Last updated: 27 November 2025
SDS DELIVER IO LTD – PRIVACY POLICY
This Privacy Policy explains how SDS Deliver IO Ltd (“SDS Deliver IO”, “we”, “us”, “our”) collects, uses and protects personal data in connection with:
- our website https://www.sdsdeliver.io;
- our client portal at https://dashboard.sdsdeliver.io;
- our IT consultancy, managed services and related technology services; and
- our sales, support and marketing activities.
We are a company registered in England and Wales with company number 15321171 and registered office at 91A Church Lane, Bulphan, Upminster, England, RM14 3TR.
For UK data protection purposes, SDS Deliver IO Ltd is the “data controller” for personal data described in this notice.
This policy is mainly aimed at business contacts: visitors to our sites, prospective customers, existing customers, suppliers and partners. It does not cover our employees or contractors, who receive a separate privacy notice. It also does not cover personal data we process purely as a processor on behalf of our customers in their own environments; that is governed by our contracts and the customer’s own privacy notices.
1. Data we collect
We collect and process personal data in several ways.
1.1 Information you give us
You may give us personal data when you:
- fill in forms on our Site or hub (for example, “Contact us” or “Get started” forms);
- book a call, request a proposal or subscribe to updates;
- enter into a contract with us or manage an ongoing engagement;
- correspond with us by email, phone, video call or messaging tools;
- engage with us via social media (LinkedIn, Instagram, etc.).
This data typically includes:
- Identity data – name, job title, role, organisation.
- Contact data – business email address, phone number, company domain, postal address.
- Business context data – information about your company, systems, requirements, projects, budgets and timelines.
- Account and contract data – proposals, SOWs, contracts, subscription details, billing contact details.
- Support data – information provided in tickets, change requests, incident reports or feedback.
- Marketing preferences – your choices about receiving updates and marketing from us.
Where you use Stripe checkout or similar, limited payment details are collected (card type, last four digits, expiry date, billing address) but full card details are handled by Stripe and not stored by us.
We do not intentionally collect special categories of data (such as health, religion or biometric data) or data about criminal convictions through our Site or normal service channels.
1.2 Information we collect automatically
When you visit our Site or hub, we automatically collect certain technical data, for example:
- IP address and approximate location;
- browser type and version;
- device type and operating system;
- pages viewed, time on page, navigation paths;
- referring URL and interaction with the site.
This is collected via standard web server logs and technologies like cookies and similar tracking technologies. See section 6 – Cookies & tracking.
1.3 Information from third parties
We may receive personal data about you from:
- your colleagues or other contacts who make introductions or list you as a project contact;
- public sources such as LinkedIn and your company website;
- referral partners and other service providers;
- our payment providers (e.g. Stripe – confirmation of payment and limited card metadata);
- our CRM, analytics and email service providers.
We only use this data where it is relevant to our relationship with you and in line with this policy.
2. How we use your data and legal bases
Under the UK GDPR we must tell you both what we do with your data and the legal basis we rely on.
2.1 Purposes and legal bases
We use personal data for the following purposes:
- Providing our services and running projects
- To discuss your requirements, prepare proposals, enter into contracts and deliver IT consultancy, DevOps and managed services.
- Legal basis: performance of a contract or taking steps at your request before entering into a contract (UK GDPR Art. 6(1)(b)); and our legitimate interests in running and growing our business (Art. 6(1)(f)).
- Operating and improving our sites and services
- To operate, secure and troubleshoot our websites, hub and service tooling; to analyse usage and improve performance and UX.
- Legal basis: our legitimate interests in running a secure and effective online presence and services (Art. 6(1)(f)).
- Customer support and communications
- To respond to enquiries, support requests and incidents; to send service-related messages (e.g. changes, outages, security notices).
- Legal basis: performance of a contract (Art. 6(1)(b)) and our legitimate interests in providing good customer service (Art. 6(1)(f)).
- Business operations, finance and compliance
- To manage billing, payments, accounting, audits and legal claims; to comply with legal obligations (e.g. tax, accounting and data protection).
- Legal basis: compliance with legal obligations (Art. 6(1)(c)) and our legitimate interests in effective business administration and risk management (Art. 6(1)(f)).
- Sales, relationship management and B2B marketing
- To follow up on enquiries, send relevant content to existing or prospective business customers, invite you to webinars or events, and maintain CRM records.
- Legal basis: our legitimate interests in promoting and growing our business (Art. 6(1)(f)), and where required by electronic marketing laws, your consent. We comply with applicable e-privacy rules (e.g. PECR) for email/SMS marketing.
- Security, fraud prevention and abuse prevention
- To monitor and protect our environments, investigate suspicious activity, misuse or attempts to compromise systems.
- Legal basis: our legitimate interests in maintaining the security and integrity of our systems and protecting our customers and business (Art. 6(1)(f)).
Where we rely on legitimate interests, we balance our interests against your rights and expectations and only proceed where we believe our processing is proportionate and reasonable.
Where we rely on consent, you can withdraw that consent at any time using unsubscribe links or by contacting us; this will not affect processing carried out before you withdrew consent.
We do not carry out automated decision-making that produces legal or similarly significant effects on individuals.
