Legal
Privacy Policy
How Serio Technical Solutions Limited handles personal information about website visitors, prospective customers, customer and supplier contacts, and people who communicate with us.
Last updated: 16 September 2026
1. Who we are
Serio Technical Solutions Limited (“STS”, “we”, “us” or “our”) provides managed IT support, Microsoft 365 services, cloud and infrastructure services, cyber security, hosting and consultancy.
Company number: 16044381. Registered in England and Wales. Registered office: 11 Crawford Close, Tunbridge Wells, TN4 8EU, England.
For privacy enquiries or to exercise your rights, contact contact@seriotechsolutions.com, or write to our registered office marked “Privacy”.
This notice explains our handling of personal information about website visitors, prospective customers, customer and supplier contacts, and people who communicate with us. It also explains our role when we handle information within customer systems.
2. Our role in handling information
For our own enquiries, customer relationship management, billing and business administration, STS normally acts as the data controller: we decide why and how that information is used.
When we host or administer a customer’s systems, databases, files, accounts or backups on that customer’s instructions, we normally act as a data processor. If that customer is itself a processor, STS may act as a sub-processor. The applicable data processing agreement governs that work.
The organisation responsible for the service you use explains its own processing in its privacy notice. This notice does not replace our customers’ privacy notices. The role we perform depends on the actual processing, and neither a contract label nor this notice removes our legal obligations.
3. Information we handle and where it comes from
Depending on your interaction with us, we handle:
- Contact and business details: your name, work email address, telephone number, employer, role, business address and nominated contact preferences.
- Enquiry and correspondence details: service interests, approximate number of users, requirements, messages, meeting notes, proposals and attachments you provide.
- Account and transaction details: contractual contacts, orders, invoices, payment status and communications about your account. Payment information handled by a payment provider is subject to that provider’s processing arrangements.
- Support and technical information: ticket contents, device or account identifiers, diagnostic information, access records and information needed to investigate an issue. Some of this is processed on a customer’s instructions rather than for our own purposes.
- Website and security information: IP addresses, request times, browser/device information and records of errors or suspicious activity, to the extent collected by our configured systems.
- Marketing preferences: permissions, objections and information needed to avoid contacting someone who has opted out.
We receive information directly from you, from your organisation or its authorised representatives, from the systems involved in providing services, and from relevant service providers. Where we obtain business contact information from public sources, referrals or a lead provider, we explain the source and intended use when required.
Please do not put passwords, payment-card details or unnecessary sensitive information in website forms or ordinary email. We will explain the appropriate method when access information is needed.
4. Why we use information
For processing where STS is the controller, our purposes and usual lawful bases are:
| Purpose | Lawful basis and relevant interest |
|---|---|
| Respond to business enquiries and prepare proposals | Our legitimate interest in responding to prospective customers. Where you personally would be party to the contract, steps requested by you before entering that contract may apply. |
| Administer and deliver a contract with an individual, including a sole trader | Performance of that contract where the processing is necessary. |
| Manage a relationship with a corporate customer or supplier and communicate with its staff | Our legitimate interest in providing services and administering business relationships. |
| Maintain invoices and records required by law | Compliance with the applicable tax, accounting or other legal obligation. |
| Protect our website, accounts and services and investigate misuse | Our legitimate interest in maintaining security and preventing fraud and abuse. |
| Manage complaints or legal claims | Our legitimate interest in resolving disputes and establishing, exercising or defending legal rights; compliance with legal obligations where applicable. |
| Send permitted business marketing | Legitimate interests where appropriate and permitted, or consent where required. The separate electronic-marketing rules also apply. |
| Use optional cookies or similar technologies requiring consent | Consent. |
Where we rely on legitimate interests, we consider whether the processing is necessary and the effect on the people concerned. These interests do not automatically override your rights.
We identify information needed to respond to a request or provide a service. If it is not supplied, we may be unable to complete that request. Optional marketing permission is not a condition of buying services.
5. Marketing and your right to object
You can object to our use of your personal information for direct marketing at any time. We will stop that use. Use the unsubscribe method in the message or email contact@seriotechsolutions.com.
A request for a quotation is not, by itself, permission for unrelated marketing. Where the law requires consent to electronic marketing, we obtain it unless a valid statutory exception applies. Different rules apply to corporate subscribers and to sole traders and some partnerships.
