Privacy Policy
Last updated: 10 August 2026
1. About this Privacy Policy
GoCX Limited (“GoCX”, “we”, “us” or “our”) is committed to protecting personal information and respecting the privacy of the people whose information we handle.
This Privacy Policy explains how we collect, use, store, protect and share personal information when you:
visit or interact with our website at www.gocx.co.uk;
contact or communicate with GoCX;
work with us as a client, prospective client, supplier, partner or other business contact;
take part in a GoCX consultancy, discovery, assessment or decision-assurance engagement;
use, access or provide information to our software and digital services, including Cenara One; or
otherwise provide personal information to us.
This Privacy Policy also explains your rights and how you can contact us about the way we use your personal information.
We process personal information in accordance with applicable UK data protection and privacy legislation, including the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (“PECR”) and the Data (Use and Access) Act 2025.
2. Who We Are
GoCX Limited is a company registered in England and Wales.
Company name: GoCX Limited
Company number: 15907073
Registered office: 41 Correnden Road, Tonbridge, England, TN10 3AU
Website: www.gocx.co.uk
Data protection contact: info@gocx.co.uk
For the personal information for which GoCX determines why and how it is processed, GoCX Limited is the data controller.
We have not described our data protection contact as a Data Protection Officer (“DPO”) because that is a specific statutory role. If GoCX formally appoints a DPO in the future, this Privacy Policy will be updated accordingly.
3. When GoCX Is a Controller and When We Are a Processor
Our role under data protection law depends on the circumstances.
When GoCX is the controller
GoCX normally acts as the data controller for personal information relating to:
website visitors;
people who contact or enquire with us;
prospective and existing clients and business contacts;
our own client and project administration;
Cenara One user accounts and access administration;
security, authentication and system administration;
service usage and analytics information;
our own business development and marketing activities;
suppliers and professional advisers; and
our legal, regulatory, accounting and compliance activities.
In these situations, GoCX determines why and how the relevant personal information is processed.
When GoCX is a processor
A GoCX client may provide, enter or upload personal information to Cenara One or provide personal information to us as part of a consultancy, assessment or decision-assurance project.
Where the client decides why that personal information is being processed and GoCX processes it only to provide the agreed service, the client will normally be the data controller and GoCX will act as a data processor on the client’s behalf.
In those circumstances, we process the information in accordance with the client’s documented instructions, our agreement with the client and applicable data protection law.
The client is responsible for establishing an appropriate lawful basis for that processing and providing any privacy information required to the individuals concerned.
Where appropriate, our client contracts include data-processing provisions governing matters such as confidentiality, security, subprocessors, assistance with data-subject rights, personal data breaches and the return or deletion of information.
4. What Personal Information We Collect
The information we collect depends on your relationship and interaction with GoCX.
Contact and professional information
We may collect your name, job title, employer or organisation, business address, email address, telephone number, professional role and other business contact information.
Communications
We may retain correspondence and communications between you and GoCX, including enquiries, emails, messages, meeting records, feedback, support requests and other information you choose to provide.
Client and commercial information
We may process information relating to proposals, contracts, projects, subscriptions, procurement, invoices, payments, client requirements and our commercial relationship with your organisation.
Cenara One account information
Where you have access to Cenara One, we may process information including your name, organisation, business contact details, username or account identifier, role, permissions, authentication information, login history, access history and other information needed to create, administer and protect your account.
We do not need or intend to store passwords in readable form.
Cenara One questionnaire and project information
Cenara One may process information supplied as part of a project, including:
questionnaire responses;
requirements;
priorities;
preferences;
ratings;
assessments;
comments;
project information;
supporting explanations;
scoring information;
comparison information;
results;
recommendations;
decision records; and
other information submitted or generated during the relevant project.
Some of this information may relate to an identifiable individual and therefore constitute personal information.
Documents and supporting evidence
Clients or authorised users may provide or upload documents, files, reports, evidence and other material for use in a GoCX or Cenara One project.
Those materials may contain personal information concerning the person uploading them or other individuals.
Usage, analytics and technical information
We may collect information about the use of our website, Cenara One and other digital services, including:
IP address;
browser and device information;
operating system;
approximate location derived from technical information;
dates and times of access;
pages, screens or functions accessed;
referring pages or services;
session information;
interaction and usage information;
performance information;
error and diagnostic information; and
security and audit logs.
Marketing information
We may process your marketing and communication preferences and information about your interaction with communications that we send where the relevant technology and use are permitted by law.
