Who we are
Mike Windsor trading as Fractional IT Manager
https://fractional-it-manager.co.uk
Email: [email protected]
Phone: 07586 252979
Address: 60 Sherwood Avenue, Askern, Doncaster, South Yorkshire, DN6 0QL
Effective Date: 25/09/2026
At Fractional IT Manager, we are committed to protecting the privacy and security of our clients and website visitors. This Privacy Policy outlines how we collect, use, disclose and safeguard your information in compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Data (Use and Access) Act 2025 (DUAA).
1. Information We Collect
We may collect and process the following types of information:
- Personal Information: Name, contact details, company name, job title and billing information.
- Enquiry Information: The details you provide when you complete our contact form or email us, including your name, email address, company, phone number and message.
- Booking Information: When you book a consultation through our website, we collect your name, email address, phone number and any details you choose to share about your enquiry, along with the date and time of your appointment. Booking data is stored on our UK-hosted web server and used only to arrange and hold your consultation.
- Technical Information: IP address, device information, browser type and system logs.
- Service Usage Data: Details of services requested, support requests and interactions with our team.
- Spam Protection: Our contact form is protected by Cloudflare Turnstile, which processes technical signals such as your IP address and browser characteristics to confirm that submissions come from a real person.
- Cookies: Our website uses only the cookies needed for security and to operate the site. If you log in to the website, WordPress sets login cookies that last for two days (or two weeks if you select “Remember Me”) and are removed when you log out.
- Embedded Content: Pages on this site may include embedded content (e.g. videos, images, articles). Embedded content from other websites behaves in the exact same way as if you had visited the other website, and those websites may collect data about you, use cookies and monitor your interaction with that content.
2. Lawful Basis for Processing
We process personal data based on the following lawful grounds:
- Consent: When you provide consent for specific data collection and usage.
- Contractual Necessity: To fulfil our obligations in providing IT management and consultancy services, or to take steps at your request before entering into a contract.
- Legal Obligation: When required by law or regulatory requirements.
- Legitimate Interests: To respond to enquiries, and for cybersecurity, fraud and spam prevention, and service improvement.
3. How We Use Your Information
We use collected data for the following purposes:
- Responding to your enquiries
- Providing and managing our IT management and consultancy services
- Billing and account management
- Security monitoring and incident prevention
- Client support and communication
- Compliance with legal obligations
4. Your Rights Under Data Protection Law (UK GDPR & DUAA)
As a data subject, you have the following rights under the UK GDPR and the Data Protection Act 2018 (as amended by the DUAA 2025):
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request that we correct inaccurate or incomplete data.
- Right to Erasure (“Right to Be Forgotten”): Request the deletion of your data, subject to our legal or regulatory retention obligations.
- Right to Restrict Processing: Limit how we use your data in specific circumstances.
- Right to Data Portability: Receive your data in a structured, machine-readable format to move between services.
- Right to Object: Object to processing based on our “legitimate interests” or for direct marketing purposes.
- Rights Regarding Automated Decision-Making (ADM): Where we use AI or automated systems to make decisions with significant effects on you, you have the right to:
- Receive an explanation of the logic behind the decision.
- Make representations (provide your own input) regarding the data used.
- Request a meaningful human review to contest the outcome.
We will respond to requests within one month. If we need further information to identify you or clarify your request, we will let you know, and the time limit will be paused until we receive it.
5. Data Sharing & Third Parties
We do not sell your personal data. To provide our services, we may share information with:
- Trusted Service Providers: Third parties who perform operational functions (e.g. website hosting, email, and Cloudflare for website security and spam protection) under strict data processing agreements.
- Law Enforcement: Regulatory or legal authorities where we have a statutory obligation to disclose information.
- Business Partners: Only where you have provided consent or where it is necessary for the performance of a contract, subject to confidentiality.
- Automated Security: Form submissions may be screened by automated spam and fraud detection services to ensure the security of our website.
Where any provider processes data outside the UK, we ensure appropriate safeguards are in place, such as UK adequacy regulations or the International Data Transfer Agreement.
6. Data Security & Retention
We implement industry-standard security measures, including encryption, access controls and regular audits to protect your data. Personal data is retained only as long as necessary for legal, contractual or operational purposes. Enquiries that do not lead to an engagement are typically deleted within 12 months; client and financial records are retained for 6 years after the end of an engagement to meet legal and tax requirements.
7. Contact & Complaints
If you have concerns about how we handle your data or wish to exercise your rights, please contact us at:
Email: [email protected]
Phone: 07586 252979
Address: 60 Sherwood Avenue, Askern, Doncaster, South Yorkshire, DN6 0QL
To make a data protection complaint, please use our online complaints form. We will acknowledge complaints within 30 days and respond without undue delay. If you cannot use the online form, please call or write to us and we will be happy to provide a paper form or help you record your complaint.
If you believe we have not adequately addressed your concerns, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO): ico.org.uk/make-a-complaint.
8. Data Breach Response
We take data security seriously. In the event of a data breach, we follow a structured response process to minimise impact and ensure compliance with the UK GDPR and other relevant regulations.
Our Data Breach Protocol:
- Detection & Assessment: Immediate identification and assessment of the breach, determining the nature, extent and affected data.
- Containment & Mitigation: Securing systems to prevent further unauthorised access, and applying patches, updates or emergency security measures.
- Notification & Reporting: Notifying affected individuals where required, reporting the breach to the Information Commissioner’s Office (ICO) within 72 hours where it poses a risk to individuals’ rights and freedoms, and informing affected third parties and business partners.
- Investigation & Remediation: Determining the cause of the breach, implementing security improvements to prevent recurrence, and reviewing internal policies and incident response plans.
- Ongoing Monitoring & Compliance: Continuous security monitoring for vulnerabilities, with regular audits and training to ensure best practice.
9. Cybersecurity Measures
We employ rigorous cybersecurity protocols to safeguard your data from unauthorised access, loss or breaches.
Key Security Measures Implemented:
- Data Encryption: All stored and transmitted sensitive data is encrypted using industry-leading standards (e.g. AES-256, TLS/SSL).
- Access Control: Strict access policies, multi-factor authentication (MFA) and role-based permissions ensure only authorised personnel handle sensitive information.
- Network Security: Firewalls, web application protection and continuous monitoring mitigate cyber threats.
- Endpoint Protection: Advanced anti-malware and endpoint security solutions prevent unauthorised access to company devices.
- Regular Security Audits: Periodic security assessments and vulnerability scans strengthen defences.
- Incident Response Plan: A comprehensive strategy to identify, mitigate and recover from cybersecurity incidents efficiently.
- Secure Cloud Infrastructure: For clients using cloud services, we implement strict security controls, encryption and access policies.
- Backup & Disaster Recovery: Regular automated backups ensure business continuity in case of unforeseen incidents.
- Ongoing Compliance: We continually review and update our security practices to align with the UK GDPR and DUAA requirements for data protection and privacy.
By implementing these cybersecurity measures, we safeguard data integrity, confidentiality and availability.
