Privacy Policy

Privacy Notice

Integrated Graphene Limited trading as iGii
Last updated: 26 August 2026

1. Introduction

1.1 Integrated Graphene Limited, trading as iGii (iGii, we, us), respects your privacy and is committed to protecting your personal data. This notice explains how we collect, use, share and protect personal data when you visit www.igii.uk (the Website), contact us, do business with us, visit our premises, attend our events or apply to work with us, and it explains your rights.

1.2 We are the controller of that personal data. We are registered in Scotland under company number SC553315 and our registered office is at Euro House, Wellgreen Place, Stirling, FK8 2DJ. Questions about this notice or about our handling of personal data should be sent to info@igii.uk or to our registered office, marked for the attention of the Directors. We have not appointed a statutory Data Protection Officer.

1.3 We process personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 and, where we deal with individuals in the European Economic Area, the EU General Data Protection Regulation.

1.4 We are a business-to-business company. Most of the personal data we hold is the business contact information of people who work for our customers, development partners, suppliers, investors, research collaborators and prospective customers.

1.5 The Website may contain links to third-party websites. This notice does not cover those websites, and we are not responsible for their privacy practices.

2. The personal data we collect

2.1 We may collect, use, store and transfer the following categories of personal data:

  • (a) Identity and Contact Data: name, title, employer or organisation, job role, business email address, business telephone number and business postal address;
  • (b) Professional Data: sector, areas of technical or commercial interest, publications, professional profile and history of dealings with us;
  • (c) Correspondence Data: the content of enquiries, emails, letters, calls, meeting notes and other communications with us;
  • (d) Contract Data: details of contracts, orders, deliveries, invoices and payments between us and the organisation you represent;
  • (e) Technical Data: internet protocol (IP) address, browser type and version, device type, operating system, time-zone setting and location, referring website and other technology on the devices you use to access the Website;
  • (f) Usage and Marketing Data: information about how you use the Website, which of our communications you open, and your marketing preferences;
  • (g) Event and Visitor Data: registration and attendance details for events, meetings and site visits, including any access or dietary requirements you choose to give us, and health-and-safety sign-in records;
  • (h) Recruitment Data: curriculum vitae, employment history, qualifications, references, right-to-work information, interview notes and assessment results; and
  • (i) Compliance Data: information needed to carry out export-control, sanctions, anti-bribery and counterparty due-diligence checks, and to respond to lawful requests from authorities.

2.2 We do not seek special category data (such as data about health, racial or ethnic origin, religion or trade-union membership) except where necessary, for example access or dietary requirements you provide for an event, or health information a job applicant chooses to provide. We process such data only with your explicit consent or where employment or other law permits, and we use it only for the purpose for which it was given. We process information about criminal convictions or offences only where required by law, for example in right-to-work or regulatory checks.

3. How we collect personal data

3.1 Directly from you: when you complete a form on the Website, email or telephone us, meet us at a conference, event or meeting, enter into a contract with us, visit our premises, apply for a role, or otherwise correspond with us.

3.2 Automatically: as you interact with the Website we collect Technical Data and Usage Data through server logs, cookies and similar technologies. See our Cookie Policy for details.

3.3 From third parties and public sources: including business-networking and professional platforms, Companies House and equivalent registers, scientific publications and conference materials, event organisers, introductions and referrals from customers and partners, recruitment agencies, and providers of delivery, IT, analytics and compliance-screening services. Where we obtain your personal data from a third party or a public source, we will make this notice available to you within a reasonable period and in any event within one month, unless an exemption applies.

4. How and why we use personal data

4.1 We use personal data only where the law allows us to. The table below sets out the purposes for which we process personal data, the categories of data involved and the lawful basis on which we rely.

PurposeDataLawful basis
Responding to enquiries and managing our relationships with customers, partners, suppliers, investors and collaboratorsIdentity and Contact; Professional; CorrespondenceLegitimate interests (running and developing our business and responding to those who contact us); performance of a contract, or steps at your request before entering one
Performing and administering contracts with customers, partners and suppliers, including deliveries, invoicing, payment and accountsIdentity and Contact; ContractPerformance of a contract; legal obligation (tax and accounting records); legitimate interests (collecting sums due)
Managing development programmes, collaborations and supplier relationships, including project co-ordination and site visitsIdentity and Contact; Professional; Correspondence; Event and VisitorPerformance of a contract; legitimate interests (delivering our programmes)
Sending news about our materials, platforms, publications, programmes and events to business contactsIdentity and Contact; Professional; Usage and MarketingLegitimate interests (promoting our business to relevant professionals); consent where required by law
Operating, securing and improving the Website, and analysing how it is usedTechnical; Usage and MarketingLegitimate interests (keeping the Website secure and improving it); consent for non-essential cookies, or the statistical-purposes exception in PECR with a right to object
Managing events, meetings and visits to our premises, including health and safetyIdentity and Contact; Event and VisitorLegitimate interests (running events safely); legal obligation (health and safety); explicit consent for access or dietary requirements
Export-control and sanctions screening, anti-bribery and counterparty due diligence, fraud prevention, and responding to lawful requests from authoritiesIdentity and Contact; Contract; ComplianceLegal obligation; legitimate interests (preventing crime and protecting our business)
Recruitment and assessment of candidatesRecruitmentSteps at your request before entering an employment contract; legitimate interests (assessing suitability); legal obligation (right to work); explicit consent or employment law for special category data
Establishing, exercising and defending our legal rights, including our intellectual property and confidential informationAny of the aboveLegitimate interests (protecting our rights); legal obligation
Corporate transactions, including investment, financing, merger, acquisition or a sale of our business or assets, including disclosure in confidence to prospective investors, acquirers and their advisersIdentity and Contact; Professional; Contract; CorrespondenceLegitimate interests (developing, financing and transferring our business)

4.2 Where we rely on legitimate interests we have considered the impact on you and concluded that our interests are not overridden by your interests, rights or freedoms. You have the right to object to processing based on legitimate interests (see section 10). Where we rely on consent you may withdraw it at any time.

