Skip to Content

Privacy Notice

Last updated: 22 July 2026

Ryzon IT Solutions Ltd (“Ryzon IT”, “we”, “us” or “our”) is committed to protecting personal information and handling it responsibly, fairly and transparently.

This Privacy Notice explains how we collect, use, store and protect personal information when someone visits our website, contacts us, receives a business communication from us, or engages us to provide IT services.

1. Who We Are

Ryzon IT Solutions Ltd is the data controller responsible for the personal information described in this Privacy Notice.

Company name: Ryzon IT Solutions Ltd

Company number: 16901486

Email: support@ryzonit.co.uk

We provide managed IT services, Microsoft 365 support, cyber security services, IT infrastructure, consultancy, project work and related technology services to businesses.

2. Personal Information We Collect

Depending on how you interact with us, we may collect:

  • Your name.

  • Business or organisation name.

  • Job title or business role.

  • Business email address.

  • Business telephone number.

  • Business address.

  • Information contained in enquiries, emails, telephone calls or contact forms.

  • Contract, quotation, invoice and payment information.

  • Information required to provide IT support or complete an IT project.

  • Technical information relating to devices, systems, accounts, networks or support requests.

  • Records of communications between you and Ryzon IT.

  • The source from which we obtained your business-contact information.

  • Email delivery and engagement information, including delivery status, opens, link clicks and unsubscribe status where campaign tracking is enabled.

  • Website technical information such as IP address, browser type, device information, pages viewed and cookie or similar identifiers where applicable.

We do not intentionally collect special-category or sensitive personal information unless it is genuinely necessary to provide a service and appropriate arrangements have been agreed.

3. How We Collect Personal Information

We may collect personal information directly from you when you:

  • Submit an enquiry through our website.

  • Contact us by email, telephone or another communication channel.

  • Request a quotation or consultation.

  • Enter into a contract with us.

  • Communicate with us while we provide support or project services.

  • Subscribe to or request communications from us.

  • Attend a meeting, networking event or business introduction.

We may also obtain business-contact information from other sources, including:

  • Company and organisation websites.

  • Companies House.

  • Publicly available professional or business profiles.

  • Professional networking platforms such as LinkedIn.

  • Business directories.

  • Industry publications and press articles.

  • Referrals and business introductions.

  • Reputable business-information or contact-data providers.

Where we obtain information from another source, we record the source where reasonably possible.

Information being publicly available does not mean that we can use it without restriction. We only use publicly available business-contact information where we consider the use to be relevant, proportionate and reasonably expected in the circumstances.

4. How We Use Personal Information

We may use personal information to:

  • Respond to enquiries and requests.

  • Prepare quotations and proposals.

  • Provide and manage IT services.

  • Deliver IT support, infrastructure projects and consultancy.

  • Communicate with clients regarding services, support requests and projects.

  • Administer contracts, accounts, invoicing and payments.

  • Maintain service records and technical documentation.

  • Protect our systems, clients and business against security threats, fraud and misuse.

  • Improve our services, website and internal operations.

  • Maintain business relationships.

  • Identify businesses that may reasonably benefit from our services.

  • Send relevant B2B marketing communications.

  • Measure the delivery and effectiveness of our business communications.

  • Manage unsubscribe requests and marketing objections.

  • Establish, exercise or defend legal claims.

  • Meet our legal, regulatory, accounting and contractual obligations.

We will not use personal information for an incompatible purpose without providing further information and identifying an appropriate lawful basis.

5. Our Lawful Bases for Processing

We rely on one or more of the following lawful bases.

Contract and pre-contractual steps

We process information where it is necessary to:

  • Provide a quotation or proposal requested by you.

  • Enter into a contract.

  • Deliver agreed services.

  • Manage an existing client relationship.

Legitimate interests

We may process information where it is necessary for our legitimate business interests, provided those interests are not overridden by the rights and interests of the individual concerned.

Our legitimate interests include:

  • Operating and developing our business.

  • Providing and improving our IT services.

  • Maintaining relationships with clients, suppliers and business contacts.

  • Protecting our systems and business from security threats.

  • Keeping appropriate records.

  • Recovering money owed to us.

  • Identifying organisations that may have a relevant requirement for our services.

  • Conducting proportionate and targeted B2B marketing.

  • Measuring the effectiveness of business communications.

  • Maintaining suppression records so that marketing objections are respected.

Before relying on legitimate interests for targeted B2B marketing, we consider the relevance of our services to the organisation, the person’s professional role, the source of the information and the likely effect of the communication on that person.

Legal obligation

We process information where necessary to comply with legal, regulatory, accounting or tax requirements.

Consent

We rely on consent where consent is required by law or where we have specifically asked for it.

Where processing is based on consent, you may withdraw that consent at any time.

6. B2B Direct Marketing

We may contact businesses that we reasonably believe could benefit from our managed IT, Microsoft 365, cyber security, infrastructure or consultancy services.

Our marketing is intended to be:

  • Business-related.

  • Relevant to the recipient’s organisation or professional responsibilities.

  • Limited and proportionate.

  • Clearly identified as being from Ryzon IT.

  • Easy to opt out of.

For unsolicited electronic marketing, we generally target corporate subscribers such as limited companies and limited liability partnerships.

We will only send unsolicited electronic marketing to sole traders, individual subscribers or other organisations treated as individuals under electronic-marketing law where valid consent or another applicable legal exception allows us to do so.

