UK GDPR statement

Data protection isn't a page on our website — it's part of how an IT company has to think. Here's how we meet our obligations, in plain English.

Last updated: 23 August 2026
Controller: IT Support World Limited (company no. 09064078), Vision House, 3 Dee Road, Richmond, Surrey, TW9 2JN — contact info@itsupportworld.co.uk.

Our two roles

Under UK GDPR (the retained EU General Data Protection Regulation, together with the Data Protection Act 2018) we wear two hats, and take both seriously:

  • As a controller — for the information of our own clients, enquirers and suppliers, as described in the privacy policy.
  • As a processor — when supporting client systems that contain their data (mailboxes, files, databases). There we act only on the client's documented instructions, under contract.

The principles, applied

  • Lawfulness, fairness, transparency — we tell you what we collect and why, and collect nothing covertly. This website stores nothing on your device and gathers only anonymous, aggregate visit counts, exactly as the data policy describes.
  • Purpose limitation — information given to get IT help is used to give IT help. Full stop.
  • Data minimisation — we ask for what the job needs and no more; remote sessions access only what the fix requires.
  • Accuracy — records corrected promptly when you tell us something has changed.
  • Storage limitation — retention periods are defined in the privacy policy, and data past them is deleted, not hoarded.
  • Integrity and confidentiality — encryption in transit and at rest, multi-factor authentication on our systems, least-privilege access, and devices that are wiped before disposal.
  • Accountability — we keep records of processing, review them, and can show our workings.

Security measures

We apply to ourselves what we sell to clients: enforced MFA, full-disk encryption on engineer devices, unique per-system credentials in a managed vault, prompt patching, tested backups, and immediate access revocation when roles change. Client credentials are stored encrypted, never in plain text, and never reused across clients.

Data breaches

If a personal-data breach ever occurs, we will assess it immediately, contain it, notify the ICO within 72 hours where the law requires, and tell affected people without undue delay when there is a real risk to them — clearly, and without lawyer-speak.

International transfers

We keep data in the UK, or with providers offering UK/EU data residency, wherever practical. Where a service processes data outside the UK, we rely on UK adequacy decisions or the approved standard contractual safeguards.

Your rights

Access, rectification, erasure, restriction, portability and objection — all described, with how to exercise them, in the privacy policy. Requests go to info@itsupportworld.co.uk and are answered within one month, free of charge in almost all cases.

Helping our clients comply

Many of our business services exist partly to keep clients compliant: retention and archival policies, access reviews, encrypted backups, secure disposal with certificates, and CCTV configured with lawful signage and retention. If UK GDPR is on your risk register, talk to us.