Privacy Notice
Your privacy means a lot to us. Learn how we collect, use, and protect your personal information.
01 About This Notice
At AA Techs, we understand the importance of your privacy and go to great lengths to ensure it is protected at all times.
This privacy notice tells you what to expect us to do with your personal information when you make contact with us or use one of our services, including IT support, DevOps solutions, and managed service provider (MSP) solutions.
This notice is provided in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Data Controller
AA Technology Solutions Ltd is the data controller responsible for your personal data.
| Company Name | AA Technology Solutions Ltd |
| Registered Address | Abbey House, 25 Clarendon Road, Redhill, Surrey, RH1 1QZ, United Kingdom |
| Contact Email | info@aatechs.co.uk |
| Telephone | 0203 488 3929 |
3. What Personal Information We Collect
When you interact with us in different ways, we may ask you for the following information:
- Personal and contact details (name, email address, telephone number, and address)
- Professional details (job title, company name, industry sector)
- Information related to service enquiries and project requirements
- Technical data (IP address, browser type, device information) for our services
- Information collected via cookies. Please refer to our Cookies Policy for more details on how we use cookies.
Special Category Data
We do not intentionally collect special category data (such as health information, religious beliefs, or biometric data) unless specifically required and with your explicit consent.
4. How and When We Collect Your Information
Directly From You
Most of the personal information we process is provided directly by you, including when you:
- Contact our business in relation to one or more of our services
- Request a quote for IT support, DevOps, or MSP services
- Attend an event hosted by us
- Provide your business card or contact details
- Submit your CV or apply for a position via a job board or our website
- Subscribe to our newsletter or marketing communications
Indirectly
We may also collect your information indirectly when:
- An employee provides your contact details as an emergency contact or referee
- We use publicly available internet resources to identify and contact individuals regarding relevant business opportunities
- Our monitoring tools process technical data as part of service delivery
- Third-party platforms where you have authorised the sharing of your data
5. Lawful Basis for Processing
Under UK GDPR, we must have a valid lawful basis to process your personal data. We rely on the following legal bases:
| Processing Activity | Lawful Basis |
|---|---|
| Delivering our IT and DevOps services | Performance of a contract |
| Responding to enquiries and providing quotations | Legitimate interests (to respond to potential clients) |
| Sending marketing communications (where consented) | Consent |
| Improving our services and website functionality | Legitimate interests (to improve user experience) |
| Complying with legal obligations | Legal obligation |
| Recruitment and processing job applications | Legitimate interests / Contract (pre-contractual steps) |
6. Why We Collect Your Information
Although our core IT services do not primarily revolve around collecting and processing personal data, we may process personal data as part of delivering our services to clients, including:
- Technical log data during system monitoring and support
- User activity data when required for troubleshooting
- Contact information for alert notifications and reporting
When acting as a data processor on behalf of our clients, we process data strictly according to their instructions and our data processing agreements.
7. How We Use Your Information
We may use the data you provide to:
- Deliver and improve our IT and DevOps services
- Optimise your client experience
- Process payments and manage accounts
- Send service updates, alerts, and important notifications
- Notify you of services or offerings that may be of interest to you (with consent)
- Provide technical support and system monitoring as contracted
9. How Long We Store Your Information
We retain personal information only for as long as necessary to fulfil the purposes for which it was collected.
Our standard retention periods include:
- Client records: 6 years after the end of the business relationship
- Marketing contacts: Until consent is withdrawn or 3 years of inactivity
- Job applications: 12 months from application date (unless employed)
- Service logs and technical data: As per client agreements, typically 12-24 months
In some cases, we may be required to retain data for longer periods to comply with legal or regulatory requirements.
10. Security and Confidentiality
As an IT services company, we take the protection of your data extremely seriously. All information provided will be stored securely and used only for the purpose for which it was provided.
Our security measures include:
- Encrypted storage and transmission of all personal data
- Access restricted to authorised personnel on a need-to-know basis
- Regular security assessments of our own systems
- Staff training on data protection and information security
- Incident response procedures for data breach management
- Physical security controls at our premises
11. International Data Transfers
We primarily store and process your data within the United Kingdom and European Economic Area (EEA).
Where we transfer personal data outside the UK/EEA, we ensure that appropriate safeguards are in place, such as:
- Transfers to countries with adequacy decisions from the UK government
- Standard Contractual Clauses (SCCs) approved by the ICO
- Other appropriate transfer mechanisms as permitted under UK GDPR
12. Links to Other Websites
Where we provide links to websites of other organisations, this privacy notice does not cover how those organisations process personal information. We encourage you to read the privacy notices on any external websites you visit.
13. Your Data Protection Rights
Under UK data protection law, you have rights that we must make you aware of. These include:
- Right of access: To request a copy of the personal information we hold about you
- Right to rectification: To request correction of inaccurate or incomplete information
- Right to erasure: To request deletion of personal information where legally applicable (the "right to be forgotten")
- Right to restrict processing: To request restriction of how we use your data
- Right to data portability: To receive your data in a structured, commonly used format where processing is based on consent or contract and carried out by automated means
- Right to object: To object to processing based on legitimate interests, direct marketing, or research purposes
- Right to withdraw consent: Where we rely on consent for processing, you may withdraw it at any time
- Rights related to automated decision-making: To not be subject to decisions based solely on automated processing that produce legal or significant effects
To exercise any of these rights, please contact us using the details below. We will respond to your request within one month of receipt. There is no fee for making a request, unless requests are manifestly unfounded or excessive.
14. Complaints
We take complaints about our privacy practices seriously. If you are unhappy with how we have handled your personal data, please contact us in the first instance, and we will endeavour to resolve your concerns.
Information Commissioner's Office (ICO)
You also have the right to lodge a complaint with the UK supervisory authority, the Information Commissioner's Office (ICO).
Website: www.ico.org.uk
Telephone: 0303 123 1113
Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
We would appreciate the opportunity to address your concerns before you approach the ICO, so please contact us first.
15. Contact Us
If you have any questions about this Privacy Notice, wish to exercise your rights, or have concerns about how we handle your personal data, you may contact us:
Get In Touch
Abbey House, 25 Clarendon Road
Redhill, Surrey, RH1 1QZ
United Kingdom
This Privacy Notice was last updated on 12 February 2026