// PRIVACY.POLICY — UK GDPR COMPLIANT

PRIVACY
POLICY

This policy explains how Teknex IT collects, uses, stores, and protects your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Last updated: 8 June 2026 Version: 1.0

// SECTION 01

Who We Are

Teknex IT is a technology services company based in the North East of England. We provide IT support, managed services, modern workplace solutions, custom software, POS systems, and web development services to businesses across the UK.

For the purposes of UK GDPR, Teknex IT is the data controller responsible for your personal data.

// CONTROLLER DETAILS

NAMETeknex IT

LOCATIONNorth East England, United Kingdom

EMAILhello@teknex-it.co.uk

WEBSITEteknex-it.co.uk

// SECTION 02

What Data We Collect

We collect personal data in the following ways and categories:

[A]

Contact and enquiry data

When you contact us via our website contact form, email, or other channels, we collect your name, email address, company name (if provided), phone number (if provided), and the content of your message.

[B]

Client and contractual data

When you engage us for services, we collect information necessary to fulfil that contract — including billing details, business addresses, system access credentials (handled securely), and communication records.

[C]

Technical and usage data

When you visit our website, we may automatically collect technical data including your IP address, browser type, operating system, referring URLs, and pages visited. This data is used for security and site improvement purposes.

[D]

Support and service data

In the course of providing IT support, we may access, process, or store data held on your systems as necessary to deliver the contracted service. This is done under a data processing agreement where applicable.

// We do not collect sensitive personal data (special category data under UK GDPR) unless strictly necessary and with your explicit consent.

// SECTION 03

How We Use Your Data

We use your personal data only for the purposes for which it was collected, based on the following lawful bases under UK GDPR Article 6:

Purpose

Lawful Basis

Responding to enquiries

Legitimate interests / pre-contractual steps

Delivering contracted services

Performance of a contract

Invoicing and payments

Legal obligation / performance of a contract

Website security & analytics

Legitimate interests

Legal compliance

Legal obligation

Service communications

Legitimate interests / consent

// SECTION 04

Data Sharing and Third Parties

We do not sell, rent, or trade your personal data to third parties for marketing purposes. We may share your data only in the following limited circumstances:

Service delivery partners

Where necessary to deliver your contracted services, we may share data with trusted technology partners (e.g. Microsoft, cloud platform providers). All such partners are subject to data processing agreements and appropriate safeguards.

Legal and regulatory obligations

We may disclose your data where required to do so by law, court order, or in response to a legitimate request by a public authority.

Business transfers

In the event of a merger, acquisition, or sale of business assets, your data may be transferred as part of that transaction. We will notify you of any such change and your rights in relation to it.

// We do not transfer your personal data outside of the UK or European Economic Area unless adequate protections are in place.

// SECTION 05

Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law. Our general retention periods are as follows:

Enquiry and contact data (no contract formed)

12 months

Client contractual and billing records

7 years

Support correspondence and records

3 years post-contract

Website technical and analytics data

26 months

// SECTION 06

Your Rights

Under UK GDPR, you have the following rights in relation to your personal data. You may exercise any of these rights by contacting us at hello@teknex-it.co.uk. We will respond within one calendar month.

Right of access

You have the right to request a copy of the personal data we hold about you (a Subject Access Request).

Right to rectification

You have the right to request that we correct any inaccurate or incomplete personal data we hold about you.

Right to erasure

You have the right to request deletion of your personal data where there is no compelling reason for its continued processing.

Right to restriction

You have the right to request that we restrict the processing of your personal data in certain circumstances.

Right to portability

You have the right to receive your personal data in a structured, commonly used, machine-readable format.

Right to object

You have the right to object to processing based on legitimate interests or for direct marketing purposes.

If you are unhappy with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

// SECTION 07

Cookies

Our website may use cookies and similar tracking technologies. Cookies are small text files stored on your device that help us understand how our website is used and improve your experience.

We use the following types of cookies:

[✓]

Strictly necessary cookies

Essential for the website to function. These cannot be disabled. They do not store personally identifiable information.

[~]

Analytics cookies

Used to understand how visitors interact with our website. We use this data in aggregate form only. These are set only with your consent.

You can control and delete cookies through your browser settings at any time. Disabling certain cookies may affect the functionality of this website.

// SECTION 08

Data Security

We take the security of your personal data seriously and have implemented appropriate technical and organisational measures to protect it against unauthorised access, loss, destruction, or alteration. These measures include:

Encryption of data in transit using TLS/SSL

Access controls and multi-factor authentication on all internal systems

Regular security reviews and vulnerability assessments

Staff awareness and data handling procedures

Secure disposal of data at end of retention period

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and affected individuals without undue delay where required by UK GDPR.

// SECTION 09

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal obligations. When we make material changes, we will update the "Last updated" date at the top of this page.

We encourage you to review this policy periodically. Continued use of our website or services following any changes constitutes your acceptance of the updated policy.

// SECTION 10

Contact Us

If you have any questions about this Privacy Policy, wish to exercise your data rights, or want to raise a concern about how we handle your personal data, please contact us:

// DATA CONTROLLER CONTACT

Email: hello@teknex-it.co.uk

Website: teknex-it.co.uk/contact