Privacy, entry by entry
Two very different piles of personal data pass through this company: the modest one we keep for ourselves, and the large one that sits inside the estates we look after for other organisations. Rather than bury that distinction in numbered clauses, we have written the whole policy as an alphabetical handbook — look up the thing you care about and read one page-worth about it.
Twenty-nine entries. Each one is self-contained, so an entry that matters to you can be read on its own and sent to a colleague without the rest. Terms set out in a signed service agreement always beat anything written here.
- R
- Recipients · Retention · Rights
Access requestsAsking for a copy of the personal data we hold about you.
Write to info@tolvara.co and put Access request in the subject line. Name the organisation you deal with and, if you can, the rough period that interests you; a request pointed at a company and a date range is answered far quicker than one that asks for everything. We will ask for something that ties the address you wrote from to the person you say you are — not because we enjoy paperwork, but because handing an estate's records to the wrong reader would itself be a breach.
The clock runs one calendar month from the day we can identify you. A genuinely tangled request can stretch that to three months in total, and if it does, the reason reaches you inside the first month. There is no charge. Should someone repeat the same request so often that answering it becomes an operational burden, we would say so in writing and explain what we propose before any cost appeared.
If the material you want sits inside a customer's tenant rather than our own files, we route the request to that customer, tell you we have done it, and support them in answering. The entries at Processor role and End users explain why the answer has to come from them.
Automated decisionsSoftware reaching a conclusion about a person with nobody reading it.
None of that happens here. Tickets are sorted by priority and skill so the right engineer picks them up, and a person reads every ticket before anything is done to an account. Monitoring tools raise alerts on their own, but an alert is a prompt for a human being, never a verdict about one. Nothing we run scores, ranks or profiles individuals, and no decision with a legal or similarly significant effect on anyone is taken by machine. Were that ever to change, this entry would name the system, describe what it decides and set out how a person can challenge the outcome and reach a human reviewer.
BackupsCopies that go on existing after the original has been removed.
Backup and continuity work means we hold copies of customer material on a rolling schedule: typically thirty-five days of daily restore points for Microsoft 365 mailboxes and file shares, with longer horizons where a contract specifies them. A backup set is written once and expires on its own timetable. We do not go digging into sealed copies to excise single records, because doing so undermines the restore we are being paid to guarantee.
The practical consequence is worth stating plainly: when something is deleted at source, the copy inside the backup cycle carries on until that cycle ends. During that window it is isolated, encrypted and untouched except for a restore. Quarterly test restores run into a scratch location, and whatever was extracted is destroyed once the test is signed off.
BreachesAny incident where personal data is lost, exposed, altered or reached by the wrong hands.
Ours. Containment comes first, assessment within hours, and a director owns both. Where the risk to the people involved is more than remote, the ICO hears from us inside seventy-two hours of the moment we became aware; if that window is ever missed, the report carries the reason for the delay rather than a tidy silence. When the risk is high, we contact those affected directly, in ordinary words, with the one practical step they should take.
Yours. When the affected data lives in a customer estate, the customer is the controller and the decision to notify anyone is theirs alone. Our job is speed and evidence. The named contact hears from us without undue delay, and gets what we know as we know it: timeline, scope, systems touched, what we shut down, what we preserved. A live incident is worked under the P1 route, which is covered around the clock.
Records. Every incident is written up whether or not it turns out to be reportable, together with the assessment that led to the decision. Those write-ups are how the next one gets caught faster.
ChildrenData about people under eighteen, which our services are not designed to gather.
Tolvara contracts with organisations, not with families, and nothing we sell is aimed at a child. We do not knowingly collect data about anyone under eighteen through this website or through our commercial activity, and no child is invited to correspond with us.
Customer estates are a different matter. A school, a charity running youth work or a clinic will hold records about children, and an engineer restoring a file share or repairing a mailbox can pass close to them. Those environments are treated as sensitive from the outset: narrower access lists, named engineers instead of the general rota, and a standing rule that nothing is opened beyond what the ticket requires. Should material about a child ever reach us by mistake — a stray attachment, a misdirected export — we tell the customer, quarantine the copy and destroy it once they confirm they have what they need.
