M-Piric IT Consultancy & Support Ltd -  Privacy Policy

1. Introduction and Scope


M-Piric IT Consultancy & Support Ltd (“M-Piric”, “we”, “us”, “our”) is committed to protecting the privacy and security of personal data. This Privacy Policy explains in detail how we collect, use, store, share, retain and protect personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

This Privacy Policy applies to:

  • Visitors to our website (including m-piric.co.uk and any related subdomains)
  • Individuals who contact us, submit forms, request resources (including the Founder’s IT Launch Kit), or book a strategy call
  • Prospective clients and other individuals who interact with us in a business capacity via our website or marketing channels


Important: This Privacy Policy does not cover personal data that we process on behalf of our clients as part of delivering managed IT services. That processing is governed by separate contracts and Data Processing Agreements (DPAs) with those clients. Where we act as a data processor, the relevant client remains the data controller.


2. Data Controller Details


Data Controller:

M-Piric IT Consultancy & Support Ltd

Registered in England and Wales

Contact for data protection enquiries:

Email: [email protected]

Telephone: 0121 416 0121 | 01283 713 900

All data protection queries, subject access requests, and related matters should be directed to the contact details above. Tony Lennon oversees data protection compliance within the business.


3. Personal Data We Collect


We may collect and process the following categories of personal data:

A. Identity Data

Full name, job title, company/organisation name.

B. Contact Data

Email address, telephone number, business address, and any other contact details you provide.

C. Enquiry and Correspondence Data

Information you submit via website forms, strategy call bookings, resource requests (including the Founder’s IT Launch Kit), emails, telephone calls, or other communications. This may include details about your business, IT environment, and requirements.

D. Technical Data

Internet Protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, device type, and other technology on the devices you use to access our website.

E. Usage Data

Information about how you use our website, including pages visited, time spent, click patterns, and referring sources.

F. Marketing and Communications Data

Your preferences regarding receiving marketing communications from us and your communication preferences.

We do not intentionally collect special category personal data (such as health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, or data concerning sex life or sexual orientation) via our website. Please do not submit such information to us through website forms or general enquiries.

We do not knowingly collect personal data from individuals under the age of 18.


4. How We Collect Personal Data


We collect personal data through the following methods:

  • Direct interactions – when you complete forms on our website, request downloads, book a strategy call, email us, telephone us, or otherwise correspond with us.
  • Automated technologies – when you interact with our website we automatically collect Technical and Usage Data using cookies, server logs, pixels, and similar technologies.
  • Third parties and publicly available sources – in limited circumstances we may receive data from analytics providers, advertising platforms, or publicly available business sources (for example Companies House) where relevant to a legitimate business enquiry.


5. Purposes of Processing and Lawful Bases

We process personal data only where we have a valid lawful basis under UK GDPR. The purposes and corresponding lawful bases are set out below:





Purpose of Processing Categories of Data Lawful Basis
Responding to enquiries, providing requested information or resources, and handling strategy call bookings Identity, Contact, Enquiry Legitimate interests (to respond to business enquiries) and/or steps necessary to enter into a contract
Delivering managed IT services to clients Identity, Contact, Client Data Performance of a contract
Managing our relationship with you (including notifying you of changes to terms or policies) Identity, Contact, Marketing Legitimate interests and/or Contract
Administering and protecting our business, website, and systems (including troubleshooting, security, testing, and fraud prevention) Identity, Contact, Technical, Usage Legitimate interests and Legal obligation
Improving our website, services, and user experience through analysis Technical, Usage Legitimate interests
Sending marketing communications about our services and resources Identity, Contact, Marketing Consent (where required) or Legitimate interests (where applicable and where you have not opted out)
Complying with legal, regulatory, accounting and tax obligations Any relevant data Legal obligation


Where we rely on legitimate interests, we have conducted a balancing test and determined that our interests are not overridden by your interests or fundamental rights and freedoms.

We do not use your personal data for solely automated decision-making (including profiling) that produces legal or similarly significant effects concerning you.


6. Marketing Communications


We may send you marketing communications regarding our services, resources, events or relevant updates only where:

  • You have provided clear affirmative consent; or
  • We are able to rely on legitimate interests (for example, where you have previously made an enquiry about our services) and you have not opted out.

You may withdraw consent or opt out of marketing at any time by:

  • Using the unsubscribe link in any marketing email;
  • Emailing [email protected] with the subject “Unsubscribe”; or
  • Contacting us by telephone or post using the details in Section 2.

We will process opt-out requests promptly. Opting out of marketing does not affect communications that are necessary for the performance of a contract or to respond to your enquiries.

We do not sell, rent or trade your personal data to third parties for their own marketing purposes.


7. Cookies and Tracking Technologies


Our website uses cookies and similar technologies. These fall into the following categories:

  • Strictly necessary cookies – essential for the operation of the website and cannot be switched off.
  • Performance / analytics cookies – allow us to recognise and count visitors and see how they move around the site (e.g. Google Analytics or equivalent).
  • Functionality cookies – enable the website to remember choices you make and provide enhanced features.
  • Targeting / advertising cookies – may be set by us or third parties to deliver content more relevant to you (where used).

You can control cookies through your browser settings. Most browsers allow you to refuse or delete cookies. Please note that disabling certain cookies may affect the functionality of our website.

