TDEW Solutions
Effective date: 2 September 2026
Data controller: Thomas Wilson trading as TDEW Solutions
Correspondence address: TDEW Solutions, Suite RA01, 195 - 197 Wood Street, London E17 3NU
Email: tom@tdewsolutions.com
Telephone: 0333 335 7906
ICO Registration Number: ZC200484
1. About this Privacy Policy
This Privacy Policy explains how I collect, use, store, disclose and otherwise process personal data when you visit the TDEW Solutions website, contact me, request or receive services, use customer or support facilities, communicate with me, or otherwise interact with TDEW Solutions.
I process personal data in accordance with applicable UK data-protection law, including the UK GDPR and the Data Protection Act 2018, as amended from time to time. Where the Data (Use and Access) Act 2025 or other legislation changes the applicable rules, I will apply the law in force at the relevant time.
2. Who is responsible for your personal data
Thomas Wilson trading as TDEW Solutions is the controller for personal data I process for my own business purposes, such as enquiries, customer administration, billing, security, service management and legal compliance.
For some managed hosting or infrastructure services, a business customer may determine the purposes and means of processing personal data hosted through the service. In that situation, the customer may be the controller and I may act as its processor for that particular processing. Separate processor terms may apply where required.
3. Personal data I may collect
Depending on how you use my website or services, I may process:
- Identity and contact information, such as your name, business name, postal or correspondence address, email address and telephone number;
- Account and service information, including customer references, account identifiers, services purchased, hosting or infrastructure details, support history and service configuration;
- Booking and appointment information, including requested dates, agreed work, appointment details and communications relating to the booking;
- Billing and payment information, including invoice numbers, amounts due and paid, payment dates and references, and information reasonably required to reconcile Faster Payments or standing-order payments. I do not need your online-banking password, PIN or security credentials;
- Technical information, which may include IP addresses, timestamps, server and security logs, browser/device information, authentication events, resource usage and information needed to diagnose or secure a service;
- Support and communications data, such as emails, support tickets, messages, call notes and information you provide when asking for help;
- Website and device information collected through necessary cookies, sessions and security technologies, as described in my Cookie Policy;
- Customer content and device information that I may encounter where reasonably necessary to provide authorised technical support, managed hosting, infrastructure, form-filling or personal-administration services; and
- Other information you choose to provide where it is relevant to an enquiry, service, complaint, legal obligation or other legitimate business purpose.
4. Special category and particularly sensitive information
I do not ask for special category personal data unless it is reasonably necessary for the service you request or I otherwise have a lawful reason to process it. Personal-administration, form-filling or technical-support work may occasionally expose me to information concerning health, disability, religion or another sensitive matter contained in your documents, device or account.
Where special category data is processed, I will only process it where an appropriate lawful basis and an applicable condition for special category processing are available. You should avoid providing sensitive information that is not reasonably necessary for the service.
5. How I obtain personal data
I may obtain personal data directly from you when you use a form, request a service, communicate with me, make a payment, use a support facility or provide information during service delivery. I may also receive relevant information from a business customer, authorised representative, supplier, hosting or infrastructure provider, domain or software provider, security system or other source where this is necessary and lawful.
If I obtain your personal data from another source rather than directly from you, I will provide privacy information where required by law and within the applicable time period, unless an exemption applies.
6. Why I use personal data and my lawful bases
I only process personal data where I have a lawful basis. The basis depends on the particular purpose and circumstances. My main purposes and lawful bases may include:
To respond to enquiries and take steps before entering into a contract: where you ask for information, a quotation, appointment or service. The lawful basis will normally be taking steps at your request before entering into a contract.
To provide and administer contracted services: including bookings, Website Care, managed hosting, Managed VPS, Managed Dedicated Servers, technical support and other agreed services. The lawful basis will normally be performance of a contract or taking steps at your request before entering one.
To issue invoices, record and reconcile payments and maintain accounting records: the lawful bases may include performance of a contract, compliance with legal obligations and legitimate interests in administering my business and recovering sums properly due.
To operate, secure and protect my website, systems and services: including authentication, fraud prevention, abuse prevention, security logging, vulnerability management and incident investigation. The lawful basis will normally be legitimate interests in protecting my business, customers, systems and services, and may also include contractual or legal obligations.
To provide support and manage customer relationships: the lawful basis may be contract and legitimate interests in delivering and improving the service and maintaining accurate service records.
To comply with law, regulation, court orders, lawful requests or tax/accounting requirements: the lawful basis will normally be compliance with a legal obligation.
To establish, exercise or defend legal claims and manage complaints: the lawful basis may be legitimate interests and, where relevant, applicable provisions of data-protection law concerning legal claims.
To send optional marketing communications: where I undertake direct marketing, I will only do so where permitted by applicable data-protection and electronic-marketing law. Depending on the circumstances, the lawful basis may be consent or legitimate interests, and you can object to direct marketing at any time.
7. Legitimate interests
Where I rely on legitimate interests, those interests may include operating and administering TDEW Solutions, protecting customers and systems, preventing fraud and abuse, maintaining service security and reliability, keeping appropriate business records, improving services, recovering money properly owed and establishing or defending legal rights. I will consider whether my interests are overridden by your rights and interests before relying on this basis where the law requires it.
Your right to object: where I rely on legitimate interests, you may have the right to object to the processing on grounds relating to your particular situation. You have an absolute right to object to personal data being used for direct marketing.
