TrustedTech Privacy Notice — United Kingdom, Ireland & European Union
Trusted Tech Team Limited (UK) · Trusted Tech Team Limited (Ireland)
Effective Date: August 28, 2026
Applies to: Individuals in the United Kingdom, the Republic of Ireland, and the European Economic Area who visit our website, use our Services, or otherwise interact with Trusted Tech Team Limited.
Does not apply to: Our workforce. If you are an employee, worker, job applicant, contractor, or director, see the TrustedTech Workforce Privacy Notice — United Kingdom, Ireland & European Union instead.
1. Who We Are and Who Controls Your Personal Data
This Privacy Notice (“Notice”) explains how Trusted Tech Team Limited collects and uses personal data when you use our website at www.trustedtechteam.co.uk (the “Site”), our customer platform and portal (the “Platform”), and our consulting, licensing, customer support, technical support, and data management services (collectively, our “Services”).
TrustedTech is a trading name used by the Trusted Tech Team group. The controller of your personal data depends on which entity you contract with or which entity is responsible for your Region:
| Entity | Details | Registered Address |
|---|---|---|
| Trusted Tech Team Limited (UK) | A private limited company registered in England and Wales, company number 14762212 | 3 New Street Square, London EC4A 3BF, United Kingdom |
| Trusted Tech Team Limited (Ireland) | A private limited company registered in Ireland, company number 822833 | Fitzwilliam Hall, Fitzwilliam Place, Dublin 2, D02 T292, Ireland |
Where both entities are involved in the same processing activity — for example, where the Irish entity contracts with you and the UK entity provides operational support — they act as joint controllers for that activity. The essence of that arrangement is set out in Section 12. You may exercise your rights against either entity.
Personal data relating to individuals in the United States is handled by Trusted Tech Team, LLC under a separate notice, and personal data relating to individuals in the United Arab Emirates is handled by TrustedTech FZCO under a separate notice.
Data protection and privacy contact:
Justin Sharrocks, Director
Trusted Tech Team Limited
3 New Street Square, London EC4A 3BF, United Kingdom
Email: compliance@trustedtechteam.com
2. The Law That Applies to You
This Notice is written to comply with:
- the UK GDPR (Assimilated Regulation (EU) 2016/679) and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025, together with the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“PECR”), for individuals in the United Kingdom; and
- the EU GDPR (Regulation (EU) 2016/679), the Irish Data Protection Act 2018, and the Irish ePrivacy Regulations 2011 (S.I. No. 336/2011), and equivalent national implementing laws, for individuals in Ireland and the wider EEA.
References in this Notice to the “GDPR” mean the UK GDPR or the EU GDPR, as applicable to you.
3. What This Notice Does Not Cover
- Third-party sites. Websites, applications, embedded content, and links operated by others. Those sites have their own privacy practices, and we are not responsible for them.
- Anonymous and aggregated information. Information that cannot reasonably be used to identify you, which is not personal data.
- Customer-controlled data. Where we process personal data on the documented instructions of a business customer in order to deliver Services, that customer is the controller and we act as processor. Our processing in that capacity is governed by our data processing agreement with that customer, and you should contact your account administrator to exercise your rights.
- Workforce data, which is covered by our separate workforce notice.
4. Personal Data We Collect
Information you give us:
- Identity and contact data — first and last name, job title, employer, business and personal email address, telephone number, postal address.
- Account and Portal data — username, credentials, authentication and multi-factor records, account preferences, and administrator designations.
- Order and transaction data — products, licences, and services purchased, order history, quotes, contract and Sales Order details.
- Financial data — billing address, VAT number, bank or payment card details (collected through our payment processors; we do not store full card numbers), invoices and payment records.
- Verification data — company registration details and, where required for licensing eligibility, export control, or sanctions screening, identity documentation and nationality information.
- Communications data — the content of your enquiries, emails, chat sessions, support tickets, and recorded telephone calls, and your marketing preferences.
- Event and survey data — registration details, dietary or accessibility requirements you tell us about, and survey and feedback responses.
Information we collect automatically:
- Technical data — IP address, device and browser type and version, operating system, time zone, language settings, and device identifiers.
- Usage data — pages viewed, time spent, clicks and scrolling, referring and exit pages, search terms, features used, and interaction with our emails and advertisements.
- Approximate location — a city- or region-level estimate derived from your IP address. We do not collect precise GPS location data.
- Cookies and similar technologies — as described in Section 8 and in our Cookie Notice.
