1. Who we are and what this notice covers
This notice explains how NUOPTIMA Limited collects and uses personal data, and what rights you have over that data.
NUOPTIMA Limited is the data controller for all of the processing described here. That means we decide why your personal data is used and how.
- Company name: NUOPTIMA Limited
- Registered in England and Wales, company number 14407366
- Registered office: 1 Beauchamp Court, 10 Victors Way, Barnet, Hertfordshire, England, EN5 5TZ
- VAT number: GB427891167
- Website: https://nuoptima.com
- Contact email for anything in this notice: [email protected]
We are a B2B marketing agency. We provide SEO, GEO (AI search optimisation), Google Ads, content and outbound lead generation, mainly to managed service providers and cybersecurity companies in the UK and the US. We sell to businesses, not to consumers.
We have not appointed a Data Protection Officer, because we are not required to. Send any privacy question to [email protected] and it will reach the person who can deal with it.
2. Who this notice applies to
This notice covers everyone whose personal data we handle, including:
- visitors to nuoptima.com
- people who fill in a form on the site, use the chat widget, or book a call with us
- clients and the people who work at our client companies
- suppliers, contractors and partners, and the people who work for them
- prospects we contact through outbound marketing, where we have obtained business contact details from other sources
Section 4 is the part that matters most if you did not give us your details yourself. Please read it.
3. Personal data we collect directly from you
Lead capture forms
When you fill in a form on our website we collect your name, email address, phone number, company domain, revenue band, the competitors you name, and the target cities you name.
Chat widget
Our chat widget is provided by GoHighLevel (LeadConnector). If you use it we collect your name, phone number, the content of the messages you send, and whether you have consented to receive SMS messages from us.
Booking a call
Our booking modal uses the LeadConnector calendar. When you book we collect your name, email address, and the details of the booking such as the date, time and anything you write in the booking form.
Server logs and security data
Our site is served through Cloudflare. Cloudflare records your IP address, your browser user agent and details of the requests your browser makes. This happens for every visitor and is how the site stays available and protected against attacks and abuse.
Correspondence, clients and suppliers
If you email us, speak to us or meet us, we keep that correspondence and any notes we make. If you become a client or a supplier we also hold contract details, billing and payment information, and the contact details of the people we deal with.
4. Personal data we obtain from other sources
We run outbound B2B marketing. To do that we build and maintain a contact database of people who work at managed service providers and cybersecurity companies, and we contact them about our services. If we have contacted you out of the blue, this section explains where your details came from.
What we hold. Business contact details only: your name, job title, employer, business email address, company website, and public professional profile information such as your LinkedIn profile. We may also hold company level information such as size, sector and location, plus a record of what we sent you and how you responded. We do not collect special category data and we do not look for personal or home contact details.
Where it comes from. Two types of source:
- publicly available sources, such as company websites, professional networking profiles, public directories and industry listings
- third party data enrichment and contact data providers, who compile business contact data commercially and license it to companies like ours. We will name the specific providers behind any given record if you ask us
Why we are allowed to do this. Our lawful basis is legitimate interests. Our interest is finding and reaching potential business customers for a B2B service that is relevant to their role. We only contact people in a professional capacity, at their employer, about services their organisation might buy. We have weighed this against your interests and we keep the data limited to what we need.
Your right to object. You can tell us to stop at any time, and we will. Reply to any message we send, use the unsubscribe link, or email [email protected]. We will stop contacting you immediately and add your details to our suppression list so it does not happen again. You do not have to give a reason.
5. How we use personal data and our lawful basis
| What we use it for | Data used | Lawful basis |
|---|---|---|
| Responding to enquiries, running chat conversations, and booking and holding calls | Name, email, phone, company details, message and booking content | Performance of a contract, or steps taken at your request before entering into a contract |
| Delivering our services to clients, and managing suppliers and partners | Contact details, contract and billing data, correspondence, campaign and reporting data | Performance of a contract, or legitimate interests where the contract is with your employer rather than you personally (our interest being to run the engagement) |
| B2B outbound marketing by email and LinkedIn to prospects | Business contact details and professional profile data, plus records of what we sent and how you responded | Legitimate interests. The interest is promoting our services to businesses likely to need them, and growing the company |
| Analytics, understanding how the site is used, advertising and remarketing | Cookie and device identifiers, IP address, pages viewed, on site behaviour including session recordings | Consent |
| Keeping the site available and secure, preventing fraud and abuse | IP address, user agent, request and traffic data, form submission patterns | Legitimate interests in protecting our systems, our clients and our business |
| Accounting, tax, and meeting other legal and regulatory duties | Billing records, contracts, correspondence | Legal obligation |
| Establishing, exercising or defending legal claims | Whatever is relevant to the claim | Legitimate interests in protecting our legal position |
Where we rely on legitimate interests you can ask us to explain our reasoning, and you can object. See section 10.
