
Privacy Policy
Scope and Controller
- This Privacy Policy explains how Gotschna Limited ("Gotschna", "we", "us", "our") collects, uses, stores and protects personal data in the following contexts:
- When you are a customer
- When you are a prospective customer
- When you browse our website
- When you contact us as a supplier, partner, journalist, or other third party
- Data Controller: Gotschna Limited
- We aim to collect and retain the minimum personal data necessary to operate our business and deliver services.
Categories of Personal Data We Collect
- Customers - We may hold:
- Name, company name, job title
- Postal address, email address, telephone number
- User account credentials and security information
- Services purchased and associated configuration data
- Support tickets, emails, and other communications
- Call recordings (where applicable)
- Billing, invoicing and payment records
- Technical logs related to service operation (e.g., IP addresses, access logs)
- Prospective Customers - We may hold:
- Name and contact details
- Company name
- Records of enquiries and correspondence
- Basic technical logs (e.g., IP addresses)
- Website Visitors (Just Browsing) - We generate limited server logs which may include:
- IP address
- Date/time of access
- Pages requested
- Browser or device metadata
- We do not attempt to identify casual visitors.
- Other Contacts (Suppliers, Partners, Press, General Enquiries) - We may hold:
- Name and contact details
- Records of correspondence
- Server log data (including IP address)
How We Use Personal Data
- Service Provision - Deliver contracted services, configure, maintain and support systems, provide customer assistance. Legal basis: Performance of contract.
- Billing and Financial Administration - Generate invoices, process payments, maintain accounting records. Legal basis: Performance of contract / Legal obligation.
- Security and Abuse Prevention - Protect infrastructure, detect misuse or attacks, maintain service integrity. Legal basis: Legitimate interest / Legal obligation.
- Communications and Quality Assurance - Respond to enquiries, maintain service records, training and service quality improvement, call recording (where used). Legal basis: Legitimate interest.
- Legal and Regulatory Compliance - Respond to lawful requests, meet statutory obligations, defend legal claims. Legal basis: Legal obligation.
- Business Relationship Management - For suppliers, partners and other contacts: manage commercial relationships, evaluate services or proposals. Legal basis: Legitimate interest / Contract.
Log Files and Technical Data
- We generate minimal log data necessary to:
- Operate services
- Diagnose faults
- Maintain security
- Logs may include IP addresses and access timestamps.
- If you prefer your real IP address not to be logged when browsing, you may use privacy-preserving technologies such as VPNs or Tor.
Cookies and Similar Technologies
- Our websites may use cookies or similar technologies to:
- Operate essential site functionality
- Improve performance and reliability
- You can control cookies through your browser settings. Disabling cookies may affect functionality.
Sharing of Personal Data
- We do not sell personal data.
- We may share data only where necessary:
- With service providers required to deliver contracted services
- With payment processors
- With upstream technology partners involved in delivering specific services
- With professional advisers (e.g., accountants, solicitors)
- Where legally required by courts, regulators or law enforcement
- All sharing is limited to what is necessary for the purpose.
International Data Transfers
- We do not routinely transfer personal data outside the UK or EEA.
- If international processing is required as part of delivering a service, appropriate safeguards will be applied.
Data Retention
- We retain personal data only for as long as necessary to:
- Provide services
- Meet legal obligations
- Resolve disputes
- Enforce agreements
- Retention periods vary by data type.
- If you choose not to provide required personal data, we may be unable to provide services.
Security Measures
- We implement appropriate technical and organisational measures to protect personal data, including:
- Access controls
- Authentication systems
- Network security controls
- Secure storage practices
- No system is guaranteed to be perfectly secure, but we design controls proportionate to risk.
Your Data Protection Rights
- Under UK data protection law, you may have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase data in certain circumstances
- Restrict processing
- Object to processing
- Data portability
- Withdraw consent (where applicable)
- Rights vary depending on legal basis and context.
Contact Details
- For privacy enquiries or rights requests, please visit our website contact page
- We may require reasonable proof of identity before processing requests.
Policy Updates
- This Privacy Policy may be updated periodically. The latest version will always be published on our website.

