WIT Privacy and Cookies Notice

v2.0, 1 September 2026

Workshop IT Ltd, trading as WIT, is committed to protecting the personal information of the people who visit our website, enquire about our services, work for our clients and suppliers, or work for us. This notice explains what we do with personal data, on what legal basis, for how long we keep it and what you can ask us to do about it.

1. About this notice

1.1This notice is published by Workshop IT Ltd, registered in England and Wales under company number 08366747, whose registered office is Legacy Centre, Hanworth Industrial Estate, Hampton Road West, Feltham, Surrey TW13 6DH. We trade as WIT and are part of the Net Essence Group. In this notice, “we”, “us” and “our” mean Workshop IT Ltd.

1.2We are registered with the Information Commissioner's Office under registration reference ZA832559.

1.3This notice covers personal data we handle as a controller: information about visitors to our website, people who enquire about our services, contacts at our clients and suppliers, job applicants and anyone who contacts us. Section 2 explains the separate and important case of personal data we handle on behalf of our clients.

1.4This notice applies to our own website. Where we link to another organisation's website, that organisation's own notice applies and we are not responsible for it.

1.5For anything to do with this notice or your personal data, contact us using the details in Section 13.

2. When we are a controller and when we are a processor

This distinction matters more for a managed IT provider than for most businesses, so we set it out plainly.

2.1We are a controller for personal data we decide the purposes and means of processing: our website and analytics, our marketing, enquiries we receive, the administration of our client and supplier relationships, recruitment and our own employment records.

2.2We are a processor for personal data that sits inside the systems we manage, support or host for our clients. That includes mailboxes, files, directories, project data and support records belonging to a client. For that data the client is the controller. We act only on the client's documented instructions under our Standard Terms and the applicable data processing schedule. We do not use it for our own purposes.

2.3If you work for one of our clients and want to exercise your rights over personal data held in your employer's systems, please contact your employer. They are the controller and we will support them in responding. We cannot act on that data on our own initiative.

2.4Where we act as a processor, we appoint sub-processors only in line with the client's contract. We remain accountable to the client for them.

3. Personal data we process as a controller

The table below sets out what we process, why, the lawful basis under the UK GDPR and how long we keep it. Retention periods run from the date the relationship or record ends.

Data and examplesWhy we process itLawful basisRetentionWebsite usage data: IP address, approximate location, device and browser, pages viewed, referral source, timing and pattern of visitsUnderstanding how the site is used and improving it; keeping the site secureLegitimate interests (running and improving our website securely), assessed in IS07a. Where the data comes from non-essential cookies, consent under PECR26 months in analytics, then aggregatedEnquiry and contact data: name, employer, job role, email, telephone, postal address and what you asked us aboutResponding to you, preparing a proposal and keeping a record of what was discussedLegitimate interests, or steps taken at your request before entering a contract24 months from the last contact if no contract followsClient and supplier contact data: names, roles, business contact details, authorisations and approvalsDelivering and administering the services, service desk access, billing and account managementPerformance of a contract, plus legitimate interests for the wider relationship6 years after the end of the contract, matching the limitation periodService records: support tickets, correspondence, asset and licence records, access approvalsProviding support, evidencing what was done and to whose instruction, plus quality and security review under ISO 9001 and ISO 27001Performance of a contract, legal obligation, plus legitimate interests in maintaining auditable records6 years after the end of the contractMarketing data: your contact details and your preferencesSending you material you have asked for or that is closely related to services you have had from usConsent, or soft opt-in and legitimate interests where you have previously engaged with usUntil you withdraw, then a suppression record kept indefinitely so we do not contact you againRecruitment data: application, CV, right to work checks and interview notesAssessing your application and meeting our employment dutiesSteps before a contract, legal obligation, plus legitimate interests12 months after the outcome unless you ask us to keep it on fileRecords for claims, insurance and advice: any of the above where neededEstablishing, exercising or defending legal claims, obtaining insurance or professional adviceLegitimate interests, plus legal obligation where one applies6 years, or longer where a claim or professional liability period requires it

3.1We do not seek or knowingly collect special category personal data through our website. We do not sell personal data to anyone.

3.2Please do not send us other people's personal data unless we have asked you to or they have agreed.

4. Marketing

4.1We send marketing by email only where you have consented, or where you have previously engaged with us about a similar service and have not opted out. Every marketing email carries an unsubscribe link.

4.2We occasionally send marketing by post, relying on consent or legitimate interests.

4.3You can change your preferences or stop marketing entirely at any time, using the unsubscribe link in any of our emails or by emailing info@wit-support.uk. There is one route and it comes to us. We act on requests promptly and in any event within one month.

5. Cookies and website analytics

5.1A cookie is a small file placed on your device by a website. Some cookies last only for your visit, others remain until they expire or you delete them. Similar technologies such as local storage and tracking pixels work in comparable ways. Where we refer to cookies we mean those too.

5.2We use cookies and similar technologies in the following categories.

CategoryWhat it doesDo we need your consent?Strictly necessaryMakes the site work: page delivery, security, load balancing and remembering your cookie choicesNo. These are exempt, because without them the site cannot provide what you asked forAnalytics and performanceTells us how the site is used so we can improve it. We use Google Analytics for thisYesFunctionality and preferencesRemembers choices you make so the site behaves consistentlyYes

5.3We ask for your consent to non-essential cookies before we set them, through the banner shown on your first visit. You can change or withdraw your choices at any time using the cookie preferences link in the site footer. You can also block or delete cookies in your browser settings. Blocking all cookies will affect how this and most other websites work.