ComplaintsWhat to do when our handling of your data is not good enough.
Start with us. Mail info@tolvara.co with Data complaint in the subject and a description of what went wrong. A director owns the answer; it does not sit in the service desk queue behind ticket volume. What comes back is written and says three things: what we found, what we have changed, and anything we could not change with the reason.
You are not obliged to argue with us first. The UK regulator takes complaints directly, at any stage, and doing so costs you nothing and changes nothing about any contract you hold with us.
| Route | Detail |
|---|---|
| Regulator | Information Commissioner’s Office — the ICO |
| Post | the ICO, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF |
| Telephone | 0303 123 1113 |
| Online | ico.org.uk |
ControllerWhoever decides why personal data gets processed. For our own records, that is us.
TOLVARA LIMITED, company number NI739585 on the Northern Ireland register, is the controller for the material described under Correspondence, Job applicants, Suppliers and Visitors to this website. Everything reaches us at info@tolvara.co; formal notices can be posted to the office held against NI739585 at Companies House.
Responsibility rests with a named director rather than a statutory data protection officer. Article 37 reserves that appointment for public authorities and for organisations whose core work is large-scale monitoring of people or large-scale handling of the Article 9 categories, and running business IT for a modest roster of corporate customers is neither of those things. Post or email marked for the Data Protection Lead arrives with that director.
We pay the data protection fee to the ICO wherever the Charges Regulations require it and keep that up while the requirement lasts. Ask and we will give you the entry as it stands on the public register.
CorrespondenceEmail, tickets, session notes and meeting records — most of what we hold in our own right.
An enquiry hands us a name, a work address, whatever you chose to type and the mail headers behind it. A live engagement adds ticket history, remote session notes, change approvals, invoices and the occasional decision minuted at a service review. We keep that material because a managed IT relationship stays argument-free only when there is a record of who asked for the firewall change, who approved the licence spend, and which engineer restored what at what hour.
The basis is contract for customer contacts and legitimate interests for enquirers and for the general upkeep of an account — see Lawful bases. None of it is sold, and nobody outside the suppliers listed under Recipients receives it for purposes of their own.
DeletionGetting rid of things: ours, yours, and the copies in between.
Ask for deletion of data we hold about you as controller and we will carry it out, unless a legal duty, a live dispute or an unexpired accounting obligation says otherwise — in which case you will be told which of those applies and when it lapses. Requests go to info@tolvara.co and follow the same identification and timing rules as Access requests.
At the end of an engagement the exit plan governs. Documentation, registers and runbooks are handed back in a form you can actually use; our working copies then come out of tooling, vaults and documentation platforms on the agreed schedule, normally within thirty days of final handover, and we confirm in writing when it is finished. Administrative accounts we hold inside your tenant are disabled first so the estate keeps working, then removed by you. What outlives everything else is the accounting trail and anything a regulator or a live claim obliges us to preserve; Retention sets out the periods. Sealed backup copies are the one honest exception, and Backups explains why.
DevicesLaptops, phones and servers managed on a customer's behalf.
Intune and its equivalents give us a management view of an enrolled device: model, serial, operating system build, patch level, disk encryption state, installed applications, compliance verdict and the account the device belongs to. That is an inventory, not a surveillance feed. We do not read personal files, capture keystrokes or follow anybody's location, and a remote session opens by invitation, announces itself on screen and is logged against a ticket with the engineer's name on it.
Where a customer wants something more intrusive than that, the decision is theirs as controller, it belongs in the notice they give their own staff, and we implement it only on written instruction. If we think that notice is missing, we will say so before the switch is thrown.
End usersPeople whose employer engaged us, and whose mailbox or laptop we therefore touch.
