Effective: 22 September 2026
Who is responsible for your information
CompTech IT Solutions Ltd is registered in England and Wales under company number 06504311. Our registered office is Lancaster House, Amy Johnson Way, Blackpool, England, FY4 2RP. Our ICO registration is ZA151218.
When CompTech decides why and how personal information is used for its website, enquiries, account administration, billing, contracts, supplier relationships, marketing and its own business administration, CompTech acts as controller.
For data protection rights or questions about this notice, contact dataprotection@comptechits.co.uk or call 01253 364656.
Who this notice covers
This notice covers website visitors, people who contact us, current and prospective customer contacts, supplier and partner contacts, people who use our public courses, people who choose to receive marketing or newsletter updates, and other public-facing business contacts. It also covers controller-side contract, account and billing administration.
It does not replace the separate privacy information that may apply to employees and workers. CompTech does not currently publish a recruitment route on this website, so this notice does not invent recruitment systems or retention periods.
Information we handle
Website and contact enquiries
The contact form asks for your name, organisation, email address, optional phone number, enquiry type and message. It also uses a hidden anti-spam field, Cloudflare Turnstile and same-origin checks to protect the form from automated misuse. Cloudflare may process limited technical request and verification information when it provides the website and protects the form. Please do not send passwords, access tokens, unnecessary sensitive personal information or anything you are not authorised to share.
Customer, prospective customer, supplier and partner contacts
We may hold business contact details, role and organisation information, correspondence, meeting notes, service interests, contractual and account records, billing contacts, supplier information and records needed to manage the relationship. The precise information depends on how you or your organisation deals with CompTech.
Where we did not obtain a prospective business contact's details directly from them, they may have come from company and organisation websites, Companies House or other public business information, public professional or business sources such as LinkedIn, networking and business events, referrals and introductions, the prospective customer's organisation, or another relevant business contact.
We provide this privacy information within a reasonable period after obtaining information indirectly and no later than one month. If we contact the person or disclose the information sooner, we provide it by the first communication or before the first disclosure, as applicable.
Data protection rights and complaints
We handle identity and contact details, the information needed to understand a request or complaint, relevant correspondence and the records needed to investigate, respond and demonstrate how it was handled. The preferred online complaint form is hosted by Microsoft Forms. It does not automatically collect your identity or email address, although you may provide contact details so we can respond.
Cyber security courses
The courses ask for a name at the start. It remains in temporary page memory, is not sent to CompTech and is not stored in cookies. Your name is used locally in your browser to create a certificate. The certificate is not recorded or externally verified by CompTech.
Cookie choices and course progress
The site stores a first-party record of your cookie choice. If you allow functional storage, it can also store course screens, activities and active learning time. Course cookies contain no personal data. The Cookie Policy lists each cookie, purpose and duration.
Optional website analytics
With your explicit analytics consent, Google Analytics (G-19LZ9S85H4) measures visits to eligible pages on www.comptechits.co.uk. It receives browser identifiers and technical usage information, including a known page route and referrer origin. Query strings and fragments are omitted. With analytics consent, we also record a successful contact form submission after our contact service confirms success, without sending form contents. Course pages are excluded. We do not send names, organisation names, email addresses, telephone numbers, messages, form contents, learner information, User-ID or hashed personal identifiers. We do not enable advertising personalisation, Google Signals, enhanced conversions or user-provided data.
Google processes analytics information under its applicable service and data protection terms, potentially outside the United Kingdom. Our international-processing explanation below applies. See Google’s privacy information. Analytics event-data retention is two months; aggregated reports may be retained for longer. Analytics cookies and our consent preference last up to 183 days. Use Cookie settings in the footer to reject or withdraw analytics separately from functional course storage. Withdrawal stops future collection and removes analytics cookies but does not automatically delete previously collected information.
Local password generator
Passwords are generated in your browser and are not sent to or stored by CompTech. This tool does not store generated values in cookies, local storage or session storage. CompTech Google Analytics is excluded from the generator page. Copying a password places it on your device clipboard, which your device may retain or sync. Clear results does not clear the clipboard.
Optional external security tools
With your separate consent, we load EasyDMARC’s domain scanner and phishing link checker. EasyDMARC receives the domain or link you submit and technical browser information. Its embeds may use cookies, Google Tag Manager and Mixpanel analytics independently of CompTech analytics, including on previews. Do not submit complete emails, personal information, passwords or private links. Tool inputs are not sent to CompTech Google Analytics.
