Privacy Notice
How UK Dedicated Servers Ltd collects, uses and protects personal data in the course of providing IP Transit and related connectivity services.
E1Who We Are
UK Dedicated Servers Ltd (registered in England and Wales under company number 05291070, registered office: Continuity House, 205 Torrington Avenue, Coventry, England, CV4 9AP) is the controller of personal data described in this Privacy Notice. References in this Notice to "we", "us" and "our" are to that company.
Our Data Protection Officer (where appointed) or privacy contact can be reached at dpo@transitx.net.
E2Scope
This Privacy Notice describes how we collect and use personal data in the course of providing IP Transit and related connectivity services to our customers (whether business or consumer). Where we provide services to a business customer, it does not describe how that customer in turn processes personal data of its own end users - for that, you should refer to your own provider's privacy notice.
E3Personal Data We Process
In the course of providing the Services, we may process the following categories of personal data:
- Business contact data: names, business email addresses, telephone numbers and job titles of customer personnel and authorised contacts.
- Account and billing data: company name, billing address, VAT number, purchase order references, signatory details.
- Technical operational data: IP addresses assigned to the customer, ASN, IRR/RPKI references, port and circuit identifiers, MAC addresses of customer-facing equipment, and authentication credentials issued for portal or NETCONF access.
- Traffic and signalling data: source and destination IP addresses, transport-layer port numbers, BGP routing announcements, NetFlow/sFlow records, and similar data generated by the operation of the network.
- Communications data with us: records of correspondence, support tickets, recorded calls (where lawful and notified), and webhook/notification logs.
- Site access data: where our personnel attend customer or co-location sites, names and signatures of attendees.
- Marketing data: where applicable, contact preferences and engagement metrics for our business marketing.
E4Source of Personal Data
We collect personal data directly from the customer (for example, on signing an Order Form), from authorised users of our portal, from publicly available registries (such as RIPE, RPKI repositories and Companies House), and from automated network telemetry generated by the Services.
E5Lawful Bases for Processing
We rely on the following lawful bases under Article 6 of the UK GDPR:
- Performance of a contract (Article 6(1)(b)) - to deliver, operate, support and bill the Services.
- Compliance with a legal obligation (Article 6(1)(c)) - to comply with retention, interception, disclosure and other obligations under English law.
- Legitimate interests (Article 6(1)(f)) - for network security and abuse prevention, fraud prevention, internal management reporting, and (where lawful) direct marketing to existing business customers, in each case where our interests are not overridden by the rights and freedoms of the data subjects.
- Consent (Article 6(1)(a)) - for any optional marketing or cookies on our website that require consent under PECR.
E6Purposes
We use personal data for the following purposes:
- to set up, configure, deliver, operate and maintain the Services;
- to communicate with the customer about the Services, including incident notifications, maintenance windows, and service updates;
- to issue invoices and collect payment;
- to monitor, manage and secure our network, prevent and detect fraud, abuse and unauthorised use, and to investigate suspected breaches of our AUP;
- to comply with applicable laws and regulatory obligations, including responding to lawful requests from competent authorities;
- to manage our business, including training, quality assurance, and management reporting;
- to enforce or defend our legal rights; and
- with consent or other lawful basis where required, to send marketing communications about our products and services.
E7Recipients
We may share personal data with the following categories of recipient:
- our group companies, on a need-to-know basis;
- our suppliers and processors, including providers of co-location, fibre, dark fibre and wave services, hosting and SaaS providers, payment processors, professional advisers, and external auditors;
- our peering partners, transit providers, IXPs, and Regional Internet Registries (such as RIPE NCC) where necessary for the operation of internet routing and addressing;
- competent law-enforcement, regulatory and tax authorities where we are required or permitted to do so by law;
- a successor to all or part of our business in connection with a sale, merger or reorganisation; and
- with the customer's consent, any other party identified to the customer at the point of consent.
E8International Transfers
We are based in the United Kingdom and our primary infrastructure is in the UK and the European Union. Where personal data is transferred to a country outside the UK that has not been the subject of an adequacy decision under the UK GDPR, we put in place appropriate safeguards, typically the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another mechanism approved under Article 46 of the UK GDPR. The customer can request a copy of the safeguards in place by contacting us at the address in clause E1.
E9Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, including:
- Account, contract & billing records
- For the duration of the customer relationship and for six (6) years thereafter, for accounting and limitation-period purposes.
- Network operational logs
- Typically up to twelve (12) months, save where we are required to retain them for longer under the Investigatory Powers Act 2016 or other law.
- CCTV at offices & POPs
- Typically thirty (30) to ninety (90) days.
- Marketing data
- Until the data subject withdraws consent or objects to processing.
At the end of the applicable retention period, we delete or anonymise the personal data.
E10Your Rights
Subject to applicable law, individuals have the following rights in respect of their personal data:
- to be informed about how their personal data is used (which is the purpose of this Notice);
- to request access to, correction of, or erasure of, their personal data;
- to request restriction of, or to object to, certain processing;
- to data portability where applicable;
- to withdraw consent where processing is based on consent; and
- to lodge a complaint with the UK Information Commissioner's Office at ico.org.uk or by post at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
To exercise any of these rights, please contact us at [email protected]. We may need to verify the identity of the person making the request before responding.
E11Security
We maintain appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss, alteration or destruction, including access controls, network segmentation, encryption in transit, logging and monitoring, vetting of personnel, and a documented information security management framework. No security measure is perfect, however, and we cannot guarantee the security of any data transmitted to or from us over the public internet.
E12Changes to this Notice
We may update this Privacy Notice from time to time. The current version is published at transitx.net/legal. Where changes are material we will notify customers in advance by email.
Continuity House, 205 Torrington Avenue
Coventry, CV4 9AP
England & Wales