Part 1: Before You Become a Client
Version: 1.0
Last updated: 4 March 2026
This privacy notice explains what personal information we collect, why we collect it, how we protect it and what rights you have.
We have split it into two parts:
1. Before you become a client – for enquiries, discovery calls and quotes.
2. After you become a client – while we provide services, support or ongoing work.
Part 1: Before You Become a Client
1. Who we are
East London Automation Consulting, also known as ELA Consulting, is responsible for the personal information covered by this part of the notice.
In data protection law, this means we are the data controller.
If you have a question about your personal information, you can contact us:
Email: contact.us@elaconsulting.uk
Telephone: +44 (0) 7958 910363
Address: Essex SS7 2AN
We do not currently need to appoint a Data Protection Officer (DPO). If this changes, we will update this notice.
2. When this part applies
This part applies when you contact us before we start providing paid services.
For example, you might:
• send us an email or call us with a question
• book a discovery call
• ask us for a quote or proposal
• tell us about a problem you want us to solve
• discuss your IT systems, security requirements or timescales
• send us documents, screenshots or process notes to help us understand what you need
3. What information we may collect
We may collect information such as:
• Your contact details: your name, job title, company, email address, telephone number and business address.
• Messages and conversations: emails, messages, meeting notes and call summaries.
• Information about your project: what you want us to automate or improve and which systems are involved.
• Basic technical information: for example, which version of Microsoft 365 you use or what Power Automate licence you have.
• Security information: for example, whether your organisation uses a VPN or multi-factor authentication (MFA).
• Billing information: for example, who should receive invoices or whether your organisation uses purchase orders.
Please do not send us passwords
We do not normally need your passwords.
If you accidentally send us a password or other login details, please tell us straight away so we can delete or secure them.
4. Where we get your information
Most of the information we hold comes directly from you.
Sometimes another person in your organisation may introduce you to us and give us your business contact details.
5. Why we use your information
We may use your information to:
• reply to your questions
• communicate with you
• understand what help you need
• discuss possible solutions
• prepare quotes, proposals and statements of work
• check whether a project is practical
• understand important security or technical requirements
• keep a record of what has been discussed
6. Why we are legally allowed to use your information
UK data protection law says businesses must have a valid legal reason for using personal information.
We may rely on:
Legitimate interests
This means we have a reasonable business need to use the information, such as replying to enquiries or preparing a proposal. We must also consider your privacy rights.
Steps before entering into a contract
If you ask us for a quote, proposal or other work that may lead to a contract, we can use the information needed to prepare for that contract.
Legal obligation
Sometimes the law requires us to keep certain information, such as accounting or tax records.
Consent
In some situations, we may ask your permission before using your information. For example, this could apply to some marketing. You can withdraw your consent later.
7. Who we may share your information with
We may need to share some information with trusted organisations that help us run our business, including:
• accountants
• insurers
• legal advisers
• email providers
• calendar providers
• file-storage and backup providers
• IT and security providers
These organisations should only use the information for the purpose for which it was provided.
We do not sell your personal information.
8. Information stored outside the UK
Some technology companies we use may store or process information outside the UK.
When this happens, we use appropriate legal and contractual safeguards to help protect your information.
9. How we protect your information
We take reasonable steps to keep personal information secure.
These may include:
• controlling who can access information
• using multi-factor authentication where available
• using secure computers and devices
• using appropriate security software
• limiting the amount of information we collect
• only keeping information that we actually need
10. How long we keep your information
If you do not become a client, we will normally keep information about your enquiry for up to 12 months after our last contact.
This allows us to deal with follow-up questions and keep a reasonable record of previous discussions.
If you become a client, information that is still needed may become part of our client records and will then be covered by Part 2 of this notice.
Sometimes we may need to keep information for longer because the law requires us to.
11. Your rights
UK data protection law gives you several rights over your personal information.
Depending on the situation, you may have the right to:
• ask what information we hold about you
• ask us to correct incorrect information
• ask us to delete information
• ask us to limit how information is used
• object to certain uses of your information
• receive certain information in a portable format
Not every right applies in every situation.
Contact us if you want to use any of these rights.
12. Complaints
If you are unhappy with how we use your personal information, please contact us first so we can try to resolve the problem.
You can also complain to the Information Commissioner's Office (ICO), which is the UK's data protection regulator.
13. Changes to this notice
We may update this privacy notice from time to time.
When we do, we will change the Last updated date shown at the top.
Part 2: After You Become a Client
1. When this part applies
This part applies once you become an ELA Consulting client and we start providing services.
This could include:
• setting up or changing IT systems
• creating automation solutions
• providing technical support
• troubleshooting problems
• carrying out change requests
• providing training
• providing ongoing support or retained services
For privacy enquiries, contact:
Email: contact.us@elaconsulting.uk
Telephone: +44 (0) 7958 910363
Address: Essex SS7 2AN
2. What information we may use
The information we need will depend on the work you ask us to carry out.
