PRIVACY POLICY.

View our Privacy Policy – Last Updated: 31 July 2026

1. About this Privacy Policy

Shackleton Technologies (Holdings) Limited respects your privacy and is committed to protecting your personal information.

This Privacy Policy explains how we collect, use, store, share and protect personal information when you:

  • visit our website;
  • contact us or submit a website enquiry;
  • communicate with us by telephone, email, post or social media;
  • subscribe to our newsletters or marketing communications;
  • apply for a role or send us your CV;
  • become, or represent, a client, prospective client, supplier, contractor or other business contact; or
  • otherwise communicate or do business with us.

 

This Privacy Policy should be read alongside our Cookie Policy, which explains how we use cookies and similar technologies on our website.

 

2. Data protection law

This Privacy Policy is provided in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Our use of cookies, similar technologies and electronic marketing communications is also governed by the Privacy and Electronic Communications Regulations 2003, as amended (PECR).

These laws have been amended by the Data (Use and Access) Act 2025. The Data (Use and Access) Act amended the existing UK data-protection framework rather than replacing the UK GDPR, Data Protection Act 2018 or PECR.

 

3. Who we are

Shackleton Technologies (Holdings) Limited is a company registered in Scotland under company number SC394067.

Our registered office is:

Unit 4, Delta House
Gemini Crescent
Dundee Technology Park
Dundee
DD2 1SW

For the personal information covered by this Privacy Policy, Shackleton Technologies (Holdings) Limited is normally the data controller. This means that we decide why and how that personal information is processed.

You can contact us about privacy, data protection or the use of your personal information at:

Email: enquiries@shacktech.co.uk
Telephone: 01382 250 900

 

4. When we act as a data processor

As a managed IT and technology provider, we may process personal information contained within our clients’ systems while providing services including:

  • managed IT support;
  • cyber security services;
  • cloud and hosting services;
  • Microsoft 365 support;
  • backup, monitoring and business-continuity services;
  • technical support and service-desk assistance; and
  • other managed technology services.

 

In these circumstances, the client will normally be the data controller and Shackleton will act as its data processor.

We process that information on the client’s documented instructions and in accordance with our contract and data-processing arrangements with that client.

Where your personal information is controlled by one of our clients, you should refer to that organisation’s privacy notice or contact it directly about your information rights.

This Privacy Policy primarily explains how Shackleton processes personal information for its own business purposes as a data controller.

 

5. Personal information we collect

The personal information we collect depends on how you interact with us.

 

Identity and contact information

This may include your:

  • name;
  • job title;
  • employer or organisation;
  • postal address;
  • email address; and
  • telephone number.

 

Enquiries and communications

This may include:

  • information submitted through our website forms;
  • emails, letters, telephone enquiries and other communications;
  • information about the services in which you are interested;
  • meeting notes;
  • appointment and call information;
  • social media messages, comments and enquiries; and
  • records of questions, requests or complaints.

 

Website enquiries are stored within the website’s WordPress submission system and are also sent to our shared enquiries@shacktech.co.uk mailbox.

Enquiries may be accessed or distributed to authorised members of our team so that the appropriate person can respond or provide the assistance requested.

 

Client, supplier and business information

This may include:

  • contact details for client and supplier representatives;
  • contracts, proposals, quotations and service records;
  • account-management and support communications;
  • information contained within support requests;
  • invoice and transaction information;
  • payment or bank information where required;
  • information about an organisation’s technology systems, service requirements and security needs; and
  • records necessary to manage our business relationship.

 

Marketing information

This may include:

  • your name, email address, job title and organisation;
  • your newsletter and marketing preferences;
  • how and when you subscribed;
  • records of consent where consent is used;
  • records of objections or unsubscribe requests; and
  • campaign delivery and engagement information provided through Mailchimp, such as whether an email was delivered or opened and whether a link was selected, where those features are enabled.

 

Website and technical information

This may include:

  • your IP address;
  • browser and device information;
  • operating system;
  • pages visited;
  • referring website;
  • dates, times and approximate duration of visits;
  • website security and error logs;
  • information about attempted unauthorised access or misuse; and
  • cookie and consent preferences.

 

Where required, we obtain consent before using optional analytical cookies or embedded-media technologies. Further information is available in our Cookie Policy.

