Privacy Policy
This is Superfast IT's Privacy Notice. It tells you waht personal data we collect about you, how we use use it, who we share it with, how long we keep it, and the rights you have. It satisfies out transparency obligations under articles 13 and 14 of the UK GDPR.
Superfast IT Limited ("Superfast IT", "we", "us", "our") is a UK-registered managed IT and cyber security services provider. We are the data controller for personal data we collect directly about you when you visit our website, enquire about or buy our services, apply to work with us, work for us, or supply goods and services to us.
Company number: 04365871. Registered office: Suite 2, Winwood Court, Norton Road, Stourbridge, West Midlands, DY8 2AE. Telephone: 0121 309 0090.
When we deliver services into a client's environment, we usually act as a data processor for personal data inside that environment. The client is the controller, and processing is governed by the Data Processing Agreement attached to their contract. This notice covers our controller activities only.
This notice applies to personal data we control about:
-
visitors to our website and people who interact with us on social media
-
prospective clients and the contacts at organisations we market to
-
clients and the named contacts at client organisations who interact with our service desk and account team
-
applicants for roles at Superfast IT
-
our employees, contractors and former staff (a fuller staff privacy notice is issued through the HR system at onboarding)
-
suppliers and the named contacts at supplier organisations
-
visitors to our premises captured by CCTV and the door-camera system
-
students placed with us through school work experience programmes
We group the personal data we collect into the categories below.
Category |
What it includes |
|
Identity data |
Name, title, job title, employer, professional accreditations. |
|
Contact data |
Work email address, postal address, telephone numbers. |
|
Financial data |
Bank account and billing details for clients and suppliers. We do not store payment card details; card payments are handled directly by our payment provider. |
|
Transaction data |
Records of services purchased, quotes, invoices, payments and credit notes. |
|
Service data |
Support tickets, communications with our service desk, account notes, meeting summaries and call recordings where notice is given. |
|
Technical data |
IP address, browser type and version, device and operating system, time zone, referral source, and pages viewed on our website. |
|
Profile and marketing data |
Interests, sector, contact preferences, marketing consents and opt-out history, survey and feedback responses, event registrations.
|
|
Applicant data |
CV, application form, references, right-to-work evidence, interview notes, basic DBS results where a role requires one. |
|
CCTV and door-camera footage |
Images and short clips captured at our premises for safety and crime prevention. Audio is disabled where the platform allows. |
We do not knowingly collect special category data (such as health, ethnicity, religion or biometric data) about visitors, prospects or clients. We hold limited special category and criminal offence data about employees and certain applicants, where there is a clear lawful basis under the Data Protection Act 2018 Schedule 1.
Our website is not directed at children. The only situation in which we control children's personal data is school work experience placements, and the dataset is limited to the student's name and school.
We collect personal data from you directly when you fill in a form on our website, subscribe to our newsletter, request a quote, send us an email, call us, attend an event, raise a support ticket, apply for a role, sign a contract with us, or visit our premises.
We collect technical and usage data automatically through cookies and similar technologies when you visit our website. Cookies are explained in section 11.
We also receive personal data about you from third parties and public sources, including Companies House, the Electoral Register, LinkedIn and other public profiles, lead-generation platforms we license, payment and accounting providers, recruitment agencies and referees you nominate, and credit reference agencies where we are extending credit terms.
We only use personal data where the UK GDPR allows us to. The table below shows what we do, the type of data involved, and the lawful basis we rely on. For some activities more than one basis applies; the most relevant is listed first.
What we do |
Categories of data |
Lawful basis |
|
Respond to enquiries and provide quotes |
Identity, Contact, Service |
Legitimate interests (responding to your request), or steps before entering into a contract. |
|
Provide our services, including service desk support, account management and incident response |
Identity, Contact, Service, Transaction, Technical |
Performance of a contract with the client; legitimate interests where the contact is an authorised representative of the client.
|
|
Bill clients, manage payments and recover debts |
Identity, Contact, Financial, Transaction |
Performance of a contract; legitimate interests (recovering money owed); legal obligation (HMRC record-keeping). |
|
Pay suppliers and manage supplier relationships |
Identity, Contact, Financial, Transaction |
Performance of a contract; legal obligation. |
|
Send marketing emails and newsletters about our services |
Identity, Contact, Profile and marketing |
Legitimate interests for B2B corporate subscribers (with a documented assessment and clear opt-out in every message); consent for sole traders and partnerships, and where required under PECR. |
|
Run our website, measure traffic and improve content |
Technical, Profile and marketing |
Consent for non-essential cookies; legitimate interests for essential website operation. |
|
Recruit for roles at Superfast IT |
Applicant data |
Steps before entering into a contract; legitimate interests for general candidate management; legal obligation for right-to-work checks. |
|
Operate CCTV and door cameras at our premises |
CCTV and door-camera footage |
Legitimate interests (safety, crime prevention, incident investigation), supported by a Legitimate Interests Assessment. |
|
Monitor our networks, systems and email for security and policy compliance |
Technical, Service |
Legitimate interests (protecting our systems and our clients' data); legal obligation (e.g. data protection, regulatory). |
|
Comply with legal, tax and regulatory obligations and respond to lawful requests |
All categories as needed |
Legal obligation. |
|
Defend or bring legal claims |
All categories as needed |
Legitimate interests (establishing, exercising or defending legal claims). |
Where we rely on consent (for example for non-essential cookies, or for marketing to a sole trader), you can withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
We share personal data only with parties who need it for the purposes set out in this notice and only under appropriate written terms.
