We respect your privacy and are determined to protect your personal data. This privacy notice explains how Tivarri Limited collects and uses personal data relating to website visitors, prospective customers and business contacts, customers and authorised users, suppliers, event attendees and other external contacts. It also explains your privacy rights and how data protection law protects you. 

What is the purpose of this privacy notice? 

This notice covers personal data we process through our website and in connection with enquiries, sales and marketing, customer registration, support and Helpdesk activity, service delivery, account management, events and our wider business relationships. Our website is not intended for children, and we do not knowingly collect personal data from children through it. 

You should read this notice together with any other privacy information we provide when collecting or using personal data for a specific purpose. 

Data controller 

Tivarri Limited is the controller responsible for your personal data and is referred to as “Tivarri”, “we”, “us” or “our” in this notice. 

Our contact details are Tivarri Limited, 28 Victoria Buildings, Bath, BA2 3EH, United Kingdom. Telephone: 01225 428879. Email: [email protected]. For data protection enquiries, rights requests or complaints, please mark your correspondence or email “Data Protection”. 

Third-party links outside of our control 

Our website may include links to third-party websites, plug-ins and applications. Those third parties may collect or use personal data about you. We do not control their websites or privacy practices and encourage you to read their privacy notices. 

The personal data we collect about you 

Personal data means information relating to an identified or identifiable individual. Depending on how you interact with us, we may collect: 

  • Identity Data, including your name, username or similar identifier.
  • Business Contact Data, including employer, job title, business email address, business telephone number, billing or delivery address and professional contact details.
  • Customer and Account Data, including organisation, services requested or purchased, account and portal information.
  • Financial and Transaction Data, including billing, invoicing, payment and transaction records where applicable.
  • Support and Communications Data, including Helpdesk tickets, service requests, enquiries, emails, calls and correspondence.
  • Technical and Security Data, including IP address, browser or device information, login information, authentication events, security alerts, logs and access records.
  • Usage Data, including information about how you use our website, portals and services.
  • Marketing and Profile Data, including marketing preferences, campaign engagement, event or prospect information and information used to assess whether a service may be relevant to your organisation.

We may create Aggregated Data, such as statistical information, from personal data. Aggregated Data is not personal data where it does not identify an individual. If aggregated information is combined with other information so that an individual can be identified, we treat it as personal data. 

We do not intentionally seek special category personal data through our website or for ordinary sales and marketing activity, nor do we routinely seek criminal offence data. Information provided through correspondence, or a support request may occasionally contain sensitive information. Where we need to process it, we will do so only where an appropriate lawful basis and, where required, an additional legal condition applies. 

If you fail to provide personal data 

Where we need personal data by law or to enter into or perform a contract and you do not provide it when requested, we may not be able to provide the relevant product or service. We will tell you if this applies. 

How we collect your personal data 

You may provide personal data directly to us by filling in forms or corresponding with us by post, telephone, Helpdesk portal, email or otherwise. This includes when you request information or a trial, purchase products or services, create an account, submit a support request, subscribe to communications, attend an event or make a sales enquiry. 

We may collect Technical, Security and Usage Data automatically when you use our website or online services through cookies, logs and similar technologies. 

We may also obtain business contact information from publicly available sources and third parties, including corporate websites, Companies House, professional networking platforms, event and conference information, business directories, professional contacts, referrals and, where appropriate, business data providers. This may include your name, job title, employer, business email address, business telephone number, professional role, business sector and information relevant to whether our services may be applicable to your organisation. 

Where we obtain personal data from another source, we will provide or make you aware of the relevant privacy information within a reasonable period and no later than one month after obtaining it, or at our first communication with you if sooner, unless a legal exemption applies. 

How we use your personal data 

We will only use personal data where the law allows us to. We most commonly rely on: 

  • Performance of a contract, where processing is necessary to enter into or perform a contract with you.
  • Legitimate interests, where processing is necessary for our legitimate business interests or those of a third party and those interests are not overridden by your rights. These interests include delivering and improving services, protecting systems and customers, managing our business and relationships, and informing relevant organisations and professional contacts about services that may be relevant to them.
  • Legal obligation, where processing is necessary to comply with a legal or regulatory obligation.
  • Consent, where you have given valid consent, including where consent is required for a marketing channel or non-essential cookies. 