5.4Our website is hosted on Squarespace, which sets strictly necessary cookies to deliver and secure the site.

5.5We do not use cookies to serve advertising to you.

6. Who we share personal data with

6.1We share personal data only where we need to and only with organisations that are contractually bound to protect it. We assess every supplier that will handle personal data before we appoint them. We keep the current list in our Record of Processing Activities.

WhoWhySquarespaceWebsite hosting and the forms on itMicrosoftEmail, files, identity and collaboration in our own Microsoft 365 tenantOur service desk platformLogging and managing support requests, plus the customer support portalGoogleWebsite analytics, where you have consentedOur professional advisers, insurers and auditorsObtaining advice or insurance, plus independent audit of our management systemCredit reference agenciesCredit checks on business accounts, where we need to before offering termsA buyer or successorIf we sell all or part of the business, personal data may transfer with it, subject to the protections in this noticeLaw enforcement, regulators or courtsWhere we are legally required to disclose, or to establish or defend legal claims

7. Where your personal data is held

7.1We hold personal data in the United Kingdom and the European Economic Area wherever we can. We choose UK or EU data residency for our own systems where the option exists.

7.2Some of our suppliers process personal data outside the UK. Where that happens we rely on UK adequacy regulations, or on the International Data Transfer Agreement or the UK Addendum to the European Commission's standard contractual clauses, together with an assessment of the risk in the destination country.

7.3You can ask us which safeguard applies to a particular transfer using the details in Section 13.

8. How long we keep personal data

8.1The retention column in Section 3 sets out our normal periods. They come from our information classification and retention standard, which we review annually.

8.2We keep personal data no longer than we need it. Where we cannot fix a period in advance, we decide it by reference to how long the relationship is live, what any contract requires, what statutory limitation periods apply and whether a claim or investigation is reasonably in prospect.

8.3When a period ends we delete the data, or anonymise it so it can no longer be linked to you.

9. How we keep personal data secure

9.1We have been certified to ISO 27001 for information security management since 2018 and to ISO 9001 for quality management since 2023. Both certifications are audited independently. Information security is managed as a documented, reviewed discipline rather than a product we have bought.

9.2Our controls include multi-factor authentication, least-privilege access, managed endpoint protection, encryption in transit and at rest, monitored patching, tested backups, staff training, supplier assessment and a rehearsed incident response process. We are also Cyber Essentials certified.

9.3If a personal data breach occurs and it presents a risk to people, we report it to the Information Commissioner's Office within 72 hours of becoming aware of it and tell the people affected where the law requires. Where the breach concerns data we process for a client, we notify that client without undue delay so they can meet their own duties.

10. Artificial intelligence and automated decisions

We tell our clients to govern their use of AI, so we set out our own position here rather than leave you to ask.

10.1We use a small, deliberately chosen set of business-grade AI tools internally, mainly to speed up documentation, drafting and routine analysis. Every tool is assessed and recorded in our AI system inventory before use, with a named owner and a decision on what data may be used with it.

10.2A person always reviews AI-assisted output before it is relied on or sent to you. AI does not make decisions about your systems, your data or your account on its own.

10.3We do not put personal data or confidential client information into consumer or public AI tools. The tools we do approve are contracted so that your data is not used to train their public models.

10.4We do not make decisions about you by solely automated means that produce legal effects or otherwise significantly affect you, nor do we profile you in that way. If that ever changes we will tell you before it does and explain your rights.

10.5Our AI governance sits inside the management system already certified to ISO 27001 and ISO 9001. We are extending it to cover AI under ISO 42001, the international standard for AI management.

10.6Where we deploy or operate AI inside a client's environment, we do so as a processor on that client's instructions and under their governance, not our own.

10.7If you want to know whether and how AI was involved in something we produced for you, ask us and we will tell you.

11. Your rights

11.1You have the right to ask us for a copy of the personal data we hold about you, to have inaccurate data corrected, to have data erased where there is no good reason for us to keep it, to restrict how we use it, to object to processing we base on legitimate interests and to receive certain data in a portable form. You can withdraw consent at any time where we rely on it. You can object to direct marketing at any time with no reason needed.

11.2Exercising these rights is free. We respond within one month and tell you if we need longer because the request is complex.

11.3We may ask you for enough information to confirm your identity, so that we do not disclose your data to somebody else. We ask only for what is proportionate. We do not require certified documents.

11.4Some rights have limits. Where we cannot do what you have asked, we explain why and tell you how to challenge that.

11.5To make a request, use the details in Section 13.

12. Changes to this notice

12.1We review this notice at least annually and whenever our processing, our suppliers or our certifications change materially. The version and date are shown at the top.

12.2Where a change materially affects you, we tell people we hold contact details for rather than relying on you to check the page.

13. Contacting us and raising a complaint

13.1For any data protection question or request: email info@wit-support.uk, telephone +44 (0)20 7183 0498, or write to the Data Protection Contact, Workshop IT Ltd, Legacy Centre, Hanworth Industrial Estate, Hampton Road West, Feltham, Surrey TW13 6DH.

13.2If you are not satisfied with how we have handled your personal data or your request, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office at any time.

13.3Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. Telephone 0303 123 1113. Website ico.org.uk.