 

Social media information

When you interact with one of our official social media profiles, including through Facebook or LinkedIn, we may receive:

  • your name or social media username;
  • publicly available profile information;
  • the content of comments, messages or enquiries;
  • reactions to or interactions with our content; and
  • any other information you choose to provide.

 

The relevant social media platform will also process information about your use of its service for its own purposes.

 

Recruitment information

Where you apply for a role or send a CV to recruitment@shacktech.co.uk, we may collect:

  • your name and contact information;
  • your CV and covering letter;
  • employment history;
  • qualifications, skills and professional experience;
  • salary expectations and availability;
  • interview notes and assessment information;
  • references, where appropriate; and
  • any other information you choose to provide as part of your application.

 

You should avoid including information that is not relevant to your application.

Where you provide special-category information, such as information about your health, disability or other protected characteristics, we will only use it where necessary and where an appropriate legal condition applies. This may include arranging reasonable adjustments, meeting employment-law obligations or establishing, exercising or defending legal claims.

 

6. How we collect personal information

We may collect personal information:

  • directly from you;
  • through our website forms;
  • through email, telephone calls, meetings or correspondence;
  • through comments, messages and other interactions with our official social media profiles;
  • when you subscribe to newsletters or marketing communications;
  • when you apply for a role or submit a CV;
  • through our contractual and business relationship with you or your organisation;
  • through cookies and website technologies, where permitted;
  • from colleagues or representatives within your organisation;
  • from professional advisers, suppliers, referral partners or business contacts where appropriate; and
  • from publicly available professional, corporate or business sources where it is lawful and reasonable to do so.

 

7. How and why we use personal information

We only process personal information where we have an appropriate lawful basis.

 

Responding to enquiries and preparing proposals

We use information to respond to enquiries, arrange meetings, understand requirements and prepare quotations or proposals.

Our lawful basis is normally taking steps at your request before entering into a contract and our legitimate interests in responding to business enquiries.

 

Providing services and managing client relationships

We use information to enter into and perform contracts, deliver services, provide technical support, manage accounts and communicate with clients.

Our lawful basis may be performance of a contract, our legitimate interests in managing our services and client relationships, and compliance with legal obligations.

 

Managing suppliers, contractors and business contacts

We use information to communicate with suppliers and contractors, purchase products or services, administer agreements and manage our business relationships.

Our lawful basis may be performance of a contract and our legitimate interests in operating our business.

 

Storing and distributing website enquiries

We store website submissions in WordPress and send them to our shared enquiries mailbox so that the appropriate member of the team can respond.

Our lawful basis is normally taking steps requested before entering into a contract and our legitimate interests in responding efficiently to enquiries.

 

Operating and securing our website and systems

We use technical and security information to operate, maintain, monitor and protect our website, networks, services and business systems.

Our lawful basis is our legitimate interests in maintaining reliable and secure systems, preventing misuse and protecting our business, clients and website visitors. We may also process information to comply with legal obligations.

 

Preventing fraud, misuse and cyber incidents

We may use information to identify, prevent, investigate and respond to fraud, cyber incidents, attempted unauthorised access and other misuse.

Our lawful basis is our legitimate interests in protecting our business, clients and systems and, where applicable, compliance with legal obligations.

 

Google Analytics

Where you consent, we use Google Analytics to understand how visitors use our website and to improve its content and performance.

Our lawful basis is consent.

 

Embedded media

Where you consent to the relevant technologies, we may provide embedded YouTube or Vimeo content.

Our lawful basis is consent where cookies or similar technologies require it.

 

Newsletters and marketing communications

We use contact and marketing-preference information to send newsletters, service information and other marketing communications.

Our lawful basis may be:

  • consent where consent is required;
  • our legitimate interests where business-to-business marketing is permitted; or
  • the existing-customer or “soft opt-in” provisions where all relevant legal conditions are met.

 

Recording marketing objections

We retain information about unsubscribe requests, withdrawals of consent and objections to marketing so that we can respect those choices.

Our lawful basis is compliance with legal obligations and our legitimate interests in ensuring that marketing preferences are followed.

 

Social media

We use information to operate our social media profiles, respond to comments and messages, moderate content, manage enquiries and communicate information about our services.

