Privacy Policy
Discus Systems plc
Last updated: [Insert date]
Discus Systems plc (“we”, “us”, “our”) is committed to protecting your privacy. This policy explains how we collect, use, store and protect your personal data when you interact with us, use our services, or visit our website.
We are a data controller for the personal data we process.
Registered Office: Patrick Farm Barns, Meriden Road, Hampton-in-Arden, Solihull, B92 0LT
Contact: [email protected] or 01675 461 310
1. Personal data we collect
a) Information you provide to us
• Name
• Job title
• Email address
• Telephone number
• Company information
• Billing and payment details
• Messages, support requests and ticket information
b) Information we collect automatically
• IP address
• Browser and device information
• Remote monitoring and management data
• Security and audit logs
• Website usage analytics
c) Information collected during service delivery
• User accounts we manage
• Domain, email and network security data
• Backup and monitoring information
• Licensing and configuration data
• Security alerts and threat data
d) Information from third parties
• Technology vendors
• Referral partners
• Credit reference checks (where applicable)
2. How we use your personal data
We use personal data to:
• Deliver IT support, cybersecurity and consultancy services
• Manage contracts, renewals, subscriptions and accounts
• Monitor and secure systems we manage
• Communicate about service updates, incidents and support tickets
• Provide reports, alerts and technical recommendations
• Process invoices and payments
• Improve services and training
• Send marketing communications (only with consent)
• Meet legal, regulatory and financial obligations
3. Sharing your data
We may share your data with:
• Technology service providers (Microsoft, Heimdal, Sendmarc, Hornetsecurity, Acronis, SuperOps)
• Approved subcontractors working under data processing agreements
• Payment processors and accounting systems
• Domain registrars and DNS providers
• Regulators or legal authorities where required
We do not sell personal data.
4. International transfers
Some providers may process or store data outside the UK/EU.
Where this occurs, we ensure appropriate safeguards are in place.
5. Data retention
We retain data only as long as necessary:
• Account data – while active and up to 7 years after closure
• Ticket logs – typically 12 to 36 months
• Backups – according to the customer’s retention policy
• Marketing data – until you unsubscribe
• Job applications – up to 12 months unless otherwise agreed
Data is deleted or anonymised when no longer needed.
6. Your rights
You have the right to:
• Access the data we hold about you
• Request corrections
• Request deletion (in certain cases)
• Restrict or object to processing
• Request portability of your data
• Withdraw consent for marketing
• Complain to the Information Commissioner’s Office
To make a request, contact: [email protected]
7. Security of your data
We use a range of technical and organisational measures including:
• Multi-factor authentication
• Encryption
• Secure password management
• Endpoint protection and monitoring
• Role-based access controls
• Regular security testing and scanning
• Staff training and phishing simulations
• Supplier and processor agreements
8. Cookies
Our website may use cookies for functionality and analytics.
You can manage cookie settings through your browser.
9. Changes to this policy
We may update this policy periodically.
The latest version will be provided on request.
10. Contact
For any questions or data requests:
Data Protection Officer
Discus Systems plc
Email: [email protected]
Telephone: 01675 461 310