tier1 – Privacy Policy
1. About this notice
This notice explains how Tier 1 Asset Management Limited collects and uses personal data about you, and what rights you have over it.
It applies when you:
- visit our website at www.tier1.com;
- buy from our online shop, or from us through an online marketplace such as eBay;
- contact us by email, telephone, post, web form or social media, including to make an enquiry or request a quotation;
- use a customer account or customer portal that we provide;
- visit our premises; or
- have business contact details that we have obtained from a public source, such as your employer’s website or a business networking site, because we are researching a possible business relationship.
2. Who we are
Tier 1 Asset Management Limited is the controller of the personal data described in this notice. That means we decide how and why it is used.
- Registered company name: Tier 1 Asset Management Limited
- Registered company number: 03708416
- Registered office and trading address: 59 Stanley Road, Whitefield, Manchester, Greater Manchester, M45 8GZ
- Data protection contact: dataprotection@tier1.com — see section 15
If you dealt with EOL IT Services. The EOL IT Services business now operates as part of Tier 1 Asset Management Limited. Where records relating to you transferred to us, we are the controller of those records and this notice applies to them. To exercise any of the rights in section 12, or to ask a question about those records, contact us using the details in section 15.
3. What this notice does not cover
We provide IT asset disposal services. Our customers send us IT equipment for reuse, data erasure, destruction and recycling, and that equipment may hold personal data belonging to their employees, customers or other individuals.
This notice does not cover that data. Where we handle personal data held on equipment supplied to us by a customer, we act as a processor on that customer’s instructions, under a separate written services agreement and data processing terms with them. The customer remains the controller of that data and decides how it is handled.
If you believe your personal data was held on equipment that your employer, or another organisation, sent to us, that organisation is the controller. Please contact them in the first instance. We will support them in responding to you.
Where you access a customer portal that we provide, this notice covers your account, your login credentials and how we administer your access to it. The asset records, erasure reports and certificates visible within the portal belong to our customer and are governed by the agreement described above, not by this notice.
4. The personal data we collect, and where it comes from
4.1 Information you give us
| Situation | Personal data |
|---|---|
| Enquiries, quotations and general correspondence | Name, employer and job title, email address, telephone number, postal address, and the content of your correspondence with us |
| Orders and sales (website shop, marketplaces, direct) | Name, billing and delivery address, email address, telephone number, order details, and payment details |
| Customer accounts and portal access | Name, business email address, job title, login credentials and access records |
| Visiting our premises | Name, organisation, vehicle registration, and time of arrival and departure |
Information you have to provide. Where we have or are entering into a contract with you, we need your name, contact details and billing or delivery address in order to perform it. If you do not provide them, we cannot supply our products or services to you. Anything else we ask for is optional, and we will say so at the point we ask.
Payments. Where you pay online, your payment is handled by a third-party payment provider and we receive confirmation of the payment rather than your full card details.
Where you pay by card over the telephone, we use your card details only to take that payment, and we do not retain them once the payment has been processed. We handle payment card data in accordance with the Payment Card Industry Data Security Standard (PCI DSS).
4.2 Information we collect automatically
When you use our website or shop, we collect information about your device and how you use the site, including your IP address, browser and device type, the pages you view, and the dates and times of your visit. We collect this using cookies and similar technologies — see section 6.
If you receive marketing email from us, we may record whether you opened it and whether you clicked a link in it.
4.3 CCTV
We operate CCTV at our premises in Manchester and Maldon. Cameras record images only — they do not record sound. Signs are displayed at the locations where CCTV is in use.
4.4 Call recording
We record incoming and outgoing telephone calls. You will be told this at the start of the call. Recording is not used while card payment details are being taken.
