Privacy Policy
This policy explains how Cloud Guard, trading as Cloud Guard (“Cloud Guard”, “we”, “us”), collects and uses personal data. It covers visitors to our website, people who contact us or enquire about our services, and our business clients and their staff.
We are an IT services provider based in Scotland. We handle personal data in two distinct roles, and this policy covers both:
- As a data controller — when we decide why and how personal data is used. This covers our website, our marketing, our client relationships and our own staff and suppliers.
- As a data processor — when we handle personal data inside our clients’ own systems while delivering managed IT, cloud, backup and support services. In those cases our client is the controller and decides what happens to the data. See section 4.
Contents
- Who we are
- What personal data we collect
- Why we use it, and our lawful basis
- Data we handle on behalf of clients
- The support desk
- Special category data
- Marketing
- Cookies and website analytics
- Who we share data with
- International transfers
- How long we keep data
- How we protect data
- Your rights
- Automated decision-making
- Children
- Changes to this policy
- Contacting us and complaints
1. Who we are
For the personal data described in this policy where we act as controller, the data controller is:
24B Hamilton Street, Carluke, ML8 4HA, United Kingdom
General enquiries: sales@cloudguard.tech
Telephone: 0330 789 0903 or +44 141 264 2729
We are not required to appoint a Data Protection Officer, but we have a named person responsible for data protection who can be reached at the privacy address above.
2. What personal data we collect
When you visit our website
- Technical data collected automatically by our web server and hosting provider: IP address, browser type and version, operating system, referring page, pages viewed, and the date and time of your visit.
- Cookie data — see section 8.
When you contact us or request a trial
- Your name, business email address, telephone number, company name and job title.
- The content of your enquiry, and any further correspondence between us.
- If you request the 7-day trial, details of the trial environment and the services you want to evaluate.
When you become a client (and for client staff)
- Contact and account data: names, work email addresses, work telephone numbers, job roles and authorisation levels of your nominated contacts and authorised users.
- Billing data: billing contact, billing address, purchase order references and payment records. Card details are handled by our payment provider and are not stored by us.
- Service delivery data: support tickets, call and email records, site visit notes, asset registers, licence assignments, and configuration records for the systems we manage.
- Monitoring and security data generated by the tools we deploy on your estate: device identifiers, usernames, logon events, alerts, patch status, backup job results and similar telemetry.
When you apply for a job or work with us as a supplier
- Candidate details and CVs you send us, and contact details for supplier representatives.
3. Why we use it, and our lawful basis
Under UK GDPR we must have a lawful basis for each use of personal data. Ours are set out below.
| What we do | Data used | Lawful basis |
|---|---|---|
| Respond to enquiries, quote for work and set up trials | Contact details, enquiry content | Legitimate interests — responding to a request about our services. Where you are a sole trader or individual, steps prior to entering a contract. |
| Deliver the services we have contracted to provide, including support, monitoring and backup | Account, service delivery and monitoring data | Performance of a contract with you, or legitimate interests in performing our contract with your employer |
| Billing, credit control and account administration | Billing and account data | Performance of a contract; legal obligation for tax and accounting records |
| Protect our systems and our clients’ systems from security threats | Technical, monitoring and security data | Legitimate interests — network and information security; legal obligation where a breach is reportable |
| Keep our website running, secure and working correctly | Technical data, essential cookies | Legitimate interests — operating a secure, functioning website |
| Send marketing about our services | Business contact details | Consent, or legitimate interests where permitted for business-to-business marketing. See section 7. |
| Improve our services and understand how our website is used | Aggregated and technical data | Legitimate interests — understanding and improving what we offer. Consent where non-essential cookies are involved. |
| Comply with law and establish or defend legal claims | Any relevant data | Legal obligation; legitimate interests in protecting our legal position |
Where we rely on legitimate interests, we have assessed that our interest does not override your rights and freedoms. You can ask us for details of that assessment, and you have the right to object — see section 13.
4. Data we handle on behalf of clients
Delivering managed IT support, Microsoft Azure services, cloud security, hyper-converged infrastructure, connectivity and private data centre backup and recovery means we necessarily have access to personal data held inside our clients’ own systems — their email, files, databases, directories, endpoints and backup sets. That data may relate to our client’s own staff, customers, patients, pupils, suppliers or members of the public.
For that data, our client is the data controller and we are the processor. We only handle it on the client’s documented instructions. We do not decide what it is used for, we do not use it for our own purposes, and we do not sell it or use it to train any product of our own.
