Version v.2026-09-15 · Last updated 15 September 2026
// At a glance
- Who we are: Securitise Limited, a UK managed IT and cyber security services provider, is the controller of the personal data described here.
- On this website we collect what you choose to tell us in our enquiry form, and basic technical data needed to run and protect the site.
- Analytics and marketing cookies are only used if you accept them. You can change your choice at any time using cookie settings.
- We never sell personal data and we do not buy marketing lists.
- Your rights: you can ask for a copy of your data, correct it, have it erased or object to its use by emailing privacy@securitise.uk.
This summary is for convenience. The full notice below explains everything in detail.
Contents
- Our role: controller and processor
- The personal data we collect
- How we obtain personal data
- Why we use personal data and our lawful bases
- Who we share personal data with
- International transfers
- How long we keep personal data
- Your rights
- Complaints
- Cookies and website analytics
- Security
- Links to other sites
- Children
- Cookie schedule
Securitise Limited (company number 14518317, registered office 20-22 Wenlock Road, London, N1 7GU) (‘Securitise’, ‘we’, ‘us’) is a managed IT and cyber security services provider. This notice explains how we collect, use, share and protect personal data, and the rights people have in relation to it, under the UK General Data Protection Regulation and the Data Protection Act 2018 (‘Data Protection Law’). It applies to visitors to www.securitise.uk, people who contact us, the representatives and users of our business customers, our suppliers’ contacts, and people who apply to work with us.
We are registered with the Information Commissioner’s Office under registration number ZB637847. Questions, requests and complaints about personal data should be sent to privacy@securitise.uk or to the registered office above, marked for the attention of the Directors.
We may update this notice from time to time. The current version is always published at www.securitise.uk/privacy-policy and listed at www.securitise.uk/legal, and we will tell our customers of any material change.
1. Our role: controller and processor
1.1 When we deliver managed IT, cloud, security, support and related services to a business customer, we handle personal data contained in that customer’s systems, Microsoft 365 tenant, devices, mailboxes, files and backups on the customer’s behalf and on its instructions. For that data the customer is the controller and we are its processor. Our obligations are set out in the Data Processing Addendum to our Master Services Agreement, and the customer’s own privacy notice explains how that data is used. If you are an employee or user of one of our customers and want to exercise your rights in relation to data held in your employer’s systems, please contact your employer; we will assist it in responding.
1.2 We are the controller of the personal data described in this notice: the information we hold about our customers’ representatives and users in order to run our own business and deliver and secure the services, about prospective customers and enquirers, about website visitors, about our suppliers’ contacts and about job applicants.
2. The personal data we collect
2.1 Customer representatives and users: name, employer, job title, work email address and telephone numbers, user names and account identifiers, authorisation level (for example whether you are an Authorised Contact), the content of support tickets, emails, chat messages and call notes, and records of the changes and instructions you give us.
2.2 Service and security data generated by the tools we operate: device names and identifiers, IP addresses, sign-in and access logs, security alerts and incident records, software inventory and patch status, and similar technical data which may identify individual users. We collect this to operate, monitor and secure the services.
2.3 Enquirers and prospects: name, organisation, job title, contact details, the content of your enquiry and our correspondence with you, and information about your organisation from public sources such as Companies House, your organisation’s website and professional networking sites. If you use the enquiry form on our website, we also collect the answers you choose to give about your organisation and requirements (such as its size and sector, who looks after its IT, the services you are interested in, your timeline and how you prefer to be contacted), whether you have asked to receive updates from us, and the reference number, date, time and web page of your enquiry.
2.4 Website visitors: IP address, browser type and version, operating system, the pages you visit, the site you came from and the date, time and duration of your visit, collected through cookies and similar technologies as described in section 10. When you submit a form, we also record a one-way coded (hashed) version of your IP address and the result of an automated check that the form was sent by a person, to protect the site from spam and abuse.
2.5 Client document library and client support page users: if you request access to the contract document library on our website, your work email address, the one-time access codes we send you, and a record of access requests, sign-ins and the documents you view or download. If you use the client support page, the work email address you enter, which we check against our client records, and a record of access.
2.6 Suppliers and partners: contact details of the people we deal with, and bank details supplied for payment.
2.7 Job applicants: the information in your CV and application, interview notes, references and, where relevant to the role, the results of right-to-work and background checks.
2.8 We do not collect payment card details through our website. Customer payments are made by bank transfer or through our accounting and payment provider, which handles card data under its own security standards.
