Data Sole
Legal

Privacy Policy

Policy Owner: Data Sole
Policy Area: Data Protection & Privacy
Version: 1.0
Effective Date: 27 August 2026
Jurisdiction: United Kingdom

Contents

  1. 1. Introduction
  2. 2. Who We Are
  3. 3. Scope of This Policy
  4. 4. Information We Collect
  5. 5. How and Why We Use Your Information
  6. 6. Cookies and Similar Technologies
  7. 7. How We Share Your Information
  8. 8. International Data Transfers
  9. 9. Data Retention
  10. 10. How We Protect Your Information
  11. 11. Your Rights
  12. 12. Customer-Controlled Cloud Content
  13. 13. Marketing Communications
  14. 14. Children's Privacy
  15. 15. Automated Decision-Making and Profiling
  16. 16. Third-Party Websites and Services
  17. 17. Changes to This Policy
  18. 18. How to Contact Us and Complaints
  19. Appendix A: Definitions
  20. Appendix B: Categories of Personal Data
  21. Appendix C: Frequently Asked Questions

1. Introduction

Data Sole (“Data Sole”, “we”, “us” or “our”) provides cloud infrastructure, hosting and related digital services. This Privacy Policy explains how we collect, use, share, retain and protect personal data in connection with our website, our services and our dealings with customers, prospective customers, website visitors, suppliers and other individuals whose personal data we process.

We recognise that trust is fundamental to the services we provide. Customers rely on us to host and safeguard their infrastructure and, in many cases, their own customers’ information; visitors to our website expect us to be transparent about what happens when they browse our pages or submit an enquiry. This Policy is written to meet that expectation in plain, accessible language, while remaining precise enough to serve as a formal statement of our practices for regulatory purposes.

This Policy should be read alongside our Data Retention Policy, which sets out in more detail how long we keep different categories of information, and our Data Processing Agreement, which governs our role as a processor of customer-controlled cloud content. Where this Policy and a signed contractual document conflict in relation to a specific processing activity, the contractual document takes precedence for that activity.

By using our website or services, you acknowledge that your personal data will be processed as described in this Policy. Where we rely on your consent for a particular processing activity, we will ask for that consent separately and you may withdraw it at any time, as explained in Section 11.

This Policy applies to Data Sole and its associated brands and service lines. Where a specific service has its own supplementary privacy notice — for example, to address a feature that collects a distinct category of information — that supplementary notice should be read alongside this Policy, and will identify clearly where its terms differ from or add to those set out here.

2. Who We Are

Data Sole is the controller of personal data processed in connection with our own business operations — for example, when you create an account with us, contact our support team, subscribe to our marketing communications, or browse our website. In these contexts, “controller” means that we decide why and how your personal data is processed, and we are responsible for complying with applicable data-protection law in respect of that processing.

In relation to content that our customers store within the infrastructure, storage or hosting services we provide, we ordinarily act as a processor, and our customer acts as the controller. Section 12 explains this distinction, and what it means for individuals whose data is held within a customer’s environment, in more detail.

Our registered contact details, and the contact details of our Data Protection Lead, are set out in Section 18. If you are unsure whether Data Sole is acting as a controller or a processor in relation to your personal data, please contact us and we will clarify.

2.1 Group and Brand Structure

Data Sole operates as part of a wider group of associated businesses. Where personal data is shared between Data Sole and another business within that group — for example, to provide a joined-up customer experience across related services — that sharing is conducted on the basis of a documented legal basis, and each entity remains separately responsible for its own compliance with applicable data-protection law in respect of the processing it carries out.

3. Scope of This Policy

This Policy applies to personal data we process in connection with:

  • Our public website and any associated subdomains, applications and portals;
  • Enquiries submitted through our website, by email or by telephone;
  • Customer accounts, including account administration, billing and support;
  • Marketing communications and campaign engagement;
  • Recruitment applications submitted to us directly (a separate recruitment privacy notice may apply where indicated);
  • Our relationships with suppliers and business contacts; and
  • Security, fraud-prevention and compliance activities connected with the above.

This Policy does not apply to content that customers upload to, or generate within, their own hosted environments, except to the extent we process that content in our capacity as a processor. Nor does it apply to the practices of independent third-party websites or services that may be linked from our website, which are addressed separately in Section 16.

