Privacy Policy for Fortray Tech Ltd

Effective date: 1 September 2026

Privacy Policy Fortray Tech Mobile Banner Privacy Policy Fortray Tech Tablet Banner Privacy Policy Fortray Tech Desktop Banner

1. Introduction

FORTRAY TECH LTD ("Fortray Tech", "we", "our" or "us") respects your privacy and is committed to protecting personal data. This Privacy Policy explains how we collect, use, disclose, retain and protect personal data when you visit www.fortraytech.com, contact us, request a quotation, or use our IT, cybersecurity, cloud and technology services.

This policy applies where FORTRAY TECH LTD acts as a data controller. Where we process personal data on behalf of a business customer while delivering contracted services, that customer will normally be the data controller and we will act as its data processor.

2. Who We Are

FORTRAY TECH LTD is a company registered in England and Wales.

  • Company number: 16631478
  • ICO registration reference: ZC117358
  • Registered office: Unit G04 Mirror Works, 12 Marshgate Lane, London, Newham, E15 2NH, United Kingdom
  • Website: https://www.fortraytech.com
  • Email: [email protected]

For data protection purposes, FORTRAY TECH LTD is the controller of personal data collected through this website and through our own business operations, unless we tell you otherwise.

3. Scope of This Policy

This policy applies to personal data collected through our website and in connection with enquiries, quotations, contracts, account management, service delivery, technical support, security assessments, consultancy, events and marketing communications.

It does not govern personal data that we process solely under a customer's documented instructions. Such processing is governed by the applicable service agreement and, where required, a data processing agreement.

4. Personal Data We Collect

4.1 Information you provide

  • Identity and contact details, including name, job title, employer, business address, email address and telephone number.
  • Enquiry and commercial details, including requested services, project requirements, quotations, proposals and correspondence.
  • Contract and account information, including authorised contacts, service records, support tickets and billing details.
  • Marketing preferences, event registrations and communication choices.
  • Information you provide during calls, meetings, assessments, support sessions or incident response activities.

4.2 Information collected automatically

  • IP address, browser type and version, device type, operating system and approximate location derived from the IP address.
  • Website activity, including pages viewed, referral source, access dates and times, and interaction data.
  • Cookie identifiers and similar technology data, subject to your consent choices where consent is required.

4.3 Service delivery and security information

  • Support tickets, diagnostic data, device and configuration information.
  • System, network, firewall, authentication and security event logs.
  • Vulnerability assessment results, endpoint alerts, incident records and remediation information.
  • User and administrator account details required to provide authorised services.

We ask customers not to provide personal data that is unnecessary for the requested service. Where special category or criminal offence data is encountered during authorised work, we will handle it only where there is a valid legal basis and appropriate safeguards.

5. How We Collect Personal Data

  • Directly from you when you contact us, complete a form, enter into a contract or communicate with our team.
  • From your employer, organisation or an authorised business contact.
  • From systems, devices and platforms that you authorise us to access for service delivery.
  • Automatically through cookies, server logs and similar technologies.
  • From service providers, business partners, professional advisers, publicly available sources and regulatory or security sources where lawful.

6. How and Why We Use Personal Data

6.1 Enquiries, quotations and pre-contract steps

We use contact and requirement information to respond to enquiries, arrange consultations, prepare quotations and take steps requested before entering into a contract. The legal basis is taking steps at your request before a contract, performance of a contract, or our legitimate interests in developing and operating our business.

6.2 Delivering and managing services

We use customer, account, technical and support information to provide IT support, managed services, cybersecurity consulting, Microsoft 365, cloud, network, firewall, compliance and related technology services. The legal basis is performance of a contract, legitimate interests, and compliance with legal obligations where applicable.

6.3 Security, fraud prevention and incident response

We use technical, authentication and security information to protect our website, systems, customers and personnel; detect misuse; investigate incidents; manage vulnerabilities; preserve evidence; and support business continuity. The legal basis is our legitimate interests, the legitimate interests of customers, and legal obligations.

6.4 Administration, billing and legal compliance

We use account, transaction and correspondence information to manage contracts, invoicing, accounting, insurance, audits, legal claims and regulatory requirements. The legal basis is performance of a contract, legal obligation and legitimate interests.

6.5 Service improvement and analytics

We may analyse website and service usage information to understand performance, improve services and develop our business. We rely on legitimate interests for essential operational analysis and consent where non-essential cookies or similar technologies require consent.

6.6 Marketing communications

We may send relevant business-to-business service updates, security information, invitations and marketing where permitted by law. We rely on consent where required or legitimate interests where permitted. You can opt out at any time by using an unsubscribe link or contacting us.