Our lawful basis is normally our legitimate interests in communicating with clients, prospective clients and other business contacts, promoting our services and managing our social media presence.

Where a social media message relates to a potential service, we may also process information to take steps requested before entering into a contract.

 

Recruitment

We use recruitment information to assess candidates, communicate with applicants, arrange interviews, make recruitment decisions and meet employment-related legal responsibilities.

Our lawful basis may be taking steps before entering into an employment contract, our legitimate interests in recruiting suitable employees and compliance with legal obligations.

 

Financial administration

We use information to administer payments, invoices, accounting records and taxation.

Our lawful basis may be performance of a contract and compliance with legal obligations.

 

Legal claims and regulatory matters

We may use information to establish, exercise or defend legal claims, respond to regulators and meet legal or professional obligations.

Our lawful basis may be our legitimate interests and compliance with legal obligations.

 

Information-rights requests and complaints

We use personal information to verify, manage and respond to information-rights requests and data-protection complaints.

Our lawful basis is compliance with legal obligations.

 

8. Legitimate interests

Where we rely on legitimate interests, we consider:

  • whether the processing is necessary for the identified purpose;
  • whether the purpose could reasonably be achieved in another way;
  • the nature of the information involved;
  • what an individual would reasonably expect;
  • the potential impact on the individual; and
  • whether the individual’s rights and interests override our interests.

 

Our legitimate interests may include:

  • operating and developing our business;
  • responding to business enquiries;
  • delivering and improving our services;
  • communicating with clients and business contacts;
  • protecting our systems and information;
  • preventing misuse and fraud;
  • managing suppliers and contractors;
  • recruiting employees;
  • promoting relevant services to business contacts; and
  • establishing or defending legal claims.

 

You have the right to object to processing based on legitimate interests in certain circumstances.

 

9. Marketing communications

We use Mailchimp to manage and send newsletters and marketing communications.

We may send marketing communications where:

  • you have specifically subscribed or provided valid consent;
  • you are an existing client or contact and the law permits us to contact you about relevant services;
  • the applicable existing-customer or soft-opt-in requirements are met; or
  • you represent a corporate organisation and business-to-business marketing is permitted.

 

We will identify ourselves in our marketing communications and provide a clear way to unsubscribe.

You can stop receiving marketing communications at any time by:

 

Unsubscribing from marketing will not prevent us from contacting you about:

  • an existing contract or service;
  • a support or security issue;
  • your account;
  • an enquiry you have made; or
  • another necessary administrative matter.

 

We may retain limited information on a suppression list after you unsubscribe or object. This enables us to record and respect your preference and helps prevent you from being accidentally added to a future marketing campaign.

The rules for electronic marketing differ depending on whether the recipient is an individual subscriber or a corporate subscriber. Corporate marketing emails may be sent without prior consent in some circumstances, but the sender must identify itself and provide a valid means of opting out. Marketing to individual subscribers normally requires consent or a valid soft opt-in.

 

10. Social media

We operate business profiles on social media platforms, including Facebook and LinkedIn.

When you interact with one of our profiles by following our page, reacting to or commenting on a post, tagging us or sending us a direct message, we may use the information available to us to:

  • respond to messages, comments and enquiries;
  • manage our social media profiles;
  • moderate content where necessary;
  • communicate information about our services;
  • manage business relationships; and
  • understand how people engage with our content.

 

Our lawful basis is normally our legitimate interests in communicating with clients, prospective clients and other business contacts, promoting our services and managing our social media presence.

Where you contact us about purchasing services, we may also process information to take steps at your request before entering into a contract.

Social media platforms process personal information for their own purposes under their own privacy policies, terms and account settings. We do not control all processing carried out by those platforms.

The platforms may provide us with aggregated statistics or insights about how people interact with our profiles and content.

Where a social media message becomes a business enquiry, client matter, complaint or recruitment enquiry, we may retain relevant information within our business systems in accordance with the retention periods described in this Privacy Policy.

Please avoid including sensitive, confidential or unnecessary personal information in public comments or social media messages.

