How we collect, use, store, share and protect personal information in connection with our website, services and business activities.
This policy explains how Tcobots collects, uses, stores, shares and protects personal information in connection with its website, services and business activities.
This Privacy Policy explains how TCOBOTS LIMITED ("Tcobots", "we", "us" or "our") collects, uses, stores, shares and protects personal information. It applies when you visit our website, contact us, request or receive our services, work with us as a client, supplier or business partner, or apply for a role with us.
We process personal information in accordance with applicable UK data protection law, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and, where relevant, the Privacy and Electronic Communications Regulations 2003 (PECR).
Tcobots is a UK technology company providing web design and digital solutions, cyber security, cloud security, penetration testing, security monitoring, IT support, business intelligence, quality assurance and related consulting services.
For the purposes described in this policy, Tcobots will usually act as the data controller. Where we process personal information strictly on a client's instructions as part of delivering a service, the client may be the controller and Tcobots may act as a processor.
The information we collect depends on how you interact with us. It may include:
| Category | Examples |
|---|---|
| Identity and contact details | Name, job title, organisation, business address, telephone number, email address and professional profile information. |
| Enquiry and communication data | Messages, meeting notes, correspondence, call details, service requests, feedback and records of our interactions. |
| Client and project information | Requirements, proposals, contracts, statements of work, project documentation, access records, support tickets and information needed to deliver services. |
| Commercial and payment information | Billing details, purchase orders, payment status and transaction records. We do not normally store complete payment-card details. |
| Technical and website data | IP address, browser type, device information, operating system, referring pages, pages viewed, timestamps, security logs, cookie identifiers and similar online information. |
| Marketing preferences | Your communication preferences, consent records and whether you have opted out of marketing. |
| Recruitment information | CV, employment history, qualifications, professional memberships, interview notes, references, right-to-work information and other information relevant to an application. |
| Supplier and partner information | Business contact details, due-diligence information, contractual records and performance information. |
| Sensitive information | Special-category or criminal-offence information only where it is genuinely necessary, lawful and subject to additional safeguards. |
We only use personal information where we have a lawful basis. The table below summarises our principal purposes and bases. More than one basis may apply depending on the circumstances.
| Purpose | How we use the information | Lawful basis |
|---|---|---|
| Respond to enquiries and prepare proposals | To communicate with you, understand requirements, arrange meetings and take steps before entering a contract. | Steps at your request before a contract; legitimate interests in developing and operating our business. |
| Deliver and manage services | To provide services, manage projects, support users, administer contracts and maintain client relationships. | Performance of a contract; legitimate interests; legal obligations where applicable. |
| Billing, accounting and administration | To issue invoices, process payments, maintain records and manage tax, audit and financial reporting. | Performance of a contract; legal obligation; legitimate interests. |
| Cyber security and service protection | To authenticate users, control access, detect threats, investigate incidents, prevent fraud and protect systems, people and information. | Legitimate interests in maintaining security; legal obligations; substantial public interest where applicable. |
| Website operation and improvement | To operate, troubleshoot and improve our website and understand how it is used. | Legitimate interests for strictly necessary operation; consent for non-essential analytics or similar technologies where required. |
| Business-to-business marketing | To share relevant service information, insights and event invitations and manage preferences. | Consent where required; otherwise legitimate interests where permitted by law. You may opt out at any time. |
| Recruitment and resourcing | To assess applications, conduct interviews, verify suitability and meet employment, immigration and legal requirements. | Steps before a contract; legitimate interests; legal obligations; consent or other conditions for sensitive data where required. |
| Supplier and partner management | To perform due diligence, obtain services, manage relationships, monitor performance and make payments. | Contract; legitimate interests; legal obligations. |
| Legal and regulatory matters | To establish, exercise or defend legal claims, respond to authorities and comply with law, regulation or court orders. | Legal obligation; legitimate interests; establishment, exercise or defence of legal claims. |
| Corporate transactions | To assess or complete a merger, restructuring, financing, acquisition or sale, subject to confidentiality and appropriate safeguards. | Legitimate interests; legal obligations. |
We may send relevant business communications to corporate contacts where permitted by law. Where consent is required, we will ask for it before sending electronic marketing. Every marketing message will provide a simple way to opt out, and you may also contact us at [email protected].
If you opt out, we may keep limited details on a suppression list so that we can respect your preference. Opting out of marketing will not prevent us from sending service, security, contractual or administrative communications.
We do not sell personal information. We may share it only where necessary and lawful, including with:
Service providers acting on our behalf are expected to process information only for agreed purposes, protect it appropriately and comply with applicable data protection requirements.
Some technology providers or service partners may process personal information outside the United Kingdom. Where information is transferred internationally, we use an appropriate legal transfer mechanism and safeguards, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another lawful mechanism. You may contact us for further information about relevant safeguards.
We keep personal information only for as long as necessary for the purpose for which it was collected, including legal, accounting, security and reporting requirements. Indicative retention periods are set out below and may be adjusted where a longer or shorter period is justified.
| Record type | Typical period |
|---|---|
| General enquiries and prospective-client records | Usually up to 24 months after the last meaningful contact. |
| Client contracts, project and financial records | Generally 6 years after the relationship or relevant financial period ends, unless a longer period is required for legal claims, security or regulation. |
| Supplier and partner records | Generally 6 years after the relationship ends or the relevant transaction is completed. |
| Marketing records | Until you opt out or the information is no longer relevant. Limited suppression data may be retained to respect your preference. |
| Unsuccessful job applications | Usually 6 months after the recruitment process, or up to 12 months where you consent to future opportunities. |
| Successful applicants | Transferred into the relevant worker or personnel records and retained under the applicable employment retention schedule. |
| Website and security logs | For periods proportionate to operational and security needs. Cookie-specific periods are described in the Cookie Policy or live cookie settings. |
| Complaints, rights requests and legal matters | For as long as needed to resolve the matter and demonstrate compliance, taking applicable limitation periods into account. |
We use proportionate technical and organisational measures designed to protect personal information against accidental or unlawful loss, misuse, alteration, unauthorised disclosure or access. Measures may include access controls, authentication, encryption where appropriate, monitoring, backups, secure configuration, supplier assessment, staff awareness and incident-management procedures.
No internet transmission or information system is completely secure. You should avoid sending highly sensitive information through unencrypted channels unless appropriate safeguards have been agreed.
Depending on the circumstances and the lawful basis used, you may have the right to:
To exercise a right, email [email protected]. We may ask for information needed to confirm your identity and understand your request. We normally respond within one month, although the law permits an extension for complex or multiple requests. Rights are not absolute and exemptions may apply.
We do not currently use solely automated decision-making that produces legal effects or similarly significant effects on individuals through our public website. If this changes, we will provide the information required by law.
Our website and business services are intended for organisations and adults and are not directed at children. We do not knowingly collect children's personal information through the website. Please contact us if you believe a child has provided personal information to us without appropriate authority.
Our website may use cookies and similar technologies. Please read our separate Cookie Policy for further information. Our website may also contain links to third-party websites. Those organisations are responsible for their own privacy practices, and we encourage you to read their notices.
We may update this Privacy Policy to reflect changes to our business, website, services, technology or legal obligations. The current version will be published on our website with its effective date. Where a change materially affects how we use personal information, we will take reasonable steps to bring it to the attention of affected individuals.
Please contact us first if you have a question, request or concern about how we use personal information:
You also have the right to complain to the UK Information Commissioner's Office (ICO):