Privacy

Privacy policy

Last updated: 24 August 2026

1. Introduction

Welcome to Noon Elite Ltd (“we”, “our”, “us”). This Privacy Policy explains how we collect, use, store and share personal information when you visit our website, use the Noon Elite Kiosk, use our software products, or contact us.

We are a UK based incorporated business, primarily serving customers in the United Kingdom. We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Our details

Legal entityNoon Elite Ltd (registered in England and Wales)
Company registration number17223153
Registered office82a James Carter Road, Mildenhall, Bury St. Edmunds, England, IP28 7DE
ICO registration number00014127862
Websitenoonelite.com
Email[email protected]

2. Which part of this policy applies to you

Our relationship with you determines who is responsible for your data. There are three cases.

If you areOur roleRead
A visitor to noonelite.com, or someone who contacts usController. We decide what is collected and whySections 3 to 9
Someone who signs in at a Noon Elite Kiosk on a client’s premisesProcessor. Our client is the controllerSection 10
A user of our software productsVaries by productSection 11

3. What we collect about website visitors and enquirers

  • Identity data: name, job title.
  • Contact data: email address, telephone number, postal address, company name.
  • Enquiry data: the content of your email, call or booking, and our correspondence with you.
  • Booking data: if you book a call, the details you give our scheduling provider (see section 7).
  • Technical data: IP address, browser type and version, operating system, and the server and security logs generated when your browser requests a page.

We do not run website analytics. We do not operate Google Analytics or any other analytics or advertising tracking on noonelite.com. We do not build visitor profiles and we do not use tracking pixels.

4. How we collect it

  • Directly from you, when you email us, call us, book a call, or send us a letter.
  • Automatically, through server and content delivery network logs generated when your browser requests a page.
  • From our licensing providers, who tell us your purchase and licence status when you buy a software product.
  • From public sources, in limited cases. Where we contact a business prospect for the first time, we may use publicly available business contact details from sources such as Companies House, a company’s own website, or business data providers. We only ever process business contact details for this purpose, never personal ones. You can ask us to stop at any time using the address in section 14, and we will.

5. Our lawful bases

We only use your personal data where the law allows. In each case the basis is one of the following.

What we doLawful basis
Reply to your enquiry and provide a quoteLegitimate interests (responding to a request made of us), or steps prior to entering a contract
Deliver services and support to a clientPerformance of a contract
Verify software licence keysPerformance of a contract
Contact a business prospect for the first timeLegitimate interests (direct marketing to a business, in a form the recipient can refuse)
Keep records for tax, accounting and legal purposesLegal obligation
Keep our systems and site secureLegitimate interests (protecting our business and our clients)

Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights. You can object at any time (section 14).

6. How we use your data

  • To respond to enquiries, provide quotes, and prepare proposals.
  • To deliver our services and support our clients.
  • To issue and verify software licences.
  • To send administrative messages about active projects, contracts and subscriptions.
  • To meet our accounting, tax and legal obligations.
  • To protect our website and systems against fraud, abuse and unauthorised access.

We do not sell your personal data. We do not share it for advertising purposes.

7. Cookies

noonelite.com sets no analytics, advertising or profiling cookies.

The only cookies set on our website are strictly necessary ones: those our content delivery and security provider (Cloudflare) uses to distinguish legitimate traffic from automated traffic, and those our website platform sets to operate the site and to keep a session active if you log in to an administrative account. These do not track you across other websites.

Booking a call takes you off our site. The “pick a time” link opens Calendly, a separate website. No Calendly cookie is set on noonelite.com. When you book, Calendly processes your name, email address, chosen time and any details you enter, and it does so on our instructions so that we can hold the meeting. Calendly’s own privacy policy governs its site.

