CitiIT
  • Home
  • Pricing
  • Branding/Logos
  • IT Services
  • Web Design
  • Portfolio
  • Contact
  • Privacy
  • Terms
PRIVACY POLICY
01
Legal & Compliance
PRIVACY
POLICY
Last updated: 2 September 2026
CitiIT Limited · Company No. 15811174 · VAT No. 473 5892 49
Contents
01   Who we are 02   Data we collect 03   How we collect it 04   Lawful bases 05   Access to client systems 06   Cookies & tracking 07   Who we share with 08   International transfers 09   How long we keep it 10   Security 11   Your rights 12   Marketing 13   Children 14   Changes 15   Contact & complaints

CitiIT Limited takes the privacy of everyone who contacts us, visits this website or engages our services seriously. This notice explains what personal data we collect, why we collect it, what we do with it and the rights you have over it. It is written to meet our obligations under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003.

01 Who we are

CitiIT Limited (“CitiIT”, “we”, “us”, “our”) is a company registered in England and Wales providing IT support, IT consultancy, website design and build, branding and digital services.

  • Registered company number: 15811174
  • VAT number: 473 5892 49
  • Registered office: [REGISTERED OFFICE ADDRESS]
  • Trading location: Maidenhead, Berkshire, United Kingdom
  • Email: david@dpaul.studio
  • ICO registration number: [ICO REGISTRATION NUMBER]

For the personal data described in this notice, CitiIT Limited is the data controller — meaning we decide what data is collected and why. Where we access personal data held within a client’s own systems while delivering IT support, we usually act as a data processor instead; see section 05.

We have not appointed a Data Protection Officer, as we are not required to under Article 37 of the UK GDPR. Data protection queries are handled directly by David Ahern at the email address above.

02 Personal data we collect

We keep data collection to the minimum needed to run the business. Depending on how you interact with us, we may hold:

CategoryExamplesWhy we hold it
Enquiry data Name, email address, telephone number, company name, and anything you choose to tell us in your message To respond to your enquiry and provide a quote
Client & contract data Billing address, contact details, purchase orders, service records, support tickets, correspondence To deliver the services and manage the relationship
Financial data Invoices, payment records, bank transfer references, VAT records To take payment and meet HMRC and Companies Act obligations
Technical data IP address, browser type and version, device type, operating system, pages viewed, referring site Security, fault diagnosis and keeping the site working
Technical support data Device names, network configuration, system logs, error reports, remote session records To diagnose and resolve technical faults

We do not deliberately collect special category data (such as data about health, ethnicity, religion, political opinions, sex life or sexual orientation) or criminal offence data. Please do not send us this kind of information unless it is genuinely necessary. If special category data reaches us incidentally — for example, because it sits within a mailbox or file server we are supporting — we handle it under our processor obligations and do not use it for any purpose of our own.

03 How we collect it

  • Directly from you — when you email us, call us, fill in a form on this site, or engage us to carry out work.
  • Automatically — through server logs and cookies when you use this website (see section 06).
  • In the course of providing services — through system logs, remote support sessions, backups and configuration data on devices we support.
  • From third parties — occasionally from publicly available sources such as Companies House or a company’s own website, and from referrals where someone has passed on your contact details.

04 Our lawful bases for processing

Under Article 6 of the UK GDPR we must have a lawful basis for each use of your personal data. Ours are:

PurposeLawful basis
Responding to an enquiry and preparing a quoteSteps taken at your request prior to entering a contract (Art. 6(1)(b))
Delivering the services you have engaged us forPerformance of a contract (Art. 6(1)(b))
Invoicing, accounting and tax recordsLegal obligation (Art. 6(1)(c))
Website security, fault diagnosis and abuse preventionLegitimate interests — keeping our systems secure and available (Art. 6(1)(f))
Contacting existing clients about related servicesLegitimate interests — maintaining the client relationship (Art. 6(1)(f))
Non-essential cookies and analyticsConsent (Art. 6(1)(a)), which you may withdraw at any time
Defending or bringing a legal claimLegitimate interests — establishing, exercising or defending legal rights (Art. 6(1)(f))

Where we rely on legitimate interests, we have considered whether that interest is overridden by your rights and freedoms, and concluded that it is not. You can ask us to explain that assessment, and you have the right to object — see section 11.

05 Access to client systems — our role as a processor

Providing IT support often means accessing systems that contain personal data belonging to our clients: mailboxes, file shares, CRM records, backups and similar. In that situation the client remains the data controller and CitiIT acts as a data processor on their behalf.

When acting as a processor we commit to the following, in line with Article 28 of the UK GDPR:

  • We process personal data only on the client’s documented instructions, unless required to do otherwise by law.
  • We access only what is necessary to carry out the task requested.
  • Everyone with access is bound by a duty of confidentiality.
  • We apply appropriate technical and organisational security measures.
  • We do not engage a sub-processor for client data without the client’s prior authorisation.
  • We assist the client in responding to data subject requests and in meeting their own security, breach-notification and impact-assessment duties.
  • At the end of the engagement we delete or return client data, unless the law requires us to retain it.
  • We make available the information needed to demonstrate compliance and submit to reasonable audits.

Business clients engaging us for ongoing support should have a written data processing agreement in place with us. We are happy to provide or sign one on request.

If you are a customer, employee or contact of one of our clients and you have questions about how your data is handled, please contact that organisation in the first instance — they are the controller. We will support them in responding to you.

06 Cookies and tracking

A cookie is a small text file placed on your device by a website. Under the Privacy and Electronic Communications Regulations we may only place non-essential cookies with your consent.

Strictly necessary

These are required for the site to function and are set without consent because you have specifically requested the service. This includes the cookie that records your cookie preferences so we do not ask you again on every page.

Analytics and other non-essential cookies

Any analytics, performance or marketing cookies are set only after you accept them via the consent banner shown on your first visit. If you decline, they are not set. You can change your mind at any time by clearing the cookies for this site in your browser, which will cause the banner to reappear.

Third-party services on this site

  • Google Fonts — typefaces are loaded from Google’s servers, which means your IP address is disclosed to Google when a page loads. Google’s privacy notice is at policies.google.com/privacy.
  • GitHub Pages — this site is hosted by GitHub, which processes server log data including IP addresses for security and delivery.
  • Cloudflare — the optional connection speed check on this site sends test data to Cloudflare’s public speed-test endpoints. It runs only when you click the button and no result is stored by us.

You can block or delete cookies through your browser settings. Doing so may affect how parts of this site behave. Guidance for all major browsers is available at aboutcookies.org.

We do not respond to “Do Not Track” browser signals, as no consistent standard for them currently exists.

07 Who we share data with

We do not sell your personal data, and we never will. We share it only where necessary, with:

  • Service providers acting on our instructions — including our website host, email and productivity provider (Google Workspace), form-handling provider, accounting software provider and payment providers. Each is bound by contract to protect your data and use it only as we direct.
  • Our accountant and professional advisers — where needed for accounts, tax or legal advice.
  • Regulators and authorities — including HMRC, the ICO, law enforcement and the courts, where we are legally required to disclose.
  • A buyer or successor — if the business or its assets are sold or restructured, in which case your data would transfer under equivalent protections.

We do not pass your details to third parties for their own marketing purposes.

08 International transfers

Some of the providers we use operate outside the United Kingdom, including in the United States. Where personal data is transferred abroad we make sure one of the following safeguards is in place, as required by Chapter V of the UK GDPR:

  • The country has UK adequacy regulations in force; or
  • The transfer is covered by the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses together with the UK Addendum; or
  • The recipient is certified under the UK Extension to the EU–US Data Privacy Framework.

You can request details of the safeguards applying to a specific transfer by emailing us.

09 How long we keep your data

We keep personal data only for as long as we need it. In practice:

DataRetention period
Enquiries that do not become workUp to 12 months from the last contact
Client records and correspondence6 years from the end of the engagement, matching the limitation period for contract claims under the Limitation Act 1980
Invoices, accounts and VAT records6 years from the end of the relevant accounting period, as required by HMRC and the Companies Act 2006
Technical support logs and remote session records12 months, unless needed for an ongoing issue
Website server logsAs set by our hosting provider, typically no more than 90 days
Marketing consents and opt-outsUntil withdrawn; suppression records kept indefinitely so we do not contact you again in error

When data is no longer needed we delete it securely or anonymise it so it can no longer identify anyone.

10 How we protect your data

As an IT business, security is central to what we do. Our measures include encrypted devices and connections, multi-factor authentication on business accounts, least-privilege access, up-to-date patching and endpoint protection, secure and tested backups, and secure disposal of hardware and records.

No transmission over the internet can be guaranteed completely secure, so any data you send us online is sent at your own risk. Once we receive it, we apply the controls above.

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner’s Office within 72 hours of becoming aware of it, and will tell you directly without undue delay where the risk is high.

11 Your rights

Under the UK GDPR you have the following rights over your personal data:

  • Access — to be told whether we hold data about you and to receive a copy of it.
  • Rectification — to have inaccurate or incomplete data corrected.
  • Erasure — to have your data deleted where there is no good reason for us to keep it.
  • Restriction — to ask us to pause processing while a concern is investigated.
  • Portability — to receive data you gave us in a structured, commonly used, machine-readable format, or have it sent to another controller.
  • Objection — to object to processing based on legitimate interests, and to object to direct marketing at any time, which we will always honour.
  • Withdrawal of consent — where we rely on consent, to withdraw it at any time without affecting processing already carried out.
  • Automated decision-making — not to be subject to decisions with legal or similarly significant effects made solely by automated means. We do not carry out this kind of processing or any profiling.

To exercise any of these rights, email david@dpaul.studio. There is no charge. We will respond within one month, and will tell you if we need to extend that by up to a further two months because the request is complex. We may ask you for proof of identity before releasing data.

12 Marketing communications

We may send occasional emails about our services to existing clients and to people who have asked to hear from us. Every message includes a way to opt out, and you can also opt out at any time by replying or emailing us. We do not use automated marketing lists or share your details with other advertisers.

13 Children

Our services are aimed at businesses and adults. We do not knowingly collect data about children under 13. If you believe a child has provided us with personal data, contact us and we will delete it.

14 Changes to this notice

We may update this notice to reflect changes in our services, technology or the law. The date at the top shows when it was last revised. Where changes are significant we will make that clear on the site. Please check back from time to time.

15 Contact and complaints

If you have any question about this notice or about how we handle your data, please contact us first — most things are resolved quickly:

  • Email: david@dpaul.studio
  • Post: Data Protection, CitiIT Limited, [REGISTERED OFFICE ADDRESS]
Your right to complain

If you are unhappy with our response, you have the right to complain to the UK supervisory authority for data protection:

Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
ico.org.uk/make-a-complaint

We would appreciate the chance to address your concerns before you approach the ICO, but you are entitled to contact them directly at any point.

Read our Terms & Conditions →

CitiIT
© 2026 CitiIT Limited. Registered Company No. 15811174. VAT No. 473 5892 49.
Privacy  ·  Terms  ·  citiit.uk  ·  Maidenhead, Berkshire