1.1 This privacy notice explains how AZIMIS collects, uses, stores and shares personal data when you:
a. visit azimis.com;
b. contact us or request a quotation;
c. upload a room, venue or installation photograph;
d. purchase or enquire about a product or service;
e. arrange delivery, mounting or installation;
f. request warranty, repair or customer support;
g. subscribe to marketing;
h. interact with our social-media accounts; or
i. communicate with us in a professional or business capacity.
1.2 We process personal data under applicable UK data-protection law, including the UK General Data Protection Regulation, the Data Protection Act 2018 as amended, and the Privacy and Electronic Communications Regulations 2003.
1.3 This notice is intended to provide clear information about our purposes, lawful bases, recipients, retention periods and your rights. These are core transparency requirements under UK data-protection law.
2.1 AZIMIS is a trading brand operated by:
Crypty Ltd
Company number: 13367065
Registered office: 20 Rochester Mews, London, England, NW1 9JB
2.2 Crypty Ltd is the controller of personal data described in this notice. This means that Crypty Ltd determines why and how that personal data is processed.
2.3 References in this notice to “AZIMIS”, “Crypty Ltd”, “we”, “us” or “our” mean Crypty Ltd trading as AZIMIS.
2.4 Our privacy contact is:
Email: privacy@azimis.com
Post: Privacy Lead, Crypty Ltd, 20 Rochester Mews, London, NW1 9JB
2.5 We have not appointed a statutory Data Protection Officer. Privacy enquiries are managed by our Privacy Lead.
3.1 Depending on your interaction with us, we may collect the following categories of personal data.
This may include:
a. name;
b. title;
c. account username;
d. company or organisation;
e. job title; and
f. customer or enquiry reference number.
This may include:
a. email address;
b. telephone number;
c. billing address;
d. delivery or installation address; and
e. business contact details.
This may include:
a. products or services requested or purchased;
b. quotation and order details;
c. quantities;
d. prices, deposits, payments and refunds;
e. delivery details;
f. installation requirements;
g. warranty information;
h. returns and cancellations; and
i. transaction identifiers.
Payments made through azimis.com are processed using Stripe.
Depending on the payment method selected, Stripe may collect and process:
a. card or bank-account details;
b. card expiry date and security information;
c. cardholder or account-holder name;
d. billing and delivery address;
e. email address and telephone number;
f. payment amount and currency;
g. order and transaction information;
h. IP address, browser, device and authentication information; and
i. fraud-prevention and payment-risk signals.
Where payment details are entered through Stripe-hosted checkout pages or Stripe-secured payment fields, AZIMIS does not ordinarily receive or store the complete card number or card security code.
AZIMIS may receive limited payment information from Stripe, including:
a. payment status;
b. payment method type;
c. the last four digits of a payment card;
d. card brand and expiry information;
e. billing details;
f. Stripe customer, payment and transaction identifiers;
g. refund and dispute information; and
h. fraud or payment-risk outcomes.
Stripe may process transaction, device and payment information to provide payment services, authenticate transactions, prevent fraud, comply with financial regulation and manage refunds or disputes.
This may include:
a. installation postcode and address;
b. room, wall, doorway, lift or access measurements;
c. intended use of the display;
d. preferred mounting method;
e. delivery-route information;
f. building-access information;
g. site-survey notes;
h. photographs, plans or videos of the proposed location; and
i. information about structural, electrical or network requirements.
This may include:
a. product model;
b. serial number;
c. purchase date;
d. software or firmware version;
e. photographs or videos showing a fault;
f. service and repair history;
g. warranty claims; and
h. communications with customer support.
This may include messages and correspondence sent by:
a. email;
b. telephone;
c. website form;
d. live chat;
e. post;
f. social media; and
g. other messaging services.
We do not record telephone calls unless we tell you before recording begins.