Our contracts with clients include the terms required by Article 28 of the UK GDPR. Under them we commit to:
- Process the data only on the client’s documented instructions, including on international transfers.
- Ensure our staff are bound by confidentiality and are trained appropriately.
- Apply appropriate technical and organisational security measures.
- Engage sub-processors only with the client’s authorisation, and pass equivalent obligations down to them.
- Assist the client in responding to requests from individuals exercising their rights.
- Assist the client with security, breach notification and data protection impact assessments.
- Notify the client without undue delay on becoming aware of a personal data breach.
- Delete or return the data at the end of the engagement, as the client directs.
- Make available the information needed to demonstrate compliance, and allow audits.
If you are an individual whose data is held in a system we manage — for example, you are a customer or employee of one of our clients — you should direct any request about your data to that organisation, not to us. They control the data and decide how requests are answered. If you contact us instead, we will refer you to them and let them know.
5. The support desk
Our support portal at supportdesk.cloudguard.tech holds the account details of authorised users at our client organisations, and the tickets they raise. Tickets, including any attachments, screenshots, log files or diagnostic output you send us, may contain personal data.
Please send us only the information needed to resolve the issue. If a ticket needs to include personal data, tell us so that we can handle it appropriately. Remote access sessions to client devices are logged, and may be recorded where the client has asked for that.
6. Special category data
We do not seek out special category data — information revealing health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, sex life or sexual orientation — or data about criminal offences, in the course of our own business as controller.
We may encounter such data incidentally as a processor, where it exists in a client system we support or back up — for example in a healthcare, legal or education setting. Where that is the case, we handle it under our client’s instructions and apply additional access controls and confidentiality obligations. Clients in those sectors should raise it with us before onboarding so that the appropriate safeguards and contractual terms are in place.
7. Marketing
We may send you information about our services by email, telephone or post where you have asked us to, where you are an existing client, or where you are a corporate contact and the law permits us to do so without prior consent.
If you have bought services from us, or enquired about them, we may email you about similar services under the “soft opt-in” rule in the Privacy and Electronic Communications Regulations. Every such message includes an unsubscribe link.
You can opt out at any time — use the unsubscribe link in any marketing email, or email Opting out of marketing does not stop service messages about work we are doing for you, such as maintenance windows, incident notifications or invoices.
We do not sell your personal data, and we do not share it with third parties for their own marketing.
8. Cookies and website analytics
Cookies are small files stored on your device by a website. We use them as follows.
| Type | Purpose | Consent needed? |
|---|---|---|
| Strictly necessary | Keeping the site working — session handling, load balancing, security, and remembering your cookie preferences. | No. These are exempt, and the site cannot work without them. |
| Analytics | Understanding which pages are visited and how visitors find us, so we can improve the site. | Yes. These are only set if you accept them. |
| Functional | Remembering preferences and supporting embedded content such as videos or maps. | Yes. |
Non-essential cookies are not set unless you consent, and you can change or withdraw your choice at any time through the cookie settings on the site. You can also block or delete cookies in your browser settings, though some parts of the site may then not work properly.
Our web server also keeps access logs containing IP addresses and request details. We use these for security and troubleshooting, and they are deleted on the schedule in section 11.
9. Who we share data with
We share personal data only where we need to, and only with organisations that are bound to protect it. Our recipients fall into these categories:
- Technology suppliers whose platforms we build on — principally Microsoft, for Microsoft 365 and Azure services.
- Hosting and data centre providers, including the UK data centres used for backup and disaster recovery.
- Our own business systems suppliers — the support desk, remote monitoring and management, documentation, email and telephony platforms we use to run the business.
- Connectivity and telecoms carriers, where we provide or manage a connectivity service.
- Professional advisers — accountants, auditors, insurers and solicitors.
- Payment and banking providers, for processing payments.
- Public authorities, regulators and law enforcement, where we are legally required to disclose.
- A buyer or successor, if we sell or reorganise all or part of the business. We would tell clients before any such transfer of their data.
Suppliers who process personal data on our behalf act under written contracts that restrict them to our instructions and require appropriate security. Clients can request our current sub-processor list for the services they take, and we give notice of changes to it as set out in their contract.
10. International transfers
We aim to keep client data in the United Kingdom. Backup and disaster recovery services are delivered from UK data centres, and Azure tenancies are provisioned in UK regions by default unless a client asks otherwise.
Some of our suppliers, including Microsoft, operate globally, so personal data may be accessed from or stored in countries outside the UK — typically for support, out-of-hours operations or service administration.
