Privacy Policy
This privacy notice explains how Revolution IT Ltd (“we”, “us”, “our”), a company registered in Ireland with its registered office at Cork, Ireland, company number 419381, processes personal data. Personal data means any information relating to an identified or identifiable individual. This notice is provided in accordance with the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018.
We process the following categories of personal data for the following purposes.
1. Business partner, customer and supplier data
This covers personal data relating to our customers, prospective customers and suppliers in the course of our business relationship with them. In particular: contact details of business contacts (name, job title, employer, business email address, telephone number) and information about the business relationship itself (services provided, correspondence, support tickets, invoicing).
We process this data to establish and conduct the business relationship, agree and manage contracts, deliver our services, and handle billing and account administration. Processing is carried out under Article 6(1)(b) GDPR (necessary for performance of a contract) and Article 6(1)(f) GDPR (legitimate interests), where our legitimate interest is maintaining our business relationships and responding to enquiries.
Providing this data is generally necessary to enter into or maintain the business relationship; without it, we may not be able to provide our services or respond to a request.
We may share this data with: our own staff and subcontractors who need it to deliver services, our accountants and auditors, and the IT platforms we use to run our business (see section 8, International transfers).
2. IT managed services — data processed on behalf of clients
As a managed service provider, Revolution IT delivers IT operations, security monitoring and helpdesk support to client organisations. In the course of this work, we may access or process personal data held within a client’s own systems (for example, data visible through remote monitoring and management tools, endpoint security platforms, email systems, or helpdesk tickets raised by a client’s own staff or customers).
Where we process such data, we do so as a data processor acting on the instructions of the relevant client, who remains the data controller for that data. The terms of that processing — including scope, security measures, retention and sub-processors — are set out in our contract or Data Processing Agreement with each client, not in this general notice. If you are an employee or customer of one of our clients and have a query about how your data is handled through our services, you should in the first instance contact that organisation directly.
Where we determine the purpose and means of processing business contact data of client staff for our own account management and support purposes (e.g. names and email addresses of the people we liaise with), that processing falls under section 1 above.
3. Email and general correspondence
We process personal data contained in email and other correspondence — the names, contact details and any other personal data included by senders and recipients — in order to communicate with customers, suppliers and other stakeholders.
The legal basis for this is Article 6(1)(f) GDPR (legitimate interest in business communication) or, where correspondence forms part of an existing contract, Article 6(1)(b).
We may share this data with employees or subcontractors handling the relevant matter, and with our IT service providers who host our email systems.
4. Website enquiries and cookies
When you contact us through our website’s contact form, we process the personal data you submit (such as your name, email address, and the content of your message) in order to respond to your enquiry. The legal basis for this is Article 6(1)(f) GDPR (legitimate interest in responding to enquiries) or, where your enquiry relates to a prospective contract, Article 6(1)(b).
Our website also uses cookies and/or analytics tools (such as Google Analytics) to understand how visitors use our site and to improve it. Where these are not strictly necessary for the site to function, we rely on your consent (Article 6(1)(a) GDPR), which you can withdraw at any time through our cookie settings or your browser settings. [Insert details of the specific analytics tool(s) used and link to your cookie consent banner/settings once confirmed.]
Providing data through the contact form is voluntary, but without it we cannot respond to your enquiry.
5. Premises security — CCTV and visitor log
Our office premises are monitored by CCTV, and visitors to our offices are asked to sign in via a visitor log. We process footage, and visitors’ names and time of entry/exit, for the purpose of ensuring the safety and security of our premises, staff and visitors.
The legal basis for this is Article 6(1)(f) GDPR — our legitimate interest in site security. Providing this data (for visitors) is not a legal requirement, but is necessary in order to be granted access to our premises.
CCTV footage and visitor logs are retained only for as long as necessary for security purposes (see section 7) and are only shared with external parties such as our security service provider, our IT service providers, or law enforcement authorities where there are reasonable grounds to do so.
6. Retention
We retain personal data only for as long as necessary for the purposes described above, taking into account legal, accounting and contractual requirements. Where we no longer have a lawful basis or business need to retain personal data, it is securely deleted or anonymised.
8. International transfers
We use a number of third-party IT platforms and service providers to run our business and deliver our services, including tools for professional services automation, endpoint security, communications, and productivity. Some of these providers are located, or process data on servers located, outside the European Economic Area (EEA) — in particular in the United States.
Where personal data is transferred outside the EEA, we ensure this is done in accordance with GDPR, relying on the European Commission’s Standard Contractual Clauses, an applicable adequacy decision, or another valid transfer mechanism, as appropriate to each provider. You can request further details of the safeguards in place by contacting us using the details in section 10.
9. Your rights
Under the GDPR, you have the right to:
- request access to the personal data we hold about you;
- request rectification of inaccurate personal data;
- request restriction of processing;
- request erasure of your personal data (“right to be forgotten”), where applicable;
- request a copy of your data in a portable format;
- object to processing carried out on the basis of legitimate interest.
To exercise any of these rights, please contact us using the details below.
10. Contact us / complaints
If you wish to exercise any of the rights above, or have a question about this notice, please contact:
Revolution IT Ltd
Unit 7 Udaras Business Park, Ballyvourney, Co. Cork, Ireland
Email: privacy@revolution-it.ie
If you believe we have not handled your personal data in accordance with the law, you also have the right to lodge a complaint with the Irish Data Protection Commission (www.dataprotection.ie).