Website privacy notice
ICT Hero Ltd
Last updated 2/7/26
1. Who we are
ICT Hero Ltd (“ICT Hero”, “we”, “us”, “our”) provides managed IT support, identity and access management, IT asset management, remote monitoring and management (RMM), and related reseller and technology services to business customers.
Registered address: ICT Hero Ltd, Camburgh House, 27 New Dover Road, Canterbury, Kent, CT1 3DN
Contact: support@icthero.co.uk
2. What this policy covers
This policy applies to personal data processed through:
- The ICT Hero Helpdesk service and mobile apps
- The ICT Hero Identity Provider (IdP) and single sign-on services
- The ICT Hero Asset Management platform
- The ICT Hero Remote Monitoring and Management (RMM) platform
- Managed IT support (MSP) services delivered under a client services agreement
- Reseller services (software and hardware licensing procured on a client’s behalf)
- The ICT Hero applications portal and related web and iOS tools
- icthero.co.uk and other ICT Hero websites
- Our own accounts, billing and marketing systems
Where a specific product or client contract has its own privacy or data processing terms, those terms take precedence for that product to the extent they conflict with this general notice.
3. Our role: when we are a controller and when we are a processor
Because ICT Hero delivers IT services on behalf of business clients, our role under UK GDPR differs depending on whose data is involved:
3.1 Where we are the controller
We are the controller for personal data relating to our own business relationships and operations, including: our clients’ business contacts, billing and account data, marketing and enquiry data, and visitors to our websites.
3.2 Where we are the processor
Where we deliver Helpdesk, IdP, Asset Management, RMM, or wider MSP services to a client, we typically process personal data belonging to that client’s own staff or end users (for example, device information, login activity, or ticket content about a named employee) on the client’s instructions. In that relationship, our client is the controller and ICT Hero is the processor.
Our processing on a client’s behalf is, or will be, governed by a Data Processing Agreement (DPA) with that client, which sets out the scope, duration, and purpose of processing, the categories of data involved, and our obligations regarding sub-processors, security, and breach notification. This public notice describes our general practices; the DPA is the governing document for processor activity and takes precedence between ICT Hero and the relevant client.
3.3 Where we license a platform to a business for their own customer use
In addition to using our own Helpdesk, Asset Management, and RMM platforms to support our clients directly, we also license these platforms — Helpdesk, Asset Management, and Remote Monitoring and Management (RMM) — to other businesses, who use them to manage support, assets, or monitored devices for their own customer base (for example, an IT reseller running our RMM platform to monitor devices belonging to their own clients, or an organisation running our Asset Management platform to track hardware belonging to their own clients).
Where an organisation licenses one of our platforms to support, monitor, or manage assets on behalf of its own customers, that organisation is the controller of any personal data it enters into or generates within the platform relating to those customers, and ICT Hero acts as a processor and platform provider on that organisation’s instructions — in the same way as described for Helpdesk above.
It is that organisation’s responsibility to manage the personal data within the platform in line with its own obligations to its customers, including removing data it no longer wishes to retain, whether during an active subscription or after it stops using our services. ICT Hero does not proactively review, filter, or delete such data on an organisation’s behalf, but we can assist with data export or deletion on reasonable request, in line with the applicable service agreement.
4. Information we collect
The categories below are collected both where ICT Hero delivers Helpdesk, Asset Management, or RMM services directly to its own clients, and where a business licenses one of these platforms to manage support, assets, or monitored devices for its own separate customer base (see Section 3.3) — in the latter case, the data described may relate to that licensee’s customers rather than to ICT Hero’s direct relationship.
4.1 Information you or your organisation provide directly
- Name, job title, and business contact details — when an account is created for you, or when you contact us directly
- Ticket content — subject, description, and attachments (including photos) submitted when raising or responding to a support request
- Communications — messages sent to or from our support, sales, or account email addresses
- Identity data — where the IdP or single sign-on service is used, credentials (never stored in plain text), authentication factors, and access history
- Asset data — device names, hardware/software inventory, licensing, and configuration details recorded in the Asset Management platform
- Marketing and enquiry data — name, business email, and details submitted via contact or enquiry forms
4.2 Information collected automatically
- Device and endpoint telemetry — where RMM agents are deployed on client devices, technical data such as device health, patch status, running processes, and performance metrics, together with recent interactive sign-in history (username and timestamp) and recent system error/warning events captured from the device for troubleshooting and security monitoring
- Device token — your device’s push-notification token, where push notifications are enabled in an ICT Hero iOS app
- IP address and browser information — collected automatically when you access our web services, for security and operational purposes
- Session data — authentication session identifiers to keep you logged in
- Usage logs — records of actions taken within our platforms (e.g. ticket opened, reply sent, asset updated, login event) for audit and support purposes
4.3 Information from third parties
- Sign-in providers — if you sign in via Google or Microsoft, we receive your name and email address from that provider. We do not receive your password or other account data held by the provider.
