Version 1.1 · Last updated 30 September 2026

1. Who we are

idash Group Limited (“idash Group”, “we”, “us”) is the controller of personal information collected through www.idash.co.uk and through business enquiries made to us directly.

idash Group Limited, 105 Great North Road, Eaton Socon, St Neots, Cambridgeshire, PE19 8EL. Registered in England and Wales, company number 13295348. idash Solutions is part of idash Group.

For anything to do with privacy, email [email protected] and mark it for the attention of the Data Protection Contact.

2. What this notice covers

This notice explains how we collect and use personal information when you visit this website, contact us, ask about or buy our services, apply to work with us, or otherwise deal with us in a business capacity.

When we provide IT support, cloud, security or software services to a customer and process personal information on their behalf, the customer is normally the controller and their own privacy notice applies. Our contract and data processing terms with that customer govern that processing.

3. Information we collect

  • Identity and contact details, such as your name, organisation, job title, email address and phone number.
  • Enquiry and relationship information, including what you tell us in the contact form or by email, correspondence, quotations, contracts and support requests.
  • Website and device information, including IP address, browser and device type, pages viewed, referring site and your cookie choices. See section 8.
  • Billing and transaction information needed to manage a customer or supplier relationship.
  • Recruitment information, if you send us a CV or apply for a role.

Please don’t send special category information (for example health details), information about criminal offences, passwords or unnecessary confidential information through the website contact form.

4. Where we get it from

  • From you, through the contact form, email, phone calls, meetings and contracts.
  • From your employer or colleagues, or from customers, suppliers and people who refer you to us.
  • Automatically from the website, as described in section 8 and our Cookie Policy.
  • From publicly available business sources, where that is lawful and proportionate.

5. Why we use it, and our lawful basis

PurposeInformationLawful basis
Reply to enquiries and give you the information you ask forIdentity, contact and enquiry informationSteps before entering a contract; legitimate interests in responding to business enquiries
Deliver, manage and support our servicesContact, account, contract, billing and support informationContract; legitimate interests in managing business relationships
Manage suppliers and professional relationshipsContact and commercial informationContract; legitimate interests in running our business
Run, secure and protect the website, including blocking spam on the contact formIP address, device, log and security informationLegitimate interests in keeping the website and our systems secure
Understand how the website is used, so we can improve itUsage and device information collected by Google AnalyticsConsent, given through the cookie banner
Send business news and service updatesContact details, role, organisation and preferencesConsent where the law requires it; otherwise legitimate interests, subject to your right to object
Meet legal, tax, accounting and security obligationsRelevant contact, transaction and incident informationLegal obligation; legitimate interests; establishing, exercising or defending legal claims
RecruitmentApplicant identity, contact, employment and assessment informationSteps before entering a contract; legitimate interests; legal obligation where applicable

Where we rely on legitimate interests, we have considered whether the processing is necessary and proportionate and what effect it has on you. You can object to it at any time (see section 13).

6. Special category and criminal offence information

We don’t intentionally collect special category or criminal offence information through the website. If we ever need it, for example as part of recruitment, we will identify a lawful basis and the additional condition the law requires, apply appropriate safeguards and tell you at the time.

7. Marketing

Sending an enquiry through the website does not add you to a mailing list. We only send business news and updates where the law allows, and we ask for consent where it is required. Every marketing email has a clear way to unsubscribe, and you can also ask us to stop at any time by emailing [email protected].

8. Cookies and similar technologies

We only use Google Analytics cookies if you accept them in the cookie banner. The website also uses strictly necessary technologies to keep it working and secure. Our Cookie Policy lists each one. You can change your choice at any time using the Cookie settings button at the bottom left of every page.

