Last updated: 5 August 2026
1. Who we are
Pickle Concepts Limited is a company registered in England and Wales under company number 11380799.
We trade as Pickle Concepts and provide technology services including managed IT support, onsite technical services, audiovisual and workplace technology, infrastructure projects, service desk support, hardware procurement, maintenance, monitoring and related professional services.
Our registered office is:
Pickle Concepts Limited
66 Paul Street
London
England
EC2A 4NA
For the purposes of UK data protection law, Pickle Concepts Limited is generally the data controller for the personal information described in this Privacy Policy.
In some circumstances, we process personal information on behalf of our customers. In those cases, the customer is normally the data controller and Pickle Concepts Limited acts as a data processor under the terms of our agreement with that customer.
Questions about this Privacy Policy or our use of personal information can be sent to:
Email: info@pickleconcepts.com
Post: Privacy Enquiries, Pickle Concepts Limited, 66 Paul Street, London, EC2A 4NA
2. Purpose of this Privacy Policy
This Privacy Policy explains how we collect, use, store and disclose personal information when you:
- visit our website;
- contact us or submit an enquiry;
- request a proposal or quotation;
- purchase or use our services;
- work for, represent or supply one of our customers, partners or suppliers;
- communicate with our service desk;
- attend an event or receive marketing from us;
- apply for employment or contract work with us; or
- otherwise interact with Pickle Concepts Limited.
Our website and services are intended for business users and are not directed at children. We do not knowingly collect personal information relating to children through our website.
3. Personal information we collect
Depending on how you interact with us, we may collect the following categories of personal information.
3.1 Identity and contact information
This may include:
- name;
- title;
- employer or organisation;
- job title and department;
- work and personal email addresses;
- telephone numbers;
- postal and business addresses;
- usernames or account identifiers; and
- professional profile information.
3.2 Customer and commercial information
This may include:
- enquiries and correspondence;
- proposals, quotations and contracts;
- products and services purchased;
- customer account information;
- billing and delivery details;
- project requirements;
- service history;
- meeting notes;
- preferences and feedback; and
- information about your organisation’s technology environment.
3.3 Service desk and technical information
Where we provide IT, audiovisual, infrastructure, monitoring or support services, we may process:
- support requests and incident tickets;
- names and contact details of users;
- device names and identifiers;
- asset and serial numbers;
- IP addresses and network information;
- system logs and diagnostic information;
- user-account and access information;
- screenshots or error messages;
- communications relating to incidents;
- equipment assignment and asset records; and
- information required to investigate and resolve technical issues.
Where this information is processed on behalf of a customer, we will process it in accordance with the customer’s documented instructions and our contract with them.
3.4 Financial and transaction information
This may include:
- bank-account information;
- payment details;
- invoices;
- payment history;
- purchase orders;
- tax information; and
- details of transactions with us.
We do not generally store full payment-card details. Where card payments are offered, they will normally be processed by an authorised payment provider.
3.5 Website and device information
When you use our website, we may collect:
- IP address;
- browser type and version;
- device and operating-system information;
- approximate location;
- referring website;
- pages viewed;
- links clicked;
- dates and times of visits;
- website interactions;
- cookie identifiers; and
- other technical and usage information.
3.6 Marketing information
This may include:
- marketing preferences;
- communication preferences;
- records of emails sent;
- email opens and link clicks, where tracking is enabled;
- event attendance;
- areas of professional interest; and
- previous interactions with our marketing content.
3.7 Supplier, contractor and engineer information
This may include:
- business and personal contact information;
- qualifications and work history;
- technical skills;
- availability;
- rates and payment details;
- insurance information;
- right-to-work information;
- identity-verification records;
- references;
- screening information;
- contractual records; and
- performance and assignment information.
3.8 Recruitment information
If you apply to work with us, we may collect:
- CV and application information;
- contact details;
- employment history;
- qualifications;
- interview notes;
- salary or rate expectations;
- availability and notice periods;
- references;
- right-to-work documentation;
- identity information;
- information from recruitment agencies; and
- role-appropriate background-screening information.
We may collect criminal-offence or other sensitive information only where it is necessary, lawful and proportionate to the role.
4. How we collect personal information
We collect personal information through the following sources.
4.1 Information provided directly by you
You may provide information when you:
- contact us;
- submit a website form;
- request a proposal;
- enter into a contract;
- contact our service desk;
- attend a meeting or event;
- subscribe to communications;
- provide feedback;
- apply for a role; or
- work with us as a supplier, contractor or partner.
4.2 Information provided by your organisation
Customers, employers, partners and suppliers may provide information about their personnel so that we can deliver services, manage projects, administer contracts or provide technical support.
4.3 Information generated through service delivery
We may generate records through:
- service desk tickets;
- monitoring systems;
- project documentation;
- asset-management systems;
- site visits;
- technical assessments;
- meeting notes;
- reports; and
- correspondence.
