1. Introduction
Centiun Limited (“Centiun”, “we”, “us”, or “our”) is committed to protecting and respecting the privacy, confidentiality, integrity, and security of personal data entrusted to us.
This Privacy Policy explains how we collect, use, disclose, transfer, store, and protect personal data when:
- You visit our website;
- You engage with us as a customer, supplier, partner, contractor, or prospect;
- You use our services, software, managed services, consulting services, or support services;
- We communicate with you in connection with our business operations; and
- We process personal data on behalf of our customers.
This Privacy Policy is intended to support:
- Public website privacy disclosures;
- Contractual and procurement requirements;
- Enterprise customer due diligence;
- Supplier assurance reviews;
- UK GDPR and EU GDPR transparency obligations; and
- Data protection compliance requirements.
This Privacy Policy should be read alongside any applicable:
- Data Processing Agreement (“DPA”);
- Master Services Agreement (“MSA”);
- Terms of Business;
- Information Security Policy;
- Cookie Policy; and
- Customer contractual documentation.
2. Company Information
Data Controller
Centiun Limited
CN House, Brooks Drive, Cheadle Royal Business Park, Cheadle, Cheshire, England, SK8 3TD, United Kingdom
For all privacy, data protection, or information governance enquiries, please contact:
Email: privacy@centiun.com
Website: https://www.centiun.com
Where Centiun processes personal data on behalf of a customer, Centiun acts as a Data Processor and the relevant customer acts as the Data Controller.
3. Scope
This Privacy Policy applies to:
- Website visitors;
- Customers and prospective customers;
- Customer users and authorised representatives;
- Suppliers and subcontractors;
- Business contacts;
- Event attendees;
- Marketing recipients;
- Job applicants and recruitment candidates; and
- Individuals whose personal data may be processed in the course of delivering our services.
This Privacy Policy applies to personal data processed:
- Electronically;
- Verbally;
- In writing; and
- Through third-party systems and cloud platforms used by Centiun.
4. Definitions
For the purposes of this Privacy Policy:
- “Personal Data” means any information relating to an identified or identifiable natural person.
- “Processing” means any operation performed on personal data including collection, storage, use, disclosure, deletion, or transfer.
- “Data Controller” means the organisation determining the purposes and means of processing personal data.
- “Data Processor” means the organisation processing personal data on behalf of a Data Controller.
- “UK GDPR” means the UK General Data Protection Regulation.
- “EU GDPR” means Regulation (EU) 2016/679.
- “Special Category Data” means sensitive personal data as defined under applicable data protection legislation.
5. Categories of Personal Data We Collect
Depending on the nature of our relationship with you, we may collect and process the following categories of personal data.
a. Identity and Contact Information
- Full name;
- Job title;
- Employer or organisation;
- Business email address;
- Telephone number;
- Postal address;
- Username or account identifiers.
b. Technical and Usage Information
- IP address;
- Browser type and version;
- Device identifiers;
- Operating system;
- Website interaction data;
- Authentication logs;
- Security logs;
- Session information;
- Usage analytics.
c. Commercial and Contractual Information
- Service engagement details;
- Project information;
- Purchase orders;
- Billing and payment information;
- Support requests;
- Communication records.
d. Recruitment Information
- CVs and employment history;
- Qualifications and certifications;
- References;
- Interview notes;
- Right-to-work documentation.
e. Marketing and Communication Preferences
- Marketing preferences;
- Event registrations;
- Communication opt-ins and opt-outs.
f. Special Category Data
Centiun does not intentionally collect Special Category Data unless:
- Required for employment, legal, regulatory, or contractual obligations;
- Explicitly provided by the data subject;
- Necessary for service delivery; or
- Required under applicable law.
Where Special Category Data is processed, Centiun applies enhanced security and access controls.
6. How We Collect Personal Data
We may collect personal data:
- Directly from you;
- Through our website forms;
- Through customer onboarding processes;
- Through contractual engagements;
- Through Microsoft 365, Dynamics 365, Power Platform, or related systems;
- Through recruitment and employment processes;
- Through events, webinars, and conferences;
- Through publicly available business sources;
- Through referrals and partner introductions;
- Through cookies and analytics technologies; and
- Through third-party service providers.
7. Lawful Bases for Processing
Centiun processes personal data under one or more lawful bases including:
a. Contractual Necessity
Processing necessary to:
- Provide services;
- Deliver projects;
- Manage customer relationships;
- Provide support services;
- Fulfil contractual obligations.
b. Legitimate Interests
Processing necessary for:
- Business administration;
- Service improvement;
- Information security;
- Fraud prevention;
- Direct business-to-business marketing;
- Customer relationship management;
- Operational efficiency.