9. Who we share information with

We only share personal information where it is necessary and proportionate. That includes:

  • Other idash Group companies, where needed to reply to you, deliver services or manage our relationship with you.
  • Service providers who support us, including:
    • Microsoft, for email and business systems (Microsoft 365). Contact form enquiries are delivered to us by email, and a copy is kept in our website’s database.
    • Cloudflare, which protects and delivers the website and runs the robot check on our forms (Cloudflare Turnstile).
    • Google, for website analytics (Google Tag Manager and Google Analytics), only if you accept optional cookies, and for a standard JavaScript library the website loads from Google’s servers.
    • CleanTalk, which checks contact form submissions for spam.
    • Adobe, which supplies the fonts used on the website (Adobe Fonts).
    • Our web hosting provider, and our accounting, IT and professional advisers.
  • Customers, suppliers and professional advisers, where needed for a particular project or service.
  • Regulators, law enforcement, courts or other authorities, where the law requires it or it is needed to protect rights and security.
  • A buyer, investor or their advisers in connection with a proposed sale or restructuring of our business, under appropriate confidentiality.

Anyone handling personal information for us is bound by appropriate contractual, confidentiality, security and data protection obligations. We do not sell personal information.

10. International transfers

Some of our service providers, including Microsoft, Cloudflare, Google, Adobe and CleanTalk, may store or access personal information outside the UK, including in the United States. Before any restricted transfer, we make sure a lawful transfer mechanism is in place, such as UK adequacy regulations (including the UK Extension to the EU–US Data Privacy Framework), the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, and we carry out a transfer risk assessment where one is required.

11. How long we keep it

We keep personal information only for as long as we need it for the purpose we collected it for, taking account of legal, contractual, tax, accounting and security requirements.

RecordHow long
Website enquiriesUp to 24 months after our last meaningful contact, unless you become a customer or supplier
Customer, contract and billing recordsFor the length of the relationship and normally six years afterwards, unless the law requires longer
Marketing recordsUntil you withdraw consent or object. We keep a minimal suppression record so we respect your choice
Recruitment informationNormally six months after the recruitment decision, unless you agree to us keeping it longer or the law requires it
Security and website logsFor a limited period set by security and operational needs
Cookie choicesStored in your browser for 12 months, after which we ask again

12. Security

We use technical and organisational measures appropriate to the risk, including access control, multi-factor authentication, encryption in transit and at rest, endpoint and network protection, logging, backups, supplier checks, staff training and incident response procedures. No transmission over the internet is completely secure, so please don’t send us more information than you need to.

13. Your rights

Subject to certain conditions and exemptions, you have the right to:

  • be told how your personal information is used;
  • get a copy of your personal information;
  • have inaccurate or incomplete information corrected;
  • have your information erased, or its use restricted;
  • receive your information in a portable format, in some circumstances;
  • object to processing based on legitimate interests, and object at any time to direct marketing;
  • withdraw consent at any time, where we rely on consent. This doesn’t affect anything we did before you withdrew it;
  • not be subject to solely automated decisions with legal or similarly significant effects, and to challenge them.

To use any of these rights, email [email protected]. There is normally no charge. We may ask for information to confirm your identity, and we will respond within one month, or tell you within that time if we need longer because the request is complex.

14. Complaints

If you are unhappy with how we have handled your personal information, please contact us first at [email protected], marked for the attention of the Data Protection Contact. We will acknowledge your complaint within 30 days, investigate it and tell you the outcome without undue delay.

You also have the right to complain to the Information Commissioner’s Office (ICO), the UK data protection regulator, at ico.org.uk/make-a-complaint or on 0303 123 1113.

15. Automated decision-making

We don’t use information from this website to make solely automated decisions that have legal or similarly significant effects on you.

16. Children

This website and our services are for businesses and are not aimed at children. If you think a child’s personal information has been sent to us, please let us know and we will delete it.

17. Other websites

This website links to other websites, such as LinkedIn. Those organisations are responsible for their own privacy practices, so please read their privacy notices.

18. Changes to this notice

We review this notice regularly and whenever our processing, our services or the law changes. The version and date at the top of this page show when it was last updated.

Get In Touch
Server room
It takes 20 years to build a reputation and a few minutes of cyber-incident to ruin it.