Privacy and Data
Privacy Policy, Data Protection & Cookie Policy
Last Updated: 04/05/2026
1. Introduction
This document outlines how we collect, use, process, and protect personal data in accordance with UK GDPR and the Data Protection Act 2018.
By using our services, you agree to this policy.
2. Data Controller Details
[Company Name]
[Registered Address]
Email: [Insert Email]
ICO Registration Number: [Insert if applicable]
3. Data We Collect
- Identity data (name, company)
- Contact data (email, phone)
- Technical data (IP address, logs, device info)
- Support data (system access, diagnostics)
- Financial data (billing, invoices)
4. Legal Basis
- Contractual necessity
- Legitimate interest (IT support, security)
- Legal compliance
- Consent (cookies/marketing)
5. How We Use Data
- Deliver IT services
- Provide support and diagnostics
- Maintain system security
- Process payments
- Improve services
6. Data Retention
- Client records: up to 6 years (legal requirement)
- Support logs: 12–24 months
- Inactive enquiries: 12 months
7. Data Security
- Encryption and secure systems
- Access control and authentication
- Regular vulnerability checks
8. Your Rights
- Access your data
- Request correction or deletion
- Restrict or object
- Data portability
- Lodge complaint with ICO
9. Cookie Policy
We use cookies to improve performance and user experience.
Types of Cookies:
- Essential (site functionality)
- Analytics (traffic insights)
- Functional (preferences)
You can manage cookies via browser settings or consent banner.
10. Data Sharing
We only share data where necessary:
- Hosting providers
- Payment processors
- Legal authorities
11. International Transfers
Where data leaves the UK, safeguards such as Standard Contractual Clauses are used.
12. Data Breach Procedures
- Immediate containment
- Risk assessment
- Notification within 72 hours if required
13. Data Processing Agreement (DPA)
When acting as a Data Processor on behalf of clients:
- We only process data under client instruction
- We implement strict security measures
- We ensure staff confidentiality
- We assist with data subject requests
- We delete or return data upon contract end
Client Responsibilities (Controller)
- Ensure lawful data collection
- Provide clear instructions
- Maintain compliance with GDPR
14. Third-Party Services
We are not responsible for external services linked or integrated.
15. Updates
We may update this document. Continued use means acceptance.
16. Contact
Email: [Insert Email]
Address: [Insert Address]