Compliance information
We may retain information relating to data protection requests, complaints, security investigations, disputes, legal matters and other matters necessary to meet our legal and regulatory obligations.
5. How We Obtain Personal Information
We may obtain personal information directly from you when you contact us, submit a form, communicate with us, attend a meeting, work with us or use one of our services.
We may also receive personal information from:
your employer or organisation;
one of our clients;
an authorised participant in a GoCX or Cenara One project;
another person authorised to provide the information;
suppliers and business partners;
our systems and digital services automatically when they generate usage, diagnostic or security information; and
publicly available professional or business sources where it is lawful and appropriate for us to use that information.
Where another person or organisation provides personal information to us about you, they are responsible for ensuring that they have an appropriate basis for doing so.
6. How and Why We Use Personal Information
We only process personal information where we have an appropriate lawful basis.
The lawful basis depends upon why we are using the information and our relationship with the individual concerned.
Providing consultancy and professional services
We process information to understand client requirements, prepare proposals, enter into and manage agreements, provide consultancy and decision-assurance services, carry out projects, communicate with clients and administer our commercial relationships.
Our lawful basis will normally be performance of a contract, taking steps at your request before entering into a contract, our legitimate interests in operating our business and providing services, or compliance with a legal obligation.
Providing and operating Cenara One
We process account, access and project information to provide, operate, administer, maintain and support Cenara One.
This includes administering accounts and permissions, delivering projects, processing project inputs, producing outputs, maintaining project records and supporting users.
Where GoCX is the controller, we normally rely on contractual necessity or our legitimate interests in providing, administering and securing our services.
Where GoCX acts solely on behalf of a client, we process personal information as the client’s processor in accordance with its documented instructions.
Questionnaires, evidence, scoring and decision support
Cenara One is designed to support structured evaluation and decision assurance.
It may process questionnaire responses, requirements, preferences, evidence, weighting, ratings, scoring and other project information in order to produce structured comparisons, analysis, results, project records and decision-support information.
Our aim is to support transparent and evidence-based human decision-making rather than obscure the reasoning behind a decision.
Where these materials contain personal information, we process that information only where necessary for the relevant project and according to our role as controller or processor.
Security and fraud prevention
We may use personal and technical information to authenticate users, control access, protect accounts and systems, investigate suspicious activity, prevent misuse, detect security incidents and maintain the confidentiality, integrity and availability of our services.
We normally rely on our legitimate interests in operating secure systems and protecting GoCX, our clients and users, and on our legal obligations where applicable.
Service administration and support
We may process information to provide technical and customer support, diagnose problems, respond to enquiries, maintain our systems and communicate important information about our services.
We rely on contractual necessity and our legitimate interests as appropriate.
Improving our website and services
We may use usage, performance, diagnostic and analytics information to understand how our website and services are used, identify technical problems, improve usability and performance and develop our services.
Where possible and appropriate, analysis is performed using aggregated or anonymised information.
Where the use of a cookie or other storage or access technology requires consent under PECR, we will rely on consent for that technology unless a statutory exception applies.
Responding to enquiries
When you contact GoCX, we use your information to understand and respond to your enquiry, arrange discussions and provide information you request.
Our lawful basis will normally be our legitimate interests or taking steps at your request before entering into a contract.
Managing our business
We process relevant information for accounting, financial administration, supplier management, insurance, business planning, auditing, corporate administration and similar legitimate business purposes.
We rely on our legitimate interests and legal obligations as applicable.
Legal and regulatory purposes
We may process information where necessary to comply with legal, tax, accounting or regulatory obligations, respond to lawful requests, establish or defend legal rights, handle disputes or complaints, prevent or investigate wrongdoing or cooperate with courts, regulators and law-enforcement authorities.
7. Our Legitimate Interests
Where we rely on legitimate interests, we consider whether the processing is necessary for a legitimate purpose and balance our interests against the rights, interests and reasonable expectations of the people concerned.
Our legitimate interests may include:
operating, developing and improving GoCX and our services;
providing professional services to clients;
administering business relationships;
protecting our systems, information, users and clients;
preventing misuse and fraud;
maintaining appropriate business records;
understanding how our services perform;
communicating with business contacts; and
promoting relevant GoCX services in a proportionate and lawful way.
We do not rely on legitimate interests where our interests are overridden by your rights and interests.
8. Cenara One
Cenara One is GoCX’s software platform used to support structured requirements gathering, assessment, evidence review, comparison, scoring, analysis and decision assurance.
Depending on the project, Cenara One may process account information, questionnaire responses, project inputs, supporting evidence, documents, scoring information, results and usage information.
Access to Cenara One information for GoCX’s own purposes is limited to authorised GoCX personnel who require access to carry out their work.
We apply access controls and other security measures intended to prevent unauthorised access to client and project information.
We do not sell personal information held within Cenara One.
We do not permit Cenara One project information to be used by unrelated third parties for their own advertising or marketing purposes.
Service providers involved in hosting, infrastructure, security, backup, communications or technical support may process information on our behalf where this is necessary to operate the service. They are not authorised by us to use that information for unrelated purposes.
Where GoCX processes Cenara One project information as a processor for a client, we use that information only in accordance with the client’s instructions and the applicable contract.
9. Uploaded Documents and Information About Other People
Cenara One and our professional services may allow or require clients to provide documents, evidence and information relating to other people.
Anyone providing personal information about another person should ensure that they are authorised to provide it and that the information is relevant and necessary for the project.
Users should avoid providing unnecessary personal information.
In particular, users should not upload sensitive personal information merely because it is available. It should only be provided where it is relevant, necessary, authorised and appropriate for the project.
Where GoCX acts as processor, responsibility for determining whether information should be provided to us rests primarily with the client controller.
10. Special Category and Criminal Offence Information
Our website and Cenara One are not designed to require special category personal information as a routine part of using our services.
However, documents, evidence or project information provided to us may occasionally contain special category information. This includes information revealing or concerning racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic information, biometric information used for identification, health, sex life or sexual orientation.
Information supplied to us may also occasionally contain information relating to criminal convictions or offences.
Where GoCX acts as controller and intentionally processes such information, we will identify an appropriate lawful basis and any additional condition required under applicable data protection law.
Where GoCX acts as processor, the relevant client controller is responsible for establishing the lawful basis and any additional condition required and for instructing us appropriately.
We do not use special category or criminal offence information for unrelated direct marketing.
11. Automated Processing and Decision-Making
Cenara One may automatically perform calculations, scoring, weighting, comparisons and other structured processing using project information.
Cenara One is intended to provide decision support.
It is not intended to replace appropriate human judgement, and GoCX does not intend Cenara One to make solely automated decisions about individuals that produce legal effects or similarly significant effects without appropriate safeguards.
Where a client uses information generated by Cenara One to inform its own decisions, the client remains responsible for how it uses those outputs and for ensuring that its decision-making process complies with applicable law.
If GoCX introduces processing involving solely automated significant decisions about individuals, we will provide the additional information and safeguards required by applicable law, including appropriate opportunities to obtain human intervention and challenge a decision where required.
12. Who We Share Personal Information With
We do not sell personal information.
Information may be disclosed within GoCX where necessary to perform an individual’s role.
We may also use carefully selected third-party service providers that process information on our behalf.
Depending on the services in use, these may include providers of:
website hosting and infrastructure;
cloud computing and software hosting;
Cenara One infrastructure;
data storage and backup;
cybersecurity and authentication;
business email and communications;
customer relationship management;
website forms and enquiry management;
email marketing;
website analytics and performance measurement;
IT and technical support;
accounting and financial services; and
other business software required to operate GoCX.
Our website may use third-party technologies associated with services such as website analytics, customer relationship management and email marketing. Where those technologies involve cookies or other storage or access technologies, their use is also governed by our cookie controls and applicable PECR requirements.
We may also disclose information where necessary to:
lawyers, accountants, auditors, insurers and other professional advisers;
courts, regulators and public authorities;
law-enforcement agencies where legally required or permitted;
protect the rights, property or safety of GoCX, our clients, users or others; or
support a proposed or completed merger, acquisition, financing, restructuring or sale of all or part of our business or assets, subject to appropriate confidentiality and data protection safeguards.
Where another organisation acts as our processor, we require appropriate contractual protections.
13. International Transfers
Some of the technology and service providers used by GoCX may operate internationally.
As a result, personal information may in some circumstances be transferred to or accessed from a country outside the United Kingdom.
Where UK international data-transfer rules apply, we take steps to ensure that an appropriate transfer mechanism is in place.
Depending on the circumstances, this may include:
a country, territory, sector or organisation covered by UK adequacy regulations;
the UK International Data Transfer Agreement;
the UK Addendum to approved standard contractual clauses;
another appropriate safeguard permitted under UK law; or
a specific statutory exception where applicable.
Where required, we assess whether the protection applying to transferred personal information is not materially lower than the protection provided under UK data protection law and consider whether additional safeguards are necessary.
You may contact us if you would like more information about the safeguards applying to a particular transfer of your personal information.