If you are an employee, contractor or supplier of Data Sole, a separate internal privacy notice may apply to the processing of your personal data in that capacity; this Policy is directed primarily at customers, prospective customers and visitors to our public-facing website and services.

4. Information We Collect

We collect personal data from a number of sources: information you provide to us directly (for example, when registering for an account or contacting support); information generated automatically through your use of our website and services (for example, technical and usage data); and, occasionally, information we receive from third parties such as payment processors, identity-verification providers or publicly available business sources.

The table in Appendix B sets out the main categories of personal data we collect, together with illustrative examples and the general purpose for which each category is used. Not every category applies to every individual; for example, a website visitor who does not create an account will typically only be reflected in technical and usage data, whereas a customer account holder will be reflected in a wider range of categories.

4.1 Information You Provide to Us

This includes information submitted when you create an account, configure a service, contact our support team, respond to a survey, apply for a role with us, or otherwise communicate with us directly. It also includes any information you choose to include within a support ticket, chat message or email, which may occasionally include special category data if you choose to disclose it — we ask that you avoid including special category data in correspondence with us unless it is genuinely necessary.

4.2 Information Collected Automatically

When you visit our website or use our services, certain information is collected automatically, including your IP address, browser and device information, pages visited, actions taken within a customer portal, and timestamps of activity. This information is generally used for security, service reliability, analytics and, where you have consented, for measuring the effectiveness of our marketing. Section 6 explains our use of cookies and similar technologies in more detail.

4.3 Information from Third Parties

We may receive information about you from payment processors (for example, confirmation that a payment was successfully authorised), from identity-verification or fraud-prevention services, from publicly available sources such as Companies House where relevant to a business relationship, and from third parties you have authorised to share information with us, such as a colleague submitting an enquiry on your behalf.

4.4 Special Category Data

We do not generally seek to collect special category data, being personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data used for identification, health data, or data concerning sex life or sexual orientation. Where such data is provided to us — for example, incidentally within a support communication, or as part of a recruitment process where relevant to a reasonable adjustment — we process it only where a specific condition under Article 9 of the UK GDPR applies, such as explicit consent or the establishment, exercise or defence of legal claims, and we apply enhanced access restrictions to it.

5. How and Why We Use Your Information

We only process personal data where we have a valid legal basis for doing so under the UK GDPR. Depending on the purpose, this may be performance of a contract with you, compliance with a legal obligation, our legitimate interests (provided these are not outweighed by your interests or fundamental rights), or your consent. The table below sets out our principal processing purposes and the legal basis we generally rely on for each.

PurposeTypical Legal Basis
Creating and administering a customer accountPerformance of a contract
Providing cloud infrastructure, hosting and storage servicesPerformance of a contract
Processing payments and issuing invoicesPerformance of a contract; legal obligation
Responding to support requestsPerformance of a contract; legitimate interests
Maintaining security, authentication and access logsLegitimate interests
Detecting and preventing fraud or abuseLegitimate interests; legal obligation
Sending service and account notificationsPerformance of a contract; legitimate interests
Sending marketing communicationsConsent (or legitimate interests for existing customers, subject to opt-out)
Complying with tax, accounting and regulatory obligationsLegal obligation
Establishing, exercising or defending legal claimsLegitimate interests; legal obligation
Improving and developing our servicesLegitimate interests

Where we rely on legitimate interests, we have considered whether that interest is genuinely served by the processing, whether the processing is necessary to achieve it, and whether it is outweighed by the interests or fundamental rights of the individual concerned. Where we rely on consent, we keep a record of when and how consent was given, and you may withdraw it at any time as described in Section 11.

5.1 Purpose Limitation

We use personal data only for the purposes for which it was collected, or for a purpose that is compatible with that original purpose. If we intend to use personal data for a new and unrelated purpose, we will notify you and, where required, seek your consent before doing so.

5.2 Service Improvement and Analytics

We analyse aggregated and, where necessary, individual usage data to understand how our services are used, to identify and resolve technical issues, and to inform the development of new features. Where practicable, we prefer to use aggregated or de-identified data for these purposes. Where individual-level data is used, it is processed on the basis of our legitimate interest in maintaining and improving a reliable, secure service, balanced against the interests and rights of the individuals concerned.

