Skip to content
  • About Us
    • Our Story
    • SA1 Group
    • Careers
  • Services
    • Managed IT Services
      • Network Management
      • IT Support
      • Server Management
    • Cyber Security
      • Microsoft Defender for Endpoint
      • RocketCyber SOC
      • Vulnerability Management
      • Incident Response
      • Datto Security
      • AI Penetration Testing
      • Cyber Essentials
      • Cyber Essentials Plus
    • O365 Tenant Migrations
      • Migration Process
      • Post-Migration Support
    • M365 Tenant Management
      • Clear Tenant
    • SharePoint Development
      • Custom SharePoint Solutions
      • SharePoint Design & Development
    • Cloud Solutions
      • Cloud Management
      • Backup Solutions
    • Telecoms Solutions
  • Resources
    • Blog
  • Customer Assistance
    • Access Support Portal
CONTACT US
CONTACT US
Legal

Privacy Notice

Last updated: August 2026 ICO reference ZA103000

This notice explains how Sa1 Solutions Limited collects and uses personal data through this website, and what rights you have over that data. It is written to comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR).

Contents

  1. Who we are
  2. What this notice covers
  3. Personal data we collect
  4. Why we use your data
  5. Cookies and similar technologies
  6. Who we share your data with
  7. International transfers
  8. How we protect your data
  9. Your rights
  10. Marketing
  11. Automated decision-making
  12. Complaints
  13. Changes to this notice

01Who we are

Sa1 Solutions Limited is the data controller for the personal data described in this notice.

Company
Sa1 Solutions Limited, also trading as BSS
Registered address
Systems House, Phoenix Way, Garngoch Industrial Estate, Gorseinon, Swansea, SA4 9WF
Company number
05562580
ICO registration
ZA103000
Email
info@sa1solutions.com
Telephone
01792 464242

02What this notice covers

This notice covers personal data we collect as a controller through this website and through direct enquiries, including visitors, prospective clients, and job applicants.

It does not cover personal data we process on behalf of our clients when delivering IT and cyber security services. In that context we act as a processor, and our handling of that data is governed by the data processing terms in each client's service agreement rather than by this notice. If you are an employee or contact of one of our clients and want to know how your data is handled, please contact your own organisation in the first instance.

03Personal data we collect

Enquiries and support requests

When you contact us through a form on this website, by email, or by telephone, we collect the information you provide. This typically includes your name, your organisation, your email address, your telephone number, and the content of your message.

Enquiries submitted through this website are recorded in our service management and ticketing platform so that they can be tracked, assigned and answered. That platform is operated by Kaseya BMS on our behalf under a written data processing agreement.

Technical data collected automatically

Our web server records standard technical information each time a page is requested. This includes your IP address, the browser and operating system you are using, the pages you visited, the referring website, and the date and time of the request.

We use this information to deliver the site correctly, to keep it secure, to diagnose faults, and to investigate misuse or attacks against our systems. We do not use it to identify individual visitors.

Job applications

If you apply for a role with us, we collect the information contained in your application, including your CV, employment history, qualifications and contact details. We use this solely to assess your suitability for the role and to manage the recruitment process.

If your application is unsuccessful, we retain your application for one month after we notify you of the outcome, so that we can respond to any query about the decision, and then delete it. If you are appointed, your application becomes part of your employment record.

04Why we use your data, and our lawful basis

PurposeLawful basis
Responding to enquiries and providing quotations Legitimate interests, and steps taken at your request prior to entering a contract
Delivering services under a contract with your organisation Performance of a contract, and our legitimate interest in administering that contract
Keeping this website and our systems secure Legitimate interests, and our legal obligation to protect personal data
Setting non-essential cookies and loading embedded third party content Consent
Sending marketing communications Consent, or the soft opt-in under PECR where you are an existing customer
Assessing job applications Steps taken at your request prior to entering a contract, and legitimate interests
Meeting accounting, tax and other statutory obligations Legal obligation

Where we rely on legitimate interests, that interest is operating and growing our business, responding to people who contact us, and protecting our systems and our clients. We have considered whether those interests are overridden by your rights, and will stop the processing if you object and we cannot show compelling grounds to continue.

05Cookies and similar technologies

Essential cookies

A small number of cookies are strictly necessary for the website to function, for example to maintain your session or to remember your cookie preferences. These are set without consent because the site cannot work without them.

Non-essential cookies and embedded content

We only set non-essential cookies, and only load third party embedded content that involves your data, after you have given consent through our cookie banner. You can change or withdraw your choice at any time using the Cookies Settings link in the footer of every page.