- Organisation account details — your employer or the IT provider managing your account may provide your name and contact details to grant you access to our services.
- Reseller and vendor partners — where we resell or provision third-party software or hardware on your organisation’s behalf, the relevant vendor may share licence or provisioning data with us, and we may share your business contact details with them to activate or support that licence.
5. How we use your information
| Purpose | Legal basis |
| Providing Helpdesk, IdP, Asset Management, RMM and wider MSP services | Contract performance / Legitimate interests |
| Providing reseller services (software/hardware licensing) | Contract performance |
| Sending service notifications by email and push notification | Legitimate interests |
| Authenticating your identity when you log in | Contract performance / Legitimate interests |
| Auditing actions within our systems for security purposes | Legitimate interests |
| Monitoring endpoint and network health via RMM | Contract performance (on client instruction) |
| Generating invoices and managing accounts (via Xero) | Contract performance / Legal obligation |
| Direct marketing to business contacts | Consent, or legitimate interests / PECR “soft opt-in” for existing business relationships |
| Improving and maintaining our services, including limited use of AI tools (see Section 6) | Legitimate interests |
We do not sell personal data, and we do not use personal data for marketing without an appropriate legal basis as set out above.
6. Use of AI tools
We use AI-assisted tools from third-party providers — currently including Anthropic, Google, and OpenAI — to help with tasks such as drafting or triaging support responses, summarising ticket content, and improving internal workflows.
6.1 What is shared
Only our Helpdesk applications send data to AI providers, and only in order to help generate a response to the person raising the request, within defined guardrail parameters. This happens only where the organisation using the Helpdesk platform has enabled the feature for their account. Where enabled, relevant ticket text and, where relevant, image attachments may be sent to the provider for that purpose. Other ICT Hero platforms (IdP, Asset Management, RMM) do not send data to AI providers.
6.2 Training use
We use these providers under business or API terms under which our data is excluded from being used to train the providers’ underlying models.
6.3 Internal use for future ticket resolution
Separately from the AI providers named above, resolutions to past support tickets are indexed within the Helpdesk platform itself so that they can be used to help resolve similar tickets in future. This is an internal ICT Hero / Helpdesk platform function, not a transfer to a third-party AI provider, and is subject to the same controller/processor position set out in Sections 3.2 and 3.3 — i.e. where this applies to a client’s or licensee’s own ticket data, it is carried out on their instructions and for their benefit in delivering their support service.
6.4 Human oversight
AI-assisted output is used as a drafting or triage aid; it does not replace human review of support requests, and no fully automated decision with legal or similarly significant effect is made about you using these tools.
7. Push notifications (iOS apps)
If you grant permission in an ICT Hero iOS app, we send push notifications for events such as ticket updates, replies, or assignments. Your device token is stored solely for this purpose and can be disabled at any time in your device’s Settings → Notifications.
8. Attachments and images
Files and images attached to support tickets are retained for as long as the relevant account or platform subscription remains active, and remain on our systems until the end user, or the organisation responsible for that data (see Section 3), requests their removal. We do not currently apply an automatic time-based deletion to ticket data; removal happens on request. We are working towards introducing an automatic backstop deletion period and will update this notice once that is in place.
Images uploaded via an iOS app (from camera or photo library) are sent directly to the relevant platform and are not separately accessed or stored by ICT Hero beyond that platform.
9. Who we share your information with
We share personal data only where necessary to deliver our services:
| Recipient | Purpose |
| Your IT provider / managing partner | If your organisation receives services via an ICT Hero partner MSP, that partner can access tickets and account information within their managed scope |
| Microsoft (Microsoft 365 tenant) | Email, calendar, file storage, and collaboration services used to deliver support and run our business |
| Google (Google Workspace tenant) | Email, file storage, and collaboration services used to deliver support and run our business |
| Anthropic, Google, OpenAI (AI providers) | AI-assisted drafting, triage, and summarisation as described in Section 6 |
| Xero | Billing and invoice generation (business contact and billing information only) |
| Apple | Device tokens transmitted via Apple’s Push Notification service (APNs) to deliver notifications |
| RMM and IdP platform vendors | Underlying software platforms used to deliver monitoring and identity services |
| Reseller and licensing vendors | Provisioning and support of software/hardware licensed on your organisation’s behalf |
| Google Analytics | Website analytics, only after cookie consent — see Section 13 |
| SMTP2GO | Sending marketing and service emails, and tracking opens/clicks — see Section 13 |
| Companies House | Looking up the company associated with a website enquiry’s email domain (domain only, not the full email address) |
| Hosting providers | Our services are hosted in the UK; some data may also be held at ICT Hero offices |
We do not sell your personal data to any third party.