6. Cookies and Similar Technologies

Our website uses cookies and similar technologies to operate correctly, to remember your preferences, to understand how our website is used, and, where you have consented, to measure the effectiveness of our marketing. Cookies are small text files placed on your device when you visit a website.

6.1 Categories of Cookies We Use

  • Strictly necessary cookies, which are required for the website and customer portal to function and cannot be switched off, such as those maintaining your logged-in session;
  • Functional cookies, which remember choices you make, such as language or display preferences;
  • Analytics cookies, which help us understand how visitors use our website so that we can improve it; and
  • Marketing cookies, which may be used, with consent, to measure the effectiveness of our marketing campaigns.

Where consent is legally required for a category of cookie, we obtain that consent through the cookie banner presented on your first visit to our website, and you can change your preferences at any time through the cookie settings link in our website footer or through your browser settings. Disabling certain cookies may affect the functionality of our website or customer portal.

6.2 Third-Party Cookies

Some cookies on our website may be set by third-party services we use, such as analytics or marketing platform providers. These third parties may use the information collected through their cookies in accordance with their own privacy policies. We select third-party service providers with regard to their own data-protection practices, and, where required, put appropriate data processing terms in place with them.

7. How We Share Your Information

We do not sell personal data. We share personal data only where necessary and in the circumstances described below, and always subject to appropriate contractual and security safeguards.

  • Service providers and sub-processors who support our operations, such as payment processors, email delivery providers, customer support tooling providers, and infrastructure providers we rely on to deliver our own services;
  • Professional advisers, including our auditors, accountants, insurers and legal counsel, where necessary for their engagement;
  • Regulators, law-enforcement authorities and courts, where we are required to do so by law, or where necessary to establish, exercise or defend legal claims;
  • A prospective buyer or successor in the event of a merger, acquisition, financing or sale of all or part of our business, subject to appropriate confidentiality protections; and
  • Other parties with your consent, for example where you ask us to share information with a named third party.

Where a third party processes personal data on our behalf, we require that party to enter into a data processing agreement that imposes obligations consistent with this Policy and applicable law, including obligations relating to security, confidentiality and retention. We maintain a record of our sub-processors and update it as our supplier relationships change.

7.1 Business Transfers

If Data Sole is involved in a merger, acquisition, reorganisation, financing, or sale of some or all of its assets, personal data may be transferred as part of that transaction. We will notify affected individuals, where required by law, of any such transfer and of any choices they may have regarding their personal data. Any acquiring entity would be expected to honour the commitments set out in this Policy in relation to personal data collected before the transaction, unless individuals are separately notified of a change.

8. International Data Transfers

We primarily store and process personal data within the United Kingdom. Where a service provider or sub-processor is located outside the United Kingdom, or where data is otherwise transferred internationally, we put in place appropriate safeguards required by applicable data-protection legislation before the transfer takes place.

These safeguards may include reliance on an applicable UK adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful transfer mechanism recognised under the UK GDPR. Further information about the safeguards applicable to a specific transfer is available on request from our Data Protection Lead.

Because we operate cloud infrastructure services, some of our own underlying infrastructure providers, content delivery networks or disaster-recovery facilities may be located outside the United Kingdom. Where this is the case, the transfer safeguards described above apply, and we select providers with regard to the strength of their security and data-protection commitments.

9. Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, in line with the principles set out in our Data Retention Policy. Retention periods vary by category of information and are generally determined by reference to the purpose of processing, any applicable statutory minimum retention period, and any need to retain information in connection with a dispute, investigation or legal hold.

Indicative retention periods for the main categories of information we hold include: active account information, for the duration of the account relationship; closed account and billing information, normally up to six years after the relationship ends, to meet accounting and tax obligations; customer support records, normally up to three years after a case is closed; authentication and infrastructure logs, normally 12 months; and security-monitoring logs, normally up to 24 months, or longer where retained as part of a documented security incident record or legal hold.

Where information is no longer needed for any of the purposes described in this Policy, we securely delete, anonymise or otherwise dispose of it in accordance with our Data Retention Policy. A copy of that Policy is available on request.

In some cases we may retain information for a longer period than the indicative periods above where necessary to comply with a legal obligation, to resolve a dispute, to enforce our agreements, or where information has been placed under a legal hold in connection with litigation, a regulatory investigation, or a security incident. Once the relevant justification no longer applies, the information returns to its normal retention and deletion cycle.

