Privacy Policy
1. Introduction
Aspen Solutions Ltd is committed to protecting and respecting privacy and ensuring that personal information is processed lawfully, fairly and transparently.
This Privacy Policy explains how Aspen Solutions Ltd collects, uses, stores, protects, shares and retains personal information when individuals interact with our organisation, use our services, visit our website or otherwise communicate with us.
Aspen Solutions Ltd processes personal information in accordance with:
- UK GDPR
- Data Protection Act 2018
- Privacy and Electronic Communications Regulations (PECR)
- Data (Use and Access) Act 2025 (where applicable)
- Other applicable privacy legislation
2. Controller and Processor Responsibilities
Aspen Solutions Ltd operates as both a Data Controller and a Data Processor depending on the nature of the processing activity.
Where Aspen is the Data Controller
Aspen acts as the Controller for personal information relating to:
- Employees
- Job applicants
- Former employees
- Website visitors
- Marketing contacts
- Supplier contacts
- Customer contacts
- Business development activities
In these circumstances Aspen determines the purposes and means of processing.
Where Aspen is the Data Processor
As a Managed Service Provider (MSP), Aspen may access, store, process or manage personal information contained within customer environments including:
- Microsoft 365 tenants
- Entra ID directories
- Customer servers
- Customer applications
- Customer backup platforms
- Customer helpdesk systems
- Customer endpoints and devices
In these circumstances Aspen acts on ly as a Data Processor and processes personal information solely on the customer’s documented instructions.
Processing activities performed as a Data Processor are governed by the relevant:
- Customer Agreement
- Data Processing Agreement (DPA)
- Statement of Work
- Customer instructions
This Privacy Policy applies only to personal information for which Aspen Solutions Ltd acts as the Data Controller.
3. Who We Are
Aspen Solutions Ltd provides:
- Managed IT Services
- Technology Consultancy
- Cloud Services
- Professional Services
- IT Project Delivery
- Cyber Security Services
- Support Services
to organisations across the hospitality and commercial sectors.
This Privacy Policy covers personal information relating to customers, suppliers, and website visitors. Personal information relating to job applicants and employees of Aspen Solutions Ltd is addressed separately in our internal HR Privacy Notice, available on request.
Registered Office
Aspen Solutions Ltd
5 Clydesmill Road
Cambuslang
Glasgow
G32 8RE
Telephone: 01236 786111
Company Registration Number: SC183651
4. Personal Information We Collect
We may collect:
Identity Data
- Name
- Job title
- Employer
- Date of birth (where required)
Contact Data
- Email address
- Telephone number
- Business address
Financial Data
- Billing information
- Payment information
- Transaction records
Technical Data
- IP address
- Device information
- Browser information
- Authentication logs
- Access logs
- Security monitoring records
Business Relationship Data
- Customer communications
- Service history
- Support requests
- Survey responses
- Customer feedback
Regulatory Information
- Due diligence records
- Compliance records
- Credit reference information where appropriate
Where personal information is required to enter into a contract or to meet a legal obligation, for example tax reporting, failure to provide it may mean Aspen Solutions Ltd is unable to deliver the relevant service.
5. How We Collect Information
Information may be collected through:
- Email correspondence
- Telephone conversations
- Meetings
- Website forms
- Customer onboarding activities
- Contract negotiations
- Support requests
Information may also be obtained from:
- Publicly available sources (name, job title, company)
- Business directories (contact and company details)
- Professional networking platforms (name, job title, professional history)
- Credit reference agencies (financial standing, credit history)
- Third parties acting on your instruction (contact details relevant to the instruction)
6. Lawful Basis for Processing
Aspen Solutions Ltd processes personal information only where a lawful basis applies.
Contract
To:
- Deliver services
- Provide support
- Manage customer accounts
- Fulfil contractual obligations
Legal Obligation
To:
- Meet regulatory requirements
- Meet tax obligations
- Maintain statutory records
- Support investigations and audits
Legitimate Interests
Including:
- Service improvement
- Relationship management
- Information security
- Fraud prevention
- Business continuity
- Quality assurance
- Operational management
These interests are balanced against individual rights and are assessed on a case-by-case basis to ensure they do not override the interests or fundamental rights of the individual.
Consent
Where required by law, Aspen will obtain consent before processing personal information.
Consent may be withdrawn at any time.
Consent is specifically obtained for marketing communications and for the use of non-essential cookies.
7. Marketing Communications
Aspen Solutions Ltd may provide information relating to:
- Managed Services
- Cloud Services
- Cyber Security Services
- Events
- Industry updates
- Technology developments
where permitted by applicable legislation.
