Legal · last updated 13 September 2026
Privacy notice
This notice explains what DeskBridge Ltd does with personal information when you visit our websites, contact us, request a quotation, use a DeskBridge account or receive a managed service.
Who is responsible for your information?
DeskBridge Ltd is a company registered in England and Wales under company number 17123038. Our registered office is 71B Liswerry Road, Newport, Wales, NP19 4LH. For website enquiries, sales, account administration and our own business operations, DeskBridge Ltd is the data controller. Contact us at contact@deskbridge.uk and put “Privacy” in the subject line.
When we operate a managed workspace or another service on a client’s documented instructions, that client will usually be the controller and DeskBridge will usually be its processor. The client’s privacy notice and the signed service agreement then explain the particular processing. DeskBridge may still be a controller for its own account, security, billing and legal records.
Whose information and what information?
- Website visitors: IP address or a one-way IP hash, security and rate-limit events, browser request information, form language and human-verification results.
- Enquirers and client contacts: name, work contact details, organisation, role, requirements, correspondence, quotation and meeting records.
- Account users and authorised contacts: identity, username, role, permissions, authentication and recovery records, device and session information, support requests and account lifecycle records.
- Client service users: operational metadata and, only where the agreed service requires it, content handled within the client workspace, mail, files, applications, backups or support process.
- Suppliers, partners and applicants: business contact, due-diligence, contract, payment and correspondence records.
- Information supplied by an organisation, authorised contact, service provider or public business source where it is necessary to establish or administer a business relationship.
Why we use it and our lawful bases
- To answer enquiries, prepare proposals and take steps requested before a contract: steps before entering a contract and our legitimate interest in responding to prospective clients.
- To provide, secure, support and administer contracted services: performance of a contract, our legitimate interests in reliable and secure operation, and compliance with legal obligations.
- To verify identity, manage access, investigate incidents, prevent fraud or misuse, maintain logs and protect tenants: our legitimate interests in protecting users, clients and our services, and legal obligations where applicable.
- To issue invoices, keep financial and company records, respond to lawful requests and establish or defend legal claims: contract, legal obligation and legitimate interests.
- To send service communications and relevant business follow-up: contract or legitimate interests. We use consent where the law requires it, and consent can be withdrawn at any time.
- To improve services using aggregated operational information and voluntary feedback: our legitimate interests in service quality, provided those interests do not override individual rights.
What you must provide
Information marked as required on a form is needed to answer the request or deliver the relevant service. Contracted users must provide the identity and account information needed for authorised access. If required information is not provided, we may be unable to respond, quote, create an account or provide the service. Optional fields may be left blank.
Who receives information?
We do not sell personal information. We do not disclose one client’s information to another client.
- Authorised DeskBridge staff and contractors who need it for sales, onboarding, support, security, finance or legal work.
- The client organisation and its authorised administrators where the information relates to that client’s service.
- Hosting, infrastructure, communications, security, payment, professional-advice and other service providers working under appropriate obligations.
- Cloudflare, where its Turnstile service is used to distinguish genuine form submissions from automated abuse.
- Regulators, courts, law-enforcement bodies, insurers, advisers or a prospective business purchaser where disclosure is lawful and necessary.
International transfers
DeskBridge is based in the United Kingdom and may deliver services involving the United Kingdom, the European Economic Area, the United Arab Emirates or another location agreed with a client. If personal information is transferred to a country without an applicable adequacy arrangement, we use an appropriate legal safeguard where required, such as an approved contractual transfer mechanism, together with proportionate technical and organisational controls. Contact us for information about the safeguard relevant to your processing.
How long do we keep it?
Specific periods can differ because of the type of record, contractual commitments, legal limitation periods, security needs, backups or a valid legal hold. We record those periods in the relevant retention schedule or service agreement rather than keeping information indefinitely.
- Unsuccessful or preliminary enquiries are reviewed and deleted or anonymised when they are no longer reasonably needed for follow-up, dispute handling or security.
- Contract, billing and company records are retained for the periods required by applicable tax, accounting and company law.
- Account, support, security, audit and backup records are kept for the period defined by the service, security and retention requirements, then deleted or anonymised under the applicable schedule.
- Rate-limit and abuse-prevention records are short-lived unless an event must be retained to investigate or evidence misuse.
- Where DeskBridge is a processor, return and deletion are governed by the client’s instructions and contract, subject to legal preservation duties.
Security and automated decisions
We use access control, authentication, tenant separation, logging, encryption and managed operational procedures appropriate to the service design. No internet service can promise absolute security.
DeskBridge does not use website enquiry information to make solely automated decisions that produce legal or similarly significant effects. Security tools may automatically flag or restrict suspicious activity, but material account or service decisions are subject to the applicable policy and review route.
Your rights
Rights depend on the circumstances and lawful basis. Contact contact@deskbridge.uk with “Privacy” in the subject. We may need to verify identity. If DeskBridge processes the information only for a client, we will normally refer the request to that client or assist it under the service agreement.
- Ask for access to your personal information and a copy of it.
- Ask us to correct inaccurate or incomplete information.
- Ask for deletion or restriction where the law allows it.
- Object to processing based on legitimate interests, including direct marketing.
- Ask for portable information where the legal conditions apply.
- Withdraw consent at any time where processing is based on consent; this does not affect earlier lawful processing.
- Complain to a data protection regulator.
Complaints and regional law
Please contact us first so we can investigate. In the United Kingdom you may also complain to the Information Commissioner’s Office at ico.org.uk or telephone 0303 123 1113. People in the UAE may have rights under Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data or an applicable free-zone regime; the responsible authority and exact rights depend on where and how the service is established and delivered.
This notice does not replace a client-specific data processing agreement, privacy notice or jurisdiction-specific addendum. We will update this page when our processing materially changes and show the revision date above.
Children
Our public websites and business services are not directed at children. Do not submit a child’s personal information through a general enquiry form. If a client service lawfully needs to handle children’s information, its scope, controller instructions and safeguards must be agreed specifically.