If you work at one of our customers, we hold data about you because your employer asked us to run the systems you use. Your employer is the controller. Retention settings, mailbox policies, monitoring choices and the scope of our access are all theirs, which means they can answer your question faster and with the authority to act on it. Ask them first.
Come to us instead and you will not be ignored. We will tell your employer's named contact that a request has arrived, help them put together an answer, and confirm to you that the handover happened. What we will not do is release the contents of a mailbox, a file share or a device to anyone other than the organisation that owns the tenant — including to the person the data is about, whose route runs through their employer.
EscalationThe route to use when the ordinary answer is not enough.
Data protection questions do not queue behind ticket volume. Mail info@tolvara.co with Data Protection Lead in the subject and it lands with a director on the same working day. Anything live and damaging goes through the P1 route written into the service agreement, which is covered day and night. The same address produces the current sub-processor list, the transfer paperwork behind a particular supplier, or a copy of whichever revision of this handbook was in force on a date that matters to you.
Job applicantsCVs, interview notes and references.
Applications are read by the people you would actually work alongside. We keep the application, our notes and any exercise you completed for six months after the decision, which is long enough to answer a question about how the process ran, and then it goes. If you would rather we held your CV for future roles, say so and we will — that is your consent, and one line of email withdraws it. References are taken after an offer and only with your agreement. Nothing from a recruitment round is used for marketing, and nothing about an unsuccessful application is shared outside the interview panel.
Keys and credentialsPasswords, administrative accounts, certificates and recovery codes.
Running other people's IT means holding the keys to their systems, so how we keep those keys is a privacy question as much as a security one. Secrets live in a dedicated vault with per-engineer accounts, multi-factor sign-in and an access log. They are never parked in tickets, spreadsheets, mailboxes or documentation pages. Administrative access is named rather than shared, privileged accounts are kept apart from everyday ones, and break-glass credentials are sealed so that any use is visible and reviewed afterwards.
When an engineer leaves us, the account and the vault access go the same day. When an engagement ends, the keys come back to you and ours are removed — see Deletion.
Lawful basesThe legal footing under each kind of processing we carry out as controller.
| What we process | Footing | Why that one |
|---|---|---|
| Enquiry correspondence | Legitimate interests | Somebody wrote to a business asking a question; replying is the obvious expectation on both sides. |
| Customer contact records | Contract | An agreement cannot be operated without knowing who approves changes and who signs off spend. |
| Tickets and change history | Contract, with legitimate interests | Evidence of what was asked, approved and done — the spine of the service. |
| Invoices and accounts | Legal obligation | Tax and company law fix both the content and the horizon. |
| Security and system logs | Legitimate interests | Estates stay standing because somebody keeps the evidence of how they behave. |
| Email to business contacts | Legitimate interests | Sent to organisations we serve or have quoted for, with the electronic marketing rules honoured. |
| Applicant records | Legitimate interests; consent to hold longer | Hiring needs a record; keeping a CV on file afterwards is your choice, not ours. |
Where legitimate interests carry the weight, the balancing exercise is written down and we will show you the reasoning behind any entry above. Consent, on the rare occasions we lean on it, is asked for separately from anything else and is as easy to take back as it was to give.
MarketingEmail that nobody is obliged to receive.
We write to people who asked us to, and to business contacts at organisations we already serve or have quoted for. Every message carries a working unsubscribe that takes one click and is honoured in days rather than weeks. Lists are never bought, rented, swapped or fattened up with data bought from brokers, and there is no advertising machinery here for anything to be fed into.
Service messages are a different animal and continue regardless of marketing preferences: maintenance windows, incident notices, renewal dates, invoices and anything else the contract obliges us to tell you.
MonitoringAgents, alerts and telemetry from the estates we run.
Managed support puts monitoring agents on servers, endpoints and network gear. What they report is machine fact: uptime, disk headroom, patch state, service health, security events, and the account tied to an event where that is what makes the alert mean anything. Alert history is kept for twelve months so that a pattern is visible across a full year of seasonal load; ticket records follow the horizons under Retention.
