IDT Support Solutions Privacy Policy
IDT Support Solutions Limited Privacy Policy
Last updated: January 2026
IDT Support Solutions Limited is committed to protecting your privacy and handling your personal information in a lawful, fair and transparent way.
This Privacy Policy explains how we collect, use, store, share and protect personal information when you visit our website, contact us, request a quote, use our products or services, apply for a role with us, or otherwise interact with us.
For the purposes of UK data protection law, including the UK General Data Protection Regulation and the Data Protection Act 2018, IDT Support Solutions Limited is the data controller for the personal information described in this Privacy Policy, unless we are processing personal information on behalf of one of our customers as their service provider.
Where we provide managed IT, support, hosting, security, connectivity, cloud, data centre or related services to our customers, we may also process personal information as a data processor on behalf of that customer. In those cases, the customer remains the data controller and our processing will be governed by our contract with that customer.
1. Who we are
IDT Support Solutions Limited
Olympic Park
3 Olympic Way
Birchwood
Warrington
WA2 0YL
United Kingdom
Email: privacy@idtsupport.com
2. Personal information we collect
We may collect and process the following types of personal information:
Contact and identity information
This may include your name, job title, business name, postal address, email address, telephone number, mobile number and other contact details.
Account and customer information
This may include customer account details, service history, support tickets, order history, billing details, contract details, communication preferences and records of your dealings with us.
Technical and service information
This may include usernames, business contact details, device information, IP addresses, system logs, audit logs, support records, remote access records, service usage information, security alerts and information required to provide, monitor, secure and support our services.
Website and usage information
When you use our website, we may collect information about your visit, including IP address, browser type, device information, pages visited, time spent on pages, referral source and other analytics data. We may collect this through cookies or similar technologies. Please see our Cookie Policy for further details.
Payment and financial information
We may process information needed to administer payments, invoices, credit control and accounting. Where card payments are made, payment details may be processed by our payment provider. We do not intend to store full payment card details unless we specifically tell you otherwise and have appropriate safeguards in place.
Marketing and communications information
This may include your marketing preferences, communication preferences, responses to surveys, event registrations and records of whether you have opted in or opted out of receiving marketing.
Recruitment information
If you apply for a job with us, we may process information contained in your CV, application form, covering letter, interview notes, employment history, qualifications, references, right-to-work information and any other information you provide as part of the recruitment process.
CCTV, call recordings and monitoring information
Where applicable, we may process CCTV footage, telephone recordings, email records, text messages, support chat records and other communications for legitimate business, security, training, compliance and crime prevention purposes.
3. How we collect personal information
We may collect personal information directly from you when you:
- contact us by phone, email, website form, live chat or social media;
- request a quote or information about our products or services;
- place an order or enter into a contract with us;
- use our support desk or managed services;
- attend a meeting, event or training session;
- complete a survey or questionnaire;
- apply for a job with us;
- visit our website or premises.
We may also receive personal information from:
- your employer or organisation;
- our customers, where we provide services to them;
- suppliers, vendors, distributors and partners;
- payment providers;
- credit reference or fraud prevention agencies, where appropriate;
- publicly available sources, such as Companies House, LinkedIn or company websites;
- IT systems, security tools, monitoring tools and service platforms used to deliver our services.
4. How we use your personal information and our lawful bases
We will only use your personal information where we have a lawful basis to do so. The main lawful bases we rely on are:
- Contract: where processing is necessary to enter into or perform a contract with you or your organisation.
- Legitimate interests: where processing is necessary for our legitimate business interests or those of a third party, provided your rights and freedoms do not override those interests.
- Legal obligation: where processing is necessary to comply with the law.
- Consent: where you have given us clear consent for a specific purpose.
- Vital interests: in rare cases, where processing is necessary to protect someone’s life.
