Privacy Policy

Last Updated August 2026

We take the privacy, confidentiality and security of personal data seriously. This Privacy Policy explains how we handle personal data in connection with our website, consulting, data migration, tape conversion and related data-processing services.

1. Our Role as a Data Processor

When we receive, access, migrate, convert, recover, store or otherwise process data on behalf of a customer, we act as a Data Processor.

Our customer remains the Data Controller and determines the purposes for which the personal data is processed.

As a Data Processor, we process personal data only:

  • on the documented instructions of the Data Controller;

  • as necessary to provide the services agreed with the Data Controller;

  • in accordance with our contractual obligations;

  • subject to appropriate confidentiality and security measures; and

  • as otherwise required by applicable law.

We do not acquire ownership of customer data and do not use customer data for our own marketing, advertising or unrelated commercial purposes.

Where required, our processing activities are governed by a contract or Data Processing Agreement between us and the relevant Data Controller.

2. Data We May Process on Behalf of Customers

The nature of our services means that the information supplied to us may vary significantly between customers.

Depending on the service being provided, customer data may include:

  • databases and structured datasets;

  • archive records;

  • legacy system data;

  • tape and other legacy-media contents;

  • documents and electronic files;

  • business and organisational records;

  • names and contact details;

  • account or reference information; and

  • other personal data contained within information supplied to us by the Data Controller.

We do not determine what personal data a customer includes within data supplied to us for processing.

3. Why We Process Customer Data

We process customer data solely for the purpose of delivering the services requested by the Data Controller.

These activities may include:

  • data migration;

  • data extraction;

  • data conversion;

  • recovery of data from legacy media;

  • Quitter tape conversion;

  • archive conversion;

  • validation and integrity checking;

  • temporary storage required to perform a service;

  • technical troubleshooting; and

  • related consulting and support services.

We do not process customer data for purposes that are incompatible with the instructions of the Data Controller.

4. Confidentiality

Access to customer data is restricted to personnel and authorised service providers who require access for the performance of their duties.

Persons authorised to process customer data are subject to appropriate confidentiality obligations.

We take reasonable organisational and technical measures designed to prevent unauthorised access, disclosure, alteration, loss or misuse of personal data.

5. Data Security

We apply appropriate technical and organisational measures having regard to the nature of the information being processed and the risks associated with that processing.

Depending on the service and customer requirements, these measures may include:

  • access controls;

  • authentication controls;

  • secure data-transfer methods;

  • controlled processing environments;

  • encryption where appropriate;

  • restricted access to customer information;

  • backup and recovery procedures where applicable;

  • secure deletion processes; and

  • internal security and confidentiality procedures.

No system can guarantee absolute security. We nevertheless take reasonable measures appropriate to the nature and sensitivity of the data entrusted to us.

6. Data Retention and Deletion

Customer data is retained only for as long as reasonably necessary to provide the contracted service, satisfy documented customer instructions, comply with contractual requirements or meet applicable legal obligations.

At the completion of a project or termination of the relevant services, customer data will be returned or securely deleted in accordance with the applicable contract, Data Processing Agreement and customer instructions, unless applicable law requires us to retain it.

Temporary working copies may also be deleted in accordance with our operational retention and backup procedures.

7. Sub-Processors

Where necessary to provide our services, we may use carefully selected third-party service providers that process personal data on our behalf.

Where a third party acts as a sub-processor, we take appropriate steps to ensure that contractual data-protection and confidentiality obligations apply to that processing.

Where required by our agreement with the Data Controller, we will obtain appropriate authorisation before appointing or replacing a sub-processor.

8. International Data Transfers

Where customer personal data is transferred outside the United Kingdom, we will ensure that the transfer is made in accordance with applicable UK data-protection requirements and any contractual obligations agreed with the Data Controller.

Where required, appropriate safeguards will be used to protect personal data transferred internationally.

9. Data Subject Requests

Because we act as a Data Processor in relation to customer data, requests from individuals concerning personal data contained within customer datasets should normally be directed to the organisation that controls that data.