The third party services that may be loaded on this site are:

  • Google Maps. Used to display the location of our office. Loading a map transmits your IP address to Google and may set cookies on your device. Google's privacy notice is available at policies.google.com/privacy.
  • Google Fonts. Used to render typefaces on the site. Where fonts are requested from Google's servers, your IP address is transmitted to Google in order to deliver the font files.

We do not use advertising cookies, tracking pixels, or cross-site behavioural profiling on this website.

Social media links

Our pages contain links to our profiles on LinkedIn, Facebook and X. These are ordinary hyperlinks, not embedded plugins. They do not transmit data to those platforms unless you click them, at which point the privacy notice of the platform concerned applies.

Managing cookies in your browser

Separately from our cookie banner, you can block or delete cookies through your browser settings. Doing so may affect how parts of this site behave. Guidance for common browsers is available from the Information Commissioner's Office.

06Who we share your data with

We do not sell personal data, and we do not share it for anyone else's marketing purposes.

We share personal data with the following categories of recipient:

  • Service providers acting on our behalf, including our hosting provider, our email provider, and our service management and ticketing platform. Each is bound by a written contract that requires them to process data only on our instructions and to keep it secure.
  • Professional advisers, such as our accountants and legal advisers, where necessary.
  • Regulators, law enforcement and other authorities, where we are legally required to disclose information or where disclosure is necessary to establish, exercise or defend legal claims.

07International transfers

Our own systems and the data we hold as a controller are located in the United Kingdom and the European Economic Area.

Some of the third party services described above are operated by companies based outside the UK, including in the United States. Where personal data is transferred outside the UK, we rely on one of the safeguards permitted by the UK GDPR, being either UK adequacy regulations for the destination country, or the International Data Transfer Agreement, or the UK Addendum to the European Commission's standard contractual clauses.

You can request further information about the safeguards applying to a specific transfer using the contact details above.

08How we protect your data

We apply technical and organisational measures appropriate to the risk, including access control, multi-factor authentication, encryption in transit, endpoint protection, logging and monitoring, and staff training. Our approach is aligned with recognised standards including Cyber Essentials.

No transmission over the internet can be guaranteed completely secure. If you would prefer not to send sensitive information through this website, please contact us by telephone instead.

09Your rights

Under the UK GDPR you have the following rights in relation to your personal data:

  • Access. To be told whether we hold data about you and to receive a copy of it.
  • Rectification. To have inaccurate data corrected and incomplete data completed.
  • Erasure. To have your data deleted where we no longer have a valid reason to keep it.
  • Restriction. To have our use of your data limited in certain circumstances.
  • Portability. To receive data you gave us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
  • Objection. To object to processing based on our legitimate interests. You can object to direct marketing at any time, and we will stop.
  • Withdrawal of consent. Where we rely on consent, to withdraw it at any time. This does not affect processing carried out before you withdrew it.
  • Automated decision-making. Not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.

To exercise any of these rights, contact us using the details in section 01. We will respond within one month. There is normally no charge, and we may ask you to verify your identity before we act on a request.

10Marketing

We will only send you marketing by email where you have consented, or where you are an existing customer and the message concerns similar services, which is permitted under the PECR soft opt-in.

Every marketing email includes an unsubscribe link. You can also opt out at any time by emailing us.

11Automated decision-making

We do not carry out automated decision-making or profiling that produces legal effects concerning you or that similarly significantly affects you.

12Complaints

If you are unhappy with how we have handled your personal data, please contact us first so that we can try to resolve it.

Information Commissioner's Office

You also have the right to complain to the ICO, the UK supervisory authority for data protection.

  • Website: ico.org.uk/make-a-complaint
  • Helpline: 0303 123 1113
  • Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

13Changes to this notice

We review this notice periodically and will update it when our processing changes. The date at the top shows when it was last revised. Where a change materially affects how we use your data, we will take reasonable steps to tell you.

Questions about how we handle your data? Get in touch and we will answer them.

Back to home
A leading IT Support provider in South Wales

Systems House, Phoenix Way,
Garngoch Industrial Estate, Gorseinon, SA4 9WF

Services

  • Managed IT Services
  • Cyber Security
  • O365 Tenant Migrations
  • SharePoint Development
  • Cloud Solutions
  • Telecoms Solutions

Company

  • About
  • Services

Get In Touch

01792 464242

info@sa1solutions.com

Copyright © 2026 SA1 Solutions. All rights reserved.

  • Privacy Policy
  • Cookies Settings