Privacy Policy

Last updated: 28 July 2026

This notice explains what personal information Maly IT Solutions Limited collects, why we collect it, how we look after it, and what rights you have over it. We have written it in plain English deliberately. If anything here is unclear, email us and we will explain it properly.

Who we are

Maly IT Solutions Limited (“Maly”, “we”, “us”) is the data controller for the personal information described in this notice.

  • Registered company name: Maly IT Solutions Limited
  • Registered in: England and Wales
  • Company registration number: 07102935
  • Registered office: 50 Princes Street, Ipswich, England, IP1 1RJ
  • VAT registration number: GB 982 6714 82
  • Email: hello@maly.co.uk
  • Telephone: 01473 934672

We are not required to appoint a statutory Data Protection Officer. Data protection questions are handled directly by the company’s directors at the address above.

Information we collect

When you contact us or request a call

If you fill in a form on this website, email us, or call us, we collect your name, your organisation, your email address, your telephone number, and whatever you choose to tell us about your business situation.

When you comment on an article

Where comments are enabled on an article, we collect the information shown in the comment form, along with your IP address and browser user agent string, which help us detect spam. An anonymised string created from your email address may be sent to the Gravatar service to check whether you use it; the Gravatar privacy policy is available at automattic.com/privacy.

When you simply browse the site

Our hosting provider records standard server log information, including IP address, browser type, pages viewed and timestamps. If you consent to analytics cookies, we also receive aggregated statistics about how the site is used. Full detail is in our Cookie Notice.

When we work with you as a client

During a project we hold business contact details, correspondence, meeting notes, project documentation and billing records. Where a project involves us accessing systems that contain your customers’ or employees’ personal data, we act as a processor on your instructions rather than as a controller, and we operate under a written contract that sets out exactly what we may and may not do with that data.

We do not knowingly collect information from children, and this website is not directed at them. We do not collect special category data (such as health or biometric data) through this website.

Why we use it, and our lawful basis

What we doWhyLawful basis (UK GDPR Article 6)
Reply to an enquiry and arrange a callYou asked us toSteps taken at your request prior to entering a contract
Keep a record of enquiries that did not proceedTo pick up the thread if you come back to us laterLegitimate interests — running the business efficiently
Deliver a project and support itTo do the work you engaged us forPerformance of a contract
Issue invoices and keep accountsWe are legally required to keep accurate recordsLegal obligation
Keep the site secure and spam-freeTo protect the site and its visitorsLegitimate interests — security of our systems
Measure how the website is usedTo improve the siteConsent (given through the cookie banner)
Send occasional updates to existing clientsTo keep you informed about relevant workLegitimate interests, with an unsubscribe link in every message

Where we rely on consent, you may withdraw it at any time and that will not affect anything we did lawfully beforehand. Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and you may object at any time using the contact details above.

Who we share it with

We do not sell your personal information, and we do not share it for anyone else’s marketing. We do share it with a small number of suppliers who help us run the business, each under a contract that requires them to protect it:

  • our website hosting provider
  • our email and productivity provider
  • our analytics provider, where you have consented to analytics cookies
  • our accountants and our accounting software provider
  • professional advisers, and regulators or law enforcement where we are legally required to disclose

Some of these suppliers process data outside the UK. Where that happens, we rely on UK adequacy regulations or on the International Data Transfer Agreement or Addendum, so that your information keeps an equivalent level of protection. You may ask us for a copy of the safeguards we have in place, and we will provide it.

Do you have to give us your information?

No. Filling in a form or giving us your details is entirely voluntary. If you choose not to, the only consequence is that we cannot contact you or answer your question.

Where we are working together under a contract, some information is necessary to do the work — we cannot build a system without access to the data it needs to hold. Anything of that kind is set out in the contract itself, so you always know what is required and why before you agree to it.

Automated decision-making

We do not use automated decision-making or profiling that produces legal effects for you, or that similarly significantly affects you. Decisions about whether and how we work with someone are made by people.

How long we keep it

  • Enquiries that do not become projects: up to 24 months, then deleted.
  • Client records and correspondence: for the life of the relationship and 6 years afterwards, which matches the limitation period for contract claims.
  • Accounting and tax records: 6 years from the end of the relevant financial year, as required by HMRC and the Companies Act 2006.
  • Website comments: kept while the article is published, unless you ask us to remove them.
  • Server logs: typically 30 to 90 days, depending on our host’s settings.

How we protect it

Maly holds ISO 27001 certification for information security management and ISO 9001 for quality management, and we have handled highly regulated data, including for global pharmaceutical clients, for many years. In practice that means access controls and least-privilege access to client systems, encryption in transit, multi-factor authentication on our business accounts, documented incident response, and supplier due diligence before we let a third party near anything sensitive.

If a personal data breach occurs that is likely to result in a risk to your rights, we will report it to the Information Commissioner’s Office within 72 hours of becoming aware of it, and we will tell you directly where the risk to you is high.

Your rights

Under the UK GDPR and the Data Protection Act 2018 you have the right to:

  • ask what personal data we hold about you, and get a copy of it
  • have inaccurate data corrected
  • ask us to delete data where we no longer have a good reason to keep it
  • ask us to restrict how we use it while a concern is resolved
  • receive data you gave us in a portable, machine-readable format
  • object to processing we carry out on the basis of legitimate interests
  • object to direct marketing at any time, with no need to give a reason
  • withdraw consent where consent is the basis we rely on

Email hello@maly.co.uk and we will respond within one month. Exercising these rights is free. We will not make you justify the request, though we may need to confirm your identity first.

If you are unhappy with how we have handled your information, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint or on 0303 123 1113.

Other sites

Our articles sometimes link to or embed content from other websites, such as YouTube videos. Those sites collect data and set their own cookies once the content loads, and their privacy policies apply to that activity, not ours.

Changes to this notice

We review this notice at least annually and whenever we change how we handle personal information. The date at the top always shows the current version.

Scroll to Top