Privacy Policy
Effective date: 1 November 2025
Who we are: Kent Electronic Services (KES) Limited (“KES”, “we”, “us”, “our”)
Company number: 10671458 • VAT: GB267703974
Registered office: 4 Bloors Lane, Rainham, Gillingham, Kent, United Kingdom, ME8 7EG
Telephone: 01622 721000 • Email: info@kesuk.net
Overview
We are the data controller for the personal data described in this notice unless stated otherwise. This notice explains how we collect, use, share and protect personal data in line with the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).
If you are a KES client and we handle personal data on your behalf (e.g., via our managed IT, security, backup or support services), we act as your data processor for that processing. In those cases, our Data Processing Agreement (DPA) and your contract with us set out the terms of processing.
1) What data we collect
- Identity & contact data: name, job title, employer, work email, phone, postal address.
- Account & contract data: proposals, orders, service and licence details, contract correspondence.
- Support & operations data: tickets, chat/phone recordings (where applicable), device identifiers, usernames (not passwords), activity logs and audit trails generated by our RMM/EDR/XDR and firewall platforms.
- Billing data: purchase orders, invoices, payment records (we do not store full card details).
- Marketing preferences: subscriptions, opt-in/opt-out records, event attendance.
- Website/analytics data: IP address, device, browser, cookie identifiers and pages viewed.
- Recruitment data (when you apply): CV, cover letter and interview notes.
We do not seek special category data (e.g., health, ethnicity). Please do not include it in tickets or emails. If it is unavoidably provided, we will handle it only where a UK GDPR condition applies (e.g., explicit consent or legal claims).
We do not target or knowingly collect data from children.
2) How we obtain data
- Directly from you (enquiries, meetings, phone, email, web forms, events).
- From your employer or colleagues when we provide services to your organisation.
- From our suppliers/partners (e.g., Microsoft, WatchGuard, N-able/Cove, Datto, Intuit QuickBooks) when necessary to provision services and licences.
- From public sources and business databases (e.g., Companies House, LinkedIn) and our telemarketing partners, where permitted by law.
- Automatically via our website, remote monitoring, security and backup systems.
3) Purposes and lawful bases
Provide and manage services — Onboarding, device and user setup, licensing, backups, security monitoring, support tickets — Lawful basis: Contract (Art. 6(1)(b)).
Billing & account administration — Invoicing, purchase orders, credit control, tax records — Lawful basis: Legal obligation (Art. 6(1)(c)); Contract.
Security & service quality — Threat detection, incident response, audit logs, service improvement — Lawful basis: Legitimate interests (security, service delivery) (Art. 6(1)(f)).
Sales & marketing — Relevant B2B emails/calls to business contacts; event invites; website analytics; cookie-based tracking (where consented) — Lawful basis: Legitimate interests for B2B marketing; Consent where required by PECR and for non-essential cookies.
Relationship management — CRM, pipeline, renewals, satisfaction surveys — Lawful basis: Legitimate interests.
Legal & compliance — Handling complaints, legal claims, regulatory responses — Lawful basis: Legal obligation; Legitimate interests.
Recruitment — Assessing candidates and making offers — Lawful basis: Legitimate interests; Contract if hired.
You can object to processing based on our legitimate interests. Where we rely on consent (e.g., certain marketing or cookies), you can withdraw it at any time.
4) Marketing, cookies and PECR
We may send business-to-business marketing to corporate subscribers about relevant services. We will always include a clear unsubscribe option. For non-essential cookies and similar technologies, we will ask for your consent via our cookie banner. See our Cookie Policy for details of cookies used and how to change your settings.
Cookie Policy: [link to your cookie policy]
5) Sharing your data
We share data where necessary with service providers/processors (e.g., Microsoft 365, WatchGuard, N-able (Cove), Datto (incl. Autotask & SaaS Defense), Intuit QuickBooks, hosting and cloud providers, telephony, email and SMS platforms, CRM/marketing tools, and our professional advisers); partners/vendor portals; delivery companies; regulators/law enforcement or courts; and prospective buyers under confidentiality during corporate transactions. We require processors to provide appropriate security and to process data only on our documented instructions.
6) International transfers
Some recipients are outside the UK (for example, in the EEA or USA). Where we transfer personal data internationally we will ensure a lawful safeguard is in place, such as a UK adequacy regulation; International Data Transfer Agreement (IDTA) or UK Addendum to the EU Standard Contractual Clauses; and/or the UK-US Data Bridge where applicable. Contact us for details.
7) Retention periods
- Enquiry and CRM data: up to 24 months after last meaningful contact (or until you unsubscribe).
- Contract, support and device records: for the contract term and then up to 6–7 years after the end of the financial year (limitation and HMRC rules).
- Security and system logs: typically 12–24 months, unless needed for investigations.
- Marketing preferences: until you opt out or we delete inactive records after a defined period.
- Recruitment data: usually 6–12 months if unsuccessful; if hired, kept in your personnel file.
Where retention is different due to legal or vendor requirements, we will apply the longer period necessary.
8) Security
We implement appropriate technical and organisational measures to protect personal data, including access controls, encryption in transit and at rest where appropriate, network and endpoint protections, vulnerability management, backup and recovery, staff training and vendor due-diligence. No system is perfectly secure; we maintain incident response processes and will notify you and/or the ICO, where legally required.
9) Acting as a processor for clients
For managed services (e.g., RMM/EDR/XDR, firewalling, backups, M365 administration, helpdesk), we often act as a processor and handle customer personal data under your instructions. Our responsibilities, sub-processors and security measures are set out in your Master Services Agreement and DPA.
10) Your rights
Under the UK GDPR, you have rights to access, rectify, erase, restrict, data portability, object (including to direct marketing), and withdraw consent where applicable. To exercise your rights, contact us using the details above. We will respond within one month (or explain if more time is needed). We may need to verify your identity.
11) Complaints
Please contact us first. You also have the right to complain to the Information Commissioner’s Office (ICO): Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Helpline: 0303 123 1113 • ico.org.uk
12) Contact us
Kent Electronic Services (KES) Limited
Registered office: 4 Bloors Lane, Rainham, Gillingham, Kent, United Kingdom, ME8 7EG
Telephone: 01622 721000 • Email: info@kesuk.net (please write “Privacy” in the subject line)
Privacy Lead/DPO (if appointed): Mark Roach, 01622 721000
13) Changes to this notice
We may update this policy from time to time. The latest version will always appear on our website with the effective date above. Significant changes will be communicated where appropriate.
Short version (plain-English summary)
- We use your work contact details, service and support information to deliver our contracts, run our business, keep systems secure and—where relevant—send you useful, relevant B2B updates.
- We only share data with trusted suppliers needed to provide our services and with authorities where required by law.
- Some suppliers are outside the UK; we use legal safeguards for international transfers.
- You can opt out of marketing at any time and manage cookies via our banner.
- You have rights over your data and can contact us—or the ICO—if you’re unhappy.