Where required by law, we will request your consent before placing non-essential cookies. Further details are available in our Cookie Notice (accessible via the website footer or cookie banner).


8. Sharing of Personal Data (Third Parties)


We may disclose personal data to the following categories of recipients only where necessary and under appropriate safeguards:

  • Service providers acting as processors who provide website hosting, cloud infrastructure, email delivery, CRM systems, analytics, security monitoring, and similar services.
  • Professional advisers including legal, accounting, insurance and banking advisers.
  • Authorities and regulators where we are legally required to do so (including HM Revenue & Customs, the Information Commissioner’s Office, law enforcement, or courts).
  • Business transferees – in the event of a merger, acquisition, restructuring or sale of assets, personal data may be transferred to the new owner, who will be bound by this Privacy Policy or an equivalent policy.

We require all third-party processors to enter into written agreements that oblige them to:

  • Process personal data only on our documented instructions;
  • Implement appropriate technical and organisational security measures;
  • Assist us in fulfilling data subject rights requests and breach notification obligations;
  • Delete or return personal data at the end of the service relationship (unless legally required to retain it).

We do not allow third-party processors to use personal data for their own purposes.


9. International Transfers


Some of our service providers may process personal data outside the United Kingdom. Where personal data is transferred outside the UK, we ensure that appropriate safeguards are in place in accordance with UK GDPR, which may include:

  • Transfers to countries covered by UK adequacy regulations;
  • Use of the UK International Data Transfer Agreement (IDTA);
  • Use of the UK Addendum to the EU Standard Contractual Clauses;
  • Other transfer mechanisms approved by the Information Commissioner’s Office.

Details of specific transfer mechanisms can be provided on request.


10. Data Security


We implement appropriate technical and organisational measures designed to protect personal data against unauthorised or unlawful processing, accidental loss, destruction or damage. These measures include (but are not limited to):

  • Access controls and authentication
  • Encryption of data in transit and, where appropriate, at rest
  • Regular security monitoring and vulnerability management
  • Staff training and confidentiality obligations
  • Incident response procedures

While we take reasonable steps to protect personal data, no method of transmission over the internet or method of electronic storage is completely secure. We cannot guarantee absolute security.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office without undue delay and, where legally required, inform affected individuals.


11. Data Retention


We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, reporting or regulatory requirements.

Indicative retention periods:

Data TypeTypical Retention PeriodGeneral website enquiries and leadsUp to 24 months from last meaningful contactMarketing contactsUntil you unsubscribe or the data is no longer relevantStrategy call and resource request recordsUp to 24 months (unless you become a client)Client contractual and service recordsDuration of the contract plus 6–7 years (or longer if required by law)Technical and analytics dataIn accordance with the retention settings of the relevant service provider and our internal policies


When personal data is no longer required, we will securely delete or anonymise it.


12. Your Rights Under UK Data Protection Law


You have the following rights in relation to your personal data:

  1. Right of access – to obtain confirmation as to whether we process your personal data and to receive a copy of it.
  2. Right to rectification – to have inaccurate personal data corrected and incomplete data completed.
  3. Right to erasure – to request deletion of your personal data in certain circumstances (the “right to be forgotten”).
  4. Right to restrict processing – to request that we limit the processing of your personal data in certain circumstances.
  5. Right to data portability – to receive personal data you have provided to us in a structured, commonly used and machine-readable format, and to transmit it to another controller where technically feasible.
  6. Right to object – to object to processing based on legitimate interests, and to object at any time to processing for direct marketing purposes.
  7. Right to withdraw consent – where processing is based on consent, you may withdraw that consent at any time (this does not affect the lawfulness of processing before withdrawal).
  8. Rights related to automated decision-making – you have rights in relation to automated decision-making and profiling. We do not currently carry out solely automated decision-making that produces legal or similarly significant effects.

To exercise any of these rights, please contact us at [email protected]. We will respond within one month (or longer if the request is complex, in which case we will notify you).

You will not normally have to pay a fee. We may charge a reasonable fee or refuse to act on a request if it is manifestly unfounded, excessive or repetitive.


13. Complaints


You have the right to lodge a complaint with the Information Commissioner’s Office (ICO) if you believe we have not handled your personal data in accordance with the law:

Information Commissioner’s Office

Wycliffe House

Water Lane

Wilmslow

Cheshire

SK9 5AF

Website: https://ico.org.uk

Telephone: 0303 123 1113

We would appreciate the opportunity to address your concerns before you contact the ICO. Please contact us first using the details in Section 2.


14. Third-Party Websites


Our website may contain links to third-party websites, plug-ins or applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements or practices. We encourage you to read the privacy policy of every website you visit.


15. Changes to This Privacy Policy


We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational reasons. The updated version will be indicated by a revised “Last Updated” date at the top of this page. Material changes will be highlighted where appropriate. We encourage you to review this Privacy Policy periodically.

Your continued use of our website after any changes constitutes your acknowledgment of the updated Privacy Policy.


16. Contact Us


If you have any questions, concerns or requests regarding this Privacy Policy or our personal data practices, please contact:

M-Piric IT Consultancy & Support Ltd

Email: [email protected]

Telephone: 0121 416 0121 | 01283 713 900