Skip to content
Legal

Privacy Notice

How Coniq collects, uses, discloses and protects personal data, and the rights available to you.

Last Updated: 19th June, 2026

Applicability

This Privacy Notice (“Notice”) only applies when Coniq is the Controller of personal data (for example: Coniq website visitors’ personal data and business-to-business contact data).

Coniq is a Processor, not a Controller, of personal data that We process on behalf of Our Clients when they use Coniq products or Services. By way of context, Coniq operates a customer engagement and loyalty platform supplied to retailers, shopping centres, outlet destinations and mixed-use retail spaces. When Our Clients use Our platform to operate their loyalty programmes and engage with their own shoppers, those Clients determine the purposes and means of the processing and are the Controllers of the personal data concerned; Coniq processes that data solely on their documented instructions in its capacity as Processor. For clarity, this means that this Notice does not apply to Coniq products and Services.

If you have questions related to how a Coniq Client utilises your personal data, please contact the relevant Client (typically the shopping centre, retailer or programme operator with whom you have a direct loyalty or marketing relationship) directly. We are not responsible for the privacy or data security practices of Our Clients.

This Notice also does not apply to personal data about current and former Coniq employees, job candidates (see Our separate Recruitment Privacy Notice at https://www.coniq.com/recruitment-privacy-policy), or contractors and agents acting in similar roles.

Introduction

This Notice applies to Codilink UK Ltd t/a Coniq and its relevant Affiliates listed in Section 13 (“Codilink”, “Coniq”, “us”, “we”, or “our”). Capitalised terms that we use are not defined in the Notice (such as Site, Services, Client etc.) have the meaning provided in our Terms and Conditions. If you are located in the European Economic Area (“EEA”), Switzerland, or the United Kingdom (“UK”), please refer to Section 11 of this Notice for more information about which specific entity or entities act as a controller of your personal data.

When does this notice apply?: This Notice only applies to personal data that Coniq handles as a Controller (meaning where Coniq controls how and why your personal data is processed).

This includes when you:

  • Visit or interact with the Coniq.com Site, our branded social media pages, and other Sites which we operate (collectively, our “Digital Properties”);
  • Register for or participate in our webinars, events, programmes, marketing and promotional activities;
  • Interact with us in person, such as when you visit our offices; and
  • Inquire about or engage in commercial transactions with us, including as a prospective or existing business customer of our platform.

This Notice should be read together with Our Cookie Policy at https://www.coniq.com/cookie-policy, which sets out further detail about the cookies and similar technologies used on Our Digital Properties.

Changes: We may update this Notice from time to time. Where the changes are material, We will give you reasonable advance notice (for example, by prominent notice on the Site or, where appropriate, by email) before the changes take effect. The version in force at any time is the one published on Our Site, and We will record the “Last Updated” date on each version. Continued interaction with Us following the effective date of any change indicates that you have read and accept the revised Notice.

Personal Data We Collect and Disclose

The below table describes what personal data we collect about you and to whom we disclose personal data. Not every category will be collected in respect of every individual; what We collect depends on how you interact with Us. California individuals: This table includes the parties We disclose personal data to for a business or commercial purpose, as defined by California law.

