Tech Updates

Tech UpdatesTech UpdatesTech UpdatesTech Updates

Tech Updates

Tech UpdatesTech UpdatesTech Updates

Privacy Policy

This manual sets out Tech Updates’ approach to privacy, information security, business-to-business marketing, artificial intelligence, staff responsibilities and data governance. It is intended to demonstrate compliance with the UK GDPR, the Data Protection Act 2018 and PECR while reflecting the company’s operational practices.


1. Privacy Policy


Purpose


Tech Updates is committed to processing personal information fairly, lawfully, transparently and securely. This policy explains what information we collect, why we collect it and how we protect it.


Lawful Basis


Our processing relies on the lawful bases of Legitimate Interests, Contract, Consent and Legal Obligation where appropriate. The majority of our B2B marketing activities are undertaken under Legitimate Interests following documented assessments that balance business needs against the rights and freedoms of individuals.


Business-to-Business Marketing


We specialise in B2B marketing. Professional business contact information may be sourced from reputable providers such as Cognism, ZoomInfo and similar services, publicly available business sources, company websites, event registrations and direct enquiries. We target individuals based on their professional role, seniority and business relevance. Every campaign contains a clear unsubscribe mechanism and suppression requests are honoured promptly.


Data Sharing


We do not sell personal information. Prospect information is not disclosed to clients unless an individual has explicitly double opted-in or otherwise directly requested contact from that client. We use an email service platform solely to manage campaign delivery. Access is restricted to authorised, trained users protected by MFA and role-based permissions.


International Transfers


We do not intentionally transfer personal information outside the United Kingdom for commercial purposes. Where approved technology providers process limited information internationally as part of their infrastructure, appropriate UK GDPR safeguards are maintained.


Cookies


Our website is a brochure-style website and does not use analytics, marketing or behavioural tracking cookies. We do not use Google Analytics, Meta Pixel, LinkedIn Insight Tag or similar tracking technologies.


AI & Automated Decisions


Approved AI tools may be used to support productivity, communications, research, data quality and business processes. AI assists employees and does not replace human decision-making. We do not make decisions that produce legal or similarly significant effects based solely on automated processing.


Your Rights


Individuals may exercise their rights of access, rectification, erasure, restriction, objection, portability, withdrawal of consent where applicable and the right to complain to the Information Commissioner’s Office. Requests are handled promptly and in accordance with statutory timescales.


2. Information Security Policy


All company systems are protected using Multi-Factor Authentication (MFA/2FA).


Strong unique passwords are generated and stored within approved password managers. Routine password changes are not mandated unless compromise is suspected, in line with modern NCSC guidance.


Company devices are encrypted, protected by anti-malware, receive regular security patches and use secure authentication.


Access to systems follows the principle of least privilege and is reviewed regularly.


Security events may be logged and monitored to protect company and client information.


Business data is securely backed up and recovery procedures are tested periodically.


Only authorised software may be installed on company equipment.


Remote Working


Remote working is permitted using company-managed devices protected by MFA and encryption. Staff must not use public Wi-Fi when accessing company systems. Approved mobile hotspots should be used where connectivity is required. Confidential discussions should not take place in public locations and devices must not be left unattended.


3. Data Lifecycle & Retention


CEC follows a controlled data lifecycle consisting of collection, validation, secure storage, campaign processing, suppression management, retention and secure deletion.


Marketing and business relationship records may be retained for up to six years following the last meaningful interaction where required to support ongoing business relationships, contractual obligations, legal compliance, audit requirements and dispute resolution. Information is securely deleted once retention periods expire.


4. AI Governance


Only approved AI platforms may be used for business purposes. Employees remain responsible for verifying AI-generated outputs before use. Confidential client information should only be processed through approved systems and AI must not be used to make autonomous legal or employment decisions. AI usage is reviewed periodically to ensure continued compliance with UK GDPR and company security standards.


5. Data Breach Response


All employees must immediately report suspected personal data breaches. Incidents are investigated, contained and risk assessed without delay. Where required by law, the ICO will be notified within the applicable statutory timeframe and affected individuals will be informed where there is a high risk to their rights and freedoms. Lessons learned are documented to improve future security.


6. Staff Responsibilities & Training


All staff receive GDPR, privacy, phishing awareness, information security and AI awareness training during onboarding and at regular intervals. Employees are responsible for protecting confidential information, reporting incidents, following acceptable use requirements and complying with this manual.


7. Governance & Continuous Improvement


CEC reviews this manual annually, monitors changes in legislation and guidance, reviews suppliers handling personal information, and continually improves security controls, policies and staff awareness.


Document Owner and Approval


The Managing Director is the owner of this document and is responsible for ensuring that this procedure is reviewed in line with the review requirements of the GDPR.


Signed: Christine Cockerton                         Date: 20/07/2026

Copyright © 2026 Tech Updates - All Rights Reserved.

  • Privacy Policy

Powered by

This website uses cookies.

We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.

DeclineAccept