BALLANTINE TECHNOLOGY
BALLANTINE TECHNOLOGY
Privacy & Device Data Handling Policy
Privacy & Device Data Handling Policy
For device diagnostics, repair, rebuild, deployment and data sanitisation services.
For device diagnostics, repair, rebuild, deployment and data sanitisation services.
Last Updated: 10/08/2026
TABLE OF CONTENTS
1. Who We Are 2. Information We May Handle 3. Minimum Access Principle 4. Why Personal Information Is Used 5. Sensitive Information 6. Passwords, PINs and Recovery Keys 7. Backups and Temporary Copies 8. Data Sanitisation 9. Malware and Security Findings 10. Proof-of-Work Evidence 11. Marketing Use 12. Business Devices 13. Data Processing Agreements 14. Sharing Information 15. International Transfers 16. Retention 17. Security 18. Personal Data Breaches 19. Data Protection Rights 20. Privacy Complaints 21. Changes 22. Contact
YOUR DEVICE. YOUR DATA.
POSSESSION OF YOUR DEVICE DOES NOT MEAN PERMISSION TO BROWSE YOUR PERSONAL FILES. A device may contain private documents, photographs, messages, browser information, accounts, business files and other personal information. Ballantine Technology aims to access only what is reasonably necessary to diagnose, repair, test, sanitise or verify agreed work. Testing without opening personal files is preferred; files are not intentionally inspected out of curiosity or unrelated purposes.
1. WHO WE ARE — Ballantine Technology is an independent UK IT consultancy and device services provider. For personal customers it generally acts as controller for account, booking, payment and service-administration information. When a business instructs handling of personal information on its devices, Ballantine Technology may instead act as processor for that device data. Privacy contact: info@ballantinetechnology.co.uk. Website: ballantinetechnology.co.uk.
2. INFORMATION WE MAY HANDLE — Contact information: name, email, telephone, service address and booking notes. Job/device information: job reference, manufacturer, model, serial/service tag, storage-device information, operating system and reported fault. Service information: quotes, approvals, invoices, payment status, correspondence, QA records and completion reports. Technical information: hardware, operating system, driver and update status, logs, error messages and malware/security findings. Limited proof-of-work screenshots/photos may be used where necessary. Credentials or recovery information are handled only where genuinely necessary and specifically provided. Personal information already on a device may be encountered incidentally during agreed work.
4–10. USE, SENSITIVE INFORMATION, SECRETS, BACKUPS, SANITISATION, SECURITY AND EVIDENCE — Information may be used for booking, communication, service delivery, diagnostics, rebuilding, sanitisation, billing, security, fraud prevention, disputes, legal obligations and lawful marketing; different lawful bases may apply. Special-category information is not normally requested, but may exist incidentally and should be avoided unless necessary and lawful. Passwords, PINs and recovery keys should not appear in general booking notes; required credentials are used only for agreed work, excluded from evidence and deleted when no longer needed; customers may be advised to change temporary passwords. Customers remain responsible for backups unless agreed otherwise. Necessary temporary copies are limited, protected and normally deleted within 30 days after completion/return unless another period is agreed or legally required. Destructive sanitisation requires authorisation; records may retain identification, method and verification rather than erased files. Malware/security findings may be documented and reported; unrelated private information is not intentionally inspected. Evidence is limited, may be cropped/redacted, and should not intentionally capture passwords, recovery keys, private files/messages or unrelated data.
1. WHO WE ARE — Ballantine Technology is an independent UK IT consultancy and device services provider. For personal customers it generally acts as controller for account, booking, payment and service-administration information. When a business instructs handling of personal information on its devices, Ballantine Technology may instead act as processor for that device data. Privacy contact: info@ballantinetechnology.co.uk. Website: ballantinetechnology.co.uk.
2. INFORMATION WE MAY HANDLE — Contact information: name, email, telephone, service address and booking notes. Job/device information: job reference, manufacturer, model, serial/service tag, storage-device information, operating system and reported fault. Service information: quotes, approvals, invoices, payment status, correspondence, QA records and completion reports. Technical information: hardware, operating system, driver and update status, logs, error messages and malware/security findings. Limited proof-of-work screenshots/photos may be used where necessary. Credentials or recovery information are handled only where genuinely necessary and specifically provided. Personal information already on a device may be encountered incidentally during agreed work.
4–10. USE, SENSITIVE INFORMATION, SECRETS, BACKUPS, SANITISATION, SECURITY AND EVIDENCE — Information may be used for booking, communication, service delivery, diagnostics, rebuilding, sanitisation, billing, security, fraud prevention, disputes, legal obligations and lawful marketing; different lawful bases may apply. Special-category information is not normally requested, but may exist incidentally and should be avoided unless necessary and lawful. Passwords, PINs and recovery keys should not appear in general booking notes; required credentials are used only for agreed work, excluded from evidence and deleted when no longer needed; customers may be advised to change temporary passwords. Customers remain responsible for backups unless agreed otherwise. Necessary temporary copies are limited, protected and normally deleted within 30 days after completion/return unless another period is agreed or legally required. Destructive sanitisation requires authorisation; records may retain identification, method and verification rather than erased files. Malware/security findings may be documented and reported; unrelated private information is not intentionally inspected. Evidence is limited, may be cropped/redacted, and should not intentionally capture passwords, recovery keys, private files/messages or unrelated data.
