Last updated: 13 August 2026

1. About this policy

2e-volve (UK) Ltd respects your privacy and is committed to protecting your personal information.

This Privacy Policy explains how we collect, use, store and protect personal information when you:

  • Visit our website;
  • Contact us or request information;
  • Ask us to provide a quotation;
  • Become or act on behalf of a client;
  • Supply products or services to us; or
  • Otherwise communicate or do business with us.

This policy should be read alongside our Cookie Policy.

2. Who we are

2e-volve (UK) Ltd is the data controller responsible for the personal information covered by this policy.

Company name: 2e-volve (UK) Ltd
Company number: SC261922
Registered office: Office 3, STEP Commercial Centre, Stirling Enterprise Park, Stirling, FK7 7RP
Email: sales@2e-volve.com
Telephone: 01786 474318

When we process information on behalf of a managed IT or website services client, the client may be the data controller and 2e-volve may act as its data processor. In those circumstances, our processing is governed by our agreement with that client.

3. Information we may collect

Depending on how you interact with us, we may collect:

Contact information

This may include your:

  • Name;
  • Job title;
  • Organisation;
  • Business address;
  • Email address; and
  • Telephone number.

Enquiry and correspondence information

This includes information you provide when:

  • Completing a website contact form;
  • Sending us an email;
  • Calling us;
  • Requesting a quotation;
  • Reporting a support issue; or
  • Communicating with us in another way.

Client and supplier information

Where you or your organisation does business with us, we may collect:

  • Business contact details;
  • Details of the services provided or received;
  • Contract and account information;
  • Support requests and service records;
  • Invoices, transactions and payment records; and
  • Relevant correspondence.

We do not normally collect complete payment-card details through our website.

Technical and security information

Our systems may record limited technical information required to operate and protect the website, including:

  • Internet Protocol address;
  • Browser and device type;
  • Date and time of access;
  • Security events;
  • Error records; and
  • Information associated with attempted misuse of the website.

We do not use this information to track visitors for advertising or marketing purposes.

4. How we collect information

We may collect personal information:

  • Directly from you;
  • From another person within your organisation;
  • Through our website contact form;
  • During the provision of IT, website or managed services;
  • From suppliers and professional advisers;
  • From publicly available business sources, including company websites, Companies House and professional networking platforms; or
  • Automatically through essential website and security technologies.

5. How we use personal information

We may use personal information to:

  • Respond to enquiries;
  • Prepare quotations and proposals;
  • Provide and manage our services;
  • Deliver technical support;
  • Communicate with clients and suppliers;
  • Manage contracts, accounts, invoices and payments;
  • Maintain accurate business records;
  • Protect our website, systems, clients and business from security threats, fraud or misuse;
  • Improve our services and business operations;
  • Establish, exercise or defend legal claims;
  • Comply with legal, tax, regulatory and contractual requirements; and
  • Send relevant business communications where permitted by law.

We will not sell your personal information.

6. Our lawful bases

UK data protection law requires us to have a lawful basis for using personal information. Depending on the circumstances, we may rely on:

Contract

We may process information where it is necessary to enter into or perform a contract with you.

Where our contract is with an organisation rather than an individual, we may instead rely on our legitimate interests in administering that business relationship.

Legitimate interests

We may process information where it is necessary for our legitimate business interests and those interests are not overridden by your rights.

These interests may include:

  • Responding to business enquiries;
  • Managing client and supplier relationships;
  • Operating and improving our business;
  • Maintaining network and information security;
  • Preventing fraud and misuse;
  • Recovering money owed to us; and
  • Communicating appropriately with existing clients and relevant business contacts.

Where required, we assess and document our legitimate interests before relying on this basis.

Legal obligation

We may process information when necessary to comply with legal obligations, including tax, accounting, employment and regulatory requirements.

Consent

Where we rely on your consent, you may withdraw it at any time by contacting us. Withdrawing consent does not affect processing carried out before consent was withdrawn.

7. Business communications and marketing

We may occasionally contact existing clients or relevant business contacts about services that we reasonably believe may be of interest to them, where permitted by law.

You can ask us to stop sending marketing communications at any time by:

  • Using any unsubscribe option included in the communication; or
  • Contacting us using the details in this policy.

We may continue to send essential service, account, security or contractual communications where necessary.

