Privacy Policy
for Kent MSP Ltd
Introduction
Kent MSP LTD respects the privacy of its customers, suppliers and partners. We have therefore formulated and implemented a policy on complete transparency regarding the processing of personal data, its purpose(s) and the possibilities to exercise your legal rights in the best possible way. For employees, we have formulated a separate privacy policy, available upon employment and upon request.
This privacy policy pertains to processing by Kent MSP LTD by means other than through the use of cookies. Kent MSP LTD has formulated a separate cookie policy, which can be found on our Kent MSP LTD’s websites: https://www.kentmsp.co.uk/
Scope
This notice explains how Kent MSP LTD (“we”, “us”) collects, uses, shares and protects personal data when you visit our public website, submit forms, subscribe to our emails, or otherwise interact with our online services. It does not cover employee or supplier data—separate notices apply in those contexts.
Definitions
- Party responsible for processing personal data: Kent MSP LTD; with registered address at Unit 8, St John’s Court, Ashford, Kent. TN24 0SJ; company registration number 13704042 (Registered in England & Wales) and Data Protection Officer James Howe who can be reached at James.howe@kentmsp.co.uk (the “Controller”).
- Data Protection Authority: The Data Protection Authority of United Kingdom.
Data Protection laws:
For European citizens or residents, the EU GDPR 2018; the EU e-privacy directive 2002 (soon to be replaced by the EU e-privacy regulation);
- For UK citizens or residents, the UK GDPR 2020 and the UK Data Protection Act 2018
- and the national laws of the countries where we operate.
Who we are and how to contact us
- Controller: Kent MSP LTD, Unit 8, St John’s Court, Ashford, Kent, TN24 0SJ, Company No. 13704042 (Registered in England & Wales).
- General contact: operations@kentmsp.co.uk
- Data Protection Officer (DPO): James Howe — DPO@kentmsp.co.uk
What data we collect via the website
- Contact details (name, email address, phone number) and the content of your enquiry when you use our contact forms;
- Account and service information if you register or request services;
- Marketing preferences (e.g., newsletter sign-up, opt-in status);
- Technical data (IP address, device identifiers, browser type/version, pages viewed, timestamps, and security logs);
- Any information you choose to provide in free-text fields.
For information about cookies and similar technologies, please refer to our separate Cookie Policy available on our website
Sharing data with third parties
We may have to share your data with third parties, including third-party service providers. We require third parties to respect the security of your data and to treat it in accordance with the law.
We may transfer your Personal Data outside United Kingdom. If we do, you can expect a similar degree of protection in respect of your Personal Data.
We will only share your Personal Data with third parties in accordance with the GDPR and as outlined in the legal justification table above.
We share your personal data with the following enterprise third parties. We also share your data with SME third parties, details of which are available upon request. You will be notified when we have engaged with a new third party recipient of your personal data.
Purpose, lawful bases and retention
|
Processing activity |
Typical data |
Purpose |
Lawful basis |
Retention |
|
Website enquiries and support |
Name, email, phone, enquiry content |
Respond to and manage your requests |
Legitimate interests (efficiently handling enquiries), or contract where requests relate to services |
12-24 months for enquiry periods |
|
Account setup/ service delivery |
Contact details, login, service metadata |
Create and manage accounts; deliver requested services |
Contract (performance and pre-contract steps) |
Life of the account + 6 years (records of service) |
|
Billing and invoicing |
Billing name, address, invoice details |
Issue invoices, collect payments, comply with tax duties |
Legal obligation (tax, financial record-keeping) |
6 years from financial year end |
|
Email marketing to individuals |
Email address preferences |
Send news and updates about our services |
Consent; or soft opt-in for existing customers for similar products/ services (PECR) |
Until withdrawal/ opt-out (suppression list kept indefinitely to respect opt- outs) |
|
Security and fraud monitoring |
IP address, device and access logs |
Protect our services and investigate suspicious activity |
Legitimate interests (security of our services) |
90 days for routine logs; longer if needed for investigations |
We will rely on legitimate interests; we balance our interests against your rights and freedoms and document this in a legitimate interests assessment (LIA).
- Directly from you when you submit forms, register an account, or communicate with us;
- Indirectly from third parties (e.g., recruitment agencies) or public sources (e.g., professional networking sites) where permitted by law.
If we obtain personal data about you indirectly, we will inform you within one month (or at the first time we contact you), including the source and categories of personal data, unless an exemption applies.
Who we share data with (categories of recipients)
- Website hosting and infrastructure providers;
- Email service and marketing automation providers;
- Customer relationship management (CRM) and ticketing tools;
- IT security and monitoring providers;
- Professional advisors (accountants, lawyers) and regulators, where required.
