Privacy Policy

Last updated: 9 October 2026

Vortex CAE is a trading name of Vortex Engineering Group Ltd, registered in England and Wales under company number 11004422.

Our registered address is:

Windsor House
Troon Way Business Centre
Humberstone Lane
Thurmaston
Leicestershire
LE4 9HA
United Kingdom

Vortex Engineering Group Ltd is responsible for the personal data described in this policy. This policy explains how we collect, use, share and protect personal data when you visit our website, contact us, evaluate or use our software, engage our consultancy services, or otherwise interact with us.

For privacy enquiries, contact us through the contact form at www.vortex-cae.com or write to Privacy Enquiries at the address above.

1. Personal data we collect

Depending on how you interact with us, we may collect:

  • Your name, job title, employer and professional contact details.

  • Information submitted through our contact, enquiry and software evaluation forms.

  • Account, licence and software registration information.

  • Details of your enquiries, support requests and communications with us.

  • Contract, billing, payment and transaction information. We normally receive only limited payment details from our payment provider.

  • Information about your use of our software and services, including licence activity, software version, technical diagnostics, device information and support logs.

  • Website information, including your IP address, browser type, device information, pages visited, referring website and cookie identifiers.

  • Information contained in engineering files, models or other materials supplied for consultancy, evaluation or technical-support purposes. These materials will not normally contain personal data, but they may identify project personnel or other individuals.

  • Marketing preferences and records of your interaction with our communications.

  • Information supplied when applying to work with us.

  • Information obtained from public business sources, professional networks, event organisers, referrals or your employer.

We do not intentionally collect special-category personal data, such as health, biometric, religious or political information. Please do not provide this information unless we have specifically requested it and agreed appropriate safeguards.

Our website and services are intended for business users and are not directed at children.

2. How we use personal data

We use personal data for the following purposes.

Enquiries, demonstrations and evaluations. We use identity, contact and communication data to respond to enquiries and arrange demonstrations or evaluations. We rely on our legitimate interests or on taking steps requested before entering a contract.

Software, consultancy and support. We use identity, business contact, account, licence, technical and transaction data to provide software, licences, consultancy, support and related services. We rely on performance of a contract and our legitimate interests.

Commercial relationships. We use contact, communication, contract and transaction data to manage customer, supplier and other commercial relationships. We rely on performance of a contract and our legitimate interests.

Billing, accounting and compliance. We use contact, transaction and contract data for billing, accounting and compliance with tax or company-law obligations. We rely on legal obligations and our legitimate interests.

Security and fault investigation. We use technical, licence, account and usage data to maintain software and service security, prevent misuse and investigate faults. We rely on our legitimate interests and, where applicable, legal obligations.

Service improvement. We use website, technical, diagnostic and feedback data to improve our website, software and services. We rely on our legitimate interests and on consent where required for cookies or similar technologies.

Business marketing. We use business contact and marketing-preference data to send relevant product, service or event information. We rely on consent or our legitimate interests, as permitted by applicable direct-marketing rules.

Legal claims. We use relevant contact, contract, technical and communication data to establish, exercise or defend legal claims. We rely on our legitimate interests and legal obligations.

Recruitment. We use application, employment-history and contact data to manage recruitment. We rely on steps requested before entering a contract, our legitimate interests and legal obligations.

Where we rely on legitimate interests, those interests include operating and improving our business, providing effective engineering and software services, protecting our systems and intellectual property, developing customer relationships and communicating with relevant business contacts.

Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing that took place before consent was withdrawn.

3. Marketing

We may send relevant business contacts information about Vortex CAE software, consultancy services, evaluations, events or technical developments where you have consented or applicable law otherwise permits us to do so.

You can unsubscribe using the link in a marketing message or by contacting us.

You have an absolute right to object to the use of your personal data for direct marketing. If you object, we will stop using your data for that purpose.

We may retain limited contact details on a suppression list so that we can respect an unsubscribe request.

