Privacy Policy

Last Updated: 19 April 2026

InsightCTO is a trading name of BeWell IT Limited ("we", "our", "us", or "InsightCTO"), a company registered in England and Wales (company number 16095961). We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, and protect information when you visit our website at insightcto.com (the "Website").

Scope: This privacy policy applies only to the insightcto.com website. It does not cover any BeWell IT Limited applications, platforms, or other products, which are governed by their own privacy policies.

1. Information We Collect

Information you provide to us:

  • Contact enquiries: If you email us via any of the contact links on our Website, we receive your email address and any information you include in your message

We do not operate an email mailing list, sell products or collect email subscriptions through the Website, or use web forms. All contact with us is via direct email.

Information collected automatically:

  • Hosting analytics: Our Website is hosted on Google Firebase Hosting, which may automatically collect basic access logs including IP addresses, browser type, referring pages, and pages visited. This data is collected by Google as part of standard hosting operations
  • Website analytics: We use Google Analytics 4 in cookieless mode (no tracking cookies are set). This collects anonymised data including pages visited, approximate geographic region (country-level, derived from IP address), device type, and referral source. No personally identifiable information is collected, and no data is shared with advertisers. This data helps us understand how visitors use our Website so we can improve it
  • Device information: Browser type, operating system, and screen resolution for the purpose of serving the Website correctly

Cookies:

We do not set any cookies on our Website. Our Google Analytics 4 integration operates in cookieless mode, meaning no cookies, local storage, or browser identifiers are used for analytics. Because no cookies are set, no cookie consent banner is required under UK PECR.

Information we do NOT collect:

  • We do not use social media tracking pixels, ad networks, or retargeting
  • We do not engage in cross-site tracking
  • We do not collect financial or payment information through the Website
  • We do not use contact forms. All communication is via direct email

2. How We Use Your Information

We use the information we collect to:

  • Respond to your enquiries and provide information about our services
  • Maintain and improve our Website
  • Comply with legal obligations

We do not carry out automated decision-making or profiling that produces legal or similarly significant effects. We do not sell, rent, or trade your personal data to third parties for any purpose.

3. Legal Basis for Processing (UK GDPR)

We process your personal data based on:

  • Legitimate interests: For responding to email enquiries you send us (it is in our legitimate interest to communicate with and respond to people who contact us), and for Website hosting, security, and service improvement, including the use of cookieless analytics to understand Website performance
  • Consent: Where you specifically ask us to do something requiring your consent (for example, if you ask to be added to future communications)
  • Legal obligations: For compliance with applicable laws

4. Data Storage and Security

  • Our Website is hosted on Google Firebase Hosting, which provides encrypted connections (HTTPS) for all visitors
  • Email communications are handled through Google Workspace with industry-standard security
  • We do not store personal data in databases accessed through the Website
  • In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of it, and affected individuals without undue delay, as required by UK GDPR Articles 33 and 34

5. Third-Party Services

Our Website uses the following third-party services, each of which acts as a data processor on our behalf:

  • Website hosting and content delivery infrastructure, provided by Google Firebase Hosting
  • Cookieless website analytics with no persistent identifiers, provided by Google Analytics 4. See the Google Privacy Policy
  • Email processing for our contact addresses (stephan@insightcto.com, privacy@insightcto.com), provided by Google Workspace. See the Google Privacy Policy
  • Typography using the DM Sans and Instrument Serif typefaces, provided by Google Fonts (which may log your IP address when fonts are loaded). See the Google Fonts Privacy notice

We do not use social pixels, ad networks, or retargeting services. Our Website links to external services (for example, LinkedIn and bewellit.com). These services have their own privacy policies which we encourage you to review.

6. International Data Transfers

Our Website is hosted on Google's global infrastructure, and our analytics and email processing are provided by Google LLC. Your data may be transferred to and processed in countries outside the UK/EEA, including the United States. We ensure appropriate safeguards through:

  • The UK Extension to the EU-US Data Privacy Framework, under which Google LLC is self-certified, for transfers of personal data to the United States
  • The UK International Data Transfer Agreement (IDTA) or the UK Addendum to EU Standard Contractual Clauses, where the Data Privacy Framework does not apply
  • Technical security measures including encryption in transit and at rest

7. Data Retention

  • Email correspondence: Retained for as long as necessary to resolve your enquiry, then for up to 2 years for record-keeping
  • Hosting logs: Retained by Google Firebase in accordance with their data retention policies
  • Analytics data: Retained by Google Analytics in accordance with the configured retention period (default 14 months)

8. Your Rights

Under UK GDPR and applicable privacy laws, you have the right to:

  • Access any personal data we hold about you
  • Rectify inaccurate data
  • Erase your data ("right to be forgotten")
  • Restrict processing of your data
  • Object to certain processing activities
  • Data portability: receive your data in a portable format
  • Withdraw consent at any time
  • Lodge a complaint with the Information Commissioner's Office (ICO)

To exercise any of these rights, including withdrawing consent at any time, email privacy@insightcto.com with "Privacy Rights Request" in the subject line. Withdrawal of consent will not affect the lawfulness of processing carried out before withdrawal.

9. California Privacy Rights

California residents have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to know what personal information is collected
  • Right to delete personal information
  • Right to opt-out of the sale of personal information (we do not sell personal data)
  • Right to non-discrimination for exercising privacy rights

10. Intended Audience

Our Website is intended for adult business users (aged 18 or over) evaluating professional services. It is not directed at children, and we do not knowingly collect personal information from anyone under 18.

11. Links to External Services

Our Website contains links to external websites and services, including bewellit.com, LinkedIn, YouTube, and app store pages. We are not responsible for the privacy practices of these external services. We encourage you to review their privacy policies.

12. Updates to This Policy

We may update this Privacy Policy from time to time. When we make changes:

  • The "Last Updated" date will be revised
  • For material changes, we will update this page prominently
  • Your continued use of the Website after changes constitutes acceptance

13. Contact Information

For questions or concerns about this Privacy Policy:

You can reach the data controller at:

BeWell IT Limited (trading as InsightCTO)
The Data Controller
68 Queens Road
Feltham TW13 5AR
United Kingdom

Email: privacy@insightcto.com

For general enquiries, email stephan@insightcto.com.

Company No: 16095961, registered in England and Wales.

14. Complaints

If you have concerns about how we handle your data, you have the right to lodge a complaint with:

UK Information Commissioner's Office (ICO)
Website: ico.org.uk
Phone: 0303 123 1113

15. Governing Law

This Privacy Policy is governed by the laws of England and Wales. Any disputes shall be subject to the exclusive jurisdiction of the courts of England and Wales, without limiting any rights or protections provided under applicable privacy laws in your jurisdiction.