This may include:
a. IP address;
b. browser and device type;
c. operating system;
d. referring website;
e. pages visited;
f. date and time of access;
g. website interactions;
h. cookie identifiers;
i. approximate location derived from an IP address; and
j. website security and error logs.
This may include:
a. marketing preferences;
b. consent records;
c. subscription status;
d. campaign interactions;
e. email opens and link clicks, where enabled; and
f. records of objections and unsubscribes.
Where we contact an organisation in a business context, we may process:
a. employee or representative name;
b. job title;
c. employer;
d. professional email address;
e. professional telephone number;
f. business address;
g. publicly stated professional responsibilities; and
h. the source from which the details were obtained.
4.1 We do not normally require special-category personal data, such as information concerning health, ethnicity, religion, political opinions, trade-union membership, biometric identification or sexual orientation.
4.2 Please do not submit special-category data unless it is genuinely necessary for us to provide an accessible delivery or installation service.
4.3 Where accessibility information is required, we will use only the minimum information necessary to accommodate the relevant requirement.
4.4 We do not intentionally collect criminal-conviction data unless necessary for fraud prevention, legal proceedings or compliance with a legal requirement.
5.1 We may obtain personal data directly from you when you:
a. complete a website form;
b. request a quotation;
c. place an order;
d. create an account;
e. upload a photograph or plan;
f. communicate with us;
g. request delivery, installation or support;
h. subscribe to marketing; or
i. interact with an AZIMIS social-media account.
5.2 We may collect technical data automatically through cookies, server logs and similar technologies.
5.3 We may obtain data from third parties, including:
a. payment providers;
b. delivery and installation partners;
c. manufacturers and suppliers;
d. fraud-prevention providers;
e. professional advisers;
f. referrals from customers or business partners;
g. social-media platforms; and
h. publicly available business sources.
5.4 Publicly available business sources may include:
a. Companies House;
b. an organisation’s website;
c. public business directories;
d. professional networking sites;
e. procurement portals;
f. industry directories; and
g. trade-event information.
5.5 When we obtain personal data from another source, we will provide appropriate privacy information within the period required by law, normally no later than one month, at our first communication, or before first disclosing it to another recipient, whichever applies first.
We use identity, contact and project data to:
a. respond to enquiries;
b. recommend products and deployment options;
c. assess access and installation requirements;
d. prepare quotations; and
e. take steps requested before entering into a contract.
Lawful basis: taking steps at your request before entering into a contract and, where appropriate, our legitimate interest in responding to enquiries.
We use identity, contact, transaction and limited payment data to:
a. accept and process orders;
b. generate Stripe payment requests or checkout sessions;
c. authenticate and authorise payments;
d. administer deposits and balance payments;
e. issue invoices and receipts;
f. process refunds and cancellations;
g. investigate failed, disputed or potentially fraudulent transactions; and
h. collect amounts properly owed to us.
Lawful basis: performance of a contract, taking steps before entering into a contract, compliance with legal obligations and our legitimate interests in preventing fraud, administering transactions and recovering amounts due.
Stripe may act as a processor when providing payment-processing services on our instructions and may also act as an independent controller where it processes data for its own regulatory, fraud-prevention, security and legal-compliance purposes.
We use contact, address, project and order data to:
a. plan deliveries;
b. assess access requirements;
c. coordinate couriers and installers;
d. recommend fixed or mobile deployment;
e. arrange installation appointments; and
f. complete project handover.
Lawful basis: performance of a contract, taking pre-contract steps and our legitimate interest in delivering services safely and efficiently.
We use submitted photographs, measurements and plans to:
a. produce an indicative display visualisation;
b. assess potential placement;
c. identify access or mounting issues; and
d. prepare a deployment recommendation.
Lawful basis: taking steps at your request before entering into a contract, performance of a contract, or our legitimate interest in producing the service you requested.
We will not use your room or venue photograph in advertising, social media, case studies or promotional materials without separate permission.
