Privacy Policy and Data Protection

Privacy and Data

Privacy Policy, Cookie Policy & Data Processing Agreement

Privacy Policy, Data Protection & Cookie Policy

Last Updated: 04/05/2026

1. Introduction

This document outlines how we collect, use, process, and protect personal data in accordance with UK GDPR and the Data Protection Act 2018.

By using our services, you agree to this policy.

2. Data Controller Details

[Company Name]

[Registered Address]

Email: [Insert Email]

ICO Registration Number: [Insert if applicable]

3. Data We Collect

  • Identity data (name, company)
  • Contact data (email, phone)
  • Technical data (IP address, logs, device info)
  • Support data (system access, diagnostics)
  • Financial data (billing, invoices)

4. Legal Basis

  • Contractual necessity
  • Legitimate interest (IT support, security)
  • Legal compliance
  • Consent (cookies/marketing)

5. How We Use Data

  • Deliver IT services
  • Provide support and diagnostics
  • Maintain system security
  • Process payments
  • Improve services

6. Data Retention

  • Client records: up to 6 years (legal requirement)
  • Support logs: 12–24 months
  • Inactive enquiries: 12 months

7. Data Security

  • Encryption and secure systems
  • Access control and authentication
  • Regular vulnerability checks

8. Your Rights

  • Access your data
  • Request correction or deletion
  • Restrict or object
  • Data portability
  • Lodge complaint with ICO

9. Cookie Policy

We use cookies to improve performance and user experience.

Types of Cookies:

  • Essential (site functionality)
  • Analytics (traffic insights)
  • Functional (preferences)

You can manage cookies via browser settings or consent banner.

10. Data Sharing

We only share data where necessary:

  • Hosting providers
  • Payment processors
  • Legal authorities

11. International Transfers

Where data leaves the UK, safeguards such as Standard Contractual Clauses are used.

12. Data Breach Procedures

  • Immediate containment
  • Risk assessment
  • Notification within 72 hours if required

13. Data Processing Agreement (DPA)

When acting as a Data Processor on behalf of clients:

  • We only process data under client instruction
  • We implement strict security measures
  • We ensure staff confidentiality
  • We assist with data subject requests
  • We delete or return data upon contract end

Client Responsibilities (Controller)

  • Ensure lawful data collection
  • Provide clear instructions
  • Maintain compliance with GDPR

14. Third-Party Services

We are not responsible for external services linked or integrated.

15. Updates

We may update this document. Continued use means acceptance.

16. Contact

Email: [Insert Email]

Address: [Insert Address]

Scroll to Top