7. Lawful Bases

Depending on the circumstances, we rely on one or more of the following lawful bases:

  • Contract: processing necessary to enter into or perform a contract.
  • Legal obligation: processing necessary to comply with a legal or regulatory requirement.
  • Legitimate interests: processing necessary for our legitimate business, operational or security interests, provided those interests are not overridden by your rights.
  • Consent: where you have given a clear choice and consent is required. You may withdraw consent at any time without affecting earlier lawful processing.
  • Vital interests: in rare circumstances, processing necessary to protect someone's life.

8. Customer Data and Our Role as a Processor

When we access or process personal data within a customer's environment solely to deliver authorised services, the customer ordinarily acts as controller and FORTRAY TECH LTD acts as processor. In that role, we will process data under documented instructions, apply appropriate technical and organisational safeguards, impose confidentiality obligations, assist the customer where contractually required, and use authorised subprocessors subject to appropriate terms.

Customers remain responsible for ensuring that their instructions are lawful, providing required notices to individuals, and establishing an appropriate lawful basis for the processing.

9. Sharing Personal Data

We do not sell personal data. We may share it only where necessary and lawful with:

  • Cloud, hosting, productivity, communication, customer relationship management, payment, accounting, security and technical service providers.
  • Professional advisers, including accountants, auditors, insurers and solicitors.
  • Business partners or subcontractors involved in delivering an authorised service.
  • Regulators, law enforcement bodies, courts, public authorities or other parties where disclosure is legally required or necessary to protect rights, security or prevent wrongdoing.
  • A buyer, investor or successor in connection with a genuine corporate transaction, subject to appropriate confidentiality and data protection safeguards.

Service providers may process personal data only for agreed purposes and under appropriate contractual and security requirements.

10. International Transfers

Some service providers may store or access personal data outside the United Kingdom. Where personal data is transferred internationally, we use an applicable lawful transfer mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another legally recognised safeguard. We may also apply supplementary contractual, technical and organisational measures where appropriate.

11. Data Retention

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including service delivery, support, accounting, legal, regulatory, insurance, dispute resolution and security requirements. Retention periods depend on the data type, contract terms, legal limitation periods, sensitivity, risk and whether continued retention is necessary. Personal data is securely deleted, anonymised or returned when it is no longer required, subject to legal and contractual obligations.

12. Information Security

We use proportionate technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure. Measures may include access controls, least privilege, multi-factor authentication, encryption, secure configuration, logging, monitoring, vulnerability management, backups, supplier controls, confidentiality commitments and staff awareness training.

No internet transmission or storage method is completely secure. You should use appropriate safeguards when communicating sensitive information and notify us promptly if you suspect unauthorised access connected with our services.

13. Cookies and Similar Technologies

Our website may use cookies and similar technologies that are necessary for operation and security, as well as optional technologies for preferences, analytics or marketing. Where required, optional cookies are used only after consent. You can manage or withdraw cookie consent through the consent controls available on the website and through your browser settings.

Please see our separate Cookie Policy for details of cookie categories, purposes, providers and retention periods.

14. Your Data Protection Rights

Depending on the circumstances and applicable law, you may have the right to:

  • Request access to your personal data.
  • Request correction of inaccurate or incomplete personal data.
  • Request erasure of personal data in certain circumstances.
  • Request restriction of processing in certain circumstances.
  • Object to processing based on legitimate interests and object at any time to direct marketing.
  • Request transfer of personal data where the right to data portability applies.
  • Withdraw consent at any time where processing is based on consent.
  • Ask for information about safeguards used for certain international transfers.
  • Complain to the Information Commissioner's Office.

These rights are not absolute and may be subject to legal conditions or exemptions. We may need to verify your identity before responding. We aim to respond within the period required by applicable law.

15. Complaints

Please contact us first so that we can try to resolve your concern. You also have the right to complain to the UK Information Commissioner's Office (ICO):

  • Website: https://ico.org.uk
  • Telephone: 0303 123 1113
  • Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom

16. Third-Party Websites

Our website may contain links to websites or services operated by other organisations. Their privacy practices are governed by their own policies. We are not responsible for third-party content, security or privacy practices.

17. Children's Privacy

Our website and services are primarily intended for organisations and business users and are not directed at children. We do not knowingly collect personal data from children through the website. If you believe a child has provided personal data to us, please contact us so that we can review and take appropriate action.

18. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes to our services, technology, legal requirements or business operations. The latest version will be published on this page with the revised "Last updated" date. Material changes may also be communicated through an appropriate additional notice.

19. Contact Us

For questions, privacy requests or concerns about this policy or our handling of personal data, contact:

  • FORTRAY TECH LTD
  • Company number: 16631478
  • ICO registration reference: ZC117358
  • Registered office: Unit G04 Mirror Works, 12 Marshgate Lane, London, Newham, E15 2NH, United Kingdom
  • Email: [email protected]
  • Website: https://www.fortraytech.com

Publication note: This policy should be reviewed against the website’s actual forms, cookies, analytics, marketing tools, service providers and international data flows before publication and whenever those arrangements materially change.