SupportNEX Privacy Policy

At SupportNEX, your privacy is our priority, and we are committed to safeguarding your personal information. This Privacy Policy details how we collect, use, disclose, and protect the data you provide when you access our website, use our services, or interact with us. By using our website or services, you agree to the terms set forth in this policy. Effective date: September 4, 2024.

Information We Collect

We may collect personal information through various interactions, including when you visit our website, complete forms, subscribe to our communications, or contact us. The data we collect may include your name, email address, phone number, company name, and any additional information you choose to provide. We may also gather technical information about your device and browsing behavior via cookies and other tracking technologies.

How We Use Your Information

SupportNEX may use the personal data collected for the following purposes:

  • To provide, manage, and improve our IT support services.
  • To respond to inquiries, service requests, and provide updates.
  • To enhance our website, services, and overall customer experience.
  • To send newsletters or periodic emails with relevant information.
  • To comply with legal obligations and safeguard our rights.

Data Sharing and Disclosure

We do not sell or rent your personal data to third parties. However, we may share your information with trusted service providers who help us operate our website or support our business. These third parties are bound to maintain the confidentiality of your data. We may also disclose your personal information if required by law or necessary to protect our legal rights or the rights of others.

Data Retention

SupportNEX retains your personal information only for as long as necessary to meet the purposes for which it was collected or as required by law. Once your data is no longer needed, we will securely delete or anonymize it.

Your Rights

Under the UK Data Protection Act (2018) and the UK General Data Protection Regulation (UK GDPR), you have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate or incomplete data.
  • Request the deletion of your personal data.
  • Restrict or object to the processing of your data.
  • Request data portability, allowing your data to be provided in a structured, commonly used format.

To exercise any of these rights, please contact us using the details at the end of this policy.

Cookies and Tracking Technologies

Our website uses cookies and similar technologies to improve your browsing experience. Cookies are small files stored on your device that allow us to analyze website traffic and improve our services. You can control cookie preferences through your browser settings. Please note that disabling cookies may impact your ability to use certain features of our site.

Data Security

We implement appropriate technical and organizational measures to safeguard your personal data against unauthorized access, alteration, disclosure, or destruction. While we take strong precautions, please be aware that no method of data transmission or storage over the internet is completely secure.

Third-Party Links

Our website may contain links to external websites. This Privacy Policy applies only to our website. We are not responsible for the privacy practices or content of third-party websites. We recommend reviewing the privacy policies of any external sites you visit.

Changes to This Privacy Policy

SupportNEX reserves the right to amend this Privacy Policy as necessary. Any updates will be posted on this page with the revised effective date. Continued use of our website and services following any changes will indicate your acceptance of the updated policy.

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at: policy@supportnex.co.uk.

GDPR Policy

SupportNEX is committed to safeguarding the personal data of our clients, employees, and partners. We adhere to the UK Data Protection Act (2018) and the UK General Data Protection Regulation (UK GDPR) to ensure that personal data is processed lawfully, fairly, and transparently. This policy outlines our approach to handling personal data, including collection, processing, storage, data retention, breach management, and data access.

Processing Personal Data SupportNEX processes personal data to deliver our IT support services. This includes client information, employee data, and service-related data. We collect personal data directly through onboarding and interactions on our website, using it strictly for specified purposes such as IT support, web design, client relationship management, and service enhancement. All data collection is done for legitimate purposes and processed in a manner aligned with those objectives.

Data Retention and Deletion We operate under a strict data retention policy. Personal data is kept only as long as necessary to achieve the purposes for which it was collected or as mandated by law. Once no longer needed, the data is securely deleted or anonymized to prevent unauthorized access. Our retention schedules are reviewed periodically to ensure compliance with current regulations.

Data Breach Response In the event of a data breach, SupportNEX has a well-defined protocol to assess and mitigate any risks. If the breach poses a threat to individuals’ rights, we will notify the affected parties and the Information Commissioner’s Office (ICO) within 72 hours, as required by law. Our breach response is documented to ensure accountability and continuous improvement in data protection.

Data Subject Access Requests (DSAR) Individuals have the right to access their personal data held by SupportNEX. To submit a Data Subject Access Request (DSAR), individuals can contact us via email or through our website. We aim to respond to all requests within one month, providing the requested data and information regarding its processing. Verification of identity may be required to protect against unauthorized data access.

Remote Connections and Data Security To ensure data security during remote support sessions, SupportNEX employs encrypted communication channels. Only authorized personnel have access to remote sessions, and detailed logs are maintained for auditing purposes. Our remote support activities comply with data protection regulations and internal policies to ensure the safety and confidentiality of personal data.

File Backups SupportNEX conducts regular file backups as part of our data management strategy to prevent data loss or corruption. Backups are securely stored and accessible only to authorized personnel. This ensures that personal data can be quickly restored in the event of an incident, minimizing disruption to client services.

GDPR Education SupportNEX ensures that all employees are trained on GDPR, data protection practices, and the importance of maintaining data security. Continuous education enables our staff to implement our policies effectively and comply with regulatory standards.

Transparency to Regulators SupportNEX maintains accurate and up-to-date records to meet legal obligations and provide transparency to regulators. We ensure timely responses to requests from supervisory authorities, as required by applicable laws, including the UK GDPR.

User Rights In compliance with the UK GDPR, individuals have the following rights regarding their personal data:

  • The right to access the personal data we hold.
  • The right to request corrections to inaccurate data.
  • The right to request the deletion of personal data.
  • The right to restrict or object to the processing of personal data.
  • The right to request data portability (transfer of data).
  • The right to file a complaint with the relevant supervisory authority.
  • The right to withdraw consent where applicable.

