Privacy Notice

Website privacy notice

ICT Hero Ltd

Last updated 2/7/26

1. Who we are

ICT Hero Ltd (“ICT Hero”, “we”, “us”, “our”) provides managed IT support, identity and access management, IT asset management, remote monitoring and management (RMM), and related reseller and technology services to business customers.

Registered address: ICT Hero Ltd, Camburgh House, 27 New Dover Road, Canterbury, Kent, CT1 3DN

Contact: support@icthero.co.uk

2. What this policy covers

This policy applies to personal data processed through:

  • The ICT Hero Helpdesk service and mobile apps
  • The ICT Hero Identity Provider (IdP) and single sign-on services
  • The ICT Hero Asset Management platform
  • The ICT Hero Remote Monitoring and Management (RMM) platform
  • Managed IT support (MSP) services delivered under a client services agreement
  • Reseller services (software and hardware licensing procured on a client’s behalf)
  • The ICT Hero applications portal and related web and iOS tools
  • icthero.co.uk and other ICT Hero websites
  • Our own accounts, billing and marketing systems

Where a specific product or client contract has its own privacy or data processing terms, those terms take precedence for that product to the extent they conflict with this general notice.

3. Our role: when we are a controller and when we are a processor

Because ICT Hero delivers IT services on behalf of business clients, our role under UK GDPR differs depending on whose data is involved:

3.1 Where we are the controller

We are the controller for personal data relating to our own business relationships and operations, including: our clients’ business contacts, billing and account data, marketing and enquiry data, and visitors to our websites.

3.2 Where we are the processor

Where we deliver Helpdesk, IdP, Asset Management, RMM, or wider MSP services to a client, we typically process personal data belonging to that client’s own staff or end users (for example, device information, login activity, or ticket content about a named employee) on the client’s instructions. In that relationship, our client is the controller and ICT Hero is the processor.

Our processing on a client’s behalf is, or will be, governed by a Data Processing Agreement (DPA) with that client, which sets out the scope, duration, and purpose of processing, the categories of data involved, and our obligations regarding sub-processors, security, and breach notification. This public notice describes our general practices; the DPA is the governing document for processor activity and takes precedence between ICT Hero and the relevant client.

3.3 Where we license a platform to a business for their own customer use

In addition to using our own Helpdesk, Asset Management, and RMM platforms to support our clients directly, we also license these platforms — Helpdesk, Asset Management, and Remote Monitoring and Management (RMM) — to other businesses, who use them to manage support, assets, or monitored devices for their own customer base (for example, an IT reseller running our RMM platform to monitor devices belonging to their own clients, or an organisation running our Asset Management platform to track hardware belonging to their own clients).

Where an organisation licenses one of our platforms to support, monitor, or manage assets on behalf of its own customers, that organisation is the controller of any personal data it enters into or generates within the platform relating to those customers, and ICT Hero acts as a processor and platform provider on that organisation’s instructions — in the same way as described for Helpdesk above.

It is that organisation’s responsibility to manage the personal data within the platform in line with its own obligations to its customers, including removing data it no longer wishes to retain, whether during an active subscription or after it stops using our services. ICT Hero does not proactively review, filter, or delete such data on an organisation’s behalf, but we can assist with data export or deletion on reasonable request, in line with the applicable service agreement.

4. Information we collect

The categories below are collected both where ICT Hero delivers Helpdesk, Asset Management, or RMM services directly to its own clients, and where a business licenses one of these platforms to manage support, assets, or monitored devices for its own separate customer base (see Section 3.3) — in the latter case, the data described may relate to that licensee’s customers rather than to ICT Hero’s direct relationship.

4.1 Information you or your organisation provide directly

  • Name, job title, and business contact details — when an account is created for you, or when you contact us directly
  • Ticket content — subject, description, and attachments (including photos) submitted when raising or responding to a support request
  • Communications — messages sent to or from our support, sales, or account email addresses
  • Identity data — where the IdP or single sign-on service is used, credentials (never stored in plain text), authentication factors, and access history
  • Asset data — device names, hardware/software inventory, licensing, and configuration details recorded in the Asset Management platform
  • Marketing and enquiry data — name, business email, and details submitted via contact or enquiry forms

4.2 Information collected automatically

  • Device and endpoint telemetry — where RMM agents are deployed on client devices, technical data such as device health, patch status, running processes, and performance metrics, together with recent interactive sign-in history (username and timestamp) and recent system error/warning events captured from the device for troubleshooting and security monitoring
  • Device token — your device’s push-notification token, where push notifications are enabled in an ICT Hero iOS app
  • IP address and browser information — collected automatically when you access our web services, for security and operational purposes
  • Session data — authentication session identifiers to keep you logged in
  • Usage logs — records of actions taken within our platforms (e.g. ticket opened, reply sent, asset updated, login event) for audit and support purposes

4.3 Information from third parties

  • Sign-in providers — if you sign in via Google or Microsoft, we receive your name and email address from that provider. We do not receive your password or other account data held by the provider.
  • Organisation account details — your employer or the IT provider managing your account may provide your name and contact details to grant you access to our services.
  • Reseller and vendor partners — where we resell or provision third-party software or hardware on your organisation’s behalf, the relevant vendor may share licence or provisioning data with us, and we may share your business contact details with them to activate or support that licence.