6. Cookies and tracking
We use cookies and similar technologies to make the site work, to understand how it is used, and to measure and target advertising. Strictly necessary cookies (mainly Cloudflare) are needed for the site to work. Functional cookies behind the chat widget and booking calendar, and analytics and advertising cookies, are only set where you have given consent, and you can change your choices at any time through Cookie Settings.
One tool is worth calling out. We use Microsoft Clarity, which records website sessions and builds heatmaps. It can capture mouse movement, scrolling, clicks and page navigation to show us how people move through the site. We configure Clarity to mask input fields, so what you type is not captured in the recording. We use these recordings to find usability problems, not to identify individuals.
The full list of cookies and trackers, who sets them, what they do and how long they last is in our Cookie Notice.
7. Who we share personal data with
We do not sell personal data. We share it with service providers who process it on our instructions, and only where they need it to do their job for us.
- Hosting, security and performance: Cloudflare
- Analytics and tag management: Google (Google Analytics 4, Google Tag Manager), Microsoft (Clarity), Ahrefs
- Advertising and conversion measurement: Google Ads, Meta, LinkedIn
- Chat widget, booking calendar and CRM: GoHighLevel (LeadConnector)
- Outbound marketing: Smartlead (email) and HeyReach (LinkedIn)
- Database and internal systems: Supabase
We also share personal data with our professional advisers (such as accountants and lawyers), and with authorities, regulators or courts where the law requires it. If our business or part of it is ever sold or restructured, personal data may transfer as part of that, and the recipient would be bound by this notice or one at least as protective.
8. International transfers
Several of the providers listed above are based outside the UK, mainly in the United States, and some in the EU or Singapore. That means your personal data may be transferred outside the UK.
Where that happens, we rely on one of the safeguards allowed under UK data protection law, depending on the provider and the country:
- UK adequacy regulations, where the destination country has been recognised as offering an adequate level of protection
- the UK Extension to the EU-US Data Privacy Framework, where the recipient is certified under it
- the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment
The right mechanism differs from provider to provider and changes as certifications are updated, so we do not list one per vendor here. If you want to know which safeguard applies to a specific provider, email [email protected] and we will tell you.
9. How long we keep personal data
- Enquiries, chat conversations and bookings that do not become clients: up to 24 months from your last contact with us, then deleted or anonymised.
- Prospect records in our outbound database: reviewed regularly, and removed when the data is out of date, the person has moved on, or the record has produced no engagement.
- Client and supplier records, contracts, invoices and accounting data: 6 years after the engagement ends. This lines up with the usual UK limitation period for contract claims and with HMRC record keeping requirements.
- Website analytics and session recording data: retained for the period set in each provider's own settings, and is no longer than 14 months for our Google Analytics property. Microsoft Clarity and Ahrefs apply their own retention limits.
- Server and security logs: short term only, typically a few weeks, as set by Cloudflare.
- Suppression and do not contact lists: kept indefinitely. We keep the minimum needed (usually just an email address or domain) for one reason: so that if you have told us to stop contacting you, we can check future campaigns against that list and not contact you again. Deleting this record would make it likely we would contact you a second time.
We may keep data for longer where we need it for a legal claim or where the law requires it.
10. Your rights
Under UK data protection law you have the following rights. Not all of them are absolute, and some only apply in certain situations, but we will always explain our answer.
- Access: ask for a copy of the personal data we hold about you, and information about how we use it.
- Rectification: have inaccurate data corrected and incomplete data completed.
- Erasure: ask us to delete your data where we no longer have a good reason to keep it.
- Restriction: ask us to pause our use of your data, for example while we check whether it is accurate.
- Portability: receive the data you gave us in a common machine readable format, or have it sent to another organisation, where we rely on consent or contract and process it by automated means.
- Objection: object to processing we carry out on the basis of legitimate interests. We will stop unless we can show compelling grounds that override your interests.
- Withdrawing consent: where we rely on consent, such as analytics and advertising cookies, you can withdraw it at any time. That does not affect anything we did before you withdrew it.
Direct marketing is different. If you object to us using your data for direct marketing, that right is absolute. There is no balancing test, no need to give a reason, and we act on it straight away.
To exercise any right, email [email protected] and tell us what you want. We may ask for enough information to confirm who you are and to find your data. We will respond within one month. If your request is complicated or you have made several, we can extend that by up to two further months, and we will tell you if that happens and why. There is normally no fee.
11. Complaints
If you are unhappy with how we have handled your personal data, please tell us first at [email protected]. We would rather fix it directly and quickly.
You also have the right to complain to the Information Commissioner's Office, the UK data protection regulator. You can do this at any time, and you do not need to come to us first.
- Website: ico.org.uk
- Helpline: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
12. Changes to this notice
We update this notice when our tools, processing or legal obligations change. The current version is always on this page. If we make a significant change we will flag it on the site, and where it affects data we hold about you and we have a way to reach you, we will tell you directly.
Last updated: 1 August 2026.