LenzIQ Privacy Notice
LenzIQ Technologies Limited
Last updated: 29 July 2026
1. Who we are and what this notice covers
LenzIQ Technologies Limited is a company registered in England and Wales under company number 16462486.
Our registered office is:
Smalls Hill Farm, Smalls Hill Road, Leigh, Reigate, RH2 8QB, United Kingdom
Privacy enquiries can be sent to:
This Privacy Notice explains how LenzIQ uses personal data where LenzIQ acts as a controller.
This may include information relating to:
- visitors to lenziq.co.uk;
- prospective customers and partners;
- customers and suppliers;
- business contacts;
- platform account holders;
- authorised platform users;
- administrators;
- technical and support contacts;
- people who request demonstrations or information; and
- people who otherwise interact directly with LenzIQ.
Where customers and channel partners use the LenzIQ platform to process CCTV footage, images, audio, incident information and other customer-controlled operational data, LenzIQ will normally process that information as a processor or sub-processor rather than as controller.
Depending on the contractual supply chain, there may be one or more processors between the organisation ultimately controlling the relevant surveillance activity and LenzIQ. UK data protection law recognises such processor/sub-processor arrangements, provided the necessary contractual chain is in place.
Processing undertaken by LenzIQ as processor or sub-processor is principally governed by the relevant commercial agreement and Data Processing Schedule.
2. When LenzIQ is the controller
LenzIQ may act as controller for purposes including:
- managing enquiries;
- business development;
- managing customer and supplier relationships;
- account administration;
- user authentication;
- maintaining service-security records;
- audit logging;
- fraud and abuse prevention;
- technical support administration;
- billing and contract administration;
- maintaining records of acceptance of contractual terms;
- operating and protecting our website;
- legal and regulatory compliance; and
- appropriate B2B marketing.
LenzIQ may therefore be a controller for some data relating to a platform user while acting as processor or sub-processor for other information accessed by that same user.
3. Personal data we may collect
Depending on your relationship with LenzIQ, we may collect:
Business and contact information
- name;
- employer or organisation;
- job title;
- department or role;
- business email address;
- business telephone number;
- business address;
- correspondence;
- contact preferences.
Sales and business-development information
- products or services of interest;
- number of CCTV towers or devices;
- technology currently used;
- requirements;
- proposal and quotation information;
- demonstration history;
- interaction and meeting records.
Platform account and administration information
- name;
- business email;
- organisation;
- user role;
- account ID;
- user permissions;
- tenant/customer association;
- account status;
- authentication events;
- login timestamps;
- IP address;
- browser and device information;
- MFA/security information;
- audit records.
Support and technical information
- support requests;
- correspondence;
- diagnostic information;
- technical logs;
- error information;
- actions taken by support personnel;
- related account and system identifiers.
Website information
We may collect:
- IP address;
- browser type;
- device information;
- pages visited;
- form submissions;
- basic security and access logs;
- cookie information where applicable.
We do not intentionally ask visitors to submit special-category personal data through the public website.
4. How we collect information
We may receive personal data when:
- you contact us;
- you submit a website form;
- you request a demonstration;
- you attend a meeting;
- you correspond with us;
- you interact with us on LinkedIn or another business channel;
- your employer or Provider creates a LenzIQ account for you;
- you log into or use the platform;
- you contact support;
- you accept contractual or End User Terms;
- your organisation enters into a commercial arrangement with us;
- another organisation in an authorised supply chain provides your details for service administration; or
- our website and systems generate legitimate technical/security records.
We may also obtain business-contact data from public business sources where legally permitted.
