Legal

Privacy notice

Last updated

This notice explains how IT SOLVER LTD ("ITSolver", "we") uses personal data when you visit itsolver.co.uk or contact us through it. It applies to visitors and prospective clients. Personal data we process while delivering services to clients is covered by the data processing agreement for that engagement.

1. Who is responsible

IT SOLVER LTD is the controller. We are registered in England and Wales, company number 15142116, with our registered office at 108 Tunstall Crescent, Nottingham NG8 5PT, United Kingdom. You can reach us at support@itsolver.co.uk or +44 115 678 5537.

2. What we collect and why

Contact enquiries

When you use the contact form or email us we process the details you provide: your name, organisation, work email address, the topic you choose and your message. We use them to understand your request, reply and, where you ask us to, prepare a proposal.

Lawful basis: our legitimate interest in responding to business enquiries and, where you are asking about our services, taking steps at your request prior to entering into a contract (UK GDPR and EU GDPR Article 6(1)(b) and 6(1)(f)). We do not rely on consent for this, and we do not add you to marketing lists.

Security and abuse prevention

The contact form is protected by Cloudflare Turnstile, which verifies that a submission comes from a person. Turnstile processes technical information about your browser and connection, including your IP address, to make that decision. Our hosting provider also records IP addresses in short-lived server logs. Lawful basis: our legitimate interest in keeping the website and our mailbox free from automated abuse (Article 6(1)(f)).

Website analytics

We measure page views and web performance using Vercel Web Analytics and Speed Insights. These services do not use cookies or persistent identifiers. A hashed, anonymised request identifier is discarded within 24 hours; only aggregated statistics such as page, country and device type are retained. Lawful basis: legitimate interest in understanding how the website is used (Article 6(1)(f)).

Error monitoring

If something on the website fails, a technical error report is sent to Sentry so that we can fix it. A report contains the error message and code location, the page address, browser and operating system type, and the time. We have configured Sentry not to record IP addresses, cookies, form contents or other identifying data, and it sets no cookies. Reports are stored in Sentry's European Union data region and deleted after 90 days. Lawful basis: legitimate interest in keeping the website working correctly (Article 6(1)(f)).

3. Cookies and similar technologies

This website sets no advertising, tracking or analytics cookies. Cloudflare Turnstile may store a short-lived technical token in your browser strictly to complete the verification; this is strictly necessary for the contact form to work and does not require consent under the Privacy and Electronic Communications Regulations. Because we use no non-essential cookies, the website does not show a cookie banner.

4. Who receives your data

We use a small number of service providers acting on our instructions:

  • Vercel Inc. (United States) hosts the website and runs the contact form function. The function that processes your enquiry runs in Frankfurt, Germany.
  • Cloudflare, Inc. (United States) provides Turnstile verification for the contact form.
  • Resend, Inc. (United States) delivers the contact form email to our mailbox using its EU sending region (Ireland) and sends an acknowledgement to you where enabled.
  • Microsoft Ireland Operations Ltd. provides the Microsoft 365 mailbox in which your enquiry is received and answered.
  • Functional Software, Inc. (Sentry) (United States) receives technical error reports, stored in its European Union data region (Frankfurt, Germany).

We do not sell personal data and we do not share it with advertisers. We may disclose data if required by law or to protect our legal rights.

5. International transfers

We are established in the United Kingdom. Personal data of visitors in the European Union is transferred to the UK under the European Commission's adequacy decision for the UK. Some of our providers are headquartered in the United States; where personal data is transferred there we rely on the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, and on the provider's certification under the EU-US Data Privacy Framework and its UK Extension where applicable. Copies of the relevant safeguards are available on request.

6. How long we keep data

  • Enquiry emails and any notes: up to 24 months after our last exchange, unless an engagement follows, in which case they become part of the client record and are retained for the duration of the relationship plus the statutory limitation period.
  • Server logs held by our hosting provider: a short period, typically no more than 30 days.
  • Email delivery logs held by Resend: a limited period set by the provider for troubleshooting.
  • Analytics: aggregated only; no personal data is retained.
  • Error reports held by Sentry: 90 days.

7. Your rights

Under the UK GDPR and, where it applies, the EU GDPR you have the right to access the personal data we hold about you, to have it corrected or erased, to restrict or object to its processing, and to data portability. Where processing relies on legitimate interests you may object at any time; we will stop unless we can show compelling legitimate grounds.

To exercise these rights, email support@itsolver.co.uk. We respond within one month. You also have the right to complain to the Information Commissioner's Office (ico.org.uk) or, if you are in the EU, to your local supervisory authority.

8. Representative in the European Union

IT SOLVER LTD has no establishment in the European Union. We have assessed our obligations under Article 27 EU GDPR: our processing of personal data relating to people in the EU through this website is occasional, does not include large-scale processing of special categories of data or data relating to criminal convictions, and is unlikely to result in a risk to the rights and freedoms of individuals. On that basis we have not appointed an EU representative. We keep this assessment under review and will update this notice if it changes.

9. How we protect data

Access to our mailbox and systems is limited to staff who need it, protected by single sign-on with multi-factor authentication. Data is encrypted in transit and at rest by our providers. Our website security practices are described on the security and operations page.

10. Children

This website is directed at businesses and is not intended for children under 16.

11. Changes to this notice

We update this notice when our practices or providers change. The date at the top shows the current version. Significant changes are highlighted on this page.

Contact

Start a conversation

Tell us about your environment and what you want to change. An engineer replies within one business day.