Home

Projects

About Us

Sustainability

FAQs

News

Contact

Legal

Privacy and cookie policy

In short

  • We collect only the personal data we need to respond to you, supply our products and services, run our website and, where you are happy for us to, keep you informed about Comtec.
  • We do not sell your personal data.
  • We use essential cookies to make the website work. We only set analytics or marketing cookies if you agree to them.
  • You have rights over your data, including to see it, correct it, delete it and object to marketing. Exercising them is free. Contact privacy@comtecgrp.com.

This policy explains how Comtec handles personal data when you visit www.comtecgrp.com (our site), contact us, attend our events, or do business with us. Please read it so you understand our practices and your rights.

1. Who we are

For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, the data controller is MCP Group Ltd, trading as Comtec, company number 09923027 registered office, currently shown as Chancery House, 30 St Johns Road, Woking, GU21 7SA].
Our privacy contact is Richard McMullan, who can be reached at hello@comtecgrp.com or by post at the address above.

2. Personal data we collect and where it comes from

We may collect and process the following categories of personal data:

 

Category Examples Where it comes from
Contact and business details Name, job title, company, email address, telephone number, business address You, when you complete a form on our site, request information or samples, or contact us; business cards at events; publicly available business sources
Enquiry and correspondence The content of emails, calls, enquiry forms and site problem reports; project or specification details you share You
Account and registration data Login details and preferences if you register to use our site You
Event and CPD data Attendance and booking details for CPD seminars, webinars and events You; event organisers or partners
Marketing preferences Your consents, opt-outs and subscription choices You
Survey and feedback responses Answers to surveys we ask you to complete (always optional) You
Technical and usage data IP address, browser type and version, operating system, device information, pages visited, and cookie identifiers Automatically, through your use of our site and cookies (see section 10)
Customer and supplier records Order, delivery, invoicing and account details; supplier contact details You or your employer

We do not knowingly collect special category data (such as health information) or criminal offence data. Please do not send it to us.

3. How we use your data, and our legal basis

We must have a lawful basis to use your personal data. The table below sets out why we use it and which basis we rely on.

What we do Data used Lawful basis
Respond to enquiries and provide the information, quotations, products or services you request Contact, enquiry Steps at your request before entering a contract, or performance of a contract; otherwise our legitimate interests in running our business
Carry out our obligations under contracts with you or your employer, including delivery, invoicing and support Contact, customer records Performance of a contract
Operate, secure and improve our site, and present content effectively for your device Technical and usage data Legitimate interests in keeping our site secure and effective; consent where non-essential cookies are involved
Let you register for, and use, interactive features of our site Account, contact Performance of a contract / legitimate interests
Run CPD seminars and events Event, contact Performance of a contract or legitimate interests
Send you marketing about our products and services (see section 4) Contact, marketing preferences Consent, or legitimate interests for business contacts where the law permits
Carry out customer satisfaction and market research surveys Survey, contact Legitimate interests in improving what we do
Notify you about changes to our service or this policy Contact Legitimate interests / legal obligation
Comply with the law, respond to regulators and legal claims, prevent fraud, and protect our rights and property Any relevant data Legal obligation; legitimate interests
Analyse site traffic using analytics cookies Technical and usage data Consent

Where we rely on legitimate interests, we balance them against your rights and freedoms. You can ask us for details of that assessment. Where we rely on consent, you can withdraw it at any time.

4. Marketing

We would like to keep you informed about Comtec products, CPD opportunities and news. We will contact you for marketing purposes:

  • by email or SMS where you have consented, or where you are an existing customer or have enquired about a similar product or service and have not opted out; and
  • by post or telephone where permitted by law. We do not make unsolicited marketing calls to numbers registered with the Telephone Preference Service (TPS) or Corporate TPS.

Every marketing email includes an unsubscribe link. You can also opt out at any time by emailing privacy@comtecgrp.com or ticking the relevant box on our forms. We will keep a record of your request so we do not contact you again.
We do not sell your data, and we will not pass it to third parties for their own marketing without your consent.

5. Who we share your data with

We only share personal data where we need to, and we require anyone who handles it on our behalf to protect it. Recipients include:

  • Group companies: members of our group, meaning our subsidiaries, our ultimate holding company and its subsidiaries, as defined in section 1159 of the Companies Act 2006.
  • Service providers (processors) acting on our instructions, such as [website hosting and maintenance, CRM system, email marketing platform, analytics provider, IT support, payment provider, couriers and logistics partners].
  • Professional advisers, such as lawyers, accountants, auditors and insurers.
  • Authorities and other parties where we are legally required to disclose data, or need to do so to enforce our terms, protect our rights, property or safety, or those of our customers or others. This includes exchanging information with other organisations for fraud prevention and credit risk reduction.
  • Buyers and sellers of a business: if we sell, buy or merge any business or assets, or if Comtec or substantially all its assets are acquired by a third party, personal data we hold may be disclosed to or transferred to the other party, who may use it as set out in this policy.

 

6. International transfers

Some of our suppliers, or members of our group, are located outside the United Kingdom, or may access data from outside the UK. When we transfer personal data out of the UK, we make sure it is protected by an appropriate safeguard, such as:

  • transferring to a country covered by UK adequacy regulations (including the UK Extension to the EU-US Data Privacy Framework for certified US recipients);
  • using the ICO’s International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses; or
  • another safeguard permitted by data protection law.

You can ask us for more information about the safeguards we use by contacting privacy@comtecgrp.com.

7. How long we keep your data

We keep personal data only for as long as we need it for the purposes in this policy, including to meet legal, accounting and reporting requirements. Typical periods are shown below; they may be longer where needed to deal with a dispute or comply with the law.

Type of data Retention period Basis for period
Enquiries that do not lead to a sale 3 years from last contact Follow-up and handling of queries
Customer and contract records 6 years after the end of the relationship Tax, accounting and limitation periods
Marketing contacts Until you unsubscribe, with a review every 2 years of inactive contacts Your consent or preferences
Marketing suppression list (opt-outs) Indefinitely To make sure we respect your choice
Event and CPD attendance records 5 years CPD record-keeping and follow-up
Website logs and analytics data 24 months Security and site improvement

8. How we protect your data

We use technical and organisational measures to protect personal data against unauthorised access, loss, misuse and alteration. These include secure (HTTPS) connections on our site, access controls limiting data to staff who need it, staff training, and agreements with our suppliers requiring them to protect the data they handle.

No transmission over the internet can be guaranteed to be completely secure. Please take care when sending us information, and do not include sensitive details in general enquiry forms or emails. If you have a password for our site, you are responsible for keeping it confidential.

If a personal data breach occurs that is likely to result in a risk to you, we will notify the Information Commissioner’s Office within 72 hours where required, and we will tell you directly where the breach is likely to result in a high risk to your rights and freedoms.

9. Your rights

Under data protection law you have the following rights. Exercising them is free of charge.

To exercise any of these rights, email hello@comtecgrp.com or write to us at the address in section 1. We will reply within one month, which we may extend by up to two further months for complex or numerous requests, and we will tell you if so. We may need to ask for proof of identity to make sure we only release data to the right person. We will not charge a fee unless a request is clearly unfounded or excessive.

10. Cookies

Cookies are small text files placed on your device when you visit a website. They help the site work, remember your preferences, and tell us how the site is used. Some are essential; others are optional and are only set if you agree.

How we use cookies

  • Strictly necessary cookies are needed for the site to function, for example to keep you logged in, keep your session secure and remember your cookie choice. These do not need consent.
  • Functional cookies remember choices such as your language or store view, and speed up page loading.
  • Analytics cookies help us understand how visitors use the site so we can improve it. We only use these if you accept them.
  • Marketing cookies are used to measure or tailor advertising. We only use these if you accept them.

Cookies on our site

The cookies in use on our site are available on our cookies policy page.

Managing your cookie choices

When you first visit our site, a cookie banner lets you accept or reject non-essential cookies. You can withdraw consent at any time.
You can also block or delete cookies in your browser settings. Visit www.aboutcookies.org for instructions for most browsers. If you block essential cookies, parts of our site may not work properly.

11. Links to other websites

Our site may contain links to and from the websites of partner networks, advertisers and affiliates. If you follow a link, please note that those websites have their own privacy policies and we are not responsible for them. Please check those policies before you submit any personal data.

12. Children

Our site and services are intended for business users and are not aimed at children. We do not knowingly collect personal data from anyone under 13. If you believe a child has given us their data, please contact us and we will delete it.

13. Changes to this policy

We will post any changes to this policy on this page and update the date and version number below. Where a change is significant, we will also notify you by email where appropriate. Please check back from time to time.

14. Contact us and complaints

Questions, comments and requests about this policy or how we use your data are welcome. Please contact privacy@comtecgrp.com or write to us at the address in section 1.

If you are unhappy with how we have handled your data, please tell us first so we can put things right. We will acknowledge complaints within 30 days and respond without undue delay. You also have the right to complain to the UK supervisory authority, the Information Commissioner’s Office (ICO), at ico.org.uk/make-a-complaint, or by telephone on 0303 123 1113.

Revision history

Right What it means
Be informed To be told how we use your data, which is the purpose of this policy.
Access To receive a copy of the personal data we hold about you and information about how we use it (a “subject access request”).
Rectification To have inaccurate or incomplete data corrected.
Erasure To ask us to delete your data in certain circumstances, for example where it is no longer needed or you withdraw consent.
Restriction To ask us to pause using your data in certain circumstances, for example while we check its accuracy.
Data portability To receive data you provided to us in a structured, commonly used format, or have it sent to another organisation, where we use it based on consent or contract and by automated means.
Object To object to processing based on legitimate interests, and to object at any time to direct marketing, which we will always stop.
Withdraw consent To withdraw consent at any time where we rely on it. This will not affect processing already carried out.
Automated decisions Not to be subject to decisions based solely on automated processing that significantly affect you. We do not make such decisions.
Version Date Description
3.0 06 October 2026 Full rewrite to reflect the UK GDPR, Data Protection Act 2018 and PECR; updated rights, lawful bases, retention, transfers and cookies; removed legacy references
2.0 2023 Previous version

Contact us

How can we help you reduce cost and risk?

Get in touch

Fill out the form below and we will get back to you.

Checkboxes

* This form collects your name, email and telephone no. so that we can contact you regarding your enquiry.