.

9. Your rights under UK GDPR

You have the following rights in relation to your personal data:

Right of access — to request a copy of the personal data we hold about you.

Right to rectification — to ask us to correct inaccurate or incomplete data.

Right to erasure — to ask us to delete your personal data in certain circumstances.

Right to restriction — to ask us to restrict processing in certain circumstances.

Right to data portability — to receive your data in a structured, machine-readable format where processing is based on consent or contract.

Right to object — to object to processing based on legitimate interests.

Right to withdraw consent — you may withdraw consent for analytics and behavioural tracking at any time using the cookie settings icon on this website. Withdrawal does not affect the lawfulness of prior processing.

To exercise any of these rights, please contact us at contact@exarlis.com. We will respond within one calendar month. We may need to verify your identity before processing your request. There is no charge in most circumstances.

10. Consent management

We use Cookiebot by Usercentrics as our consent management platform (CMP). On your first visit, a cookie banner is displayed that allows you to accept or decline analytics and behavioural tracking cookies.

You can update your preferences at any time by clicking the cookie settings icon on this website. Your consent ID and the date of your consent decision are stored as a record of your choice.

Consent records are retained for 6 months in accordance with Cookiebot’s data retention settings.

11. Complaints

If you believe we have not handled your personal data correctly, you have the right to lodge a complaint with the UK’s supervisory authority: Information Commissioner’s Office (ICO). Website: ico.org.uk.

We would welcome the opportunity to address any concern directly before you contact the ICO. Please email contact@exarlis.com in the first instance.

12. Security

We take appropriate technical and organisational measures to protect your personal data, including: HTTPS encryption for all data transmitted to and from this website. Access controls limiting who within our organisation can access personal data. Use of reputable, GDPR-compliant third-party processors with data processing agreements in place.

No method of internet transmission is completely secure. While we take all reasonable steps, we cannot guarantee absolute security.

13. Third-party links

Our website may contain links to third-party websites. We are not responsible for their privacy practices and encourage you to review their privacy policies before providing personal data.

14. Children

Our services are directed at business professionals and are not intended for individuals under the age of 18. We do not knowingly collect personal data from children.

15. Changes to this policy

We may update this policy to reflect changes in our practices or legal requirements. Material changes will be indicated by an updated “Last updated” date at the top of this page. We encourage you to review this policy periodically.

16. Contact us

Exarlis Ltd. Registered address: 1259 London Road, C/O MCL Accountants, Leigh-on-Sea, Essex, SS9 2AF. Email: contact@exarlis.com. Company number: 16981902. ICO registration reference: ZC096677.

Take your next steps with confidence

exarlis logo

Independent. Assured. Accountable.

©2026 Exarlis®. All rights reserved.

contact@exarlis.com

Take your next steps with confidence

exarlis logo

Independent. Assured. Accountable.

©2026 Exarlis®. All rights reserved.

contact@exarlis.com

Take your next steps with confidence

exarlis logo

Independent. Assured. Accountable.

©2026 Exarlis®. All rights reserved.

contact@exarlis.com