Privacy

Last updated: 16th June 2026  |  Version: 1.1

1. Introduction

Ray Technologies Limited (“Ray Technologies”, “we”, “us” or “our”) respects your privacy and is committed to protecting your personal data. This privacy notice explains how we collect, use, share and protect your personal data, and sets out your rights under data protection law.

We are the “controller” of the personal data we process, which means we decide how and why your personal data is used. Please read this notice carefully so that you understand how we handle your personal data.

This notice applies to personal data we process about clients, suppliers, prospective employees, website users and other contacts. We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and, where we process the personal data of individuals in the European Economic Area (EEA), the EU General Data Protection Regulation (EU GDPR).

2. Who we are

We are Ray Technologies Limited, a company registered in England and Wales company number 8553765.

Registered/principal office: Centurion House, London Road, Staines-upon-Thames, TW18 4AX.

We are registered with the Information Commissioner’s Office (ICO) under registration number ZB521927.

We provide a range of consulting services and collect and process personal data in order to provide those services.

3. How to contact us about your data

If you have any questions about this notice, or wish to exercise your rights, you can contact our data protection contact:

4. Keeping your personal data accurate

It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.

5. The personal data we collect

“Personal data” means any information from which a living individual can be identified, directly or indirectly. It does not include anonymised data from which an individual can no longer be identified.

Clients and suppliers

When you become our client, or when we engage you as a supplier, we collect and process:

Job applicants

When you apply to work for us, we collect and process:

Please provide only the personal data that is necessary for your application. We ask that you do not include special category data (see below) or financial data in your CV or application unless we specifically ask for it.

Website users

When you visit our website, we collect technical data about your device and browsing, and any information you submit through our forms (see the Cookies section below).

Special category data and criminal records data

We do not generally collect special category personal data. Special category data means data revealing your racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, genetic or biometric data (where used to identify you), data concerning health, and data concerning your sex life or sexual orientation. We only process such data where you have specifically asked us to in the context of a service we provide, and where we have an appropriate lawful basis and condition for doing so.

We do not routinely collect information about criminal convictions or offences.

6. How we collect your personal data

Direct interactions

You may give us your personal data when you:

Cookies and similar technologies

When you visit our website we may automatically collect technical data about your device, browsing actions and preferences using cookies and similar technologies. Non-essential cookies (for example analytics and advertising cookies) are only set with your consent, which you give through our cookie banner and can change or withdraw at any time.

For full details of the cookies we use, please see our Cookie Policy.

Third parties and publicly available sources

We do not usually collect personal data from third party sources. However, we may connect with clients and contacts via social media networks such as LinkedIn, Facebook and X (formerly Twitter). In those circumstances we may see your publicly available profile details from that source. We do not download that data or integrate it with our systems.

7. How and why we use your personal data

We collect and use the personal data described above to provide our services, to market our services, to operate and improve our website, and to recruit staff.

We only use your personal data when the law allows us to. The lawful bases we rely on are:

The table below sets out the main purposes for which we process personal data, the categories of data involved and the lawful basis we rely on.

Purpose / activityCategories of dataLawful basis
Managing our relationship with clients: setting you/your company up on our systems; liaising with you about projects we undertake for you; processing and collecting payment of invoices; telling you about updates to our services and relevant developments where you have asked us to Identity; Contact; Financial; Marketing and communications Performance of a contract with you; compliance with a legal obligation (e.g. tax/accounting); our legitimate interests (running and developing our business)
Recruitment and selection of candidates: creating a profile of prospective employees and preparing interview notes Identity; Contact; CV / application details Our legitimate interests (assessing and recruiting candidates); taking steps at your request before entering into a contract
Operating, securing and improving our website: troubleshooting, data analysis, testing, research, statistics and surveys; keeping the website safe; measuring the effectiveness of, and delivering, relevant content/advertising; making suggestions and recommendations Identity; Contact; Technical; Usage; Marketing and communications Our legitimate interests (running, securing and improving our website and business); consent (for non-essential cookies and electronic marketing); compliance with a legal obligation (security)

8. Marketing

We may send you information about our services where you have asked us to, or where we are otherwise permitted to do so. We only send electronic marketing (such as marketing emails) where we have your consent or another lawful basis to do so, in line with the Privacy and Electronic Communications Regulations (PECR).

You can ask us to stop sending you marketing at any time by contacting us using the details above, or by using the “unsubscribe” link in any marketing email.

9. Who we share your personal data with

We may share your personal data with members of our team, including consultants who work on your account, and with selected business associates, suppliers and contractors who help us provide our services – for example our web hosting and IT/cloud service providers. Where we use such providers, they act as our processors and may only process your personal data on our instructions and subject to a duty of confidentiality and appropriate contractual safeguards.

We may also disclose your personal data to third parties:

A list of the categories of third parties we share personal data with is set out in Schedule 1.

10. How long we keep your personal data

We keep your personal data only for as long as necessary to fulfil the purposes for which we collected it, including to satisfy any legal, accounting, tax or reporting requirements. The retention period depends on the type of data and the purpose for which we use it.

Our indicative retention periods are: client records: 6 years after the end of the relationship for tax/limitation purposes; unsuccessful job applicants: 6–12 months. For further information about our retention periods, please contact us at privacy@raytl.co.uk.

11. Transfers of your personal data outside the UK and EEA

Some of our service providers may be based outside the UK or the EEA, so providing our services may involve transferring your personal data outside the UK and/or EEA.

Whenever we transfer your personal data out of the UK or the EEA, we make sure a similar degree of protection is given to it by ensuring at least one of the following safeguards is in place:

If you would like more information about the safeguards we use when transferring your personal data internationally, please contact us at contactus@raytl.co.uk.

12. Data security

We have put in place appropriate technical and organisational security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed.

We limit access to your personal data to those employees, agents, contractors, consultants and other third parties who have a business need to know. They will only process your personal data on our instructions and are subject to a duty of confidentiality.

We have procedures to deal with any suspected personal data breach and will notify you and the relevant regulator of a breach where we are legally required to do so.

13. Your rights

Under data protection law you have the following rights in relation to your personal data:

Where our processing is based on your consent, you have the right to withdraw that consent at any time. This will not affect the lawfulness of any processing carried out before you withdraw your consent.

You can exercise any of these rights by contacting us using the details in section 3. You will not usually have to pay a fee, and we will respond within one month of receiving your request. We may extend this period by up to a further two months for complex or numerous requests, in which case we will let you know and explain why.

14. Complaints

If you are unhappy with how we have handled your personal data or a request you have made, please contact us first using the details in section 3 so that we can try to put things right. We operate an internal complaints procedure for data protection matters and will acknowledge your complaint within 30 days.

You also have the right to lodge a complaint with a supervisory authority. In the UK this is the Information Commissioner’s Office (ICO): www.ico.org.uk, helpline 0303 123 1113. If you are in the EEA, you may complain to the supervisory authority in your country. We would, however, appreciate the chance to address your concerns before you approach the regulator.

15. Changes to this notice

We may update this notice from time to time. Any changes will be posted on our website and will take effect when posted. Please review this notice periodically. This notice was last updated on 16th June 2026.

Schedule 1 – Categories of recipients

We share personal data with the following categories of third parties, where relevant: