Privacy Policy. What we collect, and why.
Effective: 4 September 2026Last updated: 4 September 2026
Baxter Price Engine is sold to banks and treasury teams. The only personal data this website collects is what you choose to send us through the contact form, plus the technical data every web server records and the cookies you agree to.
About this policy
This policy explains what personal data Baxter Solutions collects through the Baxter Price Engine website, why it is collected, how long it is kept, who it is shared with, and what rights you have over it. It is the privacy notice required by Articles 13 and 14 of the General Data Protection Regulation.
It applies to Baxter-it.com. It does not cover the Baxter Price Engine software itself once deployed inside a bank's own environment — where a bank runs the engine, that bank is the controller of the data flowing through it, and its own privacy notice applies. Nor does it cover third-party websites reached from links on this site.
Cookies are covered separately, in more detail, in the Cookie Policy.
Who is responsible
The data controller is:
Dublin D02PF75,
Ireland
We are not required to appoint a Data Protection Officer, and have not appointed one. Privacy questions go to the address above and are handled by Baxter It.
What we collect
3.1 Data you give us — the contact form
Submitting the form sends us the fields you filled in. First name, last name, email and your message are required; the rest are optional.
| Field | Required | Why |
|---|---|---|
| First and last name | Required | To address you properly in the reply |
| Email address | Required | To send the reply |
| Message | Required | To understand what you are asking |
| Company | Optional | To route the enquiry to the right person |
| Job title | Optional | To pitch the answer at the right level |
| Phone number | Optional | Only used if you would rather be called |
3.2 Data collected automatically — server logs
Like every web server, ours records each request: your IP address, the date and time, the page requested, the response status, your browser and operating system, and the referring page. These logs exist to keep the site running and secure — diagnosing faults, detecting abuse, blocking attacks. They are not used to build a profile of you and are not combined with the analytics data described below.
3.3 Data collected with your consent — cookies
If, and only if, you opt in, Google Analytics and our advertising tags record how you use the site. Nothing non-essential is set before you choose. Full detail, cookie by cookie, is in the Cookie Policy.
Why, and on what legal basis
Every processing operation needs a lawful basis under Article 6 of the GDPR. Ours are:
| Purpose | Data | Lawful basis |
|---|---|---|
| Replying to your enquiry | Contact form fields | Article 6(1)(b) — steps taken at your request before entering a contract, where your enquiry concerns buying or trialling the product |
| Handling general enquiries and keeping a record of correspondence | Contact form fields | Article 6(1)(f) — our legitimate interest in responding to people who contact us and running the business |
| Following up on a sales conversation you started | Name, email, company, job title | Article 6(1)(f) — legitimate interest in business-to-business marketing to a professional contact who approached us; you may object at any time |
| Keeping the site available and secure | Server logs | Article 6(1)(f) — legitimate interest in network and information security |
| Measuring how the site is used | Analytics cookies | Article 6(1)(a) — your consent, withdrawable at any time |
| Advertising and retargeting | Advertising cookies | Article 6(1)(a) — your consent, withdrawable at any time |
| Meeting legal and accounting obligations | Correspondence, where relevant | Article 6(1)(c) — compliance with a legal obligation |
Where we rely on legitimate interests, we have weighed those interests against your rights and concluded they do not override them — the data is professional contact information, you initiated the contact, and you can object at any time. Ask us and we will share that assessment.
Providing your data is voluntary. The only consequence of not providing it is that we cannot reply to you.
Cookies and analytics
Only strictly necessary cookies are set when you arrive. Analytics and advertising cookies — from Google Analytics 4, Google Ads and the LinkedIn Insight Tag — load only after you opt in, and you can withdraw that consent at any time.
The Cookie Policy lists every cookie by name, purpose, provider and duration.
Who your data is shared with
We do not sell personal data, and we do not share it for anyone else's marketing. It reaches these parties only:
| Recipient | Role | What they receive |
|---|---|---|
| Baxter Technologies Ltd. | Processor | Contact form submissions, which arrive and are stored as email in our inbox |
| Fastmail | Processor | Server logs and anything transiting the site |
| Google Ireland Limited | Processor / independent controller | Analytics and advertising data, only where you consented |
| LinkedIn Ireland Unlimited Company | Independent controller | Advertising and retargeting data, only where you consented |
| Professional advisers | Controller | Accountants or lawyers, only where a specific matter requires it |
| Public authorities | Controller | Only where we are legally obliged to disclose |
Each processor is bound by a written contract under Article 28 of the GDPR that permits them to act only on our instructions.