 

11. Recruitment and unsolicited CVs

Applications and CVs should be sent to:

recruitment@shacktech.co.uk

We may use recruitment information to:

  • assess suitability for current roles;
  • communicate with applicants;
  • arrange and conduct interviews;
  • consider reasonable adjustments;
  • obtain references where appropriate;
  • make recruitment decisions; and
  • meet our legal and regulatory responsibilities.

 

If your application is unsuccessful, we will normally retain your recruitment information for up to six months after the recruitment process has ended.

Where you send us an unsolicited CV and no suitable vacancy exists, we will normally retain it for no longer than six months.

We may ask whether you would like us to retain your information for up to 12 months so that we can contact you if a suitable future opportunity becomes available.

If you become an employee, relevant recruitment information may be transferred to your personnel record and retained in accordance with our employee record-retention arrangements.

 

12. Who we share personal information with

We may share personal information with:

  • authorised Shackleton employees and contractors who require access for legitimate business purposes;
  • website hosting, maintenance, security and technical-support providers;
  • Microsoft 365 and other communication or business-system providers;
  • Mailchimp for newsletter and marketing management;
  • Google where Google Analytics or other relevant Google services are used;
  • YouTube and Vimeo where embedded content is enabled;
  • social media platforms where you interact with our profiles;
  • accountants, auditors, solicitors, insurers and other professional advisers;
  • recruitment providers, referees or professional advisers where appropriate;
  • regulators, courts, law-enforcement bodies and public authorities where required;
  • prospective purchasers, investors and advisers involved in a sale, merger or business reorganisation; and
  • other service providers necessary to operate our business or provide our services.

We do not sell personal information.

Where another organisation processes personal information on our behalf, we require it to protect that information and only use it for the agreed purposes.

 

13. International transfers

Some of our technology and service providers, including Mailchimp, Microsoft, Google and certain social media, video or cloud-service providers, may process personal information outside the United Kingdom.

Where personal information is transferred outside the UK, we take steps to ensure that the transfer is protected by a mechanism permitted under UK data-protection law.

Depending on the provider and destination, this may include:

  • UK adequacy regulations;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to approved standard contractual clauses;
  • an approved data-protection framework; or
  • another safeguard or exception permitted by UK data-protection law.

 

Further information about the safeguards applying to a particular provider is available on request.

 

14. How long we retain personal information

We keep personal information only for as long as reasonably necessary for the purpose for which it was collected and to meet legal, accounting, contractual, security and regulatory requirements.

Our normal retention approach is as follows.

Website enquiries

Website enquiries that do not lead to a client relationship will normally be retained for up to 24 months after the last meaningful contact.

Client, contract and supplier records

Client, contract, transaction and supplier records will generally be retained for up to six years after the relevant relationship or transaction ends, unless a longer period is legally required.

Marketing contacts

Marketing information will be retained for as long as we have an appropriate marketing relationship, until you unsubscribe or object, or until we determine that the information is no longer required.

Marketing suppression records

Limited suppression information may be retained for as long as necessary to ensure that an unsubscribe request or objection continues to be respected.

Social media enquiries

Social media enquiries or messages transferred into our business systems will be retained in accordance with the retention period applying to the relevant enquiry, complaint, recruitment matter or business relationship.

Recruitment records

Unsuccessful job applications and unsolicited CVs will normally be retained for up to six months.

Where you agree that we may retain your CV for possible future opportunities, it may be retained for up to 12 months.

Website analytics

Website analytics information will be retained in accordance with our Google Analytics settings and Cookie Policy.

Website and security logs

Website, access and security logs will be retained in accordance with our hosting and security arrangements, or for longer where required to investigate an incident, prevent fraud or defend a legal claim.

Data-protection requests and complaints

Records relating to data-protection requests and complaints will be retained for as long as necessary to manage the matter and demonstrate compliance. They may normally be retained for up to six years after the matter is closed where this is necessary for legal or regulatory purposes.

Information may be retained for longer where:

  • required by law;
  • a dispute or legal claim is anticipated or ongoing;
  • necessary to investigate fraud, misuse or a security incident; or
  • another legitimate and lawful reason applies.

 

15. Keeping personal information secure

We use appropriate technical and organisational measures designed to protect personal information against:

  • unauthorised access;
  • accidental loss;
  • misuse;
  • alteration;
  • unauthorised disclosure; and
  • destruction.

