Legal
Privacy policy
How Quo Vadis CCS Ltd collects, uses, shares and protects personal data, and the choices and rights you have.
1. Who we are
This website, www.qvccs.com, is operated by Quo Vadis CCS Limited ("QVCCS", "we", "us", "our"), a private limited company registered in England and Wales under company number 14685379, with its registered office at Savoy House, Savoy Circus, London, W3 7DA, United Kingdom.
For the personal data described in this policy, QVCCS is the controller under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We also comply with the Privacy and Electronic Communications Regulations 2003 (PECR), each as amended, including by the Data (Use and Access) Act 2025. Where we process the personal data of individuals in the European Economic Area, we apply the equivalent protections of the EU GDPR.
You can contact us about privacy at enquiries@qvccs.com, by telephone on +44 (0)20 4620 3200, or by post to our registered office, marked "For the attention of: Data Protection".
2. Scope of this policy
This policy applies to:
- visitors to this website;
- people who contact us by telephone, email or social media, or who meet us at events;
- business contacts at our clients, prospective clients, systems integrator and technology partners, and suppliers;
- people who apply to work with us.
Client data in our professional services work. When we design, build, test, support or monitor a Genesys Cloud CX solution, we may have access to personal data held in our client's systems. In that work we act as a processor (or sub-processor) on our client's instructions, under the data processing terms in our contract with them, and the client's own privacy notice applies. This policy does not cover that processing. Please contact the organisation concerned if you have questions about it.
3. The personal data we collect
Information you give us
- Identity and contact details: your name, job title, employer, business email address, telephone number and postal address.
- Enquiry and correspondence: the content of your calls, emails and messages, including what you tell us about your requirements, and records of meetings, workshops and demonstrations.
- Commercial information: information needed to prepare proposals, contracts, purchase orders and invoices, and to manage our relationship with your organisation.
- Recruitment information: your CV, work history, qualifications and certifications, references and right-to-work information, if you apply to work with us.
Information collected automatically
- Technical and server log data: when you visit the site, our hosting provider records standard information such as IP address, browser type, the pages requested and the date and time. This is used only to deliver, secure and troubleshoot the site. Nothing else is collected automatically: the site sets no cookies and runs no analytics or tracking tools (see section 5).
Information from other sources
- Business contact details shared with us by your colleagues, or by partners such as Genesys and systems integrators, when they introduce you to us for a specific engagement.
- Information you have made public in a professional context, such as on LinkedIn or a company website, used only to understand your role in a matter you or your organisation are already engaged with us on. We never use it to approach you unprompted.
This website has no forms and no user accounts, and it does not ask for payment details. We do not knowingly collect special category data, such as health or ethnicity, except where you volunteer it, for example to tell us about adjustments you need during recruitment. In that case we use it only for that purpose.
4. How we use it and our lawful bases
| Purpose | Lawful basis (UK GDPR Article 6) |
|---|---|
| Responding to your enquiries, arranging calls, workshops and demonstrations | Legitimate interests (responding to people who contact us) or, where you are acting for a prospective client, steps prior to entering into a contract |
| Preparing proposals and delivering, managing and supporting our services | Performance of a contract, or legitimate interests where the contract is with your employer |
| Supplier and partner management, accounting, invoicing and record keeping | Legal obligation, and legitimate interests (running our business) |
| Operating, securing and troubleshooting the website, including server logs | Legitimate interests (providing a secure, reliable site) |
| Recruitment and assessing applications | Steps prior to entering into a contract, legitimate interests and legal obligation (right-to-work checks) |
| Complying with law, responding to lawful requests, and establishing or defending legal claims | Legal obligation and legitimate interests |
These are the only purposes for which we use personal data. We do not use it for marketing of any kind (see section 6). Where we rely on legitimate interests, we have balanced our interests against your rights and expectations. You can ask us for more information about that assessment. We do not sell personal data, we do not use it for profiling that has legal or similarly significant effects, and we make no decisions about you by automated means alone.
5. No cookies, analytics or tracking
This website sets no cookies and stores nothing on your device. It uses no local storage, session storage or any similar technology, so there is no cookie banner and nothing to accept or decline.
The site runs no analytics, tracking, advertising, marketing or webmaster tools of any kind. That means no Google Analytics, no Google Search Console or Bing Webmaster Tools verification, no Microsoft Clarity, no Cloudflare Web Analytics, no session recording or heatmaps, no tracking pixels, no social media plugins and no remarketing. We do not fingerprint your browser or follow you across other websites.
