Privacy Notice
Last updated: 14 August 2026
Review frequency: At least annually
1. Who we are
RAZIX (Razix Technology Ltd) provides IT support, managed IT services, cloud services and Microsoft cloud solutions to businesses.
Our services may include Microsoft 365, Azure, Microsoft Entra ID, Microsoft Intune, licensing, cloud migrations, cybersecurity, monitoring, backup and general IT support.
We take the privacy and security of personal information seriously and process personal data in accordance with applicable UK data protection legislation, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
For data protection enquiries, requests or complaints, please contact:
Company: Razix Technology Ltd
Email: [email protected]
2. Information we collect
The personal information we collect depends on your relationship with us and the services we provide.
This may include:
- Name and job title
- Business email address
- Telephone number
- Company and department
- Billing and invoicing information
- Account and customer reference information
- Communications with us
- Support requests and ticket information
- Device names and identifiers
- Usernames and account information
- System, security and audit logs
- Microsoft 365, Azure, Entra ID and Intune information where required to provide our services
- Technical information about devices, applications and systems
- Information provided to us during projects, migrations or support activities
We only collect information that is reasonably required for our business activities or to provide services to our customers.
3. How we obtain personal information
We may obtain information:
- Directly from you
- From your employer or organisation
- Through our website and contact forms
- Through email, telephone or support requests
- During the delivery of IT projects and managed services
- Through systems we manage on behalf of customers
- Through Microsoft cloud services and administration portals
- From suppliers, distributors and other technology partners
- From monitoring, security and management tools used to provide our services
4. Why we use personal information
We may process personal information to:
- Provide IT support and managed services
- Supply and manage Microsoft licences and subscriptions
- Administer Microsoft 365 and Azure environments
- Manage user accounts, devices and access
- Investigate and resolve technical problems
- Monitor the availability and security of managed systems
- Manage cybersecurity incidents
- Perform migrations and IT projects
- Maintain customer and supplier relationships
- Respond to enquiries
- Provide quotations and proposals
- Process orders, invoices and payments
- Maintain financial and accounting records
- Meet contractual obligations
- Meet legal and regulatory requirements
- Protect our systems, customers and business
- Maintain appropriate business and security records
We do not use personal information for purposes that are incompatible with the reason it was originally collected unless permitted or required by law.
5. Our lawful basis for processing
Under UK GDPR, we must have a lawful basis for processing personal information.
Depending on the circumstances, we may rely on:
Contract – where processing is necessary to provide services under a contract or to take steps before entering into a contract.
Legitimate interests – where processing is necessary for our legitimate business activities, such as providing support, maintaining security, managing customer relationships and operating our business, provided those interests do not override individuals' rights.
Legal obligation – where we are required to process or retain information to comply with the law.
Consent – where we specifically ask an individual for permission to process their information for a particular purpose.
Where we process special category personal data, we will ensure that an appropriate additional condition under data protection legislation applies.
6. Managed IT services and customer data
As an MSP and CSP, we may have administrative or technical access to systems containing personal information belonging to our customers.
For example, our authorised personnel may access customer Microsoft 365, Azure, Entra ID, Intune, devices, servers or other systems while providing support.
In many of these circumstances, the customer is the data controller and we act as a data processor on the customer's behalf.
We only access and process customer data where required to provide the agreed services and in accordance with our contractual obligations and the customer's instructions.
Access to customer systems is restricted to authorised personnel and appropriate technical and organisational security measures are used to protect customer information.
7. Microsoft cloud services
We make extensive use of Microsoft products and cloud services in operating our business and delivering services to customers.
These may include:
- Microsoft 365
- Exchange Online
- SharePoint Online
- OneDrive
- Microsoft Teams
- Microsoft Azure
- Microsoft Entra ID
- Microsoft Intune
- Microsoft Defender
Personal information may therefore be processed or stored within Microsoft services.
Microsoft may act as a data processor or subprocessor depending on the service and circumstances. Microsoft's own contractual and data protection terms apply to its processing of information.
8. Sharing personal information
We do not sell personal information.
We may share information with third parties where this is necessary to operate our business or provide services.
These may include:
- Microsoft
- IT distributors and cloud service providers
- Software and technology vendors
- Backup and cybersecurity providers
- Professional advisers
- Accountants
- Payment providers and banks
- Service providers acting on our behalf
- Government, regulatory or law enforcement bodies where legally required
Where a third party processes personal information on our behalf, we take appropriate steps to ensure suitable contractual and data protection arrangements are in place.
9. International data transfers
Some technology and cloud service providers may process information outside the United Kingdom.
Where personal information is transferred internationally, we take reasonable steps to ensure that appropriate safeguards required by UK data protection legislation are in place.
These may include UK adequacy regulations, approved contractual safeguards or other legally recognised transfer mechanisms.
10. How we protect information
We use appropriate technical and organisational security measures to protect personal information.
Depending on the information and systems involved, these may include:
- Multi-factor authentication
- Access controls
- Role-based permissions
- Encryption
- Secure Microsoft cloud services
- Endpoint security
- Security monitoring
- Patch and vulnerability management
- Backups
- Logging and auditing
- Security policies and procedures
- Staff security awareness
- Restricted administrative access
Access to personal information is limited according to business requirements and the principle of least privilege.
11. How long we keep information
We only retain personal information for as long as it is reasonably required for the purpose for which it was collected or where we have a legal, regulatory or contractual requirement to retain it.
Different types of information may have different retention periods.
We periodically review the information we hold and securely delete or dispose of information when it is no longer required.
12. Your data protection rights
Depending on the circumstances, UK data protection law provides individuals with rights over their personal information.
These may include the right to:
- Request access to personal information we hold about you
- Request correction of inaccurate information
- Request deletion of information
- Request restriction of processing
- Object to certain processing
- Request transfer of your information
- Withdraw consent where processing is based on consent
Not all rights apply in every circumstance.
To exercise your rights, contact us using the details provided in this Privacy Notice.
Where we process information solely on behalf of one of our customers, we may need to refer your request to that customer because they are the data controller.
13. Marketing
Where we send electronic marketing communications, we do so in accordance with applicable data protection and electronic communications requirements.
You can ask us to stop sending marketing communications at any time by using the unsubscribe option provided or contacting us directly.
14. Cookies and website information
Our website may use cookies and similar technologies for essential functionality, security, preferences and, where applicable, analytics.
Where consent is legally required for non-essential cookies, we will request consent before those cookies are used.
Further information may be provided in our Cookie Policy.
15. Data breaches
We maintain procedures for identifying, investigating and responding to personal data breaches.
Where a breach creates a risk to individuals' rights and freedoms, we will assess whether notification to the Information Commissioner's Office (ICO) is required.
Where legally required, affected individuals will also be informed.
Where an incident involves information that we process on behalf of a customer, we will notify and assist the relevant customer in accordance with our contractual and legal obligations.
16. Complaints
If you have concerns about how we use your personal information, please contact us first so that we can investigate the matter.
Email: [email protected]
You also have the right to raise a complaint with the Information Commissioner's Office (ICO), the UK's data protection supervisory authority.
Information about making a complaint is available from the ICO at www.ico.org.uk.
17. Changes to this Privacy Notice
We review this Privacy Notice at least annually and whenever there are significant changes to our business, services, systems or processing activities.
Any updated version will be published on our website with the date of the latest revision shown at the top of the notice.
Last Review: 14 August 2026
Next Review: August 2027
