Privacy Notice

Last updated: 23 August 2026

About this notice

Oxford Macintosh Solutions Ltd, trading as OMSUK (“OMSUK”, “we”, “us” or “our”), is committed to protecting personal information and handling it transparently, securely and in accordance with applicable data-protection law.

Oxford Macintosh Solutions Ltd is registered in England and Wales under company number 03187204. Our business address is 50 Acre End Street, Eynsham, Oxfordshire, OX29 4PD.

This notice explains how we handle personal information relating to clients, prospective clients, suppliers, website visitors and other business contacts. Information relating to current and former employees, workers and applicants is covered by separate privacy information.

If you have a question about this notice or how we use personal information, please contact:

Email: hello@omsuk.com
Telephone: 01865 882504
Post: OMSUK Ltd, 50 Acre End Street, Eynsham, Oxfordshire, OX29 4PD

Please mark written correspondence for the attention of the Data Protection Lead.

Our role when handling personal information

OMSUK may act as either a controller or a processor of personal information.

We act as a controller when we determine why and how personal information is used for our own business purposes. This includes managing client and supplier relationships, administering contracts, processing payments, responding to enquiries, operating our website and meeting our legal obligations.

When providing managed IT, technical support, consultancy, cloud-management or cybersecurity services, we may access or process personal information on behalf of a client. In those circumstances, the client will normally be the controller and OMSUK will act as its processor. We process that information in accordance with the client’s documented instructions, our contract with the client and applicable data-protection law.

Questions about information held within a client’s systems should normally be directed to that client in the first instance.

Personal information we collect

Depending on your relationship with OMSUK, we may collect and use:

  • Your name, job title, organisation and business contact details.

  • Information supplied through enquiries, proposals, contracts and service requests.

  • Support tickets, emails, call notes and other business communications.

  • Usernames, account identifiers, device information and technical diagnostic information.

  • Information about IT systems, software, licences and services for which we provide support.

  • Remote-support session details and audit records.

  • Information needed to verify identity or authorise sensitive requests.

  • Billing, purchasing, payment and transaction information.

  • Supplier, contractor and professional-adviser information.

  • Website enquiry information, IP addresses and technical logs.

  • Marketing preferences and records of previous communications.

  • Information required to investigate security incidents, complaints or legal claims.

Our support work may occasionally give us incidental access to other information held on a client’s systems. We only access such information where necessary to provide the requested service, investigate an issue, protect systems or comply with a legal obligation.

We do not intentionally collect special-category information through our website. Where our work gives us access to special-category or criminal-offence information held by a client, we handle it under the client’s instructions and apply appropriate safeguards.

Where personal information comes from

We may receive personal information:

  • Directly from you.

  • From your employer or another organisation for which you work.

  • From a client that has authorised us to support you or administer its systems.

  • Through support, security, monitoring and remote-management systems.

  • From suppliers, professional advisers and business partners.

  • From publicly available business sources.

  • Through our website, email, telephone and other approved communication channels.

If a client provides us with personal information about its personnel, the client is responsible for ensuring it has an appropriate lawful basis for doing so and for providing any privacy information required.

How and why we use personal information

We may use personal information to:

  • Respond to enquiries and prepare proposals.

  • Enter into and manage contracts.

  • Deliver managed IT, support, consultancy, cloud and cybersecurity services.

  • Identify users and verify instructions.

  • Create and manage support tickets.

  • Administer user accounts, devices, software and cloud services.

  • Monitor the security, availability and performance of supported systems.

  • Investigate faults, security events and suspected misuse.

  • Communicate service information, planned work and security advice.

  • Process orders, invoices and payments.

  • Manage suppliers and professional relationships.

  • Maintain business, accounting, contractual and audit records.

  • Establish, exercise or defend legal claims.

  • Meet legal, regulatory, insurance and contractual obligations.

  • Improve our services and internal processes.

  • Protect OMSUK, our clients, our personnel and other individuals from fraud, cyberattack and other harm.

  • Send relevant business-to-business marketing where permitted by law.

  • Operate, secure and improve our website.

Our lawful bases

Depending on the circumstances, we rely on one or more of the following lawful bases:

Contract: Where processing is necessary to enter into or perform a contract with you.

Legal obligation: Where processing is necessary to comply with an obligation imposed by UK law, including applicable tax, accounting, employment and data-protection requirements.

Legitimate interests: Where processing is necessary for our legitimate business interests, or those of a client or another party, and those interests are not overridden by your rights and freedoms. These interests may include providing and improving our services, managing business relationships, maintaining accurate records, recovering debts, protecting systems and information, preventing fraud and communicating with business contacts.

Where we rely on legitimate interests, we consider the purpose, necessity and likely effect of the processing before proceeding.

Consent: Where we have asked for and received your freely given consent. You may withdraw your consent at any time, although this will not affect processing that took place before it was withdrawn.

Vital interests: In exceptional circumstances, where processing is necessary to protect someone’s life.

Where special-category information is processed, an additional condition under data-protection law will also be identified.

Marketing communications

We may contact relevant business contacts with information about OMSUK services where this is permitted by law and where we believe the information may be of genuine professional interest.

You can ask us to stop using your information for direct marketing at any time by contacting hello@omsuk.com or using the unsubscribe option included in the communication.

You have an absolute right to object to the use of your personal information for direct marketing. If you object, we will stop using your information for that purpose.

Who we share personal information with

We only share personal information where this is necessary and lawful.

Depending on the services involved, information may be shared with:

  • IT hosting, cloud and communications providers.

  • Ticketing, documentation and customer-management platforms.

