Privacy notice
Last updated: 25 July 2026
1. Who we are
Argyle IT Consulting Limited (“we”, “us”) is a company registered in England and Wales, company number 08378973, registered office Ramsay Brown, The Brentano Suite, Solar House, 915 High Road, North Finchley, London N12 8QJ.
We are registered with the Information Commissioner’s Office under reference ZA275303.
This notice explains how we handle personal data for which we are the controller. It covers our website and our business relationships. It does not cover personal data we process on behalf of our clients — see section 9.
2. What personal data we collect
Enquiry data
If you contact us by email we hold your name, email address, any other contact details you provide, and the content of your message.
Client and supplier contact data
Where we work with an organisation we hold names, job titles, work contact details and correspondence relating to the engagement.
Website data
This website uses no analytics, no advertising and no third-party tracking, and makes no requests to third-party servers.
Our public pages set no cookies. When you sign in to the customer portal we set a cookie that keeps you signed in and maintains the state of your session. This cookie is strictly necessary to provide the service you have asked for, so under the Privacy and Electronic Communications Regulations we do not need to ask for your consent to set it. It is removed when your session ends. We do not use it for any other purpose.
Our hosting provider records standard server logs, which include IP addresses, for security and diagnostic purposes.
3. Why we use it and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Responding to enquiries | Legitimate interests — responding to someone who has contacted us |
| Delivering contracted services | Performance of a contract, or legitimate interests where our client is the contracting party |
| Maintaining business records | Legal obligation, and legitimate interests |
| Securing our systems and website | Legitimate interests — protecting our services from misuse |
Where we rely on legitimate interests we have considered whether those interests are overridden by your rights. You may object to processing on this basis — see section 7.
4. Who we share it with
We do not sell personal data and we do not use it for marketing. We share it only with:
- our IT and hosting suppliers, who act as our processors under written terms;
- Microsoft, as our provider of email and business productivity services, acting as our processor;
- our professional advisers, where necessary;
- regulators, law enforcement or other bodies where we are legally required to do so.
5. Where we hold it
Client systems
All systems we host, develop or maintain for clients, and all data held within them, are located in the United Kingdom.
Our own business systems
We use Microsoft cloud services for email, documents and internal administration. These are hosted within the European Economic Area. The UK Government has determined that EEA countries provide an adequate level of data protection, so no additional transfer safeguards are required for that hosting. Where Microsoft carries out support activity from outside the EEA this is governed by Microsoft’s data protection terms, which incorporate the UK International Data Transfer Addendum.
We do not transfer personal data to any other third country.
6. How long we keep it
- Enquiries that do not lead to an engagement: up to 12 months.
- Client and supplier records: for the duration of the relationship and for six years afterwards, consistent with the limitation period for contractual claims.
- Statutory financial records: six years from the end of the relevant accounting period.
- Website server logs: as set by our hosting provider, typically not more than 90 days.
7. Your rights
Under UK data protection law you have the right to ask us to give you a copy of your personal data; correct it if it is inaccurate; erase it in certain circumstances; restrict how we use it; object to processing based on legitimate interests; and receive it in a portable format where processing is by automated means and based on consent or contract.
To exercise any of these, email enquiries@argyleit.co.uk. We will respond within one month. We may ask you to confirm your identity first.
We do not carry out automated decision-making that produces legal or similarly significant effects.
8. Complaints
If you are unhappy with how we have handled your personal data please contact us first. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113.
9. Data we process on behalf of clients
In much of our work we act as a processor, not a controller. Where we host, develop or maintain a system for a client, that client remains the controller of the personal data within it and determines how it is used. Our processing is governed by a written agreement meeting the requirements of Article 28 UK GDPR.
If you are a patient, member of staff or other individual whose data is held in a system we operate for a client, you should direct requests and questions to that organisation. We will support them in responding.
10. Changes
We may update this notice. The date at the top shows when it was last revised.