Home/Privacy notice
Privacy notice
This notice explains what personal data WB TECH SYSTEMS LTD collects, why we collect it, how long we keep it and what rights you have. It is written to meet the UK GDPR and the Data Protection Act 2018.
Last updated: 25 August 2026
1. Who we are
WB TECH SYSTEMS LTD ("WB Tech Systems", "we", "us") is a private company limited by shares, registered in England and Wales under company number 16177605, with its registered office at 408 New Hythe Lane, Larkfield, Aylesford, Kent, England ME20 6SA.
We are the data controller for personal data collected through this website and through our direct dealings with enquirers, clients and suppliers. Where we administer systems on behalf of a client, we act as a data processor for the personal data held in those systems, under the terms of the services agreement between us.
Questions about this notice should be sent to support@wbtechsystems.org.
2. What we collect
We keep data collection to what is necessary. In practice that means:
| Category | Examples | Where it comes from |
|---|---|---|
| Enquiry data | Name, organisation, email address, telephone number if you provide it, and the content of your message | You, when you email us |
| Client contact data | Names, work email addresses, job roles and work telephone numbers of your staff who raise tickets or authorise changes | Your organisation |
| Service records | Support tickets, correspondence, engineer notes, asset and configuration records, monitoring and audit logs | Generated during the service |
| Contract & billing data | Agreements, purchase orders, invoices, payment records | You and our accounting records |
| Technical data | IP address, browser type and pages requested, recorded in standard web-server logs by our hosting provider | Automatically, when you visit this site |
This website has no contact form, no analytics, no advertising tags and no tracking cookies. Nothing you type into a page is transmitted to us — contact is by email only.
3. Why we use it, and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Replying to an enquiry and preparing a proposal | Legitimate interests, and steps taken at your request prior to entering a contract |
| Delivering support, monitoring and project services | Performance of a contract |
| Maintaining asset, configuration and incident records | Performance of a contract, and legitimate interests in operating a documented service |
| Invoicing, credit control and statutory accounting | Legal obligation, and performance of a contract |
| Protecting our systems and investigating misuse | Legitimate interests in the security of our services |
| Responding to legal or regulatory requests | Legal obligation |
Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights and freedoms, and we have concluded that they are not, because the processing is limited, expected in a business context, and necessary to provide a service you or your employer has asked for.
4. Marketing
We do not operate a marketing mailing list, we do not buy contact data, and we do not send unsolicited campaigns. If you contact us and do not become a client, we may follow up once about that specific enquiry; you can ask us to stop at any time and we will.
5. Who we share it with
We do not sell personal data. We share it only where necessary, with:
- Service providers we rely on — email and file hosting, remote monitoring and management tooling, backup platforms, ticketing and accounting software, and our website host. Each is bound by contract to process data only on our instructions.
- Your own suppliers — connectivity providers, hardware vendors or software publishers, where resolving your issue requires us to raise a case on your behalf, and only with the details that case needs.
- Professional advisers — accountants, insurers and legal advisers, where they need the information to advise us.
- Authorities — where we are legally required to disclose, or to establish, exercise or defend legal claims.
Some providers may process data outside the UK. Where that happens we rely on UK adequacy regulations or on the International Data Transfer Agreement or Addendum, so that your data keeps an equivalent level of protection.
6. How long we keep it
| Record | Retention |
|---|---|
| Enquiries that do not become clients | Up to 12 months from the last contact |
| Client correspondence and support tickets | Duration of the agreement, then up to 6 years |
| Contracts, invoices and accounting records | 6 years after the end of the financial year they relate to |
| Configuration and asset documentation | Duration of the agreement, then handed over and deleted on request |
| Web-server logs held by our host | Short-term, per the host's standard retention |
When a retention period ends, records are deleted or securely destroyed.
7. How we protect it
- Access is limited to the people who need it, using individual named accounts.
- Multi-factor authentication is enforced on our email, management and administrative systems.
- Client credentials are held in an encrypted secret store, never in plain documents or email.
- Company devices are encrypted, patched and centrally managed.
- Backups of our own records are taken and periodically restore-tested.
No system is perfectly secure, but if a personal data breach occurs that is likely to result in a risk to individuals we will notify the Information Commissioner's Office within 72 hours, and affected individuals or client organisations without undue delay.
8. Your rights
Under UK data protection law you have the right to:
- be informed about how your data is used — this notice;
- request a copy of the personal data we hold about you;
- have inaccurate data corrected;
- request erasure, where we have no continuing lawful reason to hold it;
- request restriction of processing while a concern is investigated;
- data portability, where processing is automated and based on consent or contract;
- object to processing carried out on the basis of legitimate interests;
- withdraw consent at any time, where consent was the basis for processing.
Email support@wbtechsystems.org to exercise any of these. We respond within one month and do not charge a fee. We may ask for proof of identity before releasing personal data. If your data sits inside a client system we administer, we will pass your request to that client, who is the controller.
9. Complaints
If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, or at ico.org.uk.
10. Changes to this notice
We review this notice when our services or systems change, and at least annually. The current version is always published here with the date it was last updated. Material changes affecting existing clients are notified by email.
Last updated: 25 August 2026