Categories of Personal Data CollectedDisclosures of Personal Data
Identifiers, such as your name, email address, postal address, phone number, and device identifiers (e.g. advertising identifiers and IP address).• Affiliates and subsidiaries within the Coniq Group, which includes parent and ultimate holding companies, affiliates, subsidiaries, business units, and other companies that we acquire in the future after they are made part of the Coniq Group • Service providers, such as security and platform vendors • Third parties that are necessary to complete a transaction, such as credit card processors • Business partners who we partner with to jointly market or sell our products and Services, such as channel partners • Third parties at your direction, such as event sponsors • Professional advisors, such as lawyers, accountants, and auditors • Entities involved in a corporate transaction, including if we sell, acquire, or merge all or some of our assets • Companies that operate Cookies and Tracking Technologies, described in Section 6, such as marketing and advertising partners • Parties to whom you have consented to the disclosure
Commercial information, including preferences, such as purchasing history or tendencies and transactional information, such as banking information.• Affiliates and subsidiaries within the Coniq Group, which includes parent and ultimate holding companies, affiliates, subsidiaries, business units, and other companies that we acquire in the future after they are made part of the Coniq Group • Service providers, such as security and platform vendors • Third parties that are necessary to complete a transaction, such as credit card processors • Professional advisers, such as lawyers, accountants and auditors • Entities involved in a corporate transaction, including if we sell, acquire, or merge all or some of our assets • Parties to whom you have consented to the disclosure
Internet or other electronic network activity information and device information, such as your browsing history, search history, device information, and other information (whether passive browsing or active engagement) regarding your interactions with us and use of our products, Services, emails, and other Digital Properties.• Affiliates and subsidiaries within the Coniq Group, which includes parent and ultimate holding companies, affiliates, subsidiaries, business units, and other companies that we acquire in the future after they are made part of the Coniq Group • Service providers, such as security and platform vendors • Companies that operate Cookies and Tracking Technologies, described in Section 6, such as marketing and advertising partners • Entities involved in a corporate transaction, including if we sell, acquire, or merge all or some of our assets
Geolocation information, such as approximate location based on your IP address, mobile device location, or information you provide to us (such as city and state you provide through a web form). You may be able to control the collection of this data through the settings of your device.• Affiliates and subsidiaries within the Coniq Group, which includes parent and ultimate holding companies, affiliates, subsidiaries, business units, and other companies that we acquire in the future after they are made part of the Coniq Group • Service providers, such as security and platform vendors • Entities involved in a corporate transaction, including if we sell, acquire, or merge all or some of our assets • Companies that operate Cookies and Tracking Technologies, described in Section 6, such as marketing and advertising partners
Audio, electronic, visual, and other sensory information, such as CCTV recordings of Our premises (e.g. if you visit Our offices); recordings of your interactions with Our sales or advocacy teams (e.g. for quality assurance or training purposes, in accordance with applicable laws); or customer support chat or messaging logs.• Affiliates and subsidiaries within the Coniq Group, which includes parent and ultimate holding companies, affiliates, subsidiaries, business units, and other companies that we acquire in the future after they are made part of the Coniq Group • Service providers, such as security and platform vendors • Entities involved in a corporate transaction, including if we sell, acquire, or merge all or some of our assets
Inferences as defined by California law, such as marketing you are likely to react positively to.• Affiliates and subsidiaries within the Coniq Group, which includes parent and ultimate holding companies, affiliates, subsidiaries, business units, and other companies that we acquire in the future after they are made part of the Coniq Group • Service providers, such as platform vendors • Entities involved in a corporate transaction, including if we sell, acquire, or merge all or some of our assets
Sensitive Personal Data, such as race or ethnicity (optional) (where permissible under applicable law), and any special category data (as defined in Article 9 UK GDPR) that you chose voluntarily to disclose to us in connection with diversity, equality and inclusion initiatives or as required for accessibility or safeguarding purposes.• Affiliates and subsidiaries within the Coniq Group, which includes parent and ultimate holding companies, affiliates, subsidiaries, business units, and other companies that we acquire in the future after they are made part of the Coniq Group • Service providers, such as platform vendors • Entities involved in a corporate transaction, including if we sell, acquire, or merge all or some of our assets • Parties to whom you have consented to the disclosure

In addition to the above disclosures, we may share your personal data to respond to lawful requests by law enforcement or other government authorities in accordance with our Government Data Request Policy. We may also de-identify, anonymise, or aggregate personal data to use or share with third parties for any purpose, where legally permitted, on the basis that anonymised data is no longer personal data for the purposes of UK GDPR.

How We Process Personal Data

We may process your personal data for the following purposes. The legal bases on which We rely include those set out in Articles 6 and (where applicable) 9 UK GDPR, including the new “recognised legitimate interests” introduced by Schedule 4 to the Data (Use and Access) Act 2025 (the “DUAA 2025”).

