Last updated: 17 September 2026
Triplepoint IT Limited ("Triplepoint", "we", "us", "our") is committed to protecting your personal data. This notice explains what personal data we collect, why, and what rights you have, in line with UK GDPR and the Data Protection Act 2018.
If you are a client whose data we process while delivering the Sophos services you've purchased (e.g. endpoint or mailbox data), that processing is governed separately by our Data Processing Agreement with you, not this notice — you remain the Controller of that data, and we act only as your Processor.
Triplepoint IT Limited, a company registered in England and Wales, company number 17306876, registered office Bumblebee Cottage, Main Street, Clanfield, Oxon, OX18 2SH, is the Controller for the personal data described in this notice.
Contact for privacy queries: privacy@triplepoint.org.uk. As a small company, Triplepoint doesn't have a formal Data Protection Officer; privacy queries go directly to the Director.
If you visit our website or contact us to enquire about our services, we may collect: your name, email address, and any other details you choose to provide in a contact form or email; and technical data about your visit (IP address, browser type, pages viewed) — see our Cookie Policy for detail on cookies specifically.
Why: to respond to your enquiry, and — where you've engaged with us as a prospect — to follow up about our services.
Lawful basis: our legitimate interests in responding to enquiries and running a business development process; where cookies require consent, that consent (see Cookie Policy).
If you're named as an Authorised Account Owner or Authorised Contact for a client account, we hold your name, work email, phone number, and role.
Why: to administer the account — billing, service notifications, support requests, and identity-verification steps that protect against invoice fraud and business email compromise.
Lawful basis: our legitimate interests in administering our contract with your employer, and performance of that contract where you are acting as its representative.
If you apply to work with Triplepoint as a self-employed associate or subcontractor, we may collect: your name and contact details, CV/qualifications, right-to-work information, references, and — where relevant to a specific engagement — vetting or screening information.
Why: to assess your suitability, and, if engaged, to administer that engagement.
Lawful basis: steps taken at your request prior to entering into a contract, and our legitimate interests in assessing candidates. Where screening involves a criminal records check, the lawful basis for processing that specific category of data will be confirmed at the time (Data Protection Act 2018, Schedule 1).
Unsuccessful applications: retained for a limited period in case a suitable engagement arises later, then deleted, unless you ask us to delete it sooner.
We share personal data only where necessary, with:
We do not sell personal data. Where any service provider is based outside the UK, we ensure an appropriate safeguard (such as the UK's International Data Transfer Addendum) is in place.
We keep personal data only for as long as necessary for the purpose it was collected for, or as required by law. For example, accounting records are kept for 6 years, and unsuccessful job applications for around 6 months. Full retention periods by data category are available on request.
See our separate Cookie Policy for detail on the cookies and similar technologies used on our website and how to control them.
Under UK GDPR, you have the right to: access the personal data we hold about you; have inaccurate data corrected; have data deleted in certain circumstances; restrict or object to certain processing; receive certain data in a portable format; and withdraw consent at any time where processing is based on consent.
To exercise any of these rights, contact us using the details in §1. We will respond within one month, as required by law.
If you're unhappy with how we've handled your personal data, please contact us first so we can try to resolve it. You also have the right to complain to the UK's data protection regulator:
Information Commissioner's Office (ICO) — ico.org.uk — 0303 123 1113.
We are in the process of registering with the ICO; our registration number will be added here once confirmed.
We may update this notice from time to time — for example, as our services, tools, or legal obligations change. The "Last updated" date at the top shows when it was last revised.
This notice does not create any contractual rights. Where it conflicts with a specific contractual document, that document governs the relevant point.