Privacy Policy
Last updated: 31 July 2026
Smart EPOS Ltd ("we", "our", or "us") is committed to protecting your privacy and handling your personal information fairly, lawfully and transparently.
This Privacy Policy explains what information we collect, why we collect it, how we use it, who we share it with, how long we keep it for, and your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who We Are
Smart EPOS Ltd is the data controller responsible for personal information collected through our website, enquiries, customer communications, billing and general business administration.
Website: https://smartepos.co.uk
Where we access or process information on behalf of a customer as part of providing EPOS products, technical support or related services, the customer may be the data controller and Smart EPOS Ltd may act as a data processor.
If you have any questions regarding this Privacy Policy or how we process personal information, please contact us using the contact details available on our website.
2. Information We Collect
When you contact us through our website, by email, by telephone or through other business communications, we may collect:
- Name
- Business name
- Job title or role
- Email address
- Telephone number
- Business address or site address
- Information you provide within your enquiry
- Any attachments or documents you choose to send
When we provide products, services, billing or support, we may also process:
- Customer account and billing information
- Invoice and payment information
- Direct Debit information processed through GoCardless
- Customer site and installation details
- EPOS product, licence or service information
- Support request details
- Device names, usernames, IP addresses or technical identifiers
- Access credentials provided to us where required for support or administration
- Information visible during a remote support session, where necessary to provide support
We may also collect limited technical information automatically when you use our website, including:
- IP address
- Browser type
- Device information
- Pages visited
- Date and time of your visit
- Cookie consent preferences
This information is collected to help operate, secure and improve the website.
3. How We Use Your Information
We use personal information to:
- Respond to enquiries
- Provide quotations
- Arrange demonstrations
- Supply products and services
- Set up, manage and support customer accounts
- Provide technical support
- Process invoices and payments
- Manage customer relationships
- Keep business and accounting records
- Meet legal, tax and regulatory obligations
- Protect our systems, services and customers from misuse, fraud or security issues
We only process personal information where we have a lawful basis for doing so.
4. Lawful Bases for Processing
Depending on the circumstances, we rely on one or more of the following lawful bases:
- Consent
- Performance of a contract
- Taking steps before entering into a contract
- Compliance with legal obligations
- Our legitimate interests in operating and improving our business
The lawful basis depends on the purpose of the processing.
For enquiries, quotations, demonstrations and product information, we rely on legitimate interests or taking steps before entering into a contract.
For supplying products and services, we rely on performance of a contract.
For providing technical support, we rely on performance of a contract or our legitimate interests.
For invoices, payments, accounting and tax records, we rely on performance of a contract and compliance with legal obligations.
For managing customer relationships and operating, securing and improving our systems, we rely on legitimate interests.
For sending permitted business communications, we rely on legitimate interests or consent where required.
For non-essential cookies, we rely on consent.
Where we rely on legitimate interests, we do so only where we consider that our interests are not overridden by your rights and freedoms.
5. Customer Support and Remote Access
Where remote technical support is required, we may use ScreenConnect to access a customer device or system with the customer's permission.
Remote support sessions are initiated only with the customer's knowledge and consent. During a session, authorised personnel may temporarily view information displayed on the customer's screen where necessary to investigate or resolve a technical issue.
Where access credentials are provided to us for support or administration, we restrict access to authorised personnel and use them only for the purpose for which they were provided.
Customers should close any personal, confidential or unrelated documents before a remote support session begins.
6. Marketing Communications
If you contact us requesting information about our products or services, we may contact you regarding your enquiry.
We will only send marketing communications where permitted by law. You can ask us to stop sending marketing communications at any time.
7. Cookies
Our website uses cookies and similar technologies.
Some cookies are necessary for the operation, security and functionality of the website. These cookies do not require consent.
Where non-essential cookies are used, such as analytics, advertising or tracking cookies, they will only be placed with your consent where required by law.
We use CookieYes to manage cookie consent preferences.
You can control cookies through the cookie banner, cookie settings tool and your browser settings.
