Last updated: 28 July 2026
This notice explains what personal information Maly IT Solutions Limited collects, why we collect it, how we look after it, and what rights you have over it. We have written it in plain English deliberately. If anything here is unclear, email us and we will explain it properly.
Who we are
Maly IT Solutions Limited (“Maly”, “we”, “us”) is the data controller for the personal information described in this notice.
- Registered company name: Maly IT Solutions Limited
- Registered in: England and Wales
- Company registration number: 07102935
- Registered office: 50 Princes Street, Ipswich, England, IP1 1RJ
- VAT registration number: GB 982 6714 82
- Email: hello@maly.co.uk
- Telephone: 01473 934672
We are not required to appoint a statutory Data Protection Officer. Data protection questions are handled directly by the company’s directors at the address above.
Information we collect
When you contact us or request a call
If you fill in a form on this website, email us, or call us, we collect your name, your organisation, your email address, your telephone number, and whatever you choose to tell us about your business situation.
When you comment on an article
Where comments are enabled on an article, we collect the information shown in the comment form, along with your IP address and browser user agent string, which help us detect spam. An anonymised string created from your email address may be sent to the Gravatar service to check whether you use it; the Gravatar privacy policy is available at automattic.com/privacy.
When you simply browse the site
Our hosting provider records standard server log information, including IP address, browser type, pages viewed and timestamps. If you consent to analytics cookies, we also receive aggregated statistics about how the site is used. Full detail is in our Cookie Notice.
When we work with you as a client
During a project we hold business contact details, correspondence, meeting notes, project documentation and billing records. Where a project involves us accessing systems that contain your customers’ or employees’ personal data, we act as a processor on your instructions rather than as a controller, and we operate under a written contract that sets out exactly what we may and may not do with that data.
We do not knowingly collect information from children, and this website is not directed at them. We do not collect special category data (such as health or biometric data) through this website.
Why we use it, and our lawful basis
| What we do | Why | Lawful basis (UK GDPR Article 6) |
|---|---|---|
| Reply to an enquiry and arrange a call | You asked us to | Steps taken at your request prior to entering a contract |
| Keep a record of enquiries that did not proceed | To pick up the thread if you come back to us later | Legitimate interests — running the business efficiently |
| Deliver a project and support it | To do the work you engaged us for | Performance of a contract |
| Issue invoices and keep accounts | We are legally required to keep accurate records | Legal obligation |
| Keep the site secure and spam-free | To protect the site and its visitors | Legitimate interests — security of our systems |
| Measure how the website is used | To improve the site | Consent (given through the cookie banner) |
| Send occasional updates to existing clients | To keep you informed about relevant work | Legitimate interests, with an unsubscribe link in every message |
Where we rely on consent, you may withdraw it at any time and that will not affect anything we did lawfully beforehand. Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and you may object at any time using the contact details above.
Who we share it with
We do not sell your personal information, and we do not share it for anyone else’s marketing. We do share it with a small number of suppliers who help us run the business, each under a contract that requires them to protect it:
- our website hosting provider
- our email and productivity provider
- our analytics provider, where you have consented to analytics cookies
- our accountants and our accounting software provider
- professional advisers, and regulators or law enforcement where we are legally required to disclose
Some of these suppliers process data outside the UK. Where that happens, we rely on UK adequacy regulations or on the International Data Transfer Agreement or Addendum, so that your information keeps an equivalent level of protection. You may ask us for a copy of the safeguards we have in place, and we will provide it.
Do you have to give us your information?
No. Filling in a form or giving us your details is entirely voluntary. If you choose not to, the only consequence is that we cannot contact you or answer your question.
Where we are working together under a contract, some information is necessary to do the work — we cannot build a system without access to the data it needs to hold. Anything of that kind is set out in the contract itself, so you always know what is required and why before you agree to it.
Automated decision-making
We do not use automated decision-making or profiling that produces legal effects for you, or that similarly significantly affects you. Decisions about whether and how we work with someone are made by people.
How long we keep it
- Enquiries that do not become projects: up to 24 months, then deleted.
- Client records and correspondence: for the life of the relationship and 6 years afterwards, which matches the limitation period for contract claims.
- Accounting and tax records: 6 years from the end of the relevant financial year, as required by HMRC and the Companies Act 2006.
- Website comments: kept while the article is published, unless you ask us to remove them.
- Server logs: typically 30 to 90 days, depending on our host’s settings.
How we protect it
Maly holds ISO 27001 certification for information security management and ISO 9001 for quality management, and we have handled highly regulated data, including for global pharmaceutical clients, for many years. In practice that means access controls and least-privilege access to client systems, encryption in transit, multi-factor authentication on our business accounts, documented incident response, and supplier due diligence before we let a third party near anything sensitive.
If a personal data breach occurs that is likely to result in a risk to your rights, we will report it to the Information Commissioner’s Office within 72 hours of becoming aware of it, and we will tell you directly where the risk to you is high.
Your rights
Under the UK GDPR and the Data Protection Act 2018 you have the right to:
- ask what personal data we hold about you, and get a copy of it
- have inaccurate data corrected
- ask us to delete data where we no longer have a good reason to keep it
- ask us to restrict how we use it while a concern is resolved
- receive data you gave us in a portable, machine-readable format
- object to processing we carry out on the basis of legitimate interests
- object to direct marketing at any time, with no need to give a reason
- withdraw consent where consent is the basis we rely on
Email hello@maly.co.uk and we will respond within one month. Exercising these rights is free. We will not make you justify the request, though we may need to confirm your identity first.
If you are unhappy with how we have handled your information, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint or on 0303 123 1113.
Other sites
Our articles sometimes link to or embed content from other websites, such as YouTube videos. Those sites collect data and set their own cookies once the content loads, and their privacy policies apply to that activity, not ours.
Changes to this notice
We review this notice at least annually and whenever we change how we handle personal information. The date at the top always shows the current version.