Privacy Policy
PRIVACY POLICY
Effective Date: 01/09/2026
Last Updated: 01/09/2026
Company Name: North IT Services Ltd
Registered Address: [Company Address]
Email: [Privacy Email Address]
Website: North-ITServiices.co.uk
1. Introduction
At North IT Services we respect your privacy and is committed to protecting your personal data.
This Privacy Policy explains how we collect, use, store, disclose and protect personal information when you:
- visit or use our website;
- contact us;
- purchase or use our IT products or services;
- enter into a contract with us;
- subscribe to our services or communications;
- interact with us as a customer, supplier, business partner or prospective customer; or
- otherwise provide personal information to us.
We process personal data in accordance with applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as applicable.
2. Who We Are
The organisation responsible for your personal data is:
North IT Services Ltd
[Registered Address]
[Company Registration Number]
[Email Address]
[Telephone Number]
For privacy-related enquiries, please contact us using the details above.
Where applicable, our Data Protection Officer or designated privacy contact can be reached at:
[DPO/Privacy Contact Email]
3. Personal Data We Collect
Depending on how you interact with us, we may collect the following categories of personal information:
Contact Information
- Name
- Email address
- Telephone number
- Postal or business address
- Company name
- Job title
Customer and Account Information
- Account details
- Service subscriptions
- Purchase and order information
- Contract information
- Customer communications
- Support requests
Technical Information
When you use our website or IT services, we may collect information such as:
- IP address
- Browser type and version
- Device information
- Operating system
- Login information
- Website usage information
- Diagnostic and technical information
- Cookies and similar technologies
Payment Information
Where applicable, we may process information necessary to administer payments, invoices and financial transactions.
Payment card details may be processed directly by our third-party payment providers rather than being stored by us.
Information You Provide to Us
We may also collect information that you voluntarily provide when you:
- complete an enquiry or contact form;
- communicate with our staff;
- request technical support;
- participate in surveys;
- register for an account;
- subscribe to marketing communications; or
- provide information in connection with our services.
4. How We Use Your Personal Data
We may use personal data for the following purposes:
- Providing and managing our IT products and services;
- Creating and administering customer accounts;
- Processing orders and payments;
- Providing customer and technical support;
- Communicating with customers and prospective customers;
- Responding to enquiries;
- Managing contracts and business relationships;
- Maintaining and improving our website, systems and services;
- Monitoring and maintaining the security of our systems;
- Detecting and preventing fraud, misuse and security incidents;
- Sending service-related communications;
- Sending marketing communications where legally permitted;
- Managing our business operations and records;
- Complying with legal and regulatory obligations; and
- Establishing, exercising or defending legal claims.
We will only use personal data for purposes that are compatible with the purposes for which it was collected, or where otherwise permitted by applicable law.
5. Lawful Bases for Processing
Under the UK GDPR, we will rely on one or more lawful bases when processing personal data.
These may include:
Contract
We may process personal data where it is necessary to enter into or perform a contract with you.
For example, this may include providing IT services, processing orders or managing customer accounts.
Legal Obligation
We may process personal data where necessary to comply with a legal or regulatory obligation.
Legitimate Interests
We may process personal data where it is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms.
Examples may include:
- operating and improving our services;
- maintaining network and information security;
- preventing fraud and misuse;
- managing business relationships; and
- administering our business.
Where we rely on legitimate interests, we will consider the impact on your rights and interests before processing your information.
Consent
Where required, we may rely on your consent to process personal data.
Where processing is based on consent, you may withdraw your consent at any time. Withdrawal of consent will not affect the lawfulness of processing carried out before withdrawal.
6. Marketing
We may send you information about our products, services, offers or company updates where permitted by applicable law.
You can unsubscribe from marketing communications at any time by:
- using the unsubscribe facility provided in the communication; or
- contacting us using the details provided in this Privacy Policy.
We will not make receiving marketing communications a condition of purchasing our services.
7. Cookies and Similar Technologies
Our website may use cookies and similar technologies to:
- operate the website;
- remember preferences;
- understand website usage;
- improve website performance; and
- where permitted, support analytics or marketing activities.
