Legal
Privacy notice
How Eazi IT collects, uses and protects personal data. Written in plain English, because a privacy notice nobody can read is not really a notice.
Last updated: 14 August 2026
Who we are
Eazi IT is a trading name of Martin Vernon-Trew, a sole trader in England, based in Bromsgrove, Worcestershire. We also trade as Fractional CxO.
For anything in this notice, including any request about your personal data, contact us:
- Email: contact@fractional-cxo.co.uk
- Telephone: +44 845 875 1878, Monday to Saturday, 9.00am to 7.00pm
Controller or processor — which one we are matters
We wear two hats, and your rights differ depending on which one applies.
We are the controller
For data about our own clients and enquirers — you contact us, we work for you, we invoice you. We decide why and how that data is used, and this notice covers it in full.
We are a processor
For data held in websites and systems we host or manage for clients — their customers, members and enquirers. Our client is the controller of that data and their own privacy notice governs it. We only act on their instructions.
If you have used a website we host and want to exercise your rights, contact the business that runs it. If you cannot reach them, contact us and we will help you find them.
What we collect, and why
| What | Why | Lawful basis |
|---|---|---|
| Enquiry details — your name, email, phone, company, and whatever you tell us about your situation | To answer you, and to work out whether we can help | Legitimate interests — responding to someone who contacted us |
| Client records — contact details, correspondence, project notes, system documentation | To deliver the work you have engaged us for | Performance of a contract |
| Billing records — invoices, payment references | To get paid, and to meet tax and accounting obligations | Legal obligation |
| Technical and security logs — IP addresses, access logs on systems we run | To keep systems available and secure, and to investigate incidents | Legitimate interests — security of our infrastructure |
| Credentials and access you give us for your systems | To do the work. Held only as long as the engagement needs them | Performance of a contract |
We do not buy marketing lists, we do not sell or rent personal data to anyone, and we do not use your data to train AI models.
How long we keep it
- Enquiries that go nowhere — up to 12 months, then deleted.
- Client records — for the engagement, then 6 years from the end of it, so we can deal with any question or claim that arises afterwards.
- Invoices and accounting records — 6 years plus the current year, as UK tax rules require.
- Access credentials — removed or revoked when the engagement ends, or sooner if no longer needed.
- Technical and security logs — typically 90 days unless an incident requires us to keep them longer.
Who else sees it
We keep the list of suppliers short deliberately. The ones that may handle personal data on our behalf are:
- IONOS — domain registration and web hosting
- Cloudflare — DNS and website security
- Microsoft — email and business documents
- Our accountant, for billing and statutory accounts
We may also disclose data if the law requires it. We do not otherwise share it.
Where it goes
We host in the UK wherever we can. Some suppliers above are international and may process data outside the UK. Where that happens it is covered by the safeguards UK data protection law requires — usually an adequacy decision or the International Data Transfer Addendum. If you want to know exactly where a particular piece of data sits, ask us and we will tell you.
How we use AI in our own work
We think you are entitled to know this rather than to guess, so: we use AI tools for research, drafting and code assistance. Analysis, recommendations and anything that carries our name is reviewed by a person who is accountable for it.
We do not put client personal data into public or consumer AI tools. Where an engagement genuinely needs AI applied to your data, we agree that with you first, in writing, and we tell you which service is involved and where it runs.
Cookies
This website uses only what it needs to work — a session cookie if you log in, and cookies your browser needs for security. We do not run advertising or cross-site tracking cookies on this site. If that ever changes we will ask your consent first, through a banner, before setting anything non-essential.
Your rights
Where we are the controller, you have the right to:
- Be told what we hold and why — this notice, plus anything else you ask
- Access a copy of your personal data
- Correct anything inaccurate or incomplete
- Erase it, where we have no continuing reason to hold it
- Restrict what we do with it while a question is resolved
- Object to processing based on legitimate interests
- Portability — receive data you gave us in a machine-readable form
- Withdraw consent at any time, where consent was the basis
Ask by email and we will respond within one month, free of charge. We may need to confirm who you are first. We do not use automated decision-making or profiling that produces legal or similarly significant effects.
Complaints
If you are unhappy with how we have handled your data, please tell us first — we would rather fix it. You also have the right to complain to the UK’s data protection regulator at any time:
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
ico.org.uk
Changes to this notice
If we change how we use personal data we will update this page and change the date at the top. Where the change is significant we will tell affected clients directly rather than relying on you to check.