The purpose is an estate that stays up, not a picture of anybody's working day, and nobody here is asked to build one. If a customer wants activity reporting on their own staff, that is their decision as controller, taken under their own notice, and it is instructed in writing before we configure anything.
Onboarding auditsThe discovery fortnight, when everything an estate contains gets written down.
A new engagement opens with an audit: identities, licences, devices, servers, backup jobs, network layout, supplier contracts and the risks nobody ever documented. The output is an asset register, a network map and a set of runbooks, all held under the customer's own space and all theirs to take away.
Personal data turns up in that work mainly as account names, mailbox lists, group memberships and licence assignments. We take the least that still describes the estate accurately — a licence report rather than a mailbox export, a folder tree rather than the documents inside it. Where discovery genuinely needs to look at content, it is agreed with the customer first and recorded on the ticket.
Processor roleThe larger half of what we do, where the data is not ours to decide about.
For everything inside a customer estate, the customer is the controller and Tolvara is the processor. That relationship lives in a data processing schedule inside the service agreement, and where the schedule and this handbook disagree about work carried out for a customer, the schedule prevails.
In daily practice it means we act on documented instruction and flag an instruction that looks unlawful before following it; our engineers are bound by confidentiality that outlasts their employment; the measures under Security apply; we help with rights requests, impact assessments and regulator correspondence; we return or destroy material at the end according to the customer's choice; and we submit to audit on reasonable notice.
Sub-processors are appointed only with the customer's agreement and only under written terms equivalent to our own, and their failures remain our responsibility. The current list travels by email on request, and any addition is notified before it takes effect, with room to object.
RecipientsWho else can see this material, and on what footing.
Categories rather than a scattering of logos, because the logos change and the categories do not. The platform vendors whose services we administer on your behalf already hold the data by definition. A small number of operational suppliers sit behind our own work: hosting, backup, documentation, ticketing and mail. Our accountants see invoices. Professional advisers and insurers would see relevant material if a dispute ever demanded it. Public bodies see what the law compels us to hand over, and nothing more than that.
Every one of those suppliers works under a written contract carrying confidentiality and security terms, and none of them may use what they see for their own ends. Nobody buys data from us, and no revenue here depends on anybody's attention.
RetentionHow long each kind of record survives, and what happens at the end.
| Record | Held for | Then |
|---|---|---|
| Enquiry that goes nowhere | 12 months | Deleted from the mailbox and its archive |
| Customer contact and account records | Contract + 6 years | Deleted after the limitation window closes |
| Tickets, changes, session notes | 3 years | Deleted, counting from closure or contract end, whichever falls later |
| Invoices and accounting records | 6 years | Archived after the financial year they belong to, then destroyed |
| Monitoring alerts and system logs | 12 months | Rolled over automatically |
| Security logs on an open incident | Until closure | Kept while any claim window remains open, then destroyed |
| Backup sets | Contracted cycle | Expire on their own schedule, typically after 35 days |
| Applicant records | 6 months | Deleted, unless you asked us to keep the CV on file |
| Incident write-ups | 6 years | Retained as evidence of the assessment we made |
Inside a customer estate, the customer's own retention policy governs their data and ours applies only to the working copies we make in order to do the job. Where the two ever collide, theirs wins and we adjust.
RightsWhat UK data protection law lets you require of us.
- A copy of the personal data we hold about you — see Access requests.
- Correction of anything inaccurate, and completion of anything half-recorded.
- Erasure, where nothing gives us a continuing reason to keep it.
- A pause on processing while an argument about accuracy or footing is settled.
- Portability — the data you gave us, handed back as a file another supplier's system can read.
- Objection, where legitimate interests were our footing; for marketing that objection is absolute and takes effect at once.
- Withdrawal of consent, where consent was what we relied on, without affecting what was lawful beforehand.
- The regulator, at any point — see Complaints.
Rights over material held inside a customer estate are exercised through that customer, since they decide and we merely operate. We support them in answering; we do not answer over their heads. Every request we receive in our own right is logged, answered in writing, and revisited if you tell us the answer missed the point.