Every page, font, image and script is served from our own domain, and the site loads nothing from third parties. Our security headers enforce this, so a third-party script could not run on the site even if one were added by mistake. Site search runs entirely in your browser, and what you type is never sent to us or anyone else.
The only record of a visit is the standard server log described in section 3, which we use only to deliver, secure and troubleshoot the site.
6. Our commitment: no marketing
QVCCS does not carry out direct marketing. This is a deliberate company policy, not a setting you have to find and switch off. We stand on our own merit: on word of mouth, on our record of delivery and on long-standing, trusted relationships with our clients and partners. We do not believe that typical marketing techniques, such as mailing lists, newsletters, cold calls, sales campaigns and online advertising, are the right way to build those relationships, and we do not use them.
We use your personal data only:
- to deal with the matter you contacted us about;
- to deliver and render our services, and to support our engagements; and
- to run our business legitimately, including meeting our legal, accounting and contractual obligations.
In particular, we commit that we will never:
- send marketing emails, newsletters, mailshots or promotional messages, by email, text message, post, social media or any other channel;
- make cold calls, or otherwise contact people who have not asked to hear from us;
- add your details to a mailing list, sales pipeline or campaign;
- sell, rent, trade, lend or share personal data with anyone for their marketing, or buy, rent or use marketing lists;
- use personal data for advertising, retargeting, advertising audiences, lead scoring or marketing profiling; or
- collect personal data for any purpose beyond the immediate and legitimate business purposes described in this policy.
Introductions. The only time we contact someone for the first time is when a client, partner or systems integrator has introduced us, and the introduction is warm and expected by the person concerned before we make contact. We then contact you only about the specific matter of that introduction.
Service communications are not marketing. Messages that form part of a service your organisation has contracted with us, such as incident and change notifications, service reviews and the weekly Genesys release-notes briefing included in our Silver, Gold and Diamond Managed Professional Services tiers, are part of delivering that service. They go only to the people your organisation nominates, and only for as long as the service runs.
Asking us a question, attending a workshop or demonstration, or working with us on a project never adds you to any list. This website carries no advertising and runs no analytics, remarketing or tracking of any kind (see section 5).
If you ever receive what appears to be marketing from QVCCS, it was not sent with our authority. Please tell us at enquiries@qvccs.com so that we can investigate.
7. Applying to work with us
This section explains how we handle personal data when you apply for a role with QVCCS, whether for an advertised position or speculatively, by emailing careers@qvccs.com as described on our Careers page.
What we collect
- At application: what you send us, typically your CV or résumé, covering note, contact details, employment history, qualifications, certifications and the evidence you provide of your skills and experience, together with your confirmation that you meet our eligibility requirements.
- During assessment: our notes and scores from reviewing your application and from interviews, and our correspondence with you.
- At offer stage only: the documents needed for the statutory right-to-work check, references, your National Insurance number, and the information needed for pre-employment screening to the Baseline Personnel Security Standard (BPSS), which includes a basic criminal record check. Where a client role requires UK Security Check (SC) clearance, the information that the clearance process requires.
Please do not send identity documents, right-to-work documents or sensitive personal information with your application. We will ask for what we need, securely, at offer stage.
Why we use it and our lawful bases
- To assess your application and decide whether to offer you a role: steps taken at your request before entering into a contract of employment, and our legitimate interests in recruiting suitably skilled people.
- To check your right to work in the UK: to comply with our legal obligations.
- For BPSS screening and, where required, security clearance: our legitimate interests and those of our clients in the security of the systems we work on. Criminal offence data is processed only where the Data Protection Act 2018 permits it in connection with employment.
- To make reasonable adjustments: to comply with our obligations under the Equality Act 2010. We use any health information you choose to share only for that purpose.
Who sees it and how long we keep it
Your application is seen only by the people involved in assessing it, typically the Managing Director, the Head of Professional Services and the relevant team leader. At offer stage we share information with your referees and, for screening or clearance, with the organisations that carry out those checks. We do not use automated decision-making to assess applications.
If your application is unsuccessful, or you apply speculatively, we keep it for up to 12 months and then securely delete it. You can ask us to delete it sooner at any time.
Talent pool. If you opt in, as described on our Careers page, we keep your application for up to 24 months and may contact you about relevant roles at QVCCS. Our lawful basis is your consent, which you can withdraw at any time by emailing careers@qvccs.com; we will then delete your application. We never use talent pool details for any other purpose.
