Privacy Policy
We take enterprise data sovereignty seriously. This policy outlines how CloudNet Technologies Limited protects, manages, and processes your proprietary business data and personal information.
We take enterprise data sovereignty seriously. This policy outlines how CloudNet Technologies Limited protects, manages, and processes your proprietary business data and personal information.
CloudNet Technologies Limited (“CloudNet”, “we”, “us” or “our”) is a private limited company registered in England and Wales under company number 14371617. Our registered office is 18 Alma Road, Manchester, England, M19 3NW. Our trading address is Unit 8B, Redfern Industrial Estate, Hyde, SK14 1RD.
This Privacy Policy explains how we collect, use, disclose, retain and protect personal information when you visit our website, contact us, receive business-to-business communications from us, purchase or use our products or services, or otherwise interact with CloudNet.
This policy applies to personal information for which CloudNet acts as a data controller. Where we process personal information solely on a customer’s documented instructions, CloudNet acts as a data processor and the customer remains the controller. In those circumstances, the relevant customer agreement, data-processing terms and the customer’s own privacy notice also apply.
We process personal information in accordance with the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (“PECR”), in each case as amended from time to time.
We design, develop, install, host, support and maintain business software and technology services, which may include:
For locally installed products, the primary database and document storage are normally held on hardware designated by the customer. CloudNet does not routinely access that information. We may access it only where the customer authorises access, requests installation or support, enables an agreed remote-access service, or where access is otherwise permitted by contract and law.
The information we collect depends on how you interact with us and which services you use.
Customers may use our products to process employee, worker, contractor, right-to-work, immigration, payroll, HR, compliance or other business records. The customer determines the purposes and means of that processing and is normally the controller. CloudNet is not the controller of that customer-controlled information merely because we supplied the software.
Where CloudNet receives or accesses customer-controlled personal information for installation, migration, support, hosting or maintenance, we process it only for the agreed service, under the customer’s documented instructions and subject to appropriate contractual and security controls.
We do not intentionally request special-category or criminal-offence information through our general website, sales or marketing channels. A customer may process such information within its own system where lawful. The customer is responsible for identifying an appropriate lawful basis, condition, retention period and access controls for that processing.
We may obtain personal information:
Where we obtain personal information from a source other than the individual, we provide privacy information within the period required by law, normally at the first communication and no later than one month after obtaining the information, unless a lawful exception applies.
We use personal information to respond to enquiries, prepare proposals, arrange demonstrations, enter into and administer contracts, install and configure products, provide support, process payments and manage customer relationships. Our lawful bases are normally performance of a contract, steps requested before entering a contract, and our legitimate interests in operating and supporting our business.
We process technical, authentication, log and account information to protect our website, systems, customers and users; detect misuse; investigate incidents; maintain backups; and ensure service continuity. Our lawful bases are our legitimate interests in securing our services and, where applicable, compliance with legal obligations.
We use information for accounting, tax, record-keeping, insurance, dispute resolution, legal claims, regulatory enquiries and compliance with lawful requests. Our lawful bases are legal obligation and our legitimate interests in protecting and administering our business.
We may use service, diagnostic and usage information to troubleshoot, measure performance, improve products and plan services. We use aggregated or anonymised information where reasonably possible. Our lawful basis is normally legitimate interests. Where cookies or similar technologies require consent, we rely on consent.
We may contact organisations and professional contacts about products or services that we reasonably believe may be relevant to their business. Where personal information is involved, our lawful basis is normally our legitimate interests in promoting relevant business services, subject to balancing those interests against the individual’s rights and expectations. Where PECR requires consent, we rely on valid consent or another applicable PECR exception.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
We may use publicly available business information to identify organisations that may have a genuine business interest in our software and technology services. Sources may include the UK Government register of licensed sponsors, Companies House, company websites, public professional profiles and business directories.
For corporate subscribers, such as limited companies and limited liability partnerships, PECR generally permits unsolicited business-to-business marketing email without prior consent. We will not conceal our identity and will provide a valid method to opt out in every marketing communication.
Sole traders, certain partnerships and other individual subscribers receive greater protection under PECR. We will not knowingly send unsolicited electronic marketing to those recipients unless we have valid consent or another lawful basis permitted by PECR, such as a valid soft opt-in.
Where a business email address identifies a person, the UK GDPR still applies. You have an absolute right to object to the use of your personal information for direct marketing at any time.