14. Cookies and Other Storage or Access Technologies
Our website and digital services may use cookies and other technologies that store information on or access information from your device.
These may include cookies, tags, scripts, pixels, local storage and similar technologies.
They may be used for purposes including:
essential website or service functionality;
security and fraud prevention;
authentication and session management;
remembering preferences;
performance monitoring;
analytics and measurement; and
marketing or communications functionality where applicable.
UK law permits some storage and access technologies to be used without consent where a statutory exception applies.
Where no relevant exception applies, we will provide appropriate information and obtain the required consent before using the technology.
Non-exempt technologies should not be activated merely because you continue browsing the website.
Where consent is required, you can refuse consent and you can subsequently change or withdraw your choices through the cookie or consent controls made available on the website.
Where applicable, our cookie controls or accompanying cookie information provide more specific information about the technologies in use, their purposes, providers and duration.
Changing or refusing non-essential cookies should not prevent you from accessing the core information on our public website, although some optional functionality may be affected.
15. Email Marketing and Business Communications
GoCX operates primarily in a business-to-business environment.
We may communicate with employees, directors and representatives of businesses and other organisations about GoCX services, events, insights or opportunities that we reasonably believe may be relevant to their professional role.
Where UK data protection law applies to the use of an individual’s business contact information, we require an appropriate lawful basis. This will commonly be our legitimate interests where those interests are not overridden by the individual’s rights.
The electronic marketing rules under PECR differ depending upon the type of recipient.
Where PECR requires consent, we will only send the relevant electronic marketing where we have consent or another lawful provision permits us to do so.
You can object to direct marketing at any time.
Marketing emails we send will include an appropriate method of opting out or unsubscribing where required.
If you unsubscribe or object to marketing, we may retain a limited suppression record so that we can respect your preference and avoid inadvertently adding you back to a marketing list.
You have an absolute right to object to the use of your personal information for direct marketing.
To exercise that right, use the unsubscribe mechanism in the communication or contact info@gocx.co.uk.
16. How Long We Keep Personal Information
We do not intend to retain identifiable personal information for longer than is reasonably necessary.
The appropriate retention period depends on the type of information and why it is being processed.
When determining retention periods, we consider:
the purpose for which the information was collected;
whether the information is still required to provide a service;
our contractual commitments;
instructions from a client controller;
legal, accounting and regulatory requirements;
relevant limitation periods;
the need to establish, exercise or defend legal claims;
security and audit requirements;
the sensitivity of the information; and
the risks associated with continued retention.
Client, contractual and financial records may be retained after a client relationship has ended where necessary for accounting, regulatory, contractual or legal purposes.
Cenara One project information is retained according to the applicable project requirements, client agreement and our role as controller or processor.
Where GoCX acts as processor, personal information will be returned, deleted or retained in accordance with the client’s instructions and our contractual obligations, except where applicable law requires us to retain particular information.
Security, audit, access and technical logs are retained for periods appropriate to their operational and security purpose.
Enquiry and business-contact information is periodically reviewed and deleted or updated when it is no longer reasonably required.
Marketing information is retained while the marketing purpose remains relevant or until you object, withdraw consent where applicable, or we determine that the information is no longer appropriate to retain.
Suppression information may be retained after an opt-out solely to ensure that the opt-out continues to be respected.
Where information has been irreversibly anonymised so that an individual is no longer identifiable, it is no longer personal information. We may retain and use genuinely anonymised information for statistical, analytical, security or service-improvement purposes.
17. How We Protect Personal Information
We use technical and organisational measures designed to protect personal information against unauthorised or unlawful processing and against accidental loss, destruction, alteration or disclosure.
Measures may include, where appropriate:
access controls;
authentication;
role-based permissions;
secure communications;
system monitoring;
logging and auditing;
backup and recovery arrangements;
security updates and maintenance;
staff confidentiality obligations;
supplier due diligence; and
appropriate contractual protections.
Access to personal information is limited according to legitimate business need.
We review our security arrangements as our technology, services and risks develop.
No website, network or internet-based service can guarantee absolute security. If we become aware of a personal data breach, we will investigate it and take the steps required by applicable data protection law, including notification to the Information Commissioner’s Office and affected individuals where legally required.
18. Your Data Protection Rights
Depending on the circumstances and the lawful basis for the processing, UK data protection law may give you rights in relation to your personal information.
