Who is responsible
IT Technology Private Limited is the data fiduciary for the personal data described in this notice. Our second studio operates as part of the same legal entity, so a single organisation is responsible wherever your data is processed. Where an engagement brings us EU, UK or other overseas personal data, the contract for that engagement sets out the additional obligations that apply to it.
Questions about this notice, and any request to exercise the rights described in it, go to the address at the foot of this page. They are read by our Head of Security & Compliance, who acts as grievance officer, not by a shared marketing inbox.
What this website collects
The site is statically generated and served without a session, an account system or a tracking script. The only personal data that reaches us from it is data you type into a form and submit.
| Source | Data | Why we hold it | Retention |
|---|---|---|---|
| Enquiry form | Name, work email, organisation, optional phone number, selected capabilities, budget range, your message | To answer your enquiry and, if it becomes an engagement, to establish the contract | 24 months from the last contact, then deleted |
| Newsletter form | Email address only | To send the engineering note you asked for | Until you unsubscribe, then deleted within 30 days |
| Server logs | IP address, user agent, requested path, timestamp | Security monitoring and abuse prevention at the hosting layer | 30 days, then rotated out |
We do not ask for special category data, and you should not send any. If a brief needs to describe clinical, biometric or financial records, describe the system rather than its contents — we will take the detail under a signed agreement instead.
The lawful basis for each use
Every use of personal data needs a stated ground. Ours are as follows, and we do not rely on a broad claim of legitimate use for anything you would be surprised by.
| Processing | Basis | Notes |
|---|---|---|
| Answering an enquiry | Legitimate interests | You approached us about professional services; a reply is what you asked for |
| Newsletter | Consent | Given by the subscription form, withdrawable from any issue in one click |
| Delivering an engagement | Contract | Processing necessary to perform the contract you have signed with us |
| Security logging | Legal obligation and legitimate interests | Keeping a client-facing system secure is a duty under our own certifications |
Where it is processed
Personal data collected through this site is processed in the countries named as our studio locations at the foot of this page, and is accessible to both studios because they are one legal entity. We do not transfer enquiry data to any other country, and we do not use a processor that does. Where an engagement requires data to stay in a particular jurisdiction, that is a contractual term of the engagement and we design the system around it.
Where an engagement requires data to be processed elsewhere, that is agreed in the engagement contract with a named transfer mechanism, not under this notice.
Your rights, and how to use them
You can exercise any of the following by emailing the address at the foot of this page. We answer within one month and there is no charge.
- Access — a copy of the personal data we hold about you.
- Rectification — correction of anything inaccurate or incomplete.
- Erasure — deletion, where we have no overriding obligation to keep it.
- Restriction — a pause on processing while a dispute is resolved.
- Portability — the data you gave us, in a machine-readable format.
- Objection — to any processing we carry out under legitimate interests.
- Withdrawal of consent — at any time, without affecting what happened before.
If we get it wrong, you can complain to the data protection authority for your jurisdiction. We would rather you told us first — the grievance officer named above answers directly — but that is your choice, not a precondition.
How it is protected
We hold ISO 27001 certification and clear the NHS Data Security and Protection Toolkit annually. In practice that means enforced multi-factor authentication, encrypted storage and transport, least-privilege access reviewed quarterly, and an incident process that has been rehearsed rather than merely written.
If a breach affects your personal data and is likely to result in a risk to your rights, we will tell you — and the relevant supervisory authority within 72 hours. We would tell you about it before an auditor found it; that is an operating principle here, not a legal minimum.
Changes to this notice
This notice is versioned, and the version and effective date are printed in the title block at the top of the page. Material changes take effect no earlier than 30 days after publication, and anyone with an open enquiry or a live engagement is told directly rather than being left to notice.
Ask us about any of this
Data protection questions, subject access requests and complaints all go to the same address. It is monitored by a named person, and you will get a named reply.
v2.1 · Last updated: 16 August 2026