8. When providing personal data is required
Some personal data is necessary for me to enter into or perform a contract with you, administer a service, verify an account, provide support, issue an invoice or comply with a legal obligation. If you do not provide information that is reasonably required, I may be unable to provide the requested service, complete a transaction, respond fully to a request or meet the relevant legal requirement.
9. Who I may share personal data with
I may disclose personal data where reasonably necessary to:
- hosting, VPS, dedicated-server, data-centre, network, software, control-panel, security, backup, domain, email and other technology providers used to deliver or support services;
- professional advisers such as accountants, insurers, legal advisers or other professional service providers where reasonably necessary;
- banks and payment-related providers where necessary to receive or reconcile payments;
- a supplier or subcontractor involved in delivering a service you requested;
- law-enforcement bodies, regulators, courts, government bodies or other authorities where disclosure is required or permitted by law;
- a prospective purchaser, transferee or adviser in connection with a genuine sale, transfer or restructuring of all or part of the business, subject to appropriate confidentiality and data-protection requirements; or
- another person where you have authorised the disclosure or I otherwise have a lawful basis to make it.
I do not sell personal data.
10. Processors and sub-processors
Where another organisation processes personal data on my behalf, I will use appropriate contractual and organisational arrangements where required by law. Where I act as processor for a business customer and appoint a sub-processor, I will apply the applicable processor requirements, including appropriate contractual protections and responsibility for the processing that I have subcontracted.
11. International transfers
Some suppliers may process personal data outside the United Kingdom. Where a restricted international transfer is made and UK data-protection law requires a safeguard, I will use an applicable lawful transfer mechanism, such as UK adequacy regulations, an appropriate UK transfer agreement/addendum, or another mechanism permitted by law.
You may contact me if you want further information about safeguards relevant to a particular transfer of your personal data.
12. How long I keep personal data
I keep personal data only for as long as reasonably necessary for the purpose for which it was collected and for any related legal, accounting, security, dispute-resolution or regulatory requirements. Different categories of information therefore have different retention periods.
When deciding how long to retain information I consider factors including the nature and sensitivity of the information, the service provided, contractual and legal requirements, limitation periods, security needs, accounting and tax obligations, backup cycles, complaint or dispute requirements and whether the information is still needed for the original purpose.
When personal data is no longer required, I will delete, anonymise or securely dispose of it as appropriate, subject to normal backup and disaster-recovery cycles.
13. Security
I use technical and organisational measures appropriate to the nature of the personal data and services. Measures may include encrypted connections, access restrictions, authentication controls, least-privilege access, security logging, firewall and server controls, software updates, backup controls and protected storage.
No internet-connected system can be guaranteed to be completely secure. However, I take reasonable steps to protect personal data under my control and will respond to personal-data breaches in accordance with applicable law.
14. Cookies and similar technologies
The website may use cookies, sessions and similar technologies for functions such as security, authentication, preferences and other website operation. Further information is set out in my Cookie Policy. Where consent is legally required for a non-essential cookie or similar technology, it will not be used on the basis of consent unless the applicable consent has been obtained.
15. Your data-protection rights
Depending on the circumstances and the lawful basis I rely on, you may have rights including:
- the right to be informed about how your personal data is used;
- the right of access to your personal data;
- the right to have inaccurate personal data corrected;
- the right to erasure in circumstances where that right applies;
- the right to restrict processing in circumstances where that right applies;
- the right to data portability for certain processing;
- the right to object to certain processing, including an absolute right to object to direct marketing; and
- rights relating to certain solely automated decisions with legal or similarly significant effects.
These rights are not absolute in every circumstance. The right that applies may depend on the lawful basis, the type of processing and any relevant legal exemption.
16. Withdrawing consent
Where I rely on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn. You can withdraw consent by contacting me using the details in this policy or by using any unsubscribe or preference mechanism provided for the relevant communication.
17. Automated decision-making
I do not currently use solely automated decision-making that produces legal effects concerning you or similarly significantly affects you as part of the ordinary TDEW Solutions customer relationship. If that changes in a way that triggers specific legal obligations, I will provide the information required by law.
18. Children's personal data
My business services are not directed at children. I do not knowingly seek to collect children's personal data through the website for marketing or account creation. If personal data concerning a child is provided because it is genuinely necessary for an authorised service, I will only process it where there is an appropriate lawful basis and it is relevant to the service.
19. Exercising your rights
To exercise a data-protection right, contact me at tom@tdewsolutions.com or write to the correspondence address above. I may ask for information reasonably necessary to confirm your identity and locate the relevant records.
I will respond within the period required by applicable data-protection law. In some circumstances the law allows that period to be extended, in which case I will tell you where required.
20. Complaints
If you have a concern about how I use your personal data, please contact me first so I can investigate it.
You also have the right to complain to the UK Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk
21. Links to other websites
My website may link to websites or services operated by other organisations. Their privacy practices are controlled by them, not by TDEW Solutions. You should review the privacy information provided by the relevant third party when using an external website or service.
22. Changes to this Privacy Policy
I may update this Privacy Policy when my services, suppliers, processing activities, technology or legal obligations change. The current version will be published on this page with its effective or last-updated date. Where the law requires me to bring a material new use of personal data to your attention before that processing begins, I will do so.
23. Contact details
Thomas Wilson trading as TDEW Solutions
Correspondence address: TDEW Solutions, Suite RA01, 195 - 197 Wood Street, London E17 3NU
Email: tom@tdewsolutions.com
Telephone: 0333 335 7906
ICO Registration Number: ZC200484