Legal

Privacy notice

How Prime Tech Technologies Ltd handles personal data under the UK GDPR and the Data Protection Act 2018. Written to be read, not to be scrolled past.

Last updated: 3 March 2026

1. Who we are

PRIME TECH TECHNOLOGIES LTD (“we”, “us”, “the company”) is a private company limited by shares, registered in England and Wales under company number 17066068, with its registered office at 1A Harrow Road, Newport, Gwent, NP19 0BU, United Kingdom.

We are the data controller for the personal data described in this notice. Questions, requests and complaints go to support@primetechltd.pro.

2. The short version

  • This website sets no cookies and runs no analytics or advertising trackers.
  • There is no contact form, so the site itself collects nothing about you.
  • We hold personal data only when you email us or become a client.
  • We never sell, rent or share your data for marketing, and we send no newsletters.
  • Enquiries that do not become engagements are deleted within twelve months.

3. What we collect, and why

a. When you email us

We receive your name, email address, whatever you choose to put in the message, and the technical headers your mail provider attaches. We use it to answer you and, if an engagement follows, to run it.

Lawful basis: legitimate interests (responding to an enquiry addressed to us), and, once a proposal is accepted, performance of a contract.

b. When you become a client

Contact details for the people we work with, notes and recordings of meetings where agreed in advance, documents you provide for review, and the records needed to raise and settle invoices.

Lawful basis: performance of a contract, and legal obligation for the accounting records.

c. Data encountered during an engagement

A technology assessment or security review may bring us into contact with personal data held in your systems — staff accounts, customer records, log files. Where that happens we act as a processor on your written instructions: we take the minimum required to answer the question, keep it only for the duration of the engagement, and destroy working copies at handover with written confirmation. Where required we will enter into a data processing agreement before access is granted.

d. Website visits

Our hosting provider records standard server logs — IP address, timestamp, page requested, user agent — for security and reliability. We do not use them to build a profile of you, and we do not combine them with anything else.

Lawful basis: legitimate interests (keeping the site available and secure).

4. What we do not do

  • No cookies, pixels, session recording, heat maps or fingerprinting.
  • No advertising networks and no remarketing of any kind.
  • No sale, rental or exchange of personal data with anybody.
  • No marketing emails or newsletters — we have no mailing list to add you to.
  • No automated decision-making and no profiling.

5. Who else sees your data

As few parties as possible. In practice: our email and hosting providers, who process data on our behalf under contract; our accountant, for invoicing and statutory records; and Google Fonts, which serves the two typefaces this site uses (see the cookie notice for what that involves and how to prevent it). We disclose data to anybody else only where the law requires it, or to establish or defend a legal claim.

6. Where your data is held

Primarily within the United Kingdom and the European Economic Area. Where a provider processes data outside the UK, we rely on UK adequacy regulations or the International Data Transfer Addendum to the EU Standard Contractual Clauses. We will tell you which providers are involved in your engagement if you ask.

7. How long we keep it

  • Enquiries that do not proceed: deleted within 12 months.
  • Client correspondence and project files: 6 years from the end of the engagement, matching the limitation period for contract claims.
  • Accounting records: 6 years from the end of the relevant financial year, as required by the Companies Act 2006.
  • Client system data seen during an engagement: destroyed at handover, with written confirmation.
  • Server logs: retained by the hosting provider on their standard short cycle.

8. Your rights

Under the UK GDPR you have the right to:

  • Be told what personal data we hold about you and receive a copy of it.
  • Have inaccurate data corrected.
  • Have data erased where we no longer have grounds to keep it.
  • Restrict our processing while a dispute about accuracy or grounds is resolved.
  • Receive data you gave us in a portable, machine-readable format.
  • Object to processing carried out on the basis of legitimate interests.
  • Withdraw consent at any time, where consent was the basis relied on.

Write to support@primetechltd.pro with “DATA REQUEST” in the subject line. We respond within one month and we do not charge for it. We may ask you to confirm your identity before disclosing anything.

9. Security

Access to client material is limited to those who need it for the engagement, protected by multi-factor authentication, and revoked when the stage closes. Devices are encrypted. Credentials you provide are never stored in plain text and are surrendered at handover. If a breach affects your rights and freedoms, we will notify you and the Information Commissioner's Office as the law requires.

10. Children

Our services are directed at organisations, not individuals, and we do not knowingly collect data about children. If you believe we hold such data, tell us and we will delete it.

11. Complaints

Please raise a concern with us first — we would rather fix it. You also have the right to complain to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, or via ico.org.uk.

12. Changes to this notice

If we change this notice we will update the date at the top of the page. Where a change materially affects people we hold data about, we will write to them directly rather than relying on them re-reading this page.

Questions about your data

Ask, and we will answer in writing.