Purpose of ProcessingLawful Basis
To provide Our products, Services, and Digital Properties to you, including processing and fulfilling transactions; enabling you to access the Digital Properties and our Services; operating, maintaining, and improving our Digital Properties and Services; communicating with you, such as by completing your support requests or providing security updates; and diagnosing, repairing, and tracking service and quality issues.Legitimate interests; Contract; Legal obligations
For our own business purposes, including maintaining internal business records and conducting internal reporting; collecting payments and performing accounting and similar business functions; auditing and managing projects related to our Services; performing IT security management and IT-related tasks, such as administration of our technologies and network; evaluating and improving our business, Services, and Digital Properties; and performing research and development of new products and services; and processing your survey and questionnaire responses.Legitimate interests; Legal obligations
For legal, safety, or security reasons, including to comply with legal requirements; establish, exercise, or defend against legal claims; protect the safety, security, and integrity of our property and the rights of those who interact with us or others; investigate any content or conduct policy violations; and detect, prevent, and respond to security incidents or other malicious, deceptive, fraudulent, or illegal activity.Legitimate interests; Legal obligations; Public interest; recognised legitimate interests (crime prevention and safeguarding) under Schedule 4 UK GDPR
For marketing our products and Services or those of third parties, such as our business partners, including soliciting or publishing testimonials or feedback about our products and Services; sending you marketing and promotional communications or product recommendations (via email, phone, or other online and offline channels) about our Services or those of third parties; facilitating your participation in a contest or event; assessing ad impressions or engage in contextual ad customisation. To manage your email preferences or unsubscribe from marketing communications, please use the link found at the bottom of any email you receive from us.Consent (where required by law); Legitimate interests; the “soft opt-in” under regulation 22(3) of the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“PECR”), where applicable
To fulfil a referral request when you use our referral service to tell a friend about our Services, including by using the name, email address, title, and company name that you provide us to contact the person you are referring. You must only provide others’ personal data if you have their consent to do so.Consent (where required by law); Legitimate interests
Diversity, equity, and inclusion, such as promoting diversity, equity, and inclusion initiatives and representation within our business (where authorised by applicable law).Consent (where required by law); Legitimate interests
Solely automated decision-making and profiling, only where lawfully permitted under Article 22A UK GDPR (substituted by section 80 of the DUAA 2025 with effect from 5th February 2026), and subject to the safeguards in Articles 22B to 22D UK GDPR, including the right to obtain meaningful information about the decision, to express your point of view, to contest the decision, and to obtain human intervention. We do not currently take any solely automated decisions producing legal or similarly significant effects in respect of your personal data; if this changes We will update this Notice.Consent or Contract (Article 22A UK GDPR); supplemented by the safeguards in Articles 22B–22D UK GDPR
Corporate transactions, such as sales, mergers, acquisitions, reorganisations, bankruptcy, and other corporate events.Legitimate interests; Legal obligations
When you have voluntarily agreed to have your personal data processed.Consent

Coniq will honour data subject rights to the extent required by law. You may have the right to access, correct, update, and, in some cases, request deletion of your personal data (subject to exceptions). Where you wish to exercise any of these rights, please use the contact details in Section 14, and We will respond within the statutory time limits. Under section 75 of the DUAA 2025, where a controller is required to take “reasonable and proportionate” searches in responding to certain requests, We may take that approach in determining what information to provide. You may submit a request via the form linked on Our Site or by emailing dataprotection@coniq.com.

Coniq uses a limited number of third-party service providers to assist Us in processing data for certain purposes. These third-party providers help support certain Site features, perform database monitoring and other technical operations, assist with data transmission, and provide data storage services. These third parties may process or store personal data while providing their services. Coniq maintains written contracts (incorporating the obligations required by Article 28 UK GDPR) with these third parties restricting their access, use and disclosure of personal data in compliance with Our obligations.

Sources of Personal Data

  • Information you provide to us directly, including when you register and communicate with us directly through our Digital Properties, visit our offices or participate in our events, marketing, and outreach activities (for example, when you request a demonstration of Our platform, attend a webinar, or download a white paper).
  • Information collected from your employer, colleagues, or friends, including information about representatives or other employees of our current, past, and prospective customers, suppliers, investors, and business partners. We may also receive your information from a friend as part of a referral for our Services.
  • Information automatically collected, including technical information about your interactions with our Digital Properties (such as IP address, browsing preferences, and purchase history). More information is available in Section 6 below and in our Cookie Notice.
  • Information from public sources, including information from public records and information you share in public forums, such as social media (and including sources such as Companies House, professional networking sites and publicly available business directories, used to qualify business contacts).
  • Information from other third parties, including information from third-party service and content providers, entities with whom we partner to sell or promote products and services, and social media networks (including widgets related to such networks, such as the “Facebook Like” button).

We may combine information that we receive from the various sources described in this Notice, including third-party sources and public sources, and use or disclose it for the purposes identified above, subject always to the legal bases on which We rely.