We may use your personal information for the following purposes:
| Purpose | Type of data | Lawful basis |
| To respond to enquiries, requests for quotes and website forms | Contact, identity and communication information | Legitimate interests; contract where the enquiry relates to a proposed service |
| To provide IT support, managed services, cloud services, security services, hosting, data centre services and other contracted services | Contact, account, technical, service and support information | Contract; legitimate interests |
| To manage customer accounts, orders, invoices, payments and credit control | Contact, account, financial and billing information | Contract; legal obligation; legitimate interests |
| To communicate with customers, suppliers and business contacts | Contact and communication information | Contract; legitimate interests |
| To manage service tickets, support requests, remote access sessions and technical issues | Technical, account, support and service information | Contract; legitimate interests |
| To monitor, secure and improve our systems, networks, services and website | Technical, security, usage and log information | Legitimate interests; legal obligation where applicable |
| To detect, investigate and prevent fraud, cyber security incidents, unauthorised access, misuse of systems or crime | Technical, security, monitoring and communication information | Legitimate interests; legal obligation |
| To comply with legal, regulatory, tax, accounting and audit obligations | Contact, account, financial, contract and communication information | Legal obligation; legitimate interests |
| To send relevant business updates, service information and marketing communications | Contact and marketing preference information | Consent where required; legitimate interests where permitted |
| To manage recruitment and job applications | Recruitment, identity and contact information | Legitimate interests; contract; legal obligation |
| To maintain business records and defend or bring legal claims | Relevant account, contract, communication and financial information | Legitimate interests; legal obligation |
| To monitor or record calls, emails, text messages, support chats or other communications | Communication and monitoring information | Legitimate interests; legal obligation where applicable |
5. Legitimate interests
Where we rely on legitimate interests, our interests may include:
- operating and managing our business;
- responding to enquiries and developing business relationships;
- providing, supporting and improving our services;
- managing contracts, suppliers and customers;
- securing our systems, networks and premises;
- preventing fraud, misuse, cyber threats and unauthorised access;
- maintaining accurate business records;
- recovering debts;
- promoting relevant products and services to business contacts;
- protecting our legal rights and interests.
Before relying on legitimate interests, we consider the impact on your privacy and whether your rights override our interests.
6. Marketing communications
We may use your contact details to send you information about our products, services, events, training, updates or offers that may be relevant to you or your organisation.
We will comply with applicable data protection and electronic marketing laws, including the Privacy and Electronic Communications Regulations.
For individuals, sole traders and some partnerships, we will only send email or SMS marketing where we have your consent or where the “soft opt-in” rules apply. The soft opt-in may apply where you have previously bought, negotiated to buy, or expressed an interest in similar products or services from us, and you were given a clear opportunity to opt out.
For corporate business contacts, we may send relevant business-to-business marketing where permitted by law, but we will always respect any objection or unsubscribe request.
You can opt out of marketing at any time by:
- using the unsubscribe link in our emails, where available;
- replying to the communication;
- emailing privacy@idtsupport.com and telling us what you want to opt out of, for example “opt-out email”, “opt-out SMS” or “opt-out telephone marketing”.
We may still send you important service, contract, security or account communications even if you opt out of marketing.
7. Cookies and website analytics
Our website may use cookies and similar technologies to operate the website, remember preferences, understand how visitors use the website and improve our services.
Some cookies may be essential for the website to work. Others, such as analytics or marketing cookies, may require your consent.
Please see our separate Cookie Policy for details of the cookies we use, why we use them and how you can manage your preferences.
8. When we share personal information
We do not sell your personal information.
We may share personal information where necessary with:
- companies within our group, if applicable;
- IT, cloud, hosting, telecommunications and security service providers;
- software vendors, distributors and technology partners;
- payment processors and banks;
- accountants, auditors, insurers, lawyers and professional advisers;
- debt recovery providers, where necessary;
- recruitment service providers, where applicable;
- regulators, law enforcement agencies, courts or public authorities where required by law;
- prospective buyers, investors or advisers in connection with a business sale, merger, restructuring or transfer.
Where we use third-party processors, we take steps to ensure they process personal information only in accordance with our instructions and with appropriate security measures in place.
We may also share personal information where this is necessary to deliver products or services ordered or used by you or your organisation.
9. International transfers
Some of our suppliers, service providers or technology platforms may process personal information outside the United Kingdom.
Where personal information is transferred outside the UK, we will take appropriate steps to ensure it is protected in accordance with applicable data protection law. This may include using UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or other lawful transfer safeguards.
10. How long we keep personal information
We keep personal information only for as long as necessary for the purposes for which it was collected, including to meet legal, accounting, tax, contractual, audit and reporting requirements.