The demonstration video loads only when you press play. Our kiosk page shows a still image of the video and a play button. Until you press it, nothing at all is requested from YouTube or Google, and no cookie or other storage is placed on your device by them. When you press play, the player is loaded from youtube-nocookie.com and your browser connects directly to Google, whose servers are outside the UK. Google may then store cookies or similar identifiers on its own domain, acting as its own controller, and its privacy policy governs that. As the owner of the channel we see aggregate view counts for the video. We are not told who watched it. If you would rather not connect to Google, do not press play, and the rest of the page works exactly as it did.

8. Who we share your data with

RecipientPurpose
Website hosting and content delivery providersServing and protecting noonelite.com
CalendlyCall scheduling, where you choose to book
Freemius and PayhipMerchants of record for software product sales. They process the payment, issue the licence key, and give us access to your name, email address and licence status so we can support you
YouTube (Google)Playing the demonstration video on our kiosk page, and only once you press play. We do not send them anything about you. Your browser connects to Google directly and Google acts as its own controller from that point
Professional advisersOur accountant, insurers and legal advisers, where necessary
Kiosk sub-processorsListed separately in section 10

We may also disclose data where required by law, or to establish, exercise or defend legal claims.

We do not store your payment card details. Card payments for software products are handled entirely by the merchant of record.

9. Retention

DataPeriod
Enquiry and prospect data12 months after the last interaction, unless it leads to a contract
Client contract and project records7 years, for tax and legal compliance
Software licence recordsFor the life of the licence, then as required by the licensing provider
Website server and security logsAs set by our hosting and content delivery providers, typically a short rolling window
Kiosk visitor dataSet by our client, not by us. See section 10

10. The Noon Elite Kiosk

Our client is the data controller. Noon Elite Ltd is the processor. The business operating the kiosk decides what is collected, how long it is kept and who can see it. Those decisions are set out in the Data Processing Agreement we sign with them, not left to us.

If you signed in as a visitor at a client’s site and want to exercise your rights over that record, contact that business. They are the controller. If you contact us instead we will pass your request to them and tell you we have done so.

The kiosk processes visitor names, employer, host, vehicle registration, arrival and departure times, site rules acknowledgements, courier names, and staff names from the client’s own list. Where the client licenses the Permit to Work module it also processes contractor email addresses, signatures and uploaded method statements. A visitor photograph is only captured if the client turns that feature on, and it is off as delivered.

No special category data is processed by design. Where photographs are used they are ordinary personal data used to identify someone on a badge. There is no facial recognition, no biometric matching and no automated decision making at any point.

Kiosk sub-processors

Sub-processorPurposeLocation
SupabaseDatabase, authentication and file storageEuropean Union, eu-west-1, Ireland
VercelApplication hosting and computeEuropean Union, eu-west-1, Ireland
PostHogProduct usage analyticsEuropean Union
SentryApplication error monitoring, with request URLs, credentials and session cookies redacted before transmissionEuropean Union
ResendTransactional email, Permit to Work module onlyDispatched from the EU. Account data, email metadata and delivery logs stored in the United States

A client’s own Microsoft Teams or Slack workspace is not a sub-processor. Where arrival notifications are enabled, that workspace is under the client’s control and the client is the controller in respect of it.

The mobile device management platform we use to administer the kiosk hardware is not a sub-processor either. The hardware is owned by Noon Elite. That platform holds device inventory for our own equipment, being device identifier, serial number, operating system version and configuration. It has no access to any personal data held within the kiosk application. We use it to lock the device to a single application and, where required, to remotely lock or erase it.

Changes to this list require 30 days’ written notice to the client, with a right to object.

Retention of kiosk data is the client’s decision, configurable per site within the range set out in the Data Processing Agreement, with a default applied where the client expresses no preference. Records are automatically and permanently deleted when the period expires. The badge audit trail is retained on a separate period, because it records who was admitted to a site and by whose authority.

