We take your privacy seriously. This policy explains what personal information we collect, why we collect it, who we share it with, how long we keep it and the rights you have over it. It is written to meet the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR).
1. Who we are
Use-IT Telecoms is the trading name of Use IT Telecoms Limited, a private limited company registered in England and Wales under company number 15657337. Our registered office is 80-84 High Street, Rishton, Blackburn, Lancashire, BB1 4LA, United Kingdom.
For the personal information described in this policy, we are the controller. That means we decide how and why it is used and we are responsible for looking after it.
If you have any question about this policy or about how we handle your information, please contact us:
- Email: info@useit-telecoms.co.uk (please put "Data protection" in the subject line)
- Telephone: 01254 919133, Monday to Friday, 09:00 to 17:30
- Post: Data Protection, Use IT Telecoms Limited, 80-84 High Street, Rishton, Blackburn, Lancashire, BB1 4LA
2. What this policy covers
This policy applies to personal information about:
- visitors to our website at useit-telecoms.co.uk;
- people who send us an enquiry, request a quote or otherwise get in touch;
- our business customers, and the people who work for them, including anyone with an account on our customer portal;
- users of the telephone, connectivity, mobile and contact centre services we supply; and
- suppliers, partners and other business contacts.
Our website links to other websites, including the website of Use-IT Computers, which is run separately. We are not responsible for how other websites handle personal information, so please read their own privacy policies.
3. Information we collect
Information you give us
- Enquiries. When you use our contact form we collect your name, email address, telephone number (optional), company name (optional), the service you are interested in and your message. We collect similar details when you phone or email us.
- Customer and account details. Names, job titles, business email addresses and telephone numbers of your contacts, billing and delivery addresses, and the details needed to set up your account and services.
- Portal accounts. If you sign in to our customer portal we hold your name, email address, a securely hashed password and your account settings.
- Billing and payment information. Invoices, payment history and, where you pay by Direct Debit or bank transfer, the bank details needed to take or match payment. Direct Debit mandates are set up and managed through GoCardless.
- Support and correspondence. Support tickets, emails, notes of phone calls and anything you choose to tell us when you ask for help.
- Feedback. Your answers if you complete one of our customer satisfaction surveys.
Information created when you use our services
- Service and network data. The telephone numbers, lines, handsets, connections and mobile SIMs assigned to your account, and their configuration.
- Call and usage records. Call detail records such as the numbers dialled and received, the date, time and duration of calls, and data or mobile usage. We use these to bill you, to support you and to meet our legal obligations. We do not listen to or record the content of your calls unless you have asked us to set up call recording for you (see section 11).
- Emergency location data. The address registered to your lines, which is passed to the emergency services when a 999 or 112 call is made.
Information collected automatically
- Technical data. When you visit our website our servers record your IP address, browser type, the pages you request and the date and time of your visit. This is used to deliver the website, keep it secure and investigate faults.
- Cookies. We only use cookies that are strictly necessary for the website to work and to protect it from abuse. We do not use advertising or analytics cookies. See our Cookie Policy for the full list.
- Spam protection. Our contact form uses Cloudflare Turnstile to check that a real person is sending the form. Turnstile processes technical signals from your browser and device to make that check.
Information from other sources
We may receive information about you from your employer (for example when they add you as a contact on their account), from our network and carrier partners when they provide services to you through us, from other communications providers when a number is transferred (ported) to or from us, and from publicly available sources such as Companies House.
4. How we use your information and our lawful basis
Data protection law says we must have a lawful basis for each way we use personal information. The table below sets out what we do and the basis we rely on.
| What we do | Lawful basis |
|---|---|
| Reply to your enquiry, prepare a quote and follow up on it | Our legitimate interests in responding to people who contact us and in winning new business. Where you are acting for yourself, taking steps at your request before entering into a contract. |
| Set up, supply, maintain and support your services, including provisioning, number porting and fault repair | Performance of our contract with you or your organisation, and our legitimate interest in supporting the people who use services on a customer's account. |
| Bill you, take payment, recover debts and keep accounting records | Performance of a contract, legal obligation (tax and accounting law) and our legitimate interest in being paid. |
| Provide and secure the customer portal, including sign in and account management | Performance of a contract and our legitimate interest in keeping accounts secure. |
| Pass your registered address to the emergency services when a 999 or 112 call is made | Legal obligation, and protecting someone's vital interests. |
| Send service messages, such as order updates, planned maintenance and changes to your services | Performance of a contract and our legitimate interests. |
| Ask for feedback and run customer satisfaction surveys | Our legitimate interest in improving our service. |
| Send you information about similar products and services | Our legitimate interests, and consent where the law requires it (see section 5). |
| Run, secure and improve our website, prevent spam and abuse, and detect fraud | Our legitimate interests in running a safe and reliable website and business. |
| Handle complaints and deal with legal claims | Our legitimate interests, and legal obligations under Ofcom's General Conditions. |
| Comply with the law and with lawful requests from regulators, courts, the police and other authorities | Legal obligation. |
Where we rely on legitimate interests, we have balanced our interests against your rights and freedoms. You can ask us for more detail about this, and you have the right to object (see section 10).
We do not make decisions about you based solely on automated processing that have a legal or similarly significant effect on you, and we do not sell your personal information.