5. Why we use personal data
| Purpose | Typical data | Lawful basis |
|---|---|---|
| Responding to enquiries | Contact details and enquiry | Legitimate interests |
| Arranging demos and commercial discussions | Contact, role, company and requirements | Legitimate interests / steps towards a contract |
| Customer and partner management | Contact and contractual information | Contract / legitimate interests |
| Creating and administering accounts | Name, email, role, organisation | Contract / legitimate interests |
| Authenticating users | Account, IP, device and authentication data | Legitimate interests |
| Platform security and fraud prevention | Logs, IP, security records, account activity | Legitimate interests |
| Providing support | Contact information and technical/support data | Contract / legitimate interests |
| Recording acceptance of End User Terms | User/account ID, terms version, timestamp, IP/device information | Contract administration / legitimate interests |
| Billing and administration | Business contact and transaction information | Contract / legal obligation |
| Business record keeping | Correspondence and commercial records | Legitimate interests / legal obligation |
| Relevant B2B marketing | Business contact and interaction information | Legitimate interests and/or consent where required |
| Maintaining opt-out records | Email/contact and preference | Legitimate interests / legal compliance |
| Defending legal claims | Relevant records | Legitimate interests / legal obligation |
| Compliance with regulatory obligations | Relevant personal data | Legal obligation |
Where we rely on legitimate interests, these may include:
- operating and protecting our business;
- providing a secure technology service;
- managing our customer and channel relationships;
- responding to relevant business enquiries;
- preventing misuse;
- maintaining records;
- developing our business; and
- communicating with relevant business contacts.
We consider the interests and rights of individuals before relying on legitimate interests.
6. Business-to-business marketing
We may contact relevant business contacts about LenzIQ products, services, events and related business matters where permitted by law.
PECR treats corporate subscribers such as limited companies differently from sole traders and certain partnerships. In general, PECR’s specific consent rule for marketing by electronic mail does not apply to corporate subscribers, although UK GDPR still applies where we process an identifiable person’s data. Sole traders and certain partnerships receive greater protection and may require consent or another permitted route such as the soft opt-in.
We therefore consider both:
- the type of organisation we are contacting; and
- the applicable data-protection lawful basis.
We will not disguise our identity and will provide an appropriate means of opting out from electronic marketing.
You can object to direct marketing at any time by using an unsubscribe option where available or contacting:
We may retain limited suppression information after an opt-out so that we can respect your preference.
We do not sell personal data to advertisers or third parties.
7. Platform data and customer-controlled CCTV information
The LenzIQ platform may process information including:
- CCTV footage;
- still images;
- video clips;
- audio;
- alarm and event information;
- incident records;
- device information;
- router and connectivity information;
- unit location;
- telemetry;
- operational reports; and
- other information configured or supplied by our customers and partners.
For this type of customer-controlled data, LenzIQ will normally act as processor or sub-processor.
The organisation acting as controller is responsible for matters including:
- deciding the purposes of surveillance;
- identifying an appropriate lawful basis;
- providing privacy information or signage;
- determining retention requirements;
- handling data-subject rights;
- deciding who may access footage;
- carrying out any required data protection impact assessment; and
- complying with applicable surveillance and data-protection law.
Where the Customer itself acts for another controller, LenzIQ may sit further down the processor chain. Processor relationships and use of sub-processors must be governed by the appropriate written contractual terms.
8. Access to customer-controlled information
LenzIQ personnel will only access customer-controlled CCTV, video, images, incident information or similar operational data where reasonably necessary and authorised, for purposes such as:
- providing the Service;
- support;
- troubleshooting;
- security investigation;
- maintenance;
- resolving technical faults;
- complying with lawful instructions; or
- another purpose authorised under the applicable customer agreement.
Our access to such information does not mean LenzIQ determines the surveillance purpose.
9. Video storage and retention
Where cloud video/media storage is enabled, retention and storage settings are determined by the relevant contracted service and customer configuration.
Under LenzIQ’s standard commercial offering, video and media may be automatically removed once the applicable retention period expires.
Customers and authorised users should ensure that incident evidence or other material required beyond the relevant retention period is appropriately retained or exported in accordance with their own legal and operational requirements.
Commercial storage allowances, overage pricing and enhanced retention packages are governed by the applicable customer agreement rather than this Privacy Notice.
10. Who we share personal data with
We may use trusted suppliers and service providers including providers of:
- cloud hosting and infrastructure;
- website hosting;
- email and workplace productivity;
- CRM/customer relationship management;
- authentication and cybersecurity;
- software development;
- technical support;
- communications;
- business administration;
- professional advice;
- accounting and insurance.
