Privacy Policy
What information we collect, why we need it, and what we do with it — in plain English.
We keep this simple because you should be able to understand it. If anything here is unclear, email Help@ITSurgery.me and we will explain it.
Who we are
IT Surgery is a trading name of IT Solution Architecture Limited, a company registered in England and Wales (company number 12066050), registered office 8 Beechwood Close, Sully, Penarth, CF64 5WW.
We are the data controller for the information described here. For any privacy question, email Help@ITSurgery.me.
What we collect
- When you contact us. Your name, phone number, email address if you give one, and whatever you tell us about your problem — through the enquiry form, WhatsApp, email or over the phone. Enquiries made through the form are recorded in our customer records system so we can follow them up properly.
- When you book online. Your name, email address, phone number and what you tell us about the problem, so we can hold the slot, send your confirmation and reminders, and raise the invoice for the booking fee.
- When we do work for you. Notes about the job, what we did, and any details needed to fix the problem. For business customers, this may include information about your systems.
- During remote support. We see your screen while helping you. We do not record sessions unless you agree to it first.
- For invoicing. Billing details and payment records, which we must keep for tax purposes.
We do not build profiles of visitors, and we do not sell or share data for other people's marketing. Website analytics and advertising cookies are used only if you say yes to them — see Cookies below.
Cookies
The site works without cookies. Two things are stored on your device only to make the site work: your light-or-dark theme choice, and your answer to the cookie question, so we do not keep asking. Neither identifies you and neither leaves your device.
If you click "Yes, that's fine" on the cookie banner, we also switch on:
- Google Analytics — tells us which pages are visited and roughly where visitors come from, so we can see what is useful and what is not. IP addresses are shortened before they are stored.
- Google Ads measurement — if you arrived from one of our adverts, it lets Google tell us the advert led to a booking or an enquiry, so we do not waste money on adverts that do not work.
Until you answer, and if you click "No thanks" or ignore the banner, no analytics or advertising cookie is set and nothing is stored on your device. Google's measurement code still runs in a "no consent" mode, which sends only anonymous, cookieless counts (for example that a page was viewed) with no identifier that could link them to you or to a later visit. Google calls this consent mode; it is what lets us see whether adverts work without tracking people who have not agreed to it. You can change your answer at any time using Cookie settings in the footer of every page. Google's own privacy policy applies to what it does with the data: policies.google.com/privacy (opens in a new tab).
Why we are allowed to hold it
- To answer your enquiry — our legitimate interest in responding to someone who has contacted us.
- To do the work — performance of our contract with you.
- To keep accounts and invoices — a legal obligation under tax law.
- Analytics and advertising cookies — your consent, which you can withdraw at any time.
Who else sees it
We do not sell your information, ever, and we do not share it for marketing. A small number of suppliers process data on our behalf:
- Netlify — hosts this website and receives enquiry form submissions.
- Cal.com — runs our online booking calendar. When you book, it receives your name, email address, phone number and what you tell us about the problem, and it sends your confirmation and reminders. Remote sessions run over Cal Video, which is part of the same service.
- Xero — our accounting system. It raises your invoice and holds your name, email address and payment record.
- Stripe — takes the card payment for the booking fee. Your card details go straight to Stripe; we never see or store them.
- Microsoft — our email and files.
- WhatsApp (Meta) — if you choose to message us that way. Messages are covered by WhatsApp's own privacy terms as well as ours.
- Google — only if you accept cookies: analytics and advertising measurement, as described under Cookies above.
- OVHcloud — hosts our customer records system, where enquiries and job notes are stored.
- Our accountant — for invoices and tax records.
We may also disclose information if the law requires it.
How long we keep it
- Enquiries that don't become work — up to 12 months, then deleted.
- Customer and job records — for as long as you are a customer, and 6 years afterwards.
- Invoices and accounts — 6 years, as tax law requires.
- Recorded remote sessions — only made with your agreement, kept no longer than 90 days unless you ask us to keep your copy longer.
Keeping it safe
Your information is held in access-controlled accounts protected by multi-factor authentication, and transmitted over encrypted connections. Only Darren has access. We will never ask you for your banking passwords, and no genuine support session ever requires them.
Your rights
Under UK data protection law you can ask us to:
- Give you a copy of the information we hold about you
- Correct anything that is wrong
- Delete it, where we are not required to keep it
- Restrict or object to how we use it
- Provide it in a portable format
Email Help@ITSurgery.me and we will respond within one month. There is no charge.
Complaints
If you are unhappy with how we have handled your information, please tell us first and we will try to put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk (opens in a new tab) or on 0303 123 1113.
Changes
If we change this policy we will update this page. This version was published in September 2026.