Cookies and Tracking Technologies

We use cookies and other tracking technologies and offer you the option to manage these settings as described in our Our Cookie Policy. Some tracking technologies enable Us to track your device activity over time and across devices and websites. Cookies which are not strictly necessary are set only after you have given your consent through Our cookie banner, in accordance with regulation 6 of PECR (as amended by section 122 of the DUAA 2025 with effect from 5th February 2026). While some browsers have incorporated Do Not Track (“DNT”) preferences, there is no established industry standard for how those signals should be interpreted, and We therefore do not currently honour DNT signals; We do, however, honour validly transmitted Global Privacy Control (“GPC”) signals and equivalent opt-out preference signals to the extent required by applicable law.

Security and Retention

We maintain appropriate security procedures and technical and organisational measures as required by Article 32 UK GDPR, to protect your personal data against accidental or unlawful destruction, loss, unauthorised disclosure, alteration, or use. As evidence of the maturity of Our information security programme, Coniq has obtained a SOC 2 Type II attestation covering the security, availability, processing integrity, confidentiality and privacy trust services criteria. A summary of Our information security programme is available on request.

Your personal data will generally be retained as long as necessary to fulfil the purposes for which We collected the personal data. Once you and/or your company has terminated the contractual relationship with Us or otherwise ended your relationship with Us, We may retain your personal data in Our systems and records to ensure adequate fulfilment of surviving provisions in terminated contracts or for other legitimate business purposes, such as to evidence Our business practices and contractual obligations, to provide you with information about Our products and services, or to comply with applicable legal, tax, or accounting requirements. When We have no ongoing legitimate business need nor lawful basis to process your personal data, We will delete, anonymise, or aggregate it or, if this is not possible (for example, because your personal data has been stored in backup archives), then We will securely store your personal data and isolate it from any further processing until deletion is possible.

Indicative retention periods. Marketing contact records: up to 24 months after last meaningful interaction. Webinar and event records: up to 36 months. Business contract records: for the duration of the contract and up to 7 years following termination, to comply with statutory accounting and limitation periods. These periods are indicative of Our current practice and (save where a specific statutory retention obligation applies, for example to tax and accounting records under the Companies Act 2006) are not legally prescribed minimums. If you want to know more about retention periods applicable to your particular circumstance, please contact us using the details provided in Section 14 below.

Children’s Privacy

Our Sites and Services are not directed to children under the age of 18 (or, where the UK GDPR or applicable local law permits a lower age in relation to information society services, the age applicable in the relevant jurisdiction), and We do not knowingly collect online personal data directly from children. Our platform is supplied to corporate clients on a business-to-business basis and is not intended to be used by children. Where Our Clients deploy Our platform for loyalty programmes that may be used by children, the relevant Client is the Controller and is responsible for any additional safeguards required by the UK GDPR (including, as relevant, the provisions on children’s data introduced by the DUAA 2025) and by the Information Commissioner’s Age Appropriate Design Code. If you are a parent or guardian of a minor child and believe that the child has disclosed online personal data to us, please contact us using the details provided in Section 14 below, and We will take appropriate steps to delete or restrict the relevant data.

External Links

When interacting with us, you may encounter links to external sites or other online services, including those embedded in third-party advertisements. We do not control and are not responsible for privacy and data collection policies for such third-party sites and services. You should consult such third parties and their respective privacy notices for more information or if you have any questions about their practices.

Supplemental Terms for California Residents

Pursuant to the California Consumer Privacy Act (“CCPA”), this Section 10 applies to certain personal data collected about California individuals where Coniq controls how and why the personal data is processed (which the CCPA calls a “business”) and supplements the rest of our Notice above. This Section 10 does not apply to current or former employees, applicants, contractors, or agents.

Additional Data Processing Disclosures:

The below table provides the categories of personal data we have sold, shared, or disclosed to third parties, as defined by the California Privacy Rights Act. For reference, the table in Section 3 provides the categories of personal data collected and our disclosures of personal data.

