Legal

Privacy Policy

How CODE AND SYSTEMS LTD collects, uses, and protects your personal data in accordance with UK GDPR and the Data Protection Act 2018.

📅 Last updated: August 2026
Plain English summary: We only collect the data we need to provide our IT services and respond to your enquiries. We never sell your data. You have full control over your personal information and can request deletion at any time.

🏢
1. Who We Are

CODE AND SYSTEMS LTD (Company Registration No. 15973638) is registered in England and Wales. We are the data controller responsible for your personal information.

🏢
Company
CODE AND SYSTEMS LTD (No. 15973638)
📍
Address
Broxburn Drive, South Ockendon, Essex, RM15 5PP, United Kingdom

📋
2. Data We Collect

We collect personal data in the following circumstances:

When you contact us or submit an enquiry

  • Full name
  • Email address
  • Phone number (if provided)
  • Company name (if provided)
  • The content of your message or enquiry

When we provide IT support services

  • Name and job title
  • Business contact details
  • Technical information about your systems (only what is necessary to resolve your issue)
  • Remote access session logs

When you visit our website

  • IP address and browser type (via server logs)
  • Pages visited and time spent (anonymised analytics if enabled)

When you use our GateCore products (MFA, Firewall & mobile authenticator)

If you or your organisation use our GateCore security products, we process the following categories of data as necessary to provide the service:

  • Account information — username and email address
  • Authentication records — sign-in events, verification status, and timestamps
  • Device identifiers — a unique identifier assigned to your registered device
  • IP address and an approximate location (city and country) derived from it — shown to you when approving a sign-in request so you can recognise activity that isn't yours
  • Service and security logs — records generated to operate and protect the service

Where your employer or organisation provides you with access to GateCore, that organisation is the data controller and CODE AND SYSTEMS LTD acts as a data processor, processing data only on their documented instructions.

GateCore Authenticator mobile app (iOS & Android)

The mobile authenticator app works as follows:

  • Camera — used only to scan QR codes when you add an authenticator account. Images are processed entirely on your device, are never saved to your photo library, and are never uploaded to us or anyone else. The app asks for camera permission the first time you scan, and you can decline.
  • Codes stored on your device — your authenticator secrets are held in the operating system's secure storage (iOS Keychain / Android Keystore). Codes are generated on the device itself and are not sent to us in order to work.
  • Optional cloud sync — if you create an account and enable sync, a copy of your authenticator accounts is stored on our UK servers so you can restore them on a new phone. Data is transmitted over encrypted TLS connections, held on access-controlled servers, and is never shared with third parties or used for any purpose other than restoring your accounts. Sync is optional; the app works without an account, and if you never enable sync nothing leaves your device.
  • Signing in with Microsoft — if your organisation uses Microsoft Entra ID (Azure AD), you may sign in with your existing work account instead of a GateCore password. Microsoft then provides us with your name, email address and a unique user identifier so we can match you to your organisation's GateCore tenant. We never receive your Microsoft password, and we do not access your mailbox, files, contacts or calendar. This is an additional option — the app's primary sign-in method is a GateCore account created with an email address and password.
  • Push approval — the app checks our servers for pending sign-in approval requests. It does not use third-party push or advertising networks, and it contains no analytics, tracking or advertising SDKs.

When your organisation enables GateCore User Activity monitoring

Some organisations choose to enable the optional User Activity feature within GateCore to support workplace security, device management and IT oversight. This feature is disabled by default and only collects data once your organisation explicitly switches it on. Where enabled, we process the following session metadata on behalf of your organisation:

  • Account name (e.g. the Windows or domain username associated with the session)
  • Session events — sign-in and sign-out, screen lock and unlock, idle start and end, and (where applicable) call start and end
  • Activity durations — time recorded as active, idle, locked or offline, calculated within your organisation's configured working hours
  • Device and machine name, and the tenant (organisation) the device belongs to
  • IP address and an approximate location (city and country) derived from it
What we never collect: GateCore User Activity records session metadata only. It does not capture keystrokes, take screenshots, record your screen, log the websites or applications you use, access file contents, or record audio or your microphone. No message, document or content data is ever collected.

Where this feature is used, your employer or organisation is the data controller and decides why and how it is used. CODE AND SYSTEMS LTD acts only as a data processor on their documented instructions. Responsibility for informing employees that monitoring is in place, and for establishing the appropriate lawful basis, rests with that organisation (see Section 5).

We do not collect sensitive personal data such as financial information, health data, or government-issued identity numbers.

⚙️
3. How We Use Your Data

PurposeData used
Responding to your enquiry or support requestName, email, phone, message content
Providing and managing IT support servicesContact details, system information
Sending service updates or invoicesName, email, company
Improving our website and servicesAnonymised usage data
Complying with legal obligationsAs required by law

We do not use your data for automated decision-making or profiling. We do not send unsolicited marketing emails.

🏢
5. Workplace Monitoring & Employee Data

This section applies where an organisation uses the optional GateCore User Activity feature to monitor workplace device usage (see Section 2). It explains who is responsible for what.

Roles and responsibilities

Where GateCore User Activity is enabled, the organisation (employer) is the data controller. They decide whether to enable the feature, for what purpose, and for how long records are kept. CODE AND SYSTEMS LTD is the data processor, and processes activity data only on the organisation's documented instructions under a data processing agreement.

As the controller, the organisation is responsible for: informing its staff that monitoring is in place; establishing an appropriate lawful basis (typically legitimate interests, supported by an assessment); carrying out any required data protection impact assessment; and responding to its employees' data protection requests. CODE AND SYSTEMS LTD supports these obligations by providing configurable retention, the ability to exclude specific devices, and privacy-by-design controls — but does not determine how the feature is used.

