ION IT Limited

Data Protection & GDPR

How ION IT Limited handles UK GDPR responsibilities as controller and processor.

ION IT takes data protection seriously. This page explains how data protection is handled across our IT, connectivity, hosting, email, domain and support services.

UK data-protection framework

Our handling of personal data is governed by applicable UK data-protection law, including the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations where relevant, and subsequent amendments including the Data (Use and Access) Act 2025.

Controller and processor roles

ION IT is a controller for information used to manage our own customers, suppliers, enquiries, billing, security and legal obligations. For many managed services, we act as a processor because the customer controls the business data held in its mailboxes, servers, backups, cloud services or applications.

Roles are determined by the facts, not simply by labels. Where ION IT acts as a processor, we process personal data only on documented instructions, subject to the service agreement, legal requirements and necessary actions to protect the service.

Data-processing commitments

  • Personnel and contractors with access are subject to confidentiality obligations.
  • Access is limited according to operational need and technical role.
  • Appropriate security measures are selected for the service and risk.
  • Sub-processors are used where necessary to deliver services and are subject to suitable contractual controls.
  • We assist customers, within the scope of the service, with rights requests, security incidents and compliance information.
  • At the end of a service, data is returned or deleted according to the contract, technical capability, retention requirements and backup lifecycle.

Security incidents

Suspected personal-data breaches should be reported promptly to Contact us online with the affected system, time discovered, nature of the event and immediate containment already taken. Where ION IT is a processor, we notify the relevant customer without undue delay after becoming aware of a personal-data breach affecting the service.

Data-subject requests

Requests concerning data controlled by an ION IT customer should normally be directed to that customer. We will assist the customer where the request concerns systems we operate. Requests concerning ION IT's own records may be sent directly to us.

Data protection complaints

A complaint can be made by email or post using the contact details on this page. Please identify the data or service concerned and explain the outcome sought. We will acknowledge a data-protection complaint within 30 days, investigate it without undue delay, provide appropriate progress information where needed and explain the outcome. A complaint may also be made to the Information Commissioner's Office.

Further information

Our Privacy Notice contains more detail about categories of data, purposes, lawful bases, sharing, transfers, retention and individual rights. Customer-specific processing arrangements may also be set out in a quotation, contract, service schedule or data-processing agreement.