Information we receive from others:
- Your employer or account administrator, who may designate you as a billing, technical, or administrative contact;
- Linked services, such as Microsoft, where you or your administrator integrate them with our Services;
- Our service providers, including hosting, payment, CRM, security, and marketing platforms;
- Business information and marketing data providers, who supply business contact details, job titles, company information, and business intent data; and
- Publicly available sources, including Companies House, the Irish Companies Registration Office, professional networking sites, sanctions and restricted-party lists, and public registers.
Special category and criminal offence data. We do not seek to collect special category data (such as data revealing health, racial or ethnic origin, religious beliefs, or trade union membership) about customers or Site visitors, except where you volunteer it — for example, accessibility or dietary requirements for an event. We may process criminal offence and sanctions-related data to the limited extent necessary for sanctions and restricted-party screening required by law.
5. How and Why We Use Your Personal Data, and Our Legal Bases
We only use your personal data where the law allows us to. The table below sets out our purposes and the legal basis we rely on for each.
| Purpose | Personal Data Used | Legal Basis |
|---|---|---|
| Responding to your enquiries, quote requests, and pre-contract communications | Identity, contact, communications | Contract (steps at your request prior to entering a contract); Legitimate interests (responding to business enquiries) |
| Providing the Services, fulfilling orders, provisioning licences, and administering your account and Portal access | Identity, contact, account, order, transaction | Contract (performance of our contract with you or your employer); Legitimate interests (administering the relationship where the contract is with your employer rather than you) |
| Processing payments, invoicing, credit control, and debt recovery | Identity, contact, financial, transaction | Contract; Legal obligation (tax and accounting law); Legitimate interests (recovering sums owed) |
| Providing customer and technical support | Identity, contact, account, communications | Contract; Legitimate interests |
| Verifying licensing eligibility, and conducting export control and sanctions screening | Identity, verification, company data | Legal obligation (UK, EU, and international sanctions and export control law); Legitimate interests (compliance risk management) |
| Recording calls for quality assurance and training | Communications | Legitimate interests (maintaining service quality and staff training), where notified to you at the outset of the call; Consent where required by local law |
| Sending marketing communications, newsletters, and event invitations | Identity, contact, usage, preferences | Consent, where required by PECR or the Irish ePrivacy Regulations; Legitimate interests for business-to-business marketing to corporate subscribers and for the “soft opt-in” to existing customers about similar products and services |
| Operating, securing, and improving our Site, Platform, and Portal | Technical, usage, account | Legitimate interests (running and improving our business and keeping our systems secure) |
| Analytics, advertising, and measuring campaign effectiveness | Technical, usage, approximate location, cookie identifiers | Consent, obtained through our cookie banner |
| Preventing fraud, protecting our systems, and investigating misuse | Technical, usage, account, communications | Legitimate interests (protecting our business, customers, and systems); Legal obligation |
| Complying with legal, regulatory, tax, accounting, and audit obligations | All categories as required | Legal obligation |
| Establishing, exercising, or defending legal claims, and managing disputes | All categories as required | Legitimate interests (protecting our legal position); Legal obligation |
| Managing corporate transactions, including mergers, acquisitions, and reorganisations | Identity, contact, transaction | Legitimate interests (structuring and completing corporate transactions) |
Legitimate interests. Where we rely on legitimate interests, we have balanced our interests against your rights and freedoms and concluded that our processing does not override them. You may ask us for details of that assessment, and you have the right to object as described in Section 10.
Consent. Where we rely on your consent, you may withdraw it at any time by contacting us or by using the unsubscribe link in our emails or our cookie preference centre. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
Automated decision-making. We do not make decisions producing legal or similarly significant effects concerning you based solely on automated processing, and we do not carry out profiling that produces such effects.
6. Who We Share Your Personal Data With
We disclose personal data to:
- Our group companies — Trusted Tech Team, LLC (United States) — for group administration, support, billing, and security purposes;
- Software and licensing vendors, including Microsoft, to provision and administer the licences and products you purchase;
- IT, cloud hosting, infrastructure, and cybersecurity providers;
- Payment processors, banks, and credit reference and fraud prevention agencies;
- CRM, email, marketing automation, and analytics providers;
- Professional advisers, including lawyers, accountants, auditors, and insurers;
- Regulators, tax authorities, law enforcement, and courts, where required by law or to establish, exercise, or defend legal claims; and
- Acquirers or successors, in connection with a merger, acquisition, financing, reorganisation, or sale of assets.
We require all service providers acting as processors to enter into a written data processing agreement meeting the requirements of Article 28 of the GDPR, to process personal data only on our documented instructions, and to apply appropriate technical and organisational security measures.
We do not sell your personal data.
7. International Transfers
We transfer personal data outside the United Kingdom and the EEA in the following circumstances.