Retention periods may vary depending on the type of information and the reason we hold it. As a general guide:
| Type of information | Typical retention period |
| Customer account, contract and service records | For the duration of the customer relationship and usually up to 7 years afterwards |
| Financial, invoicing and accounting records | Usually 6 to 7 years, depending on legal and tax requirements |
| Support tickets and technical service records | For the duration needed to provide support and maintain service records, then deleted or anonymised when no longer required |
| Security logs and monitoring records | For a limited period appropriate to security, audit and operational needs, unless needed for investigation or legal reasons |
| Marketing prospect records | No longer than 3 years from collection or last meaningful interaction, unless you opt out earlier or ask us to delete the data |
| Job application records for unsuccessful applicants | Usually up to 6 to 12 months after the recruitment process, unless we ask for your consent to keep details for longer |
| Records needed for legal claims or disputes | For as long as needed to establish, exercise or defend legal rights |
When personal information is no longer needed, we will delete it, anonymise it or securely archive it.
11. How we protect personal information
We take appropriate technical and organisational measures to protect personal information against unauthorised access, loss, misuse, alteration or destruction.
These measures may include:
- access controls;
- encryption where appropriate;
- secure authentication;
- network and endpoint security controls;
- monitoring and logging;
- staff training;
- data backup and recovery processes;
- supplier due diligence;
- physical security controls;
- policies and procedures for handling personal information.
We use industry standard TLS certificates to help protect data transmitted through our websites and management portals. Access to our websites and management portals is protected by HTTPS where applicable.
Please be aware that communications over the internet, including email, are not always secure unless they are encrypted. Information may pass through systems or countries outside our direct control. We cannot guarantee the security of information transmitted to us over the internet.
12. Your data protection rights
Depending on the circumstances, you may have the following rights under data protection law:
- Right of access: to ask for a copy of personal information we hold about you.
- Right to rectification: to ask us to correct inaccurate or incomplete information.
- Right to erasure: to ask us to delete personal information in certain circumstances.
- Right to restriction: to ask us to restrict how we use your information in certain circumstances.
- Right to object: to object to processing based on legitimate interests or direct marketing.
- Right to data portability: to receive certain information in a structured, commonly used and machine-readable format.
- Right to withdraw consent: where we rely on consent, you can withdraw it at any time.
- Right to complain: to complain to the Information Commissioner’s Office if you are unhappy with how we handle your personal information.
To exercise your rights, please contact us at privacy@idtsupport.com.
We may need to verify your identity before responding to your request. We will respond within the time required by law.
13. Recruitment privacy
If you apply for a role with us, we will use your personal information to assess your application, communicate with you, conduct interviews, carry out checks where appropriate and manage the recruitment process.
If your application is successful, relevant information may become part of your employment record.
If your application is unsuccessful, we will normally retain your recruitment information for a limited period after the process ends, unless you consent to us keeping your details for future opportunities.
You may withdraw consent for future opportunity contact at any time by emailing privacy@idtsupport.com.
14. Social media, blogs and reviews
If you post comments, reviews or messages about us on social media platforms, blogs or public review sites, those posts may be visible to other users and may be governed by the privacy policies and terms of the relevant platform.
We do not control how those platforms use your information. You should review the privacy settings, terms and policies of any social media or review platform you use.
Any comments you make on our blogs, social media pages or user community services must not be offensive, insulting, unlawful or defamatory. You are responsible for ensuring that your comments comply with applicable laws and platform rules.
15. Monitoring and recording communications
We may monitor or record calls, emails, text messages, support chats and other communications for legitimate business purposes, including:
- quality control;
- staff training;
- customer service;
- evidence of business communications;
- system security;
- preventing unauthorised use of our systems;
- ensuring effective operation of our services;
- detecting or preventing crime;
- complying with legal and regulatory obligations.
16. If our business changes ownership
If we undergo a reorganisation, merger, sale, acquisition or transfer of all or part of our business or assets, personal information may be transferred to the relevant buyer, successor organisation or adviser where necessary for that transaction.
Where this happens, we will ensure appropriate safeguards are in place and that personal information continues to be handled in accordance with applicable data protection law.
17. Contact us
If you have any questions about this Privacy Policy or how we handle personal information, please contact:
IDT Support Solutions Limited
Olympic Park
3 Olympic Way
Birchwood
Warrington
WA2 0YL
United Kingdom
Email: privacy@idtsupport.com
18. Complaints
You also have the right to complain to the UK data protection regulator:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
Website: www.ico.org.uk
We would appreciate the opportunity to deal with your concerns first, so please contact us before raising a complaint with the ICO.
19. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our business, services, legal obligations or data protection practices.
The latest version will be published on our website. Where we make significant changes, we may take additional steps to notify you where appropriate.