10. International data transfers
Our core infrastructure is hosted in the UK, and data may also be held at ICT Hero’s own offices. However, some third-party providers we use — including certain AI providers — may process data outside the UK.
Where AI features are enabled, ticket content may be processed by Anthropic or OpenAI in the United States, or by Google (Gemini) in the European Union. Transfers to the United States rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, as published by each provider for UK customers; processing within the EU relies on the UK’s adequacy arrangements with the EU. Supplementary measures include encryption in transit and contractual exclusion of customer data from model training.
11. Data retention
| Data type | Retention period |
| Support tickets, replies, and attachments (ICT Hero’s own support of its clients) | Retained while the account is active, and until removal is requested. No automatic time-based deletion is currently applied to ticket data; we are working towards introducing one |
| RMM device metrics, cron logs, and rule logs (ICT Hero’s own management of its clients’ devices) | We do not retain this data for longer than 90 days — automatically enforced |
| RMM device alerts, script run history, and asset inventory/asset history (ICT Hero’s own management of its clients’ devices/assets) | Retained while the underlying client contract is active, and until removal is requested. No automatic time-based deletion is currently applied to this data; we are working towards introducing one |
| Data entered into a licensed platform (Helpdesk, Asset Management, or RMM) by an organisation for its own customers | Retained at that organisation’s discretion for as long as their subscription is active. That organisation is responsible for removing data it no longer wishes to retain, including after it stops using the service. ICT Hero can assist with export or deletion on request but does not delete this data proactively. |
| Account and identity information | Retained while the account is active; deleted within 30 days of account closure on request |
| Helpdesk platform audit log | We do not retain this data for longer than 90 days — automatically enforced |
| Asset Management and Identity Provider (IdP) audit logs | Retained until removal is requested. These logs are currently designed to be append-only for security-audit purposes and do not yet have an automatic deletion process; we are working towards introducing a defined retention period |
| Backups | We do not retain backup copies for longer than 90 days |
| Push device tokens | Deleted when you log out of the app or uninstall it |
| Marketing and enquiry data | Until you opt out |
| Billing records | 7 years (legal requirement) |
Where a stated period above is a maximum rather than a fixed schedule, we may delete data sooner in the ordinary course of operating the service.
12. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data (subject to legal obligations)
- Object to processing based on legitimate interests
- Data portability — receive your data in a structured format
- Withdraw consent where processing is based on consent
To exercise any of these rights, email support@icthero.co.uk. We will respond within 30 days.
If your organisation is the controller of your data (see Section 3), we may direct your request to them where they are best placed to respond.
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.
13. Cookies and tracking
13.1 Strictly necessary cookies
Our platforms use session cookies that are strictly necessary for authentication and core functionality (e.g. keeping you logged in). These do not require consent and cannot be switched off.
13.2 Analytics cookies
Our websites use Google Analytics, together with analytics provided by our hosting platform, to understand how visitors use our sites (e.g. pages viewed, general location, device type). These cookies are not strictly necessary and are only set once you consent via our cookie banner. Legal basis: consent.
13.3 Marketing email tracking
We use SMTP2GO to send marketing and service-related emails. SMTP2GO’s tracking features record whether an email has been opened and whether links within it have been clicked, which we use to understand engagement with our communications and improve them. Legal basis: consent, or legitimate interests / PECR “soft opt-in” for existing business contacts, consistent with Section 5.
13.4 Managing your preferences
A cookie banner is shown on first visit to our websites, allowing you to accept or reject non-essential cookies such as analytics.
14. Security
We protect personal data using:
- HTTPS/TLS encryption for all data in transit
- Encrypted storage for sensitive content (e.g. Secure Send feature uses AES-256-CBC)
- Access controls — data is scoped to your organisation; staff can only see data within their access level
- Authentication via the ICT Hero Identity Provider, with multi-factor authentication support
- Endpoint monitoring via our RMM platform to detect and respond to security issues on managed devices
15. Children’s privacy
Our services are intended for business use only and are not directed at children under 13. We do not knowingly collect personal data from children.
16. Changes to this policy
We will update this page when this policy changes and update the “Last updated” date above. Continued use of our services after changes constitutes acceptance of the updated policy.
17. Contact
ICT Hero Ltd
Camburgh House, 27 New Dover Road, Canterbury, Kent, CT1 3DN
Email: support@icthero.co.uk
Website: icthero.co.uk
