Legal
Privacy Policy.
How Puzzle Technology handles personal data
Version 1.0 · Approved 21 September 2026 · download as a PDF
This page and the PDF are the same document, word for word: the page is generated from the PDF rather than written alongside it, and our build refuses to publish a page whose PDF has changed. This page is the one to read — it works with a screen reader, reflows on a phone and takes your own text size, none of which a PDF does well. The PDF is the approved copy and it carries the approval record, and it is what /privacypolicy gives you, so that is the one to keep or print. If you ever find the two disagreeing, tell us at hello@puzzletech.co.uk — and until we have fixed it, the PDF is the version that applies.
1. Who we are
Puzzle Technology Ltd (“Puzzle”, “PuzzleTech”, “we”, “us” or “our”) provides IT support and technology services to businesses.
We are registered in England and Wales under company number 10006894. Our registered office is:
Ground Floor, 1 Avro Court Ermine Business Park Huntingdon PE29 6XS
For questions about this policy, to exercise your data protection rights or to make a privacy complaint, contact:
Email: privacy@puzzletech.co.uk Telephone: 01480 570339 Post: Privacy Contact, Puzzle Technology Ltd, at the address above. ICO registration reference: ZA192040
2. What this policy covers
This policy explains how we collect and use personal information about website visitors, people who contact us, prospective customers, customer contacts and supplier contacts.
It also explains our role when we handle personal information within customers’ IT systems.
When we decide how information is used
We act as a data controller when we decide why and how personal information is used for our own business activities. These include responding to enquiries, managing customer relationships, invoicing, marketing and protecting our own systems.
When we handle information for customers
When we access, host, support, secure or back up personal information on a customer’s instructions, we act as a data processor. If our customer is itself a processor, we may act as its sub-processor.
The organisation responsible for that information decides the purposes of processing and the applicable lawful basis. Its privacy notice explains those uses. Our processing is governed by the relevant service agreement and data processing terms.
The same support request can contain both our own administrative records and information we handle on a customer’s instructions. We apply the appropriate responsibilities to each.
Recruitment and employment information is covered by separate applicant and employee privacy notices.
3. The information we collect and where it comes from
Depending on your relationship with us, we collect:
| Information | Examples and sources |
|---|---|
| Contact and business details | Your name, work email address, telephone number, employer and job title, supplied by you or your organisation. |
| Enquiries and correspondence | Messages, callback requests, meeting notes and communications you send us. |
| Customer and supplier records | Contracts, service requirements, authorised contacts, orders and correspondence supplied during our business relationship. |
| Financial information | Billing details, invoices, payment status and bank details where needed to receive or make payments. |
| Support information | Support requests, troubleshooting notes and relevant technical information supplied by you, your organisation or the systems we support. |
| Website information | IP address, browser and device details, access times and security logs. Cookie and analytics information depends on the technologies used and your choices. |
| Marketing preferences | Subscription choices, consent records, objections and unsubscribe requests. |
When delivering customer services, we may also handle user accounts, device identifiers, system logs, files, email content, backups and information visible during authorised remote support. The information involved depends on the service and the customer’s instructions.
Categories:
B2B B2B Calls B2C
B2C Calls
NB We do not collect child data
Please provide only the information needed for your enquiry. Do not include passwords or sensitive personal information in a general website enquiry.
4. Why we use information and our lawful bases
The following applies where Puzzle acts as a controller.
| Purpose | Lawful basis |
|---|---|
| Responding to business enquiries and arranging discussions | Our legitimate interest in answering requests and developing business relationships. Where you personally would be party to a contract, taking steps at your request before entering that contract. |
| Managing customer and supplier relationships, authorised contacts and service administration | Our legitimate interest in delivering and administering business services. Contract where the agreement is with you personally. |
| Issuing invoices, managing payments and maintaining financial records | Our legitimate interest in managing payments; legal obligation for records required by applicable accounting and tax law; contract where relevant to an agreement with you personally. |
| Protecting our website and business systems, investigating misuse and managing security incidents | Our legitimate interest in protecting information, maintaining service availability and preventing unauthorised activity. Legal obligation where a specific reporting or other statutory duty applies. |
| Handling privacy requests and complaints | Compliance with our data protection obligations. |
| Establishing, exercising or defending legal claims | Our legitimate interest in protecting our legal rights. |
| Sending marketing | Consent where required, or our legitimate interest in promoting relevant business services where the rules permit this. See section 5. |
| Using optional website analytics or tracking technologies | Our legitimate interest in analysing website performance and visitor trends to optimize user experience. Data is collected using privacy-configured Matomo Analytics in a completely cookieless environment, with individual IP addresses automatically anonymised upon collection. |
Where we rely on legitimate interests, we consider the necessity of the use and its effect on your rights and reasonable expectations. You can contact us for more information about that assessment.
We do not rely on a contract with your employer as though it were a contract with you.
If information is needed to answer your request, administer an agreement or meet a legal requirement, we will explain this when collecting it. Without that information, we may be unable to respond or provide the relevant service. Optional marketing consent is not a condition of receiving our services.
5. Marketing and your choices
Where you subscribe to marketing, we use your contact details to send the updates you requested.
Where permitted, we may send relevant business marketing to corporate contacts using legitimate interests. For individuals, sole traders and certain partnerships, we obtain consent unless the existing-customer exception applies. That exception requires us to have obtained the details during a sale or sales discussion, market our own similar services, and offer an opt-out both when collecting the details and in each message.