International transfers
Your data is processed within the European Economic Area wherever possible. Two exceptions:
- Google and LinkedIn may transfer data to the United States. Both Google LLC and Microsoft Corporation, LinkedIn's parent, are certified under the EU–US Data Privacy Framework, and the transfers are additionally covered by the European Commission's Standard Contractual Clauses.
- Our website hosting and email service providers process personal data on our behalf to operate our website and manage communications. Where these services involve transfers of personal data outside the European Economic Area (EEA), we rely on applicable adequacy decisions or appropriate safeguards, such as the European Commission's Standard Contractual Clauses. You can contact us for further information about these transfers and the safeguards used.
How Long We Keep Your Data
We retain personal data only for as long as necessary for the purposes for which it was collected, including to comply with legal obligations, fulfil contractual requirements and establish, exercise or defend legal claims.
Our retention periods are as follows:
| Data Category | Retention Period |
|---|---|
| Unsuccessful enquiries | Up to 24 months after the last interaction, where necessary for legitimate business purposes. |
| Customer correspondence | For the duration of the business relationship and afterwards as necessary to comply with legal obligations or manage potential legal claims. |
| Financial and tax records | Generally six years, or longer where required by applicable law. |
| Server logs | Up to 90 days for security and operational purposes, unless longer retention is necessary for an investigation. |
| Google Analytics data | User-level and event-level data is retained for up to 14 months, subject to Google's retention settings. Aggregated statistical reports may remain available for longer. |
| Cookie preferences | Consent preferences are refreshed at least every six months. Records evidencing consent may be retained for longer where necessary to demonstrate compliance. |
When personal data is no longer required, we delete or anonymise it, unless continued retention is necessary to comply with applicable law or for the establishment, exercise or defence of legal claims.
How we protect it
Traffic to this site is encrypted in transit with TLS. Access to the inbox holding enquiries is limited to the staff who need it and protected by multi-factor authentication. Suppliers are chosen partly on their security posture, and each is contractually bound to appropriate technical and organisational measures.
No system is perfectly secure. Where a breach is likely to result in a risk to your rights, we will notify the Data Protection Commission within 72 hours, and you directly where the risk is high.
Your rights
Under the GDPR you have the right to:
- Access — get confirmation of what we hold about you, and a copy of it.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — have data deleted where we no longer need it, or where you withdraw consent.
- Restriction — have processing paused while a dispute about accuracy or legitimate interests is resolved.
- Portability — receive data you gave us in a structured, machine-readable format.
- Object — object to processing based on legitimate interests, including any direct marketing. Where you object to direct marketing, we stop, without exception.
- Withdraw consent — at any time, for anything based on consent, without affecting what was lawful beforehand.
Write to info@baxter-it.com. We reply within one month, as Article 12(3) requires, and may extend that by two months for a complex request — we will tell you if we do. There is no charge unless a request is manifestly unfounded or excessive. We may ask you to confirm your identity before disclosing data.
Profiling and automated decisions
We make no decisions about you by automated means that produce legal effects or similarly significantly affect you. Nothing on this site decides whether you get a product, a price or a service.
Where you consent to advertising cookies, Google and LinkedIn do build an interest profile of your browser in order to show you relevant ads. That is profiling in the GDPR's sense, it happens only with your consent, and refusing or withdrawing consent to advertising cookies stops it.
Changes, contact and complaints
This policy is reviewed at least once a year, and whenever what we collect or who receives it changes. The effective date at the top records the current version. Material changes are flagged on the site before they take effect.
Questions, or to exercise any right above: info@baxter-it.com, or the postal address in section 02.
If you are not satisfied with our response, you can complain to the Irish supervisory authority:
Dublin 2, D02 RD28,
Ireland
If you live in another EEA state, you may complain to your local supervisory authority instead. You also have the right to an effective judicial remedy.