Legal

Privacy Policy

Last updated: 15 July 2026

This privacy policy explains how MBITGROUP ("we", "us", "our") collects, uses, and protects personal data when you use this website or contact us about our IT services. We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who we are

MBITGROUP is the data controller for personal data collected through this website and related booking or enquiry forms.

  • Address: 9 Cemetery Road, Heckmondwike WF16 9QS, West Yorkshire
  • Email: [email protected]
  • Phone: 07823 332691

2. Personal data we collect

We may collect:

  • Identity and contact data — name, email address, telephone number, company name
  • Enquiry and booking data — message content, service interest, preferred appointment date/time, notes you provide
  • Technical data — IP address, browser type, and pages visited when privacy-friendly analytics are enabled and you have consented (where consent is required)
  • Communication records — emails and messages you send us in connection with a booking or enquiry

We do not intentionally collect special category data through this website. Please do not include sensitive health, biometric, or similarly sensitive information in forms unless we specifically ask for it for a supported service.

3. How we collect data

  • Directly from you via contact forms, quote requests, and consultation bookings
  • When you email or phone us using the details published on this site
  • Automatically via cookies or similar technologies where analytics are configured and consent has been given (or where cookies are strictly necessary)

4. Why we use your data

We use personal data to:

  • Respond to enquiries and quote requests
  • Schedule, confirm, remind, and manage consultations and appointments
  • Provide and administer IT services you engage us to deliver
  • Send service-related communications (for example booking confirmations and reminders)
  • Improve our website and understand aggregate usage (analytics, where enabled)
  • Comply with legal and regulatory obligations, and defend legal claims if required

5. Lawful bases

  • Contract / steps prior to contract — handling bookings, quotes, and delivering requested services
  • Legitimate interests — running and securing our business, responding to general enquiries, and keeping basic records of correspondence, where these interests are not overridden by your rights
  • Consent — non-essential cookies and analytics (where the cookie banner is enabled); you may withdraw consent at any time by clearing site data or contacting us
  • Legal obligation — where we must retain or disclose information to meet tax, accounting, or other legal requirements

6. Sharing your data

We do not sell your personal data. We may share it with trusted processors who help us operate the business, for example:

  • Hosting and infrastructure providers for this website and database
  • Email delivery providers used to send confirmation, reminder, and notification messages
  • Analytics providers (such as a self-hosted or managed Umami instance) when configured
  • Professional advisers (accountants, solicitors) where reasonably necessary
  • Authorities when required by law

Where processors are used, we take steps to ensure appropriate confidentiality and security protections are in place.

7. International transfers

Some service providers may process data outside the UK. Where that happens, we rely on appropriate safeguards recognised under UK data protection law (such as adequacy regulations or standard contractual clauses) where required.

8. How long we keep data

  • Enquiries — typically up to 24 months after the last meaningful contact, unless a longer retention period is needed for an ongoing relationship or claim
  • Bookings — for the life of the appointment record and a reasonable period afterwards (usually up to 24 months) for operational and dispute-resolution purposes
  • Customer / contract records — for the duration of the engagement and thereafter as required for accounting and legal retention (often up to 6 years)
  • Analytics — according to the analytics tool configuration, typically in aggregated or pseudonymous form

9. Cookies and analytics

Essential cookies may be used for basic site functionality (for example remembering cookie preferences). If analytics are enabled in our site settings, we may load a privacy-friendly analytics script (such as Umami) after you accept non-essential cookies via the banner — unless the banner is disabled, in which case analytics load according to our configuration.

You can decline non-essential cookies using the banner, or clear local storage / site data in your browser to reset your choice.

10. Your rights

Under UK GDPR you may have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Request erasure in certain circumstances
  • Restrict or object to processing in certain circumstances
  • Data portability where processing is based on consent or contract and is automated
  • Withdraw consent where processing is consent-based

To exercise these rights, contact us at [email protected] or via our contact page. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.

11. Security

We apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or misuse. No method of transmission or storage is completely secure; if you suspect a security issue involving your data, please contact us promptly.

12. Children

This website and our business services are aimed at organisations and adults. We do not knowingly collect personal data from children under 16 through this site.

13. Changes to this policy

We may update this policy from time to time. The "Last updated" date at the top of this page will change when we do. Continued use of the site after an update constitutes notice of the revised policy where permitted by law.