We are an IT services company. Most of the personal data we hold belongs to people at client businesses who have contacted us about a project, and to visitors who browse this website. This policy explains what we collect, why we are allowed to collect it, how long we keep it and what you can tell us to do with it.
We serve clients principally in the United Kingdom and the United States while operating from India. We therefore apply UK GDPR standards to everyone we deal with, regardless of where you are, and honour the additional rights that US state privacy laws give their residents.
Where we build, host or maintain a system for a client and that system holds data about the client's own customers, the client is the controller of that data and we act as their processor. Our handling of it is governed by our contract with them, not by this policy.
We do not ask for and do not want special category data — information about health, race, religion, political opinions, trade union membership, sexual orientation, genetics or biometrics. Please do not send it to us. If you do, we will delete it unless we are legally required to keep it.
We do not collect card numbers. Payments are handled by regulated payment providers who take the card details directly; we see only a confirmation that payment succeeded and the last four digits.
Our services are aimed at businesses. We do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, tell us and we will remove it.
UK and EU law requires us to have a specific legal reason for each use of your data. Ours are set out below.
| What we do | Data used | Lawful basis |
|---|---|---|
| Respond to your enquiry and prepare a quote | Identity, contact, project information | Steps taken at your request before entering a contract |
| Deliver the services you have engaged us for | Identity, contact, project information, correspondence | Performance of our contract with you |
| Invoice you and collect payment | Identity, billing details | Performance of contract, and legal obligation for tax records |
| Keep the website secure and prevent abuse | Technical data, usage data | Our legitimate interest in protecting our systems |
| Understand how the site is used and improve it | Usage data, analytics cookies | Your consent, given through the cookie banner |
| Send marketing emails and newsletters | Identity, contact | Your consent, or our legitimate interest where you are an existing client |
| Keep records for accounting, audit and legal defence | All of the above as relevant | Legal obligation, and our legitimate interest in defending claims |
Where we rely on legitimate interests, we have weighed our interest against your rights and concluded ours does not override yours. You can ask us for that assessment, and you can object at any time under clause 8.
We only send marketing emails where you have opted in, or where you are an existing client and the message concerns services similar to those we have already provided. Every marketing email carries an unsubscribe link that works immediately and without needing to log in. Unsubscribing from marketing does not stop the operational emails we must send about a live project.
We do not sell personal data. We share it only where it is necessary, and only with:
We do not permit our service providers to use your data for their own purposes.
We are based in India and use cloud services hosted in several countries, including the United States and the European Economic Area. If you are in the UK or EEA, this means your data will be transferred outside your home jurisdiction.
India has not been the subject of a UK or EU adequacy decision. Where we transfer personal data from the UK or EEA to ourselves or to a provider in a country without adequacy, we rely on the appropriate safeguards permitted by law — principally Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the transfer originates in the UK. We assess each transfer for risk and apply additional technical measures such as encryption in transit and at rest.
You may request a copy of the safeguards we rely on by emailing us.
| Category | Retention period |
|---|---|
| Enquiries that did not become projects | 24 months from last contact |
| Client project records and correspondence | 6 years after the engagement ends |
| Invoices and accounting records | 8 years, to satisfy tax record-keeping requirements |
| Marketing consents and opt-out records | Until withdrawn, then a suppression record kept indefinitely |
| Website analytics | Up to 26 months, then aggregated |
| Server and security logs | 12 months |
The six-year figure for project records reflects the period during which a contractual claim could still be brought. When a retention period expires we delete the data or anonymise it so it can no longer identify you.
Subject to the conditions in the applicable law, you may ask us to:
We do not make decisions about you by automated means that produce legal or similarly significant effects.
Email info@troubleshootersit.com telling us which right you want to use. We may ask for proof of identity so that we do not disclose your data to someone else. We respond within one month. If a request is unusually complex we may extend that by up to two further months and will tell you why within the first month. There is no charge, unless a request is manifestly unfounded or excessive.
Please raise concerns with us first — we would rather fix it directly. You also have the right to complain to a supervisory authority.
If you live in California, Colorado, Connecticut, Utah, Virginia or another state with comprehensive privacy legislation, you have rights to know what personal information we have collected, to have it deleted, to correct it, to obtain a portable copy, and to opt out of its sale or of targeted advertising. You are entitled to exercise these rights without being discriminated against in the price or quality of service you receive.
We do not sell personal information, and we do not share it for cross-context behavioural advertising in exchange for money. Where our advertising measurement cookies could be treated as "sharing" under California law, you can opt out through the cookie settings link in our footer or by sending a Global Privacy Control signal from your browser.
To make a request, email us at the address above with "US privacy request" in the subject line. An authorised agent may act for you if you give them written permission and we can verify it with you directly.
We apply access controls so that staff see only what their role requires, encrypt data in transit using TLS and at rest where our providers support it, require multi-factor authentication on business-critical accounts, keep systems patched, and review supplier security before engaging them.
No system is perfectly secure, and we will not pretend otherwise. If a breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and tell affected individuals directly where the risk is high.
Our site links to third-party websites and embeds a video player. Following a link takes you outside our control, and this policy stops at our boundary. Please read the privacy notice of any site you visit.
We review this policy at least annually and whenever we change how we handle data. The effective date at the top shows when it last changed. Where a change materially affects your rights, we will tell you directly rather than relying on you noticing the update.