8. Sharing personal information

We may share personal information with trusted organisations where necessary, including:

  • IT, hosting, cloud and communications providers;
  • Software and service-platform providers;
  • Payment, banking and accounting providers;
  • Professional advisers, including accountants, lawyers and insurers;
  • Suppliers and subcontractors involved in providing our services;
  • Public authorities, regulators, law-enforcement bodies or courts where required; and
  • A prospective purchaser, investor or adviser if our business undergoes a sale, restructuring or similar transaction.

Service providers handling personal information on our behalf must protect it and may only use it in accordance with our instructions and applicable law.

We may also disclose information where necessary to protect our rights, systems, clients, staff or other people.

9. International transfers

Some of our service providers may store or process information outside the United Kingdom.

Where personal information is transferred internationally, we take appropriate steps to ensure that it remains protected. These measures may include:

  • Transferring information to a country recognised by the UK as providing adequate protection;
  • Using approved contractual safeguards; or
  • Relying on another lawful transfer mechanism.

Further information about the safeguards used for a particular transfer can be requested using the contact details in this policy.

10. How long we retain information

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including to meet legal, accounting, tax, contractual and reporting requirements.

In determining an appropriate retention period, we consider:

  • The nature and sensitivity of the information;
  • Why we collected it;
  • Whether we continue to have a business or legal need for it;
  • Applicable limitation periods; and
  • Legal, regulatory and contractual requirements.

As a general guide:

  • Unsuccessful enquiries and quotations are normally retained for up to two years after the last meaningful contact;
  • Client and supplier records are normally retained for the duration of the relationship and for up to six years afterwards;
  • Financial and transaction records are normally retained for at least six years where required for tax or accounting purposes;
  • Security and technical records are retained only for as long as reasonably necessary to protect and administer our systems; and
  • Marketing preferences may be retained so that we can respect an opt-out request.

Information may be retained for longer where necessary to resolve a dispute, respond to a complaint, establish or defend a legal claim, or comply with a legal requirement.

When information is no longer required, it will be securely deleted, destroyed or anonymised.

11. Information security

We use appropriate technical and organisational measures to protect personal information from:

  • Unauthorised access;
  • Accidental loss;
  • Misuse;
  • Alteration;
  • Disclosure; and
  • Destruction.

Access to personal information is restricted to people who have a genuine business need to use it. Those people are required to handle the information securely and confidentially.

No internet-based system can be guaranteed to be completely secure. If we become aware of a personal data breach, we will investigate it and make any required notifications.

12. Your data protection rights

Depending on the circumstances, you may have the right to:

  • Ask for access to the personal information we hold about you;
  • Ask us to correct inaccurate or incomplete information;
  • Ask us to delete your information;
  • Ask us to restrict how we use your information;
  • Object to processing based on legitimate interests;
  • Object to direct marketing at any time;
  • Ask for certain information to be transferred to you or another organisation;
  • Withdraw consent where processing is based on consent; and
  • Complain about how we use your information.

These rights are not absolute and may be subject to legal exemptions.

You will not normally have to pay to exercise your rights. We may ask for information to confirm your identity before responding.

To exercise a right, contact us using the details in section 2.

13. Data protection complaints

If you have a concern or complaint about how we have handled your personal information, please contact us using the details in section 2.

We will:

  • Acknowledge your complaint within 30 days;
  • Investigate it appropriately; and
  • Explain the outcome and any action we have taken.

If you are dissatisfied with our response, you may complain to the Information Commissioner’s Office:

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Telephone: 0303 123 1113
Website: www.ico.org.uk

We would appreciate the opportunity to address your concern directly, but you do not have to contact us before approaching the ICO.

14. Cookies

Our website uses essential cookies only. We do not use cookies for advertising, visitor profiling or website analytics.

Further information is available in our Cookie Policy.

15. Links to other websites

Our website may contain links to websites operated by other organisations.

We are not responsible for the privacy practices or content of external websites. You should review the privacy policy of any external website before providing personal information.

16. Children’s information

Our website and services are intended for businesses and are not directed at children. We do not knowingly collect personal information from children through the website.

17. Automated decision-making

We do not use personal information collected through our website to make solely automated decisions that have legal or similarly significant effects on individuals.

18. Changes to this policy

We may update this Privacy Policy to reflect changes to our website, services, business practices or legal obligations.

The latest version will be published on our website with its effective date.