2. Scope
This policy applies whenever Ostratto processes Personal Data on behalf of a customer while delivering services including:
- Consultancy
- Professional Services
- Implementation
- Technical Support
- Managed Services
- Software Development
- Software Configuration
- Data Migration
- System Integration
- Managed Devices
- Security Services
- Training
This policy applies regardless of whether Personal Data is processed electronically or physically.
3. Our Commitment
Where Ostratto processes Personal Data on behalf of customers, we are committed to:
- Processing Personal Data lawfully and only for legitimate business purposes
- Following documented customer instructions where applicable
- Protecting Personal Data from accidental or unlawful destruction, loss, alteration or unauthorised disclosure
- Limiting access to authorised personnel only
- Processing only the minimum Personal Data necessary to deliver our services
- Maintaining appropriate technical and organisational security measures
- Complying with applicable data protection legislation
4. Roles and Responsibilities
When providing services to customers, Ostratto will generally act as a Data Processor, with the customer acting as the Data Controller.
The customer remains responsible for determining the purposes and means of processing Personal Data.
Ostratto processes Personal Data only to deliver the agreed services or where otherwise required by law.
Certain activities, including billing, customer relationship management, legal compliance and financial accounting, may require Ostratto to process Personal Data as an independent Data Controller.
5. Categories of Personal Data
Depending upon the services provided, Ostratto may process Personal Data including:
- Names
- Email addresses
- Telephone numbers
- Postal addresses
- Usernames
- Customer records
- Employee information
- Supplier information
- Financial information
- Support records
- CRM information
- Other Personal Data contained within customer systems
Ostratto does not intentionally process Special Category Personal Data unless necessary to provide the agreed services.
6. How We Process Personal Data
Personal Data may be processed for purposes including:
- Delivering contracted services
- Providing technical support
- Configuring software platforms
- Maintaining customer systems
- Migrating data
- Troubleshooting technical issues
- Providing consultancy
- Delivering training
- Fulfilling contractual obligations
- Complying with legal obligations
We process only the Personal Data necessary to perform the agreed services.
7. Information Security
Ostratto implements appropriate technical and organisational measures designed to protect Personal Data from accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Our security controls include, where appropriate:
- Multi-factor authentication
- Least privilege access controls
- Secure password management
- Endpoint protection
- Device encryption where supported
- Operating system and software updates
- Secure cloud infrastructure
- Security awareness training
- Physical security controls
- Incident response procedures
Further information about our security controls can be found within our:
8. Access to Personal Data
Access to Personal Data is limited to authorised personnel who require access to perform their duties.
Personnel authorised to process Personal Data:
- Are subject to confidentiality obligations
- Receive appropriate security guidance
- Are expected to follow our Information Security Policy
- Access Personal Data only where necessary to deliver the agreed services
Access rights are reviewed periodically and removed when no longer required.
9. Third-Party Service Providers
Ostratto may engage carefully selected third-party service providers where necessary to deliver our services.
These providers may include services relating to:
- Cloud infrastructure
- Business productivity platforms
- Customer relationship management
- Payment processing
- Communications
- Security services
- Backup and disaster recovery
Where Personal Data is processed by third parties, we seek to ensure appropriate contractual and security safeguards are maintained.
10. International Transfers
Where Personal Data is transferred outside the United Kingdom, Ostratto will ensure appropriate safeguards are implemented in accordance with applicable data protection legislation.
These safeguards may include adequacy decisions, International Data Transfer Agreements, the UK Addendum to the EU Standard Contractual Clauses or other lawful transfer mechanisms.
11. Personal Data Breaches
Ostratto maintains procedures for identifying, investigating and responding to information security incidents.
Where we become aware of a Personal Data Breach affecting customer information, we will notify the affected customer without undue delay where required by law or contractual obligation.
Where reasonably available, we will provide:
- Details of the incident
- The likely impact
- Steps taken to contain the incident
- Actions being taken to reduce future risk
12. Assistance
Where reasonably required, Ostratto will assist customers with their obligations under applicable data protection legislation.
This may include assistance relating to:
- Subject Access Requests
- Requests for rectification
- Requests for erasure
- Requests for restriction
- Requests for portability
- Objections to processing
- Data Protection Impact Assessments
- Regulatory enquiries
13. Data Retention and Disposal
Personal Data processed on behalf of customers is retained only for as long as necessary to provide the agreed services or comply with applicable legal obligations.
Upon completion of the services, Personal Data will be securely deleted or returned where appropriate unless retention is required by law.
14. Compliance
Ostratto is committed to complying with applicable data protection legislation including:
- UK General Data Protection Regulation (UK GDPR)
- Data Protection Act 2018
- Privacy and Electronic Communications Regulations where applicable
This policy should be read alongside our:
15. Review
This policy is reviewed periodically to ensure it remains accurate, effective and aligned with changes in legislation, technology and our business operations.
Where significant changes are made, the latest version will be published on our website.