Privacy Policy
Last updated: 19 September 2026
Version: 2.0
-
INTRODUCTION
CoreBridge Technology Ltd (“CoreBridge”, “we”, “us” or “our”) is committed to protecting personal information and handling it lawfully, fairly and transparently.
This Privacy Policy explains how we collect, use, store, share and protect personal information when you:
-
Visit our website.
-
Contact us by email, telephone or through an online form.
-
Request a quotation or free consultation.
-
Subscribe to our newsletter.
-
Become a client or act as a representative of a client.
-
Receive IT support or another service from us.
-
Communicate with us in connection with our business.
We process personal information in accordance with the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 and other applicable UK data-protection legislation.
This Privacy Policy should be read alongside our Cookie Policy and Terms of Service.
2. WHO WE ARE
CoreBridge Technology Ltd is registered in England and Wales under company number 17334064.
Registered office:
Suite RA01
195–197 Wood Street
London
E17 3NU
CoreBridge provides practical IT support, Microsoft 365 assistance and technology planning for schools, charities and small businesses.
For personal information collected through our website, business communications, newsletter, consultation forms, quotations, invoicing and client administration, CoreBridge will normally act as the Data Controller. This means we determine why and how that information is processed.
When we access or process personal information contained within a client’s systems solely to provide agreed IT services, the client will normally act as the Data Controller and CoreBridge will act as a Data Processor. In those circumstances, we will process the information according to the client’s documented instructions, the applicable service agreement and any required Data Processing Agreement.
Questions about this Privacy Policy or our handling of personal information can be sent to:
privacy@corebridgetechnology.co.uk
3. PERSONAL INFORMATION WE COLLECT
The personal information we collect depends on how you interact with CoreBridge.
3.1 Contact and identity information
This may include:
-
Your name.
-
Organisation name.
-
Job title or professional role.
-
Business address.
-
Email address.
-
Telephone number.
-
Your preferred method of communication.
3.2 Enquiry and consultation information
This may include:
-
Information submitted through our contact or consultation forms.
-
The IT services in which you are interested.
-
Your preferred consultation date or time.
-
Details of your technology concerns or requirements.
-
Records of correspondence, telephone messages and meetings.
-
Documents or other information you choose to provide.
Please do not send passwords, authentication codes, highly sensitive personal information or confidential client data through an ordinary website form or unsecured email. We will provide an appropriate method where secure information is genuinely required.
3.3 Client and commercial information
This may include:
-
Quotations and proposals.
-
Accepted scopes of work.
-
Contracts and service agreements.
-
Client contact records.
-
Appointment and site-visit details.
-
Invoices, payment status and accounting records.
-
Records of agreed instructions, approvals and service communications.
We do not normally collect or store complete payment-card details. Payments are handled through the payment method or financial provider identified on our invoice.
3.4 Technical and support information
Where necessary to provide agreed IT services, we may process:
-
Device names, serial numbers and asset information.
-
Device types, operating systems and software information.
-
IP addresses and basic network information.
-
Microsoft 365 usernames, account details, licence information and access roles.
-
Mailbox, Teams, SharePoint and OneDrive configuration information.
-
Multi-factor authentication status and security-setting information.
-
Support requests, error messages and technical logs.
-
Details of hardware, warranties and device lifecycles.
-
Information about suppliers and existing support arrangements.
-
Remote-support session details.
We will only access information reasonably necessary to provide the agreed Services.
We do not ask clients to disclose user passwords unless there is a specific, authorised and secure reason. Clients and users should never send passwords or multi-factor authentication codes through ordinary email or website forms.
3.5 Website and cookie information
When you use our website, we may collect:
-
IP address.
-
Browser type.
-
Device type.
-
Pages visited.
-
Date and time of visits.
-
Referral information.
-
Cookie choices.
-
Basic website-performance and security information.
Some of this information is collected automatically through Wix and associated website technologies. Optional cookies will only be used where the appropriate consent has been obtained.
3.6 Newsletter information
When you subscribe to our newsletter, we collect your email address and a record of your consent and subscription preferences.
3.7 Special-category and children’s information
Our public website forms are not designed to collect special-category personal data, criminal-offence data or information directly from children.
Where CoreBridge supports a school or another organisation, we may occasionally encounter personal information held within the client’s systems. In those circumstances, we will process the information only as necessary to provide the agreed service and according to the client’s documented instructions.
4. HOW WE COLLECT PERSONAL INFORMATION
We may collect personal information:
-
Directly from you when you contact us.
-
When you complete a website, consultation or newsletter form.
-
When you request a quotation or enter into an Agreement with us.
-
During meetings, telephone calls, support requests and onsite visits.
-
When an authorised representative of your organisation provides information to us.
-
When we access a client’s system for authorised support purposes.