Lawful basis for monitoring

Where monitoring is used, the usual lawful basis relied upon by the controller is legitimate interests — for example protecting workplace systems, managing devices and access, and supporting IT oversight — balanced against the rights and reasonable expectations of employees. The controlling organisation is responsible for making and documenting this assessment.

If you are an employee

If your employer uses GateCore User Activity, questions about why you are being monitored, what is done with the data, or requests to access or delete your data should be directed to your employer, as they control this data. We will assist your employer in responding to any such request. You also retain the right to complain to the ICO (see Section 14).

🤝
6. Sharing Your Data

CODE AND SYSTEMS LTD does not sell, rent, or trade your personal data to third parties.

We may share your data with trusted third parties only where necessary:

  • Microsoft 365 — our email and productivity platform
  • Microsoft Entra ID (Azure AD) — where you choose to sign in with a work account, to verify your identity
  • Remote support tools — only during active support sessions you have authorised
  • Legal authorities — if required by UK law or a court order

All third parties we work with are required to handle your data securely and in accordance with UK GDPR.

🌍
7. International Data Transfers

Where you use our mobile authenticator app, certain data may be processed by app platform and infrastructure providers (such as Apple, Google and Microsoft) whose systems may operate outside the United Kingdom.

Where personal data is transferred outside the UK, we ensure an appropriate safeguard is in place — such as an adequacy decision or Standard Contractual Clauses — so that your data continues to receive a level of protection consistent with UK GDPR.

🗂️
8. Data Retention

We retain your personal data only for as long as necessary for the purpose it was collected:

Data typeRetention period
Enquiry and contact form data2 years from last contact
Active client service recordsDuration of contract + 6 years
Invoices and financial records7 years (UK legal requirement)
Remote support session logs90 days
GateCore User Activity recordsSet by your organisation (retention period is configurable); deleted automatically once it expires
GateCore account & synced authenticator dataUntil you delete your account — deleted immediately and permanently on request (see Section 9)
Account deletion records24 months from deletion (security and fraud prevention — see Section 9)
Website server logs30 days

After these periods, data is securely deleted or anonymised.

🛡️
9. Your Rights

Under UK GDPR, you have the following rights regarding your personal data:

  • Right to access — request a copy of the data we hold about you
  • Right to rectification — ask us to correct inaccurate or incomplete data
  • Right to erasure — request deletion of your data ("right to be forgotten")
  • Right to restriction — ask us to limit how we use your data
  • Right to data portability — receive your data in a structured, machine-readable format
  • Right to object — object to processing based on legitimate interests
  • Right to withdraw consent — where processing is based on consent, you may withdraw at any time
To exercise any of these rights, contact us at info@codeandsystems.co.uk. We will respond within 30 days.

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

Deleting your GateCore Authenticator account

If you created an account in the GateCore Authenticator mobile app, you can delete it yourself at any time — you do not need to contact us. In the app, open Settings → Danger Zone → Delete Account and confirm. Deletion happens immediately and cannot be undone.

What is permanently erased from our servers:

  • Your account and profile, including your email address
  • The cloud-synced copies of all your authenticator accounts and their secrets
  • Registered devices, push tokens and trusted-device settings
  • Any pending sign-in approval requests

What stays on your phone: your authenticator codes remain on the device and keep working, so that deleting your account does not lock you out of the other services those codes protect. They will no longer sync or be backed up — if you lose or reset the phone after deleting your account, they cannot be recovered. You can remove them yourself at any time by deleting individual accounts in the app or uninstalling the app.

What we keep after deletion, and why: when an account is deleted we retain a single minimal record of the deletion event: the account identifier and email address, the date and time, the IP address and approximate location (city and country) it was requested from, the device name and platform, and the number of authenticator accounts removed. We do not keep your authenticator secrets, your password, or the list of services you had set up.

We keep this record for 24 months under our legitimate interests, so that we can confirm a deletion was genuinely carried out, resolve disputes, and investigate account takeover or abuse. After 24 months it is deleted. If you believe this record should be erased sooner, contact us and we will consider your request under Article 17 UK GDPR.

If your GateCore access was provided by your employer or organisation, that organisation controls your account and deletion requests should be directed to them (see Section 5). You can also ask us to delete your account by emailing info@codeandsystems.co.uk if you are unable to use the app.

🍪
10. Cookies

Our website uses minimal cookies necessary for basic functionality. We do not use advertising or tracking cookies.

CookiePurposeDuration
Session cookieMaintains your browsing sessionSession only
Preference cookieRemembers your settings (if any)1 year

You can control or disable cookies through your browser settings. Disabling cookies will not affect your ability to use our website.

🔒
11. Security

CODE AND SYSTEMS LTD takes data security seriously. We implement appropriate technical and organisational measures to protect your personal data, including:

  • TLS/SSL encryption for all data transmitted via our website, apps and email
  • Secure Microsoft 365 infrastructure for email and file storage
  • Access controls limiting data access to authorised personnel only
  • Regular security assessments of our systems and processes

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the ICO within 72 hours as required by UK GDPR.

🔗
12. Third-Party Links

Our website may contain links to third-party websites, including Trustpilot and LinkedIn. These sites have their own privacy policies and we are not responsible for their content or data practices. We recommend reading the privacy policy of any third-party site you visit.

📝
13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we do, we will update the "Last updated" date at the top of this page.

We encourage you to review this policy periodically. Continued use of our website or services after any changes constitutes acceptance of the updated policy.

✉️
14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or how CODE AND SYSTEMS LTD handles your personal data, please get in touch:

📍
Post
CODE AND SYSTEMS LTD, Broxburn Drive, South Ockendon, Essex, RM15 5PP

You also have the right to complain to the Information Commissioner's Office (ICO) if you believe your data has not been handled correctly.