Privacy policy

At Siarp we are committed to protecting and respecting your privacy.

This privacy policy explains how we use any personal information we collect, the conditions under which we may disclose it to others, and how we keep it secure. This information may relate to customers, suppliers, business contacts and employees.

Who we are

Siarp is an IT company providing strategic IT advice, cybersecurity and IT support services, as well as managed services covering cybersecurity, cloud tools such as Microsoft 365 and Google Workspace, and general IT infrastructure for small and medium sized businesses.

Your information

We may use your information to:

  • carry out our obligations arising from any contracts entered into by you and us
  • seek your views or comments on the services we provide
  • notify you of changes to our services
  • notify you of software and licence updates
  • process a job application
  • comply with legal or regulatory requirements
  • send you communications which you have consented to or which are of legitimate interest, such as information about similar products and services we provide, our latest campaigns or upcoming events

Even if you have consented to receive marketing, you may opt out later. You have the right to stop us from contacting you for marketing purposes at any time. All marketing communications will contain details of how to opt out.

Information that we hold

This information may include name, job title, email address, company details, landline number and mobile number, to enable us to carry out our obligations arising from any contracts entered into between us. We may also collect personal data from customers, or from a third party acting on the customer’s instructions.

Marketing

From time to time we would like to stay in touch with business contacts about similar products and services which are of legitimate interest. Where we collect your details as a business contact, we may contact you by post, email, telephone or social media (such as LinkedIn) about our services and marketing material on the basis of legitimate interest.

We will not use your personal information to send you promotional information about third parties.

You have the right to stop us from contacting you for marketing purposes at any time, whether we are relying on legitimate interest or your consent. All marketing communications will contain details of how to opt out. Please email hello@siarp.uk.

Who we share your data with, and why

We will not share your information with third parties for marketing purposes.

To deliver our services, we work with a number of trusted software and technology providers. Personal information may pass through these platforms where it’s necessary to support, secure or manage your IT systems. We have appropriate agreements in place with each of them covering how your data is handled.

Companies we use include:

  • Pax8 – our software and cloud services marketplace, used for licensing and billing of Microsoft 365 and other cloud subscriptions.
  • Kaseya (including Datto RMM and Autotask) – our remote monitoring, management and ticketing platforms, used to support, monitor and secure your IT systems.
  • Microsoft – provider of Microsoft 365 and related cloud services used by many of our clients.
  • Google – provider of Google Workspace and related cloud services used by some of our clients.
  • Anthropic – provider of Claude, an AI assistant we may use internally to help draft communications, documentation and support our own work. We do not input client personal data into AI tools without appropriate safeguards in place.
  • Sophos – our cybersecurity and endpoint protection software provider.
  • Capsule CRM – our customer relationship management system, used to store contact and account details for our clients.
  • MailerLite – our email marketing platform, used to send newsletters and marketing communications to those who have not opted out.

We will not share your personal information with third parties, except where we are legally permitted. This may include:

  • trusted third parties such as sub-contractors, for specialist advice or other services related to our services to you
  • HMRC, law enforcement or other government and regulatory agencies, or other third parties, where this is required by law
  • our IT hardware and software application providers, solely for the purposes of testing, diagnosing and resolving hardware or software issues. Data will be transported via secure means, and we will have a data sharing agreement in place with the provider that ensures your data remains confidential

Lawful basis for processing

We process personal data under one or more of the following lawful bases:

  • Performance of a contract
  • Compliance with a legal obligation
  • Legitimate interests
  • Consent, where required

International data transfers

Some of the companies we use, including Microsoft, Google and Anthropic, are based in or operate servers in the United States and other countries outside the UK. Where your personal data is transferred outside the UK, we make sure appropriate safeguards are in place, such as Standard Contractual Clauses, the UK International Data Transfer Addendum, or a recognised adequacy decision, so that your data continues to receive a level of protection equivalent to that under UK data protection law.

Artificial Intelligence (AI) and productivity tools

We use AI powered tools, including Claude from Anthropic and Microsoft Copilot, to help with tasks such as drafting communications, documentation, and other internal work. These tools help us work more efficiently, but we take care over what information is shared with them.

We do not input sensitive personal data, client confidential information, or special category data into AI tools without appropriate safeguards and agreements in place. Where AI tools are used as part of the services we deliver to you, this will always be subject to the same data protection and confidentiality standards set out in this policy and in our contract with you.

Automated decision making

We do not use solely automated decision making which produces legal or similarly significant effects on individuals. Where AI assisted technologies are used, meaningful human oversight remains in place.

Use of ‘cookies’

Like many other websites, the Siarp website uses cookies. Cookies are small pieces of information sent by an organisation to your computer and stored on your hard drive, allowing that website to recognise you when you visit. They collect statistical data about your browsing actions and patterns and do not identify you as an individual. This helps us improve our website and deliver a better, more personalised experience.

You can choose to accept or decline cookies. Most web browsers automatically accept cookies, but you can usually modify your browser settings to decline cookies if you prefer. This may prevent you from taking full advantage of our website.

Keeping your data secure

As a cybersecurity company, we take the security of your personal information seriously. We use appropriate technical and organisational measures to protect your data, including encryption, access controls, staff training and regular review of our systems and processes. Access to personal data is limited to those who need it to do their job.

Your rights

You have a number of rights over the personal information we hold about you. These include the right to:

  • request a copy of the information we hold about you (access)
  • ask us to correct information that is inaccurate or incomplete
  • ask us to delete your information in certain circumstances (erasure)
  • ask us to restrict how we use your information in certain circumstances
  • ask us to provide your information in a portable format, where relevant
  • object to us processing your information, including for marketing purposes

If you would like to exercise any of these rights, please email hello@siarp.uk.

We want to make sure that your personal information is accurate and up to date. You may ask us to correct or remove information you think is inaccurate.

If you are unhappy with how we have handled your personal information, you also have the right to complain to the Information Commissioner’s Office (ICO), the UK’s data protection regulator. You can find out more at ico.org.uk or by calling 0303 123 1113.

Retention of data

Your data will be retained for a period of up to 6 years from the date of your last interaction with us.

Changes to our Privacy Policy

We keep our privacy policy under regular review, and we will place any updates on our website. This privacy policy was last updated in August 2026.

Any questions?

Any questions regarding this policy and our privacy practices should be sent by email to hello@siarp.uk, or by writing to Office 19, Towyside Sales Rooms, Old Station Road, Carmarthen, SA31 1JN

Data Controller

The Data Controller is Siarp Limited, company registration number: 12429544.