Legal

Privacy policy

Our commitment

We recognise the importance of the correct and lawful processing of personal data in maintaining full confidence in our business operation. We are committed to processing data carefully, fairly, and in compliance with the UK GDPR, the Data Protection Act 2018, and equivalent legislation. You retain ownership of your data and the rights set out below, and we pledge to address any errors quickly.

Our role under the UK Data Protection Act and GDPR

We act in two different capacities, depending on the context.

Where we're providing managed IT support to a client, we may need access to personal data that belongs to that client's own business, for example data held in their email systems, files or backups, in order to deliver the service. In that relationship, the client is the Data Controller of their own business's data, and we act as their Data Processor, under a Data Processing Agreement that limits us to using it only to provide the service, never for our own purposes.

For everything else, including our own prospects and clients' day-to-day points of contact, we act as the Data Controller ourselves.

Where we get your data from

If you're a point of contact at a business we support, for example the person we deal with day to day on IT matters, we hold your name and contact details because you're part of that relationship, collected when the relationship was set up or as it's needed.

Otherwise, we collect data directly from you: when you get in touch through this website, book a discovery call, sign up to hear from us, or contact us by phone or email. We don't buy contact lists or receive data from data brokers.

How we use your data

We use contact details to respond to enquiries, deliver IT support, and to keep in touch with people who've expressed an interest in what we do, by email, phone or post.

Reaching out to other UK businesses about our services is a legitimate interest, and you can object to this at any time. Where we send more general marketing, such as our newsletter, we only do so with your consent, which you can withdraw at any time.

Calls with us may be recorded, whether that's an initial discovery call booked through this website, or an ongoing support call with our helpdesk team. We do this so we can refer back to what was discussed and for staff training and quality purposes. We keep recordings only for as long as necessary for those purposes.

How we share and protect your data

We share data with the suppliers who support our operations, under Data Processing Contracts that require them to protect it to the same standard we do. This includes Vercel, who host this website, and Resend, who deliver emails sent from our contact and newsletter forms. We do not sell your data to any other organisation.

Vercel and Resend are based outside the UK. Where personal data is transferred internationally as a result, we rely on recognised safeguards, such as Standard Contractual Clauses, to protect it to UK GDPR standards.

We participate in the UK Cyber Essentials security standard.

We don't make any decisions about you using automated processing or profiling that would have a legal or similarly significant effect on you.

In the unlikely event of a data breach affecting your rights and freedoms, we will notify the ICO, and you where required, without undue delay.

How long we keep your data

We keep personal data for as long as necessary for the purposes described in this policy, and no longer.

  • Enquiries and contact form submissions that don't turn into a client relationship are kept for up to 24 months, so we can follow up reasonably, then deleted.
  • Client data is kept for the duration of our relationship, plus up to 6 years afterwards, in line with standard UK limitation periods for contractual and tax-related claims.
  • Marketing contact preferences are kept until you object or withdraw consent, at which point we suppress further contact.

Children's data

This website and our services are aimed at businesses, not children. We don't knowingly collect personal data from children, and if we become aware that we have, we'll delete it.

Our website

Contact forms and any downloads on this website collect information as described in this policy. This site does not use tracking or advertising cookies. We use privacy-friendly, cookieless analytics to understand aggregate traffic patterns, which does not identify you personally.

Your rights

You have the right to:

  • correct inaccurate or incomplete data
  • object to how we're processing your data
  • request a copy of the data we hold about you
  • request erasure of your data
  • request that we restrict how your data is processed
  • request your data in a portable format, where technically feasible
  • withdraw consent at any time, where processing relies on consent

If your data is held by one of our clients as Data Controller, initial requests should go to them directly. For requests relating to data we control ourselves, contact dpo@atema.co.uk. We typically respond within two working days.

Changes to this policy

We may update this policy from time to time, for example as our services, suppliers or the law change. We'll update the date below when we do, and encourage you to check back periodically.

Our company registration details

Atema Ltd, company number 10827258, registered at Willow Court, Beeches Green, Stroud, Gloucestershire, GL5 4BJ. ICO registration: ZA346238. If you're unhappy with how we've handled your data, you can complain to the ICO at ico.org.uk.

Statement last updated: 20 July 2026.