Where these suppliers act as processors or sub-processors, we use appropriate contractual arrangements.
Processors must only process relevant data in accordance with applicable instructions and contractual obligations. Where a processor appoints a sub-processor, UK GDPR requires appropriate authorisation and contractual obligations to be flowed down.
We may also disclose information:
- where required by law;
- to a regulator or authority;
- in connection with legal proceedings;
- where necessary to protect LenzIQ’s legal rights;
- in connection with a genuine business sale, investment, restructuring or acquisition, subject to appropriate safeguards.
We do not sell personal data.
11. International transfers
Some technology providers or support resources may process or access personal data outside the UK.
Where a transfer is subject to UK international-transfer restrictions, we will use an appropriate lawful mechanism and safeguards as required by applicable data-protection law.
These may include:
- adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to appropriate standard contractual clauses; or
- another legally recognised transfer mechanism.
12. How long we retain information
We retain personal data only for as long as reasonably necessary for the purpose for which it is being used and for legitimate legal, regulatory, security and dispute-resolution requirements.
Typical periods may include:
| Information | Typical approach |
|---|---|
| Website enquiries | Up to 2 years after last meaningful contact |
| Sales/prospect records | While relevant to the relationship, followed by reasonable review/deletion |
| Customer/business contractual records | Contract term plus up to 6 years where appropriate |
| Marketing contacts | Until objection/opt-out or the information is no longer relevant |
| Suppression records | As long as reasonably required to respect the opt-out |
| Website/security logs | Normally up to 12 months unless required longer for security |
| Platform account records | For the account/service period plus an appropriate administration/security period |
| End User Terms acceptance records | For the relevant contractual relationship and any subsequent period reasonably required to evidence acceptance |
| Dispute/legal records | For the applicable limitation or regulatory period |
Customer-controlled platform content is retained according to the relevant customer contract, platform settings and instructions.
Backups may retain deleted information securely for a limited period until overwritten through the normal backup cycle.
13. Security
We use technical and organisational measures designed to protect personal data against:
- unauthorised access;
- loss;
- destruction;
- alteration;
- misuse; and
- inappropriate disclosure.
Measures may include, as appropriate:
- role-based access;
- supported multi-factor authentication;
- controlled administrative access;
- encryption;
- logging and monitoring;
- vulnerability and patch management;
- backups;
- supplier controls;
- incident-response procedures.
No internet-connected service can guarantee absolute security.
Users are responsible for keeping credentials secure and complying with their organisation’s access-control requirements.
14. Your rights
Depending on the circumstances and applicable law, you may have rights including:
- access to your personal data;
- correction of inaccurate data;
- deletion;
- restriction;
- objection;
- portability;
- withdrawal of consent where consent is relied upon; and
- objection to direct marketing.
Where LenzIQ holds information only as a processor or sub-processor for another organisation, requests concerning that information will normally need to be handled by the relevant controller.
If you submit such a request to LenzIQ, we may refer you to the appropriate customer or controller or assist them in accordance with our contractual obligations.
To exercise rights relating to personal data for which LenzIQ is controller, contact:
15. Complaints
If you have concerns about how LenzIQ uses personal data, please contact us first so that we can investigate.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK’s data-protection regulator.
16. Cookies
Our website may use cookies or similar technologies.
We may use strictly necessary technologies for functions such as:
- website security;
- maintaining sessions;
- remembering essential preferences;
- providing forms; or
- basic site operation.
Any non-essential analytics, advertising or tracking technologies will be used in accordance with applicable privacy and electronic-communications requirements, including obtaining consent where required.
We may provide a separate cookie-control mechanism or Cookie Notice where appropriate.
17. Third-party websites
Our website or platform may contain links to third-party websites and services.
Those organisations are responsible for their own privacy practices where they act independently of LenzIQ.
You should review their privacy information before providing personal data to them.
18. Changes to this Privacy Notice
We may update this Privacy Notice from time to time to reflect:
- legal developments;
- changes to the LenzIQ platform;
- new processing activities;
- new technologies; or
- changes to our suppliers and business operations.
The latest version will be published on our website with the relevant effective date.