NetGeniusIT Privacy Notice
Effective date: 11 August 2026
1. Who we are
NetGeniusIT is the trading name of Steven Marshall, a sole proprietor. For the personal information described in this notice, the controller is Steven Marshall trading as NetGeniusIT.
Business contact location: Uffculme, Devon EX15 3BS. Privacy contact: accounts@netgeniusit.co.uk. Existing-customer support: support@netgeniusit.co.uk.
2. Scope of this notice
This notice applies to prospective and current customers, customer staff and authorised users, suppliers, business contacts, website and customer-portal visitors, and people who contact the service desk. It covers enquiries, quotations, contracts, service delivery, managed IT, projects, monitoring, remote support, security, billing, payment administration, complaints and legal compliance.
Applicable data-protection law includes the UK GDPR and Data Protection Act 2018 as amended, including by the Data (Use and Access) Act 2025, and the Privacy and Electronic Communications Regulations where relevant.
3. When we are controller and processor
We are generally an independent controller for our own account management, sales, billing, service administration, security, fraud prevention, legal compliance and business records.
When we handle personal information only on a business customer's documented instructions while supporting that customer's systems, the customer is normally the controller and NetGeniusIT acts as processor. In that situation, the customer's privacy notice also applies and the Data Processing Schedule governs our processing.
4. Personal information we may use
Depending on the relationship and Services, we may use:
- name, organisation, job title, role and authorised-contact details;
- business, service and billing contact details;
- quotation, contract, order, subscription, invoice and payment-status records;
- payment-provider customer, mandate and collection identifiers and statuses, but not raw bank details in Odoo;
- portal account, invitation, authentication, access, session and audit information;
- support tickets, email, call notes, attachments, service history and internal support notes;
- device, user, licence, asset, configuration, monitoring, alert, network and security information;
- IP address, browser and device information, request logs and necessary-cookie information;
- preferences, complaints, rights requests and marketing choices; and
- information needed to investigate misuse, fraud, security events, disputes or legal claims.
5. Sensitive information and credentials
We do not intentionally request special-category or criminal-offence information for ordinary Services. If it is genuinely necessary, we will identify an additional legal condition and safeguards before using it.
Do not place passwords, recovery codes, private keys, API secrets, full payment-card information or raw bank details in ordinary email, support tickets or public forms. Use an approved secure exchange route when we specifically request sensitive access information.
6. Sources of information
We obtain information directly from the person, their employer or organisation, authorised customer administrators and users, systems the customer asks us to support, and approved suppliers used to deliver the Services. We may also receive business contact information from distributors, vendors, professional advisers, payment providers, public authorities or public business sources where necessary and lawful.
We do not infer marketing consent from a public source. Existing opt-outs are preserved during migration between systems.
Where identity, authority, service, billing or payment-administration information is needed to enter into or perform a contract, comply with law, protect an account or provide a requested service, we identify that requirement at collection where it is not already obvious. If required information is not provided, we may be unable to prepare or accept an order, verify authority, create portal access, deliver or support the Service, administer billing or comply with a legal duty. Optional information is identified as optional and is not used to deny an unrelated Service.
7. Enquiries, quotations and onboarding
We use contact and requirement information to respond to an enquiry, prepare and discuss a quotation, verify authority, plan onboarding and take requested steps. Contract or steps before contract apply only where the individual is personally a party or has personally asked us to take those steps. For an employee, officer or other representative of a company or organisation, we normally rely on legitimate interests in responding to and administering the organisation's request and verifying the representative's authority; we do not treat the organisation's contract as a contract with its staff.
8. Customer administration and service delivery
We use account, contact, service, device and communication information to manage the relationship, provide contracted Services, coordinate authorised access, document work, maintain service records and communicate operational information. Contract applies where the individual is personally the customer. For customer staff and authorised users, we normally rely on legitimate interests in delivering and securing the organisation's Services, together with legal obligation where applicable.