To exercise any of these rights, individuals should contact our DPO at dpo@supportnex.co.uk. Our privacy and security teams are trained to handle such requests in line with our “privacy by design” principles.

Incident Response SupportNEX has a detailed process in place to handle any data breach incidents. In case of a breach, we will notify data controllers, regulators, and affected individuals as required by law. Immediate action is taken to mitigate risks and prevent future breaches.

Legal Documentation Our legal team regularly reviews and updates all legal documentation to ensure it complies with the latest regulations, including the mandatory processor provisions under Article 28 of the GDPR.

For any queries related to this policy, please contact dpo@supportnex.co.uk

 

SupportNEX Terms and Conditions

These Terms and Conditions govern your use of the SupportNEX website and services. By accessing or using our services, you agree to abide by these Terms and Conditions. If you disagree with any portion of these terms, please discontinue using our services.

Acceptance of Terms

By visiting supportnex.co.uk and utilizing our services, you confirm that you have read, understood, and agreed to be bound by these Terms and Conditions.

Services Provided

SupportNEX offers a variety of IT support services, including:

  • Remote IT support
  • Software Licenses
  • IT device leasing
  • Website design and branding services
  • Data protection and cybersecurity solutions
  • Infrastructure Development & Management

We reserve the right to modify, update, or discontinue any part of our services at any time without prior notice.

Client Responsibilities

You agree to provide accurate, current, and complete information when engaging with SupportNEX services. You are responsible for safeguarding your account credentials and any activities conducted under your account. SupportNEX will not be liable for any loss or damages resulting from unauthorized access due to your failure to secure your account information.

Fees and Payment Terms

Our services may be subject to fees, which are detailed in specific service agreements. By utilizing our services, you agree to pay all applicable charges. Unless stated otherwise in writing, payments are due upon receipt of the invoice. All payments are non-refundable.

Limitation of Liability

SupportNEX is not responsible for any indirect, incidental, consequential, or punitive damage related to your use of our services. Our liability is limited to the fullest extent allowed by law, and in no event will our liability exceed the total fees paid by you for the services within the six months prior to the incident.

Indemnification

You agree to indemnify, defend, and hold harmless SupportNEX, its affiliates, employees, and agents from any claims, losses, liabilities, damages, costs, or expenses (including legal fees) arising from your use of our services, violation of these Terms and Conditions, or infringement of any third-party rights.

Privacy Policy

Your use of our services is governed by our Privacy Policy, which explains how we collect, use, and protect your personal data. By using our services, you consent to the terms outlined in our Privacy Policy.

Governing Law

These Terms and Conditions are governed by and construed in accordance with the laws of England and Wales. Any disputes arising out of or related to these terms will be subject to the exclusive jurisdiction of the courts of England and Wales.

Changes to Terms and Conditions

SupportNEX reserves the right to modify these Terms and Conditions at any time. We will notify you of changes by updating this page with the revised terms. Your continued use of our services after any modifications constitutes your acceptance of the new Terms and Conditions.

Contact Us

For any questions or concerns about these Terms and Conditions, please contact us at info@supportnex.co.uk

SupportNEX Remote Access Policy

This Remote Access Policy sets forth the guidelines for secure remote access to client systems by SupportNEX personnel. The policy is designed to ensure confidentiality, integrity, and security of client data during remote support and maintenance.

Purpose

The purpose of this policy is to outline the acceptable use and security requirements for remote access by SupportNEX IT Solutions to client systems. This policy ensures the protection of sensitive client information from unauthorized access and supports compliance with relevant data protection regulations.

Scope

This policy applies to all employees, contractors, and authorized personnel of SupportNEX who are granted remote access to client systems. It covers all devices and software used to establish such remote access.

Authorization for Remote Access

  • Client Authorization: Remote access must be explicitly authorized by the client prior to any connection. Clients must provide documented consent before SupportNEX personnel can access their systems.
  • Access Levels: SupportNEX grants remote access based on the principle of least privilege, meaning personnel can only access the systems and data necessary for their support duties.

Secure Remote Access Methods

  • Remote Access Tools: SupportNEX uses only secure, approved remote access tools that provide encryption and adhere to industry-standard security protocols.
  • Session Management: All remote sessions must be initiated with client consent and are continuously monitored for security compliance. SupportNEX maintains detailed logs of all remote access sessions for accountability.

Data Protection and Confidentiality

  • Protection of Client Data: SupportNEX personnel must handle all client data with care. Sensitive information must not be stored on SupportNEX devices unless explicitly permitted by the client.
  • Confidentiality Agreements: All employees and contractors must sign Non-Disclosure Agreements (NDAs) to ensure the protection of client data before accessing client systems.

Security Measures

  • Endpoint Security: All devices used for remote access must have up-to-date antivirus, anti-malware software, and enabled firewalls.
  • User Authentication: Secure authentication methods, including multi-factor authentication (MFA), are required for all remote access activities.

Monitoring and Compliance

  • Access Logs: SupportNEX maintains logs of all remote access sessions for auditing and monitoring purposes. Clients may request access to these logs.
  • Compliance Checks: Regular audits are conducted to ensure adherence to this policy and applicable data protection regulations.

Incident Reporting

SupportNEX personnel must report any suspected security incidents, unauthorized access attempts, or security concerns related to client systems to the designated client representative and internal IT management immediately.

Training and Awareness

SupportNEX provides regular training to all employees on secure remote access practices and the importance of protecting client data. Employees are encouraged to seek clarification on any aspects of this policy as needed.

Policy Review

This Remote Access Policy will be reviewed annually, or whenever significant changes occur in remote access technology, practices, or regulations. Clients will be notified of any updates or changes to this policy. Policy updated: 4th September 2024