-
Automatically through essential website and security technologies.
-
Through optional website cookies where you have provided consent.
-
From publicly available business sources, such as an organisation’s website, Companies House or a professional networking profile.
-
From an agreed supplier, professional adviser or specialist partner where sharing is lawful and relevant to the Services.
We collect only information that is reasonably necessary for the purposes described in this Privacy Policy.
5. HOW AND WHY WE USE PERSONAL INFORMATION
We must have a lawful basis under UK data-protection law for each purpose for which we use personal information.
5.1 Responding to enquiries and consultation requests
Purpose:
-
Receiving and responding to enquiries.
-
Arranging free consultations.
-
Understanding initial IT requirements.
-
Communicating with prospective clients.
Lawful basis:
Our legitimate interests in responding to business enquiries and developing client relationships. Where an individual asks us to take specific steps before entering into a contract, we may also rely on steps requested before entering into a contract.
5.2 Preparing quotations and providing Services
Purpose:
-
Understanding client requirements.
-
Preparing quotations, proposals and scopes of work.
-
Delivering IT support, Microsoft 365 assistance, reviews and technology advice.
-
Managing appointments, remote sessions and onsite visits.
-
Communicating about support requests and project progress.
Lawful basis:
Performance of a contract or steps requested before entering into a contract where the contract is with an individual.
Where the client is a company, school, charity or other organisation, we rely on our legitimate interests in administering the relationship and communicating with the client’s representatives.
5.3 Client administration and financial records
Purpose:
-
Maintaining client records.
-
Issuing invoices.
-
Recording payments.
-
Managing contracts and support arrangements.
-
Maintaining appropriate accounting and tax records.
-
Recovering unpaid commercial debts where necessary.
Lawful basis:
Contract, legitimate interests in administering our business and collecting payment, and compliance with legal obligations concerning accounting, taxation and record keeping.
5.4 Providing IT support
Purpose:
-
Investigating technical problems.
-
Configuring authorised devices and accounts.
-
Providing remote or planned onsite assistance.
-
Supporting Microsoft 365 administration.
-
Reviewing devices, licences, access and practical security settings.
-
Producing agreed reports and recommendations.
-
Coordinating with approved suppliers or specialists.
Lawful basis:
Contract or legitimate interests in delivering Services requested by a client.
Where information is processed on behalf of a client, CoreBridge will rely on the client’s instructions and act as a Data Processor.
5.5 Website operation and security
Purpose:
-
Operating and protecting our website.
-
Maintaining website forms and functionality.
-
Recording cookie preferences.
-
Detecting misuse, fraud or security incidents.
-
Understanding basic website performance.
Lawful basis:
Our legitimate interests in operating and protecting our website and business systems.
Essential cookies are used where necessary to provide and secure the website. Optional cookies are used only where the required consent has been obtained.
5.6 Newsletter and service updates
Purpose:
Sending practical IT guidance, Microsoft 365 information and CoreBridge service updates to subscribers.
Lawful basis:
Consent.
You may withdraw consent at any time by using the unsubscribe link in an email or contacting us.
5.7 Legal and regulatory requirements
Purpose:
-
Complying with applicable laws and lawful requests.
-
Maintaining required business records.
-
Responding to regulatory authorities.
-
Establishing, exercising or defending legal claims.
-
Protecting the rights, security and property of CoreBridge, our clients and others.
Lawful basis:
Legal obligation and our legitimate interests in protecting the business and its legal rights.
6. PROCESSING INFORMATION ON BEHALF OF CLIENTS
When CoreBridge accesses personal information within a client’s system to provide IT support, the client will normally remain responsible for deciding:
-
Why the information is processed.
-
The applicable lawful basis.
-
Which individuals should have access.
-
How long the information should be retained.
-
What information may be disclosed to CoreBridge.
-
What instructions CoreBridge should follow.
CoreBridge will:
-
Process personal information only on documented instructions, unless otherwise required by law.
-
Access only the information reasonably necessary for the agreed Services.
-
Apply appropriate security and confidentiality measures.
-
Limit access to authorised people.
-
Notify the client without undue delay if we become aware of a relevant personal-data breach.
-
Return or securely delete personal information where required at the end of the Services, subject to lawful retention requirements.
-
Enter into an appropriate Data Processing Agreement where required by applicable law.
Clients must ensure that they have the necessary authority and lawful basis before providing CoreBridge with access to personal information.
7. SHARING PERSONAL INFORMATION
We do not sell, rent or trade personal information to other organisations for their own marketing purposes.
We may share limited personal information with:
7.1 Technology and business-service providers
These may include providers supporting:
-
Website hosting, forms and cookie management.
-
Domain registration and DNS.
-
Business email, cloud storage and collaboration.
-
Telephone and virtual-reception services.