Sub-processors that handle personal data on our behalf to deliver our services are listed in our Sub-processor List, which we keep current. The list is available at superfast-it.notion.site/client-assurance-pack. Each sub-processor is bound by a written contract that includes UK GDPR Article 28 obligations.
Other recipients include our accountant, our cyber insurer and broker, our solicitor, our pension provider and our bank, all under their own professional and legal duties. We share data with HM Revenue and Customs and other public authorities where the law requires it. We share data with law enforcement and regulators where the law requires it or to defend our rights. If we sell or restructure parts of our business, personal data may be transferred to a successor entity that takes on the same obligations.
We do not sell personal data, and we do not share it with third parties for their own marketing.
Most of the personal data we control stays in the United Kingdom or the European Economic Area. Some of our sub-processors are headquartered outside the UK, and limited processing may take place in the United States or other countries.
Where personal data leaves the UK we rely on one of the following safeguards: a UK adequacy decision (including the UK extension to the EU-US Data Privacy Framework, often called the UK-US Data Bridge); the UK International Data Transfer Agreement (IDTA); or the EU Standard Contractual Clauses with the UK International Data Transfer Addendum. A transfer risk assessment is recorded for each arrangement where a UK adequacy decision does not apply. Our Data Protection Lead approves every international transfer before it is implemented.
We keep personal data only for as long as we need it for the purposes set out in this notice, or for a longer period where the law requires us to. Retention periods by data category are set in our Data Retention Policy and recorded in our Data Register. Examples include:
-
enquiry and lead data: retained while there is a live commercial relationship and for a limited period afterwards, then deleted or anonymised
-
client service records and contracts: retained for the life of the contract and for six years after termination to meet legal and tax obligations
-
finance and tax records: retained for at least seven years to meet HMRC requirements
-
applicant data for unsuccessful candidates: retained for up to twelve months for candidate management, then deleted unless you have agreed otherwise
-
CCTV footage: retained for thirty days by default, unless required for an investigation or legal claim
-
website analytics: retained per the cookie and analytics provider's defaults, as described in our cookie banner
When personal data is no longer needed it is securely deleted or anonymised.
In some circumstances you can ask us to delete your data: see “Request erasure” below for further information.
In some circumstances, we may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes in which case we may use this information indefinitely without further notice to you.
We operate a documented information security programme aligned to Cyber Essentials Plus, IASME Cyber Assurance, the IASME Quality Principles and the UK Cyber Assessment Framework (CAF 4). Controls include encryption in transit and at rest, phishing-resistant multi-factor authentication, least-privilege access, vulnerability management, logging and monitoring, and tested incident response.
Where a personal data breach occurs and is likely to risk your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware. Where the risk is high we will also notify you directly without undue delay.
You have rights over your personal data under the UK GDPR:
-
the right to be informed (this notice and any further notices we give you at the point of collection)
-
the right of access (a copy of the personal data we hold about you)
-
the right to rectification (correction of inaccurate or incomplete data)
-
the right to erasure in defined circumstances
-
the right to restrict processing in defined circumstances
-
the right to data portability for data you provided to us and which we process by automated means under consent or contract
-
the right to object, including an absolute right to object to direct marketing
-
the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects (we do not currently make such decisions)
-
the right to withdraw consent where we rely on consent
To exercise any of these rights, contact us using the details in section 14. We respond within one calendar month, extendable by a further two months for complex or numerous requests, in which case we will tell you why. We may need to verify your identity before responding.
Where your request relates to personal data we process on behalf of a client (for example, your employer), we will forward the request to that client without undue delay and support them in responding under the Data Processing Agreement.
Our website uses cookies and similar technologies. Strictly necessary cookies are required for the website to work and are set without consent. Analytics, marketing and preference cookies are only set after you give consent through our cookie banner. You can withdraw or change consent at any time using the cookie controls on the site. Most browsers also allow you to block or delete cookies. If you block cookies, parts of the website may not work as intended.
We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. We may use simple segmentation (for example by sector or company size) to tailor marketing communications. You can opt out of marketing at any time using the link in every marketing email or by contacting us.
If you are unhappy with how we have handled your personal data, please contact us first using the details in section 14 so we can try to put things right.
You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection. The ICO can be reached at ico.org.uk, on 0303 123 1113, or by post at Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
Our Data Protection Lead is James Cash, Managing Director. Day-to-day data protection operations are supported by Mark Poulding, Information Security Manager.
For any privacy question, to make a request about your rights, or to raise a concern, contact us at hello@superfast-it.com, on 0121 309 0090, or by post at Suite 2, Winwood Court, Norton Road, Stourbridge, West Midlands, DY8 2AE.
We review this notice at least once a year and whenever a change to our processing, our suppliers or applicable law requires it. The version and last review date are shown at the top of the page. Where a change materially affects how we handle your data, we will tell you directly where we can.