Privacy Notice

GDPR and Data Protection

Introduction

InterSys Micronics Ltd (“InterSys”, “we”, “our”, or “us”) is committed to protecting the privacy and security of personal data and complying with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and all applicable data protection legislation.

This Privacy Notice explains how we collect, process, use, and protect personal information obtained through our business-to-business activities and customer interactions. It applies to personal data obtained through emails, telephone conversations, meetings, support requests, projects, managed services, telecommunications services, and other business engagements that do not involve our website whose specific policy is available elsewhere.

Who We Are

InterSys Micronics Ltd

Registered Address

The Old Fire Station
Edward Street
Lytham St. Annes
FY8 1XR

Email: intersys@intersys-group.com
Phone: 01253 716800

For any questions regarding this Privacy Notice or our handling of personal data, please contact us using the details above.

Our Role

InterSys Micronics Ltd operates primarily as an IT services provider for business customers.

In most circumstances, we act as a Data Processor on behalf of our customers, who remain the Data Controllers of any personal data stored within their systems, networks, applications, communications, or databases.

Where InterSys processes personal data relating to its own business activities, including sales, account management, supplier management, customer relationship management, invoicing, and contractual administration, InterSys acts as a Data Controller

Personal Data We Collect

For our own business purposes, we may collect and process:

Business Contact Information

  • Name
  • Job title
  • Company name
  • Business address
  • Email address
  • Telephone number

Customer Relationship Information

  • Account details
  • Correspondence records
  • Meeting notes
  • Support requests
  • Contractual information
  • Service history

Financial Information

  • Billing and payment information
  • Purchase order information
  • Credit control records

Communications Records

  • Emails
  • Telephone call records
  • Written correspondence
  • Support tickets
  • Complaint records

Personal Data Accessed During Service Delivery

As part of delivering IT, telecommunications, managed services, consultancy, and technical support services, authorised InterSys personnel may occasionally have access to personal data contained within customer systems.

Such access may arise during:

  • Technical support and troubleshooting
  • Remote administration
  • Network management
  • Cloud services management
  • Software deployment and maintenance
  • System migrations and upgrades
  • Cybersecurity monitoring
  • Backup and disaster recovery activities
  • Telecommunications support
  • Incident investigation and resolution

The personal data encountered may include:

  • Names
  • Business contact details
  • Email communications
  • User account information
  • Documents and files
  • System and audit logs
  • Other information stored within customer systems

This access is incidental to the delivery of our contracted services and is limited to what is necessary to perform those services.

Statement Regarding Engineer Access

Our engineers may occasionally view information that contains personal data whilst diagnosing faults, performing maintenance, administering systems, or providing technical support.

Such access is strictly limited to what is necessary to deliver the service requested by the customer.

InterSys Micronics Ltd does not routinely collect, use, analyse, or retain this information for its own purposes and will only access customer data where necessary to complete service requests.

All personnel are subject to confidentiality obligations and data protection requirements.

How We Collect Information

We may collect information directly from:

  • Customers
  • Prospective customers
  • Suppliers
  • Business partners
  • Employees of customer organisations

This information may be obtained through:

  • Telephone calls
  • Email correspondence
  • Face-to-face meetings
  • Customer support requests
  • Project engagements
  • Service contracts
  • Industry events and exhibitions
  • Referrals
  • Publicly available business information

Purposes of Processing

We process personal data for the following purposes:

Customer Relationship Management

  • Responding to enquiries
  • Providing quotations
  • Managing customer accounts
  • Maintaining business relationships

Service Delivery

  • Delivering contracted services
  • Providing support and maintenance
  • Managing projects
  • Monitoring service performance

Administration

  • Contract management
  • Billing and invoicing
  • Financial record keeping
  • Supplier management

Business Development

  • Providing information regarding our services
  • Informing customers of relevant service updates
  • Managing business communications

Legal and Regulatory Compliance

  • Compliance with statutory obligations
  • Fraud prevention
  • Enforcement of contractual rights
  • Regulatory reporting requirements

Lawful Basis for Processing

We process personal data under one or more of the following lawful bases:

Contract

Processing necessary for the performance of a contract or to take steps prior to entering into a contract.

Legal Obligation

Processing necessary to comply with legal and regulatory requirements.

Legitimate Interests

Processing necessary for our legitimate business interests, including:

  • Customer relationship management
  • Delivery of services
  • Business administration
  • Information security
  • Service improvement

We balance these interests against the rights and freedoms of individuals.

Consent

Where required by law, we will obtain consent before processing personal data and individuals may withdraw consent at any time.

Data Minimisation

InterSys is committed to the principle of data minimisation.

We:

  • Only access data necessary to perform the services requested.
  • Restrict access to authorised personnel.
  • Avoid unnecessary copying or downloading of customer data.
  • Retain personal data only where required for legitimate business or contractual purposes.
  • Review stored information regularly to ensure it remains necessary.

Storage and Retention

InterSys does not generally retain personal data belonging to customers that is encountered during support or administrative activities.

However, temporary retention may occasionally be necessary for purposes such as:

  • Diagnostic analysis
  • Incident investigations
  • Technical support records
  • Backup and recovery processes
  • Audit requirements
  • Future legal proceedings

Where personal data is temporarily retained, it will be protected appropriately and deleted once no longer required.

Business records that contain personal data will be retained in accordance with applicable legal, contractual, and regulatory requirements.

Security Measures

We implement appropriate technical and organisational measures to safeguard personal data, including:

  • Access controls and permissions
  • Multi-factor authentication where appropriate
  • Encryption technologies
  • Secure remote-access systems
  • Anti-malware protection
  • Network security controls
  • Staff training and awareness
  • Confidentiality agreements
  • Incident management procedures

Access to customer information is restricted to personnel with a legitimate business need.

Sharing Personal Data

We do not sell personal data.

Personal data may be shared only where necessary with:

  • Authorised subcontractors and service providers
  • Professional advisers
  • Regulators and government authorities
  • Law enforcement agencies where legally required

Any third parties processing personal data on our behalf are required to maintain appropriate security and confidentiality standards.

International Transfers

Where personal data is transferred outside the United Kingdom, InterSys will ensure appropriate safeguards are in place, including:

  • UK International Data Transfer Agreements (IDTAs)
  • UK-approved Standard Contractual Clauses
  • Transfers to countries recognised as providing adequate protection

Individual Rights

Where InterSys acts as a Data Controller, individuals may have the right to:

  • Access their personal data
  • Correct inaccurate information
  • Request erasure of personal data
  • Restrict processing
  • Object to processing
  • Request data portability
  • Withdraw consent where applicable

Where InterSys acts solely as a Data Processor, requests relating to personal data should generally be directed to the relevant customer who acts as the Data Controller.

InterSys will assist customers with such requests where required under applicable contractual or legal obligations.

Personal Data Breaches

InterSys maintains procedures for identifying, reporting, and investigating suspected personal data breaches.

Any breach involving customer data will be managed promptly and, where required, reported to the relevant customer and applicable regulatory authorities in accordance with legal requirements.

Complaints

If you have concerns regarding how InterSys Micronics Ltd handles personal data, please contact us in the first instance.

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO):

Information Commissioner’s Office (ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Website: https://ico.org.uk
Telephone: 0303 123 1113

Changes to this Privacy Notice

InterSys Micronics Ltd may update this Privacy Notice periodically to reflect changes in legal obligations, industry practices, or business operations.

The most current version will be made available upon request and is available on our website at https://www.intersys-group.com