 

These measures include:

  • restricting access to people who require information for legitimate business purposes;
  • using appropriate authentication and access controls;
  • maintaining security and monitoring measures;
  • protecting systems against unauthorised access and malicious activity;
  • using reputable technology and service providers; and
  • applying security measures proportionate to the nature and sensitivity of the information.

 

People who have access to personal information are expected to handle it securely and in accordance with their duties and our internal requirements.

No internet-based system can be guaranteed to be completely secure. However, we regularly consider the risks associated with our systems and take appropriate steps to manage them.

 

16. Your data-protection rights

Depending on the circumstances and the lawful basis being used, you may have the right to:

  • request access to personal information we hold about you;
  • ask us to correct inaccurate or incomplete information;
  • ask us to erase your information;
  • ask us to restrict how your information is used;
  • object to processing based on legitimate interests;
  • object at any time to the use of your information for direct marketing;
  • receive certain information in a portable format;
  • withdraw consent where processing is based on consent;
  • ask for human intervention in relation to certain automated decisions; and
  • complain about how your information has been handled.

Withdrawing consent will not affect the lawfulness of processing carried out before consent was withdrawn.

Some rights are subject to legal conditions and exemptions. We may need to confirm your identity before acting on a request.

We do not normally charge a fee for exercising data-protection rights, although the law permits a reasonable fee or refusal in certain limited circumstances.

To exercise your rights, contact:

enquiries@shacktech.co.uk

 

17. Automated decision-making

We do not currently make decisions about individuals based solely on automated processing where those decisions would produce legal or similarly significant effects.

If this changes, we will provide appropriate information about:

  • the automated processing involved;
  • the reasoning or logic used;
  • the likely significance and consequences; and
  • the rights and safeguards available.

 

18. Data-protection complaints

If you are concerned about how we have collected or used your personal information, please contact us so that we can investigate.

You can submit a data-protection complaint by emailing:

enquiries@shacktech.co.uk

Please include enough information for us to understand the issue and identify the personal information or processing concerned.

We will:

  • provide a clear way for you to make a complaint;
  • acknowledge receipt of your complaint within 30 days;
  • take appropriate steps to investigate it without undue delay;
  • make appropriate enquiries;
  • keep you informed where appropriate; and
  • communicate the outcome to you without undue delay.

 

You also have the right to raise a concern with the Information Commissioner’s Office, the UK supervisory authority for data protection.

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Telephone: 0303 123 1113

We would appreciate the opportunity to address your concern, but you are not required to contact us before approaching the Information Commissioner’s Office.

 

19. Cookies and embedded content

Our website uses necessary technologies to operate our Cookie Control system and remember visitors’ privacy choices.

Subject to your choices, we may also use:

  • Google Analytics;
  • embedded YouTube content; and
  • embedded Vimeo content.

Our Cookie Policy explains:

  • which technologies are used;
  • their purposes;
  • their providers;
  • how long relevant cookies may remain; and
  • how you can accept, reject or change your preferences.

 

20. Links to other websites

Our website and social media content may contain links to websites operated by other organisations.

We are not responsible for the content, security or privacy practices of external websites.

You should review the privacy information provided by the relevant organisation before submitting personal information to it.

 

21. If you do not provide information

Where we need personal information to:

  • respond to an enquiry;
  • prepare a proposal;
  • enter into or perform a contract;
  • deliver services;
  • assess a job application; or
  • comply with a legal requirement,

we may be unable to proceed if the necessary information is not provided.

 

22. Changes to this Privacy Policy

We may update this Privacy Policy where:

  • our services or business practices change;
  • we introduce, remove or change systems or service providers;
  • legal or regulatory requirements change;
  • our use of personal information changes; or
  • we identify that the policy requires clarification.

 

The date at the top of this page shows when the Privacy Policy was last updated.

We will review this Privacy Policy periodically and after significant changes to our business, website, systems or personal-information processing.

 

23. Contact us

Questions, information-rights requests and data-protection complaints should be sent to:

Shackleton Technologies (Holdings) Limited
Unit 4, Delta House
Gemini Crescent
Dundee Technology Park
Dundee
DD2 1SW

Email: enquiries@shacktech.co.uk
Telephone: 01382 250 900