SecurityThe measures sitting underneath every entry above.
Multi-factor authentication guards every account capable of reaching a customer system. Access is granted by role, scoped to the engagement, and reviewed whenever people or contracts change. Traffic is encrypted in transit throughout, and data at rest is encrypted on laptops, servers and backup targets alike. We hold ourselves to the same patching discipline we contract to give our customers, keep administrative accounts segregated from ordinary ones, centralise logging with alerting on top, and test restores of our own systems as well as yours.
Engineers are background-checked in proportion to the access they hold, trained on the handling rules in this handbook, and reviewed after every incident and near-miss. Security here is a working habit reinforced at each service review, not a document written once and filed.
Special categoriesHealth, beliefs, union membership, biometrics and the rest of Article 9.
We neither seek this material nor build services that need it. Our own records hold almost none, the exception being sickness and accessibility information that comes with employing people, which a single director handles.
Customer estates are another story: an HR system, a clinic or a charity will hold plenty of it, and an engineer restoring a mailbox may pass close by. The rules there belong to the customer. We apply least-privilege access, work strictly to the task written on the ticket, and never extract, copy or examine such material outside it. Records about criminal offences and proceedings are treated on exactly the same footing.
SuppliersContact records for the businesses we buy from.
Names, work addresses, telephone numbers and the correspondence that comes with buying services. The footing is contract or legitimate interests, the horizon follows the accounting trail under Retention, and nothing about a supplier contact is used for anything except running that relationship.
Transfers out of the UKWhat happens when data leaves the country.
Our own working data stays in the United Kingdom and the European Economic Area wherever the choice belongs to us, and customer platforms are configured for UK or EU regions whenever the tenant permits it. Some vendors nonetheless provide support from beyond that footprint, and that is an international transfer.
Where the destination is covered by UK adequacy regulations, that settles it. Where it is not, the contract carries the UK International Data Transfer Agreement, or the EU standard contractual clauses with the UK Addendum bolted on, together with a written assessment of the destination and, where the assessment warrants it, additional protection such as encryption whose keys stay on our side. Ask about a particular supplier and we will tell you which of those routes it sits on.
Updates to this handbookHow the text changes, and how you find out.
The revision line under the title moves whenever the words do. Small corrections happen quietly. A change to why or how we process anything is emailed to customer contacts before it takes effect, with enough notice to raise an objection. An update is never used to bolt a new purpose onto old data retrospectively: a new purpose needs its own footing, and where that footing would be consent, its own request. Superseded revisions are kept, and whichever one was in force on a date that matters to you is available by email.
Visitors to this websiteWhat tolvara.co learns about you, which is very little.
The site is static: pages, one stylesheet, a small script that opens the navigation drawer, and images. Nothing is stored on your device, there is no analytics package, no advertising pixel and no third-party tracker, which is why no consent banner appears in front of the content.
Our host writes the ordinary server log line — address, timestamp, path, response code, browser string — and keeps it briefly for security and traffic diagnosis. It is never joined to anything else and never used to build a profile. The three typeface families this site sets its text in come from Google's font service as a page loads: Google serves the stylesheet from fonts.googleapis.com, while the font files themselves arrive from fonts.gstatic.com, so your address and browser details are visible to Google at that moment. The cookie handbook goes through this in more detail.
Written instructionsThe rule that keeps a processor honest.
Anything unusual that touches customer data — a mailbox export, a device wipe, an activity report on named staff, a restore into a different tenant, disclosure to a third party — happens on a documented instruction from someone the customer has authorised, and it is recorded against a ticket. Verbal requests in the middle of an incident are honoured when the situation demands it and confirmed in writing afterwards, same day.
Two things this discipline buys you. The customer always has an audit trail of what was asked and by whom. And an instruction that looks unlawful gets challenged before it is carried out rather than explained afterwards, which is the whole point of writing it down.
↑ Back to the A–Z index