Where consent is required for non-essential cookies, we will request your consent before placing or using those cookies.
You can manage your cookie preferences through our cookie consent mechanism or your browser settings.
8. Sharing Personal Data
We may share personal data with trusted third parties where necessary to provide our services, operate our business or comply with legal obligations.
These may include:
- cloud hosting providers;
- IT and cybersecurity providers;
- software and SaaS providers;
- payment processors;
- professional advisers;
- accountants and auditors;
- telecommunications providers;
- customer relationship management providers;
- email and communications providers;
- analytics providers;
- insurers; and
- government, regulatory or law-enforcement authorities where legally required.
We require appropriate safeguards from third parties that process personal data on our behalf and, where applicable, enter into appropriate data processing agreements.
We do not sell personal data to third parties.
9. International Data Transfers
Some of our service providers may process personal data outside the United Kingdom.
Where personal data is transferred internationally, we will ensure that appropriate safeguards are in place as required by applicable data protection law.
These safeguards may include:
- UK adequacy regulations;
- adequacy decisions;
- International Data Transfer Agreements (IDTAs);
- UK Addendums to approved Standard Contractual Clauses; or
- other lawful transfer mechanisms.
10. Data Security
We take appropriate technical and organisational measures to protect personal data against:
- unauthorised access;
- accidental loss;
- destruction;
- alteration;
- disclosure; and
- other unlawful or unauthorised processing.
Depending on the nature of the information and our services, security measures may include access controls, authentication, encryption, backups, monitoring, secure infrastructure and staff security procedures.
However, no method of transmitting or storing information can be guaranteed to be completely secure.
11. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including to:
- provide our services;
- maintain business and accounting records;
- comply with legal and regulatory obligations;
- resolve disputes; and
- establish, exercise or defend legal claims.
The exact retention period will depend on the type of information and the purpose for which it is processed.
When personal data is no longer required, we will securely delete, anonymise or otherwise dispose of it in accordance with our retention procedures.
12. Your Data Protection Rights
Subject to applicable law, you may have the following rights:
- Right to be informed about how your personal data is used;
- Right of access to your personal data;
- Right to rectification of inaccurate or incomplete information;
- Right to erasure ("right to be forgotten") in certain circumstances;
- Right to restrict processing in certain circumstances;
- Right to data portability in certain circumstances;
- Right to object to certain processing, including direct marketing;
- Right to withdraw consent where processing is based on consent; and
- Rights relating to automated decision-making and profiling, where applicable.
These rights are not absolute and may be subject to legal conditions and exemptions.
13. How to Exercise Your Rights
To exercise any of your data protection rights, please contact us:
Email: [Privacy Email Address]
Postal Address: [Company Address]
We may need to verify your identity before responding to your request.
We will normally respond to valid requests within the period required by applicable data protection law.
14. Complaints
If you have concerns about how we process your personal data, we encourage you to contact us first so that we can investigate and resolve your concern.
You also have the right to complain to the UK's data protection supervisory authority:
Information Commissioner's Office (ICO)
Website: https://ico.org.uk/
The ICO is the UK's independent authority responsible for upholding information rights.
15. Children's Data
Our services are not generally directed at children, and we do not knowingly collect children's personal data where it is not necessary for the provision of our services.
If you believe that a child has provided personal information to us without appropriate consent, please contact us so that we can investigate and take appropriate action.
16. Automated Decision-Making and Profiling
We do not currently make decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects on individuals, unless we inform you otherwise and provide any rights required by applicable law.
17. Third-Party Websites
Our website may contain links to third-party websites or services.
We are not responsible for the privacy practices, content or security of third-party websites. We recommend reviewing the privacy policy of any third-party website you visit.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our business, services, technology or applicable legal requirements.
The latest version will be published on our website with the relevant "Last Updated" date.
Where required, we will take reasonable steps to notify individuals of significant changes before they take effect.
19. Contact Us
If you have any questions about this Privacy Policy or how we process personal data, please contact:
North IT Services Ltd
Address: [Company Address]
Email: [Privacy Email Address]
Telephone: [Telephone Number]
Privacy Policy Version: 1.0
Effective Date: 01/09/2026
Last Reviewed: 01/09/2026
