1. Introduction and Data Controller
FullTech Solutions (“we”, “us”, or “our”) is a technology solutions provider offering custom software development, solutions architecture, website design, and software-as-a-service (SaaS) products. We are committed to protecting and respecting your privacy.
This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our website at https://fulltechsolutions.co.uk/ or engage our services. It also explains your rights under the EU General Data Protection Regulation (GDPR) and the Gibraltar Data Protection Act 2018.
FullTech Solutions is a company registered in Gibraltar and acts as the data controller for the personal data you provide to us. We are responsible for deciding how your personal data is processed in line with this policy.
2. Personal Data We Collect
We collect information that you provide directly to us, as well as information collected automatically when you use our website or services.
2.1 Information You Provide
- Contact and enquiry data: your name, email address, phone number, and company name when you submit a form, request a consultation, or contact us.
- Project data: details you share with us about your business requirements, existing systems, and technical infrastructure to enable us to scope and deliver services.
- Account data: email address and password (where applicable) for access to our SaaS products or client portals.
- Marketing preferences: your choices regarding how you wish to be contacted by us.
2.2 Information Collected Automatically
- Technical data: your IP address, browser type and version, device information, operating system, and time zone settings.
- Usage data: the pages you visit, the time and date of each visit, how long you spend on each page, page response times, and referral sources.
- Location data: an approximate location derived from your IP address.
3. How We Use Your Personal Data
We process your personal data for the following purposes:
- To respond to your enquiries and provide information about our software development, architecture, website design, and SaaS services.
- To deliver, manage, and maintain the services and products you engage us to provide.
- To communicate with you about projects, support requests, and account administration.
- To process and administer proposals, contracts, invoices, and payments.
- To improve our website, services, and user experience, including troubleshooting and analytics.
- To send you marketing communications where you have provided consent or where we have another lawful basis.
- To comply with our legal, regulatory, and contractual obligations.
- To protect the security and integrity of our systems and detect, prevent, or address fraud or misuse.
4. Legal Basis for Processing
Under the GDPR, we rely on the following legal bases to process your personal data:
- Consent (Article 6(1)(a)): where you have consented to receive marketing communications or the use of certain cookies.
- Contractual necessity (Article 6(1)(b)): to take steps before entering into a contract with you, and to perform a contract once agreed.
- Legal obligation (Article 6(1)(c)): where we must comply with a legal or regulatory obligation.
- Legitimate interests (Article 6(1)(f)): for our legitimate business interests, such as website security, analytics, fraud prevention, and improving our services, provided these do not override your rights and freedoms.
You have the right to withdraw your consent at any time by contacting us using the details in Section 13. Withdrawing consent will not affect the lawfulness of processing before withdrawal.
5. Cookies and Tracking Technologies
Our website uses cookies and similar tracking technologies (such as web beacons and pixel tags) to recognise you and remember your preferences. Cookies are small files stored on your device.
We use the following categories of cookies:
- Strictly necessary cookies: required for the website to function correctly. These cannot be disabled.
- Performance and analytics cookies: help us understand how visitors use our website so we can improve it.
- Functionality cookies: remember your preferences and settings.
- Marketing cookies: used to deliver relevant advertisements and track the effectiveness of campaigns, where you have consented.
You can manage or disable cookies through your browser settings. However, disabling some cookies may affect the functionality of the website.
6. Sharing Your Personal Data
We do not sell your personal data. We may share your personal data with:
- Service providers and processors: trusted third parties who act on our behalf to deliver services, such as hosting providers, analytics platforms, payment processors, and email service providers. These parties are bound by contractual obligations to protect your data.
- Professional advisors: lawyers, accountants, and auditors where necessary for legal or advisory purposes.
- Public authorities: where required by law, court order, or to protect our legal rights, safety, or the safety of others.
- Business transferees: in the event of a merger, acquisition, or sale of all or part of our business, we may transfer your data as part of that transaction.
7. International Data Transfers
Your personal data is primarily stored and processed within Gibraltar and the European Economic Area (EEA). Where we transfer personal data outside the EEA, we will ensure that appropriate safeguards are in place, such as:
- Transfers to countries recognised as providing an adequate level of data protection by the European Commission.
- Use of the European Commission’s Standard Contractual Clauses (SCCs).
- Additional safeguards where necessary to protect your data.
8. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, or reporting requirements. Specific retention periods include:
- Enquiry and contact data: up to 24 months after our last interaction, unless you ask us to remove it sooner.
- Project and contract data: for the duration of the engagement plus a reasonable period thereafter to meet legal, tax, and contractual obligations (typically up to 7 years).
- Marketing data: until you opt out or until we reasonably determine the data is no longer relevant.
- Website analytics data: typically retained for up to 26 months.
When your data is no longer required, we will securely delete or anonymise it.
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, or disclosure. These measures include:
- Encryption of data in transit using TLS (Transport Layer Security).
- Access controls that limit data access to authorised personnel only.
- Regular security reviews and vulnerability assessments.
- Secure data storage and backup practices.
- Staff training on data protection and information security.
Despite our efforts, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security, but we will take reasonable steps to protect your data.
10. Your Data Protection Rights
Under the GDPR and the Gibraltar Data Protection Act 2018, you have the following rights regarding your personal data:
- Right to be informed: to receive clear, transparent information about how we use your data (this policy).
- Right of access: to request a copy of the personal data we hold about you.
- Right to rectification: to ask us to correct inaccurate or incomplete data.
- Right to erasure: to request deletion of your personal data in certain circumstances.
- Right to restrict processing: to ask us to limit how we use your data in certain situations.
- Right to data portability: to receive your data in a structured, machine-readable format and, where technically feasible, to have it transferred to another provider.
- Right to object: to object to processing based on legitimate interests, direct marketing, or research purposes.
- Rights relating to automated decision-making: to not be subject to decisions based solely on automated processing that have a significant effect on you.
To exercise any of these rights, please contact us using the details in Section 13. We will respond to your request within one month, though this may be extended by two months for complex requests. If you are dissatisfied with how we handle your data, you have the right to complain to the Gibraltar Regulatory Authority (GRA), the data protection supervisory authority in Gibraltar, at https://www.gra.gi/data-protection.
11. Children’s Privacy
Our website and services are intended for businesses and individuals aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe we have collected personal data from a child, please contact us so we can delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the services we offer. We will update the “last updated” date at the bottom of this page when we make changes. We encourage you to review this policy periodically. Where significant changes are made, we will provide a more prominent notice on our website or contact you directly where appropriate.
13. Contacting Us
If you have any questions about this Privacy Policy or how we handle your personal data, or if you wish to exercise any of your data protection rights, please contact us:
- By email: info@fulltechsolutions.co.uk
- Via our website: https://fulltechsolutions.co.uk/
Last updated: 14 September 2026
