GDPR Compliance
BritHaven Tech is committed to processing personal data responsibly, lawfully, and transparently. This page sets out our approach to compliance with the UK GDPR and the Data Protection Act 2018.
Our Commitment to Data Protection
BritHaven Tech Limited is committed to processing personal data responsibly, lawfully, and transparently. As an authorised UK technology reseller, we handle personal data in the course of our day-to-day commercial activities, including managing client accounts, processing orders, and operating our website.
We recognise that data protection is not merely a legal obligation but a fundamental aspect of the trust our clients and partners place in us. We are committed to embedding a culture of privacy across our organisation and to continually reviewing and improving our data protection practices. We do not sell personal data. We process only what is necessary. We are transparent about how and why we process data. We uphold the rights of every individual whose data we handle.
Our Legal Framework
BritHaven Tech Limited processes personal data in accordance with the following legislation and regulatory guidance:
- the primary legislative framework governing the processing of personal data in the United Kingdom following the UK's exit from the European Union.
- Data Protection Act 2018 (DPA 2018) โ the UK statute that supplements and gives effect to the UK GDPR and governs certain processing activities not covered by it.
- Privacy and Electronic Communications Regulations 2003 (PECR) โ which govern electronic marketing, the use of cookies, and related communications.
- Network and Information Systems (NIS) Regulations 2018 โ relevant to our obligations as a technology service provider in respect of cybersecurity and incident reporting.
We monitor regulatory guidance issued by the Information Commissioner's Office (ICO) and update our practices accordingly.
Our Role as Data Controller
BritHaven Tech Limited acts as the data controller in respect of personal data collected through our website, quote request process, and direct commercial relationships. As data controller, we determine the purposes and means of processing and bear
primary responsibility for ensuring that processing is lawful. In certain circumstances โ for example, where we process personal data on behalf of a client organisation โ we may act as a data processor. In such cases, processing is governed by a written Data Processing Agreement (DPA) in accordance with Article 28 of the UK GDPR.
Lawful Bases for Processing
We process personal data only where we have identified a valid lawful basis under Article 6 of the UK GDPR. The lawful bases we rely upon are as follows:
| Lawful Basis | Article Ref. | How We Use It |
|---|---|---|
| Performance of a Contract | Article 6(1)(b) | We process personal data where it is necessary to perform a contract to which the data subject is party, or to take steps at their request prior to entering into a contract. This applies to the processing of client contact details, order information, invoice management, and account administration. |
| Legitimate Interests | Article 6(1)(f) | We process personal data where it is necessary for our legitimate business interests, provided those interests are not overridden by the rights and freedoms of the data subject. We conduct Legitimate Interests Assessments (LIAs) in respect of all processing activities where this basis is relied upon, including direct marketing to existing business contacts and website analytics. |
| Legal Obligation | Article 6(1)(c) | We process personal data where necessary to comply with a legal obligation to which we are subject, including tax reporting, VAT record-keeping, anti-money laundering checks, and compliance with court orders or regulatory requirements. |
| Consent | Article 6(1)(a) | Where we rely on consent โ for example, in respect of non-essential cookies or certain marketing communications โ we ensure that consent is freely given, specific, informed, and unambiguous. Data subjects may withdraw consent at any time without detriment. |
Data Minimisation and; Core Principles
We apply all seven data protection principles set out in Article 5 of the UK GDPR to every processing activity we undertake:
All new data processing activities are reviewed by our Privacy team prior to implementation to ensure compliance with these principles.
Data Subject Rights
We respect and uphold the rights of all data subjects under the UK GDPR. We have established documented procedures for handling rights requests and aim to respond to all valid requests within one (1) calendar month. We do not charge a fee for exercising rights except in cases of manifestly unfounded or excessive requests.
Data Retention
We retain personal data only for as long as is necessary for the purpose for which it was collected, or as required by applicable law.
All personal data is subject to our Data Retention Schedule, which defines retention periods across all data categories and is reviewed at least annually.
Our standard retention periods are as follows:
- Quote request data (where no Order follows): 12 months from the date of the request.
- Order and contract records: 7 years from the end of the contractual relationship, in accordance with our legal and tax obligations.
- Marketing contact data: Until you withdraw consent or opt out, or until we determine the data is no longer relevant to our legitimate interests.
- Website analytics data: Up to 26 months, in line with standard analytics practice.
- Legal claims data: For the duration of any proceedings and up to 6 years thereafter, in accordance with the Limitation Act 1980.
- General correspondence and emails: 3 years, for business records and dispute resolution purposes.
Upon expiry of the applicable retention period, personal data is securely deleted or irreversibly anonymised in accordance with our documented disposal procedures. We conduct periodic audits of retained data to ensure ongoing compliance.
Data Security
We implement appropriate technical and organisational security measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Our security measures include:
Third-Party Processors & Vendor Relationships
As a technology reseller, BritHaven Tech operates within a supply chain that involves a number of third-party Vendors and service providers. We manage these relationships as follows:
Where we engage third-party processors (sub-processors) to process personal data on our behalf, we conduct appropriate due diligence and enter into written Data Processing Agreements in accordance with Article 28 of the UK GDPR. Sub-processors are permitted to process personal data only in accordance with our documented instructions and for no other purpose.
