Data Processing Policy
Version History
v1.0- Date: 2026-09-04
- Summary: Initial version
![[Version Description]]
![[Who]]
What
This document sets out publicly and internally the minimum standard by which we collect, use, retain and protect personal data belonging to clients, prospective clients and other individuals it deals with in the course of business.
As a company registered and trading in the United Kingdom, our baseline legal obligations are the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018 (“DPA 2018”). Thus policy is built around those requirements and applies to all personal data processed by is, regardless of the format in which it is held.
Contact
You may use the standard contact details from above to discuss this policy. In order to keep this document generic, our Data Protection Officer is not named, however they can be also be contacted directly with the following details:
Email: dpo (at) 417-tech (dot) com
Our ICO registration number is ZC200887.
Data Minimisation
In line with the UK GDPRs data minimisation principle, we only collect the personal data reasonably necessary to form and perform a contract, meet legal obligations, and run the business. As a minimum operating baseline, this is limited to:
- Client business contact details
- Name
- Job title
- Business email address
- Phone number
- Billing and account information:
- Company name
- Billing address
- VAT number
- Payment details (processed via a PCI-compliant payment provider, no details are stored by us)
- Contract and engagement records
- Signed agreements
- Statements of work
- Correspondence needed to deliver the service
- Communications reasonably necessary for service delivery and support (e.g. emails)
- Where applicable:
- Employee / HR data limited to what is required for payroll
- Tax and employment law compliance
We do not collect special category data (e.g. health, biometric, or similarly sensitive data) about clients, and do not collect data from data subjects who are minors, unless a specific, documented business reason and lawful basis exists.
Where a client provides more personal data than this minimum (for example, personal data about their own end customers or employees embedded in project material), the client remains responsible for ensuring they have a lawful basis to share that data with us, and for instructing us accordingly under the data processing agreement where we act as a processor rather than a controller.