Version Date 01/01/2026
DATA PROTECTION POLICY 1. Introduction This Policy sets out the obligations of Cleverbox UK Ltd, a company registered in the United Kingdom under number 03887275, whose registered office is at 33 London Road, Bromley, England, BR1 1DG (“Cleverbox”, “Us”, “We”) regarding data protection and the rights of clients, end users of our clients’ websites, and Cleverbox employees (“data subjects”) in respect of their personal data under the UK’s data protection legislation, including the UK General Data Protection Regulations (UK GDPR). This Policy outlines Cleverbox’s obligations as a data controller and as a data processor regarding the collection, processing, transfer, storage, and disposal of personal data. The procedures and principles set out within this policy must be followed at all times by Cleverbox, its employees, agents, contractors, or other parties working on behalf of Cleverbox.
Cleverbox UK GDPR compliance programme Building on the technical and organisational security measures we already have in place to to meet our obligations under the UK GDPR. ● We have reviewed the data we collect and process and follow guidelines from the ICO and the National Cyber Security Centre to ensure appropriate technical and organisational security measures are in place to protect any personal data we control or process. ● We are registered with the ICO (number ZA359100). ● Our customer terms and conditions include a data processor clause that will enable us (and you) to comply with the requirements of the UK General Data Protection Regulation, which governs controller-processor contracts. ● We have worked with our subcontractors and suppliers to ensure that appropriate security measures and contractual arrangements are in place. ● Our other internal procedures relating to personal data have been analysed to ensure that we comply with the UK GDPR’s requirements, including those in respect of: (i) privacy by design and default; (ii) data subject consents; (iii) processing records; (iv) data retention and deletion; (v) data subject rights; (vi) impact assessments and (vii) breach notification. ● We have appointed a Data Representative who is responsible for ensuring we comply with our obligations under the UK GDPR. ● We ensure our staff are trained in best UK GDPR day-to-day practice and general knowledge. All staff are bound by an employee contract to maintain confidentiality in line with this data protection policy. We will ensure that staff are informed of any special data protection requirements relevant to their work. Those with access to any client personal data, in order to support our clients with the on-going management of their websites, undergo relevant training in data protection, including how to obtain appropriate verification from a data controller, when instructed to act on their behalf.
Cleverbox, 33 London Road, Bromley, Kent BR1 1DG T: 0208 466 7222 team@cleverbox.co.uk www.cleverbox.co.uk