To the United States — to Trusted Tech Team, LLC and to service providers established in the United States, for group administration, support, billing, hosting, and security purposes.
To the United Arab Emirates — to TrustedTech FZCO, for group administration and support purposes.
Where we make such a transfer, we rely on one or more of the following safeguards:
- an adequacy decision or adequacy regulations, where the European Commission (for EU transfers) or the UK Secretary of State (for UK transfers) has determined that the destination country, territory, sector, or organisation provides an adequate level of protection. This includes, where the US recipient is self-certified and the transfer falls within its scope, the EU–US Data Privacy Framework and the UK Extension to the EU–US Data Privacy Framework (the “UK–US Data Bridge”);
- the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914) for EU transfers, and the International Data Transfer Agreement or the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner for UK transfers, in each case supported by a transfer risk assessment and, where appropriate, supplementary technical and organisational measures; or
- where no other safeguard is available, a derogation under Article 49 of the GDPR, such as the necessity of the transfer for the performance of a contract with you.
Transfers to the United Arab Emirates are made on the basis of Standard Contractual Clauses or the International Data Transfer Agreement, as applicable, supported by a transfer risk assessment. The United Arab Emirates is not the subject of an adequacy decision or adequacy regulations.
You may request a copy of the transfer safeguards we have in place by emailing compliance@trustedtechteam.com. Commercially sensitive terms may be redacted.
Data residency. Personal data submitted through the Portal by customers in the EU Region is hosted on servers located in the European Union. We may access or transfer limited data outside your Region where necessary to provide support, billing, or security services, or to comply with applicable law, subject to the safeguards described above.
8. Cookies and Similar Technologies
We use cookies, pixels, tags, and similar technologies on our Site. Cookies that are strictly necessary for the operation of the Site, and those used solely for the transmission of a communication, are set without your consent, as permitted by PECR and the Irish ePrivacy Regulations. All other cookies — including analytics, functional, and advertising cookies — are set only where you have given consent through our cookie banner.
You can accept, reject, and change your cookie choices at any time through the cookie banner that appears on your first visit and through the cookie preference centre linked in the footer of the Site. You can also control cookies through your browser settings; details are available in your browser’s help documentation. If you reject non-essential cookies, some features of the Site may not function as intended.
Our Site does not respond to browser “do not track” signals. Our Cookie Notice sets out the specific cookies we use, their purpose, and their duration.
9. How Long We Keep Your Personal Data
We keep personal data only for as long as necessary for the purposes described in this Notice, and for the periods required by law. Where more than one period applies to a record, we apply the longest.
| Category | Retention Period | Basis for the Period |
|---|---|---|
| Customer contract, order, invoice, and payment records | 6 years from the end of the accounting period or the end of the contract, whichever is later | UK: Finance Act 1998, Sch. 18, para. 21 (corporation tax); Value Added Tax Act 1994, Sch. 11, para. 6(3). Ireland: Taxes Consolidation Act 1997, s. 886; Value-Added Tax Consolidation Act 2010, s. 84 |
| Company and accounting records | 6 years from the end of the financial year | UK: Companies Act 2006, ss. 388 and 1075. Ireland: Companies Act 2014, s. 286 |
| Contractual and dispute records generally | 6 years from the end of the contract | UK: Limitation Act 1980, s. 5. Ireland: Statute of Limitations 1957, s. 11(1). Contracts executed as a deed: 12 years (UK, Limitation Act 1980, s. 8) |
| Export control and sanctions screening records | 6 years from the date of the transaction | UK: Export Control Order 2008 and retained EU dual-use recordkeeping requirements; EU: Regulation (EU) 2021/821, Art. 27 (at least 5 years) |
| Customer support, technical support, and communications records | 3 years from the date of the communication, unless part of a contract file | Business need; no statutory period |
| Recorded telephone calls | 6 months, unless retained for a specific dispute or compliance purpose | Data minimisation; no statutory period |
| Portal access, authentication, and audit logs | 24 months | Security, audit, and incident investigation needs |
| Prospective customer enquiries and quotes that do not lead to a contract | 24 months from last contact | Legitimate interests; no statutory period |
| Marketing contact data and consent records | For as long as you remain subscribed, plus 2 years after your last engagement or your withdrawal of consent, in order to evidence consent and honour objections. A minimal suppression record is kept indefinitely | PECR reg. 22; Irish ePrivacy Regulations, reg. 13; GDPR Art. 5(2) accountability |
| Cookie and advertising identifiers | Maximum 13 months from collection or last refresh | ICO and EDPB cookie guidance |
| Website analytics data | 26 months in identifiable or pseudonymised form; indefinitely once aggregated | Analytics platform defaults and business need |
| Records of data subject rights requests | 12 months from completion of the request | GDPR Art. 5(2) accountability; complaint-handling requirements under the Data (Use and Access) Act 2025 |
| Records subject to a legal hold, regulatory investigation, or ongoing claim | For the duration of the hold or proceedings, notwithstanding any shorter period above | Legal preservation obligations |
At the end of the applicable period we securely delete or anonymise the data.
