Privacy Policy
How CODE AND SYSTEMS LTD collects, uses, and protects your personal data in accordance with UK GDPR and the Data Protection Act 2018.
1. Who We Are
CODE AND SYSTEMS LTD (Company Registration No. 15973638) is registered in England and Wales. We are the data controller responsible for your personal information.
2. Data We Collect
We collect personal data in the following circumstances:
When you contact us or submit an enquiry
- Full name
- Email address
- Phone number (if provided)
- Company name (if provided)
- The content of your message or enquiry
When we provide IT support services
- Name and job title
- Business contact details
- Technical information about your systems (only what is necessary to resolve your issue)
- Remote access session logs
When you visit our website
- IP address and browser type (via server logs)
- Pages visited and time spent (anonymised analytics if enabled)
When you use our GateCore products (MFA, Firewall & mobile authenticator)
If you or your organisation use our GateCore security products, we process the following categories of data as necessary to provide the service:
- Account information — username and email address
- Authentication records — sign-in events, verification status, and timestamps
- Device identifiers — a unique identifier assigned to your registered device
- IP address and an approximate location (city and country) derived from it — shown to you when approving a sign-in request so you can recognise activity that isn't yours
- Service and security logs — records generated to operate and protect the service
Where your employer or organisation provides you with access to GateCore, that organisation is the data controller and CODE AND SYSTEMS LTD acts as a data processor, processing data only on their documented instructions.
GateCore Authenticator mobile app (iOS & Android)
The mobile authenticator app works as follows:
- Camera — used only to scan QR codes when you add an authenticator account. Images are processed entirely on your device, are never saved to your photo library, and are never uploaded to us or anyone else. The app asks for camera permission the first time you scan, and you can decline.
- Codes stored on your device — your authenticator secrets are held in the operating system's secure storage (iOS Keychain / Android Keystore). Codes are generated on the device itself and are not sent to us in order to work.
- Optional cloud sync — if you create an account and enable sync, a copy of your authenticator accounts is stored on our UK servers so you can restore them on a new phone. Data is transmitted over encrypted TLS connections, held on access-controlled servers, and is never shared with third parties or used for any purpose other than restoring your accounts. Sync is optional; the app works without an account, and if you never enable sync nothing leaves your device.
- Signing in with Microsoft — if your organisation uses Microsoft Entra ID (Azure AD), you may sign in with your existing work account instead of a GateCore password. Microsoft then provides us with your name, email address and a unique user identifier so we can match you to your organisation's GateCore tenant. We never receive your Microsoft password, and we do not access your mailbox, files, contacts or calendar. This is an additional option — the app's primary sign-in method is a GateCore account created with an email address and password.
- Push approval — the app checks our servers for pending sign-in approval requests. It does not use third-party push or advertising networks, and it contains no analytics, tracking or advertising SDKs.
When your organisation enables GateCore User Activity monitoring
Some organisations choose to enable the optional User Activity feature within GateCore to support workplace security, device management and IT oversight. This feature is disabled by default and only collects data once your organisation explicitly switches it on. Where enabled, we process the following session metadata on behalf of your organisation:
- Account name (e.g. the Windows or domain username associated with the session)
- Session events — sign-in and sign-out, screen lock and unlock, idle start and end, and (where applicable) call start and end
- Activity durations — time recorded as active, idle, locked or offline, calculated within your organisation's configured working hours
- Device and machine name, and the tenant (organisation) the device belongs to
- IP address and an approximate location (city and country) derived from it
Where this feature is used, your employer or organisation is the data controller and decides why and how it is used. CODE AND SYSTEMS LTD acts only as a data processor on their documented instructions. Responsibility for informing employees that monitoring is in place, and for establishing the appropriate lawful basis, rests with that organisation (see Section 5).
We do not collect sensitive personal data such as financial information, health data, or government-issued identity numbers.
3. How We Use Your Data
| Purpose | Data used |
|---|---|
| Responding to your enquiry or support request | Name, email, phone, message content |
| Providing and managing IT support services | Contact details, system information |
| Sending service updates or invoices | Name, email, company |
| Improving our website and services | Anonymised usage data |
| Complying with legal obligations | As required by law |
We do not use your data for automated decision-making or profiling. We do not send unsolicited marketing emails.
4. Legal Basis for Processing
Under UK GDPR, we process your personal data on the following legal bases:
- Legitimate interests — responding to enquiries and providing services you have requested
- Contract performance — where we have a service agreement with you or your organisation
- Legal obligation — where we are required to retain records by law
- Consent — where you have explicitly agreed (e.g. newsletter sign-up, if applicable)
5. Workplace Monitoring & Employee Data
This section applies where an organisation uses the optional GateCore User Activity feature to monitor workplace device usage (see Section 2). It explains who is responsible for what.
Roles and responsibilities
Where GateCore User Activity is enabled, the organisation (employer) is the data controller. They decide whether to enable the feature, for what purpose, and for how long records are kept. CODE AND SYSTEMS LTD is the data processor, and processes activity data only on the organisation's documented instructions under a data processing agreement.