We use identity, contact, transaction, product and support data to:
a. answer questions;
b. troubleshoot products;
c. administer warranties;
d. arrange repair or replacement;
e. investigate complaints; and
f. manage product-safety or recall matters.
Lawful basis: performance of a contract, compliance with legal obligations and our legitimate interest in providing effective support.
We process transaction, order, invoice and payment data to:
a. maintain accounting records;
b. prepare tax returns;
c. comply with company, tax and consumer law;
d. respond to regulators; and
e. demonstrate compliance.
Lawful basis: compliance with legal obligations and our legitimate interest in maintaining accurate business records.
We process identity, payment, order, technical and communication data to:
a. verify transactions;
b. detect fraudulent or unauthorised activity;
c. secure our website and accounts;
d. prevent misuse;
e. investigate security incidents; and
f. establish, exercise or defend legal claims.
Lawful basis: legitimate interests and, where applicable, compliance with legal obligations.
We process technical and usage data to:
a. provide website functionality;
b. maintain shopping baskets and account sessions;
c. diagnose faults;
d. measure performance;
e. understand how the website is used; and
f. improve content and navigation.
Lawful basis: legitimate interests for essential operation and security; consent for non-essential analytics, personalisation and advertising technologies.
We may use contact and marketing data to send information about:
a. AZIMIS displays;
b. accessories;
c. installation services;
d. product launches;
e. demonstrations;
f. trade pricing; and
g. related AZIMIS services.
Lawful basis: consent, the customer soft opt-in where its legal conditions are satisfied, or legitimate interests for permitted business-to-business marketing.
We may process relevant data to:
a. obtain professional advice;
b. manage insurance;
c. protect our legal rights;
d. respond to legal proceedings;
e. restructure, finance or sell part of the business; and
f. audit business activity.
Lawful basis: legitimate interests and compliance with legal obligations.
We process identity, contact, request and complaint data to:
a. verify identity;
b. respond to rights requests;
c. investigate data-protection complaints;
d. communicate outcomes; and
e. demonstrate compliance.
Lawful basis: compliance with legal obligations and legitimate interests in handling requests accurately.
7.1 Where we rely on legitimate interests, those interests may include:
a. operating and developing AZIMIS;
b. responding to prospective customers;
c. administering customer and supplier relationships;
d. supporting business customers;
e. securing our website and systems;
f. preventing fraud;
g. improving products and services;
h. maintaining business records;
i. recovering debts;
j. protecting our legal rights; and
k. conducting proportionate business-to-business marketing.
7.2 Before relying on legitimate interests, we consider whether the processing is necessary and whether your interests, rights or freedoms override our interests.
7.3 You may ask us for further information about a legitimate-interest assessment relevant to your personal data.
8.1 Certain personal data is required to:
a. respond to a quotation request;
b. enter into a contract;
c. take payment;
d. deliver a product;
e. arrange installation; or
f. comply with law.
8.2 If you do not provide required information, we may be unable to provide a quotation, accept an order, arrange delivery or complete the requested service.
8.3 Optional marketing information is not required to purchase a product or obtain a quotation.
9.1 Before uploading a room or venue image, you should where practical:
a. remove or obscure personal documents;
b. remove visible financial or medical information;
c. avoid including identifiable people;
d. avoid showing security-system details;
e. obscure vehicle registration numbers; and
f. avoid including anything unrelated to the proposed installation.
9.2 You must have authority to provide any photograph, plan or measurement submitted to us.
9.3 Visualisations are used for indicative planning and do not replace a physical site survey, final measurement or structural assessment.
9.4 We will not publish an uploaded photograph or completed visualisation without separate authorisation.
10.1 The AZIMIS website and products are not directed at children.
10.2 Orders and installation contracts must be entered into by an adult with legal capacity to contract.
10.3 We do not knowingly collect personal data directly from children for marketing purposes.
10.4 If you believe a child has provided personal data to us without appropriate authority, contact privacy@azimis.com.
11.1 We may share personal data where necessary with the following recipient categories.
This includes:
a. GoDaddy, which provides website hosting, website-building, commerce, form and related infrastructure;
b. email and communications providers;
c. cloud-storage providers;
d. website-security providers; and
e. IT support providers.
