Privacy Policy

Privacy Policy

for Kent MSP Ltd

Introduction

Kent MSP LTD respects the privacy of its customers, suppliers and partners. We have therefore formulated and implemented a policy on complete transparency regarding the processing of personal data, its purpose(s) and the possibilities to exercise your legal rights in the best possible way. For employees, we have formulated a separate privacy policy, available upon employment and upon request.

This privacy policy pertains to processing by Kent MSP LTD by means other than through the use of cookies. Kent MSP LTD has formulated a separate cookie policy, which can be found on our Kent MSP LTD’s websites: https://www.kentmsp.co.uk/

Scope

This notice explains how Kent MSP LTD (“we”, “us”) collects, uses, shares and protects personal data when you visit our public website, submit forms, subscribe to our emails, or otherwise interact with our online services. It does not cover employee or supplier data—separate notices apply in those contexts.

Definitions

  • Party responsible for processing personal data: Kent MSP LTD; with registered address at Unit 8, St John’s Court, Ashford, Kent. TN24 0SJ; company registration number 13704042 (Registered in England & Wales) and Data Protection Officer James Howe who can be reached at James.howe@kentmsp.co.uk (the “Controller”).
  • Data Protection Authority: The Data Protection Authority of United Kingdom.

Data Protection laws:

For European citizens or residents, the EU GDPR 2018; the EU e-privacy directive 2002 (soon to be replaced by the EU e-privacy regulation);

  • For UK citizens or residents, the UK GDPR 2020 and the UK Data Protection Act 2018
  • and the national laws of the countries where we operate.

Who we are and how to contact us

  • Controller: Kent MSP LTD, Unit 8, St John’s Court, Ashford, Kent, TN24 0SJ, Company No. 13704042 (Registered in England & Wales).
  • General contact: operations@kentmsp.co.uk
  • Data Protection Officer (DPO): James Howe — DPO@kentmsp.co.uk

What data we collect via the website

  • Contact details (name, email address, phone number) and the content of your enquiry when you use our contact forms;
  • Account and service information if you register or request services;
  • Marketing preferences (e.g., newsletter sign-up, opt-in status);
  • Technical data (IP address, device identifiers, browser type/version, pages viewed, timestamps, and security logs);
  • Any information you choose to provide in free-text fields.

For information about cookies and similar technologies, please refer to our separate Cookie Policy available on our website

Sharing data with third parties

We may have to share your data with third parties, including third-party service providers. We require third parties to respect the security of your data and to treat it in accordance with the law.

We may transfer your Personal Data outside United Kingdom. If we do, you can expect a similar degree of protection in respect of your Personal Data.

We will only share your Personal Data with third parties in accordance with the GDPR and as outlined in the legal justification table above.

We share your personal data with the following enterprise third parties. We also share your data with SME third parties, details of which are available upon request. You will be notified when we have engaged with a new third party recipient of your personal data.

Purpose, lawful bases and retention

Processing activity

Typical data

Purpose

Lawful basis

Retention

Website enquiries and support

Name, email, phone, enquiry content

Respond to and manage your requests

Legitimate interests (efficiently handling enquiries), or contract where requests relate to services

12-24 months for enquiry periods

Account setup/ service delivery

Contact details, login, service metadata

Create and manage accounts; deliver requested services

Contract (performance and pre-contract steps)

Life of the account + 6 years (records of service)

Billing and invoicing

Billing name, address, invoice details

Issue invoices, collect payments, comply with tax duties

Legal obligation (tax, financial record-keeping)

6 years from financial year end

Email marketing to individuals

Email address preferences

Send news and updates about our services

Consent; or soft opt-in for existing customers for similar products/ services (PECR)

Until withdrawal/ opt-out (suppression list kept indefinitely to respect opt- outs)

Security and fraud monitoring

IP address, device and access logs

Protect our services and investigate suspicious activity

Legitimate interests (security of our services)

90 days for routine logs; longer if needed for investigations

We will rely on legitimate interests; we balance our interests against your rights and freedoms and document this in a legitimate interests assessment (LIA).

Where we get your data from

  • Directly from you when you submit forms, register an account, or communicate with us;
  • Indirectly from third parties (e.g., recruitment agencies) or public sources (e.g., professional networking sites) where permitted by law.

If we obtain personal data about you indirectly, we will inform you within one month (or at the first time we contact you), including the source and categories of personal data, unless an exemption applies.

Who we share data with (categories of recipients)

  • Website hosting and infrastructure providers;
  • Email service and marketing automation providers;
  • Customer relationship management (CRM) and ticketing tools;
  • IT security and monitoring providers;
  • Professional advisors (accountants, lawyers) and regulators, where required.