We require all recipients to protect personal data and act only under our instructions, and we put appropriate contracts in place with processors
Where we transfer personal data outside the UK to countries without UK adequacy regulations, we use the Information Commissioner’s Office (ICO) standard mechanisms—either the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses—and we complete a Transfer Risk Assessment (TRA). We may apply supplementary safeguards such as encryption and pseudonymisation. Data transfers from the EEA to the UK are currently covered by EU adequacy decisions (subject to ongoing monitoring).
|
Category |
Examples |
Retention |
|
Website enquires |
Contact from messages, email threads |
12-24 months |
|
Account/ service records |
Account details, service tickets |
Account life + 6 years |
|
Financial records |
Invoices, payment records |
6 years from FY end |
|
Marketing preferences |
Opt-in/ opt-out status |
Kept until opt-out; suppression list retained indefinitely |
|
Security logs |
Access logs, IP addresses |
90 days routinely; longer if required |
Storage and protection of data
Your data is protected by Kent MSP LTD and its processors in pursuance to all legal requirements set by the relevant data processing laws. Kent MSP LTD has taken technical and organisational security measures to protect your data and requires its data processors to meet the same requirements. Kent MSP LTD has signed processing agreements with its processors to ensure an adequate level of data protection.
The following security measures are taken by Kent MSP LTD to protect your personal data in the course of the listed business processes:
- Right to be informed, access, rectification, erasure;
- Right to restrict processing and to object;
- Right to data portability;
- Rights related to automated decision-making, including profiling.
To exercise your rights, contact operations@kentmsp.co.uk. We will respond within one month and may extend by two months where requests are complex. Requests are free of charge unless manifestly unfounded or excessive. You may also lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk or by post to Wycliffe House, Water Lane, Wilmslow, SK9 5AF.
Organisational security measures
Staff
Kent MSP LTD staff members are required to conduct themselves in a manner consistent with Kent MSP LTD’s guidelines regarding confidentiality, business ethics, appropriate usage, and professional standards. All staff members undergo appropriate background checks prior to hiring and sign a confidentiality agreement outlining their responsibility in protecting customer data.
We continuously train staff members on best security practices, including how to identify social hacks, phishing scams, and hackers.
Access controls
Kent MSP LTD maintains your data privacy by allowing only authorized individuals access to information when it is critical to complete tasks for you. Kent MSP LTD staff members will not process customer data without authorization.
Data hosting
As a rule, data is hosted within countries and areas that provide a substantially similar level of protection as data subjects have under the GDPR. To ensure this, we rely on Adequacy Decisions as a legal basis for our international data transfers. In exceptional circumstances, where data is transferred to a country or area not subject to an Adequacy Decision, we rely on Standard Contractual Clauses with the recipient and take supplementary security measures to secure this data transfer, such as anonymisation.
Physical security
The data centres on which personal data is hosted are secured and monitored 24/7 and physical access to facilities is strictly limited to select staff.
Technical security measures
All devices which are used to access personal data for which we are responsible are secured with antivirus software, firewalls, encryption and access management. We regularly update operating systems and software to ensure vulnerabilities cannot be exploited.
We carry out regular vulnerability scanning of our website and have engaged credentialed external auditors to verify the adequacy of our security and privacy measures.
Marketing and PECR
We only send electronic marketing to individuals with your consent or under the “soft opt-in” (where you provided your details during a sale or negotiation for a similar product/service). Every message clearly identifies us and includes a free, simple unsubscribe. We also maintain suppression lists to ensure we respect opt-outs. For corporate subscribers, we follow good practice and honour objections.
Children’s data
Our website and services are not intended for children under 18. We do not knowingly collect children’s personal data. If we become aware that a child has provided personal data without appropriate consent, we will delete it or seek parental/guardian consent as appropriate.
Applicable law
These conditions are governed by the laws and regulations of the country where we are headquartered. The court in the district where we are headquartered has the sole jurisdiction if any dispute regarding these conditions may arise, save when a legal exception applies.
Updates to this notice
We review and update this notice regularly. Material changes will be highlighted on this page. The revision history is maintained in the document footer or history table.
Contact Us
Kent MSP Ltd
Unit 8, St John’s Court, Willesborough, Ashford, Kent, TN24 0SJ
T: 01233 553010
E: operations@kentmsp.co.uk
© Kent MSP. All rights reserved. Jan 2026 | Kent MSP Ltd | Company No: 13704042 | Registered in England & Wales | VAT Reg No: GB394346272