11. Our software products

  • Noon Elite Audit Engine (WordPress plugin). Installed on your own website, where you remain the data controller for any leads it captures. The plugin sends that data from your visitors directly to your own systems. We do not intercept, view or store the end user leads generated on your site.
  • Snapsheets (Chrome extension). Data stays in your browser and is not transmitted to our servers.
  • Licence verification. If you hold a premium licence, the software periodically contacts our licensing provider to confirm the key is active. This transmits your licence key, a unique machine or site identifier and your website URL. Nothing else.

12. International transfers

Kiosk visitor, contractor and delivery records are processed in the European Union. Transfers from the UK to the EU rely on the UK adequacy regulations for the EEA, so no standard contractual clauses or transfer risk assessment are required.

One exception, stated plainly.

  • Resend, and only where a client licenses the Permit to Work module, dispatches email from the EU but stores account data, email metadata and delivery logs in the United States. The personal data involved is limited to contractor names, email addresses and permit references inside those messages. That transfer runs on Resend’s certification to the UK Extension to the EU-US Data Privacy Framework, supported by the UK Addendum to the EU Standard Contractual Clauses in our processing addendum with them.

Where a client does not license Permit to Work, no personal data belonging to their visitors, contractors, couriers or personnel is stored in the United States.

Some of the providers we use to run our own business, such as Calendly and our licensing providers, operate globally. Where a transfer outside the UK occurs, it is made under an appropriate safeguard: an adequacy decision, the UK Extension to the EU-US Data Privacy Framework, or the UK Addendum to the EU Standard Contractual Clauses.

13. Security

  • Encryption in transit. TLS on every connection.
  • Encryption at rest, provided by our hosting and database providers.
  • Access control. Kiosk database credentials are never held in a browser or on a kiosk device. Every read and write is mediated by server side code. Our own administrative accounts require multi factor authentication and cannot be used without it.
  • Tenant separation. Every kiosk record is bound to its client organisation, enforced in application code and by row level security in the database.
  • Credential protection. Approver PINs are stored as salted scrypt digests and are never recoverable. Contractor access links are cryptographically signed, expiring and single use where appropriate.
  • Rate limiting and brute force protection on kiosk endpoints, PIN entry and contractor authentication codes.
  • Photographs are held in a private object store, are not publicly addressable, and are reachable only through short lived signed links.
  • Access on a need to know basis. Only people with a business need can reach client data.

No system is perfectly secure and we do not claim otherwise. Where a personal data breach occurs in kiosk data we notify the affected client within 48 hours of becoming aware of it, and it is the client, as controller, who decides on any report to the ICO.

14. Your rights

Under UK data protection law you have the right to:

  • Access copies of your personal information.
  • Rectification of information that is inaccurate or incomplete.
  • Erasure of your data, in certain circumstances.
  • Restriction of how we process your data, in certain circumstances.
  • Object to processing carried out on the basis of legitimate interests, including direct marketing. Where you object to direct marketing we will stop, without exception.
  • Data portability, where processing is based on consent or a contract and is carried out by automated means.
  • Withdraw consent at any time, where we rely on consent.

To exercise any of these, email [email protected]. We will respond within one month. There is no charge. If your request concerns data held on a kiosk at a client’s premises, see section 10, because the client is the controller of that record.

15. Chrome Web Store data usage

To comply with Google’s User Data Policy, we confirm that for our Chrome extensions:

  • We do not sell user data to third parties.
  • We do not use or transfer user data for purposes unrelated to the item’s single purpose.
  • We do not use user data to determine creditworthiness or for lending purposes.
  • The extension requests the minimum permissions necessary to perform the function you request.

16. Changes to this policy

We may update this policy. The date at the top shows when it last changed. Where a change materially affects how we handle data for an existing client, we will tell them directly rather than rely on this page.

17. How to complain

Contact us first at [email protected] and we will try to resolve it.

You also have the right to complain to the Information Commissioner’s Office at any time. ICO website: ico.org.uk. Helpline: 0303 123 1113.