4. Cookies and website analytics

Our website may use:

  • Strictly necessary cookies required for security and website operation.

  • Preference cookies that remember your choices.

  • Analytics cookies that help us understand how the website is used.

  • Marketing or embedded-content cookies, where applicable.

We request consent before using non-essential cookies where required. You can manage optional cookies through the controls presented on our website. Disabling some cookies may affect website functionality.

5. Information supplied through our services

When a customer supplies personal data for us to process solely on its instructions—for example, within engineering project materials—the customer will normally be the controller and Vortex Engineering Group Ltd will act as its processor.

In those circumstances, the customer’s privacy notice and our contract or data-processing terms will govern that processing.

Customers should avoid including unnecessary personal data in simulation models, project files or support materials.

6. Sharing personal data

We may share personal data with:

  • Website hosting, cloud storage, communications and IT-support providers.

  • Software licensing, customer-management, analytics and support-service providers.

  • Payment processors, accountants, auditors, insurers and professional advisers.

  • Contractors or technical partners assisting us in delivering services, subject to appropriate confidentiality and data-protection obligations.

  • Regulators, courts, law-enforcement bodies or public authorities where disclosure is required or permitted by law.

  • A purchaser, investor or adviser involved in a proposed sale, merger, restructuring or transfer of our business or assets.

We do not sell personal data.

Service providers acting on our behalf may use personal data only for the agreed services and must protect it appropriately.

7. International transfers

Some service providers may store or access personal data outside the United Kingdom.

Where this creates a restricted transfer, we use an appropriate legal mechanism. This may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved contractual clauses or another safeguard permitted by UK data-protection law.

Where required, we also assess the risks associated with the transfer. You may contact us for further information about the safeguards relevant to your personal data.

8. Retention

We retain personal data only for as long as reasonably necessary. Our intended retention periods are:

  • General enquiries: up to two years after the last meaningful contact.

  • Evaluation and prospective-customer records: up to two years after the evaluation or last meaningful contact.

  • Customer, contract and transaction records: generally seven years after the relationship ends.

  • Support correspondence and technical records: for the contract term and up to three years afterwards, unless longer retention is necessary for security or legal claims.

  • Website security logs: generally up to 12 months.

  • Marketing records: until you unsubscribe or after two years without meaningful engagement, subject to periodic review.

  • Suppression-list records: for as long as reasonably necessary to respect your objection.

  • Unsuccessful recruitment applications: generally six months after the recruitment process ends.

We may retain information for longer where required by law, necessary for legal claims or agreed in a customer contract. Data may be anonymised rather than deleted where it can no longer identify an individual.

9. Security

We use proportionate technical and organisational measures designed to protect personal data against unauthorised access, loss, alteration or disclosure.

These measures may include access controls, authentication, encryption, backups, staff confidentiality obligations and security monitoring.

No internet transmission or storage system is completely secure. Please contact us promptly if you believe personal data or account credentials have been compromised.

10. Your rights

Depending on the circumstances, UK data-protection law may give you the right to:

  • Obtain confirmation that we process your personal data and receive a copy of it.

  • Correct incomplete or inaccurate data.

  • Request deletion of personal data.

  • Restrict how personal data is used.

  • Object to processing based on legitimate interests.

  • Receive certain data in a portable format.

  • Withdraw consent at any time.

  • Object to direct marketing.

  • Ask for information about safeguards concerning an international transfer.

  • Challenge certain decisions made solely by automated means.

These rights are not absolute and may depend on our lawful basis and the circumstances. We may request information necessary to confirm your identity. We normally respond within one month.

We do not currently use personal data to make solely automated decisions that produce legal or similarly significant effects.

11. Complaints

Please contact us first so that we can try to resolve your concern.

You may also complain to:

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
Website: Make a complaint to the ICO

12. Changes to this policy

We may update this policy to reflect changes to our services, systems or legal obligations. The latest version will be published on our website with its revision date.

We will provide additional notice where a change materially affects how we use personal data.