Use Cookie settings to withdraw External security tools permission. This unloads the tools but does not delete information or cookies already held by EasyDMARC. Its privacy information explains its processing, retention and applicable rights. Our Cookie Policy explains the separate 183-day preference.
Optional email breach checks
With your separate permission, we load an external checker using Have I Been Pwned data. Your submitted email address or phone number is sent to the provider for the lookup. The provider also receives technical request information and may use service cookies. Our page does not read the submitted address or lookup results, and does not send them to CompTech Google Analytics or our contact form.
Only check details you own or have permission to check. Never enter passwords. You can withdraw Email breach checker permission in Cookie settings; this unloads the frame but does not delete information already received by the provider. The separate preference lasts up to 183 days. We do not promise that the provider retains nothing. For questions about provider handling or deletion, contact us using the privacy details in this notice. See also Have I Been Pwned’s privacy information.
Marketing and newsletters
If you choose to receive updates, or where CompTech is otherwise permitted to send relevant business-to-business communications, we may use your business contact details and communication preferences. We do not assume that PECR consent is required for every message to a corporate subscriber. Individual subscribers, including individuals, sole traders and certain partnerships, receive the additional PECR protections that apply to them. Where marketing uses personal information, UK data protection law still applies.
You can opt out or object to direct marketing at any time. The right to object to use of personal information for direct marketing is absolute. We may keep a minimal suppression record so that an opt-out continues to be respected.
Why we use information
The applicable lawful basis depends on the activity and the relationship involved. A contract with an organisation does not mean that contract is automatically the basis for using its representative's personal information.
| Activity and purpose | Lawful basis |
|---|---|
| Loading the optional email breach checker and sending a requested lookup to its provider. | Consent, requested separately and withdrawable through Cookie settings. |
| Loading optional EasyDMARC security tools and their associated third-party processing. | Consent, requested separately and withdrawable through Cookie settings. |
| Measuring use of eligible website pages with Google Analytics. | Consent, requested separately from functional course storage and withdrawable through Cookie settings. |
| Responding to enquiries and discussing requested services. | Steps requested before entering a contract where you would personally be party to it. Otherwise, our legitimate interest in responding to business enquiries and developing legitimate business relationships. |
| Protecting the website, forms and systems against abuse. | Our legitimate interest in protecting CompTech's website, forms, systems and communications. |
| Administering customer relationships, accounts and service communications. | Our legitimate interest in operating and administering CompTech's business and communicating with customer representatives. Contract applies only where the individual is personally party to the contract. Legal obligation applies only to processing genuinely required by law. |
| Maintaining billing, financial and statutory business records. | Legal obligation where financial, tax, accounting or other record keeping is required by law. Contract may apply where the individual is personally party to it. Otherwise, our legitimate interest in administering accounts and keeping appropriate business records. |
| Communicating with prospective customers and other business contacts. | Our legitimate interest in responding to business enquiries, developing legitimate business relationships and conducting proportionate business-to-business marketing where permitted. Consent is used where required. |
| Administering supplier and partner relationships. | Our legitimate interest in operating CompTech's business and communicating with supplier and partner representatives. Contract applies only where the individual is personally party to it. Legal obligation applies where processing is genuinely required by law. |
| Sending direct marketing and newsletters. | Consent where required. Where electronic-communications rules permit communication without consent, our legitimate interests may apply to proportionate business-to-business marketing. We consider those rules and individual rights before using this basis. |
| Handling data protection rights requests and complaints. | Legal obligation where processing is necessary to meet our statutory data protection duties. Our legitimate interest in keeping an appropriate record may also apply where necessary for disputes or legal claims. |
| Remembering cookie choices and, with permission, course progress. | The learner name is used only in temporary browser memory and is not sent to CompTech. Course progress contains no personal data. We ask for permission before storing functional course-progress cookies, while the cookie-choice record is necessary to remember the setting you selected. |
| Delivering services using customer-controlled personal information solely on the customer's instructions. | This is processor-side service delivery, not a separate controller purpose or lawful basis for CompTech. The customer normally decides the relevant purpose and lawful basis. |
Our legitimate interests
Where we rely on legitimate interests, the relevant interests are operating and administering CompTech's business, communicating with customer, supplier and partner representatives, responding to business enquiries, protecting our website, forms and systems against abuse, developing legitimate business relationships, and proportionate business-to-business marketing where permitted. We consider the nature of the information, the context, what people reasonably expect and the effect on their rights. Legitimate interests do not automatically override those rights.