We conduct balancing assessments where required.
c. Legal Obligations
Processing necessary to comply with:
- Tax obligations;
- Employment obligations;
- Regulatory requirements;
- Court orders;
- Law enforcement requests.
d. Consent
Where required by law, we rely on consent for:
- Certain marketing communications;
- Non-essential cookies;
- Specific optional processing activities.
Consent may be withdrawn at any time.
e. Vital Interests and Public Interest
Where applicable, processing may occur to:
- Protect individuals;
- Support legal claims;
- Protect critical systems or infrastructure.
8. Purposes of Processing
Centiun may process personal data for the following purposes:
- Delivering consulting and managed services;
- Implementing and supporting Microsoft technologies;
- Providing customer support;
- Service administration and account management;
- Project delivery and governance;
- Security monitoring and incident management;
- Billing and financial administration;
- Supplier management;
- Recruitment and employment;
- Marketing and communications;
- Website administration and analytics;
- Compliance, legal, and regulatory obligations;
- Business continuity and disaster recovery;
- Internal reporting and operational management;
- Quality assurance and service improvement.
9. Cookies and Website Technologies
Our website may use cookies, analytics tools, and similar technologies.
These technologies may be used to:
- Operate website functionality;
- Improve user experience;
- Analyse website traffic and performance;
- Support cybersecurity protections;
- Manage consent preferences.
Cookies may include:
- Essential cookies;
- Functional cookies;
- Analytics cookies;
- Performance cookies;
- Marketing cookies.
Where legally required, non-essential cookies will only be deployed following consent.
Further information is available within our Cookie Policy and cookie consent mechanisms.
10. Marketing Communications
Centiun may send marketing and business communications where permitted by applicable law.
You may opt out of marketing communications at any time by:
- Using unsubscribe links;
- Contacting us directly; or
- Updating communication preferences.
Centiun does not sell personal data to third parties.
11. Data Sharing and Disclosure
Centiun may share personal data with:
a. Group Companies and Personnel
- Employees;
- Directors;
- Contractors;
- Approved subcontractors.
Access is restricted on a least-privilege basis.
b. Technology and Service Providers
Including providers of:
- Cloud hosting;
- Microsoft 365 services;
- Dynamics 365 services;
- IT support;
- Security services;
- CRM systems;
- Accounting platforms;
- Communication tools;
- Recruitment systems.
c. Professional Advisors
Including:
- Legal advisors;
- Auditors;
- Insurers;
- Accountants;
- Compliance advisors.
d. Regulatory Authorities and Law Enforcement
Where legally required or necessary to:
- Comply with legal obligations;
- Defend legal claims;
- Prevent fraud or cybercrime;
- Protect rights and property.
e. Customers and Customer Systems
Where required for service delivery, support, project implementation, or managed services.
All third parties are expected to maintain appropriate security and confidentiality controls.
12. International Transfers
Personal data may be transferred to, stored in, or accessed from countries outside the United Kingdom or European Economic Area.
Where international transfers occur, Centiun implements appropriate safeguards including:
- UK International Data Transfer Agreements (“IDTAs”);
- EU Standard Contractual Clauses (“SCCs”);
- Adequacy regulations;
- Vendor due diligence;
- Technical and organisational safeguards.
We assess transfer risks where required under applicable law.
13. Information Security
Centiun maintains a comprehensive information security programme designed to protect personal data against:
- Unauthorised access;
- Accidental loss;
- Destruction;
- Disclosure;
- Alteration;
- Cybersecurity threats.
Security measures may include:
- Access controls and role-based permissions;
- Multi-factor authentication;
- Encryption in transit and at rest;
- Endpoint security controls;
- Security monitoring and logging;
- Backup and disaster recovery procedures;
- Vulnerability management;
- Secure development practices;
- Supplier security reviews;
- Staff training and awareness programmes.
Centiun adopts a risk-based approach to information security and continually reviews and improves its controls.
14. Data Retention
Centiun retains personal data only for as long as necessary to:
- Fulfil the purposes for which it was collected;
- Meet contractual obligations;
- Comply with legal and regulatory requirements;
- Resolve disputes;
- Enforce agreements.
Retention periods are determined based on:
- Legal requirements;
- Regulatory obligations;
- Business necessity;
- Industry standards;
- Customer contractual commitments.
At the end of retention periods, personal data is securely deleted, anonymised, or destroyed.
