CitiIT Limited takes the privacy of everyone who contacts us, visits this website or engages our services seriously. This notice explains what personal data we collect, why we collect it, what we do with it and the rights you have over it. It is written to meet our obligations under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003.
01 Who we are
CitiIT Limited (“CitiIT”, “we”, “us”, “our”) is a company registered in England and Wales providing IT support, IT consultancy, website design and build, branding and digital services.
- Registered company number: 15811174
- VAT number: 473 5892 49
- Registered office: [REGISTERED OFFICE ADDRESS]
- Trading location: Maidenhead, Berkshire, United Kingdom
- Email: david@dpaul.studio
- ICO registration number: [ICO REGISTRATION NUMBER]
For the personal data described in this notice, CitiIT Limited is the data controller — meaning we decide what data is collected and why. Where we access personal data held within a client’s own systems while delivering IT support, we usually act as a data processor instead; see section 05.
We have not appointed a Data Protection Officer, as we are not required to under Article 37 of the UK GDPR. Data protection queries are handled directly by David Ahern at the email address above.
02 Personal data we collect
We keep data collection to the minimum needed to run the business. Depending on how you interact with us, we may hold:
| Category | Examples | Why we hold it |
|---|---|---|
| Enquiry data | Name, email address, telephone number, company name, and anything you choose to tell us in your message | To respond to your enquiry and provide a quote |
| Client & contract data | Billing address, contact details, purchase orders, service records, support tickets, correspondence | To deliver the services and manage the relationship |
| Financial data | Invoices, payment records, bank transfer references, VAT records | To take payment and meet HMRC and Companies Act obligations |
| Technical data | IP address, browser type and version, device type, operating system, pages viewed, referring site | Security, fault diagnosis and keeping the site working |
| Technical support data | Device names, network configuration, system logs, error reports, remote session records | To diagnose and resolve technical faults |
We do not deliberately collect special category data (such as data about health, ethnicity, religion, political opinions, sex life or sexual orientation) or criminal offence data. Please do not send us this kind of information unless it is genuinely necessary. If special category data reaches us incidentally — for example, because it sits within a mailbox or file server we are supporting — we handle it under our processor obligations and do not use it for any purpose of our own.
03 How we collect it
- Directly from you — when you email us, call us, fill in a form on this site, or engage us to carry out work.
- Automatically — through server logs and cookies when you use this website (see section 06).
- In the course of providing services — through system logs, remote support sessions, backups and configuration data on devices we support.
- From third parties — occasionally from publicly available sources such as Companies House or a company’s own website, and from referrals where someone has passed on your contact details.
04 Our lawful bases for processing
Under Article 6 of the UK GDPR we must have a lawful basis for each use of your personal data. Ours are:
| Purpose | Lawful basis |
|---|---|
| Responding to an enquiry and preparing a quote | Steps taken at your request prior to entering a contract (Art. 6(1)(b)) |
| Delivering the services you have engaged us for | Performance of a contract (Art. 6(1)(b)) |
| Invoicing, accounting and tax records | Legal obligation (Art. 6(1)(c)) |
| Website security, fault diagnosis and abuse prevention | Legitimate interests — keeping our systems secure and available (Art. 6(1)(f)) |
| Contacting existing clients about related services | Legitimate interests — maintaining the client relationship (Art. 6(1)(f)) |
| Non-essential cookies and analytics | Consent (Art. 6(1)(a)), which you may withdraw at any time |
| Defending or bringing a legal claim | Legitimate interests — establishing, exercising or defending legal rights (Art. 6(1)(f)) |
Where we rely on legitimate interests, we have considered whether that interest is overridden by your rights and freedoms, and concluded that it is not. You can ask us to explain that assessment, and you have the right to object — see section 11.
05 Access to client systems — our role as a processor
Providing IT support often means accessing systems that contain personal data belonging to our clients: mailboxes, file shares, CRM records, backups and similar. In that situation the client remains the data controller and CitiIT acts as a data processor on their behalf.
When acting as a processor we commit to the following, in line with Article 28 of the UK GDPR:
- We process personal data only on the client’s documented instructions, unless required to do otherwise by law.
- We access only what is necessary to carry out the task requested.
- Everyone with access is bound by a duty of confidentiality.
- We apply appropriate technical and organisational security measures.
- We do not engage a sub-processor for client data without the client’s prior authorisation.
- We assist the client in responding to data subject requests and in meeting their own security, breach-notification and impact-assessment duties.
- At the end of the engagement we delete or return client data, unless the law requires us to retain it.
- We make available the information needed to demonstrate compliance and submit to reasonable audits.
Business clients engaging us for ongoing support should have a written data processing agreement in place with us. We are happy to provide or sign one on request.
If you are a customer, employee or contact of one of our clients and you have questions about how your data is handled, please contact that organisation in the first instance — they are the controller. We will support them in responding to you.
06 Cookies and tracking
A cookie is a small text file placed on your device by a website. Under the Privacy and Electronic Communications Regulations we may only place non-essential cookies with your consent.
Strictly necessary
These are required for the site to function and are set without consent because you have specifically requested the service. This includes the cookie that records your cookie preferences so we do not ask you again on every page.