You can object to direct marketing at any time. We will stop using your personal information for that purpose, including related profiling.
Use the unsubscribe option in a message or contact us using section 1. We retain a limited record of your objection so that you are not added back to our marketing lists.
Service messages, such as information about an active support request or an invoice, are separate from marketing.
6. Cookies and similar technologies
We set no cookies. Our analytics is configured not to, there is no advertising or tag manager, and nothing on this site tracks you across other sites — which is why there is no cookie banner. Our CDN may set a short-lived cookie to tell automated traffic from real visitors; that is a security measure, it identifies no one, and it is not used for analytics or marketing.
7. Who receives personal information
We share relevant information with organisations needed to operate our business and deliver the agreed services. Depending on the activity, these include:
Hosting, cloud, email and business application providers. Support, remote management, cyber-security and backup providers. Telecommunications, software licensing and hardware suppliers. Accounting, banking and payment service providers. Marketing and website service providers, subject to applicable choices. Professional advisers, auditors and insurers. Regulators, courts or public authorities where disclosure is required or otherwise lawful.
If a business sale or restructuring requires disclosure, we limit the information shared and apply appropriate confidentiality safeguards.
Providers processing information on our behalf must act under contractual restrictions and protect it. Some recipients, such as banks or professional advisers, may act as independent controllers.
Where we appoint sub-processors for customer services, we follow the authorisation and information requirements in our customer agreements.
8. International transfers
Where a restricted transfer takes place, we use an applicable lawful transfer mechanism. Depending on the destination and recipient, this can be UK adequacy regulations or appropriate contractual safeguards, such as the UK International Data Transfer Agreement or the UK Addendum to the European Commission’s Standard Contractual Clauses.
Where required, we assess the protection available in the destination and put additional measures in place.
You can contact us using section 1 for information about the safeguards applying to your information and how to obtain a copy, with confidential details redacted where necessary.
9. How long we keep information
In its everyday business operations, Puzzle Technology collects and stores records of many types and in a variety of different formats. Data will have different legal and business requirements which will determine the retention period.
Information security is the preservation of confidentiality, integrity and availability of information. It may also include the authenticity, accountability, non repudiation and reliability of Puzzle Technology’s information depending on circumstances.
Puzzle Technology requires Storage limitation of personal information to be maintained in order to ensure that it is able to rely on its information for its needs and meets its statutory, regulatory and legislative policy obligations.4
For more detail, please contact us for a copy of our complete retention policy quoting document reference 10190 - Puzzle Technology - Retention Policy
10. How we protect information
We use technical and organisational safeguards appropriate to the information and the risks involved. Access is limited to people who need it for their work and who are subject to confidentiality requirements.
We investigate personal information breaches and notify the relevant customer, regulator or affected individuals where required by our role and applicable law.
11. AI, profiling and automated decisions
Puzzle may provide AI related services. Where we configure or support an AI system on a customer’s instructions, the customer’s privacy information should explain its use of personal information and any decisions made using that system.
12. Your rights
Depending on the circumstances, you can:
Ask for access to your personal information and a copy. Ask us to correct inaccurate or incomplete information. Ask us to erase information. Ask us to restrict its use. Object to processing based on legitimate interests. Receive certain information in a portable format where processing is automated and based on consent or a contract with you. Withdraw consent at any time, without affecting the lawfulness of earlier processing. Exercise applicable safeguards concerning significant automated decisions.
Your right to object to direct marketing applies at any time. You do not need to give a reason.
Contact us using section 1. Requests are normally free. We may ask for the minimum additional information necessary to confirm your identity.
We respond without undue delay and normally within one month. Where legally permitted because of complexity or the number of requests, we can extend this by up to two further months and will explain the extension within the initial month. If the law permits a pause while we obtain necessary information, we will explain how this affects your request.
Rights are subject to applicable conditions and exemptions. If we cannot fulfil a request, we will explain why and how you can complain.
Where your request concerns information we process for a customer, contact the organisation responsible for that information. If you contact us, we will help direct your request and assist the customer as required.
13. Complaints
If you are concerned about our use of your information, contact us using section 1.
We will acknowledge your complaint within 30 days, investigate without undue delay, keep you informed and explain the outcome.
You also have the right to complain to the Information Commissioner’s Office, the UK data protection regulator:
Website: ico.org.uk/make-a-complaint
14. Changes to this policy
We update this policy when our activities or relevant requirements change. The date at the top shows when it was last updated.
Where a change materially affects how we use your information, we will bring it to your attention through an appropriate channel. If we intend to use information for a new purpose, we will provide the required privacy information before that use begins and obtain consent where necessary.
Version control Approved by robert.childs@puzzletech.co.uk on 21 Sept 2026.
| Version | Status | Actions | Action by | Date |
|---|---|---|---|---|
| 1.0 | Draft | Initial version. Edited in-app | robert.childs@puzzletech.co.uk | 18 Sept 2026 |
| 1.0 | Draft | Published To ISMS Uploaded | robert.childs@puzzletech.co.uk | 18 Sept 2026 |
| 1.0 | Approved | Reviewed and approved at version 1.0. Reviewed | robert.childs@puzzletech.co.uk | 21 Sept 2026 |