Need Urgent Business IT Help? (01344) 935008

Privacy Policy

Last updated: 25 August 2026 • Effective immediately

TCP123 UK ("we", "our", "us") is committed to protecting your privacy. This policy explains how we collect, use, store, and protect your personal data when you use tcp123.uk or our services. We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Contents

1. Data Controller

TCP123 UK is the data controller for personal data collected through this website. Our contact details are provided in section 13.

If you are a client receiving managed IT services from us, a separate data processing agreement governs that relationship and supplements this website privacy policy.

2. Data We Collect

We collect the following categories of personal data through our website:

2.1 Information you provide directly

  • Quote requests: contact name, business telephone number, work email address, business postcode (for ETA calculation), selected service type, optional project notes.
  • Client portal enquiries: username, password (hashed), workstation identifier (for session persistence).
  • Support tickets: name, email, ticket subject, ticket description, optional file attachments.
  • Phone calls: caller name, callback number, call purpose notes (recorded only with prior consent).

2.2 Information collected automatically

  • Server logs: IP address, browser type, referring URL, pages visited, timestamp.
  • Google Analytics 4: anonymised usage patterns, device category, approximate location (city-level).

3. Lawful Basis for Processing

Under UK GDPR Article 6, we process your personal data on the following bases:

Purpose Lawful Basis
Responding to quote requests and enquiries Contract (Article 6(1)(b)) β€” taking steps at your request prior to entering a contract
Delivering managed IT services to clients Contract (Article 6(1)(b))
Billing, accounting, and tax record-keeping Legal obligation (Article 6(1)(c)) β€” HM Revenue & Customs requirements
Website analytics, security monitoring, fraud prevention Legitimate interests (Article 6(1)(f)) β€” operating and protecting our website
Marketing communications (where you have opted in) Consent (Article 6(1)(a)) β€” withdrawable at any time

4. How We Use Your Data

We use personal data for the following purposes:

  1. To respond to your enquiries and provide quotations.
  2. To deliver managed IT services under contract.
  3. To maintain accurate business records and comply with HMRC requirements.
  4. To monitor and protect the security of our website and infrastructure.
  5. To analyse website usage and improve user experience (via anonymised analytics).
  6. To send service updates and operational communications to existing clients.
  7. To send marketing communications to subscribers (only with explicit consent).

We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.

5. Data Sharing & Third Parties

We do not sell personal data. We share data only with the following categories of processors, each bound by UK GDPR-compliant data processing terms:

  • Brevo (Sendinblue) β€” Transactional email delivery for quote responses and service notifications. EU-based, ISO 27001 certified.
  • Cloudflare β€” Website hosting, edge caching, DDoS protection. US-based, EU-US Data Privacy Framework participant.
  • Google β€” Google Analytics 4 (anonymised usage analytics). US-based, EU-US Data Privacy Framework participant.
  • GitHub β€” Encrypted ticket attachments storage for client support workflow. US-based, EU-US Data Privacy Framework participant.

We may also disclose personal data where required by law (e.g., to HMRC, law enforcement, or courts), or to protect our legitimate legal interests.

6. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements.

Data category Retention period
Quote enquiries (no contract) 12 months from last contact
Client contract data 7 years post-contract-end (HMRC requirement)
Support tickets and attachments Active ticket + 12 months post-resolution
Server logs 90 days rolling
Google Analytics 4 raw data 14 months (auto-deleted by GA4)
Marketing email subscriptions Until you unsubscribe

Ticket binary attachments (screenshots, PDFs) are automatically purged from GitHub upon ticket closure as part of our UK GDPR data minimisation protocol.

7. Your Rights

Under the UK GDPR, you have the following rights regarding your personal data:

  • Right of access (Article 15) β€” request a copy of the personal data we hold about you.
  • Right to rectification (Article 16) β€” request that we correct inaccurate or incomplete data.
  • Right to erasure / "right to be forgotten" (Article 17) β€” request deletion of your data in certain circumstances.
  • Right to restrict processing (Article 18) β€” request that we limit how we use your data in certain circumstances.
  • Right to data portability (Article 20) β€” receive your data in a structured, machine-readable format.
  • Right to object (Article 21) β€” object to processing based on legitimate interests or for direct marketing.
  • Right to withdraw consent (Article 7(3)) β€” where processing is based on consent, withdraw at any time.
  • Right to lodge a complaint (Article 77) β€” with the Information Commissioner's Office (ICO).

To exercise any of these rights, contact us using the details in section 13. We will respond within one calendar month as required by Article 12(3).

8. Cookies & Tracking

We use a minimal set of cookies and similar technologies on this website:

Cookie / technology Purpose Duration Type
tcp123-theme Stores light/dark theme preference 365 days Functional
tcp123-portal-user Remembers portal username ("Remember this workstation") 365 days Functional
_ga, _ga_* (Google Analytics 4) Anonymised visitor analytics 13 months Analytics (UK GDPR compliant β€” no PII)
_cfuvid (Cloudflare) Distinguishes between humans and bots; rate limiting Session Strictly necessary

We do not use advertising cookies or third-party tracking cookies for behavioural profiling.

9. Data Security

We implement appropriate technical and organisational measures to protect personal data, including:

  • UK GDPR Article 32-aligned encryption in transit (TLS 1.2+ for all web traffic) and at rest (AES-256 for ticket attachments).
  • Edge-based DDoS protection and bot mitigation via Cloudflare.
  • Strictly-need-to-know access controls; all engineering staff are DBS-checked UK residents.
  • Immutable audit logs for ticket access and modifications.
  • Cyber Essentials Standard accreditation; UK GDPR and ICO compliance training for all staff.

10. International Transfers

Some of our processors (Cloudflare, Google, GitHub) are based outside the UK. Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place:

  • Transfers to the United States rely on the EU-US Data Privacy Framework (adequacy decision).
  • Where applicable, Standard Contractual Clauses (SCCs) supplement the safeguards.
  • Brevo (EU-based) is used for transactional email, avoiding transfer of contact data to non-EU jurisdictions where possible.

11. Complaints

If you are unhappy with how we handle your personal data, please contact us first so we can resolve the issue informally:

Email: privacy@tcp123.uk
Phone: (01344) 935008

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection:

ICO
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
Website: ico.org.uk/make-a-complaint

12. Changes to This Policy

We may update this privacy policy from time to time. The "Last updated" date at the top reflects the most recent revision. Material changes will be highlighted on the homepage for at least 30 days before taking effect.

Previous versions are available on request.

13. Contact

For privacy enquiries, data access requests, or any questions about this policy:

TCP123 UK
Ascot, Berkshire, SL5
United Kingdom

Email: privacy@tcp123.uk
Phone: (01344) 935008
Hours: Mon–Fri 08:00–18:00