10. How We Protect Your Information

We maintain technical and organisational measures designed to protect personal data against unauthorised or unlawful processing, accidental loss, destruction or damage. These measures include encryption of data in transit and, where appropriate, at rest; access controls based on the principle of least privilege; logging and monitoring of access to sensitive systems; regular review of our security posture; and contractual security requirements imposed on our service providers.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a personal data breach that poses a risk to individuals, we will assess the incident and, where required by law, notify the Information Commissioner’s Office and affected individuals without undue delay, in accordance with our Incident Response Plan.

You also have a role to play in keeping your account secure, including using a strong, unique password, enabling multi-factor authentication where available, and promptly notifying us if you suspect unauthorised access to your account.

10.1 Access Controls

Access to systems containing personal data is restricted to personnel who need it to perform their role, following the principle of least privilege. Access is reviewed periodically and revoked promptly when no longer required, such as when an employee changes role or leaves the business. Where personnel access customer environments for support purposes, this is generally logged and, where our service design permits, subject to customer authorisation.

11. Your Rights

Where we act as a controller of your personal data, you have the following rights under the UK GDPR, subject to certain conditions and exemptions:

  • Right of access – to obtain a copy of the personal data we hold about you and information about how it is processed.
  • Right to rectification – to have inaccurate or incomplete personal data corrected.
  • Right to erasure – to request deletion of your personal data in certain circumstances.
  • Right to restrict processing – to request that we limit how we use your personal data in certain circumstances.
  • Right to data portability – to receive personal data you have provided to us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
  • Right to object – to object to processing based on legitimate interests, or to processing for direct marketing purposes at any time.
  • Rights related to automated decision-making – to obtain human intervention, express your point of view and contest a decision based solely on automated processing that has a legal or similarly significant effect on you.
  • Right to withdraw consent – where processing is based on consent, to withdraw that consent at any time, without affecting the lawfulness of processing before withdrawal.

To exercise any of these rights, please contact us using the details in Section 18. We will normally respond within one month of receiving a valid request, and may extend this period by a further two months for complex or numerous requests, in which case we will explain why the extension is necessary. We may need to verify your identity before acting on a request, and we may decline a request, in whole or in part, where a legal exemption applies, in which case we will explain our reasoning.

11.1 Complaints

If you are unhappy with how we have handled your personal data, we would welcome the opportunity to resolve your concern directly — please contact our Data Protection Lead in the first instance. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s independent supervisory authority for data protection, whose contact details are set out in Section 18.

12. Customer-Controlled Cloud Content

Where our customers use our infrastructure, hosting or storage services to store their own data — which may include personal data relating to their own customers, employees or other individuals — we act as a processor on the customer’s instructions, and the customer acts as the controller of that data.

If you are an individual whose personal data has been provided to one of our customers, and that customer stores your data within our services, your data-protection rights should generally be exercised against that customer directly, as they determine the purposes and means of processing your data and are best placed to respond. We will support our customers in responding to such requests in accordance with our Data Processing Agreement, but we do not independently access or review customer-controlled content except where necessary to provide the service, to comply with the law, to enforce our terms of service, or to protect the rights, property or safety of Data Sole, our customers or others.

If you contact us directly about personal data held within a customer’s environment and we are able to identify the relevant customer, we will, where appropriate, direct your request to that customer or forward it on your behalf.

12.1 Our Obligations as a Processor

As a processor, we process customer-controlled content only on the documented instructions of the relevant customer, unless we are required to do otherwise by law, in which case we will, where legally permitted, inform the customer of that legal requirement before processing. We assist customers, where reasonably required and consistent with the nature of the processing, in responding to requests from individuals exercising their data-protection rights, and in meeting their own security and breach-notification obligations.

13. Marketing Communications

Where you have consented, or where permitted by applicable law in the context of an existing customer relationship, we may send you marketing communications about our services, offers and updates. You can opt out of marketing communications at any time by using the unsubscribe link included in each communication, adjusting your communication preferences within your account, or contacting us directly.

Opting out of marketing communications does not affect our ability to send you service-related communications, such as notices about changes to your account, billing, or security matters, which are necessary for us to provide our services and are not classified as marketing.