These can include the right to:
be informed about how your personal information is used;
ask whether we process your personal information;
obtain access to personal information we hold about you;
ask us to correct inaccurate or incomplete personal information;
ask us to erase personal information in certain circumstances;
ask us to restrict processing in certain circumstances;
receive certain personal information in a portable format where the right to data portability applies;
object to certain processing;
object at any time to direct marketing;
withdraw consent at any time where processing is based on consent; and
receive appropriate safeguards in relation to significant solely automated decisions where applicable.
These rights are not absolute. Whether a particular right applies depends on factors including the purpose of the processing, our lawful basis and any applicable legal exemptions.
Withdrawing consent does not affect the lawfulness of processing carried out before consent was withdrawn.
You will not normally have to pay a fee to exercise a data protection right. However, the law may permit a reasonable fee or other action in limited circumstances.
To exercise a right, contact info@gocx.co.uk.
Please provide enough information to allow us to understand your request and identify the relevant records.
We may need to verify your identity before disclosing or changing personal information. Any identification information requested will be limited to what is reasonably necessary.
Where GoCX holds information solely as processor for one of our clients, we may refer your request to the relevant client controller or assist that client in responding to your request.
19. Your Right to Object
You have the right to object to certain uses of your personal information.
Where we rely on legitimate interests, you may object to the processing because of your particular situation.
If you object, we will consider your request and whether we have compelling legitimate grounds to continue the processing or whether the information is required for the establishment, exercise or defence of legal claims.
Your right to object to direct marketing is stronger. If you object to the processing of your personal information for direct marketing, we will stop using it for that purpose.
Contact info@gocx.co.uk to exercise your right to object.
20. Data Protection Complaints
You have the right to complain if you believe that GoCX has not handled your personal information in accordance with data protection law.
We provide an electronic route for data protection complaints.
Please email:
We recommend using “Data Protection Complaint” as the email subject.
Please explain what has happened, the personal information or processing involved and, where possible, what you would like us to do.
We will acknowledge receipt of a data protection complaint within 30 days.
We will take appropriate steps to investigate the complaint without undue delay. This may include reviewing relevant records and speaking to the people involved.
We will keep you appropriately informed about the progress of the complaint and will communicate the outcome without undue delay.
If you make a complaint on behalf of another person, we may ask for evidence that you are authorised to act for them.
We encourage you to raise concerns with us so that we have an opportunity to investigate and resolve them.
You also have the right to complain to the UK’s data protection regulator, the Information Commissioner’s Office (“ICO”).
The ICO can be contacted through its website and complaints services.
Its postal address is:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
21. Children
GoCX provides business-to-business consultancy and technology services.
Our public website and Cenara One are not intended or designed primarily for children.
We do not knowingly seek to collect personal information directly from children through our general business website for marketing purposes.
Information relating to a child could nevertheless appear in material legitimately supplied as part of a client project.
Where that occurs, we process it only where authorised and appropriate and subject to the protections required by applicable law.
Where GoCX acts as processor, the relevant client controller remains responsible for ensuring that its collection and use of children’s information has an appropriate legal basis and that any required privacy information is provided.
22. Third-Party Websites
Our website and communications may contain links to websites, platforms or services operated by other organisations.
Those organisations may process personal information independently from GoCX.
GoCX is not responsible for the privacy practices of independent third-party websites or services.
You should review the privacy information provided by the relevant organisation before providing personal information to it.
23. Changes to Our Business
If GoCX is involved in a merger, acquisition, investment, restructuring, financing, sale of assets or similar corporate transaction, information may be disclosed to prospective purchasers, investors, professional advisers and other appropriate parties where necessary.
We will take reasonable steps to protect personal information during any such process.
If responsibility for personal information transfers to another controller as part of a transaction, affected individuals will be provided with appropriate information where required by law.
24. Changes to This Privacy Policy
We may update this Privacy Policy from time to time.
Changes may be made to reflect developments in:
GoCX’s services;
Cenara One;
our website or technology;
our suppliers and service providers;
our business operations; or
applicable law and regulatory guidance.
The current version will be published on www.gocx.co.uk.
The “Last updated” date at the beginning of this Privacy Policy will show when the policy was most recently revised.
Where a change materially affects how we use personal information, we will take reasonable steps to bring the change to the attention of affected people where appropriate.
25. Contact Us
If you have a question about this Privacy Policy, the way GoCX uses personal information, your data protection rights or a data protection complaint, please contact:
Data Protection Contact
GoCX Limited
41 Correnden Road
Tonbridge
England
TN10 3AU
Email: info@gocx.co.uk
Website: www.gocx.co.uk
GoCX Limited — Company number 15907073
Last updated: 10 August 2026