Privacy Policy

Last updated: 23 September 2026

This Privacy Policy explains how Storm Vault Systems Ltd ("we", "us") handles personal data. It covers two different roles we have:

  • As controller, for information about visitors to our Site, prospective customers, and our customers' contacts (Sections 2 to 9).

  • As processor, for the data in the backups we store for customers (Section 10).

1. Who We Are

Storm Vault Systems Ltd, a company registered in England and Wales, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Contact for privacy matters: office@storm-vault.net.

2. Data We Collect as Controller

  • Site visit data: IP address, browser and device type, pages visited, referring page, and timestamps, processed automatically by our servers and hosting provider.

  • Enquiries and support: name, email address, phone number, company, and the content of your messages when you contact us or use our support channels.

  • Customer account and billing data: business contact details, billing address, plan details, and transaction status. Where you pay by card, payment is handled by a third-party payment provider and we do not store full card numbers.

  • Service operations data: metadata such as backup job status, timestamps, error logs, and restore-test results, used to run and support the Services.

  • Cookies: we do not use advertising cookies. If we use analytics or other non-essential cookies, we will ask for your consent where the law requires it.

3. How and Why We Use It

Purpose Legal basis (UK GDPR) Providing and supporting the Services Contract Billing, accounting, and tax records Contract; legal obligation Securing the Site and preventing abuse Legitimate interests Responding to enquiries Legitimate interests; steps before a contract Non-essential cookies or analytics (if used) Consent

4. Sharing

We share personal data only with service providers acting on our instructions (for example hosting, storage, email, support, payment, and accounting providers) and with authorities when the law requires. A list of our sub-processors is available on request at office@storm-vault.net. We do not sell personal data.

5. International Transfers

If personal data is transferred outside the UK, we use appropriate safeguards, such as the UK International Data Transfer Agreement or Addendum, or an adequacy decision.

6. Retention

We keep personal data only as long as necessary for the purposes above. Technical logs are kept for as long as needed for security and troubleshooting, then deleted or anonymised. Enquiries and support records are kept while relevant to our relationship with you. Billing and accounting records are kept for 6 years, as required by UK law.

7. Security

We use encryption in transit and at rest, access controls, monitoring, and regular testing to protect data. No system is completely secure, and we will notify affected customers and regulators of qualifying personal data breaches as the law requires.

8. Your Rights

Under UK GDPR you may request access to, correction of, deletion of, or restriction of your personal data, object to certain processing, request data portability, and withdraw consent where we rely on it. Contact office@storm-vault.net. You can complain to the Information Commissioner's Office (ICO) at ico.org.uk. If your data is in a customer's backup and you wish to exercise rights over it, please contact that customer first, as we act only on their instructions.

9. Children

Our Services are for businesses and not directed to children.

10. Customer Backup Data (We Act as Processor)

When you use our Services, we store and process the data you ask us to back up, which may include personal data of your own customers, employees, and users (for example website orders and customer records, emails, and documents).

  • Roles: you are the controller; we are your processor. We process this data only on your documented instructions, to provide the Services.

  • No other use: we do not use backup data for our own purposes, sell it, or use it for advertising.

  • Access: our staff access backup contents only when needed to provide support or restore data at your request, or to meet legal obligations.

  • Security: backups are encrypted in transit and at rest and stored offsite.

  • Sub-processors: we use the sub-processors available on request at office@storm-vault.net and will notify you of changes as set out in our Data Processing Agreement.

  • Deletion: on termination we delete or return backup data as set out in the Terms (Section 6).

  • Your obligations: you are responsible for having a lawful basis to back up personal data and for informing the individuals concerned, as required by data protection law.

  • DPA: the full Article 28 terms are in our Data Processing Agreement, which you can request at office@storm-vault.net.

11. Changes to This Policy

We may update this Policy from time to time. The "Last updated" date shows the latest version, and we will notify customers of material changes.

12. Contact

Storm Vault Systems Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom Email: office@storm-vault.netя