Last updated: 11 July 2026 · Version 2.0
This policy applies to all personal data processed by SOG-SYS Solutions Limited through this website (www.sog-syssolutions.co.uk) and in the delivery of our services to clients and prospective clients across the United Kingdom.
| Issued by | SOG-SYS Solutions Limited |
| Company Registration Number | 17073385 |
| Registered Office | 144 Meadfoot Road, Coventry, CV3 3DS |
| ICO Registration Number | ZC190136 |
| GDPR Officer | Gbaye Owolabi Samuel (MD & CEO) |
| GDPR Officer Email | samuel@sog-syssolutions.co.uk |
| GDPR Officer Phone | 07873 694110 |
| Governing Law | UK GDPR · Data Protection Act 2018 · Data Use & Access Act 2025 |
Introduction
Welcome to the Privacy & Data Protection Policy of SOG-SYS Solutions Limited (referred to as “SOG-SYS”, “we”, “us” or “our”).
SOG-SYS Solutions Limited has developed this privacy policy to ensure that your personal data, as a visitor to our website at www.sog-syssolutions.co.uk (the “Website”) or as a client or prospective client of our services, is collected, used, and protected securely, privately, and in full compliance with applicable UK data protection and privacy laws.
This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, how long we retain it, and the rights you have in relation to it under UK law. It should be read together with our Cookie Policy in Section 7 below.
The Website is not intended for children under the age of 16, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately using the details below so we can take appropriate action.
1. Important Information and Who We Are
Purpose of this policy
This policy tells you how SOG-SYS Solutions Limited collects and processes your personal data through your use of this Website, including any data you provide when you contact us through our contact form, book a free IT review, subscribe to our newsletter, or engage us to provide IT services.
Who we are
SOG-SYS Solutions Limited is the data controller responsible for your personal data. If you have any questions about this policy or our data protection practices, please contact our GDPR Officer using the details above.
Registration with the ICO
SOG-SYS Solutions Limited is registered as a data controller with the UK Information Commissioner’s Office. Our ICO registration number is ZC190136. You can verify our registration at ico.org.uk.
Complaints
You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues. We would, however, welcome the chance to address your concerns first. You can contact the ICO online at ico.org.uk/make-a-complaint, by post at Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, or by telephone on 0303 123 1113.
Third-party links
Our Website may include links to third-party websites, plug-ins and applications. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our Website, we encourage you to read the privacy policy of every website you visit.
2. The Data We Collect About You
Personal data means any information about an individual from which that person can be identified. Depending on our relationship with you, we may collect, use, store and transfer the following kinds of personal data:
| Data category | Examples |
|---|---|
| Identity Data | First name, last name, job title, company name, username or similar identifier. |
| Contact Data | Email address, telephone number, business address, billing address. |
| Technical Data | IP address, browser type and version, time zone setting and location, operating system and platform, device information and other technology on the devices you use to access this Website. |
| Usage Data | Information about how you use our Website, including pages visited, time spent, links clicked, and referral source. |
| Communications Data | The content of any message, enquiry, or request you submit to us through our contact form, email, or telephone. |
| Transaction Data | Details of services you have purchased from us, invoices, payment references, and transaction history. |
| Financial Data | Bank account or payment card details where relevant to the performance of a contract. These are processed securely and never stored in plain text. |
| Marketing & Preferences Data | Your preferences in receiving marketing and communications from us, and your communication preferences. |
| IT Environment Data | Where we provide IT managed services to you, we may process information about your IT systems, infrastructure, software, and users solely for the purpose of delivering those services under a separate service agreement. |
Special categories: We do not intentionally collect special category data (such as data about race, health, religious beliefs, or criminal convictions). Please do not include such information in communications to us; if you do, we will delete it promptly.
Aggregated data: We may collect and use aggregated statistical data for analytics. This is not personal data in law as it does not reveal your identity.
3. How Is Your Personal Data Collected?
Direct interactions
You may give us your personal data directly by completing our contact form, booking a free IT review, subscribing to our newsletter or requesting our free IT security checklist, corresponding with us by email, telephone or post, or entering into a service agreement with us.
Automated technologies
As you interact with our Website, we may automatically collect Technical Data and Usage Data using cookies, server logs and similar technologies (see Section 7). Where we use privacy-respecting analytics such as Google Analytics 4, data may be processed outside the UK, see Section 6.
