• Plan Your Expansion

      countries

      Where To Expand First

      Helping brands launch, localise and thrive in the UK & EU’s top markets

      expansion-globale

      Global Expansion Pathway (GEP©)

      Successful international expansion starts with informed decisions.

      expert-tips

      Expansion Videos

      Plan your global expansion with expert led videos and strategies.

      FAQ's

      Ask-Andy-Anything

      Ask Andy Anything

      A place where our eCommerce Guru, Andy Hooper, gets to answer all your questions.

      Events

      upcoming events

      Upcoming Events

      Discover expert-led sessions, workshops, and opportunities to connect and grow.

  • Expandly3PL
  • Prices
  • Book Demo
  • Contact

Privacy Policy

1. Who We Are

This privacy policy explains how GEE Expandly Ltd (trading as Expandly) collects, uses, stores and protects your personal data when you use our website at www.expandly.com, www.expandly3pl.com or engage with our services.

Data Controller: GEE Expandly Ltd, Botley Mills, Southampton, Hampshire, SO30 2GB, United Kingdom
Data Protection Officer: data@expandly.com
ICO Registration Number: ZB796188

We are registered with the Information Commissioner’s Office (ICO) as a data controller.

2. Legal Framework

We process your personal data in accordance with:

  • The UK General Data Protection Regulation (UK GDPR)
  • The Data Protection Act 2018
  • The Privacy and Electronic Communications Regulations 2003 (PECR)

This policy replaces all previous versions, including any policy issued prior to May 2018.

3. What Personal Data We Collect

3.1 Data you provide directly

  • Full name and job title
  • Company name and registered address
  • Contact details including email address and telephone number
  • Demographic information such as postcode, preferences and interests
  • Information provided through customer surveys, enquiry forms or correspondence

3.2 Data collected automatically

  • IP address and browser type
  • Pages visited, time spent on site and referring URLs
  • Cookie identifiers (see Section 8)

3.3 Client business data (SaaS platform users)

If you are a client using the Expandly platform, we also process sales data, order data and marketplace performance data that you upload or connect to our platform. This is processed to deliver the contracted service and to power our AI-assisted recommendations (see Section 7).

4. Lawful Bases for Processing

Under UK GDPR, we are required to have a lawful basis for processing your personal data. We rely on the following:

4.1 Consent (Article 6(1)(a))

We rely on your consent to send you marketing communications and to place non-essential cookies on your device. You may withdraw consent at any time by contacting data@expandly.com or using the unsubscribe link in any marketing email.

4.2 Contract Performance (Article 6(1)(b))

Where you are a client or in the process of entering into an agreement with us, we process your data as necessary to fulfil that contract — for example, to set up your account, deliver the platform, and provide support.

4.3 Legitimate Interests (Article 6(1)(f))

We process certain data based on our legitimate business interests, including improving our website and services, conducting market research, and detecting fraud or misuse. Where we rely on this basis, we have conducted a Legitimate Interests Assessment (LIA) to ensure our interests do not override your rights.

4.4 Legal Obligation (Article 6(1)(c))

We may process your data where we are required to do so by law — for example, to comply with HMRC obligations, court orders, or regulatory requirements.

5. How We Use Your Personal Data

  • To provide and improve our website and platform services
  • To respond to enquiries and manage your account
  • To fulfil contractual obligations
  • To send service-related communications (transactional emails, updates)
  • To send marketing communications where you have consented
  • To conduct market research and analyse usage patterns to improve our services
  • To generate AI-assisted strategic recommendations (see Section 7)
  • To comply with legal and regulatory obligations
  • To detect, prevent and investigate fraud or security incidents

6. How Long We Keep Your Data

We do not keep your personal data for longer than necessary. Our standard retention periods are:

  • Client account data: retained for the duration of the contract and for 6 years thereafter (in line with the Limitation Act 1980)
  • Marketing contact data: retained until you withdraw consent or opt out
  • Website analytics data: retained for 26 months
  • Correspondence and support records: retained for 3 years after the last interaction

After the relevant retention period, data is securely deleted or anonymised.

7. AI-Assisted Recommendations and Automated Processing

Expandly uses AI-powered analysis to help clients identify suitable international marketplaces and regions for business expansion. This involves processing your sales data, order history and marketplace performance data to generate strategic suggestions.

Important points about this processing:

  • The AI recommendations are advisory only — they do not constitute binding decisions and do not produce legal or similarly significant effects on you as an individual
  • A human review step is available and encouraged before acting on any AI-generated suggestion
  • This processing is carried out under our legitimate interests basis and, where applicable, under contract performance
  • Your client data is used solely to generate recommendations for your own business — it is not used to train shared models or benchmarked against other clients’ data without anonymisation

You have the right to request human review of any AI-generated output that affects your business relationship with us. Please contact data@expandly.com to exercise this right.