If you join us, your recruitment records become part of your employee record, and copies of right-to-work documents are kept for the duration of your employment and for two years afterwards, as Home Office guidance requires.
8. Who we share it with
We share personal data only where necessary, and only with:
- Our service providers (processors). These include website hosting, email and productivity tools, our customer relationship management (CRM) system, IT support and security, and accounting. They act on our instructions under written contracts that require confidentiality and appropriate security.
- Genesys and systems integrator partners. We share with them only where needed to deliver or support an engagement you or your organisation are involved in, for example to raise a support case or coordinate a joint project.
- Professional advisers, such as lawyers, accountants, auditors and insurers, under a duty of confidentiality.
- Authorities and regulators, where we are legally required to, or to protect the rights, property or safety of QVCCS, our clients or others.
- A buyer or successor, if all or part of our business is reorganised, sold or transferred. Your data would remain protected in line with this policy.
We never sell, rent or trade personal data, and we never buy marketing lists.
9. International transfers
Some of our service providers, such as our email and productivity provider, may process data outside the UK, notably in the United States. Where personal data leaves the UK, we make sure it is protected by one of the following:
- UK adequacy regulations, including the UK Extension to the EU–US Data Privacy Framework for certified US organisations;
- the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses;
- another transfer mechanism the law allows.
Where needed, these are supported by a transfer risk assessment. You can ask us for details of the safeguards for a particular transfer.
10. How long we keep it
| Data | Retention |
|---|---|
| General enquiries that do not lead to an engagement | Up to 2 years from our last contact |
| Client, partner and supplier contact and contract records | The life of the relationship plus 6 years, in line with the limitation period for contract claims |
| Financial and tax records | 6 years from the end of the financial year they relate to |
| Unsuccessful and speculative job applications | Up to 12 months, or up to 24 months if you join our talent pool (see section 7) |
| Website server logs | Typically up to 90 days, unless needed to investigate a security incident |
When data is no longer needed, we securely delete it or anonymise it.
11. How we protect it
We protect personal data with technical and organisational measures appropriate to the risk. These include:
- access restricted to people who need it, with multi-factor authentication and least-privilege permissions;
- encryption in transit, and at rest where our providers support it;
- a hardened, static website served only over HTTPS, with strict security headers and no server-side code to attack;
- confidentiality obligations for everyone at QVCCS;
- due diligence on our service providers.
The same professional disciplines we apply to clients' Genesys Cloud CX solutions apply to our own systems. If a personal data breach occurs, we will assess it promptly. Where the law requires, we will notify the Information Commissioner's Office within 72 hours and tell affected individuals without undue delay.
12. Your rights
Under UK data protection law you have the right to:
- access your personal data and receive a copy;
- rectification of inaccurate or incomplete data;
- erasure of your data in certain circumstances;
- restrict how we use your data in certain circumstances;
- object to processing based on legitimate interests, and to direct marketing at any time (an absolute right). Because QVCCS does not carry out direct marketing, this right never needs to arise with us, but it remains yours;
- data portability for data you gave us, where processing is based on consent or contract and carried out by automated means;
- withdraw consent at any time, where we rely on it (for example, for our talent pool), without affecting processing that took place before you withdrew it;
- not be subject to decisions based solely on automated processing that have legal or similarly significant effects. We do not make such decisions.
To exercise any right, contact us at enquiries@qvccs.com. We may need to confirm your identity before acting on a request. We will respond within one month, which the law allows us to extend by up to two further months for complex or numerous requests, in which case we will tell you why. There is normally no fee.
13. Questions and complaints
If you have a concern about how we handle your personal data, please contact us first at enquiries@qvccs.com so we can try to put it right. We will acknowledge your complaint within 30 days and tell you the outcome without undue delay.
You also have the right to complain to the UK supervisory authority, the Information Commissioner's Office (ICO), at ico.org.uk/make-a-complaint or on 0303 123 1113. If you are in the European Economic Area, you may also complain to your local data protection authority.
14. Other important information
Children. Our website and services are intended for businesses and are not directed at children. We do not knowingly collect personal data from anyone under 18.
Links to other websites. Our site links to third-party websites, including Genesys documentation and partner sites. Those sites have their own privacy policies, and we are not responsible for their practices.
Changes to this policy. We review this policy regularly and at least once a year. When we make material changes, we will update the "last updated" date and version above and, where appropriate, tell you directly.
Please also read our terms and conditions.
Last reviewed