Legals
Welcome to Plug & Play’s privacy policy.
Plug & Play is committed to protecting the privacy and security of your personal data. This privacy policy contains important information about how we collect and use personal information about you, in accordance with data protection laws. It also explains your rights in relation to your personal data and how to contact us or supervisory authorities in the event you have a complaint.
Our website uses cookies to distinguish you from other users of our website. This helps us to provide you with a good experience when you browse our website and also allows us to improve our site.
We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about use of our site with our social media, advertising and analytics partners who may combine it with other information you’ve provided to them or that they’ve collected from your use of their services. You consent to our cookies if you continue to use our website.
Please see our Cookie Policy for further details.
Plug & Play Limited is a ‘data controller’ which means that we are responsible for deciding how we hold and use your personal information. When we say ‘we,’ ‘us’ or ‘our’ in this policy, we are referring to Plug & Play Limited and Plug & Play Design. We are registered as a data controller with the Information Commissioner’s Office as follows:
Plug And Play Design Ltd, 1 Portsmouth Road, Guildford, GU2 4BL
ICO Registration number: ZA313864
We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:
We also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data could be derived from your personal data but is not considered personal data in law as this data will not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific website feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy policy.
We do not collect any Special Categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data). Nor do we collect any information about criminal convictions and offences.
Where we need to collect personal data by law, or under the terms of a contract we have with you, and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with services). In this case, we may have to cancel a service you have with us but we will notify you if this is the case at the time.
We collect your personal data from you direct, through you completing the contact form on our website or emailing us. However, we may also collect information via/from third party sources. Those third party sources include but are not limited to:
We will only process your personal information where we have a lawful basis for doing so. Under the General Data Protection Regulation, there are six lawful bases. We have given some examples of where each basis applies, as follows:
We may use your data in the following ways:
In the course of carrying out our work and your instructions we sometimes need to share your personal data with third parties, including but not limited to:
We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.
Some of our external third parties are based outside of the UK so their processing of your personal data will involve a transfer of data outside the UK.
Whenever we transfer your personal data out of the UK, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the UK.
The security of your personal data is of paramount importance to us. We store the personal data we hold in our CRM, email accounts and cloud document storage. These services are password protected and encrypted.
Your data may be stored by third parties processing your data on our behalf (see who we share your data with) but in accordance with a data sharing agreement.
We retain your personal data in accordance with our Terms of Business and our Data Retention Policy. Different retention periods apply for different types of data. Please contact us if you would like to see a copy of our Data Retention Policy.
We strive to provide you with choices regarding certain personal data uses, particularly around marketing and advertising.
We may use your Identity, Contact, Technical and Usage Data to form a view on what we think you may want or need, or what may be of interest to you. This is how we decide which services and offers may be relevant for you (we call this marketing).
You will receive marketing communications from us if you have requested information from us or purchased services from us and you have not opted out of receiving that marketing.
We do not share your personal data with any third party for marketing purposes.
You can ask us or third parties to stop sending you marketing messages at any time by following the opt-out links on any marketing message sent to you or by contacting us at [email protected] at any time.
Where you opt out of receiving these marketing messages, this will not apply to personal data provided to us as a result of service purchase, service experience or other transactions.
Under the GDPR you can exercise a number of rights, as follows:
Right of access To be provided with a copy of your personal data
Right to rectification To require us to correct any mistakes in your personal data
Right to be forgotten To require us to delete your personal data – in certain situations
Right to restrict processing To require us to restrict processing of your personal data – in certain circumstances
Right to data portability To receive the personal data you provided to us, in a structured, commonly used and machine-readable format and/or transmit that data to a third party – in certain situations
Right to object To object to your personal data being processed for direct marketing and, in certain other situations, to our continued processing of your personal data
Rights related to automated decision-making The right not to be subject to a decision based solely on automated processing
You will not have to pay a fee to exercise any of your rights, however, we may charge a reasonable fee if a request for access is clearly unfounded or if it is deemed to be excessive. Alternatively, we may refuse to comply with a request in such circumstances. We will ask for proof of identity before we provide any personal information, to prevent any unauthorised access.
If you would like to exercise any of these rights, please contact us – see below ‘How to contact us.’
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
We have security measures which strive to prevent personal data from being accidentally lost, or used or accessed unlawfully. We follow strict procedures as to how your personal information is processed, to prevent any unauthorised person obtaining access to it. All personal information you register on our website will be located behind a firewall and we will use our strict procedures and security features to try to prevent unauthorised access to our systems. Unfortunately, the transmission of information via the internet is not completely secure and although we strive to protect your personal data, we cannot absolutely guarantee the security of your data. Those processing your information within our business and on our behalf, will do so only in an authorised manner and are subject to a duty of confidentiality.
We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.
If you would like to contact us to discuss any aspect of this Policy, please use the following details:
Email: [email protected]
Telephone: 01483 276699
Address: Innovation House, 2-6 High Street, Guildford, GU2 4AJ
The Managing Director is responsible for Data Protection Compliance.
We hope that we can resolve any query or concern you may raise about our use of your information. However, the General Data Protection Regulation also gives you the right to lodge a complaint with a supervisory authority, particularly in the European Union (or European Economic Area) state where you work, normally live or where any alleged infringement of data protection laws occurred. The supervisory authority in the UK is the Information Commissioner who may be contacted at https://ico.org.uk/concerns or telephone: +44 0303 123 1113.
This policy was updated in August 2018 and subsequently updated in March 2019.
It was again reviewed without changes on the 14th May 2020.
It was reviewed without changes on 14th June 2021.
This policy was updated in August 2026.