Legal · Privacy

Privacy notice

How TECH 52 LIMITED handles personal data, written to be read rather than to be defensible. If anything here is unclear, ask us and we will explain it plainly.

Last updated 31 August 2026 · Version 1.0

1. Who we are

TECH 52 LIMITED ("Tech 52", "we", "us") is the data controller for the personal data described in this notice. We are a private company limited by shares, registered in England and Wales with company number 17047936. Our registered office is 1 Gossington Close, Chislehurst, England, BR7 6TG.

For any question about this notice, or to exercise a right described in it, write to support@tech52.org. We are not required to appoint a data protection officer and have not appointed one; enquiries are handled by the company's director.

2. What we collect

We keep the collection deliberately narrow. In practice it amounts to:

  • Enquiry and correspondence data — your name, email address, any telephone number or organisation you choose to give, and the content of the messages you send us, including anything attached to them.
  • Client and project data — contact details for the people we work with, project documentation, meeting notes, credentials shared for a specific task, and the records needed to run an engagement.
  • Billing records — invoicing details, payment references and the accounting records that UK law requires a company to keep.
  • Technical logs — our hosting and email providers record standard server information such as IP address, timestamp, requested page or message metadata, for security and reliability purposes.

We do not buy contact lists, we do not enrich your details from third-party data brokers, and we do not ask for special category data. Please do not send us passwords, payment card numbers or sensitive personal information by email.

3. Why we use it, and on what lawful basis

  • To answer your enquiry and quote for work — legitimate interests (responding to someone who has contacted a business about its services), or steps taken at your request before entering a contract.
  • To deliver a project and support it afterwards — performance of our contract with you, or with the organisation you represent.
  • To invoice, keep accounts and meet statutory obligations — legal obligation, including the Companies Act 2006 and HMRC record-keeping rules.
  • To keep our systems and this website secure — legitimate interests in preventing abuse, fraud and service failure.
  • To send an occasional message about your live project — legitimate interests. We do not operate a marketing mailing list; if we ever start one it will be opt-in, and consent will be the basis for it.

4. This website

tech52.org is a static website. It sets no cookies of its own, runs no analytics product, no advertising tags, no session recording, no fingerprinting and no social media tracking pixels. Nothing you do on these pages is profiled.

The pages load typefaces from Google Fonts, which means your browser makes a request to fonts.googleapis.com and fonts.gstatic.com; Google will see your IP address and browser information as part of serving those files. Our web host also keeps standard access logs. The cookie notice explains both in more detail. If we ever introduce analytics, this notice and the cookie notice will be updated first and a consent mechanism added where the law requires one.

5. Who we share it with

We do not sell personal data, and we do not share it for anyone else's marketing. Data is shared only with suppliers who process it on our instructions in order to run the business, and with professional advisers or authorities where the law requires it. Those suppliers fall into a small number of categories:

  • Email hosting and the office software we use to write and store documents.
  • Website and application hosting, including backup and monitoring providers.
  • Accounting software and our accountant, for invoicing and statutory accounts.
  • Where a client engages us to manage advertising, the advertising platforms concerned — always within the client's own accounts, under the client's own agreements with those platforms.

6. International transfers

We prefer suppliers who store data in the United Kingdom or the European Economic Area. Some widely used providers process data elsewhere, including the United States. Where that happens we rely on the safeguards permitted by UK data protection law — an adequacy decision covering the recipient country or scheme, or the International Data Transfer Agreement or Addendum. Write to us if you would like to know which providers are involved in a particular engagement.

7. How long we keep it

  • Enquiries that do not become projects — up to 12 months from the last message, then deleted.
  • Client project records — for the life of the engagement and up to 6 years afterwards, which matches the limitation period for contract claims in England and Wales.
  • Accounting and tax records — 6 years after the end of the relevant financial year, as required by law.
  • Server and email logs — typically weeks to months, set by the provider's standard retention.

8. Security

Access to client systems and correspondence is limited to those who need it, protected by strong unique credentials and multi-factor authentication where the service supports it. Devices are encrypted and kept up to date. Credentials shared with us for a project are stored in a password manager, never in a spreadsheet or an email thread, and access is handed back or revoked at the end of an engagement.

No system is perfect. If a personal data breach occurs that is likely to result in a risk to people's rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it, and tell the people affected where the law requires it.

9. Your rights

Under the UK GDPR you have the right to be informed; to request a copy of the personal data we hold about you; to have inaccurate data corrected; to ask for erasure; to ask us to restrict processing; to data portability; and to object to processing carried out on the basis of legitimate interests. Where we rely on consent, you may withdraw it at any time without affecting what was done before.

Write to support@tech52.org. We will respond within one month, and will tell you if we need to verify your identity first. Exercising these rights is free of charge in all ordinary cases.

10. When we act for a client rather than as controller

When we build or run a portal, or manage advertising accounts, we often handle personal data that belongs to our client's users or customers. In those cases the client is the controller and Tech 52 is a processor: we act only on the client's documented instructions, under a written agreement containing the terms required by Article 28 of the UK GDPR.

If you are a member of the public who has used a portal we built for someone else, your request should go to that organisation as controller. Send it to us and we will forward it, but they, not we, decide the outcome.

11. Children

Our services are sold to organisations and this website is not directed at children. We do not knowingly collect personal data about children through it. If a client's portal is intended to be used by children, the additional obligations — including the Age Appropriate Design Code — are addressed within that project's own documentation.

12. Changes, and how to complain

If this notice changes materially we will update the version and date at the top of this page. The current version is shown there.

If you are unhappy with how we have handled your personal data, please tell us first — we would rather fix it. You also have the right to complain to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, or through ico.org.uk.