Who we are
BritonOne Technology Ltd is a private limited company incorporated in England and Wales. Our registered office is at 134 Westbourne Terrace, London W2 6QB, United Kingdom.
We are registered with the Information Commissioner's Office (ICO) as a data controller and as a data processor (when operating inside client cloud accounts on engagements). Our ICO registration reference is available on request.
Information we collect
We collect personal data in three contexts: (1) when you contact us via this website or by email; (2) when you become a client, supplier, or candidate; and (3) when you visit our website.
Contact and enquiry data
When you submit our contact form, send us an email, or reach out via LinkedIn, we collect name, work email, company, role, country, industry, and the content of your message.
Client and supplier data
For active engagements we collect contracting-party data necessary for the master services agreement and statements of work, including registered company name, registered address, billing contact, and named technical points of contact.
Candidate and engineer data
For our hiring process we collect CV data, references, right-to-work documentation, and background-check evidence (BS7858 standard). Successful candidates also provide payroll, tax, and emergency-contact information.
Website telemetry
We collect basic visit telemetry (page views, referrer, country-level location, device class) via privacy-aware analytics. We do not use third-party advertising cookies on this website.
How we use information
We use personal data only for the purpose for which it was collected, plus a narrow set of legitimate-interest uses listed below.
- To respond to your enquiry and engage in pre-contract discussion.
- To deliver contracted services, including team mobilisation and billing.
- To meet our legal and regulatory obligations (tax, employment, ICO registration).
- To improve our website and content based on aggregate telemetry.
- To screen and recruit BritonOne Technology engineers and operate payroll.
Lawful basis for processing
We rely on the following lawful bases under UK GDPR Article 6, depending on the processing context:
- Contract (Article 6(1)(b)): for processing necessary to perform an engagement or take pre-contract steps at your request.
- Legitimate interest (Article 6(1)(f)): for ordinary business correspondence, internal recruiting, and analytics.
- Legal obligation (Article 6(1)(c)): for tax, employment, anti-money-laundering, and KYC processing.
- Consent (Article 6(1)(a)): only where you have explicitly opted in (for example, marketing communications).
Data retention
We retain personal data only as long as necessary for the purpose for which it was collected, or as required by law. Standard retention periods are:
- Enquiry data: 24 months from last contact, then deletion.
- Client engagement data: duration of the engagement plus seven years (UK statute of limitations).
- Candidate data (unsuccessful): 12 months from last interview, with consent for longer-term retention.
- Employee data: duration of employment plus six years.
- Website telemetry: aggregated and retained for 26 months.
Your rights
Under UK GDPR you have the right to access, rectify, erase, restrict, port, and object to processing of your personal data. You also have the right to withdraw consent at any time where we rely on consent as the lawful basis.
To exercise any of these rights, email our Data Protection contact below. We will respond within one calendar month, with no charge for ordinary requests. If you are unhappy with our handling, you have the right to lodge a complaint with the ICO (ico.org.uk).
International transfers
We primarily operate inside the UK and EU. Where personal data is transferred outside the UK or EEA (for example, to a US-based cloud provider), we rely on adequacy decisions where they exist, or on UK GDPR-approved Standard Contractual Clauses with additional safeguards.
Security
We hold ISO 27001 and SOC 2 Type II certifications. Personal data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Access is role-based and audited; multi-factor authentication is enforced for all employees and contractors handling client data.
Changes to this policy
We update this policy when our practices change or when law requires. Material changes will be flagged on this page with a banner for 30 days. The 'Last updated' date at the top reflects the most recent change.
Email: hello@britonone.co.uk
Data Protection · BritonOne Technology Ltd134 Westbourne TerraceLondon W2 6QBUnited Kingdom