5. How we use your information

PurposeLegal basis
Providing Helpdesk, IdP, Asset Management, RMM and wider MSP servicesContract performance / Legitimate interests
Providing reseller services (software/hardware licensing)Contract performance
Sending service notifications by email and push notificationLegitimate interests
Authenticating your identity when you log inContract performance / Legitimate interests
Auditing actions within our systems for security purposesLegitimate interests
Monitoring endpoint and network health via RMMContract performance (on client instruction)
Generating invoices and managing accounts (via Xero)Contract performance / Legal obligation
Direct marketing to business contactsConsent, or legitimate interests / PECR “soft opt-in” for existing business relationships
Improving and maintaining our services, including limited use of AI tools (see Section 6)Legitimate interests

We do not sell personal data, and we do not use personal data for marketing without an appropriate legal basis as set out above.

6. Use of AI tools

We use AI-assisted tools from third-party providers — currently including Anthropic, Google, and OpenAI — to help with tasks such as drafting or triaging support responses, summarising ticket content, and improving internal workflows.

6.1 What is shared

Only our Helpdesk applications send data to AI providers, and only in order to help generate a response to the person raising the request, within defined guardrail parameters. This happens only where the organisation using the Helpdesk platform has enabled the feature for their account. Where enabled, relevant ticket text and, where relevant, image attachments may be sent to the provider for that purpose. Other ICT Hero platforms (IdP, Asset Management, RMM) do not send data to AI providers.

6.2 Training use

We use these providers under business or API terms under which our data is excluded from being used to train the providers’ underlying models.

6.3 Internal use for future ticket resolution

Separately from the AI providers named above, resolutions to past support tickets are indexed within the Helpdesk platform itself so that they can be used to help resolve similar tickets in future. This is an internal ICT Hero / Helpdesk platform function, not a transfer to a third-party AI provider, and is subject to the same controller/processor position set out in Sections 3.2 and 3.3 — i.e. where this applies to a client’s or licensee’s own ticket data, it is carried out on their instructions and for their benefit in delivering their support service.

6.4 Human oversight

AI-assisted output is used as a drafting or triage aid; it does not replace human review of support requests, and no fully automated decision with legal or similarly significant effect is made about you using these tools.

7. Push notifications (iOS apps)

If you grant permission in an ICT Hero iOS app, we send push notifications for events such as ticket updates, replies, or assignments. Your device token is stored solely for this purpose and can be disabled at any time in your device’s Settings → Notifications.

8. Attachments and images

Files and images attached to support tickets are retained for as long as the relevant account or platform subscription remains active, and remain on our systems until the end user, or the organisation responsible for that data (see Section 3), requests their removal. We do not currently apply an automatic time-based deletion to ticket data; removal happens on request. We are working towards introducing an automatic backstop deletion period and will update this notice once that is in place.

Images uploaded via an iOS app (from camera or photo library) are sent directly to the relevant platform and are not separately accessed or stored by ICT Hero beyond that platform.

9. Who we share your information with

We share personal data only where necessary to deliver our services:

RecipientPurpose
Your IT provider / managing partnerIf your organisation receives services via an ICT Hero partner MSP, that partner can access tickets and account information within their managed scope
Microsoft (Microsoft 365 tenant)Email, calendar, file storage, and collaboration services used to deliver support and run our business
Google (Google Workspace tenant)Email, file storage, and collaboration services used to deliver support and run our business
Anthropic, Google, OpenAI (AI providers)AI-assisted drafting, triage, and summarisation as described in Section 6
XeroBilling and invoice generation (business contact and billing information only)
AppleDevice tokens transmitted via Apple’s Push Notification service (APNs) to deliver notifications
RMM and IdP platform vendorsUnderlying software platforms used to deliver monitoring and identity services
Reseller and licensing vendorsProvisioning and support of software/hardware licensed on your organisation’s behalf
Google AnalyticsWebsite analytics, only after cookie consent — see Section 13
SMTP2GOSending marketing and service emails, and tracking opens/clicks — see Section 13
Companies HouseLooking up the company associated with a website enquiry’s email domain (domain only, not the full email address)
Hosting providersOur services are hosted in the UK; some data may also be held at ICT Hero offices

We do not sell your personal data to any third party.

