Privacy Policy
Privacy Policy
Last updated: 1 September 2026
Subset Solutions UK Limited (“Subset”, “Subset Enterprise”, “we”, “us” or “our”) respects your privacy and is committed to protecting your personal information.
This Privacy Policy explains how we collect, use, store and protect personal information when you visit our website, contact us, enquire about our services or become a customer.
1. Who we are
Subset Solutions UK Limited is a company registered in England and Wales.
Company name: Subset Solutions UK Limited
Company number: 09542306
Trading name: Subset / Subset Enterprise
Registered office: C/O JT Accounts Limited, 9 Woodgrange Avenue, Enfield, England, EN1 1EW
Website: subsetenterprise.co.uk
Email: [email protected]
Telephone: +44 (0) 203 468 1421
For the purposes of UK data protection law, Subset Solutions UK Limited is normally the data controller for personal information described in this Privacy Policy.
In some circumstances, particularly where we provide hosting, IT support, communications or other managed services to business customers, we may process personal information on behalf of that customer. In those circumstances, the customer will normally be the data controller and we will act as a data processor in accordance with our contract and any applicable data processing terms.
2. Information we collect
The personal information we collect depends on how you interact with us.
It may include:
- your name;
- business or organisation name;
- job title;
- email address;
- telephone number;
- postal or business address;
- information you provide in an enquiry or contact form;
- correspondence between you and Subset;
- customer and account information;
- billing and transaction information;
- service history and support records;
- technical information such as your IP address, device information, browser type and operating system;
- information relating to services, equipment, telephone systems, hosting accounts or network connections that we provide or manage;
- website usage information; and
- any other information you choose to provide to us.
Please avoid including sensitive or special category personal information in website enquiry forms unless it is genuinely necessary.
3. How we collect personal information
We may collect information:
- directly from you when you contact us;
- when you submit a form through our website;
- when you telephone, email or otherwise communicate with us;
- when you request a quotation or purchase a service;
- during the provision of IT, hosting, connectivity, communications or support services;
- automatically when you visit our website, through server logs, cookies and similar technologies;
- from your employer or another organisation where you are a contact for one of our customers or suppliers;
- from service providers and business partners involved in delivering services to you; and
- from publicly available sources where appropriate.
4. How we use your information
Respond to enquiries
We use information you provide through our website, email or telephone to respond to your questions, prepare quotations and discuss our services.
Our lawful basis will normally be our legitimate interests in responding to business enquiries or taking steps at your request before entering into a contract.
Provide our services
We use customer information to set up, provide, maintain, manage and support the services you purchase from us.
This can include IT support, managed workplace services, internet connectivity, hosting, communications and related technology services.
Our lawful basis will normally be performance of a contract or taking steps before entering into a contract.
Manage customer accounts
We may use information to administer customer accounts, manage user permissions, maintain service records, process changes and provide customer support.
Our lawful basis will normally be performance of a contract and/or our legitimate interests in operating and administering our services.
Billing and accounting
We use relevant information to issue invoices, process payments, maintain financial records and meet our accounting and taxation obligations.
Our lawful bases are performance of a contract and compliance with our legal obligations.
Operate and secure our systems
We may process technical information, including IP addresses, device information and system logs, to:
- operate our website and services;
- diagnose technical problems;
- prevent fraud and misuse;
- detect and investigate security incidents;
- protect our systems, networks and customers; and
- maintain appropriate audit and security records.
Our lawful basis is normally our legitimate interests in maintaining secure, reliable and effective systems and services.
Improve our website and services
We may analyse information about the use and performance of our website and services to identify faults, understand how our services are used and make improvements.
Where this involves non-essential cookies or similar technologies, we will obtain consent where required.
Comply with legal obligations
We may process or disclose personal information where necessary to comply with applicable laws, regulations, court orders or requests from regulators and law enforcement authorities.
Our lawful basis is compliance with a legal obligation or, where appropriate, our legitimate interests in protecting our legal rights.
Establish or defend legal claims
We may retain and use relevant information where necessary to establish, exercise or defend legal claims.
Our lawful basis is our legitimate interests in protecting the company and its legal rights.
5. Our legitimate interests
Where we rely on legitimate interests, those interests may include:
- operating and developing our business;
- responding to enquiries;
- communicating with business contacts;
- administering customer relationships;
- providing effective customer support;
- protecting our infrastructure and services;
- preventing fraud, abuse and cyber-security incidents;
- maintaining appropriate business records; and
- improving our products and services.
Where required, we consider whether our interests are outweighed by your rights and interests before relying on this lawful basis.
6. Marketing
We may occasionally contact existing or prospective business customers about services that we believe may be relevant to them where permitted by law.
Where consent is required, we will obtain it before sending marketing communications.
You can ask us to stop sending marketing communications at any time by contacting us or by using an unsubscribe facility contained within the communication.
Stopping marketing communications will not prevent us from contacting you about services you currently receive from us, invoices, security issues or other necessary service-related matters.
7. Cookies and similar technologies
Our website may use cookies and similar technologies.
Some cookies are necessary for the website to operate correctly or securely. Other cookies may be used for functionality, analytics or other purposes.
Where consent is legally required for a cookie or similar technology, it will not be used until you have provided the appropriate consent.
You can change or withdraw your cookie choices where our website provides a cookie management facility.
Further information about the cookies used by this website should be provided in our separate Cookie Policy.
8. Information processed when providing services to customers
Some of the services we provide may require us to process personal information belonging to our customers, their staff, users or customers.
For example, this may occur when providing:
- managed IT services;
- technical support;
- hosting;
- backup services;
- network services;
- internet connectivity;
- communications and telephone systems;
- email or server services; or
- related infrastructure services.
This information could include account details, usernames, IP addresses, device identifiers, service records, communications information or other data stored within customer systems.
Where we process this information solely on the instructions of a customer, we act as a data processor rather than the data controller.
Our processing in those circumstances is governed by our agreement with the relevant customer and applicable data processing terms.
Individuals wishing to exercise their data protection rights in relation to information controlled by one of our customers should normally contact that customer directly.
9. Who we share information with
We do not sell personal information.
We may share information where reasonably necessary with:
- companies that provide infrastructure, connectivity or telecommunications services used to deliver our services;
- hosting, data centre and cloud service providers;
- software and technology suppliers;
- payment processors and financial institutions;
- accountants, auditors, insurers and professional advisers;
- contractors or suppliers assisting us in delivering services;
- security, fraud prevention and monitoring providers;
- government bodies, regulators, law enforcement authorities or courts where legally required; and
- prospective purchasers, investors or advisers in connection with a sale, restructuring or transfer of all or part of our business.
We only disclose information where there is an appropriate reason to do so and, where required, put contractual safeguards in place with organisations processing information on our behalf.
10. International transfers
Some of the technology providers or suppliers we use may process information outside the United Kingdom.
Where personal information is transferred outside the UK, we take reasonable steps to ensure that an appropriate lawful transfer mechanism and safeguards are in place where required.
These safeguards may include:
- transferring information to countries recognised as providing an adequate level of protection;
- use of approved contractual safeguards; or
- another transfer mechanism permitted under UK data protection law.
You may contact us if you would like further information about the safeguards applying to a particular transfer.
11. How long we keep information
We only retain personal information for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, security and regulatory requirements.
The period will depend on the nature of the information and our relationship with you.
For example:
- enquiry records may be retained for a reasonable period after an enquiry has concluded so that we can respond to follow-up questions and maintain business records;
- customer, contractual, billing and service records may generally be retained for up to six years after the relevant relationship or transaction has ended where necessary for tax, accounting or legal purposes;
- security and technical logs are retained for periods appropriate to their operational and security purpose;
- marketing information may be retained until you unsubscribe or object to the processing, subject to retaining limited suppression information to ensure that your preference is respected.
We may retain information for longer where required by law, where a dispute exists or where it is reasonably required for the establishment, exercise or defence of legal claims.
Information that is no longer required will be securely deleted, anonymised or otherwise disposed of.
12. How we protect your information
We use appropriate technical and organisational measures designed to protect personal information against:
- unauthorised access;
- accidental loss;
- misuse;
- alteration;
- disclosure; and
- destruction.
Measures may include access controls, authentication systems, encryption, network security, monitoring, backup procedures and restrictions on access to personal information.
No internet or electronic storage system can be guaranteed to be completely secure, but we regularly review the measures used to protect our systems and information.
13. Your data protection rights
Depending on the circumstances, UK data protection law may give you the right to:
- request access to personal information we hold about you;
- request correction of inaccurate or incomplete information;
- request deletion of your personal information;
- request restriction of our use of your information;
- object to certain processing, including processing based on legitimate interests;
- object to direct marketing;
- request the transfer of certain information to you or another organisation;
- withdraw consent where we rely on consent; and
- raise a complaint about how your personal information has been handled.
These rights are not absolute and exemptions may apply in some circumstances.
We may need to verify your identity before responding to a request.
You will not normally be charged for exercising your rights, although the law allows a reasonable fee to be charged or a request to be refused in certain limited circumstances.
To exercise any of these rights, contact us at [email protected].
14. Complaints
If you have concerns about how we use your personal information, please contact us first so that we can investigate the issue.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK’s independent data protection regulator.
Information about making a complaint is available through the ICO website.
15. Third-party websites
Our website may contain links to websites operated by other organisations.
We are not responsible for the privacy practices or content of third-party websites. You should review the privacy information provided by those organisations when visiting their websites or using their services.
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to our services, technology, suppliers or legal obligations.
The latest version will be published on this website and the “Last updated” date at the top of this policy will be changed accordingly.
We encourage you to review this policy periodically.
17. Contact us
If you have any questions about this Privacy Policy or how we handle personal information, please contact:
Subset Solutions UK Limited
75 Millmarsh Lane
Enfield
EN3 7UY
Email: [email protected]
Telephone: +44 (0) 203 468 1421