14. Children's Privacy

Our website and services are directed at businesses and professionals and are not intended for use by children. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected personal data from a child without appropriate consent, we will take steps to delete that information promptly. If you believe a child has provided us with personal data, please contact us using the details in Section 18.

15. Automated Decision-Making and Profiling

We may use automated tools to support certain operational decisions, such as fraud-detection systems that flag potentially suspicious payment activity for review, or automated rules that temporarily restrict access to a service where unusual usage patterns are detected. Where such tools are used, they are generally supplemented by human review before any decision with a significant effect on you is finalised.

We do not currently make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you, without the possibility of human review. If this changes, we will update this Policy and provide information about the logic involved, the significance of the processing, and your right to request human intervention, in accordance with Section 11.

16. Third-Party Websites and Services

Our website may contain links to third-party websites, plug-ins and applications that are not operated by us. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements or practices. We encourage you to review the privacy policy of any third-party website or service you visit or connect with.

17. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, services, technologies or legal obligations. Where we make material changes, we will take reasonable steps to notify affected individuals, for example by email or by a prominent notice on our website, before the change takes effect. The date at the top of this Policy indicates when it was last revised, and we encourage you to review it periodically.

Non-material changes, such as clarifications of existing practice or minor updates to contact details, may be made without separate notification, but will always be reflected in the version history maintained internally by our Data Protection Lead.

18. How to Contact Us and Complaints

If you have questions about this Policy, wish to exercise a data-protection right, or have a concern about how we handle personal data, please contact our Data Protection Lead through the contact channels published on our website, or by writing to our registered business address.

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO), which can be contacted at ico.org.uk, by telephone on 0303 123 1113, or by post at Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom.

Appendix A: Definitions

  • “Controller” means the entity that determines the purposes and means of processing personal data.
  • “Cookie” means a small text file placed on a device when a website is visited, used to remember information about the visit.
  • “Personal Data” means any information relating to an identified or identifiable living individual.
  • “Processor” means an entity that processes personal data on behalf of, and under the instructions of, a controller.
  • “Special Category Data” means personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for identification, health data, or data concerning sex life or sexual orientation.
  • “UK GDPR” means the retained EU law version of the General Data Protection Regulation as it forms part of the law of England and Wales, Scotland and Northern Ireland, together with the Data Protection Act 2018.

Appendix B: Categories of Personal Data

CategoryExamplesPrimary Purpose
Identity dataName, job title, company name, usernameAccount creation, contract performance
Contact dataEmail address, billing address, telephone numberCommunication, invoicing, service delivery
Account dataAccount credentials, service configuration, subscription tierService provisioning and administration
Billing and financial dataPayment card details (tokenised via payment processor), invoice history, VAT/tax identifiersBilling, accounting, fraud prevention
Technical dataIP address, browser type, device identifiers, operating systemSecurity, service reliability, analytics
Usage dataLog-in history, feature usage, API calls, support interactionsService improvement, support, security monitoring
Communications dataSupport tickets, emails, chat transcripts, call notesCustomer support, dispute resolution
Marketing dataMarketing preferences, consent records, campaign engagementMarketing communications, suppression management
Customer cloud contentContent customers store within Data Sole hosting/storage servicesProvision of the hosting/storage service (processor role)

Appendix C: Frequently Asked Questions

Does Data Sole read the content I store on my hosted service?

No, not as a matter of routine. We access customer-controlled content only where necessary to provide the service, to comply with the law, to enforce our terms of service, or to protect the rights, property or safety of Data Sole, our customers or others, as described in Section 12.

Can I ask Data Sole to delete everything it holds about me?

You can request erasure, and we will comply where a legal basis for erasure applies. As explained in Section 11, some information may need to be retained for a period even after an erasure request, for example to meet accounting or tax obligations, or where a legal hold applies.

How do I update my marketing preferences?

You can update your marketing preferences at any time using the unsubscribe link in any marketing email, through your account settings, or by contacting us directly, as described in Section 13.

Who do I contact if I am not a customer but believe Data Sole holds my data?

Please contact our Data Protection Lead using the details in Section 18. We will investigate and respond in accordance with your rights under Section 11.

Contact

Skydatasol Holdings Plc., 321-323 High Road, Chadwell Heath, London RM6 6AX. Email cloud@skydatasol.com.