Privacy Notice

animation-four

Privacy Notice

Last updated: 4th September 2026

1. About us

CJ Systems Limited (“CJ Systems”, “we”, “us” or “our”) is a managed IT services provider.

CJ Systems Limited is a company registered in England and Wales under company number 07269143.

CJ Systems Limited is registered with the Information Commissioner’s Office under registration number ZA254545.

Our registered office is:

CJ Systems Limited
Unit 4J, Westpark 26
Chelston
Wellington
Somerset
TA21 9AD

This Privacy Notice explains how we collect, use, store and protect personal information when you interact with us, use our website, enquire about or purchase our services, work with us as a supplier or business partner, or otherwise deal with CJ Systems.

For the personal information described in this notice, CJ Systems Limited will normally be the data controller.

There are also circumstances where we process personal information on behalf of our customers as a data processor. These circumstances are explained further in section 5.

For questions about this Privacy Notice, our use of your personal information, or to exercise your data protection rights, please contact:

Email: info@cjsystems.co.uk
Telephone: 01823 478515


2. The personal information we collect

The personal information we collect depends on how you interact with us.

It may include:

·         your name;

·         job title and organisation;

·         business address;

·         telephone number;

·         email address;

·         information you provide when completing forms on our website;

·         information contained in enquiries, quotations and correspondence;

·         customer and supplier account information;

·         billing, payment and transaction information;

·         information contained in support requests and service tickets;

·         records of communications with us;

·         information concerning devices, systems or services relevant to the IT services we provide;

·         IP addresses, device information and technical information generated when you access our website or services;

·         website usage and cookie information, where applicable; and

·         other personal information you choose to provide to us.

We generally do not need you to provide special category personal information, such as information about your health, ethnicity, religion or political opinions. Please avoid providing this type of information unless it is necessary for the matter you are contacting us about.

Because of the nature of IT support, we may occasionally encounter personal or sensitive information while troubleshooting or accessing a customer’s systems. Where we do so on behalf of a customer, we will normally be acting as their data processor rather than using that information for our own purposes.


3. How we obtain personal information

We may obtain personal information:

·         directly from you;

·         from the organisation you work for;

·         when you complete a form on our website;

·         when you telephone, email or otherwise communicate with us;

·         when you submit or participate in an IT support request;

·         through our customer, supplier and service-management systems;

·         from our technology and service providers;

·         from referrals or introductions;

·         from publicly available business information, such as company websites, Companies House or professional business directories; and

·         automatically when you use our website or certain services, for example through server logs and cookies.


4. How and why we use your personal information

We only use personal information where we have a lawful reason to do so.

Enquiries and quotations

We use your contact details and information about your requirements to respond to enquiries, discuss our services and prepare quotations or proposals.

Our lawful basis will normally be our legitimate interests in operating and developing our business or taking steps at your request before entering into a contract.

Providing our services

We use customer and business contact information to establish and manage customer relationships, deliver IT services, provide technical support, manage projects and communicate about the services we provide.

Our lawful bases may include performance of a contract, taking steps before entering into a contract, and our legitimate interests in providing and managing services to our business customers.

Customer support and service management

We may record information about technical issues, users, devices, systems, correspondence and the actions taken by our engineers in our service-management systems.

We do this because it is necessary to deliver our services, maintain accurate support records, manage customer relationships, ensure service quality and protect our customers and our business.

IT monitoring and security

Where relevant to services we provide or systems we operate, we may process technical information such as device identifiers, system status, security alerts, IP addresses, audit information and system logs.

We use this information to provide support, monitor service performance, detect and investigate security incidents, prevent fraud or misuse and maintain the security of our systems and services.

Our lawful basis is normally our legitimate interests in maintaining secure and reliable IT services and, where applicable, performance of our contractual obligations.

Billing and administration

We use contact, account and transaction information for invoicing, accounting, credit control and other business administration.

Our lawful bases include performance of a contract, compliance with our legal obligations, and our legitimate interests in managing our business.

Suppliers and business partners

We process the contact details of individuals working for suppliers, technology partners and other organisations with whom we do business.

We normally rely on our legitimate interests in establishing and managing business relationships.

Improving our services

We may use information about enquiries, support requests, service performance and customer feedback to monitor and improve our services, processes and customer experience.

We rely on our legitimate interests in improving and developing our business, provided those interests are not overridden by your rights and interests.

Legal and regulatory requirements

We may process personal information where necessary to:

·         comply with legal, regulatory or tax obligations;

·         establish, exercise or defend legal claims;

·         investigate suspected fraud, misuse or security incidents; or

·         respond to lawful requests from courts, regulators, law-enforcement bodies or other public authorities.

Our lawful basis will be compliance with a legal obligation or our legitimate interests, as appropriate.


5. Personal information we process on behalf of our customers

As a managed IT services provider, CJ Systems frequently provides services that involve processing personal information held by our customers.

For example, this may occur when we:

·         administer Microsoft 365 or other cloud services;

·         provide remote or onsite technical support;

·         administer servers, computers, networks and user accounts;

·         provide backup and disaster-recovery services;

·         provide IT monitoring, endpoint management or cybersecurity services;

·         migrate data between IT systems; or

·         investigate technical or security issues.

In these circumstances, the customer will normally determine why and how the personal information is used and will therefore be the data controller. CJ Systems will normally act as a data processor on the customer’s behalf.

We process such information only as necessary to provide the agreed services and in accordance with the customer’s instructions, our contractual obligations and applicable data-protection law.

If your personal information is held within the systems of one of our customers and you wish to exercise your data-protection rights in relation to that information, you should normally contact that customer directly. We will assist our customer with such requests where required.


6. Our legitimate interests

Where we rely on legitimate interests, those interests may include:

·         providing and managing high-quality IT services;

·         managing relationships with customers, prospective customers, suppliers and business partners;

·         maintaining appropriate records of communications and support activity;

·         securing our systems and those we manage on behalf of customers;

·         preventing fraud, misuse and cybersecurity incidents;

·         improving our services and business processes;

·         managing and developing our business; and

·         establishing, exercising or defending legal rights.

Before relying on legitimate interests, we consider whether our interests are proportionate and whether your rights, freedoms or reasonable expectations override those interests.


7. Marketing

We may contact existing or prospective business customers about CJ Systems services that we believe may be relevant to them.

Where we use personal information for direct marketing, we will do so in accordance with UK data-protection law and the Privacy and Electronic Communications Regulations (PECR).

Depending on the circumstances, our lawful basis may be legitimate interests or consent.

You have the right to object to direct marketing at any time.

If you ask us to stop sending marketing communications, we may retain limited information about you on a suppression list so that we can ensure your preference continues to be respected.


8. Who we share personal information with

We do not sell personal information.

Where necessary for the purposes described in this notice, we may share personal information with carefully selected third parties, including:

·         cloud computing and email service providers;

·         IT service-management and business-management system providers;

·         remote monitoring, cybersecurity, backup and other technology providers;

·         hosting and telecommunications providers;

·         software vendors and distributors where necessary to supply or support services;

·         payment, banking and accounting providers;

·         professional advisers including accountants, solicitors and insurers;

·         subcontractors or specialist service providers engaged by us;

·         regulators, courts, law-enforcement agencies or public authorities where required by law; and

·         prospective purchasers or advisers if CJ Systems is involved in a business sale, merger or restructuring.

We require service providers processing personal information on our behalf to protect that information appropriately and only use it for authorised purposes.


9. International transfers

Some of the technology and cloud services used by CJ Systems or our suppliers may involve personal information being processed outside the United Kingdom.

Where personal information is transferred internationally, we take steps to ensure that the transfer complies with UK data-protection law.

Depending on the destination and circumstances, this may include relying on:

·         UK adequacy regulations;

·         the UK International Data Transfer Agreement;

·         the UK Addendum to approved EU Standard Contractual Clauses;

·         other legally recognised safeguards; or

·         an applicable statutory exception.

Where required, we also assess the protection available in the destination country and the safeguards provided by the recipient.


10. How long we keep personal information

We do not keep personal information for longer than we reasonably need it.

The appropriate retention period depends on the type of information, why we hold it and any legal, contractual, security or operational requirements.

As a general guide:

Enquiries and prospective customer information
Normally retained for up to two years after our last meaningful contact, unless there is a reason to retain it for longer.

Customer account, contractual and service records
Normally retained throughout the customer relationship and for up to six years afterwards where necessary for contractual, legal, insurance or legitimate business purposes.

Support tickets and technical records
Retained for as long as reasonably necessary to provide support, maintain appropriate service records, investigate issues and meet contractual or legal requirements. Retention may vary according to the service and system concerned.

Financial and accounting records
Normally retained for at least six years, or for any longer period required by applicable law.

Marketing information
Retained while we have an appropriate reason to contact you. Where you opt out, we may retain sufficient information on a suppression list to ensure that we continue to respect your preference.

Security and system logs
Retained for a period appropriate to the relevant system and security purpose, taking into account the need to detect, investigate and respond to security incidents.

When information is no longer required, we will securely delete it, anonymise it or otherwise dispose of it appropriately.


11. Keeping personal information secure

We take the security of personal information seriously.

We use appropriate technical and organisational measures designed to protect information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

These measures include appropriate access controls, authentication, security monitoring, system protection, staff procedures and other technical and organisational controls appropriate to the information and risks involved.

No system can guarantee absolute security, but we regularly review our security arrangements and update them where appropriate.


12. Cookies and website information

Our website may use cookies and similar technologies to operate correctly, protect the website, remember preferences and, where applicable, understand how visitors use the site.

Cookies that are strictly necessary for the operation or security of the website may be used without consent where permitted by law.

Where consent is required for other cookies or similar technologies, we will ask for your consent before using them.

You can use the cookie controls provided on our website to manage your preferences.

Information about the particular cookies and similar technologies in use should also be provided through our website’s cookie information or consent-management system.


13. Your data-protection rights

Depending on the circumstances, you may have the right to:

·         ask us for a copy of the personal information we hold about you;

·         ask us to correct inaccurate or incomplete information;

·         ask us to delete your personal information;

·         ask us to restrict how we use your personal information;

·         object to our use of your personal information;

·         receive certain information in a portable format;

·         withdraw your consent where we rely on consent; and

·         object at any time to the use of your personal information for direct marketing.

These rights are subject to certain legal conditions and exemptions, so they do not apply in every circumstance.

You will not normally have to pay a fee to exercise your rights.

We may need to request information from you to confirm your identity before dealing with a request.

To exercise any of these rights, please contact us at:

info@cjsystems.co.uk


14. Automated decision-making

CJ Systems does not currently use personal information to make decisions based solely on automated processing that produce legal effects or similarly significant effects on individuals.

If this changes, we will update this Privacy Notice and provide the information required by data-protection law.


15. Data-protection complaints

If you have concerns about how CJ Systems has collected or used your personal information, please contact us in the first instance so that we have an opportunity to investigate and resolve the matter.

You can make a data-protection complaint by emailing:

info@cjsystems.co.uk

or by writing to:

CJ Systems Limited
Unit 4J, Westpark 26
Chelston
Wellington
Somerset
TA21 9AD

We will acknowledge receipt as soon as reasonably practical.

We will take appropriate steps to investigate the complaint without undue delay, keep you informed of progress where appropriate, and communicate the outcome to you without unjustifiable or excessive delay.

You also have the right to complain to the UK’s data-protection regulator, the Information Commissioner’s Office (ICO).

Information about how to make a complaint is available at:

www.ico.org.uk/make-a-complaint/


16. Changes to this Privacy Notice

We may update this Privacy Notice from time to time to reflect changes to our business, services, technology or legal obligations.

The current version will be published on our website and the “Last updated” date at the top of this notice will show when it was most recently reviewed.