Privacy Policy

How iTechU collects, uses, shares and protects personal information

Controller: iTech Prestige Limited trading as iTechU

Website: www.itechu.co.uk

Effective date: 17 August 2026

Contact: info@itechu.co.uk

This Privacy Notice explains how we handle personal information when you visit our website, book or purchase a service, contact us, submit a device, make a payment, request data erasure or disposal, or otherwise deal with iTechU.

1. Who We Are

iTech Prestige Limited trading as iTechU (“iTechU”, “we”, “us” or “our”) is the controller of personal information covered by this Notice, except where a separate agreement states that we act only as a processor for a business customer.

Our business address is 270 Knutsford Road, Warrington, WA4 1AZ, England, UK. You can contact us about privacy at info@itechu.co.uk.

2. Scope of This Notice

This Notice applies to personal information collected through www.itechu.co.uk and through our repair, diagnostic, retail, customer-support, data-erasure, recycling and disposal services. It does not govern third-party websites or services that have their own privacy notices.

3. Personal Information We Collect

Depending on how you use our website and services, we may collect:

  • identity and contact details, such as your name, billing or delivery address, email address and telephone number;

  • booking and transaction information, including selected services, appointment details, quotations, job sheets, invoices, payment status, refunds, collections and delivery information;

  • device and repair information, such as manufacturer, model, serial number, IMEI, reported fault, physical condition, diagnostic results, repair history and installed parts;

  • device-access information, such as a passcode or temporary access instructions, where reasonably necessary for an authorised repair, calibration or functional test;

  • payment and fraud-prevention information. Card details are normally entered directly into a payment provider’s secure service; we generally receive transaction references, payment status and limited card information rather than complete card details;

  • communications, including enquiries, complaints, warranty claims, reviews, survey responses and records of consent or instructions;

  • website and technical information, such as IP address, browser, operating system, approximate location, referral source, pages viewed, actions taken and cookie or similar-technology identifiers; and

  • marketing preferences, including whether you agreed to receive email or text marketing and when you changed that choice.

A submitted device may contain personal information belonging to you or other people. We do not seek to inspect that content except where access is reasonably necessary for the authorised service, testing, security or legal obligations.

4. How We Obtain Personal Information

We obtain information directly from you when you use our website, book a repair, submit equipment, communicate with us, make a payment or request a service. We may also receive information from:

  • a person or organisation authorised to act for you;

  • business customers that submit equipment or authorised-user details;

  • payment, booking, fraud-prevention, delivery or communications providers;

  • device manufacturers or diagnostic platforms used for an authorised service; and

  • cookies and similar technologies used on our website, subject to applicable consent requirements.

5. Why We Use Personal Information and Our Lawful Bases

We use personal information only where we have a lawful basis. The principal purposes and bases are summarised below.

Purpose Information used Lawful basis
Booking, supplying and administering repairs, products and related services Identity, contact, booking, transaction, device and communication information Contract; steps requested before entering a contract
Taking payment, issuing invoices and managing refunds Contact, transaction and limited payment information Contract; legal obligation; legitimate interests in accurate payment administration
Diagnosing, repairing, calibrating and testing devices Device, diagnostic and access information Contract; legitimate interests in delivering and verifying the authorised service
Customer service, complaints and warranty claims Identity, contact, job and communication records Contract; legal obligation; legitimate interests in resolving issues and defending claims
Fraud prevention, security and debt recovery Identity, contact, transaction, technical and risk information Legal obligation where applicable; legitimate interests in protecting customers and our business
Accounting, tax, legal and regulatory compliance Transaction, invoice, service and communication records Legal obligation; legitimate interests in maintaining evidence and records
Website operation, security and improvement Technical, usage and cookie information Legitimate interests for essential operation and security; consent where required for non-essential technologies
Marketing by email, text or similar channels Contact details, preferences and engagement information Consent, or another lawful PECR route where available and properly applied
Corporate data erasure, recycling and disposal Authorised-contact, asset, chain-of-custody and erasure records Contract; legal obligation; legitimate interests in secure and auditable service delivery

Where we rely on legitimate interests, we consider the purpose, necessity and effect on individuals before using the information. You may object to processing based on legitimate interests in the circumstances described under “Your Rights”.

6. Device Passcodes, Diagnostics and Device Content

Where a passcode or access instruction is required, we use it only for the authorised diagnosis, repair, calibration and functional testing. Access is restricted to personnel who need it for that work. Passcodes should not be included in permanent job notes and are removed from active repair records when the repair and necessary testing are closed, unless retention is required to resolve an ongoing issue or by law.

We ask customers to back up their devices and remove or minimise sensitive content before submission where possible. Business customers should provide documented instructions and ensure they are entitled to permit access to personal information on submitted equipment.

7. Payments

Payments may be processed by a specialist payment provider. That provider may act as an independent controller for payment-card and fraud-prevention information and will provide its own privacy information. We do not intentionally store complete payment-card numbers or card security codes in our ordinary business systems.