10. International data transfers

Our core infrastructure is hosted in the UK, and data may also be held at ICT Hero’s own offices. However, some third-party providers we use — including certain AI providers — may process data outside the UK.

Where AI features are enabled, ticket content may be processed by Anthropic or OpenAI in the United States, or by Google (Gemini) in the European Union. Transfers to the United States rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, as published by each provider for UK customers; processing within the EU relies on the UK’s adequacy arrangements with the EU. Supplementary measures include encryption in transit and contractual exclusion of customer data from model training.

11. Data retention

Data typeRetention period
Support tickets, replies, and attachments (ICT Hero’s own support of its clients)Retained while the account is active, and until removal is requested. No automatic time-based deletion is currently applied to ticket data; we are working towards introducing one
RMM device metrics, cron logs, and rule logs (ICT Hero’s own management of its clients’ devices)We do not retain this data for longer than 90 days — automatically enforced
RMM device alerts, script run history, and asset inventory/asset history (ICT Hero’s own management of its clients’ devices/assets)Retained while the underlying client contract is active, and until removal is requested. No automatic time-based deletion is currently applied to this data; we are working towards introducing one
Data entered into a licensed platform (Helpdesk, Asset Management, or RMM) by an organisation for its own customersRetained at that organisation’s discretion for as long as their subscription is active. That organisation is responsible for removing data it no longer wishes to retain, including after it stops using the service. ICT Hero can assist with export or deletion on request but does not delete this data proactively.
Account and identity informationRetained while the account is active; deleted within 30 days of account closure on request
Helpdesk platform audit logWe do not retain this data for longer than 90 days — automatically enforced
Asset Management and Identity Provider (IdP) audit logsRetained until removal is requested. These logs are currently designed to be append-only for security-audit purposes and do not yet have an automatic deletion process; we are working towards introducing a defined retention period
BackupsWe do not retain backup copies for longer than 90 days
Push device tokensDeleted when you log out of the app or uninstall it
Marketing and enquiry dataUntil you opt out
Billing records7 years (legal requirement)

Where a stated period above is a maximum rather than a fixed schedule, we may delete data sooner in the ordinary course of operating the service.

12. Your rights

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your data (subject to legal obligations)
  • Object to processing based on legitimate interests
  • Data portability — receive your data in a structured format
  • Withdraw consent where processing is based on consent

To exercise any of these rights, email support@icthero.co.uk. We will respond within 30 days.

If your organisation is the controller of your data (see Section 3), we may direct your request to them where they are best placed to respond.

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.

13. Cookies and tracking

13.1 Strictly necessary cookies

Our platforms use session cookies that are strictly necessary for authentication and core functionality (e.g. keeping you logged in). These do not require consent and cannot be switched off.

13.2 Analytics cookies

Our websites use Google Analytics, together with analytics provided by our hosting platform, to understand how visitors use our sites (e.g. pages viewed, general location, device type). These cookies are not strictly necessary and are only set once you consent via our cookie banner. Legal basis: consent.

13.3 Marketing email tracking

We use SMTP2GO to send marketing and service-related emails. SMTP2GO’s tracking features record whether an email has been opened and whether links within it have been clicked, which we use to understand engagement with our communications and improve them. Legal basis: consent, or legitimate interests / PECR “soft opt-in” for existing business contacts, consistent with Section 5.

13.4 Managing your preferences

A cookie banner is shown on first visit to our websites, allowing you to accept or reject non-essential cookies such as analytics.

14. Security

We protect personal data using:

  • HTTPS/TLS encryption for all data in transit
  • Encrypted storage for sensitive content (e.g. Secure Send feature uses AES-256-CBC)
  • Access controls — data is scoped to your organisation; staff can only see data within their access level
  • Authentication via the ICT Hero Identity Provider, with multi-factor authentication support
  • Endpoint monitoring via our RMM platform to detect and respond to security issues on managed devices

15. Children’s privacy

Our services are intended for business use only and are not directed at children under 13. We do not knowingly collect personal data from children.

16. Changes to this policy

We will update this page when this policy changes and update the “Last updated” date above. Continued use of our services after changes constitutes acceptance of the updated policy.

17. Contact

ICT Hero Ltd

Camburgh House, 27 New Dover Road, Canterbury, Kent, CT1 3DN

Email: support@icthero.co.uk

Website: icthero.co.uk