Third parties and public sources
We may receive information about you from third parties or public sources, for example professional directories or LinkedIn in the course of business development (relating to your professional role), from partners who introduce you to us, or from public records such as Companies House.
4. How We Use Your Personal Data
We will only use your personal data when the law allows us to, most commonly to perform a contract with you, for our legitimate interests, to comply with a legal obligation, or with your consent. The table below sets out the ways we use your data and the lawful basis we rely on.
| Purpose / activity | Data types | Lawful basis |
|---|---|---|
| Respond to enquiries and contact form submissions | Identity, Contact, Communications | Legitimate interests (responding to requests made to us) |
| Book and conduct free IT reviews | Identity, Contact | Legitimate interests (pre-contract engagement) |
| Deliver contracted IT managed services | Identity, Contact, Technical, IT Environment | Performance of a contract with you |
| Issue invoices and process payments | Identity, Contact, Financial, Transaction | Performance of a contract / Legal obligation |
| Send our newsletter or resources (where requested) | Identity, Contact, Preferences | Consent (withdrawable at any time) |
| Send marketing communications to existing clients | Identity, Contact, Preferences | Legitimate interests (direct marketing to clients) |
| Improve and optimise our Website | Technical, Usage | Consent (via cookie preferences) |
| Maintain the security of our systems and Website | Technical, Usage | Legitimate interests (IT and network security) |
| Comply with legal, accounting and regulatory obligations | Identity, Contact, Financial, Transaction | Legal obligation |
| Resolve disputes and enforce our legal rights | All relevant data | Legitimate interests / Legal obligation |
Marketing
We may send marketing communications where you have requested information, engaged us for services, or otherwise consented. We always include a clear way to opt out. You may unsubscribe at any time by clicking the unsubscribe link in any marketing email, emailing samuel@sog-syssolutions.co.uk, or calling 07873 694110. Opting out of marketing will not affect service-related communications such as invoices or responses to your enquiries.
5. Disclosure of Your Personal Data
We may share your personal data with third parties who respect its security and process it only on our instructions, including:
- IT service and hosting providers (website hosting, email, cloud storage, IT infrastructure)
- Contact form and CRM platform providers, who process enquiry data on our behalf
- Email marketing platform providers, who distribute our newsletter and communications
- Analytics providers such as Google LLC (Google Analytics 4)
- Payment processing providers, to facilitate billing for our services
- Professional advisers including solicitors, accountants, auditors and insurers
- Regulators and public authorities such as HMRC, the ICO, or law enforcement, where required by law
No selling of data: We do not sell, rent, or trade your personal data to any third party for their own marketing or commercial purposes.
6. International Transfers
Some third-party providers may process personal data outside the UK or EEA. Where they do, we ensure appropriate safeguards are in place, such as UK Standard Contractual Clauses, the International Data Transfer Agreement (IDTA), or transfer to a country with a UK adequacy decision.
| Service | Country / region | Safeguard |
|---|---|---|
| Website analytics (e.g. Google Analytics 4) | USA (Google LLC) | EU Standard Contractual Clauses / Google Ads Data Processing Terms |
| Email delivery service | USA or EEA (provider dependent) | Standard Contractual Clauses / IDTA |
| Cloud storage | EEA / USA (Microsoft Azure or equivalent) | Microsoft Data Processing Agreement / SCCs |
7. Cookies
Cookies are small text files placed on your device when you visit a website. We do not use cookies to build advertising profiles or serve third-party adverts, and we will not place non-essential cookies on your device without your prior consent. You can block or delete cookies at any time through your browser settings, though this may affect parts of the Website.
| Category | Cookie / provider | Purpose | Duration |
|---|---|---|---|
| Strictly necessary | Session cookies (this Website) | Enable core website functionality, navigation and security | Session (deleted when browser closes) |
| Strictly necessary | CSRF / security tokens | Protect against cross-site request forgery attacks | Session |
| Analytics (consent required) | Google Analytics 4 (_ga, _gid) | Understand how visitors use the website: pages visited, time on site, traffic source | _ga: 2 years / _gid: 24 hours |
| Preferences | wp-settings (if WordPress) | Store your website preference settings | Up to 1 year |
8. Data Security
As a cyber security and managed IT provider, the security of personal data is central to everything we do. Our technical and organisational measures include:
- Encryption of data in transit (TLS/SSL) and at rest
- Multi-factor authentication (MFA) on all internal systems
- Role-based access controls, so data is accessible only to those who need it
- Regular security patching and vulnerability assessments
- Endpoint protection and real-time threat monitoring
- Secure, UK-based data storage
- Staff training in data protection and information security
- Annual review of all technical and organisational security measures
We have procedures to deal with any suspected personal data breach and will notify you and any applicable regulator where legally required under UK GDPR.
