This practical template should be checked against ARB’s actual systems, suppliers, retention periods and legal responsibilities. It is not a substitute for professional legal advice.
1. Who we are
ARB Marketing and IT Services provides website development, mobile application development, digital marketing and IT support services. For the purposes of applicable UK data-protection law, ARB is the controller of personal information described in this policy unless another arrangement is stated.
Website: https://arbitservices.co.uk/
Email: hello@arbitservices.co.uk
2. Information we may collect
- Contact details, including name, email address and telephone number.
- Organisation and professional information supplied during an enquiry.
- Project, marketing or IT-support requirements described to us.
- Correspondence, proposals, agreements and service records.
- Technical information made available when diagnosing or supporting a system.
- Website usage and cookie information where relevant tools are enabled and permitted.
Please do not send passwords, payment-card details or sensitive access information through the general contact form.
3. How and why we use information
We may use personal information to respond to enquiries, assess requirements, prepare proposals, deliver agreed services, provide support, administer our relationship, maintain security, meet legal obligations and improve our services.
Depending on the circumstances, our lawful basis may be taking steps before entering a contract, performing a contract, complying with a legal obligation, pursuing legitimate business interests, or consent where consent is specifically required. We will not rely on consent where another lawful basis is more appropriate.
4. When information may be shared
Information may be shared with trusted service providers where necessary for hosting, email, website operation, professional advice, project delivery or technical support. Providers should only receive information needed for their role and should be required to protect it appropriately.
We may also disclose information where required by law, to protect legal rights, or in connection with a business reorganisation. We do not sell personal information.
5. International processing
Some technology providers may process information outside the United Kingdom. Where this occurs, appropriate safeguards should be used as required by applicable data-protection law. This section must be reviewed against the hosting, analytics, email, cloud and other suppliers actually used by ARB.
6. How long information is kept
Information is retained only for as long as reasonably necessary for the purpose for which it was collected, including service delivery, support, security, accounting, dispute resolution and legal requirements. Enquiries that do not become active work should be periodically reviewed and deleted when no longer needed. ARB should document and apply specific retention periods for its live systems.
7. Security
We take proportionate technical and organisational measures intended to protect personal information from accidental loss, unauthorised access, alteration or disclosure. No internet or email transmission can be guaranteed completely secure.
8. Your data-protection rights
Depending on the circumstances, you may have rights to request access, correction, deletion, restriction, portability or objection, and to withdraw consent where processing relies on consent. Some rights are subject to legal conditions and exemptions.
You may also complain to the UK Information Commissioner’s Office. Visit ico.org.uk for current guidance.
9. Cookies
Information about cookies and similar technologies is provided in our Cookie Policy.
10. Changes to this policy
This policy may be updated when services, suppliers or legal requirements change. The review date at the top should be updated whenever material changes are made.
11. Contact us
To ask a privacy question or exercise a data-protection right, email hello@arbitservices.co.uk. We may need to verify identity before responding to certain requests.