4.5 Information we receive from others
We also receive personal data from sources other than you:
| Source | What we receive |
|---|---|
| Online marketplaces and e-commerce platforms (for example eBay, Shopify) | Buyer name, contact details, delivery address and order details, provided to us so that we can fulfil your order |
| Our customers and business contacts | Contact details of the individuals we should deal with at their organisation |
| Publicly available sources, such as company websites and business networking sites | Business contact details, where we are researching a prospective customer or supplier |
5. How and why we use your personal data
We must have a lawful basis for using your personal data. The table below sets out what we use it for and the basis we rely on.
| What we use it for | Lawful basis |
|---|---|
| Responding to your enquiries and providing quotations | Our legitimate interests — responding to people who contact us, and pursuing business opportunities. Where you are asking about a possible contract, taking steps at your request before entering into a contract |
| Taking, fulfilling and delivering your order, and providing our services | Performance of a contract with you, or taking steps at your request before entering into one |
| Where our contract is with your employer rather than with you personally, administering that contract and dealing with you as its contact | Our legitimate interests — performing and administering our contracts with our customers and suppliers |
| Administering customer accounts and portal access, including authentication and access control | Performance of a contract; our legitimate interests in securing access to our systems |
| Taking payment, and pursuing sums owed to us | Performance of a contract; our legitimate interests in recovering money owed |
| Handling payment card data securely, and meeting the requirements of the Payment Card Industry Data Security Standard | Performance of a contract; our legitimate interests in preventing payment fraud and meeting the standards required of us by the card schemes |
| Keeping business records, and accounting and tax records | Compliance with a legal obligation; our legitimate interests in keeping accurate records |
| Keeping our website, shop and systems secure and available, and preventing fraud and misuse | Our legitimate interests — protecting our business, our systems and our customers |
| Understanding how our website is used so that we can improve it | Our legitimate interests in improving our website. Where this relies on non-essential cookies, your consent — see section 6 |
| Sending marketing communications | Our legitimate interests in promoting our business, or your consent — see section 7 |
| Advertising to you on other websites and measuring how our advertising performs | Your consent, given through our cookie banner — see section 6 |
| Recording who is on our premises, and when | Our legitimate interests — the security of our sites, our staff and the assets in our care, and knowing who is on site in an emergency; compliance with our health and safety obligations |
| Operating CCTV at our premises in Manchester and Maldon | Our legitimate interests — the security of our premises, staff and the assets in our care, the prevention and detection of crime, and meeting the physical security standards required by our accreditations |
| Recording telephone calls for quality monitoring, training, and keeping an accurate record of instructions and transactions | Our legitimate interests in the matters listed |
| Establishing, exercising or defending legal claims, and handling complaints, insurance matters and regulatory enquiries | Our legitimate interests in protecting our legal position; compliance with a legal obligation |
Where we rely on legitimate interests, we have considered whether those interests are outweighed by your interests and rights. You have the right to object to processing carried out on that basis — see section 12.
Special category data. We do not usually collect special category data, such as information about health.
If you tell us about a health condition or disability so that we can make adjustments when you visit our premises, we rely on your explicit consent under Article 9(2)(a) of the UK GDPR, and we use the information only for that visit.
Change of purpose. We will only use your personal data for the purposes set out in this notice, unless we reasonably consider we need to use it for another compatible purpose. If we need to use it for an unrelated purpose, we will tell you and explain the lawful basis for doing so.
6. Cookies and similar technologies
Cookies are small files placed on your device when you visit a website. We also use similar technologies such as pixels and tags. We group them as follows.
Strictly necessary. These are needed for our website and shop to work — delivering pages, keeping you signed in, remembering the contents of your basket, and protecting our forms against automated abuse. We use Google reCAPTCHA for that last purpose. These do not require your consent and cannot be switched off.
Preference. These remember choices you make about how the site behaves. These do not require your consent, but you can object to them free of charge using our cookie settings.
Statistical. We use Google Analytics to understand how our site is used so that we can improve it. Because this information is also available to Google for its own purposes, we only use it if you consent.