Analytics and other non-essential cookies
Any analytics, performance or marketing cookies are set only after you accept them via the consent banner shown on your first visit. If you decline, they are not set. You can change your mind at any time by clearing the cookies for this site in your browser, which will cause the banner to reappear.
Third-party services on this site
- Google Fonts — typefaces are loaded from Google’s servers, which means your IP address is disclosed to Google when a page loads. Google’s privacy notice is at policies.google.com/privacy.
- GitHub Pages — this site is hosted by GitHub, which processes server log data including IP addresses for security and delivery.
- Cloudflare — the optional connection speed check on this site sends test data to Cloudflare’s public speed-test endpoints. It runs only when you click the button and no result is stored by us.
You can block or delete cookies through your browser settings. Doing so may affect how parts of this site behave. Guidance for all major browsers is available at aboutcookies.org.
We do not respond to “Do Not Track” browser signals, as no consistent standard for them currently exists.
07 Who we share data with
We do not sell your personal data, and we never will. We share it only where necessary, with:
- Service providers acting on our instructions — including our website host, email and productivity provider (Google Workspace), form-handling provider, accounting software provider and payment providers. Each is bound by contract to protect your data and use it only as we direct.
- Our accountant and professional advisers — where needed for accounts, tax or legal advice.
- Regulators and authorities — including HMRC, the ICO, law enforcement and the courts, where we are legally required to disclose.
- A buyer or successor — if the business or its assets are sold or restructured, in which case your data would transfer under equivalent protections.
We do not pass your details to third parties for their own marketing purposes.
08 International transfers
Some of the providers we use operate outside the United Kingdom, including in the United States. Where personal data is transferred abroad we make sure one of the following safeguards is in place, as required by Chapter V of the UK GDPR:
- The country has UK adequacy regulations in force; or
- The transfer is covered by the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses together with the UK Addendum; or
- The recipient is certified under the UK Extension to the EU–US Data Privacy Framework.
You can request details of the safeguards applying to a specific transfer by emailing us.
09 How long we keep your data
We keep personal data only for as long as we need it. In practice:
| Data | Retention period |
|---|---|
| Enquiries that do not become work | Up to 12 months from the last contact |
| Client records and correspondence | 6 years from the end of the engagement, matching the limitation period for contract claims under the Limitation Act 1980 |
| Invoices, accounts and VAT records | 6 years from the end of the relevant accounting period, as required by HMRC and the Companies Act 2006 |
| Technical support logs and remote session records | 12 months, unless needed for an ongoing issue |
| Website server logs | As set by our hosting provider, typically no more than 90 days |
| Marketing consents and opt-outs | Until withdrawn; suppression records kept indefinitely so we do not contact you again in error |
When data is no longer needed we delete it securely or anonymise it so it can no longer identify anyone.
10 How we protect your data
As an IT business, security is central to what we do. Our measures include encrypted devices and connections, multi-factor authentication on business accounts, least-privilege access, up-to-date patching and endpoint protection, secure and tested backups, and secure disposal of hardware and records.
No transmission over the internet can be guaranteed completely secure, so any data you send us online is sent at your own risk. Once we receive it, we apply the controls above.
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner’s Office within 72 hours of becoming aware of it, and will tell you directly without undue delay where the risk is high.
11 Your rights
Under the UK GDPR you have the following rights over your personal data:
- Access — to be told whether we hold data about you and to receive a copy of it.
- Rectification — to have inaccurate or incomplete data corrected.
- Erasure — to have your data deleted where there is no good reason for us to keep it.
- Restriction — to ask us to pause processing while a concern is investigated.
- Portability — to receive data you gave us in a structured, commonly used, machine-readable format, or have it sent to another controller.
- Objection — to object to processing based on legitimate interests, and to object to direct marketing at any time, which we will always honour.
- Withdrawal of consent — where we rely on consent, to withdraw it at any time without affecting processing already carried out.
- Automated decision-making — not to be subject to decisions with legal or similarly significant effects made solely by automated means. We do not carry out this kind of processing or any profiling.
To exercise any of these rights, email david@dpaul.studio. There is no charge. We will respond within one month, and will tell you if we need to extend that by up to a further two months because the request is complex. We may ask you for proof of identity before releasing data.
12 Marketing communications
We may send occasional emails about our services to existing clients and to people who have asked to hear from us. Every message includes a way to opt out, and you can also opt out at any time by replying or emailing us. We do not use automated marketing lists or share your details with other advertisers.
13 Children
Our services are aimed at businesses and adults. We do not knowingly collect data about children under 13. If you believe a child has provided us with personal data, contact us and we will delete it.
14 Changes to this notice
We may update this notice to reflect changes in our services, technology or the law. The date at the top shows when it was last revised. Where changes are significant we will make that clear on the site. Please check back from time to time.
15 Contact and complaints
If you have any question about this notice or about how we handle your data, please contact us first — most things are resolved quickly:
- Email: david@dpaul.studio
- Post: Data Protection, CitiIT Limited, [REGISTERED OFFICE ADDRESS]
If you are unhappy with our response, you have the right to complain to the UK supervisory authority for data protection:
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
ico.org.uk/make-a-complaint
We would appreciate the chance to address your concerns before you approach the ICO, but you are entitled to contact them directly at any point.