Where we rely on legitimate interests, we consider the purpose, necessity and impact of the processing and your reasonable expectations. 

Purposes for which we will use your personal data 

Purpose / activity 

Type of data 

Lawful basis 

Responding to enquiries, trials and proposals 

Identity; Business Contact; Communications; Marketing/Profile 

Steps before a contract; legitimate interests in responding to enquiries and developing our business 

Registering and managing customers, accounts and services 

Identity; Business Contact; Customer/Account 

Contract; legal obligation where applicable 

Providing products, services, Helpdesk support and service management 

Identity; Business Contact; Customer/Account; Support/Communications; Technical/Security 

Contract; legitimate interests in managing and securing our services 

Billing, invoicing, accounting and payment administration 

Identity; Business Contact; Financial/Transaction 

Contract; legal obligation; legitimate interests in financial administration 

Protecting systems and services, including authentication, monitoring, fraud prevention and incident response 

Identity; Customer/Account; Technical/Security; Support/Communications 

Legitimate interests in cybersecurity and preventing misuse; legal obligation where applicable 

Sending service, administrative or contractual communications 

Identity; Business Contact; Customer/Account; Communications 

Contract; legal obligation; legitimate interests in managing our relationship 

Operating and improving our website and understanding its use 

Technical/Security; Usage 

Legitimate interests for security and essential operation; consent or another applicable PECR permission where required 

B2B prospecting and direct marketing about Tivarri services 

Identity; Business Contact; Marketing/Profile; Communications; source information 

Legitimate interests where PECR does not require consent; consent where required or obtained 

Complying with law, audits, complaints, regulatory requests and legal claims 

Relevant categories 

Legal obligation; legitimate interests in establishing, exercising or defending legal rights 

We may process personal data on more than one lawful basis depending on the purpose and circumstances. 

Marketing 

We may use relevant Identity, Business Contact, Customer, Usage and Marketing/Profile Data to decide which Tivarri products, services or information may be relevant to you or your organisation. This may involve limited marketing segmentation. We do not use personal data to make solely automated decisions that produce legal or similarly significant effects. 

For business-to-business marketing, UK GDPR and the Privacy and Electronic Communications Regulations 2003, as amended, apply in different ways. Where we use an identifiable person’s business contact details, UK GDPR applies. We may rely on legitimate interests to market to relevant professional contacts where PECR does not require consent and our interests are not overridden by the individual’s rights and expectations. 

For electronic marketing to corporate subscribers, such as limited companies and limited liability partnerships, prior consent is not generally required under the electronic mail rules in PECR. We will comply with UK GDPR where personal data is used and provide a clear way to opt out. Sole traders and certain partnerships are treated as individual subscribers and generally require consent for unsolicited electronic marketing unless a lawful soft opt-in applies. We will also comply with applicable telephone marketing rules and previous objections. 

Publicly available contact details do not amount to consent. Where we use publicly sourced or third-party business contact information, we will be transparent about the source and use and respect any objection or opt-out. 

Third-party marketing 

We will obtain express consent before sharing your personal data with an unrelated third party for that third party’s own direct marketing. 

Your right to object to direct marketing 

You have an absolute right to object at any time to the use of your personal data for direct marketing, including related profiling. If you object, we will stop using it for that purpose. You can use the unsubscribe or opt-out method in a marketing message or contact us directly. We may keep the minimum information needed on a suppression list so that we can respect your preference. 

Cookies and similar technologies 

We use cookies and similar technologies to operate, secure and improve our website and, where enabled, understand how it is used. Some technologies may be used without consent where permitted by PECR. Where consent is required, we will ask for a clear positive action before setting or using them. Continuing to browse our website does not, by itself, constitute consent. 

Online identifiers such as IP addresses and cookie identifiers may be personal data. Our Cookie Policy explains the technologies in use, their purposes, providers and durations, and how you can manage or withdraw your preferences. 

Change of purpose 

We will use personal data for the purpose for which it was collected unless another use is compatible with that purpose. If we need to use it for an unrelated purpose, we will tell you and explain the lawful basis unless the law permits or requires otherwise. 