3. How we share personal data
We share personal data only as necessary, on a need-to-know basis:
3.1 Service providers (processors)
We use trusted third-party service providers to help us deliver our services and run our business, for example:
- website and application hosting and content delivery;
- analytics and monitoring;
- CRM and customer support platforms;
- email and communications tools;
- payment processing (e.g. Stripe);
- professional advisors (accountants, lawyers, auditors).
These providers act as data processors and may only process personal data in line with our instructions, under contract, and with appropriate security measures.
3.2 Other disclosures
We may also share personal data:
- with your organisation where you are a business contact, for example to coordinate work, reporting and billing;
- with professional advisers (lawyers, accountants, insurers) where reasonably necessary;
- with authorities or regulators where required by law or reasonably necessary to protect our rights, customers or others;
- in connection with a business transaction, such as a merger, acquisition or sale of some or all of our assets, subject to appropriate confidentiality protections.
We do not sell personal data.
4. International transfers
We are based in the UK. Some of our service providers or their sub-processors may be located outside the UK and the European Economic Area (EEA). Where personal data is transferred internationally, we will ensure that appropriate safeguards are in place, such as:
- an adequacy regulation for the destination country; or
- approved Standard Contractual Clauses or equivalent contractual protections.
You can contact us for more information about specific international transfers relevant to you.
5. Data retention
We keep personal data only for as long as reasonably necessary for the purposes described in this policy, including to meet legal, accounting and reporting requirements.
Broadly:
- Contract and billing records – normally kept for up to 7 years after the end of the relevant financial year or customer relationship (to comply with tax and accounting rules and to handle potential legal claims).
- General enquiries and pre-sales correspondence – usually kept for up to 2 years from last meaningful contact.
- Support and operational records – retained for the duration of the relevant service and for a period afterwards where needed for audit, troubleshooting or legal purposes.
- Marketing contacts – kept until you opt out or we reasonably determine that you are no longer actively engaged, at which point we will suppress or delete your details in line with our retention rules.
Where data is kept beyond its active use (for example, in backups), it will be securely stored with restricted access and deleted in line with our backup retention cycles.
6. Cookies & tracking
Our sites use cookies and similar technologies to:
- make the sites work (for example, load balancing, security and session management);
- remember certain preferences;
- understand how visitors use our content so we can improve it.
Cookies and similar technologies may be set by us (“first-party cookies”) or by third parties providing services to us (for example, analytics providers).
Where required by law, we will ask for your consent before setting non-essential cookies (for example, analytics tags). You can:
- use your browser settings to refuse or delete cookies; and
- use any consent management tools we provide on our sites to adjust your cookie preferences.
Blocking some types of cookies may impact your experience or some features of the site.
7. Security
We take appropriate technical and organisational measures to protect personal data, including:
- access controls and least-privilege principles;
- security monitoring and logging;
- encryption in transit (and at rest where appropriate);
- vulnerability management and patching;
- internal policies and awareness around information security and data protection.
However, no system or transmission is completely secure. We cannot guarantee absolute security of your data, but we aim to keep risk proportionate and under active management.
Where we become aware of a personal data breach that is likely to result in a risk to individuals’ rights and freedoms, we will act in line with our legal obligations, which may include notifying you and/or the ICO.
8. Your data protection rights
Under UK data protection law, you have certain rights in relation to your personal data.
Subject to conditions and exceptions, these include:
- Right of access – to obtain confirmation that we process your personal data and a copy of that data.
- Right to rectification – to have inaccurate or incomplete personal data corrected.
- Right to erasure – to request deletion of your personal data in certain circumstances (for example, where it is no longer needed for the original purpose and we have no overriding legitimate reason to keep it).
- Right to restriction – to ask us to suspend processing of your data in certain cases.
- Right to data portability – to receive personal data you provided to us in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible and where the legal basis is consent or contract.
- Right to object – to object to processing based on legitimate interests, and always to object to direct marketing.
- Rights in relation to automated decision-making – where applicable, to request human intervention, express your view and contest decisions.
Where our processing is based on consent, you have the right to withdraw that consent at any time.
Some of these rights are not absolute and only apply in certain circumstances. We will explain clearly if we believe an exemption applies.
To exercise any of these rights, contact us using the details in section 9.
9. How to contact us
For any questions about this Privacy Policy or how we handle personal data, or to exercise your rights, you can contact us by:
- writing to:
SDS Deliver IO Ltd
91A Church Lane
Bulphan, Upminster
England
RM14 3TR - emailing [email protected]
- using the contact form on our website at: https://www.sdsdeliver.io/#contact
You can also contact us using any email address or phone number published from time to time on our Site or client portal.
We have not appointed a formal Data Protection Officer as we are not currently required to do so, but we take data protection seriously and aim to respond promptly and transparently to privacy-related queries.
10. Complaints
If you are unhappy with how we handle your personal data, please contact us first; we would like the opportunity to resolve your concerns.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline: 0303 123 1113
Website: https://www.ico.org.uk
11. Third-party links
Our sites may contain links to third-party websites, services or platforms (for example, partner sites or social media). If you follow these links, please note that those sites have their own privacy policies and we do not control, and are not responsible for, how they handle personal data.
12. Changes to this policy
We may update this Privacy Policy from time to time, for example to reflect changes in law, guidance or how we operate.
When we make changes, we will update the “Last updated” date at the top of this page and, where appropriate, notify you by email or via our sites.
Your continued use of our sites or services after any update takes effect will be treated as acceptance of the revised policy.