To opt out, reply to a marketing email with “unsubscribe” or email [email protected]. We will act on the request without undue delay and retain the minimum information needed on a suppression list so that we do not contact you again for marketing.
We do not sell personal information. If we use email-tracking pixels or similar technologies, we will do so only in accordance with PECR and applicable data-protection requirements.
Depending on the purpose, we rely on one or more of the following lawful bases:
When relying on legitimate interests, we consider whether the processing is necessary and whether your interests, rights or freedoms override our interests. You may request further information about a relevant legitimate-interests assessment by contacting us.
If information is required to enter into or perform a contract and you do not provide it, we may be unable to provide the requested product or service.
We share personal information only where necessary, proportionate and lawful. Recipients may include:
Service providers acting as processors must process personal information under contract, follow our documented instructions, keep the information secure and use it only for the agreed purposes. We remain responsible for selecting providers that offer appropriate safeguards.
We do not sell or rent personal information to data brokers or unrelated third parties.
Depending on the service and your choices, we may use or integrate with providers such as:
Third-party services operate under their own terms and privacy notices where they act as independent controllers. Where they process personal information on our behalf, we require appropriate contractual and security safeguards.
Links to external websites are provided for convenience. We are not responsible for the privacy practices of external websites and recommend that you read their privacy notices.
Some service providers or their support teams may be located outside the United Kingdom, or may make personal information accessible from outside the United Kingdom. Where this constitutes a restricted transfer, we use a lawful transfer mechanism and appropriate safeguards.
Depending on the circumstances, safeguards may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another mechanism permitted by UK law. We also assess the recipient, the destination, security arrangements and any supplementary measures required.
You may contact us for further information about the safeguards relevant to a particular transfer.
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, security and contractual requirements. Our typical retention approach is:
We may retain information for a longer period where necessary to establish, exercise or defend legal claims, investigate fraud or security incidents, comply with a legal hold, or meet a statutory obligation. When information is no longer required, we delete it securely or anonymise it.
We use cookies and similar technologies for website operation, security, session continuity, preferences, analytics and, where enabled, advertising.
Strictly necessary technologies may be used without consent where permitted by law. Non-essential analytics, advertising and similar technologies are used only after an appropriate consent choice where consent is required. You may manage your choices through our cookie controls.
Further information is available in our Cookies Policy.
We use appropriate technical and organisational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures may include:
No system can be guaranteed to be completely secure. We regularly review safeguards according to the nature of the information, available technology, implementation costs and the risks to individuals.
If we become aware of a personal-data breach, we will assess it and notify affected controllers, individuals or the Information Commissioner’s Office where required by law.
Subject to legal conditions and exemptions, you may have the right to:
To exercise a right, email [email protected]. We may need to verify your identity and clarify the request. We normally respond within one month, although the law allows additional time for complex or numerous requests.
Some rights are not absolute. We may lawfully refuse or limit a request and will explain the reason where the law permits us to do so.
CloudNet does not use personal information under this Privacy Policy to make decisions based solely on automated processing that produce legal or similarly significant effects on individuals.
Our products may include OCR, matching, alerts, reporting or workflow automation. These functions assist authorised users and do not replace the customer’s responsibility to review information, make decisions and comply with applicable law.
If we introduce solely automated significant decision-making, we will provide the information and safeguards required by law before doing so.
Our website and business services are intended for organisations and professional users and are not directed at children. We do not knowingly collect personal information directly from children for marketing purposes.
A customer may lawfully process information relating to children within a customer-controlled system, for example in an education, care or employment context. The customer is responsible for ensuring that such processing is lawful, transparent, proportionate and appropriately protected.
We may update this Privacy Policy to reflect changes in our services, technology, suppliers or legal obligations. We will publish the updated version on this page and change the effective or last-reviewed date.
Where a change materially affects how we use personal information, we will take reasonable steps to bring it to the attention of affected individuals where required.
For privacy enquiries, rights requests, marketing objections or complaints, contact:
Data Controller: CloudNet Technologies Limited
Company Number: 14371617
Registered Office: 18 Alma Road, Manchester, England, M19 3NW
Trading Address: Unit 8B, Redfern Industrial Estate, Hyde, SK14 1RD
Email: [email protected]
Telephone: 0161 710 4311
Website: https://cloudnettech.co.uk
We encourage you to contact us first so that we can try to resolve your concern.
You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority for data protection: