Privacy notice
This notice explains what personal data Ramko Tech Consulting Ltd collects, why, on what lawful basis, how long it is kept and what rights you have over it. It is written to be read rather than to be defended.
1. Who is responsible for your data
Ramko Tech Consulting Ltd (“Ramko”, “we”, “us”) is the data controller for the personal data described in this notice. We are a private company limited by shares, registered in England and Wales under company number 17022162, with our registered office at 2 Cherry Croft, Croxley Green, Rickmansworth, England WD3 3AL.
All privacy enquiries, including requests to exercise your rights, should be sent to support@ramkotech.pro. We have not appointed a Data Protection Officer; we are not required to, and the director handles these requests personally.
2. What this website collects
Nothing directly. ramkotech.pro is a set of static pages. It has no contact form, no login, no comments, no chat widget, no advertising and no analytics. It sets no cookies of its own and stores nothing in your browser. See the cookie notice for the detail.
Two things nevertheless involve a third party, and you should know about both:
- Typefaces. The pages request fonts from Google Fonts (fonts.googleapis.com and fonts.gstatic.com). Making that request necessarily discloses your IP address and basic browser information to Google, who state that they use it to serve the fonts. We receive nothing from it and cannot identify you through it.
- Hosting. Our hosting provider may keep standard server logs — IP address, timestamp, page requested, user agent — for security and reliability purposes. We do not use these logs for analytics, marketing or profiling.
3. What we collect when you contact us
If you email support@ramkotech.pro, we receive and hold what you send: your name and email address, your organisation, and whatever you choose to write about your situation, together with our replies.
Please do not send credentials, passwords, security keys, or personal data about your staff or customers in an initial enquiry. If an engagement proceeds and such information is genuinely needed, we will agree an appropriate route and, where applicable, a written data processing agreement first.
4. What we collect during an engagement
Advisory work necessarily involves information about your organisation. Where that information includes personal data — the names and roles of the people we interview, for example, or the contents of documents you provide — we hold it only for the duration and purpose of the engagement.
Where we handle personal data on your instructions rather than our own, you are the controller and we act as a processor. In that case the arrangement is set out in a written agreement covering purpose, duration, security and deletion, entered into before the data is transferred.
5. Why we hold it, and the lawful basis
- To answer your enquiry and to scope possible work — legitimate interests (Article 6(1)(f)): you have contacted us about a service and expect a reply.
- To perform an engagement you have accepted — performance of a contract (Article 6(1)(b)).
- To keep accounting and tax records — legal obligation (Article 6(1)(c)) under UK company and tax law.
- To keep a record of advice given, in case a question arises later — legitimate interests (Article 6(1)(f)), balanced against the retention limits below.
We do not use your data for marketing. We operate no mailing list, send no newsletter, and run no follow-up sequences. We will not add you to anything.
6. Who it is shared with
We do not sell, rent or trade personal data, and we do not share it for anyone else's marketing. Data is disclosed only:
- to our email and IT service providers, who process it on our instructions in order to operate the mailbox and store our files securely;
- to our accountant, in relation to invoices and statutory accounts;
- to our professional advisers, where we need legal or insurance advice on a matter;
- where we are required to by law, by a court order, or by a regulator.
We do not share the contents of an engagement with anyone outside your organisation without your written permission — which is also why no client is named anywhere on this website.
7. International transfers
Our email and file storage providers may process data outside the United Kingdom. Where that happens we rely on the transfer mechanisms permitted under UK data protection law, such as UK adequacy regulations or the International Data Transfer Addendum to the European Commission's standard contractual clauses. You may ask us which providers are involved and on what basis.
8. How long we keep it
- Enquiries that do not lead to an engagement — up to 12 months from the last message, then deleted.
- Engagement records, reports and correspondence — 6 years from the end of the engagement, which reflects the limitation period for contractual claims in England and Wales.
- Invoices and accounting records — 6 years from the end of the accounting period, as required by UK tax law.
- Client data held as a processor — returned or deleted at the end of the engagement, in accordance with the written agreement covering it.
9. Security
Access to our mailbox and files is protected by multi-factor authentication and is limited to the director. During an engagement we ask for the least access that will answer the question, read-only wherever possible, granted through accounts you control and revoked at the end. We do not copy client systems or data beyond what the engagement requires.
No arrangement is perfect. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it, and tell you directly where the risk is high.
10. Your rights
Under the UK GDPR you have the right to:
- be told what personal data we hold about you, and to receive a copy of it;
- have inaccurate data corrected;
- have data erased where we no longer have a good reason to keep it;
- restrict how we use it while a dispute about accuracy or legitimate interests is resolved;
- object to processing based on legitimate interests;
- receive data you provided in a portable format, where that right applies;
- withdraw consent at any time, where we have relied on consent.
Write to support@ramkotech.pro. We respond within one month, free of charge, and will tell you at the outset if identity verification is needed.
11. Complaints
If you are unhappy with how we have handled your data, please tell us first — we would rather fix it. You also have the right to complain to the UK supervisory authority:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
0303 123 1113 · ico.org.uk
12. Changes to this notice
If this notice changes materially, the version number and date at the top of this page change with it. We do not make silent amendments. Where a change affects a live engagement, we will tell the client directly.