2.9 Where we contract with you or your organisation, we need the name, business contact details and authorisation level of the people who will deal with us, and the account and user details needed to set up and secure the services. If that information is not provided we may be unable to enter into or perform the contract, provision users or respond to instructions, and we will tell you if that is the case.
3. How we obtain personal data
3.1 Most of the data we hold is given to us directly by you, or by your employer when it becomes our customer and identifies you as a contact or user. Service and security data is generated automatically by the systems we operate. Website data is collected automatically when you visit the site. We may add information from public sources to verify or complete business contact details.
4. Why we use personal data and our lawful bases
4.1 To provide, administer, support and invoice the services we have contracted to supply: where you are the customer, this is necessary for the performance of our contract with you; where your employer is the customer, we rely on our legitimate interests in performing that contract and in dealing with the people our customer has nominated.
4.2 To monitor, protect and secure our customers’ systems and our own, including our website and its forms, to detect, investigate and respond to security incidents, and to prevent fraud, spam and misuse: we rely on our legitimate interests and those of our customers in the security of their information, and, where applicable, on our legal obligations.
4.3 To respond to enquiries and quotations, and to manage our relationship with prospective customers: our legitimate interests in running and developing our business. We use the answers given in our enquiry form to route and prioritise enquiries internally. Every enquiry is reviewed by a person, and this does not involve any decision with legal or similarly significant effects on you.
4.4 To send occasional information about our services to existing customers and to people who have enquired about them: our legitimate interests in promoting our business. We send electronic marketing to corporate contacts, and to individuals only where they have consented or where the soft opt-in under the Privacy and Electronic Communications Regulations applies. Every marketing message includes an unsubscribe link and you may opt out at any time by emailing privacy@securitise.uk. We do not buy marketing lists.
4.5 To operate and improve our website and understand how it is used: our legitimate interests, and your consent for any cookies that are not strictly necessary.
4.6 To give authorised customer contacts secure access to contract documents through our client document library, and to keep a record of that access: our legitimate interests, and those of our customers, in sharing contractual documents securely.
4.7 To manage suppliers and partners, keep accounts and records, and comply with tax, accounting, regulatory and insurance obligations: performance of a contract, legal obligation and our legitimate interests.
4.8 To recruit staff and contractors: steps taken at your request before entering into a contract, our legitimate interests in assessing candidates, and legal obligations such as right-to-work checks.
4.9 To establish, exercise or defend legal claims, and in connection with any sale, merger or reorganisation of our business: our legitimate interests, and legal obligation where applicable.
4.10 Where we rely on legitimate interests we have considered the balance between those interests and your rights, and you may object at any time as described in section 8. We do not use personal data for automated decision-making that has legal or similarly significant effects on you, and we do not sell personal data.
5. Who we share personal data with
5.1 Our staff and, under contract and confidentiality obligations, our subcontracted service desk and engineering resource in the European Economic Area.
5.2 The technology providers whose platforms we use to deliver and secure the services and to run our business, in the following categories: Microsoft and other cloud platforms; remote monitoring, endpoint management and security tooling; backup platforms; email security, security awareness training and email signature management; service management, ticketing and documentation; accounting, quoting and payment services; website hosting, content delivery, and form and bot protection; website analytics and advertising measurement (only where you have consented to analytics or marketing cookies); and our Microsoft indirect provider (account, order and billing data only). These providers act on our instructions as processors, or as independent controllers where they provide services directly to our customers under their own terms.
5.3 Credit reference and fraud prevention agencies, to which we may submit a customer’s name, address and payment record and from which we may obtain information when assessing credit risk, as our contracts permit; our professional advisers, insurers, bankers and auditors; regulators, law enforcement and other authorities where we are required or permitted by law to disclose; and a prospective or actual purchaser of all or part of our business, under confidentiality obligations.
5.4 We do not disclose the identity of individual technology providers in this notice because they change from time to time. Our customers may obtain the current list under their contract, and anyone may ask us at privacy@securitise.uk which categories of provider hold their data. The providers that set cookies on our website are named in the cookie schedule.
6. International transfers
6.1 We hold personal data primarily in the United Kingdom and the European Economic Area, which the UK treats as providing adequate protection. Some of the technology providers we use are based in, or provide support from, the United States or other countries outside the UK. Where personal data is transferred to such a country we rely on the UK adequacy regulations where they apply (including the UK-US Data Bridge for certified organisations) and otherwise on the Information Commissioner’s International Data Transfer Agreement or the UK Addendum to the European Commission’s standard contractual clauses, together with any supplementary measures needed. You can ask us at privacy@securitise.uk for information about the safeguards applied to a particular transfer.
