Data Processing / Data Protection Policy

Vyper Networks Ltd

Vyper Networks Ltd is committed to complying with UK data protection laws, including the UK General Data Protection Regulation and the Data Protection Act 2018.

This Data Processing / Data Protection Policy explains how we handle personal data and how we manage our responsibilities when providing IT support, cloud, hosting, backup, Microsoft 365, cyber security and related services.

Company Information

Vyper Networks Ltd
11 Old Bond Street
Mayfair
London
W1S 4PN

Registered office:
6th Floor, Manfield House
1 Southampton Street
London
WC2R 0LR

Telephone: 033 022 3 1562
Email: info@vypernetworks.com
Website: https://vypernetworks.com/

Company Number: 09518430

Purpose Of This Policy

The purpose of this policy is to ensure that personal data handled by Vyper Networks Ltd is processed lawfully, fairly, transparently and securely.

This policy applies to personal data relating to website visitors, customers, client staff, suppliers, contractors, business contacts and individuals whose data may be processed through client systems that we support.

Data Controller And Data Processor Roles

Vyper Networks Ltd may act as a data controller where we decide how and why personal data is processed. This may include personal data relating to enquiries, customer contacts, billing, website use, support records and our own business administration.

Vyper Networks Ltd may act as a data processor where we process personal data on behalf of a client. This may occur when we provide IT support, hosting, email hosting, file hosting, Microsoft 365 services, backup services, cyber security tools, customer portals or cloud services for a client.

Where we act as a processor, we will process personal data in accordance with the client’s documented instructions, applicable law and any agreed data processing terms.

Personal Data We May Handle

We may handle personal data including:

Names
Business names
Job titles
Email addresses
Telephone numbers
IP addresses
Login records
Support ticket details
Device information
Network information
System logs
Hosting account information
Domain information
Email hosting information
Microsoft 365 information
File hosting information
Backup records
Security alert information
Customer portal records
Billing information
Correspondence

Where we support client systems, we may also incidentally access personal data stored within client emails, files, backups, databases, servers, cloud systems or devices.

Data Protection Principles

We aim to ensure that personal data is:

Processed lawfully, fairly and transparently
Collected for specific, clear and legitimate purposes
Adequate, relevant and limited to what is necessary
Accurate and kept up to date where required
Stored only for as long as necessary
Protected against unauthorised access, loss, misuse or disclosure

Lawful Processing

Where we act as controller, the lawful bases we may rely on include:

Contractual necessity
Legal obligation
Legitimate interests
Consent

Where we act as processor, the client is usually responsible for identifying the lawful basis for processing.

Data Security Measures

We take reasonable technical and organisational measures to protect personal data.

These may include:

Access controls
Password protection
Multi-factor authentication where appropriate
Encryption where appropriate
Secure backup procedures
Endpoint security tools
Anti-virus and anti-malware protection
Email security measures
Firewall and network protection
System monitoring
Restricted staff access
Secure support procedures
Secure deletion where appropriate
Supplier due diligence where appropriate

Client Responsibilities

Clients are responsible for ensuring that their own data protection obligations are met.

This includes ensuring that personal data is collected lawfully, staff and customer privacy information is provided where required, access permissions are appropriate, users follow security procedures and data is backed up or retained in accordance with agreed services.

Clients must provide accurate instructions and notify us promptly of any data protection, security or service concerns.

Sub-Processors And Third Parties

We may use third-party providers to deliver services.

These may include Microsoft 365, cloud infrastructure providers, hosting providers, domain registrars, backup service providers, cyber security vendors, monitoring platforms, email security providers, IT support tools, payment providers and website providers.

Where appropriate, we will take reasonable steps to ensure suppliers provide appropriate security and data protection standards.

Data Retention

Personal data will only be retained for as long as necessary.

Support records, billing records, logs, hosting records, backup data and service information may be retained in accordance with contractual, legal, tax, accounting, security, support or operational requirements.

Backup retention periods will depend on the agreed backup service, client settings and applicable service terms.

Data Breaches And Security Incidents

Any suspected personal data breach or relevant security incident will be reviewed promptly.

Where we act as a processor, we will notify the client where required and provide reasonable assistance so the client can meet their legal obligations.

Where we act as controller, we will notify the Information Commissioner’s Office and affected individuals where required by law.

International Transfers

Some cloud, hosting, Microsoft 365, backup, security or support tools may involve data processing outside the UK.

Where international transfers occur, we will take reasonable steps to ensure appropriate safeguards are in place where required.

Individual Rights

Individuals may have rights under UK data protection law, including rights to access, correct, delete, restrict, object to processing, withdraw consent and request data portability where applicable.

Where Vyper Networks Ltd acts as processor, requests may need to be referred to the relevant client as data controller.

Policy Review

This policy may be reviewed and updated from time to time.