  • Remote monitoring, support, backup and cybersecurity providers.

  • Software vendors and distributors.

  • Payment, accounting and financial-service providers.

  • Couriers and delivery providers.

  • Insurers, auditors, solicitors and other professional advisers.

  • Regulators, law-enforcement bodies, courts or public authorities where disclosure is required or permitted by law.

  • A prospective buyer, seller or adviser if OMSUK undergoes a reorganisation, merger or sale.

  • Other parties where you or the relevant client have authorised us to disclose the information.

Our service providers are only permitted to use personal information for the agreed purpose and must protect it appropriately.

When we act as a processor for a client, details of relevant subprocessors and processing arrangements are governed by our contract with that client.

International transfers

Some of the service providers used by OMSUK may process or store personal information outside the United Kingdom.

Where a restricted international transfer takes place, we use an approved legal transfer mechanism where required. This may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses or another safeguard permitted by UK data-protection law.

Further information about the safeguards applying to a particular transfer can be requested using the contact details in this notice.

How we protect personal information

We use appropriate technical and organisational measures to protect personal information against unauthorised access, loss, alteration, disclosure or destruction.

These measures include, where appropriate:

  • Role-based access controls and individual user accounts.

  • Multi-factor authentication.

  • Encryption of supported devices and communications.

  • Endpoint protection and security monitoring.

  • Secure password and privileged-access management.

  • Device-management and compliance controls.

  • Security awareness training.

  • Backup and recovery arrangements.

  • Supplier security assessment.

  • Logging, auditing and incident-response procedures.

  • Policies governing acceptable use, information handling and data transfer.

Access is limited to personnel and approved providers who need the information for their work.

No method of electronic storage or communication is completely secure. However, we regularly review our safeguards and work to ensure that the protection applied remains appropriate to the nature and risk of the information.

How long we retain personal information

We retain personal information only for as long as it is reasonably required for the purpose for which it was collected, including legal, regulatory, contractual, insurance, security and dispute-resolution requirements.

Typical retention periods include:

  • Client contracts, proposals and associated business records: normally six years after the end of the relevant contract or relationship.

  • Accounting and transaction records: normally six years after the end of the relevant financial period.

  • Support, project and service records: for the duration of the client relationship and an appropriate period afterwards, taking account of contractual, operational, insurance and legal requirements.

  • Prospective-client information: normally no longer than two years after the last meaningful contact, unless a longer period is justified.

  • Supplier and professional-contact information: for the duration of the relationship and an appropriate period afterwards.

  • Security and system logs: according to the purpose of the log, the service configuration and the relevant security requirements.

  • Information held in backups: until it is overwritten or deleted in accordance with the applicable backup-retention schedule.

  • Information processed on behalf of a client: in accordance with the client’s instructions and our contract with that client.

Information may be retained for longer where required by law, where a dispute or investigation is ongoing, or where it is necessary to establish, exercise or defend a legal claim.

At the end of the applicable retention period, information will be securely deleted, anonymised or placed beyond normal operational use.

Your data-protection rights

Depending on the circumstances and the lawful basis used, you may have the right to:

  • Be informed about how your personal information is used.

  • Ask for access to your personal information.

  • Ask us to correct inaccurate or incomplete information.

  • Ask us to erase your personal information.

  • Ask us to restrict how your information is used.

  • Object to certain uses of your information.

  • Receive certain information in a portable format.

  • Withdraw consent where processing is based on consent.

  • Raise a complaint about how your information has been handled.

  • Ask for human intervention where a significant decision has been made solely by automated means.

These rights are not absolute and exemptions may apply. For example, we may need to retain information to comply with the law, fulfil a contract, protect another person’s rights or establish, exercise or defend a legal claim.

We may ask for information needed to confirm your identity before responding to a request.

We will normally respond to a valid request within one month. We will tell you if the request is complex, if we require further information or if the law permits us to extend the response period.

Automated decision-making

OMSUK does not currently make decisions about individuals based solely on automated processing where those decisions produce legal or similarly significant effects.

We may use automated security, monitoring and filtering systems to identify suspicious activity, technical faults, malware or unwanted communications. Appropriate human review is available where these systems affect the delivery of our services or require further action.

Data-protection complaints

If you are concerned about how we have handled your personal information, please contact us using the details at the beginning of this notice.

We will:

  • Provide a clear and accessible way for you to make a complaint.

  • Acknowledge your complaint within 30 days.

  • Investigate it without undue delay.

  • Keep you appropriately informed about our progress.

  • Tell you the outcome without undue delay.

If you remain dissatisfied, you have the right to complain to the Information Commissioner’s Office:

Website: ico.org.uk/make-a-complaint
Telephone: 0303 123 1113
Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

We would appreciate the opportunity to investigate and resolve your concern before you contact the ICO, but you are not required to obtain our permission before doing so.

Personal-data breaches

OMSUK maintains procedures for identifying, investigating and responding to suspected personal-data breaches.

Where we act as a controller, we will assess whether a breach must be reported to the Information Commissioner’s Office and whether affected individuals must be informed.

Where we act as a processor, we will notify the relevant client without undue delay after becoming aware of a personal-data breach affecting information processed on its behalf.

Other websites

Our website may contain links to websites operated by other organisations. OMSUK is not responsible for the privacy practices or content of those websites. You should review the privacy information provided by the relevant organisation before supplying personal information.

Changes to this notice

We may update this notice to reflect changes in our services, systems, suppliers or legal obligations. The current version and its last-updated date will be published on this page.

If a change would materially affect how we use existing personal information, we will take reasonable steps to bring it to the attention of affected individuals.