-
Invoicing, accounting and financial administration.
-
Secure remote-support technology.
-
Business security and device management.
-
Newsletter delivery.
Providers used by CoreBridge may include Wix, Microsoft, Namecheap, Soho66 and Zoho, depending on the particular business function involved.
These providers may act as our Data Processors or as independent Data Controllers, depending on the service and applicable terms.
7.2 Professional advisers
We may share relevant information with solicitors, accountants, insurers, auditors or other professional advisers where reasonably necessary.
7.3 Specialist suppliers and partners
Where specialist work or supplier coordination is agreed with a client, we may share the minimum information necessary with the approved specialist or supplier.
The respective responsibilities of CoreBridge and the third party will be explained where appropriate. A third party may act as its own Data Controller or as a processor, depending on the circumstances.
7.4 Public authorities
We may disclose information to a court, regulator, law-enforcement agency, government authority or other public body where required or permitted by law.
7.5 Business restructuring
If CoreBridge is involved in a genuine sale, merger, restructuring or transfer of its business, relevant information may be disclosed subject to appropriate confidentiality and data-protection safeguards.
Whenever we share personal information, we will take reasonable steps to ensure that:
-
Only necessary information is shared.
-
The sharing has a lawful purpose.
-
Appropriate contractual and security protections are used where required.
-
Information is not used for an incompatible purpose.
8. INTERNATIONAL TRANSFERS
CoreBridge is established in the United Kingdom. However, some technology providers may process or store personal information outside the United Kingdom.
Where an international transfer is restricted under UK data-protection law, we will use an appropriate transfer mechanism. This may include:
-
A UK adequacy regulation.
-
The UK International Data Transfer Agreement.
-
The UK Addendum to the European Commission’s Standard Contractual Clauses.
-
Another legally approved safeguard.
We will also consider the security, contractual protections and data-handling arrangements of relevant providers.
You may contact us if you would like further information about the safeguards applying to a particular transfer.
9. MARKETING COMMUNICATIONS
CoreBridge currently uses email to send its newsletter, practical IT guidance and relevant service updates to people who have subscribed.
We will:
-
Record the consent given when someone subscribes.
-
Include an unsubscribe method in marketing emails.
-
Respect withdrawal of consent.
-
Keep limited suppression information where necessary to ensure that an unsubscribe request continues to be respected.
You can unsubscribe at any time by:
-
Selecting the unsubscribe link in a marketing email; or
-
Contacting privacy@corebridgetechnology.co.uk.
Withdrawing from marketing will not prevent us from sending necessary communications about an enquiry, quotation, appointment, invoice, security matter or active service arrangement.
We do not currently use SMS marketing or sell contact details to marketing companies.
10. COOKIES AND WEBSITE TECHNOLOGIES
CoreBridge uses cookies and similar technologies to operate and secure its Wix website.
10.1 Essential technologies
Essential technologies may support:
-
Website navigation and delivery.
-
Security.
-
Online forms.
-
Cookie-consent preferences.
-
Basic website functionality.
Essential technologies cannot always be disabled through our cookie settings because they are required for the website to operate.
10.2 Optional analytics
Wix may provide information about how visitors use our website. Where analytics requires optional cookies or similar technologies, they will only be activated after the visitor provides the appropriate consent.
As at the date of this Privacy Policy, CoreBridge has not connected a separate analytics service such as Google Analytics.
10.3 Advertising technologies
As at the date of this Privacy Policy, CoreBridge does not use personalised advertising integrations such as Meta Pixel, TikTok Pixel or Google advertising tags.
If this changes, we will update our Privacy Policy and Cookie Policy and obtain consent where required.
10.4 Managing cookie preferences
You can accept, reject or manage optional cookies through the website cookie banner or privacy-settings control.
You can also manage cookies through your browser. Blocking essential cookies through browser settings may affect website functionality.
Further information is available in our Cookie Policy.
11. DATA RETENTION
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected and to meet applicable legal, accounting, contractual and regulatory requirements.
Our usual retention periods are:
11.1 Unsuccessful enquiries and consultation requests
Normally up to 24 months after our last meaningful communication, unless there is a lawful reason to keep the information longer or you request earlier deletion where that right applies.
11.2 Client contracts and business records
Normally for the duration of the client relationship and up to six years afterwards where required for contractual, legal, insurance or legitimate business purposes.
11.3 Invoices, payment and accounting records
Normally for at least six years from the end of the relevant financial year or accounting period, or longer where required by law or a relevant authority.
11.4 Technical-support records
Support records and service documentation will be retained for the duration of the service arrangement and for an appropriate period afterwards.
Records relevant to contractual obligations, complaints, security incidents or legal claims may be retained for up to six years. Routine technical information that is no longer needed may be deleted sooner.