Categories of Personal Data We CollectCalifornia Privacy Rights Act Details: Categories of Third Parties to Whom Personal Data is “Sold or Shared”
Identifiers• Companies that operate Cookies and Tracking Technologies, described in Section 6, such as marketing and advertising partners. • Business partners who we partner with to jointly market or sell our products and Services, such as channel partners.
Commercial information• Not applicable
Internet or other electronic network activity information and device information• Companies that operate Cookies and Tracking Technologies, described in Section 6, such as marketing and advertising partners.
Geolocation information• Companies that operate Cookies and Tracking Technologies, described in Section 6, such as marketing and advertising partners.
Audio, electronic, visual, and other sensory information• Not applicable
Inferences as defined by California law• Not applicable
Sensitive Personal Data• Not applicable

Although we have not “sold” or “shared” personal data for money in the past 12 months, we engage in routine practices with our Digital Properties involving third parties that could be considered a “sale” or “sharing” as defined under California law. We do not knowingly sell or share any personal data of minors under the age of 16. We do not collect or process “sensitive personal information”, as defined by California law, to infer characteristics about you. Coniq only uses sensitive personal information consistent with the exceptions to the right to limit sensitive personal information.

Financial Incentives: We may offer a benefit or offering in exchange for you providing personal data, such as a discount or coupon to individuals who respond to a survey. As part of these surveys, we may collect personal data, such as your name, contact information, preferences, experiences, beliefs, opinions, and other responses to the survey questions. Participation in surveys is governed by the applicable terms and conditions for the survey, which will describe any financial incentives associated with that survey and how to participate. The value of your data is the value of the offer presented to you. We have calculated such value by using the expense related to the benefit. You may withdraw from any financial incentive at any time by emailing us at dataprotection@coniq.com. If we offer another type of financial incentive, we will share with you the material terms of each offer when we ask you to participate.

Your Data Protection Rights:

Subject to legal limitations, certain California residents may have the below rights.

  • Right to Know. You have the right to request information about the categories of personal data we have collected about you, the categories of sources from which we collected the personal data, the purposes for collecting the personal data, the categories of third parties to whom we have disclosed your personal data and the purpose for which we disclosed your personal data (“Categories Report”). You may also request information about the specific pieces of personal data we have collected about you (“Specific Pieces Report”).
  • Right to Delete. You have the right to request that we delete personal data that we have collected from you.
  • Right to Correct. You have the right to request that we correct inaccurate personal data that we maintain about you.
  • Right to Opt-Out of Sale or Sharing. We do not sell personal data to third parties in exchange for money. However, as we explain in Section 6, we share information with advertising partners and allow advertising partners to collect information from our Digital Properties. This exchange may be considered a “sale” or “sharing” under California law, and you have the right to opt out of this “sale” or “sharing” of personal data.

California residents may request to exercise the Right to Know, the Right to Delete, and the Right to Correct by emailing us at dataprotection@coniq.com or by submitting your request at https://share-eu1.hsforms.com/2kG3LLLTITcmIUPLfO9esNg2cgv1o. We will not discriminate against you in any manner prohibited by applicable law for exercising these rights.

How to Fully Exercise the Right to Opt-Out of Sale or Sharing: To fully exercise the Right to Opt-Out of Sale or Sharing with respect to any “sale” or “sharing” of information, you must undertake both of the following steps:

  • Submit a Right to Opt-Out of Sale or Sharing request by emailing us at dataprotection@coniq.com.
  • Disable the use of advertising cookies and other tracking technologies by clicking the “Do Not Sell or Share My Personal Information” link in our website footer. You must complete this step on each of our Sites from each browser and on each device that you use. These steps are necessary so that we can place a first-party cookie signalling that you have opted out on each browser and each device you use.

If you block cookies, we will be unable to comply with your Right to Opt-Out of Sale or Sharing requests for device data that we automatically collect and disclose to third parties online using cookies, pixels, and other tracking technologies. If you clear the cookies in your browser, you will need to follow Step 2 above again. To the extent required by California law, we will honour “Do Not Sell or Share” opt-out preference signals sent in a format commonly used and recognised by businesses at the browser level, such as an HTTP header field or JavaScript object.

Verification: To process California data protection requests, we will need to obtain information to locate you in our records or verify your identity, depending on the nature of the request. In most cases, we will request information about you, which may include your name, email address, or other information. If you submit a Right to Know “Specific Pieces Report”, we may also request a signed declaration, under penalty of perjury, that you are who you say you are. We may request alternative information under certain circumstances and/or use third parties to help verify your identity.

Authorised Agents: Authorised agents may exercise California data protection rights on behalf of California individuals, but we reserve the right to verify the individual’s identity directly as described above. Authorised agents must contact us by submitting a request through our web form and indicate that they are submitting the request as an agent. We may require the agent to demonstrate authority to act on your behalf by providing signed permission from you. We may also require you to verify your own identity directly with us or to directly confirm with us that you provided the authorised agent permission to submit the request.

