Privacy Policy
This policy explains how CLOUKNOW TECH LTD collects, uses, shares and protects personal data, and what rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Last updated: 16 September 2026
1. Who we are
CLOUKNOW TECH LTD is a company registered in England and Wales under company number 16806560, with its registered office at 6 Rancliffe Cres, Leicester, United Kingdom, LE3 1NQ. We trade as Clouknow Tech and provide custom software development, integration and support services.
For the data described in section 2 we act as the data controller. For the data described in section 3 we normally act as a processor on behalf of our clients. You can reach us at [email protected] or +44 7481 236590.
2. Data we collect as a controller
When you contact us or engage us for a project, we collect and use:
- identification and contact data: your name, job title, email address and telephone number;
- business data: company name, website, registered address and billing details;
- project data: the content of your enquiry, requirements, documents and correspondence you send us;
- contractual and financial records: agreements, statements of work, invoices and payment records;
- technical data from our website: IP address, browser type and pages viewed, where such data is generated by essential hosting logs.
Our website has no server-side forms. Enquiry buttons open your own email client, so any information you send reaches us by email and is held in our mailbox.
3. Personal data in client systems
During development, data migration and support work we may be given access to systems belonging to our clients. Those systems can contain personal data relating to the client's own customers, employees or suppliers. In respect of that data the client is the controller and we act as a processor under a written agreement meeting the requirements of Article 28 of the UK GDPR. Under that agreement we:
- process personal data only on the client's documented instructions;
- ensure that our personnel are bound by a duty of confidentiality;
- engage subcontractors and sub-processors only with the client's authorisation, and pass equivalent obligations on to them;
- return or delete personal data at the end of the engagement, at the client's choice;
- assist the client in responding to requests from data subjects;
- notify the client without undue delay if we become aware of a personal data breach;
- make available the information needed to demonstrate compliance and allow audits.
Wherever it is possible, development and testing are carried out on anonymised or synthetic data instead of production data. Development, staging and production environments are kept separate and access is granted on a least-privilege basis.
We do not request special category data. Where such data is present in a client system, it is handled under a heightened protection regime: restricted access, additional encryption and, where appropriate, pseudonymisation before it is used for testing.
4. Purposes and legal bases
- Responding to enquiries and preparing proposals — legitimate interests (Article 6(1)(f)): replying to people who approach us about our services.
- Performing a contract — Article 6(1)(b): delivering the project, providing support and managing the client relationship.
- Invoicing, accounting and tax records — legal obligation (Article 6(1)(c)).
- Securing our systems and preventing misuse — legitimate interests (Article 6(1)(f)).
- Sending occasional updates about our services — consent (Article 6(1)(a)), which you may withdraw at any time.
- Establishing, exercising or defending legal claims — legitimate interests (Article 6(1)(f)).
5. Sharing with third parties
We do not sell personal data. We share it only with the following categories of recipient, and only as far as necessary:
- cloud hosting and infrastructure providers used to run our own systems and, where instructed, the client's environments;
- email, collaboration, project tracking and source code hosting providers;
- error monitoring, logging and analytics providers used for the operation of delivered systems;
- accountants, auditors, insurers and legal advisers;
- payment and banking providers;
- subcontracted engineers engaged on a project, subject to confidentiality and, where they act as sub-processors, to the client's authorisation;
- public authorities, regulators or courts where we are required by law to disclose information.
6. International transfers
We prefer infrastructure located in the United Kingdom or the European Economic Area. Where a sub-processor or an item of infrastructure is located outside the UK, we rely on an appropriate transfer mechanism: UK adequacy regulations, the International Data Transfer Agreement, or the UK Addendum to the European Commission's Standard Contractual Clauses, together with a transfer risk assessment and, where needed, supplementary technical measures such as encryption. Clients are told before their data is processed in a new jurisdiction.
7. Retention
- enquiries that do not lead to a contract: up to 12 months from the last contact;
- project correspondence and documentation: for the term of the contract and up to 6 years afterwards, in line with limitation periods for contractual claims;
- invoices and accounting records: 6 years from the end of the relevant financial year, as required by UK tax law;
- data held in client systems as a processor: for as long as the agreement with the client requires, then returned or deleted on the client's instruction;
- marketing contacts: until consent is withdrawn.
Data that is no longer needed is deleted or irreversibly anonymised.
8. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit (TLS) and at rest, role-based access control with multi-factor authentication, separation of development, staging and production environments, code review and dependency scanning, logging and monitoring, regular backups with tested restores, and a documented incident response procedure. Access rights are reviewed and revoked when an engagement ends. No transmission over the internet can be guaranteed to be completely secure, but we work to reduce that risk continuously.
9. Cookies
This website is a static site. It sets no cookies of its own, uses no advertising or tracking technologies, and stores nothing in your browser's local or session storage. Web fonts are requested from Google Fonts, which means your IP address is visible to that provider in order to deliver the font files. Your browser settings let you block such requests. If we introduce non-essential cookies in future, we will ask for your consent first.
10. Your rights
Subject to the conditions set out in the UK GDPR, you have the right to:
- access the personal data we hold about you and receive a copy;
- have inaccurate data rectified and incomplete data completed;
- have your data erased in certain circumstances;
- restrict our processing of your data;
- receive your data in a portable, machine-readable format and have it transmitted to another controller;
- object to processing based on our legitimate interests, and to direct marketing at any time;
- withdraw consent where processing is based on consent;
- not be subject to decisions based solely on automated processing — we do not make such decisions.
To exercise any of these rights, email [email protected]. We respond within one month and may ask for information to verify your identity. If your request concerns data held in a client's system, we will pass it to the relevant client, who is the controller for that data.
11. Withdrawing consent
Where we rely on your consent, you may withdraw it at any time by emailing us or by using the unsubscribe link in any message we send. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal, and does not affect processing we carry out on another legal basis, such as the performance of a contract.
12. Complaints
If you are unhappy with how we handle your personal data, please contact us first so we can put it right. You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority, at ico.org.uk, by calling their helpline, or by writing to Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
13. Age restriction
Our services are aimed at businesses. This website is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
14. Changes to this policy
We may update this policy to reflect changes in our services, technology or the law. The current version is always published on this page with the date it was last updated. Where a change materially affects you, we will tell you by email or through a notice on the website.
15. Contact us
CLOUKNOW TECH LTD, company number 16806560
6 Rancliffe Cres, Leicester, United Kingdom, LE3 1NQ
Email: [email protected]
Phone: +44 7481 236590