8. Cookies

8.1 What are cookies?

Cookies are small text files placed on your device when you visit a website. They allow the site to recognise your device on subsequent visits and store preferences.

For more information about cookies generally, visit www.allaboutcookies.org or www.youronlinechoices.eu.

8.2 Cookies we use

Category 1 — Strictly necessary cookies: These are essential for the website to function. They cannot be disabled. No consent is required for these cookies.

Category 2 — Performance cookies: These collect anonymous data about how visitors use our site (e.g. pages visited, error pages). They help us improve the site. We will only place these cookies with your consent.

Category 3 — Functionality cookies: These remember your preferences (e.g. language, region) to provide a more personalised experience. We will only place these cookies with your consent.

Category 4 — Targeting and advertising cookies: These track your browsing to deliver relevant adverts and measure campaign effectiveness. We will only place these cookies with your explicit consent.

8.3 Managing your cookie preferences

When you first visit our website, you will be presented with a cookie consent banner. You may accept or decline non-essential cookies at that point, or update your preferences at any time via the cookie settings link in our website footer.

Please note: simply continuing to use our website does not constitute consent to non-essential cookies.

9. Sharing Your Personal Data

We will not sell, rent or trade your personal data. We may share your data in the following limited circumstances:

  • With trusted third-party service providers who process data on our behalf (e.g. cloud hosting, email platforms, analytics tools) — all governed by data processing agreements under Article 28 UK GDPR
  • With professional advisors (lawyers, accountants, auditors) under obligations of confidentiality
  • With regulators or law enforcement where we are legally required to do so
  • In the event of a merger, acquisition or business sale, where data may transfer to a successor entity (you will be notified)

We do not share your data with third parties for their own marketing purposes unless you have explicitly consented.

10. International Data Transfers

As a business supporting international ecommerce expansion, some of our service providers may be located outside the UK. Where we transfer personal data outside the UK, we ensure appropriate safeguards are in place, including:

  • UK adequacy regulations (for countries recognised as providing adequate protection)
  • International Data Transfer Agreements (IDTAs) approved by the ICO
  • Standard Contractual Clauses (SCCs) where applicable

You may request details of the safeguards in place for any specific transfer by contacting data@expandly.com.

11. Your Rights Under UK GDPR

  • Right of access — to request a copy of the personal data we hold about you (Subject Access Request)
  • Right to rectification — to ask us to correct inaccurate or incomplete data
  • Right to erasure — to request deletion of your data in certain circumstances (‘right to be forgotten’)
  • Right to restriction — to ask us to limit processing in certain circumstances
  • Right to data portability — to receive your data in a structured, machine-readable format
  • Right to object — to object to processing based on legitimate interests or for direct marketing
  • Rights in relation to automated decision-making — to request human review of AI-generated outputs that affect you
  • Right to withdraw consent — at any time, without affecting the lawfulness of prior processing

To exercise any of these rights, please contact: data@expandly.com

We will respond to all valid requests within one calendar month. There is no charge for exercising your rights. If a request is manifestly unfounded or excessive, we may charge a reasonable fee or refuse, and will explain why.

12. Security

We take the security of your personal data seriously. We have implemented appropriate technical and organisational measures including:

  • Encryption of data in transit (TLS) and at rest
  • Access controls and role-based permissions
  • Regular security assessments and penetration testing
  • Staff training on data protection and information security
  • Incident response procedures in line with ICO breach notification requirements

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and inform affected individuals without undue delay, as required by Article 33–34 UK GDPR.

13. Third-Party Websites

Our website may contain links to external websites. We are not responsible for the privacy practices of those sites and this policy does not apply to them. We recommend reviewing the privacy policy of any external site you visit.

14. Children’s Data

Our website and services are directed at business users and are not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact data@expandly.com immediately.

15. Complaints

If you have concerns about how we handle your personal data, please contact us in the first instance at data@expandly.com. We will aim to resolve your concern promptly.

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at any time:

  • Website: www.ico.org.uk
  • Telephone: 0303 123 1113
  • Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

16. Changes to This Policy

We may update this policy from time to time to reflect changes in law, technology or our business practices. When we make significant changes, we will notify you by email (where we hold your address) and update the ‘Last updated’ date at the top of this page. We encourage you to review this policy periodically.

17. Contact Us

  • Email: data@expandly.com
  • Post: Data Protection Officer, GEE Expandly, Botley Mills, Southampton, Hampshire, SO30 2GB, United Kingdom

This policy is governed by and construed in accordance with the laws of England and Wales.