Timing: We will process Right to Opt Out of Sale or Sharing requests within fifteen business days from the date received. We will respond to Requests to Delete and Requests to Know within forty-five days unless we need more time, in which case we will notify you, and it may take up to ninety days to respond to your request.

Supplemental Information for the EEA, Switzerland, and the UK

The following terms supplement the Notice with respect to our processing of EEA (i.e. European Union Member States, Iceland, Liechtenstein, and Norway), Swiss, and UK personal data. In the event of any conflict or inconsistency between the other parts of the Notice and the terms of this Section 11, Section 11 shall govern and prevail with regard to the processing of EEA, Swiss, and UK Personal Data, to the extent applicable.

Data Controller: The Coniq entity with which you have a primary relationship (such as the entity that concluded the Services contract with you; the entity that has provided you with marketing materials and promotional communications; or the primary entity in the region where you access our Site) is the controller within the scope of this Notice. In the majority of cases, this will be Codilink UK Ltd (trading as Coniq), a company registered in England and Wales under company number 06269999, whose registered office is at 2 Communications Road, Greenham Business Park, Newbury, Berkshire RG19 6AB, with its principal office and contact address for the purposes of this Notice at 140 Goswell Road, London EC1V 7DY, unless We specifically inform you otherwise.

Legal Basis for Processing: Please see Section 4 for the legal basis on which We rely for the collection, processing, and use of personal data, which We have updated to reflect the “recognised legitimate interests” introduced by the DUAA 2025.

Your Data Protection Rights:

Under applicable data protection laws, you may exercise certain rights regarding your personal data:

  • Right to Access. You have the right to obtain confirmation from us whether we are processing your personal data and related information, as well as the right to obtain a copy of your personal data undergoing processing.
  • Right to Data Portability. You may receive your personal data, that you have provided to us, in a structured, commonly used, and machine-readable format, and you may have the right to transmit it to other data controllers without hindrance. This right only exists if the processing is based on your consent or a contract, and the processing is carried out by automated means.
  • Right to Rectification. You have the right to request the rectification of inaccurate personal data and to have incomplete data completed.
  • Right to Objection. You have the right to object to the processing of your personal data in certain cases.
  • Right to Restrict Processing. You may request that we restrict the processing of your personal data in certain cases.
  • Right to Erasure. You may request that we erase your personal data in certain cases.
  • Right to Lodge a Complaint. You have the right to lodge a complaint with a supervisory authority. In the UK, the supervisory authority is the Information Commission (the statutory successor to the Information Commissioner’s Office under Part 6 of the DUAA 2025); contact details are set out below. Under section 162 of the DUAA 2025 We encourage you, where reasonably practicable, to raise your concern with Us first so that We have the opportunity to resolve it before you complain to the supervisory authority. We commit to co-operate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs) and the UK Information Commission with regard to unresolved complaints concerning Our handling of personal data received.
  • Right to Refuse or Withdraw Consent. In case we ask for your consent to process your personal data, you are free to refuse to give it. If you have given your consent, you may withdraw it at any time without any adverse consequences. The lawfulness of any processing of your personal data that occurred prior to the withdrawal of your consent will not be affected.
  • Right to Not Be Subject to Automated Decision-making and Profiling. For UK individuals, Articles 22A to 22D UK GDPR (as substituted by section 80 of the DUAA 2025 with effect from 5th February 2026) provide a revised framework for solely automated decision-making and profiling. We do not currently take any decisions about you that (i) are based solely on automated processing (including profiling) and (ii) produce legal effects concerning you or similarly significantly affect you. Should this change, We will only do so where permitted by Article 22A UK GDPR (typically on the basis of your explicit consent, where necessary for entering into or performing a contract with you, or where authorised by law), and We will apply the safeguards required by Articles 22B to 22D UK GDPR, including providing meaningful information about the decision, enabling you to express your point of view, to contest the decision, and to obtain human intervention. For EEA and Swiss individuals, the equivalent rights under Article 22 EU GDPR and applicable Swiss law continue to apply.

You may exercise these rights by contacting us using the details provided in Section 14 above. Please note that we may refuse to act on requests to exercise data protection rights in certain cases, such as where providing access might infringe someone else’s privacy rights or impact our legal obligations, or where the request is manifestly unfounded or excessive; in any such case We will explain Our reasons and, where applicable, your right to complain to the Information Commission or other relevant supervisory authority.