Individuals may opt out at any time through:
- Email unsubscribe links
- Direct contact with Aspen
- Contacting the DPO
Aspen Solutions Ltd does not sell personal information.
8. Information Sharing
Information may be shared where necessary with:
- Microsoft
- Cloud hosting providers
- Payment processors
- Professional advisers
- Accountants
- Auditors
- Insurers
- Approved subcontractors
- Regulatory authorities
All recipients are expected to implement appropriate security measures and comply with applicable privacy obligations.
9. International Transfers
Where personal information is transferred outside the UK, Aspen Solutions Ltd implements appropriate safeguards including:
- International Data Transfer Agreements
- Standard Contractual Clauses
- Adequacy decisions
- Other approved transfer mechanisms
10. Information Security
Aspen Solutions Ltd operates an Information Security Management System (ISMS) aligned with ISO/IEC 27001:2022.
Security measures include:
- Microsoft Entra ID identity management
- Multi-Factor Authentication (MFA)
- Role-based access controls
- Least-privilege access principles
- Quarterly access reviews
- BitLocker device encryption
- Endpoint Detection & Response (EDR)
- Security monitoring and logging
- Vulnerability management
- Patch management
- Backup and recovery processes
- Information security awareness activities
- Incident response procedures
- Supplier security assessments
Where Aspen supports customer environments, access is limited to authorised personnel and controlled in accordance with customer requirements, contractual obligations and security policies.
11. Personal Data Breaches
Aspen Solutions Ltd operates formal Information Security Incident Management procedures.
Where a personal data breach occurs Aspen will:
- Investigate the incident
- Assess the risk to individuals
- Contain and remediate the issue
- Notify the Information Commissioner’s Office where legally required
- Notify affected individuals where legally required
Trust Keith, acting as Aspen’s appointed DPO service provider, may assist with breach assessment and regulatory reporting obligations.
12. Data Retention
Aspen Solutions Ltd retains personal information only for as long as necessary to fulfil the purpose for which it was collected.
Retention periods are determined by:
- Legal requirements
- Regulatory obligations
- Contractual requirements
- Legitimate business needs
Detailed retention periods are defined within Aspen’s:
- Data Retention & Information Deletion Schedule
- Legal & Regulatory Register
- Record Management Procedures
When information is no longer required it will be securely deleted, anonymised or destroyed.
13. Your Rights
Individuals may have the following rights under UK GDPR:
- Right of Access
- Right to Rectification
- Right to Erasure
- Right to Restrict Processing
- Right to Object
- Right to Data Portability
- Rights relating to Automated Decision Making
Aspen Solutions Ltd does not carry out any automated decision-making, including profiling, that produces legal or similarly significant effects on individuals.
Requests will normally be responded to within one month.
14. Cookies
Aspen Solutions Ltd uses cookies and similar technologies to support the operation, security, performance and user experience of our website.
Certain cookies are strictly necessary for website functionality and security and do not require consent.
Where non-essential cookies are used, Aspen Solutions Ltd will provide users with an appropriate mechanism to manage cookie preferences and, where required by law, obtain consent before such cookies are used.
Users may amend, withdraw or update their cookie preferences at any time through the cookie management tools made available on the website.
Further information is available within the Aspen Solutions Ltd Cookie Policy.
15. Third-Party Websites
Our website may contain links to external websites.
This Privacy Policy applies only to Aspen Solutions Ltd.
Users should review the privacy notices of any external websites they choose to visit.
16. Changes to this Policy
Aspen Solutions Ltd may update this Privacy Policy periodically.
The current version will always be made available through our website and upon request.
17. Contact Details
Data Protection Officer
Email: dpo@aspensolutions.co.uk
or write to:
Aspen Solutions Ltd
5 Clydesmill Road
Cambuslang
Glasgow
G32 8RE
Telephone: 01236 786111
General Enquiries
Email: enquiries@aspensolutions.co.uk
18. Complaints
Aspen Solutions Ltd takes privacy concerns seriously and encourages individuals to raise any concerns directly with us in the first instance.
If you are dissatisfied with how your personal information has been handled, please contact Aspen Solutions Ltd using the details above so that we may investigate and attempt to resolve the matter.
If you remain dissatisfied following our response, you may have the right to raise the matter with the Information Commissioner’s Office (ICO).
Information Commissioner’s Office
Telephone: 0303 123 1113
Website: www.ico.org.uk
Approved By: Paul Harkins, Managing Director, Aspen Solutions Ltd
Version: 2.1 | Classification: Public | Aligned to ISO/IEC 27001:2022
Next Review Date: 01-07-2027