11–15. MARKETING, BUSINESS, SHARING AND TRANSFERS — Proof of work is not automatic permission to use customer information for marketing. Appropriate permission is required before publishing identifiable customer, device or customer-specific evidence. Business customers may remain controllers, with Ballantine Technology acting as processor where it processes solely on their behalf; special handling, confidentiality, chain-of-custody, security and retention requirements should be disclosed before shipment. Appropriate controller/processor terms may be needed; this policy does not replace every data-processing agreement. Customer information is not sold. Limited sharing may occur with operational providers such as payment, email/cloud, booking, accounting, courier or professional advisers, or where legally required. Providers may process outside the UK; lawful safeguards are used where required.
16. RETENTION — General enquiries not becoming jobs: normally up to 12 months. Booking, quotation, job, approval and completion records: normally up to 6 years after completion where reasonably required for accounting, contractual, warranty or legal-claim purposes. Invoices: retained according to applicable tax/accounting requirements. Temporary customer-device data: normally deleted within 30 days following completion/return unless otherwise agreed or legitimately required. Credentials/recovery information: deleted or securely disposed of when no longer required. Proof-of-work/QA evidence: only as long as reasonably necessary for service, warranty, dispute or compliance. Retention may vary for legal obligations, disputes or agreed requirements.
17–22. SECURITY, BREACHES, RIGHTS, COMPLAINTS, CHANGES AND CONTACT — Technical and organisational measures appropriate to the nature and risk may include access controls, account/device security, encryption where appropriate, updates, secure procedures, limited access and controlled deletion; no system is claimed completely secure. Suspected loss, unauthorised access, disclosure or compromise is assessed and documented. Where processor, the business customer is informed without undue delay where required; where controller, ICO/individual notification is assessed where legally required. Rights may include access, rectification, erasure, restriction, objection and portability, subject to conditions/exemptions; identity verification may be required. Contact info@ballantinetechnology.co.uk first; individuals may also complain to the Information Commissioner’s Office at ico.org.uk. The policy may be updated when services, systems, suppliers, laws or practices change. Contact Ballantine Technology at info@ballantinetechnology.co.uk or ballantinetechnology.co.uk. MINIMUM ACCESS. SECURE HANDLING. DOCUMENTED RESULTS. BUILT. TESTED. PROVEN.
11–15. MARKETING, BUSINESS, SHARING AND TRANSFERS — Proof of work is not automatic permission to use customer information for marketing. Appropriate permission is required before publishing identifiable customer, device or customer-specific evidence. Business customers may remain controllers, with Ballantine Technology acting as processor where it processes solely on their behalf; special handling, confidentiality, chain-of-custody, security and retention requirements should be disclosed before shipment. Appropriate controller/processor terms may be needed; this policy does not replace every data-processing agreement. Customer information is not sold. Limited sharing may occur with operational providers such as payment, email/cloud, booking, accounting, courier or professional advisers, or where legally required. Providers may process outside the UK; lawful safeguards are used where required.
16. RETENTION — General enquiries not becoming jobs: normally up to 12 months. Booking, quotation, job, approval and completion records: normally up to 6 years after completion where reasonably required for accounting, contractual, warranty or legal-claim purposes. Invoices: retained according to applicable tax/accounting requirements. Temporary customer-device data: normally deleted within 30 days following completion/return unless otherwise agreed or legitimately required. Credentials/recovery information: deleted or securely disposed of when no longer required. Proof-of-work/QA evidence: only as long as reasonably necessary for service, warranty, dispute or compliance. Retention may vary for legal obligations, disputes or agreed requirements.
17–22. SECURITY, BREACHES, RIGHTS, COMPLAINTS, CHANGES AND CONTACT — Technical and organisational measures appropriate to the nature and risk may include access controls, account/device security, encryption where appropriate, updates, secure procedures, limited access and controlled deletion; no system is claimed completely secure. Suspected loss, unauthorised access, disclosure or compromise is assessed and documented. Where processor, the business customer is informed without undue delay where required; where controller, ICO/individual notification is assessed where legally required. Rights may include access, rectification, erasure, restriction, objection and portability, subject to conditions/exemptions; identity verification may be required. Contact info@ballantinetechnology.co.uk first; individuals may also complain to the Information Commissioner’s Office at ico.org.uk. The policy may be updated when services, systems, suppliers, laws or practices change. Contact Ballantine Technology at info@ballantinetechnology.co.uk or ballantinetechnology.co.uk. MINIMUM ACCESS. SECURE HANDLING. DOCUMENTED RESULTS. BUILT. TESTED. PROVEN.