15. Data Subject Rights
Subject to applicable law, individuals may have the right to:
- Access their personal data;
- Correct inaccurate personal data;
- Request erasure;
- Restrict processing;
- Object to processing;
- Withdraw consent;
- Request portability of data;
- Object to automated decision-making;
- Lodge complaints with supervisory authorities.
Requests may be submitted to:
Centiun may request proof of identity before responding to requests.
We aim to respond within applicable statutory timeframes.
16. Automated Decision-Making
Centiun does not generally conduct solely automated decision-making that produces legal or similarly significant effects.
Where automated processing is used, appropriate safeguards will be implemented.
17. Children’s Privacy
Centiun’s services and website are not directed at children.
We do not knowingly collect personal data from children without appropriate legal basis or parental authority.
18. Customer Data Processing
Where Centiun processes personal data on behalf of customers:
- Processing activities are governed by contractual agreements and Data Processing Agreements;
- Centiun acts only on documented customer instructions;
- Customer data ownership remains with the customer;
- Appropriate confidentiality and security obligations apply;
- Sub-processors may be used subject to contractual protections.
Customers remain responsible for:
- Determining lawful bases for processing;
- Responding to data subject requests;
- Ensuring accuracy of customer-provided data;
- Configuring customer systems appropriately.
19. Sub-processors
Centiun may use sub-processors and third-party providers to support service delivery.
These may include providers of:
- Cloud infrastructure;
- Managed hosting;
- Cybersecurity services;
- Collaboration platforms;
- Monitoring services;
- Support tooling;
- Professional services.
Sub-processors are subject to:
- Due diligence;
- Security assessments;
- Confidentiality obligations;
- Contractual data protection obligations.
A list of key sub-processors may be provided upon reasonable request subject to confidentiality obligations.
20. Confidentiality
All Centiun personnel, contractors, and authorised third parties with access to personal data are subject to confidentiality obligations.
Access to personal data is restricted to individuals with a legitimate business need.
21. Incident Management and Data Breaches
Centiun maintains procedures for:
- Detecting security incidents;
- Investigating incidents;
- Responding to incidents;
- Escalating incidents;
- Recovering from incidents.
Where legally required, Centiun will notify:
- Customers;
- Supervisory authorities; and/or
- Affected individuals
within applicable statutory or contractual timeframes.
22. Third-Party Websites
Our website or services may contain links to third-party websites or services.
Centiun is not responsible for the privacy, content, or security practices of third-party organisations.
Users should review the privacy notices of third-party websites independently.
23. Recruitment and Employment Data
Centiun processes recruitment and employment-related personal data for:
- Recruitment;
- Candidate evaluation;
- Right-to-work verification;
- Employment administration;
- Payroll and benefits;
- Training and compliance;
- Performance management;
- Health and safety obligations.
Additional privacy notices may apply to employees and applicants.
24. Accessibility and Inclusivity
Centiun is committed to ensuring that privacy information is accessible and understandable.
Individuals requiring this Privacy Policy in an alternative format may contact us.
25. Regulatory Compliance
Centiun seeks to maintain compliance with applicable data protection and information governance legislation including, where applicable:
- UK GDPR;
- EU GDPR;
- Data Protection Act 2018;
- Privacy and Electronic Communications Regulations (“PECR”);
- Applicable cybersecurity and sector-specific regulations.
26. Changes to This Privacy Policy
Centiun may update this Privacy Policy from time to time to reflect:
- Legal changes;
- Regulatory updates;
- Operational changes;
- Service developments;
- Security improvements.
The latest version will always be made available through our website or upon request.
Material changes may be communicated directly where appropriate.
27. Contact Information
For all privacy, data protection, or information governance enquiries, please contact:
Centiun Limited
CN House, Brooks Drive, Cheadle Royal Business Park, Cheadle, Cheshire, England, SK8 3TD, United Kingdom
Email: privacy@centiun.com
Website: https://www.centiun.com/contact
28. Supervisory Authority
Individuals located in the United Kingdom have the right to lodge complaints with the Information Commissioner’s Office (“ICO”).
Information about the ICO is available at:
Individuals located within the European Economic Area may also contact their local supervisory authority.
29. Contractual and Enterprise Use Statement
This Privacy Policy is designed to support:
- Enterprise procurement reviews;
- Security and compliance due diligence;
- Customer onboarding;
- Supplier assurance activities;
- Contractual referencing;
- Website publication.
Nothing within this Privacy Policy limits obligations contained within executed contractual agreements, Data Processing Agreements, or applicable law.