8. Sharing Your Information
We do not sell your personal information.
We may share personal information with trusted third-party service providers where this is necessary to operate our business, deliver our services, process payments, provide support or meet legal obligations.
These providers include:
- Wix, for website hosting, website security and contact form processing.
- Microsoft 365, for business email, documents and communications.
- QuickBooks, for invoicing, accounting and financial record management.
- GoCardless, for Direct Debit payment processing and associated payment records.
- ScreenConnect, for remote technical support provided with customer permission.
- ICR Products, for EPOS product supply, service provision, licensing, support or related product services where applicable.
- CookieYes, for cookie consent management.
These organisations process personal information only where necessary to provide their services to us and are required to maintain appropriate security, confidentiality and data protection safeguards.
We may also disclose personal information where required to do so by law, to comply with legal obligations, or to establish, exercise or defend legal claims.
9. International Transfers
Some of our third-party service providers may process personal information outside the United Kingdom.
Where personal information is transferred internationally, we ensure that appropriate safeguards are in place in accordance with UK data protection law.
These safeguards may include transfers to countries recognised by the UK Government as providing an adequate level of data protection, or the use of approved contractual safeguards such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or other recognised transfer mechanisms where required.
We take reasonable steps to ensure that any organisation processing personal information on our behalf maintains appropriate technical and organisational security measures to protect that information.
10. Data Security
We use appropriate technical and organisational measures to protect personal information against unauthorised access, loss, alteration, disclosure or destruction.
Our core business systems are provided through established third-party platforms, including Microsoft 365, QuickBooks, GoCardless, Wix, ScreenConnect, CookieYes and relevant ICR Products services.
Our security measures include:
- Two-factor authentication on supported business systems
- Password-protected access
- Individual user accounts where available
- Access limited to authorised personnel who need it for their role
- Use of established third-party platforms with their own security and data protection controls
- Secure remote support through ScreenConnect
- Review and removal of access where it is no longer required
- Reasonable steps to protect customer information from unauthorised access, loss, misuse or disclosure
During remote support sessions, authorised personnel may temporarily view information displayed on a customer's device where necessary to investigate or resolve a technical issue.
Although no system or internet transmission can ever be guaranteed to be completely secure, we take reasonable and proportionate steps to protect the personal information under our control.
11. Data Retention
We retain personal information only for as long as necessary for the purpose for which it was collected, including legal, accounting, tax, contractual and support requirements.
Our usual retention periods are as follows.
Website enquiries are retained for up to 24 months after the last contact, unless the enquiry becomes a customer relationship.
Customer contact and account information is retained for the duration of the customer relationship and then for up to 6 years.
Quotations and sales records are retained for up to 6 years.
Invoices, accounting records and payment records are retained for 6 years in line with UK tax and accounting requirements.
Support records are retained for up to 3 years after the support matter is closed, unless they are required for ongoing service history.
Remote support access details are retained only for as long as required to provide support or administer the service.
Marketing preferences are retained until you unsubscribe or object.
Cookie consent records are retained as required to demonstrate consent and manage preferences.
Where information is no longer required, it is securely deleted, anonymised or archived where appropriate.
12. Your Rights
Under UK data protection law, you have the right to:
- Request access to your personal information
- Request correction of inaccurate or incomplete information
- Request deletion of your personal information where appropriate
- Request restriction of processing
- Object to certain types of processing
- Request transfer of your information to another organisation where applicable
- Withdraw consent where processing relies on consent
Some rights only apply in certain circumstances.
To exercise any of these rights, please contact us using the details on our website.
13. Complaints
If you are unhappy with how we have handled your personal information, we would appreciate the opportunity to resolve your concerns first.
You also have the right to lodge a complaint with the Information Commissioner's Office, the UK's data protection regulator.
ICO website: https://ico.org.uk
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, our services, suppliers or business practices.
The latest version will always be published on this page with the revised "Last updated" date.
Contact
If you have any questions regarding this Privacy Policy or our handling of personal information, please contact Smart EPOS Ltd using the contact information provided on our website.