We require all recipients to protect personal data and act only under our instructions, and we put appropriate contracts in place with processors

International transfers

Where we transfer personal data outside the UK to countries without UK adequacy regulations, we use the Information Commissioner’s Office (ICO) standard mechanisms—either the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses—and we complete a Transfer Risk Assessment (TRA). We may apply supplementary safeguards such as encryption and pseudonymisation. Data transfers from the EEA to the UK are currently covered by EU adequacy decisions (subject to ongoing monitoring).

Retention periods

Category

Examples

Retention

Website enquires

Contact from messages, email threads

12-24 months

Account/ service records

Account details, service tickets

Account life + 6 years

Financial records

Invoices, payment records

6 years from FY end

Marketing preferences

Opt-in/ opt-out status

Kept until opt-out; suppression list retained indefinitely

Security logs

Access logs, IP addresses

90 days routinely; longer if required

Storage and protection of data

Your data is protected by Kent MSP LTD and its processors in pursuance to all legal requirements set by the relevant data processing laws. Kent MSP LTD has taken technical and organisational security measures to protect your data and requires its data processors to meet the same requirements. Kent MSP LTD has signed processing agreements with its processors to ensure an adequate level of data protection.

The following security measures are taken by Kent MSP LTD to protect your personal data in the course of the listed business processes:

Your rights

  • Right to be informed, access, rectification, erasure;
  • Right to restrict processing and to object;
  • Right to data portability;
  • Rights related to automated decision-making, including profiling.

To exercise your rights, contact operations@kentmsp.co.uk. We will respond within one month and may extend by two months where requests are complex. Requests are free of charge unless manifestly unfounded or excessive. You may also lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk or by post to Wycliffe House, Water Lane, Wilmslow, SK9 5AF. 

Organisational security measures

Staff

Kent MSP LTD staff members are required to conduct themselves in a manner consistent with Kent MSP LTD’s guidelines regarding confidentiality, business ethics, appropriate usage, and professional standards. All staff members undergo appropriate background checks prior to hiring and sign a confidentiality agreement outlining their responsibility in protecting customer data.

We continuously train staff members on best security practices, including how to identify social hacks, phishing scams, and hackers.

Access controls

Kent MSP LTD maintains your data privacy by allowing only authorized individuals access to information when it is critical to complete tasks for you. Kent MSP LTD staff members will not process customer data without authorization.

Data hosting

As a rule, data is hosted within countries and areas that provide a substantially similar level of protection as data subjects have under the GDPR. To ensure this, we rely on Adequacy Decisions as a legal basis for our international data transfers. In exceptional circumstances, where data is transferred to a country or area not subject to an Adequacy Decision, we rely on Standard Contractual Clauses with the recipient and take supplementary security measures to secure this data transfer, such as anonymisation.

Physical security

The data centres on which personal data is hosted are secured and monitored 24/7 and physical access to facilities is strictly limited to select staff.

Technical security measures

All devices which are used to access personal data for which we are responsible are secured with antivirus software, firewalls, encryption and access management. We regularly update operating systems and software to ensure vulnerabilities cannot be exploited.

We carry out regular vulnerability scanning of our website and have engaged credentialed external auditors to verify the adequacy of our security and privacy measures.

Marketing and PECR

We only send electronic marketing to individuals with your consent or under the “soft opt-in” (where you provided your details during a sale or negotiation for a similar product/service). Every message clearly identifies us and includes a free, simple unsubscribe. We also maintain suppression lists to ensure we respect opt-outs. For corporate subscribers, we follow good practice and honour objections.

Children’s data

Our website and services are not intended for children under 18. We do not knowingly collect children’s personal data. If we become aware that a child has provided personal data without appropriate consent, we will delete it or seek parental/guardian consent as appropriate.

Applicable law

These conditions are governed by the laws and regulations of the country where we are headquartered. The court in the district where we are headquartered has the sole jurisdiction if any dispute regarding these conditions may arise, save when a legal exception applies.

Updates to this notice

We review and update this notice regularly. Material changes will be highlighted on this page. The revision history is maintained in the document footer or history table.

Contact Us

Kent MSP Ltd

Unit 8, St John’s Court, Willesborough, Ashford, Kent, TN24 0SJ 

T: 01233 553010 

E: operations@kentmsp.co.uk

© Kent MSP. All rights reserved. Jan 2026 | Kent MSP Ltd | Company No: 13704042 | Registered in England & Wales | VAT Reg No: GB394346272