International Transfers of Personal Data:

Due to the global nature of our operations, some of the recipients mentioned in Section 3 of the Notice may be located in countries outside the EEA, Switzerland, or the UK, which do not provide an adequate level of data protection as defined by data protection laws in the EEA, Switzerland, and the UK. Transfers within the Coniq Group or to third parties located in such third countries take place using a valid data transfer mechanism, such as the EU Standard Contractual Clauses and/or the UK Addendum to such clauses (or the UK International Data Transfer Agreement), approved codes of conduct and certification mechanisms, on the basis of permissible statutory derogations, or any other valid data transfer mechanism issued or approved by the EEA, Swiss, or UK authorities. For UK transfers, Our transfer assessments take account of the “data protection test” as set out in section 6 of the DUAA 2025 (which amends section 17A of, and inserts new Schedule 21 to, the Data Protection Act 2018), as well as guidance from the Information Commission.

Certain third countries have been officially recognised by the EEA, Swiss, and UK authorities as providing an adequate level of protection and no further safeguards are necessary. Please reach out to us using the contact information in Section 14 below, if you wish to receive further information about how we transfer personal data or, where available, a copy of the relevant data transfer mechanism.

Data Protection Officer / Privacy Contact: The contact details for our data protection officer are as follows: dataprotection@coniq.com, Codilink t/a Coniq, Attn: Head of Information Security, 140 Goswell Rd., London EC1V 7DY. Coniq is not required by Article 37 UK GDPR to appoint a statutory Data Protection Officer; the Head of Information Security acts as Our nominated privacy contact.

The Information Commission (the statutory successor to the Information Commissioner’s Office under Part 6 of the DUAA 2025) can be contacted:

  • By Post: Information Commissioners Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
  • By Website: https://ico.org.uk/concerns/complaints-and-compliments-about-us/
  • By Email: casework@ico.org.uk
  • By Phone: 0303 123 1113 (Local rate) or 01625 545 745 (National rate)

References in this Notice to the “ICO” or the “Information Commissioner’s Office” should be read, on and from the operative date of the relevant provisions of Part 6 of the DUAA 2025, as references to the Information Commission as the statutory successor.

Supplemental Information for Other Regions

  • Canada: Personal data, as defined in the Personal Information Protection and Electronic Documents Act (“PIPEDA”) and, where applicable, in Quebec’s Act respecting the protection of personal information in the private sector, will be collected, stored, used, and/or processed by the Coniq Group in accordance with the Coniq Group’s obligations under PIPEDA and any other applicable Canadian data protection legislation.
  • Nevada: We do not presently sell personal data as defined under Nevada law. If you are a Nevada resident, you may nevertheless email us using the information above to exercise your right to opt-out of sale under Nevada Revised Statutes §603A et seq.
  • United Kingdom: Personal data collected, stored, used, and/or processed by the Coniq Group, as described in this Privacy Notice, is collected, stored, used, and/or processed in accordance with UK GDPR (being Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland and Northern Ireland), the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“PECR”), and the Data (Use and Access) Act 2025, in each case as amended or replaced from time to time.

Coniq Affiliates

The members of the Coniq Group at the date of this Notice are as follows. The relevant Controller for the purposes of this Notice is identified by reference to your primary relationship with Coniq (see Section 11).

  • Codilink UK Ltd (trading as Coniq), registered in England and Wales under company number 06269999; registered office at 2 Communications Road, Greenham Business Park, Newbury, Berkshire RG19 6AB; principal office at 140 Goswell Road, London EC1V 7DY
  • Codilink DOOEL Skopje, registered in North Macedonia
  • Codilink FZE, registered in the United Arab Emirates
  • Codilink SL, registered in Spain
  • Coniq Inc, registered in the United States

Contact Information

If you have questions or complaints regarding this Notice or about the Coniq Group’s privacy practices, please contact us by email at dataprotection@coniq.com or via post to:

Codilink UK Ltd t/a Coniq, Attn: Head of Information Security, 140 Goswell Rd., London EC1V 7DY.

If you are dissatisfied with Our response, you have the right to lodge a complaint with the Information Commission (or, if you are located in the EEA or Switzerland, the supervisory authority in your country of residence).