Who we share your personal data with 

  • service providers acting on our instructions, including providers of cloud and IT services, hosting, CRM, accounting, Helpdesk and support systems, cybersecurity, website services, analytics and subcontracted services;
  • professional advisers and other independent controllers, including lawyers, auditors, insurers, banks and financial institutions where they determine their own purposes and legal responsibilities;
  • HM Revenue & Customs, regulators, courts, law-enforcement bodies and other authorities where disclosure is required or permitted by law; and
  • third parties involved in a proposed or completed sale, transfer, merger, acquisition or restructuring of our business.

Where a third party acts as our processor, we require it by contract to protect personal data, act only on documented instructions and use the data only for authorised purposes. Where a recipient is an independent controller, it is responsible for its own use of personal data under applicable law. 

International transfers 

Some of our technology and service providers operate internationally and may process personal data outside the UK, including in the EEA and the United States. 

Where a transfer from the UK to a separate organisation outside the UK is a restricted transfer, we ensure an appropriate mechanism applies. Depending on the recipient, this may include UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework where applicable, or safeguards such as the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. Where required, we carry out the relevant transfer risk assessment or data protection test. 

You can contact us for information about the safeguards applying to a particular transfer and how to obtain a copy where available. 

Data security 

We have appropriate technical and organisational measures designed to protect personal data against accidental loss, unauthorised access, alteration or disclosure. These include access controls and authentication, encryption where appropriate, security logging and monitoring, backup and recovery arrangements, supplier controls and incident response procedures. Access is limited to people with a business need to know and who are subject to confidentiality obligations. 

Tivarri is certified to ISO 27001:2022 and Cyber Essentials. We maintain procedures for responding to suspected personal data breaches and will notify affected individuals and the Information Commissioner’s Office where the law requires us to do so. 

Data retention 

We keep personal data only for as long as necessary for the purpose for which it was collected, taking account of legal, accounting, contractual, security and reporting requirements and the need to establish or defend legal claims. 

Customer, contractual, billing and accounting records may be kept for the relationship and an appropriate period afterwards, commonly up to six years where necessary for tax, accounting or legal claims. Enquiry, prospect and marketing information is retained only while it remains relevant for reasonable follow-up or marketing, subject to your right to object. If you opt out, we may retain minimal suppression information to honour your request. 

Helpdesk and service records are retained as required for service history, audit, contractual and legal purposes. Security and technical logs are kept for the period necessary for security monitoring, investigation and audit and may be retained longer where an incident or legal requirement applies. Analytics and cookie information is retained in line with our Cookie Policy and provider settings. Backup copies are overwritten in accordance with our backup and recovery schedules. 

In some circumstances you may ask us to delete personal data. We may also anonymise data so that it can no longer identify you, in which case we may use it without further notice. 

Automated decision-making and profiling 

We may use limited profiling or segmentation to understand service relevance or marketing engagement. We do not currently make solely automated decisions about individuals that have legal or similarly significant effects. 

Your legal rights 

Subject to applicable exemptions, you may have the right to request access to your personal data; request correction; request erasure; request restriction of processing; object to processing based on legitimate interests; object at any time to direct marketing; withdraw consent where consent is the lawful basis; and request data portability where applicable. 

To exercise a right, contact us using the details above. 

No fee required – with some exceptions 

You will not usually have to pay a fee to exercise your rights. We may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive, where the law permits. 

What we may need from you 

We may request information reasonably necessary to confirm your identity or clarify your request. This helps prevent personal data being disclosed to someone who is not entitled to receive it. 

Time limit to respond 

We respond to rights requests within the period required by data protection law. In most cases this is one month, although the period may be extended where the law permits. We will tell you if an extension applies.  

Data protection complaints 

You can make a data protection complaint to us by email at [email protected] with the subject “Data Protection Complaint”, by telephone on 01225 428879, or in writing to Tivarri Limited, 28 Victoria Buildings, Bath, BA2 3EH, United Kingdom. 

We will acknowledge a data protection complaint within 30 days, take appropriate steps to investigate it without undue delay, keep you informed as appropriate and communicate the outcome without undue delay. 

You also have the right to complain to the Information Commissioner’s Office. You can contact the ICO through ico.org.uk, by telephone on 0303 123 1113, or by post at Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom. We would appreciate the opportunity to address your concern directly, but you do not have to contact us before approaching the ICO. 

Changes to this notice and your duty to inform us of changes 

We keep this privacy notice under review and will publish material updates on our website. Please keep us informed if personal data relevant to your relationship with us changes.