Privacy Policy
Who we are
This website is operated by Office 21 Ltd (“Office 21”, “we”, “us”, “our”), a UK-based Managed Service Provider (MSP) providing IT support, cloud, cybersecurity and related services.
- Website: https://o21.uk
- Registered company: Office 21 Ltd, registered in England and Wales, company number 13848331
- Registered office: 29a High Street, West Wickham, United Kingdom, BR4 0LP
- ICO registration number: 00011762314
- Data protection contact: Guy Edelstyn, Data Protection Lead, dpo@o21.uk
- Telephone: 0204 553 0000
We are the “controller” of the personal data described in this notice, which means we decide how and why it is processed.
Scope of this notice
This notice explains how we handle personal data where we act as a controller: visitors to our website, people who contact or enquire with us, our clients’ and prospects’ business contacts, and recipients of our messages.
Where we deliver IT services to a client and access personal data held in that client’s systems, we normally act as a “processor” on the client’s behalf. That processing is governed by our contract and Data Processing Agreement (DPA) with the client, not by this website notice.
The personal data we collect and why
Website visits. Our website does not have user accounts or comments. Like any website, our hosting provider (Cloudflare) processes technical data such as your IP address and browser details to deliver pages, keep the site secure and block abuse.
Contact and enquiry forms. When you contact us through a form, by email or by phone, we collect the details you provide (such as name, business, email address, telephone number and the content of your enquiry) so we can respond and, where relevant, provide a quotation or service.
Clients and prospects. We process business contact details and correspondence to manage our relationship, provide services, handle billing, and for legitimate marketing to business contacts.
Text messaging (SMS). Where you have opted in, we process your mobile telephone number and message content to send you service, account, appointment or support-related messages. See “Text messaging” below.
Cookies and analytics. See “Cookies” and “Analytics” below.
Lawful bases
Where we act as a controller, we rely on one or more of the following lawful bases under UK GDPR:
- Performance of a contract, to provide services you or your organisation have requested.
- Legitimate interests, to operate, secure, improve and market our services, and to respond to enquiries, balanced against your rights and freedoms.
- Legal obligation, to meet accounting, tax and other statutory duties.
- Consent, where required (for example certain cookies and certain marketing messages). You can withdraw consent at any time.
Text messaging (SMS)
We send SMS messages only to people who have provided their mobile number and opted in (for example by requesting updates, providing consent on a form, or by an existing service relationship where you have agreed to be contacted this way).
- Message frequency varies depending on the nature of your interaction with us.
- Message and data rates may apply, depending on your mobile carrier and plan.
- To stop receiving messages, reply STOP at any time. To get help, reply HELP or contact us at dpo@o21.uk.
- No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Mobile opt-in and consent data are never sold or shared. We only share mobile information with the sub-processors that operate our messaging platform (for example our messaging provider) so that messages can be delivered on our behalf.
Full terms are set out in our SMS Terms and Conditions.
Cookies
Our website does not set cookies for tracking or advertising, so we do not show a cookie banner. Our contact form uses Cloudflare Turnstile to check that a real person is submitting it; Turnstile may process technical signals from your browser for that purpose only. Embedded tools on specific pages (for example our remote support page) may set their own cookies when you use them.
Embedded content from other websites
Articles may include embedded content (such as videos, images or articles). Embedded content from other websites behaves as if you had visited that website, and those websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that content, including where you are logged in to them.
Analytics
We use Cloudflare Web Analytics to understand how our site is used. It does not use cookies or local storage, does not fingerprint visitors, and reports only aggregate figures that do not identify individuals.
Artificial intelligence and large language models
We use software tools that incorporate artificial intelligence, including large language models (LLMs), to help us deliver, support, secure and improve our services (for example, drafting and reviewing communications, summarising information, and improving the quality and efficiency of our support). Where these tools process personal data, that processing takes place on services hosted within the European Union or European Economic Area (EU/EEA), or the United Kingdom.
Where we use third-party AI providers, they act as our processors under a written contract. We select providers that:
- process personal data only on our documented instructions;
- do not use your personal data to train their own, public or foundation models;
- apply appropriate technical and organisational security measures; and
- host and process the data within the EU/EEA or the UK.
Our lawful basis for this processing is our legitimate interests in operating, securing and improving our services efficiently, balanced against your rights. We do not use AI to make solely automated decisions that produce legal or similarly significant effects about you; a member of our team remains responsible for decisions that affect you.
Where we handle personal data on behalf of a client (as a processor), any use of AI tools is carried out under that client’s instructions and the relevant Data Processing Agreement.
Who we share your data with
We do not sell your personal data. We share it only where necessary, with:
- our IT, hosting, website and communications sub-processors (including our website host, messaging/SMS provider and email provider);
- Cloudflare, which hosts our website and provides spam protection for our contact form;
- AI/LLM providers as described above;
- professional advisers (such as accountants and legal advisers) and regulators where required by law.
We put appropriate contracts and safeguards in place with our sub-processors. As stated above, mobile opt-in and consent data are never shared with third parties for their own or for marketing purposes.
International transfers
We are UK-based and provide services to clients in the UK and the EU/EEA. Some of our personnel are located outside the UK (including Japan) and may access personal data to deliver our services. Where personal data is transferred to, or accessed from, outside the UK or EEA, we ensure an appropriate transfer mechanism and safeguards are in place (such as adequacy regulations or the International Data Transfer Agreement / Addendum).
How long we keep your data
We keep personal data only as long as necessary.
- For our business records (enquiries, clients, contracts, billing and correspondence), our default retention is up to six years, for contractual, legal, accounting and defence-of-claims purposes, and shorter where longer retention is not necessary.
- Where a legal hold, dispute or regulatory requirement applies, retention may be extended for the duration of that matter.
How we protect your data
Office 21 is Cyber Essentials certified. We apply security controls appropriate to the risk, including multi-factor authentication for administrative access, encryption in transit and at rest where supported, least-privilege access, secure remote access, 24×7 security monitoring, and a defined incident response process for security incidents and personal data breaches.
Your rights
Under UK GDPR you have the right to access, rectify, erase, restrict or object to processing, to data portability, and to withdraw consent where processing is based on consent. You can request an export of the personal data you have provided, and request erasure (this does not include data we must keep for administrative, legal or security purposes).
To exercise any of these rights, contact dpo@o21.uk. We will verify your identity before responding.
Complaints
If you have a concern about how we handle your personal data, please contact us first at dpo@o21.uk. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK regulator, at https://ico.org.uk or 0303 123 1113.
Changes to this notice
We review this notice at least annually and whenever our services, systems or the law change materially. The effective date and version above indicate the current version.