Information needed from you
Some information may be needed to respond to an enquiry, establish or administer a customer or supplier relationship, provide requested services, invoice or administer an account, or comply with legal requirements. Not every field or item of information is mandatory. If necessary information is not supplied, we may be unable to respond fully, enter into or administer the relevant relationship, provide the requested service, or complete the relevant transaction or legal process.
When CompTech acts on a customer's instructions
When CompTech handles personal data solely to deliver managed IT or another service on a customer's instructions, CompTech may act as processor and that customer remains the relevant controller. The customer's privacy notice should explain how it uses the information and how to exercise your rights.
This distinction does not remove your rights. If you contact us about information that we process only for a customer, we will explain where this applies and assist the customer as required. We handle concerns about CompTech's own controller processing ourselves.
Who receives information
Authorised CompTech staff receive information where they need it for their work. The website runs on Cloudflare infrastructure and uses Cloudflare Email Service for contact enquiries and Cloudflare Turnstile for form protection. Microsoft Forms hosts the preferred data protection complaint form. These providers process relevant information under their service and data protection terms.
Information may also be shared with professional advisers, service providers, authorities or other organisations where this is necessary for the relevant purpose, required by law or needed to establish, exercise or defend legal rights. We do not sell personal information or use it for third-party advertising.
International processing
Some service providers may process personal information outside the United Kingdom. Where this involves a restricted transfer, CompTech uses an applicable lawful transfer route. Depending on the destination and provider, this may include United Kingdom adequacy regulations or appropriate contractual safeguards. Contact dataprotection@comptechits.co.uk for further information about safeguards relevant to your circumstances.
How long information is kept
Enquiries and prospective customers
We keep information while dealing with an enquiry or actively considering or developing the potential relationship. Afterwards, we retain it only where reasonably needed to keep a record of the interaction, manage an objection or suppression request, resolve a dispute, establish, exercise or defend legal claims, or meet another applicable legal requirement.
Customer contacts and relationship records
We keep relevant contact and relationship information while the customer relationship continues. After it ends, relevant records are retained according to applicable accounting and tax obligations, contractual record requirements, dispute and claims requirements, and other legal obligations. Different customer records may therefore have different lifespans.
Billing, financial and contractual records
Records subject to statutory accounting, tax or other legal record keeping requirements are kept for the applicable legal period. Other contractual records are retained only while reasonably needed for administration, disputes, legal claims or another applicable requirement.
Supplier and partner contacts
We keep relevant information while the relationship is active and afterwards only where needed for legitimate business records, legal or accounting obligations, or related claims.
Marketing
We keep marketing contact information while we have an appropriate lawful basis and it remains relevant for permitted marketing activity. If someone objects, unsubscribes or withdraws applicable consent, we stop marketing use as appropriate. We may retain a minimal suppression record so we can respect the objection and avoid adding the person again.
Data protection rights and complaints
We keep information while handling a request or complaint and afterwards where reasonably required to evidence compliance, respond to regulatory enquiries, deal with disputes, or establish, exercise or defend legal claims.
Courses and cookie choices
Course learner names disappear when the page is refreshed or closed. The cookie-choice record lasts for 183 days. If you allow functional storage, course-progress cookies last for 180 days or until you reset progress or withdraw functional consent. The Cookie Policy explains these cookies in more detail.
Your data protection rights
Depending on the circumstances, you may have the right to ask for access to your personal information, correction, deletion, restriction, objection, or transfer of information you provided. You can also withdraw consent where processing relies on consent. Some rights have legal limits and we may need to confirm your identity before responding.
Contact dataprotection@comptechits.co.uk if you want to exercise a data protection right or have a question about how we use your personal information.
Complaints
If you are unhappy with how we have handled your personal information, you have the right to complain to us. We will acknowledge your complaint within 30 days. We will investigate it without undue delay, keep you informed of progress and tell you the outcome without undue delay.
How to make a data protection complaint
You also have the separate right to complain to the Information Commissioner's Office, the United Kingdom data protection regulator. You do not have to complete CompTech's complaint process before contacting the ICO.
Security and external links
CompTech uses proportionate technical and organisational measures intended to protect personal information, but no online service can promise absolute security. CompTech Google Analytics is contacted only after analytics opt-in. EasyDMARC and its own tracking providers are contacted separately when external tools are allowed. Cloudflare hosting and form protection operate independently of that choice. Following external links also contacts the relevant providers, whose privacy information applies.
Changes to this notice
We may update this notice when our activities, website features, providers or legal requirements change. The effective date at the top shows the current version.