This may include requests relating to:

  • access;

  • correction;

  • deletion;

  • restriction;

  • objection;

  • portability; or

  • other rights available under applicable data-protection legislation.

If we receive a request relating to personal data that we process on behalf of a customer, we will, where appropriate, refer the request to the relevant Data Controller and provide reasonable assistance in accordance with our contractual and legal obligations.

We will not independently determine the outcome of a data-subject request where that decision is the responsibility of the Data Controller.

10. Personal Data Breaches

If we become aware of a personal data breach affecting customer data, we will take appropriate steps to contain and investigate the incident.

Where required, we will inform the relevant Data Controller without undue delay and provide reasonable information and assistance to enable the Data Controller to meet its obligations under applicable data-protection law.

11. Information You Provide Directly to Us

There are limited circumstances in which we may determine the purpose for which personal information is used rather than acting solely on a customer's instructions.

For example, this may occur when you:

  • contact us through our website;

  • send us an email;

  • request information about our services;

  • enter into a commercial relationship with us; or

  • provide business contact information for administrative, contractual or billing purposes.

For these limited activities, we may act as a Data Controller because we determine why that information is required and how it is used.

This is separate from our role as a Data Processor for customer data entrusted to us as part of the services we provide.

We will use such information only for legitimate business, administrative, contractual, security and legal purposes.

12. Website Information and Cookies

Our website may collect limited technical information required for its operation and security, such as IP addresses, browser information, device information and server logs.

Where cookies or similar technologies are used, additional information may be provided through our Cookie Policy or cookie-management interface.

We will obtain consent for cookies or similar technologies where consent is required by applicable law.

13. Sharing Personal Data

We do not sell customer personal data.

We may disclose information where reasonably necessary:

  • to provide services on behalf of a Data Controller;

  • to authorised sub-processors;

  • to comply with a legal obligation;

  • to establish, exercise or defend legal claims;

  • to protect the security or integrity of our systems; or

  • where instructed or authorised by the relevant Data Controller.

Any disclosure of customer data remains subject to our contractual and legal obligations.

14. Our Data-Protection Commitments

When acting as a Data Processor, we aim to:

  • process personal data only on documented instructions;

  • maintain appropriate confidentiality;

  • implement appropriate technical and organisational security measures;

  • control the appointment of sub-processors;

  • assist Data Controllers with relevant data-protection obligations where required;

  • assist with appropriate data-subject requests;

  • provide appropriate assistance following personal data breaches;

  • return or delete customer data at the conclusion of processing, subject to applicable requirements; and

  • provide information reasonably necessary to demonstrate compliance with our processor obligations.

15. Complaints

If you have concerns about how personal data is being processed as part of services we provide to one of our customers, you should ordinarily contact the relevant Data Controller first.

Where the matter concerns processing for which we are responsible, you may contact us using the details below.

Nothing in this Privacy Policy limits any statutory right you may have to raise a complaint with the Information Commissioner's Office (ICO) or another competent data-protection supervisory authority.

16. Governing Law and Disputes

This Privacy Policy and any non-statutory dispute arising from or relating to it shall be governed by the laws of England and Wales.

Subject to any rights or remedies that cannot lawfully be excluded or restricted, disputes relating to this Privacy Policy or our processing services will be managed in England and shall be subject to the jurisdiction of the courts of England and Wales.

Nothing in this section limits an individual's rights under applicable data-protection legislation, including the right to make a complaint to an appropriate supervisory authority or exercise any other statutory remedy.

17. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes to our services, business practices, legal requirements or data-protection guidance.

The latest version will be published on our website together with the date on which it was last updated.

18. Contact Us

Questions concerning this Privacy Policy, our data-processing practices or the security of personal data can be directed to our Contact Us page.

Where your enquiry relates to data that we process on behalf of one of our customers, please identify the relevant customer or service where possible so that we can determine the appropriate Data Controller.

Ready to Elevate your Data?

Contact us today

© 2026 Nephology Partners. All rights reserved.