8. Who We Share Personal Information With

We share personal information only where reasonably necessary and proportionate. Recipients may include:

  • website hosting, booking, customer-management, communications and IT-support providers;

  • payment processors, banks and fraud-prevention providers;

  • couriers, collection providers and delivery partners;

  • device manufacturers, parts suppliers and authorised diagnostic or calibration platforms;

  • repair specialists, data-erasure providers, waste carriers, recyclers and approved treatment facilities;

  • professional advisers, insurers, auditors and debt-recovery providers;

  • government bodies, regulators, law-enforcement agencies and courts where disclosure is required or permitted by law; and

  • a buyer, investor or adviser involved in a proposed or completed sale, reorganisation or transfer of all or part of our business, subject to appropriate confidentiality and legal safeguards.

Where a supplier processes personal information on our behalf, we require appropriate contractual, confidentiality and security protections. Business customers may receive more specific processor and sub-processor information in their service agreement.

9. International Transfers

Some service providers may store or access personal information outside the UK. Where UK data-protection law restricts such a transfer, we use an applicable safeguard, such as a UK adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another lawful mechanism. You may contact us for further information about safeguards relevant to your information.

10. How Long We Keep Personal Information

We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including service delivery, warranty, accounting, tax, legal, security and dispute-resolution requirements. Our usual periods are:

  • repair, sales, invoice, payment and core customer-service records: normally up to six years after the transaction or completion of the service;

  • device passcodes and temporary access instructions: removed from active records when the repair and necessary testing are closed, subject to any unresolved issue or legal requirement;

  • enquiries that do not lead to a transaction: normally up to 12 months after the last meaningful contact;

  • marketing records: until you withdraw consent or we stop the relevant activity, with minimal suppression information retained where necessary to respect an opt-out;

  • corporate asset, chain-of-custody, erasure, destruction and recycling records: for the period agreed with the business customer or reasonably required for legal, audit and security purposes; and

  • cookie and analytics information: for the period stated in our Cookie Policy or cookie-preference tool.

We may keep information longer where required by law, reasonably necessary for legal claims, or requested by a regulator or law-enforcement body. We may retain properly anonymised information that no longer identifies an individual.

11. Cookies and Similar Technologies

Our website may use cookies, pixels, local storage and similar technologies for essential operation, security, booking functions, preferences, analytics and marketing. We provide more detail in our Cookie Policy and cookie-preference tool.

Where consent is required, non-essential technologies are not used until you choose to accept them. You can reject non-essential technologies and change your choices through the cookie settings. Withdrawing consent does not affect earlier lawful processing.

12. Direct Marketing

We send electronic marketing only where we have a lawful basis and comply with applicable electronic-marketing rules. Consent is not obtained through pre-ticked boxes. You can unsubscribe using the link in a marketing message or by contacting info@itechu.co.uk. Service messages about a booking, repair, payment, warranty or security issue are not marketing and may still be sent where necessary.

13. Your Data-Protection Rights

Depending on the circumstances, you may have the right to:

  • request access to your personal information;

  • ask us to correct inaccurate or incomplete information;

  • request erasure of information where the legal conditions are met;

  • request restriction of processing;

  • object to processing based on legitimate interests or to direct marketing;

  • request transfer of information you provided to us where the right to portability applies;

  • withdraw consent at any time where processing relies on consent; and

  • complain to the Information Commissioner’s Office.

These rights are not absolute and may be subject to legal exceptions. To exercise a right, email info@itechu.co.uk. We may request information reasonably necessary to verify your identity or authority. We normally respond within one month, subject to lawful extensions for complex or multiple requests.

14. Automated Decisions

We do not currently make decisions that produce legal or similarly significant effects about customers solely through automated processing. If this changes, we will provide the information and safeguards required by law.

15. Information Security

We use technical and organisational measures designed to protect personal information against unauthorised access, alteration, disclosure, accidental loss and destruction. Measures are selected according to the nature of the information and the risk, and may include access controls, staff confidentiality, secure systems, supplier checks, controlled device handling and incident-management procedures.

No internet transmission or storage system is completely secure. Please do not send device passcodes, complete card information or highly sensitive content through ordinary email unless we specifically instruct you to use an approved secure method.

16. Children

Our website and repair services are not directed at children acting independently. A person under 18 should ask a parent, guardian or other authorised adult to make a booking or purchase on their behalf. If we learn that information was collected from a child without appropriate authority, we will take reasonable steps to address it.

17. Changes to This Notice

We may update this Notice to reflect changes in our services, suppliers, technology or legal obligations. The current version will be published on our website with its effective date. Where a change materially affects how we use existing personal information, we will provide additional notice where required.

18. Contact Us and Make a Complaint

Privacy enquiries and rights requests may be sent to:

iTech Prestige Limited trading as iTechU

270 Knutsford Road

Warrington

WA4 1AZ

England, UK

Email: info@itechu.co.uk

If you are dissatisfied with our response, you may complain to the Information Commissioner’s Office (ICO). Current contact details and complaint options are available at https://ico.org.uk/make-a-complaint/. You may also call the ICO on 0303 123 1113.