Privacy and personal information
Privacy Notice
This notice explains what personal information JM Restart Limited uses, why we use it, who we may share it with and the choices available to you.
Last updated: 4 September 2026
Who we are
JM Restart Limited is a company registered in England and Wales under company number 09488029. Our registered office is Suite D4 & D5, Whitehouse Distribution Centre, 46 White House Road, Ipswich, Suffolk, England, IP1 5NX.
For the personal information described in this notice, JM Restart Limited is normally the data controller. During some IT support, cloud, backup, security or managed-service work, we may instead handle information on a customer’s documented instructions as their data processor. The relevant quotation, contract, service schedule or data-processing agreement provides further detail where this applies.
You can contact us about privacy by emailing [email protected], calling 01473 527430, or writing to our registered office. Our ICO registration number is ZA375055.
Information we may collect
- Enquiry and contact details: your name, organisation, email address, telephone number, enquiry type, message and correspondence.
- Customer and commercial records: quotations, contracts, service details, account contacts, invoices, payment references and records of agreed work.
- Support and technical records: ticket information, relevant device or service identifiers, diagnostic results, security events, remote-support session records and information needed to deliver an agreed service.
- Website and security information: IP address, browser and device information, server logs, security events and your cookie choices.
- Information supplied by other people: for example, an employer, colleague, authorised family member, supplier or service provider asking us to assist you or an organisation.
Please do not send passwords, authentication codes, full payment-card information or unnecessary sensitive information through our website form or ordinary email.
Why we use personal information
We use personal information only where we have a lawful reason. Depending on the circumstances, this may be necessary to take steps at your request before entering a contract, to perform a contract, to meet a legal obligation, for our legitimate interests, or because you have given consent.
- Responding to enquiries and preparing quotations: steps requested before a contract and our legitimate interest in communicating with potential customers.
- Delivering and managing services: performance of a contract and our legitimate interest in providing secure, accountable support.
- Billing, accounting and legal records: performance of a contract and compliance with legal obligations.
- Protecting customers, systems and our business: our legitimate interests in security, fraud prevention, service quality, audit and the establishment or defence of legal claims.
- Optional analytics, advertising and marketing technologies: consent where it is required. These technologies must remain disabled until the appropriate choice has been made.
- Direct marketing: consent or another lawful route permitted by applicable marketing rules. You can opt out at any time.
Where we rely on legitimate interests, we consider the benefit of the processing, whether it is necessary and its impact on the people involved. You can object where this lawful basis applies.
Who we may share information with
We do not sell personal information. We may share only the information reasonably needed with:
- website hosting, email delivery, cloud productivity, security, backup, remote-support and other technology providers;
- payment providers such as GoCardless where a customer agrees to pay by Direct Debit;
- authorised employees, technicians, subcontractors and specialist partners who need the information to perform agreed work;
- accountants, insurers, legal advisers and other professional advisers;
- regulators, courts, law-enforcement bodies or other authorities where disclosure is required or permitted by law; and
- a buyer, investor or successor where our business or relevant assets are reorganised or transferred, subject to appropriate confidentiality and data-protection controls.
Some providers may process information outside the United Kingdom. Where this happens, we use an applicable adequacy arrangement, contractual safeguards or another lawful transfer mechanism. You can ask us for more information about the safeguards relevant to your information.
How long we keep information
- General enquiries that do not progress: normally up to six months after the last meaningful contact.
- Customer, contract, invoicing and tax records: for the applicable legal, accounting, contractual and claims periods, normally up to six years after the relevant relationship or transaction unless a different period is required.
- Primary remote-support portal logs: normally up to twelve months. Records copied into a customer file follow the relevant support, security or contract record period.
- Temporary encrypted backups created before agreed technical work: normally removed within three months unless an earlier return or deletion is agreed, or a legal reason requires otherwise.
- Security and server logs: for a proportionate period based on security, diagnostic and hosting requirements.
- Cookie records: for the periods shown in our Cookie Policy.
If an enquiry becomes a quotation, customer relationship, support ticket, complaint, contract or legal matter, the relevant record may move to the retention period for that purpose. We review retention and securely delete or anonymise information when it is no longer needed.
Your data-protection rights
Depending on the circumstances, you may have rights to access, correct, erase or restrict the use of your personal information, receive certain information in a portable format, and object to processing. Where we rely on consent, you can withdraw it at any time without affecting earlier lawful processing.
We do not currently use website information to make decisions based solely on automated processing that produce legal or similarly significant effects.
To exercise a right, email [email protected]. We may need to verify your identity before acting. If you are unhappy with our response, please tell us first so we can try to resolve the matter. You also have the right to complain to the Information Commissioner’s Office.
Security and changes to this notice
We use proportionate technical and organisational measures to protect personal information. No system can remove every risk, so please use an appropriate secure route and avoid sending secrets through the website form.
We may update this notice when our services, providers or legal responsibilities change. The date at the top shows the latest published version. Material changes will be highlighted where appropriate.