Where we use the name or identifiable business email address of a particular employee or representative, that information is treated as personal information under UK data-protection law.

Our initial communication will identify Ryzon IT, explain the business reason for contacting the recipient, provide access to this Privacy Notice and include a straightforward way to unsubscribe.

We may use email-delivery or mail-merge technology, to manage campaigns, personalisation, delivery, unsubscribe requests and campaign engagement.

Where enabled, we may record whether an email was successfully delivered, opened or interacted with. We use this information to understand the effectiveness of our communications, improve their relevance and avoid repeatedly contacting businesses that are not interested.

Recipients may object to direct marketing at any time by:

  • Using the unsubscribe option within the email.

  • Replying to the email and asking not to be contacted.

  • Contacting support@ryzonit.co.uk.

There is no charge for objecting.

Once an objection or unsubscribe request is received, we will stop using the relevant personal information for direct-marketing purposes.

We may retain a limited suppression record containing information such as the email address and unsubscribe status. This is retained solely to ensure that the individual or organisation is not accidentally added to a future marketing campaign.

7. Sharing Personal Information

We may share personal information with trusted organisations where necessary to operate our business or provide our services, including:

  • Microsoft and other cloud-service providers.

  • Website, hosting and domain-service providers.

  • Email, communication and mail-merge providers.

  • IT management, remote-support, security and backup platforms.

  • Customer relationship management and business administration systems.

  • Accountants, legal advisers, insurers and other professional advisers.

  • Payment, banking and accounting providers.

  • Suppliers, contractors and subcontractors involved in delivering an agreed service.

  • Government bodies, regulators, law-enforcement agencies or courts where required by law.

These organisations are only provided with the information reasonably necessary for their role.

Where an organisation processes personal information on our behalf, we require it to protect the information appropriately and only process it in accordance with our instructions and applicable data-protection law.

We do not sell personal information.

We do not provide personal information to unrelated third parties for their own marketing purposes.

8. International Data Transfers

Some of the technology and cloud-service providers we use may process information outside the United Kingdom.

Where personal information is transferred internationally, we take reasonable steps to ensure that an appropriate legal transfer mechanism and suitable protections are in place.

These protections may include an adequacy decision, approved contractual safeguards or another lawful transfer mechanism.

Further information about the safeguards relevant to a particular service can be requested by contacting us.

9. Data Retention

We only retain personal information for as long as reasonably necessary for the purpose for which it was collected.

The retention period will depend on factors including:

  • Whether you are a client, former client, supplier or prospective business contact.

  • The nature and duration of our relationship.

  • Whether the information forms part of a contract, support record or project file.

  • Legal, regulatory, insurance, tax or accounting requirements.

  • Whether information may be required to establish, exercise or defend a legal claim.

Prospective-business contact information used solely for marketing will normally be reviewed and deleted where it is no longer relevant or there has been no meaningful engagement for an appropriate period.

Where an individual or organisation has objected to marketing, we may retain the minimum information necessary on a suppression list for as long as needed to ensure that the objection continues to be respected.

When personal information is no longer required, it will be securely deleted or anonymised.

10. Data Security

We use appropriate technical and organisational measures designed to protect personal information against:

  • Unauthorised access.

  • Accidental loss.

  • Inappropriate disclosure.

  • Alteration.

  • Misuse.

  • Destruction.

These measures may include:

  • Access controls and account-security measures.

  • Multi-factor authentication.

  • Secure cloud systems.

  • Device and endpoint security.

  • Encryption where appropriate.

  • Backup and recovery arrangements.

  • Restricted access based on business need.

  • Security monitoring and maintenance.

  • The use of reputable technology providers.

Although we take reasonable precautions, no internet-based system or transmission method can be guaranteed to be completely secure.

11. Your Data-Protection Rights

Depending on the circumstances, you may have the right to:

  • Request access to your personal information.

  • Request correction of inaccurate or incomplete information.

  • Request deletion of your information.

  • Request restriction of processing.

  • Object to processing based on legitimate interests.

  • Object to direct marketing.

  • Request transfer of information where data portability applies.

  • Withdraw consent where processing is based on consent.

  • Complain to the Information Commissioner’s Office.

The right to object to the use of personal information for direct marketing is an absolute right. When a valid objection is received, we will stop processing the information for direct-marketing purposes.

Some rights are subject to legal conditions and exceptions. For example, we may need to retain certain information to comply with a legal obligation or maintain a marketing suppression record.

To exercise your rights, contact:

Email: support@ryzonit.co.uk

We may need to request sufficient information to confirm your identity before dealing with certain requests.

12. Automated Decision-Making

We do not use personal information to make solely automated decisions that produce legal or similarly significant effects on individuals.

We may use basic business criteria to identify organisations that appear relevant to our services, such as their industry, location, size or likely technology requirements. Any resulting communication remains subject to the safeguards described in this Privacy Notice.

13. Complaints

Please contact us first if you have any concerns about how we use personal information. We will investigate and respond appropriately.

You also have the right to complain to the Information Commissioner’s Office, the UK regulator responsible for data protection.

Details of how to submit a complaint are available on the Information Commissioner’s Office website.

14. Changes to This Privacy Notice

We may update this Privacy Notice from time to time to reflect changes in:

  • Our services.

  • The technology providers we use.

  • Our marketing activities.

  • Our legal obligations.

  • Data-protection guidance or legislation.

The latest version will be published on our website with the relevant “last updated” date.