Last updated: 27 November 2025

SDS DELIVER IO LTD – PRIVACY POLICY

This Privacy Policy explains how SDS Deliver IO Ltd (“SDS Deliver IO”, “we”, “us”, “our”) collects, uses and protects personal data in connection with:

We are a company registered in England and Wales with company number 15321171 and registered office at 91A Church Lane, Bulphan, Upminster, England, RM14 3TR.

For UK data protection purposes, SDS Deliver IO Ltd is the “data controller” for personal data described in this notice.

This policy is mainly aimed at business contacts: visitors to our sites, prospective customers, existing customers, suppliers and partners. It does not cover our employees or contractors, who receive a separate privacy notice. It also does not cover personal data we process purely as a processor on behalf of our customers in their own environments; that is governed by our contracts and the customer’s own privacy notices.

1. Data we collect

We collect and process personal data in several ways.

1.1 Information you give us

You may give us personal data when you:

This data typically includes:

Where you use Stripe checkout or similar, limited payment details are collected (card type, last four digits, expiry date, billing address) but full card details are handled by Stripe and not stored by us.

We do not intentionally collect special categories of data (such as health, religion or biometric data) or data about criminal convictions through our Site or normal service channels.

1.2 Information we collect automatically

When you visit our Site or hub, we automatically collect certain technical data, for example:

This is collected via standard web server logs and technologies like cookies and similar tracking technologies. See section 6 – Cookies & tracking.

1.3 Information from third parties

We may receive personal data about you from:

We only use this data where it is relevant to our relationship with you and in line with this policy.

2. How we use your data and legal bases

Under the UK GDPR we must tell you both what we do with your data and the legal basis we rely on.

2.1 Purposes and legal bases

We use personal data for the following purposes:

  1. Providing our services and running projects
    • To discuss your requirements, prepare proposals, enter into contracts and deliver IT consultancy, DevOps and managed services.
    • Legal basis: performance of a contract or taking steps at your request before entering into a contract (UK GDPR Art. 6(1)(b)); and our legitimate interests in running and growing our business (Art. 6(1)(f)).
  2. Operating and improving our sites and services
    • To operate, secure and troubleshoot our websites, hub and service tooling; to analyse usage and improve performance and UX.
    • Legal basis: our legitimate interests in running a secure and effective online presence and services (Art. 6(1)(f)).
  3. Customer support and communications
    • To respond to enquiries, support requests and incidents; to send service-related messages (e.g. changes, outages, security notices).
    • Legal basis: performance of a contract (Art. 6(1)(b)) and our legitimate interests in providing good customer service (Art. 6(1)(f)).
  4. Business operations, finance and compliance
    • To manage billing, payments, accounting, audits and legal claims; to comply with legal obligations (e.g. tax, accounting and data protection).
    • Legal basis: compliance with legal obligations (Art. 6(1)(c)) and our legitimate interests in effective business administration and risk management (Art. 6(1)(f)).
  5. Sales, relationship management and B2B marketing
    • To follow up on enquiries, send relevant content to existing or prospective business customers, invite you to webinars or events, and maintain CRM records.
    • Legal basis: our legitimate interests in promoting and growing our business (Art. 6(1)(f)), and where required by electronic marketing laws, your consent. We comply with applicable e-privacy rules (e.g. PECR) for email/SMS marketing.
  6. Security, fraud prevention and abuse prevention
    • To monitor and protect our environments, investigate suspicious activity, misuse or attempts to compromise systems.
    • Legal basis: our legitimate interests in maintaining the security and integrity of our systems and protecting our customers and business (Art. 6(1)(f)).

Where we rely on legitimate interests, we balance our interests against your rights and expectations and only proceed where we believe our processing is proportionate and reasonable.

Where we rely on consent, you can withdraw that consent at any time using unsubscribe links or by contacting us; this will not affect processing carried out before you withdrew consent.

We do not carry out automated decision-making that produces legal or similarly significant effects on individuals.

3. How we share personal data

We share personal data only as necessary, on a need-to-know basis:

3.1 Service providers (processors)

We use trusted third-party service providers to help us deliver our services and run our business, for example:

These providers act as data processors and may only process personal data in line with our instructions, under contract, and with appropriate security measures.

3.2 Other disclosures

We may also share personal data:

We do not sell personal data.

4. International transfers

We are based in the UK. Some of our service providers or their sub-processors may be located outside the UK and the European Economic Area (EEA). Where personal data is transferred internationally, we will ensure that appropriate safeguards are in place, such as:

You can contact us for more information about specific international transfers relevant to you.

5. Data retention

We keep personal data only for as long as reasonably necessary for the purposes described in this policy, including to meet legal, accounting and reporting requirements.

Broadly:

Where data is kept beyond its active use (for example, in backups), it will be securely stored with restricted access and deleted in line with our backup retention cycles.

6. Cookies & tracking

Our sites use cookies and similar technologies to:

Cookies and similar technologies may be set by us (“first-party cookies”) or by third parties providing services to us (for example, analytics providers).

Where required by law, we will ask for your consent before setting non-essential cookies (for example, analytics tags). You can:

Blocking some types of cookies may impact your experience or some features of the site.

7. Security

We take appropriate technical and organisational measures to protect personal data, including:

However, no system or transmission is completely secure. We cannot guarantee absolute security of your data, but we aim to keep risk proportionate and under active management.

Where we become aware of a personal data breach that is likely to result in a risk to individuals’ rights and freedoms, we will act in line with our legal obligations, which may include notifying you and/or the ICO.

8. Your data protection rights

Under UK data protection law, you have certain rights in relation to your personal data.

Subject to conditions and exceptions, these include:

Where our processing is based on consent, you have the right to withdraw that consent at any time.

Some of these rights are not absolute and only apply in certain circumstances. We will explain clearly if we believe an exemption applies.

To exercise any of these rights, contact us using the details in section 9.

9. How to contact us

For any questions about this Privacy Policy or how we handle personal data, or to exercise your rights, you can contact us by:

You can also contact us using any email address or phone number published from time to time on our Site or client portal.

We have not appointed a formal Data Protection Officer as we are not currently required to do so, but we take data protection seriously and aim to respond promptly and transparently to privacy-related queries.

10. Complaints

If you are unhappy with how we handle your personal data, please contact us first; we would like the opportunity to resolve your concerns.

You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection:

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Helpline: 0303 123 1113
Website: https://www.ico.org.uk

11. Third-party links

Our sites may contain links to third-party websites, services or platforms (for example, partner sites or social media). If you follow these links, please note that those sites have their own privacy policies and we do not control, and are not responsible for, how they handle personal data.

12. Changes to this policy

We may update this Privacy Policy from time to time, for example to reflect changes in law, guidance or how we operate.

When we make changes, we will update the “Last updated” date at the top of this page and, where appropriate, notify you by email or via our sites.

Your continued use of our sites or services after any update takes effect will be treated as acceptance of the revised policy.