READ

Latest Policy

Privacy Policy

Last updated: 17 August 2026

1. Who We Are

This Privacy Policy explains how SVG IT collects, uses, stores and protects your personal data, and the rights you have over the information we hold about you.

For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, the data controller is:

  • Legal entity: [REGISTERED COMPANY NAME] trading as SVG IT

  • Registered in England and Wales, company number: [COMPANY NUMBER]

  • Registered office: [REGISTERED OFFICE ADDRESS]

  • ICO registration number: [ICO REGISTRATION NUMBER]

  • Email: sales@svgit.co.uk

We have not appointed a statutory Data Protection Officer, as we are not required to do so. Data protection queries should be sent to the email address above.

2. Information We Collect

Personal Information
We may collect personal details such as your name, business name, job title, email address, telephone number, and any other information you choose to provide when you contact us, request a quotation, apply for a role, or use our services.

Device and Usage Data
We automatically gather data about how you interact with our website, including your IP address, device type, operating system, browser type, referring page and site navigation.

Service and Support Data
Where we deliver services to you, we may process contact details and records of correspondence, support tickets and system access needed to provide those services.

3. How We Use Your Information and Our Legal Bases

Under the UK GDPR we must have a lawful basis for processing your personal data. We rely on the following:

Contractual Necessity: To perform a contract with you or take steps at your request before entering into a contract, including delivering agreed services, providing support, and managing our client relationship.

Legitimate Interests: To respond to business enquiries, improve our services and website, maintain security, prevent fraud, and carry out business administration, provided those interests do not override your rights and freedoms.

Consent: For non-essential cookies and analytics, and for marketing communications where consent is required. You can withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.

Legal Obligation: To comply with legal and regulatory requirements, including accounting, tax and record-keeping obligations.

We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.

4. Cookies and Similar Technologies

We use cookies and similar technologies to operate our website, remember your preferences and analyse site traffic.

Strictly necessary cookies are required for the website to function and are set without consent.

Analytics and performance cookies help us understand how the site is used. Under the Privacy and Electronic Communications Regulations (PECR), these are only set where you have given your consent.

You can accept or reject non-essential cookies when you first visit the site, change your preferences at any time through our cookie settings, and additionally control or delete cookies through your browser settings. Blocking some cookies may affect how the website works.

5. Data Sharing and Disclosure

We do not sell or rent your personal information. We may share data in the following circumstances:

Service Providers: With third-party suppliers who process data on our behalf under written contracts, such as website hosting, analytics, email, CRM and IT support providers. They may only process your data on our instructions.

Professional Advisers: With accountants, insurers and legal advisers where necessary.

Legal Requirements: Where we are required to disclose information by law or regulation, or in response to a valid legal request.

Business Transfers: In the event of a merger, acquisition or sale of assets, your information may be transferred, subject to the protections in this policy.

6. International Transfers

Some of our service providers are located outside the United Kingdom. Where we transfer personal data internationally, we ensure an appropriate safeguard is in place, such as UK adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses. You may request details of the safeguards we rely on by contacting us.

7. How Long We Keep Your Data

We keep personal data only for as long as necessary for the purposes set out in this policy.

  • Enquiries that do not lead to a contract: up to 24 months from last contact.

  • Client records and contracts: for the duration of the relationship and 6 years afterwards, to meet contractual and legal obligations.

  • Financial and accounting records: 6 years, as required by HMRC.

  • Recruitment applications: up to 12 months from the outcome of the application, unless you ask us to keep them for longer.

  • Website analytics data: up to 26 months.

When data is no longer required, we securely delete or anonymise it.

8. Data Security

We take appropriate technical and organisational measures to protect your data against unauthorised access, disclosure, alteration or loss. However, no online service is entirely secure and we cannot guarantee absolute security. Where a personal data breach is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner’s Office within 72 hours and, where required, notify you.

9. Your Data Rights

Under the UK GDPR you have the following rights in relation to your personal data:

Access: To request a copy of the data we hold about you.

Rectification: To have inaccurate or incomplete data corrected.

Erasure: To request deletion of your data, subject to our legal obligations.

Restriction: To ask us to limit how we use your data in certain circumstances.

Data Portability: To receive data you provided to us in a structured, commonly used and machine-readable format, or to have it transmitted to another controller.

Object: To object to processing based on legitimate interests, and to object to direct marketing at any time.

Withdraw Consent: To withdraw your consent at any time where we rely on it.

Automated Decision-Making: Not to be subject to decisions based solely on automated processing that significantly affect you.

To exercise any of these rights, contact us at sales@svgit.co.uk. We will respond within one month, and there is normally no charge.

Complaints: If you are unhappy with how we have handled your personal data, we would like the chance to put it right. You also have the right to complain to the UK supervisory authority, the Information Commissioner’s Office, at ico.org.uk/make-a-complaint or on 0303 123 1113.

10. Marketing

Where we send marketing communications we do so in line with PECR and the UK GDPR. Every marketing email includes an unsubscribe link, and you can opt out at any time by contacting us. Opting out of marketing does not affect communications necessary to deliver services you have requested.

11. Third-Party Links

Our website may contain links to third-party websites or services. We are not responsible for the privacy practices or content of those external sites, and we encourage you to review their privacy policies.

12. Children’s Privacy

Our website and services are intended for business users and are not directed at children. We do not knowingly collect personal information from anyone under the age of 13. If we learn that we have collected such data without appropriate consent, we will delete it.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Any changes will be published on this page with an updated revision date. Where changes are significant, we will take reasonable steps to notify you.

14. Contact Us

If you have any questions or concerns about this Privacy Policy or how we handle your data, please contact us at sales@svgit.co.uk or write to us at [REGISTERED OFFICE ADDRESS].