9. Support, monitoring and security
We use ticket, configuration, monitoring, alert, log and security information to diagnose issues, provide support, prevent misuse, protect systems, investigate incidents and maintain evidence. The usual lawful bases are contract, legitimate interests and legal obligation. Access is limited to what is reasonably necessary for the authorised purpose.
10. Billing, accounting and debt administration
We use quotation, contract, invoice, payment-status and correspondence records to bill for Services, reconcile payments, manage genuine disputes, keep accounting records and recover undisputed debt. Contract applies where the individual is personally the customer. Legal obligation and legitimate interests normally apply to company contacts, accounting records, payment administration, fraud prevention and recovery of undisputed business debt.
11. Direct Debit administration
Where Direct Debit is offered, authorisation uses the payment provider's secure hosted process. The provider and relevant banking participants use the information required to establish and operate a mandate and collection. We receive operational identifiers, mandate and payment status, notice and reconciliation information. Odoo, support tickets and public website forms must not collect raw bank-account details.
Cancelling a mandate does not itself cancel the underlying Service contract. We may retain mandate and collection status records where necessary for reconciliation, dispute handling and legal records.
12. Purposes and lawful bases
We use personal information only where there is a lawful basis. The principal bases are:
- contract or steps requested before contract, only where the individual is personally a party or has personally requested the pre-contract step, for relevant quotations, orders, onboarding, service delivery, support, portal access, billing and authorised collection;
- legal obligation, for accounting, tax, consumer, data-protection and lawful-disclosure duties;
- legitimate interests, for operating and securing the business, managing relationships, improving Services, preventing fraud or misuse, recovering undisputed business debt, maintaining evidence and establishing or defending legal claims;
- consent, where it is the appropriate basis for optional electronic marketing or non-essential cookies; and
- vital interests, in a genuine emergency where applicable.
Where we rely on legitimate interests, we consider necessity, reasonable expectations and the effect on the person, and do not proceed where rights and freedoms override the interest.
13. Service providers and recipients
We share information only where necessary and lawful. Categories of recipient may include:
- Odoo for CRM, quotations, subscriptions, invoicing, portal and Helpdesk functions;
- Microsoft for business email, identity, collaboration and cloud administration;
- GoCardless and relevant banking participants when Direct Debit is used;
- hosting, backup, monitoring, remote-management, security and support providers used for the purchased Services;
- distributors, vendors, carriers and subcontractors needed to quote or deliver an order;
- professional advisers, insurers, auditors and debt or legal services where appropriate;
- regulators, courts, law enforcement and public authorities where required; and
- a genuine buyer or successor in a business sale or reorganisation, subject to suitable confidentiality and safeguards.
We do not sell personal information.
14. Processor and independent-controller recipients
Some suppliers act as processors on our instructions. Others, such as banks, payment schemes, professional advisers or public authorities, may act as independent controllers for their own legal or operational purposes. Their own privacy information applies to that independent processing.
We select processors that provide appropriate assurances and use written terms addressing confidentiality, security, instructions, sub-processors, assistance, return or deletion and audit information as required by law.
15. International transfers
Some providers may store or access information outside the United Kingdom. Before a restricted transfer, we use an applicable UK adequacy regulation, recognised contractual safeguards or another lawful mechanism, and carry out any required transfer-risk assessment. Information about relevant providers and safeguards is available on reasonable request where disclosure is lawful and does not compromise security.
16. Retention
We retain information according to purpose, legal duties, limitation periods, security needs and data minimisation. Our working schedule is:
- accounting and invoice records: 7 years;
- contracts, Service Orders and material commercial correspondence: contract duration plus 6 years;
- closed support tickets: up to 6 years, shortened where content is unnecessary or disproportionately sensitive;
- security and operational logs: the shortest period appropriate to investigation, assurance and Service requirements;
- unsuccessful or abandoned portal authorisation state: a short operational period for security, replay prevention and troubleshooting;
- marketing choices and suppression records: as long as needed to respect the choice; and
- protected backups: until expiry under the applicable backup cycle.