4.3 We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.

5. Marketing

5.1 We may send information about our materials, platforms, publications, programmes and events to people who work for organisations that are, or that we reasonably consider may become, our customers, partners or collaborators, or who have expressed an interest in our work. We do this on the basis of our legitimate interests, or with consent where the law requires it.

5.2 You can opt out at any time by using the unsubscribe link in any marketing email or by contacting info@igii.uk. Opting out does not affect communications about contracts or programmes in which you are involved.

5.3 We do not sell personal data and do not share it with third parties for their own marketing.

6. Who we share personal data with

6.1 We may share personal data with:

  • (a) service providers who process data on our behalf, including providers of website hosting and content delivery, cloud storage and IT systems, customer-relationship management, email and communications, analytics, logistics and delivery, event and recruitment platforms, and compliance-screening services;
  • (b) our professional advisers, including lawyers, accountants, auditors, insurers and bankers;
  • (c) our development partners and customers, limited to the contact details necessary to co-ordinate programmes in which you are involved;
  • (d) regulators, courts, law-enforcement and other authorities where required by law or to protect our rights;
  • (e) prospective investors, lenders, acquirers or transferees of our business or assets, and their advisers, in confidence and subject to appropriate safeguards; and
  • (f) other companies in the Integrated Graphene group, including our parent company, Integrated Graphene Holding Limited, for group administration, governance and reporting.

6.2 We require service providers to process personal data only on our documented instructions and under written contracts that meet the requirements of the UK GDPR.

7. International transfers

7.1 Some of the organisations listed in section 6 are located outside the United Kingdom, including cloud and software providers based in the United States, and we deal with customers and partners around the world. Where we transfer personal data outside the United Kingdom we ensure that it is protected by one of the following: a UK adequacy regulation covering the destination country; the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, with any supplementary measures required; or another safeguard or derogation permitted by law, such as where the transfer is necessary to perform a contract with you. Details are available on request.

8. Security

8.1 We have put in place appropriate technical and organisational measures to prevent personal data from being accidentally lost, used, accessed, altered or disclosed in an unauthorised way, including access controls, encryption in transit, secure hosting and staff confidentiality obligations. We limit access to personal data to those who have a business need to know it. We have procedures to deal with any suspected personal data breach and will notify you and the regulator where we are legally required to do so.

9. How long we keep personal data

9.1 We keep personal data only for as long as necessary for the purposes for which we collected it, including to satisfy legal, accounting, tax and reporting requirements and to establish, exercise or defend legal claims. In determining retention periods we consider the amount, nature and sensitivity of the data, the risk of harm from unauthorised use or disclosure, and applicable legal requirements. As a guide:

  • (a) enquiries and business-contact records: for the duration of our relationship and three years after our last contact;
  • (b) contracts, invoices and payment records: six years after the end of the financial year to which they relate, as required for tax and accounting purposes;
  • (c) marketing data: until you opt out or three years after your last interaction with us;
  • (d) recruitment data for unsuccessful candidates: twelve months after the decision, unless you agree to remain in our talent pool;
  • (e) Website server logs: twelve months; and
  • (f) compliance-screening records: six years, or such longer period as the law requires.

9.2 At the end of the retention period we delete or anonymise the data.

10. Your rights

10.1 Subject to certain conditions and exemptions, you have the right to:

  • (a) access the personal data we hold about you and receive a copy of it;
  • (b) rectification of inaccurate or incomplete data;
  • (c) erasure of your data in certain circumstances;
  • (d) restriction of processing in certain circumstances;
  • (e) portability of data you have provided to us, where we process it by automated means on the basis of consent or contract;
  • (f) object to processing based on legitimate interests, and to object at any time to direct marketing;
  • (g) withdraw consent at any time where we rely on consent; and
  • (h) not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects.

10.2 To exercise any of these rights, contact info@igii.uk. We do not normally charge a fee, but we may need to verify your identity, and we may charge a reasonable fee for, or refuse, a request that is manifestly unfounded or excessive. We aim to respond within one month, which may be extended by up to two further months for complex requests.

10.3 If you are unhappy with the way we have handled your personal data, please tell us first at info@igii.uk. We will acknowledge your complaint within 30 days of receiving it, look into it without undue delay, and tell you the outcome and any action we have taken, in accordance with section 164A of the Data Protection Act 2018.

10.4 You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection: ico.org.uk, 0303 123 1113, or Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. The ICO may ask whether you have first raised your complaint with us. If you are in the EEA you may complain to your local supervisory authority.

11. Children

11.1 The Website is not directed at children, and we do not knowingly collect personal data from anyone under the age of 16.

12. Changes to this notice

12.1 We may update this notice from time to time. The date at the top shows when it was last revised. Where a change is significant we will take reasonable steps to bring it to the attention of those affected.

13. Contact

13.1 info@igii.uk — Integrated Graphene Limited, Euro House, Wellgreen Place, Stirling, FK8 2DJ, United Kingdom.


View All Policies

Let’s build
what’s next.

The future belongs to the companies that build on better materials. We’re ready when you are.

Start the conversation