10. Your Rights
Under the GDPR you have the following rights, subject to the conditions and exemptions in the legislation:
- Access. To be told whether we process personal data about you and, if so, to receive a copy of it and information about how we use it.
- Rectification. To have inaccurate personal data corrected and incomplete data completed.
- Erasure (“right to be forgotten”). To have your personal data deleted where it is no longer necessary for the purposes for which it was collected, where you withdraw consent and there is no other legal basis, where you object and there are no overriding legitimate grounds, or where it has been processed unlawfully.
- Restriction. To ask us to limit how we use your personal data — for example, while we check its accuracy or consider an objection.
- Portability. To receive personal data you provided to us, where we process it by automated means on the basis of consent or contract, in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
- Objection. To object at any time to processing based on our legitimate interests. You have an absolute right to object to processing for direct marketing purposes, and we will stop such processing immediately on request.
- Withdrawal of consent. To withdraw consent at any time where we rely on it.
- Rights relating to automated decision-making. Not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. As noted above, we do not carry out such processing.
- Complaint. To complain to us and to a supervisory authority, as set out in Section 11.
How to exercise your rights. Email compliance@trustedtechteam.com, or write to the Data Protection Officer at the address in Section 1. Exercising your rights is free of charge. We may ask for information to verify your identity, and we may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive.
Our response time. We will respond within one month of receiving your request. We may extend that period by up to two further months where the request is complex or where you have made a number of requests, and we will tell you within one month if we do so and why. Where we need identity verification or clarification before we can act, the time limit runs from the point at which we receive what we have asked for.
11. Complaints
If you are unhappy with how we have handled your personal data, please contact us first at compliance@trustedtechteam.com so that we have the opportunity to put things right. We will acknowledge your complaint without undue delay and respond substantively without undue delay and in any event within 30 days.
You also have the right to complain to a supervisory authority at any time:
- United Kingdom — the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF; telephone 0303 123 1113; https://ico.org.uk/make-a-complaint/
- Ireland — the Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28; https://www.dataprotection.ie/
- Elsewhere in the EEA — the supervisory authority in the Member State of your habitual residence, place of work, or the place of the alleged infringement.
12. Joint Controllership
Where Trusted Tech Team Limited (UK) and Trusted Tech Team Limited (Ireland) determine the purposes and means of processing together, they are joint controllers under Article 26 of the GDPR. Under their arrangement:
- the entity that contracts with you has primary responsibility for providing this Notice and for the lawfulness of the processing;
- the UK entity operates the shared systems, security controls, and support function, and maintains the records of processing on behalf of both entities;
- data subject requests may be made to either entity and will be handled centrally by the Data Protection Officer; and
- each entity remains responsible for compliance with the GDPR in respect of the processing it carries out.
Regardless of this arrangement, you may exercise your rights against, and in respect of, each of the joint controllers.
13. Security
We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, having regard to the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. These include access controls, encryption in transit and at rest, network and endpoint security, logging and monitoring, vendor due diligence, and staff training. We maintain a personal data breach response procedure and will notify the relevant supervisory authority, and where required you, in accordance with Articles 33 and 34 of the GDPR.
14. Children
Our Site and Services are directed at businesses and are not intended for children. We do not knowingly collect personal data from anyone under the age of 16. If you believe we have collected personal data from a child, please contact compliance@trustedtechteam.com and we will delete it.
15. Changes to This Notice
We may update this Notice from time to time. The current version is always available on our Site, and the effective date appears at the top. Where changes materially affect your rights, we will take appropriate steps to bring them to your attention, which may include emailing you or displaying a prominent notice on the Site.
16. Contact Us
Data protection contact: Justin Sharrocks, Director, Trusted Tech Team Limited
Email: compliance@trustedtechteam.com
United Kingdom: Trusted Tech Team Limited, 3 New Street Square, London EC4A 3BF, United Kingdom · Telephone +44 8081 642033
Ireland: Trusted Tech Team Limited, Fitzwilliam Hall, Fitzwilliam Place, Dublin 2, D02 T292, Ireland
General support: support@trustedtechteam.com