GoDaddy’s data-processing terms state that the website customer remains responsible as controller and that GoDaddy processes customer personal data as processor or subprocessor.
We use Stripe to process online and remote payments.
For UK merchants, Stripe’s contractual structure may involve Stripe Payments Europe Limited and Stripe Payments UK Limited. Stripe Payments UK Limited provides applicable regulated UK payment services and is authorised by the Financial Conduct Authority as an electronic-money institution under reference number 900461.
When you begin or complete a payment, relevant personal data may be disclosed to Stripe, including:
a. your name and contact information;
b. billing and delivery addresses;
c. order and purchase information;
d. payment-method information;
e. payment amount, date and currency;
f. device, browser and IP-address information; and
g. information used for authentication, fraud prevention and security.
Stripe may share relevant payment information with banks, card networks, payment-method providers and financial institutions where necessary to authorise, authenticate, settle or refund a payment and to prevent fraud.
Stripe processes personal data in accordance with its own privacy information and applicable Stripe service terms.
We may share relevant contact, address, access and order information with:
a. couriers;
b. freight providers;
c. warehouse operators;
d. site-survey providers;
e. mounting specialists;
f. installation contractors; and
g. technical-support partners.
We provide only the information reasonably required to complete the relevant service.
We may share product, serial-number, purchase and fault information with a manufacturer, distributor or supplier to:
a. confirm specifications;
b. obtain technical support;
c. administer warranty claims;
d. arrange replacement parts; or
e. address product-safety issues.
This may include:
a. accountants;
b. auditors;
c. lawyers;
d. insurers;
e. banks; and
f. business consultants.
We may disclose personal data to courts, regulators, law-enforcement bodies, tax authorities or other public authorities where legally required or necessary to protect legal rights.
Personal data may be disclosed to advisers, prospective purchasers, investors or successor organisations in connection with a proposed sale, financing, merger, restructuring or transfer of the business.
11.9 We do not sell personal data to data brokers.
11.10 We require processors acting on our behalf to protect personal data and use it only for the agreed service.
12.1 The AZIMIS display may enable access to third-party operating systems, applications, streaming platforms, voice services or connected-device services.
12.2 Unless expressly stated otherwise, AZIMIS does not control and does not ordinarily receive:
a. viewing history;
b. application usage;
c. streaming-account details;
d. voice-command content;
e. third-party advertising identifiers; or
f. account information supplied directly to an operating-system or application provider.
12.3 Those providers process data under their own privacy notices and account settings.
12.4 AZIMIS may receive limited product data such as a model number, serial number, firmware version or diagnostic information when required to provide technical or warranty support.
12.5 You should review the privacy settings and notices displayed by the television operating system and each application you use.
13.1 Some website, cloud, payment, communication, social-media and technology providers may process personal data outside the United Kingdom.
13.2 Where personal data is transferred internationally, we will use an approved legal mechanism where required, which may include:
a. UK adequacy regulations;
b. the UK Extension to the EU-US Data Privacy Framework;
c. the UK International Data Transfer Agreement;
d. the UK Addendum to the EU Standard Contractual Clauses; or
e. another legally recognised safeguard.
13.3 GoDaddy states that it transfers personal data internationally and participates in the UK Extension to the EU-US Data Privacy Framework. Its listed subprocessors include providers located outside the UK.
13.4 You may contact us for further information about the safeguards applying to a relevant transfer.
Stripe and its affiliates, subprocessors, banking partners and payment networks may process personal data outside the United Kingdom.
Where international transfers require safeguards, Stripe states that it uses applicable transfer mechanisms and contractual protections described in its privacy documentation and data-processing terms.