5. Marketing
We may send business contacts information about products and services similar to those they have asked about or already use. For individuals and sole traders, we only send marketing emails or texts if you have agreed to receive them or you are an existing customer and have not opted out. We check telephone numbers against the Telephone Preference Service and Corporate Telephone Preference Service before making marketing calls.
You can opt out of marketing at any time by using the unsubscribe link in any marketing email, or by contacting us using the details in section 1. Opting out of marketing does not stop service messages we need to send you about your account.
6. Who we share your information with
We only share personal information where we need to, and we require the organisations we work with to keep it secure and to use it only for the purposes we allow. They include:
- Network and service partners such as 8x8, Evonex, wholesale network operators and mobile networks, who provide the platforms and connections behind our services.
- Hosting and infrastructure providers. Our website and customer portal are hosted on Laravel Cloud, on servers in London, United Kingdom. Cloudflare provides security and performance services, including bot protection and the Turnstile spam check on our contact form.
- Email delivery. Resend sends the emails our systems generate, such as enquiry confirmations, portal notifications and invoices.
- Payment providers. GoCardless collects Direct Debit payments on our behalf. When you set up a Direct Debit, GoCardless processes your name, email address, bank details and payment history, and may use them to prevent fraud. See GoCardless's privacy notice.
- Accounting and IT providers, including our accounting software provider and the developers who build, support and back up our systems.
- Other communications providers when a telephone number is moved to or from us at your request.
- Emergency services, who receive the registered address of a line when an emergency call is made.
- Professional advisers such as our accountants, auditors, insurers and lawyers.
- Regulators and authorities, including Ofcom, the Information Commissioner's Office, HMRC, the police and the courts, where the law requires or allows it.
- A buyer or successor if we sell, transfer or merge all or part of our business, in which case your information may be transferred as part of that transaction.
Our website loads its fonts from Google Fonts. When a page loads, your browser connects to Google's servers, which receive your IP address. Google does not receive any information you enter on our website.
7. International transfers
We store our main systems in the United Kingdom. Some of our suppliers, including Resend, Cloudflare, Google and GoCardless, may process personal information in the United States or other countries outside the UK. When that happens we make sure the transfer is protected by one of the safeguards recognised by UK data protection law, such as a UK adequacy regulation (including the UK Extension to the EU US Data Privacy Framework, where the recipient is certified), or the International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses. You can contact us for more information about the safeguards we use.
8. How long we keep your information
We keep personal information only for as long as we need it for the purposes in this policy, including meeting legal, accounting and reporting requirements. As a guide:
| Information | How long we keep it |
|---|---|
| Enquiries that do not lead to a contract | Up to 2 years after our last contact with you |
| Customer account, contract, billing and payment records | For the life of the contract and 6 years after it ends, to meet tax and accounting law and to deal with any legal claims |
| Call detail and usage records | As long as needed to bill and support you and to meet our legal obligations, and in any event no longer than 6 years |
| Support tickets and correspondence | For the life of the contract and 6 years after it ends |
| Complaint records | 6 years after the complaint is closed |
| Customer portal accounts | Until the account is closed, or earlier if you ask us to remove a user |
| Website server logs | Up to 90 days, unless needed to investigate a security incident |
| Marketing suppression list | Indefinitely, so that we can respect your request not to be contacted |
When information is no longer needed we delete it or anonymise it so that it can no longer identify you. Backups are overwritten on a rolling cycle.
9. Keeping your information secure
We use appropriate technical and organisational measures to protect personal information from loss, misuse and unauthorised access. These include encrypted connections (HTTPS) across our website and portal, hashed passwords, role based access so staff only see what they need for their job, activity logging, regular backups and contractual security commitments from our suppliers. No system can be completely secure, so if we become aware of a breach that affects you, we will tell you and the Information Commissioner's Office where the law requires us to.
10. Your rights
You have the following rights over your personal information. Some of them only apply in certain circumstances.
- Access. You can ask for a copy of the personal information we hold about you.
- Rectification. You can ask us to correct information that is wrong or incomplete.
- Erasure. You can ask us to delete your information where we no longer have a good reason to keep it.
- Restriction. You can ask us to limit how we use your information, for example while we check that it is accurate.
- Objection. You can object to us using your information where we rely on legitimate interests, and you can always object to direct marketing.
- Portability. You can ask us to give you information you provided to us in a structured, commonly used, machine readable format, or to send it to another organisation.
- Withdrawing consent. Where we rely on your consent, you can withdraw it at any time. This does not affect anything we did before you withdrew it.
To use any of these rights, contact us using the details in section 1. We will not charge you in most cases, and we will respond within one month. If your request is complex we may extend this by up to two further months, and we will tell you if we do. We may need to ask you for proof of identity before we act on a request.
11. When we act on behalf of our customers
Some of our services process personal information on behalf of our business customers, for example when a customer uses call recording, voicemail, contact centre or call reporting features for their own staff and callers. In those cases the customer is the controller of that information and we act as their processor, following their instructions under our contract with them. If you have a question about how one of our customers uses your information, please contact that organisation directly.
12. Complaints to the Information Commissioner's Office
If you are unhappy with how we have handled your personal information, please contact us first so that we can try to put it right. You also have the right to complain to the Information Commissioner's Office (ICO), the UK regulator for data protection:
- Website: ico.org.uk/make-a-complaint
- Telephone: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
13. Changes to this policy
We may update this policy from time to time, for example when we change our services or when the law changes. The date at the top of this page shows when it was last updated. If we make a significant change that affects how we use your information, we will let our customers know directly.