4.4 Third parties and public sources
We may receive personal information from:
- customers;
- suppliers and technology vendors;
- recruitment agencies;
- professional advisers;
- referral partners;
- business-information providers;
- professional networking platforms;
- Companies House;
- publicly available company websites; and
- other legitimate public sources.
4.5 Automated website technologies
Our website may collect information through cookies, server logs, analytics tools and similar technologies.
Further information should be provided through our cookie banner and, where applicable, a separate Cookie Policy.
5. How we use personal information
We may use personal information to:
- respond to enquiries;
- prepare proposals and quotations;
- enter into and manage contracts;
- provide IT, audiovisual and infrastructure services;
- deliver onsite and remote technical support;
- operate our service desk;
- manage incidents, service requests and escalations;
- manage customer and supplier relationships;
- procure and deliver hardware and services;
- administer user accounts and access;
- maintain asset and equipment records;
- monitor service quality and performance;
- produce operational and service reports;
- invoice customers and process payments;
- manage our finances and insurance;
- maintain security and prevent fraud;
- investigate complaints or disputes;
- manage suppliers, contractors and engineers;
- recruit employees and contractors;
- improve our website and services;
- conduct business development and marketing;
- comply with legal, regulatory and contractual requirements;
- establish, exercise or defend legal claims; and
- protect our business, customers, personnel and systems.
6. Our lawful bases for processing
We must have a lawful basis whenever we process personal information. The lawful basis depends on the activity concerned. The ICO requires organisations to identify and communicate both their purposes and lawful bases. (ICO)
We normally rely on the following bases.
6.1 Contract
We process information where this is necessary to:
- take steps at your request before entering into a contract;
- provide contracted products or services;
- administer a customer or supplier agreement;
- process payments; or
- fulfil our contractual obligations.
6.2 Legitimate interests
We may process information where it is necessary for our legitimate business interests, provided those interests are not overridden by your rights.
These interests may include:
- responding to business enquiries;
- managing business relationships;
- delivering and improving our services;
- maintaining service, network and information security;
- administering our business;
- preventing fraud;
- managing suppliers and contractors;
- keeping appropriate business records;
- promoting relevant services to business contacts; and
- establishing or defending legal claims.
Where appropriate, we assess and document whether our legitimate interests are proportionate.
6.3 Legal obligation
We may process information where necessary to comply with:
- tax and accounting requirements;
- employment law;
- health and safety requirements;
- insurance obligations;
- court orders;
- regulatory requirements; or
- other legal obligations.
6.4 Consent
We may rely on consent where required, including for certain:
- marketing communications;
- non-essential cookies;
- optional website tracking; or
- uses of sensitive personal information.
You may withdraw your consent at any time. Withdrawal does not affect processing carried out lawfully before consent was withdrawn.
6.5 Legal claims and substantial public interest
Where legally permitted, we may process special-category or criminal-offence information where necessary for:
- employment and social-protection obligations;
- establishing, exercising or defending legal claims;
- preventing or detecting unlawful acts;
- safeguarding individuals; or
- another condition permitted by the Data Protection Act 2018.
7. Marketing communications
We may send business-related marketing communications where:
- you have asked to receive them;
- you have previously enquired about or purchased relevant services;
- you represent a corporate organisation and we believe the communication may be relevant to your role; or
- another lawful basis permits us to do so.
You can stop receiving marketing communications by:
Opting out of marketing will not prevent us from sending necessary service, security, billing or contractual communications.
We may retain limited information on a suppression list to ensure that we continue to respect your request not to receive marketing.
8. Cookies and website analytics
Our website may use:
- essential cookies required for the website to function;
- preference cookies;
- analytics cookies;
- marketing cookies; and
- similar technologies.
9. When we act as a processor
When we process personal information on behalf of a customer in connection with managed support, monitoring, service desk, infrastructure or professional services:
- the customer normally determines why and how the information is used;
- we process the information only for agreed purposes and documented instructions;
- we apply contractual confidentiality and security obligations;
- we assist the customer with relevant data-protection obligations where contractually required; and
- we delete or return the information in accordance with the applicable contract.
Requests relating to information controlled by one of our customers may need to be referred to that customer.
10. Who we share information with
We may share personal information with:
- our employees, contractors and authorised personnel;
- technology vendors and distributors;
- service desk, CRM and business-software providers;
- cloud hosting and data-storage providers;
- communications and email providers;
- website hosting and analytics providers;
- payment and banking providers;
- accountants, auditors, insurers and legal advisers;
- recruitment agencies and screening providers;
- logistics, delivery and disposal partners;
- subcontractors and specialist engineers;
- customers, where necessary to deliver services;
- regulators, courts, law-enforcement bodies or public authorities;
- prospective investors, funders, purchasers or advisers in connection with a corporate transaction; and
- other parties where required or permitted by law.