Lawful basis for monitoring
Where monitoring is used, the usual lawful basis relied upon by the controller is legitimate interests — for example protecting workplace systems, managing devices and access, and supporting IT oversight — balanced against the rights and reasonable expectations of employees. The controlling organisation is responsible for making and documenting this assessment.
If you are an employee
If your employer uses GateCore User Activity, questions about why you are being monitored, what is done with the data, or requests to access or delete your data should be directed to your employer, as they control this data. We will assist your employer in responding to any such request. You also retain the right to complain to the ICO (see Section 14).
6. Sharing Your Data
CODE AND SYSTEMS LTD does not sell, rent, or trade your personal data to third parties.
We may share your data with trusted third parties only where necessary:
- Microsoft 365 — our email and productivity platform
- Microsoft Entra ID (Azure AD) — where you choose to sign in with a work account, to verify your identity
- Remote support tools — only during active support sessions you have authorised
- Legal authorities — if required by UK law or a court order
All third parties we work with are required to handle your data securely and in accordance with UK GDPR.
7. International Data Transfers
Where you use our mobile authenticator app, certain data may be processed by app platform and infrastructure providers (such as Apple, Google and Microsoft) whose systems may operate outside the United Kingdom.
Where personal data is transferred outside the UK, we ensure an appropriate safeguard is in place — such as an adequacy decision or Standard Contractual Clauses — so that your data continues to receive a level of protection consistent with UK GDPR.
8. Data Retention
We retain your personal data only for as long as necessary for the purpose it was collected:
| Data type | Retention period |
|---|---|
| Enquiry and contact form data | 2 years from last contact |
| Active client service records | Duration of contract + 6 years |
| Invoices and financial records | 7 years (UK legal requirement) |
| Remote support session logs | 90 days |
| GateCore User Activity records | Set by your organisation (retention period is configurable); deleted automatically once it expires |
| GateCore account & synced authenticator data | Until you delete your account — deleted immediately and permanently on request (see Section 9) |
| Account deletion records | 24 months from deletion (security and fraud prevention — see Section 9) |
| Website server logs | 30 days |
After these periods, data is securely deleted or anonymised.
9. Your Rights
Under UK GDPR, you have the following rights regarding your personal data:
- Right to access — request a copy of the data we hold about you
- Right to rectification — ask us to correct inaccurate or incomplete data
- Right to erasure — request deletion of your data ("right to be forgotten")
- Right to restriction — ask us to limit how we use your data
- Right to data portability — receive your data in a structured, machine-readable format
- Right to object — object to processing based on legitimate interests
- Right to withdraw consent — where processing is based on consent, you may withdraw at any time
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
Deleting your GateCore Authenticator account
If you created an account in the GateCore Authenticator mobile app, you can delete it yourself at any time — you do not need to contact us. In the app, open Settings → Danger Zone → Delete Account and confirm. Deletion happens immediately and cannot be undone.
What is permanently erased from our servers:
- Your account and profile, including your email address
- The cloud-synced copies of all your authenticator accounts and their secrets
- Registered devices, push tokens and trusted-device settings
- Any pending sign-in approval requests
What stays on your phone: your authenticator codes remain on the device and keep working, so that deleting your account does not lock you out of the other services those codes protect. They will no longer sync or be backed up — if you lose or reset the phone after deleting your account, they cannot be recovered. You can remove them yourself at any time by deleting individual accounts in the app or uninstalling the app.
We keep this record for 24 months under our legitimate interests, so that we can confirm a deletion was genuinely carried out, resolve disputes, and investigate account takeover or abuse. After 24 months it is deleted. If you believe this record should be erased sooner, contact us and we will consider your request under Article 17 UK GDPR.
If your GateCore access was provided by your employer or organisation, that organisation controls your account and deletion requests should be directed to them (see Section 5). You can also ask us to delete your account by emailing info@codeandsystems.co.uk if you are unable to use the app.
10. Cookies
Our website uses minimal cookies necessary for basic functionality. We do not use advertising or tracking cookies.
| Cookie | Purpose | Duration |
|---|---|---|
| Session cookie | Maintains your browsing session | Session only |
| Preference cookie | Remembers your settings (if any) | 1 year |
You can control or disable cookies through your browser settings. Disabling cookies will not affect your ability to use our website.
11. Security
CODE AND SYSTEMS LTD takes data security seriously. We implement appropriate technical and organisational measures to protect your personal data, including:
- TLS/SSL encryption for all data transmitted via our website, apps and email
- Secure Microsoft 365 infrastructure for email and file storage
- Access controls limiting data access to authorised personnel only
- Regular security assessments of our systems and processes
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the ICO within 72 hours as required by UK GDPR.
12. Third-Party Links
Our website may contain links to third-party websites, including Trustpilot and LinkedIn. These sites have their own privacy policies and we are not responsible for their content or data practices. We recommend reading the privacy policy of any third-party site you visit.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we do, we will update the "Last updated" date at the top of this page.
We encourage you to review this policy periodically. Continued use of our website or services after any changes constitutes acceptance of the updated policy.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or how CODE AND SYSTEMS LTD handles your personal data, please get in touch:
You also have the right to complain to the Information Commissioner's Office (ICO) if you believe your data has not been handled correctly.