If you opt out, we may retain a minimal suppression record to ensure your preference is respected. Essential service or billing communications may still be sent.
6. Who receives information
Where necessary for the purposes described, information may be shared with:
- Suppliers of website hosting, email delivery, communications and business software.
- Support, remote administration, monitoring, security and backup providers used to deliver the relevant service.
- Payment and accounting providers, professional advisers and insurers.
- Authorised personnel and contractors who need access for their work.
- Authorities or other recipients where disclosure is legally required or justified for the protection of legal rights.
- Parties involved in a genuine proposed business transfer, subject to appropriate confidentiality and data protection arrangements.
We use appropriate contractual arrangements with providers processing information on our behalf. Some recipients, such as professional advisers or payment providers, may act as independent controllers for their own purposes.
We do not sell personal information.
7. Hosting and international processing
The locations and providers used depend on the service involved. STS-operated hosting and third-party cloud services are distinct arrangements; a service’s primary storage location does not necessarily establish where support access or other processing occurs.
Where a restricted transfer takes place, we use the mechanism required by applicable UK data protection law. Depending on the destination and recipient, this may be UK adequacy regulations or appropriate contractual safeguards, supported by the required assessment. Contact us for details or a copy of relevant safeguards, with confidential information protected where appropriate.
Locations and authorised sub-processors for customer-hosted information are addressed in the relevant service and data processing arrangements.
8. How long we retain information
We retain information for the purpose for which it is needed and take account of legal requirements, disputes and your rights. Our routine retention arrangements are:
| Record | Retention period or deletion trigger |
|---|---|
| Enquiries that do not become customers | For as long as needed to manage the enquiry after last meaningful contact. |
| Customer relationship and contractual records | For as long as needed after the contract ends, taking account of legal and dispute requirements. |
| Accounting and tax records | As required by applicable accounting and tax rules. |
| Support records held for our own administration | For as long as needed after ticket closure for our own administration; customer-controlled content follows the customer’s instructions. |
| Website and security logs | For as long as needed for security and operations, and longer where needed in connection with an incident. |
| Marketing records | Reviewed periodically and deleted when no longer needed; minimal suppression information retained for as long as needed to respect an objection. |
| Customer data processed on instructions | As specified in the customer’s data processing agreement and documented retention instructions. |
Information relevant to a legal obligation or dispute may need to be retained longer. Where deletion from individual backup copies is not immediately practicable, copies remain protected, are not used for unrelated purposes and expire under the applicable backup cycle.
9. Security
We apply technical and organisational measures appropriate to the information and the risks involved. Access is limited to authorised people who need it for their work. The measures relevant to a contracted service are set out in that service’s security and processing arrangements.
No system can eliminate every security risk. If a personal data breach occurs, we assess it and make notifications required by law and our contractual obligations.
10. Cookies and similar technologies
This website uses technologies needed to provide the pages and features you request, including the contact form. We do not currently use optional analytics or advertising cookies on this site.
Where a technology requires consent, we ask before using it and provide a way to withdraw that consent. Necessary technologies may remain active to provide requested functions. Browser controls may offer additional options, but disabling necessary technologies can affect functionality.
11. Your rights
Depending on the circumstances, you may request access, correction, deletion, restriction of processing or transfer of certain information. You may object to processing based on legitimate interests. Direct-marketing objections are explained separately above.
Where we rely on consent, you can withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
Contact us using the details in section 1. We may need proportionate information to verify your identity. We respond within the applicable statutory timescale, normally one month, and explain any lawful extension, restriction or refusal.
If your request concerns information we hold on a customer’s instructions, we will help direct it to the appropriate organisation and assist that organisation as required.
12. Automated decisions and children
We do not make decisions about individuals based solely on automated processing that produce legal or similarly significant effects.
Our website is intended for business enquiries and is not directed at children. Where customers use our services to process children’s information, that processing is governed by their instructions and the relevant contractual safeguards.
13. Questions and complaints
Please contact contact@seriotechsolutions.com if you have a concern. You also have the right to complain to the Information Commissioner’s Office. Visit ico.org.uk/make-a-complaint for information. You do not have to obtain our permission before contacting the ICO.
14. Changes
We review this notice when our practices change. The current version and its update date are published on this page. Where required, we will draw material changes to your attention before new processing begins.