It may include:
Client and contact information
For example:
• names
• business email addresses
• telephone numbers
• authorised contacts
• project managers
• people who approve work
• billing contacts
Project information
For example:
• statements of work
• project plans
• meeting notes
• decisions
• change requests
• technical requirements
Support information
For example:
• support tickets
• emails
• error reports
• call notes
Technical and security information
For example:
• usernames and work email addresses
• system roles
• access requirements
• MFA requirements
• approved IP addresses
• VPN requirements
We do not normally need your passwords.
Automation information
This could include:
• scripts
• automated workflows
• configuration files
• system logs
• automation run histories
• error reports
Remote-access records
If remote support is used, the tools involved may create records showing when systems were accessed and by whom.
Information inside your systems
Sometimes we may need temporary access to information stored inside your organisation's systems so that we can complete the work.
This could include personal information about your employees or customers.
We will only access this information where it is reasonably needed for the work.
3. Sensitive personal information
Some information receives extra protection under data protection law.
This is called special category data and can include information about someone's:
• health
• race or ethnic background
• religion
• political opinions
• sexual orientation
• biometric or genetic information
If a project may involve this type of information, we will agree appropriate controls with the client before work starts.
4. Why we use information
We may use information to:
• provide the services you have asked us to provide
• safely manage access to IT systems
• build and test automation solutions
• operate and support solutions
• investigate technical problems
• improve reliability
• manage invoices and payments
• keep business and project records
• meet legal and regulatory requirements
• deal with legal claims or disputes if necessary
5. Why we are legally allowed to use the information
Depending on the situation, we may rely on:
Contract
We may need to use information to provide the services the client has asked us to provide.
Legal obligation
We may need to keep or use information because the law requires us to.
Legitimate interests
We may have a reasonable business need to use information, such as protecting systems, preventing fraud, maintaining records or improving services.
We must balance these interests against people's privacy rights.
Consent
In some situations, we may ask for someone's permission. This is less common when providing business-to-business services.
If special category information is involved, we will make sure there is an appropriate legal reason for processing it.
6. When we work with information owned by a client
Sometimes there is an important difference between a controller and a processor.
The controller decides why personal information is used and what should happen to it.
The processor handles personal information on behalf of the controller and follows the controller's instructions.
In many ELA Consulting projects, the client is the controller because the client decides how information in its systems should be used.
ELA Consulting may then act as a processor when we access or handle that information to complete the agreed work.
Where appropriate, we will agree things such as:
• what information we can access
• who can access it
• how access will be provided
• how information will be protected
• where information can be stored
• when information should be deleted
• what should happen if there is a security incident
We normally use named accounts and give people only the access they need to do their job. This is sometimes called least-privilege access.
7. Who we may share information with
Where necessary, information may be shared with:
• authorised people within the client's organisation
• companies that provide our email, file storage, backup, accounting or security systems
• accountants
• insurers
• legal advisers
• government or regulatory authorities where the law requires us to
We do not sell personal information.
8. Information stored outside the UK
Some suppliers may process or store information outside the UK.
Where this happens, we use appropriate safeguards, such as recognised legal transfer arrangements and contractual protections.
9. How we protect information
We use practical security measures appropriate to the work being carried out.
These may include:
• access controls
• multi-factor authentication
• least-privilege access
• secure file storage
• encrypted transfer where available
• separating information from different clients where appropriate
• keeping suitable security and troubleshooting logs
10. How long we keep information
How long we keep information depends on what it is and why we need it.
Our normal approach is:
Contracts, invoices and accounting records:
Usually up to 6 years, where required for business, tax or accounting purposes.
Project documents and deliverables:
Usually up to 6 years after the project ends. This can help if there are later questions, audits, warranty issues or disputes.
Support tickets and operational logs:
Usually around 12 to 24 months, unless we need them for longer because support is still being provided or for legal reasons.
Information taken from client systems:
We try not to copy or keep client information unless it is needed.
For example, we may temporarily export a system log to investigate an error. Once we no longer need it, we aim to delete it securely.
A client can ask us to agree shorter retention periods where this is practical and legally possible.
11. Your rights
Depending on the situation, UK data protection law may give you the right to:
• ask what personal information is held about you
• have incorrect information corrected
• ask for information to be deleted
• ask for its use to be restricted
• object to certain uses
• receive certain information in a portable format
If ELA Consulting is only acting as a processor for a client's information, we may pass your request to that client because they are the organisation responsible for deciding how the information is used.
We will also assist our client where required.
12. Complaints
If you have concerns about how your information has been handled, please contact us so we can try to resolve the issue.
You can also complain to the Information Commissioner's Office (ICO).
The ICO is the independent UK organisation responsible for enforcing data protection law.
13. Changes to this notice
We may update this notice from time to time.
If we make changes, we will update the Last updated date.