Home · Privacy
Legal
Privacy notice
How Lanrigson I-Tech Limited handles personal data — both the little we collect through this website, and the far more sensitive material that sits on a device left with us for repair.
1. Who we are
LANRIGSON I-TECH LIMITED ("we", "us", "the company") is a private company limited by shares, registered in England and Wales under company number 16720987, with its registered office at 3 Millfields Road, London, England, E5 0AA. We are the data controller for the personal data described in this notice.
Questions, requests and complaints about data protection should be sent to support@lanrigson.org or by post to the registered office above.
2. What this notice covers
There are two quite different kinds of personal data involved in what we do:
- Data you give us directly — your name, email address, the details of your enquiry, and the records created while we carry out work for you.
- Data that happens to be on your device — the documents, photographs, messages and accounts stored on a computer you leave with us. We do not seek this out, but a repair, migration or recovery necessarily brings us into contact with it.
3. Data we collect
3.1 When you contact us
- Your name and email address, and any telephone number or postal address you choose to give.
- The content of your message, including any photographs or files you attach.
- Where you are contacting us on behalf of an organisation, its name and your role.
3.2 When we carry out work
- Device details: make, model, serial number, condition on arrival and photographs taken at booking-in.
- Fault descriptions, diagnostic results, work performed, parts fitted and test results.
- Quotes, approvals, invoices and payment records (we do not store card details; payments are handled by our bank or payment provider).
- Any credentials you provide so that a device can be tested — held only for the duration of the job, and only where the job cannot be completed without them.
3.3 When you use this website
This is a static website. It sets no cookies, runs no analytics, contains no tracking pixels, no advertising technology and no contact form. The only third-party request the pages make is to Google Fonts, which serves the typefaces and, in doing so, receives your IP address and browser user-agent as part of an ordinary web request. Blocking that request leaves the site fully readable in your system fonts. Our hosting provider keeps standard server logs (IP address, timestamp, requested file) for security and troubleshooting; we do not use those logs to build any profile of visitors.
4. Why we use it, and our lawful basis
- To answer your enquiry — necessary for taking steps at your request prior to entering a contract, or our legitimate interest in responding to correspondence.
- To carry out the work — performance of our contract with you.
- To keep records of what was diagnosed, agreed and done — legitimate interest in being able to evidence our work, and to honour the warranty.
- To meet accounting and tax obligations — legal obligation.
- To keep our systems and premises secure — legitimate interest.
We do not use personal data for marketing. We do not sell, rent or share contact details with third parties for their own purposes, and enquiries are never added to a mailing list.
5. Data on devices left with us
This is the part that matters most, so it is set out plainly:
- We access files only where the work requires it — a data recovery, a migration, or verifying that a repaired machine boots and runs correctly.
- We do not read, copy, retain or disclose personal files beyond that necessity.
- Where a recovery or migration requires a working copy of your data, that copy is held on encrypted storage, kept only until you confirm you have everything, and then securely destroyed.
- Credentials supplied to test a device are used for that purpose only, are not written into any permanent record, and should be changed by you after the work is complete.
- Where we carry out secure erasure or dispose of equipment on your instruction, we confirm in writing what was erased or destroyed.
- If, in the course of work, we encounter material we are legally obliged to report, we will comply with that obligation. This is rare, and it is the only circumstance in which we would look further than the job requires.
Please back up your data before any repair. We take reasonable care, but a device arriving for repair is by definition already failing, and no repair can guarantee the survival of data on it.
6. Who we share data with
Only where it is needed to do the work or to run the company:
- Suppliers and manufacturers — where a part must be ordered or a warranty claim made, limited to the device and job details required.
- Specialist providers — for example a cleanroom data-recovery laboratory, where we have told you first and you have agreed.
- Our accountant, bank and payment provider — for invoicing, payment and statutory accounts.
- Our IT and hosting providers — email and website hosting, under contract and bound to confidentiality.
- Regulators, law enforcement or legal advisers — where we are required by law or need to establish or defend legal claims.
Where a provider is located outside the United Kingdom, transfers are made under the UK adequacy regulations or the International Data Transfer Agreement / UK Addendum, as applicable.
7. How long we keep it
- Enquiries that do not become jobs — up to 12 months, then deleted.
- Job records, quotes and work notes — 6 years from completion, to cover the warranty period and the limitation period for contract claims.
- Invoices and accounting records — 6 years after the end of the accounting period, as required by UK tax law.
- Working copies of recovered data — destroyed as soon as you confirm receipt, and in any case within 30 days of handover unless you ask us in writing to hold them longer.
- Credentials — deleted at completion of the job.
8. Security
Devices left with us are held in a locked workspace. Working storage is encrypted, accounts use multi-factor authentication where the service supports it, and access to job records is limited to those carrying out or invoicing the work. Equipment we dispose of on your behalf is erased to a recognised standard or physically destroyed. No measure is perfect, and we will tell you promptly — and notify the Information Commissioner's Office where required — if a breach affects your data.
9. Your rights
Under the UK GDPR you have the right to:
- be told how your data is used — this notice;
- request a copy of the personal data we hold about you;
- have inaccurate data corrected;
- ask for data to be erased, where we have no continuing legal or contractual reason to keep it;
- ask us to restrict processing, or object to processing based on legitimate interests;
- receive data you gave us in a portable format;
- withdraw consent, where consent was the basis for a particular use.
Write to support@lanrigson.org. We respond within one month. There is no charge unless a request is manifestly unfounded or excessive. We may need to confirm your identity before releasing data — particularly where a device or account is involved.
10. Complaints
If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, or at ico.org.uk.
11. Changes to this notice
We will update this notice when our practices change, and the version and date at the top of the page will change with it. Material changes affecting existing customers will be notified by email.