Legal holds, active disputes and mandatory retention may extend a period. Information is deleted or anonymised when no longer required.
17. Backup copies
Deletion from an active system may not immediately remove every protected backup copy. Backup data is isolated from ordinary use, retained only for the applicable cycle and overwritten or expires according to that cycle, unless restoration or legal preservation is required.
18. Security measures
Measures are selected according to risk and may include access control, role separation, authentication, encryption, supported configuration, patching, malware protection, logging, backup and restoration controls, secure disposal, supplier assessment and incident response. Access is limited to authorised purposes. No internet-connected service can be guaranteed completely secure.
19. Personal data incidents
We investigate suspected loss, misuse, unauthorised access or disclosure and take proportionate containment and recovery action. Where law requires, we notify the relevant controller, the Information Commissioner's Office and affected people within the applicable timeframe. We retain appropriate incident records even where notification is not required.
20. Portal and account security
Portal access is invitation-only for existing customers. Users must protect their account access and tell us promptly if they suspect compromise. We may record authentication, access and security events, limit or disable access, and request identity or authority evidence before a sensitive account action.
21. Cookies and similar technologies
The customer portal uses cookies or similar storage needed for login, session security, preferences and core operation. We do not use non-essential advertising cookies on the portal. Any future non-essential analytics or advertising technology requires a separate assessment and an appropriate consent mechanism before activation.
22. Marketing and service communications
Service, security, billing and contract communications are not marketing. Optional electronic marketing is sent only where a lawful basis exists and includes a simple way to opt out. An opt-out does not stop necessary operational or contractual messages.
23. Automated decisions and artificial intelligence
We do not use personal information to make solely automated decisions that produce legal or similarly significant effects. Automated categorisation, routing, monitoring or security alerts may assist staff, but a person remains responsible for material decisions. Lead enrichment or mining is not used without an approved purpose, lawful source and appropriate notice.
24. Children's information
Our Services are intended for businesses and adults. We do not knowingly offer the customer portal to children or intentionally collect children's information for ordinary Services. If we learn that information was collected inappropriately, we will investigate and delete or restrict it as required.
25. Your rights
Subject to applicable law and exceptions, a person may ask us to:
- provide access to their personal information;
- correct inaccurate or incomplete information;
- delete information;
- restrict processing;
- provide portable information supplied under contract or consent;
- stop processing based on legitimate interests;
- stop direct marketing at any time; or
- record withdrawal of consent for future processing where consent is relied upon.
26. How to exercise a right
Contact accounts@netgeniusit.co.uk and describe the request. We may ask for proportionate evidence of identity and authority, particularly where a request concerns a business account or another person. We normally respond within one month. The law may permit an extension for a complex request or several requests, and may permit refusal or a reasonable fee for a manifestly unfounded or excessive request. We will explain any lawful exception we rely on.
27. Complaints
Raise a data-protection complaint by emailing accounts@netgeniusit.co.uk and describing what concerns you. No special form or legal wording is required. We will acknowledge receipt within 30 days, normally much sooner; make appropriate enquiries without undue delay; keep you informed where an investigation continues; and tell you the outcome. We may ask for proportionate evidence of identity or authority, but will not use that request to obstruct a complaint.
You may also complain to the Information Commissioner's Office at https://ico.org.uk/make-a-complaint/. You do not have to wait for our process where the law permits direct contact with the ICO, and court rights are unaffected.
28. Changes to this notice
We review this notice at least annually and when Services, providers, purposes or law materially change. A material change will be highlighted through the website, portal or direct communication where appropriate. The effective date above identifies the current published version.
29. Further information
You may ask the privacy contact for more information about a lawful basis, legitimate-interest assessment, retention decision, relevant service provider, international-transfer safeguard or our role as controller or processor. We may withhold information where disclosure would compromise security, confidentiality or another person's rights, but will explain the basis where appropriate.