Where personal data leaves the UK, we rely on one of these safeguards:
- Transfer to a country covered by UK adequacy regulations.
- The UK International Data Transfer Agreement, or the UK Addendum to the European Commission’s Standard Contractual Clauses, together with a transfer risk assessment.
- Another safeguard recognised under Article 46 of the UK GDPR.
You can ask us for details of the safeguard applying.
11. How long we keep data
We keep personal data only as long as we need it, then delete it securely or anonymise it.
| Data | Retention period |
|---|---|
| Website enquiry and contact form submissions that do not lead to a contract | 24 months from last contact |
| Web server access logs | 12 months |
| Marketing contact details and consent records | Until you opt out, plus a suppression record kept indefinitely so we do not contact you again |
| Client contract, account and service records | 6 years after the end of the engagement, in line with the prescription period in Scotland |
| Invoices, payment records and accounting data | 6 years from the end of the relevant accounting period, as required by HMRC |
| Support tickets and remote session logs | [CONFIRM — typically 24 to 36 months] |
| Security and monitoring telemetry | [CONFIRM — typically 12 months] |
| Backup data held for clients | As set out in the client’s service schedule. Backups age out on their retention cycle, so deletion from a live system may take until the cycle completes. |
| Unsuccessful job applications | 12 months, unless you ask us to keep your details for longer |
Where we act as processor, retention is set by our client, not by us.
12. How we protect data
We are a security provider, and we apply to ourselves the controls we recommend to clients. These include:
- Encryption of data in transit, and at rest where the platform supports it.
- Multi-factor authentication on administrative and remote access.
- Role-based access control and least privilege, with privileged access reviewed regularly.
- Separation between client environments.
- Endpoint protection, patching and vulnerability management.
- Logging and monitoring of administrative activity.
- Staff vetting, confidentiality obligations and data protection training.
- Documented incident response and business continuity procedures, which we test.
No system can be guaranteed completely secure. If a personal data breach occurs that is likely to result in a risk to people’s rights and freedoms, we will report it to the Information Commissioner’s Office within 72 hours of becoming aware, and tell affected individuals where the risk is high. Where we are a processor, we notify the client without undue delay so that they can meet their own obligations.
13. Your rights
Under UK data protection law you have the right to:
- Be informed about how your data is used — which is the purpose of this policy.
- Access a copy of the personal data we hold about you.
- Rectification — have inaccurate data corrected, or incomplete data completed.
- Erasure — have data deleted, where we no longer have grounds to keep it.
- Restrict processing — have us pause use of your data in certain circumstances, for example while accuracy is being checked.
- Data portability — receive data you gave us in a structured, commonly used, machine-readable format, where processing is based on consent or contract and is automated.
- Object to processing based on legitimate interests. You can object to direct marketing at any time, and we must stop.
- Withdraw consent at any time, where we rely on it. Withdrawing consent does not affect processing carried out before you withdrew it.
- Not be subject to a solely automated decision with legal or similarly significant effects — see section 14.
To exercise any of these, email [PRIVACY EMAIL] or write to us at the address in section 1. We will respond within one month. If a request is complex or there are several, we may extend that by up to two further months, and we will tell you if so. There is no charge, unless a request is manifestly unfounded or excessive.
We may need to confirm your identity before acting, to make sure we do not disclose data to the wrong person.
If your data sits in a system we manage for a client, we cannot action your request directly — please see section 4.
14. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you by solely automated means, and we do not carry out profiling of that kind.
Our security and monitoring tools do apply automated rules — for example, flagging a suspicious logon, quarantining a file or raising an alert. These protect systems rather than make decisions about individuals, and a person reviews anything that affects someone’s access.
15. Children
Our website and services are aimed at businesses and other organisations, not at children, and we do not knowingly collect children’s data through them. Where we support an organisation whose systems contain children’s data, such as a school, we handle it as a processor under that organisation’s instructions and the safeguards agreed with them.
16. Changes to this policy
We review this policy regularly and may update it to reflect changes in our services, our systems or the law. The date at the top shows when it was last changed. If we make a significant change, we will tell clients directly and give reasonable notice before it takes effect.
17. Contacting us and complaints
For any question about this policy or about how we handle your data:
Telephone: 0330 789 0903Post: Data Protection, Cloud Guard, 24B Hamilton Street, Carluke, ML8 4HA
We would always rather hear from you first and put something right. You also have the right to complain to the UK’s data protection regulator at any time:
Information Commissioner’s OfficeWycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113
ico.org.uk/make-a-complaint