• Home
  • Privacy policy

Privacy policy

How we collect, use and look after personal data.

Last updated:

Template — needs your review before launch. This is a working skeleton written around UK GDPR and the Data Protection Act 2018. Fill in every CAPITALISED placeholder, check it describes what you actually do, and have it reviewed by someone qualified. It is not legal advice.

1. Who we are

UHIY Tech Solutions is a trading name of YOUR FULL NAME, a sole trader established in the United Kingdom, trading from BUSINESS ADDRESS.

For the personal data described in this policy we are the data controller. Where we process personal data on behalf of our clients — for example the customer contacts held inside a client’s account — we act as a data processor under a separate data processing agreement.

We are registered with the Information Commissioner’s Office under registration number ZA000000. You can contact us about anything in this policy at support@uhiy-tech.com.

2. What we collect

DataWhenWhy
Name, email, phone, business name You complete a form or book a call To respond to your enquiry and provide the service
Billing and payment details You become a client To take payment and meet our accounting obligations
Account and usage data You use the platform To deliver, support and improve the service
Correspondence You contact us To keep an accurate record of what was agreed

Simply browsing this website collects nothing. We use no analytics and set no cookies — see our cookie policy. We only hold what you choose to send us. If we add analytics in future we will update this table and ask for your consent first.

We do not knowingly collect data from children, and we do not collect special category data.

3. Our lawful bases

  • Contract — to provide the services you have signed up for and take payment.
  • Legitimate interests — to respond to enquiries, secure our systems, keep records and improve our services. We have assessed that these do not override your rights.
  • Consent — for marketing emails and texts, and for non-essential cookies. You can withdraw consent at any time.
  • Legal obligation — to keep financial records for the periods HMRC requires.

4. Marketing

We only send marketing where you have consented, or where the PECR soft opt-in applies because you are an existing customer and were given a clear chance to refuse. Every marketing message includes a one-click unsubscribe, and texts accept a STOP reply. Opting out of marketing does not stop service messages about your account.

5. Who we share it with

We never sell your personal data. We share it only with suppliers who help us run the business, each under a contract that limits what they may do with it. These include hosting and platform providers, payment processors, email and SMS providers, and our accountants. We will also disclose data where we are legally required to.

Where a supplier processes data outside the UK, we rely on UK adequacy regulations or on the International Data Transfer Agreement or Addendum, with appropriate safeguards in place.

6. How long we keep it

  • Enquiries that don’t become clients: up to 24 months.
  • Client records: for the life of the contract and 6 years afterwards, to meet accounting and limitation requirements.
  • Financial records: 6 years from the end of the accounting period.
  • Marketing consent records: until consent is withdrawn, plus a record of the withdrawal.

7. Your rights

Under UK GDPR you have the right to:

  • be told how your data is used and get a copy of it;
  • have inaccurate data corrected;
  • have data erased where there is no continuing reason to hold it;
  • restrict or object to processing, including objecting to direct marketing at any time;
  • data portability;
  • withdraw consent where consent is our lawful basis.

Email support@uhiy-tech.com and we will respond within one month. If you are unhappy with how we have handled it you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113, though we would appreciate the chance to put it right first.

8. Security

We use encryption in transit, access controls, multi-factor authentication on administrative accounts and regular backups. No system is perfectly secure, but we take this seriously and will notify you and the ICO of any qualifying breach within the required timeframes.

9. Changes

We may update this policy from time to time. The date at the top always reflects the current version, and we will tell clients directly about any significant change.