11.5 Information accessed within client systems
Information accessed while CoreBridge acts as a Data Processor will be retained only for as long as required to provide the agreed Services or as instructed by the client.
It will be returned or securely deleted according to the applicable Agreement or Data Processing Agreement, subject to legal retention requirements.
11.6 Newsletter records
Subscription information will be retained until consent is withdrawn or the subscription otherwise ends.
Limited suppression information may be retained afterwards to ensure that we continue to respect the unsubscribe request.
11.7 Website and cookie information
Website, cookie and consent information will be retained for the periods stated in our Cookie Policy, cookie settings or consent-management platform.
When personal information is no longer required, we will securely delete, anonymise or otherwise dispose of it.
12. DATA SECURITY
CoreBridge uses appropriate technical and organisational measures designed to protect personal information from accidental or unlawful loss, destruction, alteration, disclosure or access.
Measures may include, where appropriate:
-
Secure website connections.
-
Access controls and least-privilege access.
-
Multi-factor authentication.
-
Secure business accounts.
-
Endpoint protection and device-security controls.
-
Security updates and patching.
-
Device encryption.
-
Secure cloud-storage providers.
-
Confidentiality requirements.
-
Procedures for responding to security incidents.
-
Appropriate security checks when selecting service providers.
No method of electronic transmission or storage can be guaranteed to be completely secure. However, we regularly review the measures appropriate to the nature and sensitivity of the information we process.
If we become aware of a personal-data breach, we will investigate it and take appropriate action. Where required by law, we will notify the Information Commissioner’s Office, the relevant client and affected individuals.
13. CHILDREN’S PRIVACY
Our website and public forms are intended for organisations and their authorised representatives. They are not directed at children, and we do not knowingly invite children to submit personal information directly through the website.
When providing Services to a school or educational organisation, CoreBridge may encounter information relating to pupils or young people.
In those circumstances:
-
The school or educational organisation will normally act as the Data Controller.
-
CoreBridge will normally act as a Data Processor.
-
Information will only be accessed where necessary to provide the agreed Services.
-
CoreBridge will follow the organisation’s documented instructions and applicable safeguarding, confidentiality and data-protection requirements.
If you believe a child has submitted personal information directly to CoreBridge through our public website, please contact privacy@corebridgetechnology.co.uk.
14. YOUR DATA-PROTECTION RIGHTS
Depending on the circumstances, you may have the right to:
-
Be informed about how your information is used.
-
Request access to your personal information.
-
Request correction of inaccurate or incomplete information.
-
Request deletion of personal information in certain circumstances.
-
Request restriction of processing in certain circumstances.
-
Object to processing based on legitimate interests.
-
Object to direct marketing at any time.
-
Receive certain information in a portable format where the right to data portability applies.
-
Withdraw consent where processing is based on consent.
-
Complain to the Information Commissioner’s Office.
-
Not be subject to certain decisions based solely on automated processing that produce legal or similarly significant effects.
CoreBridge does not currently use personal information to make solely automated decisions that have legal or similarly significant effects.
To exercise a right, contact:
privacy@corebridgetechnology.co.uk
We may need to request information to confirm your identity and prevent unauthorised disclosure.
We will normally respond within one month. This period may be extended where a request is complex or multiple requests have been received, as permitted by law.
There is normally no fee. However, where permitted by law, we may charge a reasonable fee or refuse to act on a request that is manifestly unfounded or excessive.
Some rights are subject to legal conditions and exemptions. We may retain information where continued processing is required by law or necessary to establish, exercise or defend legal claims.
Where CoreBridge processes personal information solely on behalf of a client, we may refer the request to that client as the responsible Data Controller.
15. QUESTIONS AND COMPLAINTS
If you have a question or concern about how CoreBridge uses personal information, please contact:
privacy@corebridgetechnology.co.uk
We will investigate the matter and aim to respond appropriately.
You also have the right to complain to the Information Commissioner’s Office, the UK regulator for data protection:
Website: www.ico.org.uk
Contacting CoreBridge first does not affect your right to raise a concern with the Information Commissioner’s Office or pursue another available legal remedy.
16. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy to reflect changes in:
-
Our Services.
-
Our use of technology and suppliers.
-
Our legal obligations.
-
Our handling of personal information.
-
Applicable regulatory guidance.
The current version will be published on our website with an updated date and version number.
Where a change materially affects how we use existing personal information, we will provide an appropriate notice where required by law.
17. CONTACT DETAILS
CoreBridge Technology Ltd
Suite RA01
195–197 Wood Street
London
E17 3NU
Telephone: 020 4610 0849
Privacy email: privacy@corebridgetechnology.co.uk
General enquiries: info@corebridgetechnology.co.uk
Website: www.corebridgetechnology.co.uk
Registered in England and Wales
Company number: 17334064