Home/Privacy Policy

Legal

Privacy policy

Last updated 13 August 2026.

Plain-English summary. We collect what we need to sell and deliver IT services, nothing else. We don't sell your data, we don't use your business data to train AI models, and you can ask us to delete it. Full detail below.

Who we are

PCR — Managed IT ("we", "us") provides managed IT and AI-powered support services. For enquiries about this policy or your data, contact [email protected].

What we collect

From website visitors: pages visited, referring source, approximate location derived from IP address, browser and device type. Used in aggregate to understand which content is useful.

From enquiries: name, work email, company, staff count and whatever you write in the message field.

From customers: contact details for authorised users; technical data about managed devices and tenants including configuration, security posture, patch state and licence assignment; support request content; and audit logs of actions taken on your systems.

What we do not do

  • We do not sell or rent personal data to anyone.
  • We do not use customer business data, tenant contents or support tickets to train AI models. Where AI processing is used in service delivery, it runs under a commercial agreement with zero data retention for training.
  • We do not access customer data beyond what is needed to deliver the contracted service.
  • We do not run advertising trackers or sell audience data.

Legal basis and purpose

We process personal data to perform our contract with you, to respond to enquiries you initiate, to meet legal and tax obligations, and for the legitimate interest of securing and improving our services. Where consent is required, we ask for it and you can withdraw it.

Sharing

We share data only with subprocessors necessary to deliver the service — cloud hosting, the Microsoft platform, monitoring and management tooling, and contracted on-site technicians where you have requested an on-site visit. All are bound by confidentiality and data-protection terms. A current subprocessor list is available on request. We disclose data to authorities only where legally compelled, and we will tell you unless prohibited from doing so.

Retention

Enquiry data is kept for 24 months unless you ask us to delete it sooner. Customer technical and support data is retained for the contract term plus 12 months, after which it is deleted. Financial records are kept for 7 years as required by law. Audit logs are retained for 24 months.

Security

Data is encrypted in transit and at rest. Access is role-based, logged and reviewed quarterly. Administrative access to customer environments uses scoped, least-privilege delegated permissions that the customer can revoke at any time. We will notify affected customers of any personal data breach without undue delay and within 72 hours of becoming aware of it.

Your rights

Depending on your jurisdiction you may have the right to access, correct, delete, restrict or object to processing of your personal data, to data portability, and to withdraw consent. Residents of the EEA and UK have these rights under GDPR; Canadian residents under PIPEDA; California residents under the CCPA/CPRA, including the right not to be discriminated against for exercising them. To exercise any right, email [email protected]. We respond within 30 days.

International transfers

We are based in North America and may process data in the United States, Canada and the European Union. Where data is transferred out of the EEA or UK we rely on Standard Contractual Clauses or an adequacy decision.

Cookies

This site uses only essential cookies required for it to function. We do not use advertising or cross-site tracking cookies. If we add analytics in future we will update this policy and request consent where required.

Changes

We will update the date at the top of this page when this policy changes, and notify customers directly of material changes.

From $29/user/monthMinimum 5 users · no bundled licences
See your price