Where our Vendor partners act as independent data controllers in respect of data shared with them โ for example, to provision licences or activate cloud services โ we ensure that such sharing is disclosed in our Privacy Policy and that an appropriate lawful basis exists. Clients are directed to the relevant Vendor's privacy policy for details of their own processing activities.
We maintain an internal register of all sub-processors engaged in the processing of personal data. This register is reviewed and updated periodically. Clients who have entered into a Data Processing Agreement with us may request details of our current sub-processors by contacting dpo@brithaven.co.uk .
International Data Transfers
Where personal data is transferred outside the United Kingdom โ for example, to Vendor partners or cloud service providers based in other countries โ we ensure that appropriate safeguards are in place before any transfer takes place. The safeguards we rely upon include:
- UK Adequacy Regulations where the destination country has been assessed as offering an adequate level of data protection by the UK Secretary of State.
- UK International Data Transfer Agreement (IDTA) for transfers to countries without a UK adequacy decision, ensuring that equivalent protections apply contractually.
- UK Addendum to EU Standard Contractual Clauses where applicable, as an alternative transfer mechanism approved by the Information Commissioner's Office (ICO).
- Binding Corporate Rules (BCRs) where a Vendor has approved BCRs in place that cover transfers to the United Kingdom.
We do not transfer personal data to countries or territories that do not offer an adequate level of protection without first implementing one of the safeguards described above. Details of the specific safeguards applicable to any transfer are available upon request from dpo@brithaven.co.uk .
Records of Processing Activities
In accordance with Article 30 of the UK GDPR, BritHaven Tech maintains a Record of Processing Activities (RoPA). This document sets out, in respect of each processing activity:
- The categories of personal data processed and the categories of data subjects affected.
- The specific purpose of processing and the lawful basis relied upon.
- Any third-party recipients of the data, including sub-processors.
- Details of any international transfers and the safeguards in place.
- Applicable retention periods and disposal methods.
- A general description of the technical and organisational security measures in place.
Our RoPA is reviewed and updated at least annually, and whenever a new processing activity is introduced or an existing activity is materially changed.
Privacy by Design & Default
BritHaven Tech adopts a Privacy by Design and by Default approach in accordance with Article 25 of the UK GDPR. This means that data protection considerations are embedded into the design of new systems, processes, and products from the outset, rather than being applied retrospectively.
By default, we process only the minimum amount of personal data necessary for each specific purpose, and data is not made accessible to third parties without explicit justification. All new systems and processes undergo a privacy review prior to implementation. Our Privacy team is consulted at the design stage of any project involving personal data. Default settings across our systems are configured to collect and share the minimum data necessary.Data Protection Impact Assessments (DPIAs) are conducted for any processing activity that is likely to result in a high risk to the rights and freedoms of individuals.
Cookies & Electronic Marketing
We use cookies and similar technologies in accordance with the Privacy and Electronic Communications Regulations 2003 (PECR) and the UK GDPR. Non-essential cookies are only placed on users' devices with their prior, informed consent. Full details of the cookies we use and how consent is managed are set out in our Cookie Policy.
In respect of electronic marketing, we comply with PECR requirements by ensuring that marketing communications are sent only to individuals who have provided prior consent, or who are existing business contacts and have not opted out, in accordance with the soft opt-in exemption for B2B communications. All marketing emails include a clear and prominent unsubscribe mechanism.
Data Protection Impact Assessments
We conduct Data Protection Impact Assessments (DPIAs) prior to undertaking any processing that is likely to result in a high risk to the rights and freedoms of data subjects. This includes, but is not limited to:
- The introduction of new technologies or significant changes to existing systems that process personal data.
- Large-scale processing of personal data, particularly where special category data is involved.
- Systematic monitoring of individuals, including through website analytics or tracking technologies.
- Processing activities involving vulnerable individuals or children.
Where a DPIA indicates a high residual risk that cannot be mitigated through reasonable organisational or technical measures, we consult the ICO prior to commencing the relevant processing activity, in accordance with Article 36 of the UK GDPR.
Complaints & Regulatory Contact
If you have a concern about our data protection practices, we encourage you to contact us in the first instance so that we can seek to resolve the matter directly and promptly.
Review & Governance
This GDPR Compliance page, together with our Privacy Policy, Cookie Policy, and associated internal documentation, is reviewed at least annually by our Privacy team and updated to reflect any changes in applicable law, regulatory guidance, or our business practices.
This page was last reviewed and updated on 27 May 2025. BritHaven Tech's commitment to data protection is endorsed at Board level. Accountability for GDPR compliance rests with our designated Data Protection Officer / Privacy Contact, who reports directly to senior management and has the authority and resource necessary to carry out their responsibilities effectively. An out-of-cycle review is triggered by any material change to applicable law, ICO guidance, or our processing activities.