We require service providers processing personal information for us to apply appropriate confidentiality, security and data-protection controls.
We do not sell personal information.
11. International transfers
Some of our suppliers and technology providers may store or process information outside the United Kingdom.
Where personal information is transferred internationally, we will use an appropriate legal mechanism, which may include:
- UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to the EU Standard Contractual Clauses; or
- another lawful safeguard.
Where required, we will assess the protections applying to the transfer and implement supplementary controls.
12. How long we retain information
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, regulatory, contractual, accounting, insurance and dispute-resolution requirements.
Indicative retention periods
- Customer contracts and principal commercial records: retained for the duration of the contract and for six years after the contract ends.
- Invoices, accounting and tax records: normally retained for six years after the end of the relevant financial period.
- Service desk tickets and operational records: retained for the duration of the customer contract and for up to six years afterwards, depending on contractual, legal and operational requirements.
- Enquiries that do not result in a customer relationship: retained for up to 24 months after the last meaningful interaction.
- Marketing contact information: retained until the individual opts out or until the information is removed following an appropriate period of inactivity.
- Supplier and contractor records: retained for the duration of the relationship and for up to six years after it ends.
- Unsuccessful recruitment applications: normally retained for six months after the recruitment decision.
- Successful applicant information: transferred to the relevant personnel record and retained in accordance with the applicable employee or contractor retention schedule.
- Website analytics and cookie information: retained for the periods stated in the Cookie Policy or cookie-management platform.
These periods may be shortened or extended where required by law, a customer contract, litigation, security requirements or an individual request.
13. Recruitment and screening
We use applicant information to:
- administer applications;
- assess skills, qualifications and experience;
- arrange interviews;
- communicate with applicants;
- undertake appropriate checks;
- decide whether to offer employment or an engagement; and
- meet legal and regulatory obligations.
Where appropriate to the role, we may verify:
- identity;
- right to work;
- employment history;
- professional qualifications;
- references;
- criminal records;
- financial probity; or
- other matters reasonably relevant to the position.
We will inform applicants about material pre-employment vetting and will only carry out checks that are lawful, necessary and proportionate to the role. (ICO)
Information may be shared with interviewers, hiring managers, recruitment agencies and screening providers where necessary.
14. Information security
We use appropriate technical and organisational measures intended to protect personal information against:
- unauthorised access;
- accidental loss;
- unlawful disclosure;
- misuse;
- alteration; and
- destruction.
Measures may include:
- access controls;
- multi-factor authentication;
- managed endpoint protection;
- security patching;
- encryption;
- backups;
- logging and monitoring;
- staff confidentiality obligations;
- supplier controls;
- incident-management procedures; and
- business-continuity arrangements.
Access to personal information is limited to people who require it for legitimate business purposes.
No internet transmission or storage system is entirely secure. We therefore cannot guarantee absolute security, but we take proportionate steps to manage and reduce risk.
15. Data breaches
We maintain procedures for assessing and responding to suspected personal-data breaches.
Where legally required, we will notify the Information Commissioner’s Office and affected individuals within the applicable statutory timescales.
Customers will be notified of relevant incidents in accordance with our contracts and data-processing obligations.
16. Your rights
Depending on the circumstances and lawful basis, you may have the right to:
- request access to your personal information;
- request correction of inaccurate or incomplete information;
- request deletion of your information;
- request restriction of processing;
- object to processing based on legitimate interests;
- object at any time to direct marketing;
- request transfer of certain information in a portable format;
- withdraw consent;
- challenge certain solely automated decisions; and
- complain to the Information Commissioner’s Office.
Some rights are subject to legal limitations and may not apply in every case.
To exercise a right, contact:
info@pickleconcepts.com
We may need to verify your identity before acting on a request. We will normally respond within one month, although the law permits an extension for complex or multiple requests.
17. Automated decision-making
We do not currently use solely automated decision-making that produces legal or similarly significant effects on individuals.
If this changes, we will update this Privacy Policy and provide the information required by law, including meaningful information about the logic and likely consequences involved.
18. Complaints
Please contact us first if you have concerns about how we use your information:
Email: info@pickleconcepts.com
Post: Privacy Enquiries, Pickle Concepts Limited, 66 Paul Street, London, EC2A 4NA
You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority for data protection.
19. Third-party websites
Our website may contain links to websites operated by other organisations.
We do not control those websites and are not responsible for their privacy practices. You should review the privacy notice of each third-party website you use.
20. Changes to this Privacy Policy
We may update this Privacy Policy to reflect:
- changes to our services;
- changes to our suppliers or systems;
- changes to our data-processing activities;
- legal or regulatory developments; or
- improvements to our privacy practices.
The latest version will be published on our website with an updated revision date.
Where a change materially affects how we use personal information, we will provide additional notice where required.