9. Data Retention
We only retain your personal data for as long as is reasonably necessary to fulfil the purposes for which we collected it, including any legal, accounting or reporting requirements.
| Data category | Retention period | Basis for retention |
|---|---|---|
| Contact form enquiries (non-clients) | 2 years from last contact | Legitimate interests (responding to and following up enquiries) |
| Client contract data (Identity, Contact) | 7 years post-contract end | Legal obligation (HMRC requirements, Limitation Act 1980) |
| Financial & transaction records | 7 years | Legal obligation (Companies Act 2006, HMRC) |
| IT service delivery data (client environments) | Duration of contract + 1 year | Performance of contract / Legal obligation |
| Marketing subscription data | Until unsubscribed + 6 years (suppression list) | Consent (active) / Legitimate interests (suppression) |
| Website analytics data | 26 months (Google Analytics default) | Consent (via cookie preferences) |
| Employee/contractor records (if applicable) | 7 years post-employment | Legal obligation (Employment law, HMRC) |
| Security logs and access records | 12 months | Legitimate interests (IT security monitoring) |
10. Your Legal Rights
Under UK data protection law (UK GDPR and the Data Protection Act 2018), you have the following rights:
| Your right | What this means |
|---|---|
| Right of Access | You can request a copy of all personal data we hold about you (a 'Subject Access Request'). We will respond within one month of receipt. |
| Right to Rectification | You can ask us to correct inaccurate or incomplete personal data we hold about you. |
| Right to Erasure ('Right to be Forgotten') | You can ask us to delete your personal data where we have no lawful reason to continue processing it, where you have withdrawn consent, or where we have processed it unlawfully. |
| Right to Restrict Processing | You can ask us to suspend processing of your personal data in certain circumstances, for example while you contest its accuracy or while we verify whether our legitimate interests override yours. |
| Right to Object | You can object to processing where we rely on legitimate interests, including for direct marketing. Where you object to direct marketing, we must stop immediately. |
| Right to Data Portability | You can request that we transfer your personal data to you or a third party in a structured, commonly used, machine-readable format. This applies where processing is based on consent or contract. |
| Right to Withdraw Consent | Where processing is based on your consent, you can withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal. |
| Right Not to Be Subject to Automated Decisions | You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects. We do not use such automated decision-making (see Section 11). |
| Right to Lodge a Complaint | You have the right to make a complaint to the ICO at any time: ico.org.uk / 0303 123 1113. |
How to exercise your rights
To exercise any of these rights, contact our GDPR Officer by email at samuel@sog-syssolutions.co.uk, by phone on 07873 694110, or by post at GDPR Officer, SOG-SYS Solutions Limited, 144 Meadfoot Road, Coventry, CV3 3DS. We will respond to all legitimate requests within one calendar month. You will not normally have to pay a fee, and we may need to verify your identity before processing your request.
11. Automated Decision-Making and Profiling
SOG-SYS Solutions Limited does not use your personal data to make any solely automated decisions that have legal or similarly significant effects on you, and we do not profile individuals in any such way. If this changes in future, we will update this policy and notify you of your rights.
12. Updates Under the Data Use & Access Act 2025
The UK Data Use & Access Act 2025 introduces updates to the UK data protection framework, including revised provisions on recognised legitimate interests and changes to the rules on automated decision-making. We are monitoring its implementation and ICO guidance, and will update this policy as relevant provisions come into force.
13. Contact Our GDPR Officer
For any questions, concerns, or requests relating to your personal data or this Privacy Policy:
Gbaye Owolabi Samuel, GDPR Officer / MD & CEO
SOG-SYS Solutions Limited · Company No. 17073385
144 Meadfoot Road, Coventry, CV3 3DS
Email: samuel@sog-syssolutions.co.uk · Phone: 07873 694110
Registered in England & Wales · ICO Registration: ZC190136