14.1 Our website may use cookies, pixels, local storage, scripts and similar technologies.
14.2 Strictly necessary technologies may be used to:
a. operate the website;
b. maintain security;
c. remember a shopping basket;
d. process transactions;
e. maintain a session; and
f. save privacy preferences.
14.3 Subject to your consent, optional technologies may be used for:
a. analytics;
b. performance measurement;
c. personalisation;
d. embedded media;
e. social-media functions; and
f. advertising or campaign measurement.
14.4 Non-essential cookies and tracking technologies will not be activated before the required consent has been obtained.
14.5 You may reject non-essential cookies or change your selection through the website’s cookie settings.
14.6 Further details, including cookie names, providers, purposes and durations, must be provided in our separate Cookie Policy.
15.1 You may receive marketing from us where:
a. you have actively consented;
b. the customer soft opt-in applies and all its requirements are satisfied; or
c. the communication is lawful business-to-business marketing.
15.2 Marketing consent is optional and must be separate from acceptance of general terms.
15.3 We do not use pre-ticked marketing-consent boxes.
15.4 Marketing emails and messages will identify AZIMIS and provide a clear way to unsubscribe.
15.5 You may object to direct marketing at any time by:
a. using the unsubscribe facility;
b. replying with an opt-out request; or
c. contacting privacy@azimis.com.
15.6 We will maintain a limited suppression record after an opt-out so that we do not inadvertently contact you again through the same marketing channel.
15.7 Public availability of a person’s contact information does not by itself amount to consent to electronic marketing.
15.8 Marketing emails or messages to individuals, sole traders and certain partnerships require consent or a valid soft opt-in. Different rules may apply to corporate subscribers, but objections and unsubscribe requests must still be respected.
You have the right to object at any time to our use of your personal data for direct marketing. When you object, we will stop using your personal data for that purpose.
16.1 Our website may link to third-party websites and social-media platforms.
16.2 When you follow a link, use a social-media feature or interact with an embedded service, the third party may collect personal data under its own privacy notice.
16.3 We are not responsible for the privacy practices of external websites or platforms.
16.4 Communications made publicly through social media may be visible to other users. Do not send payment information, identification documents or sensitive personal data through public posts.
17.1 We use proportionate technical and organisational measures intended to protect personal data against:
a. unauthorised access;
b. accidental loss;
c. misuse;
d. alteration;
e. disclosure; and
f. destruction.
17.2 Measures may include:
a. encrypted website connections;
b. account access controls;
c. multi-factor authentication where available;
d. access restriction;
e. password management;
f. secure payment providers;
g. system updates;
h. backups; and
i. incident-response procedures.
17.3 Access to personal data is restricted to personnel and service providers with a business need to access it.
17.4 No internet transmission or storage system can be guaranteed to be completely secure.
17.5 If a personal-data breach occurs, we will assess it and notify affected individuals and the Information Commissioner’s Office where legally required.
18.1 We retain personal data only for as long as necessary for the purpose for which it was collected, including legal, accounting, warranty and dispute-resolution requirements.
18.2 Our standard retention periods are:
a. General enquiries: up to 24 months after the last meaningful interaction;
b. Unsuccessful quotations: up to 24 months after expiry or last contact;
c. Room photographs and visualisation materials: up to 12 months after an enquiry closes, or up to 24 months following project completion, unless required for warranty, safety or legal purposes;
d. Orders, invoices, payments and accounting records: normally six years from the end of the relevant financial year, or longer where legally required;
e. Delivery and installation records: normally six years after completion where required to manage contractual, safety or legal matters;
f. Warranty and service records: for the warranty period and normally up to six years after the relevant service or claim closes;
g. Marketing records: while you remain subscribed or until the marketing purpose ends;
h. Suppression records: for as long as reasonably necessary to honour an unsubscribe or objection;
i. Cookie data: for the period stated in the Cookie Policy;
j. Technical and security logs: normally up to 12 months, unless needed for an active security investigation;
k. Rights requests: normally three years after closure; and
l. Data-protection complaints: normally three years after final resolution.
18.3 UK limited-company and tax records may need to be retained for six years, and data-protection law requires organisations to justify retention and delete or anonymise information no longer needed.
18.4 Retention periods may be extended where:
a. litigation is pending or reasonably anticipated;
b. a regulator or court requires continued retention;
c. a transaction spans multiple accounting periods;
d. a product-safety matter remains open; or
e. continued retention is otherwise required by law.
18.5 At the end of a retention period, personal data will be deleted, securely destroyed or irreversibly anonymised.
19.1 Depending on the circumstances and lawful basis, you may have the right to:
a. be informed about our processing;
b. request access to your personal data;
c. request correction of inaccurate data;
d. request completion of incomplete data;
e. request erasure;
f. request restriction of processing;
g. object to processing based on legitimate interests;
h. object to direct marketing;
i. receive certain data in a portable format;
j. withdraw consent; and
k. challenge certain solely automated decisions.
19.2 These rights are not absolute. A legal exemption or overriding legal requirement may apply.
19.3 Withdrawing consent does not affect processing carried out lawfully before withdrawal.
19.4 To exercise a right, contact:
19.5 We may request information needed to verify your identity and protect personal data from unauthorised disclosure.
19.6 We normally respond to valid rights requests within one month. Where permitted by law, additional time may be taken for a complex request, and we will explain the extension.
19.7 We do not ordinarily charge a fee. A reasonable fee may be charged, or a request refused, where legally permitted because it is manifestly unfounded or excessive.
20.1 AZIMIS does not currently make decisions based solely on automated processing that produce legal or similarly significant effects for customers.
20.2 A payment or fraud-prevention provider may use automated systems when deciding whether to authorise or investigate a transaction. That provider’s privacy notice will explain its own processing and applicable rights.
20.3 If AZIMIS introduces significant automated decision-making, we will update this notice before beginning that processing.
21.1 You may make a data-protection complaint if you believe we have not handled personal data lawfully, fairly, securely or transparently.
21.2 Complaints may concern, for example:
a. how personal data was collected;
b. how it was used or shared;
c. its accuracy;
d. how long it was retained;
e. security measures;
f. marketing; or
g. the handling of a rights request.
21.3 Submit a complaint by:
Email: privacy@azimis.com
Subject: Data Protection Complaint
or by post to:
Privacy Lead
Crypty Ltd
20 Rochester Mews
London
NW1 9JB
21.4 Include where possible:
a. your name and contact details;
b. a description of the concern;
c. relevant dates;
d. relevant correspondence or reference numbers; and
e. the outcome you are seeking.
21.5 We will:
a. provide a clear means of making a complaint;
b. acknowledge the complaint within 30 days;
c. take appropriate steps to investigate it;
d. keep you informed where appropriate; and
e. communicate the outcome without unjustifiable or excessive delay.
These complaint-handling duties became legally effective for UK organisations on 19 June 2026.
22.1 We ask that you first give us an opportunity to investigate and resolve your concern.
22.2 If you remain dissatisfied, you may complain to the Information Commissioner’s Office:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
The ICO provides an online data-protection complaints service.
22.3 Your right to complain to the ICO is not affected by contacting us first.
23.1 We may update this privacy notice to reflect:
a. changes to our products or services;
b. new website functions;
c. new processors or partners;
d. changes to law or regulatory guidance; or
e. changes to our processing activities.
23.2 The latest version will be published on azimis.com with its revision date.
23.3 Where a change materially affects how we use existing personal data, we will provide an appropriate additional notice before beginning the new processing.
24.1 Questions, rights requests and data-protection complaints should be sent to:
Privacy Lead
Crypty Ltd trading as AZIMIS
20 Rochester Mews
London
NW1 9JB
Email: privacy@azimis.com