Trust, security and transparency

Releasing the potential of people and technology, securely.

Our Trust Centre brings together the compliance information, data protection resources, subprocessors and FAQs customers commonly request during security and supplier reviews.

Compliance

Data collection

Updated

Types of personal data processed

  • Information about current, past and prospective customers, suppliers, employees and other third parties.
  • Personal data such as names, contact details, IP addresses and identifiable information.
  • Client-owned data processed as part of managed IT services and support delivery.

Sources of data

  • Directly from data subjects via email, phone, forms and written communication.
  • From business partners, subcontractors and service providers.
  • From systems and platforms used to provide IT services.

How we use data

Personal data is processed to deliver IT support, managed services, security monitoring, service communication, billing and contractual obligations. Processing is carried out lawfully, fairly and transparently in line with GDPR.

Data storage and security

Personal data is stored on secure local and cloud-based systems with strict access controls, authentication, encryption and monitoring. Access is restricted based on job role and protected using industry standard controls including multi-factor authentication and endpoint security.

Controls

Updated

Infrastructure security

  • Encryption key access restricted
  • Unique account authentication enforced
  • Production system access restricted
  • Firewall protection enforced
  • Network segmentation implemented
  • Secure remote access controls

Organisational security

  • Anti-malware technology deployed
  • Staff security training completed
  • Role-based access controls
  • Acceptable use policies enforced
  • Access reviews conducted

Service security

  • Data encrypted in transit
  • Endpoint detection enabled
  • Patch management enforced
  • Continuous monitoring
  • Vulnerability management processes

Internal procedures

  • Incident response process defined
  • Backup and recovery in place
  • Configuration management enforced
  • Change control processes applied

Data and privacy

  • Data retention policies enforced
  • Data subject rights supported
  • Secure data transfer processes

Subprocessors

Updated

To deliver our services, Fluid IT uses trusted third-party suppliers who may process personal data on our behalf. Below is a list of these providers, the purpose of processing, and data location information.

Subprocessor Purpose Location / region Data categories Status
ConnectWise Ltd / ConnectWise LLC (BrightGauge, CPQ, PSA, WisePay, Automate, ScreenConnect, ITBoost) CRM, service desk, reporting and system management EU / US / AU Contact details, client-owned data, device identifiers Active
Gradwell (Onecom Group) Telephony and remote access services EU Contact details Active
Microsoft Office 365 Hosted email, office tools and document management UK & EEA Contact details, client-owned data, device identifiers Active
Google Workspace Hosted email, office tools and document management EU / US Contact details Active
Microsoft 365 (Fluid IT internal) Collaboration (Exchange, SharePoint, OneDrive, Teams) UK & EEA Contact details, communications, documents Active
NinjaOne LLC Remote Monitoring & Management (RMM), Vulnerability Management US, UK Extension to EU-U.S. DPF, SCCs where applicable IP addresses, Device names, Hardware/software inventories, Usernames, System logs, File and folder names containing personal data Active
Axcient Backup and business continuity EU Contact details, client-owned data Active
Acronis Backup and business continuity EU Contact details, client-owned data Active
CloudAlly (OpenText) Backup and cloud data protection EU / US Contact details, client-owned data Active
Addigy Device management (Macs and iOS) US Device identifiers, client-owned data Active
MigrationWiz Data and email migration services US / Global Contact details, client-owned data Active
MCloud Server and email migration services UK Contact details, client-owned data Active
AppRiver Email filtering UK Contact details, email metadata Active
INKY Email filtering and protection EU Contact details, email metadata Active
PIA Trade Co Pty Process automation EU Contact details, Device identifiers Active
Auvik Network monitoring and threat detection EU Device identifiers Active
SentinelOne Endpoint detection and response (EDR) EU Device identifiers, client-owned data Active
Rawstream Content filtering EU Device identifiers, client-owned data Active
usecure Awareness training EU Customer personally identifiable information, Employee personally identifiable information Active
Keeper Password manager EU Device identifiers, Customer personally identifiable information, Employee personally identifiable information Active
Idnet / Convergence Group Connectivity and telephony provision UK Contact details Active
GoDaddy / Gandi / UKWSD / Krystal Domain registration, DNS and hosting UK / EU Administrative contact details Active
Open Mesh / Aruba (HPE) / CloudTrax / Grandstream WiFi and network infrastructure management UK / EU Device identifiers, contact details Active
Adobe Cloud storage of documents and media EU / US Client-owned data, contact details Active
Upstreamly Accounts processing and invoice management UK Contact details Active
Xero Invoice processing and account management UK & EEA Contact details Active
GoCardless Payment processing UK & EEA Account holder names and contact details Active
Ingram Micro / AppRiver / Giacom / Pax8 / Brigantia Cloud licensing provision UK / EU Contact details Active
Ingram Micro / Tech Data / Utility Networks / SEG / Exertis / BNC Distribution Hardware supply and logistics UK / EU Delivery contact details Active

Resources

FAQs

Use the resource link above or email salesteam@fluid-it.com with your request for information.
Yes, our current certification can be found here: https://registry.blockmarktech.com/organisations/GBLTD05445643/
Our ICO certificate can be viewed here: blob:https://trusthub.info/136232ea-61f3-423a-93c2-093631ddd027
Data subjects must make a formal request for information Fluid IT holds about them. This must bemade in writing. Once a request is made, we will respond in accrodance with the governing requirments set by GDPR UK and the ICO.