Skip to content
BritonOne Technology
Legal

Privacy Policy

How BritonOne Technology Ltd collects, uses, stores, and protects personal data. This policy applies to all personal data we hold as a data controller, and references our processor obligations where we operate inside client cloud accounts.

01

Who we are

BritonOne Technology Ltd is a private limited company incorporated in England and Wales. Our registered office is at 134 Westbourne Terrace, London W2 6QB, United Kingdom.

We are registered with the Information Commissioner's Office (ICO) as a data controller and as a data processor (when operating inside client cloud accounts on engagements). Our ICO registration reference is available on request.

02

Information we collect

We collect personal data in three contexts: (1) when you contact us via this website or by email; (2) when you become a client, supplier, or candidate; and (3) when you visit our website.

Contact and enquiry data

When you submit our contact form, send us an email, or reach out via LinkedIn, we collect name, work email, company, role, country, industry, and the content of your message.

Client and supplier data

For active engagements we collect contracting-party data necessary for the master services agreement and statements of work, including registered company name, registered address, billing contact, and named technical points of contact.

Candidate and engineer data

For our hiring process we collect CV data, references, right-to-work documentation, and background-check evidence (BS7858 standard). Successful candidates also provide payroll, tax, and emergency-contact information.

Website telemetry

We collect basic visit telemetry (page views, referrer, country-level location, device class) via privacy-aware analytics. We do not use third-party advertising cookies on this website.

03

How we use information

We use personal data only for the purpose for which it was collected, plus a narrow set of legitimate-interest uses listed below.

  • To respond to your enquiry and engage in pre-contract discussion.
  • To deliver contracted services, including team mobilisation and billing.
  • To meet our legal and regulatory obligations (tax, employment, ICO registration).
  • To improve our website and content based on aggregate telemetry.
  • To screen and recruit BritonOne Technology engineers and operate payroll.
04

Lawful basis for processing

We rely on the following lawful bases under UK GDPR Article 6, depending on the processing context:

  • Contract (Article 6(1)(b)): for processing necessary to perform an engagement or take pre-contract steps at your request.
  • Legitimate interest (Article 6(1)(f)): for ordinary business correspondence, internal recruiting, and analytics.
  • Legal obligation (Article 6(1)(c)): for tax, employment, anti-money-laundering, and KYC processing.
  • Consent (Article 6(1)(a)): only where you have explicitly opted in (for example, marketing communications).
05

Sharing and disclosure

We do not sell personal data. We share data only where necessary to operate, with the categories of recipient listed below, and only under written processor agreements.

  • Payroll and HR providers (for our employees and contractors).
  • Cloud and SaaS providers (storage, communication, CRM): UK or EU-region by default.
  • Background-check providers (for candidates only, with explicit consent).
  • Our auditors, accountants, and legal advisers under professional confidentiality.
  • Law-enforcement or regulators where compelled by valid legal process.
06

Data retention

We retain personal data only as long as necessary for the purpose for which it was collected, or as required by law. Standard retention periods are:

  • Enquiry data: 24 months from last contact, then deletion.
  • Client engagement data: duration of the engagement plus seven years (UK statute of limitations).
  • Candidate data (unsuccessful): 12 months from last interview, with consent for longer-term retention.
  • Employee data: duration of employment plus six years.
  • Website telemetry: aggregated and retained for 26 months.
07

Your rights

Under UK GDPR you have the right to access, rectify, erase, restrict, port, and object to processing of your personal data. You also have the right to withdraw consent at any time where we rely on consent as the lawful basis.

To exercise any of these rights, email our Data Protection contact below. We will respond within one calendar month, with no charge for ordinary requests. If you are unhappy with our handling, you have the right to lodge a complaint with the ICO (ico.org.uk).

08

International transfers

We primarily operate inside the UK and EU. Where personal data is transferred outside the UK or EEA (for example, to a US-based cloud provider), we rely on adequacy decisions where they exist, or on UK GDPR-approved Standard Contractual Clauses with additional safeguards.

09

Security

We hold ISO 27001 and SOC 2 Type II certifications. Personal data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Access is role-based and audited; multi-factor authentication is enforced for all employees and contractors handling client data.

10

Changes to this policy

We update this policy when our practices change or when law requires. Material changes will be flagged on this page with a banner for 30 days. The 'Last updated' date at the top reflects the most recent change.

Data protection contact

Email: hello@britonone.co.uk

Data Protection · BritonOne Technology Ltd134 Westbourne TerraceLondon W2 6QBUnited Kingdom

This is one of BritonOne Technology’s published legal and governance documents. The others are linked from the footer on every page.

← Back to home