7. How long we keep personal data
7.1 Customer contract, service, billing and correspondence records, including support tickets and the details of customer contacts: for the duration of the contract and seven (7) years after it ends, to meet accounting and tax requirements and to deal with any claim.
7.2 Service and security logs and alerts generated by our tools: normally for twelve (12) months, or longer where they form part of an incident record or are needed for a claim or investigation.
7.3 Enquiries and prospective customer records, including enquiries submitted through our website: twenty-four (24) months from our last contact with you.
7.4 Marketing preferences: until you unsubscribe, after which we keep a suppression record of your email address so that we do not contact you again.
7.5 Supplier records: seven (7) years after the end of the relationship. Job applications: six (6) months after the recruitment decision for unsuccessful candidates, or for the duration of employment and six (6) years thereafter for successful ones.
7.6 Client document library and client support page access records: twelve (12) months.
7.7 Website data: for the periods stated in the cookie schedule. Data deleted from live systems may persist in backups for a limited period until those backups are cycled, during which it is not used for any other purpose.
8. Your rights
8.1 You have the right to ask for a copy of the personal data we hold about you; to have inaccurate data corrected; to have data erased where there is no good reason for us to keep it; to restrict our use of it in certain circumstances; to receive data you have given us in a portable form; and to withdraw consent where consent is the basis for processing. You can withdraw consent to analytics or marketing cookies at any time using cookie settings.
8.2 Your right to object. You have the right to object at any time to our use of your personal data for direct marketing, and if you do we will stop. You also have the right to object to any processing we carry out on the basis of our legitimate interests (see section 4) on grounds relating to your particular situation; we will then stop unless we can show compelling legitimate grounds which override your interests, rights and freedoms, or the processing is needed for legal claims. To object, email privacy@securitise.uk or use the unsubscribe link in any marketing message.
8.3 To exercise a right, email privacy@securitise.uk. We may need to verify your identity. We will respond within one month, or tell you within that time if we need longer for a complex request. There is no charge unless a request is manifestly unfounded or excessive. Where your request concerns data we process on behalf of a customer, we will pass it to that customer and assist it in responding.
9. Complaints
9.1 If you are unhappy with how we have handled your personal data, please tell us at privacy@securitise.uk. We will acknowledge your complaint within thirty (30) days, investigate it and let you know the outcome without undue delay. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113, and to seek a remedy through the courts, but we would welcome the chance to resolve your concern first.
10. Cookies and website analytics
10.1 Our website uses a small number of cookies and similar technologies, such as browser storage. Strictly necessary cookies are needed for the site to work, to keep it secure and to record your cookie choices; they are set without consent. Analytics cookies, which help us understand how the site is used, and marketing cookies, which help us measure our advertising, are set only if you accept them through the banner shown on your first visit, and those services are not loaded until you do. You can change your choice at any time using the cookie settings link at the bottom of every page or through your browser settings. The cookies we use, their purpose and how long they last are listed in the cookie schedule at the end of this notice and in our Cookie Policy.
11. Security
11.1 We apply technical and organisational measures appropriate to the risk, which where appropriate include multi-factor authentication, encryption of data in transit and at rest, least-privilege access controls, logging and monitoring, and staff training, and we require the providers we use to maintain appropriate security measures of their own. No system can be guaranteed to be completely secure, but we review our measures regularly against recognised standards. If you believe personal data we hold has been lost, misused or accessed without authority, please tell us immediately at privacy@securitise.uk.
12. Links to other sites
12.1 Our website may link to third-party sites, including Microsoft and other providers’ portals. Those sites have their own privacy notices and we are not responsible for their content or their handling of your data.
13. Children
13.1 Our website and services are intended for businesses and are not directed at children. We do not knowingly collect personal data from children.
Cookie schedule
This schedule lists every cookie and similar technology our website sets or may set. Third-party analytics and marketing tools are only switched on if we choose to use them, and even then they are never loaded until you accept that category.
Strictly necessary (always on)
Needed for the website to work, to keep it secure and to remember your choices. These do not require consent.
Analytics (only with your consent)
Help us understand how visitors use the website so we can improve it. Set only if you accept analytics cookies.
Marketing (only with your consent)
Help us measure the effectiveness of our advertising and show relevant adverts to businesses on other platforms. Set only if you accept marketing cookies.
Functionality
None currently used. If this changes, this schedule will be updated and we will ask for your consent where it is required.