Advertising and targeting. We use these to show you our advertising on other websites, to measure whether our advertising works, and to tell which of our advertising generated a telephone call to us — which means the telephone number displayed on our site may change depending on how you reached it. We only use these if you consent.
| Provider | Purpose | Category |
|---|---|---|
| Tier 1 Asset Management Limited (our own site) | Page delivery, sign-in, basket, security | Strictly necessary |
| Tier 1 Asset Management Limited (our own site) | Remembering choices you make about how the site behaves | Preference |
| Google reCAPTCHA | Protecting our forms from automated abuse | Strictly necessary |
| Google Analytics | Understanding how our site is used | Statistical — consent |
| Google Ads (including call tracking) | Measuring and targeting our advertising, and identifying which advertising generated a call | Advertising — consent |
| LinkedIn Insight Tag | Measuring and targeting our advertising on LinkedIn | Advertising — consent |
You can accept or reject non-essential cookies when you first visit our site, and you can change your choice at any time using the Cookie settings link in the footer of our website. That page also lists each individual cookie we use, who provides it, what it does and how long it lasts, and is kept up to date as our site changes.
You can also block or delete cookies in your browser settings, though this may stop parts of our site working.
7. Marketing
We may send you information about our products and services by email.
If you have bought from us, or negotiated with us about buying from us, and we obtained your contact details in the course of that sale or negotiation, we may send you marketing about our similar products and services. We rely on our legitimate interests, in reliance on the “soft opt-in” under regulation 22 of the Privacy and Electronic Communications (EC Directive) Regulations 2003. We will have given you a simple way to refuse marketing at the point we collected your details, and every message we send will include one.
In all other cases we will ask for your consent before sending you marketing email.
You can stop marketing at any time. Use the unsubscribe link in any marketing email, or contact us using the details in section 15. This is an absolute right and we will act on it — there is no need to give a reason. It may take up to 10 working days to take effect across our systems.
Opting out of marketing does not stop us sending you messages we need to send about an order, a contract or an account.
We also advertise on third-party websites and platforms. Where that advertising relies on cookies or similar technologies on our site, it is subject to your consent as described in section 6.
We do not sell your personal data.
8. Who we share your personal data with
We share personal data with the following categories of recipient:
- Service providers who act for us. These include providers of website and shop hosting, IT and cloud infrastructure, email and document management, our ERP and customer relationship management systems, delivery and logistics partners, payment providers, marketing platforms, and professional and IT support services. They act as our processors under written contracts that require them to act only on our instructions, keep the data confidential, and apply appropriate security measures.
- Online marketplaces and e-commerce platforms, where you buy from us through them.
- Our professional advisers, including lawyers, accountants, auditors and insurers, where they need the information to advise us.
- Certification and accreditation bodies, and regulators, where they require information as part of an audit or investigation.
- Law enforcement, courts, regulators and other public authorities, where we are legally required to disclose information, or where disclosure is necessary to establish, exercise or defend legal claims, or to prevent crime.
- A buyer or successor, if we sell or reorganise all or part of our business. We would require them to continue to protect your personal data in a manner consistent with this notice.
Other than as described in this notice, we do not disclose your personal data to third parties for their own purposes.
Technology providers with AI features. Some of the software and cloud services we use include artificial intelligence features that may process personal data in order to help us draft, summarise, classify, search or organise information — for example when handling correspondence or preparing documents. Where they do, the providers act as our processors under the contracts described above, which require them to process personal data only on our instructions and for no purpose of their own.
We do not make decisions about you that are based solely on automated processing and that have legal effects for you or otherwise significantly affect you. Decisions that affect you are reviewed by a person.
9. Transfers outside the UK
Some of the service providers described in section 8 are based outside the United Kingdom, or use infrastructure or support teams outside it, including in the European Economic Area and the United States.
Where we transfer personal data outside the UK, we make sure it is protected by one of the following:
- the country has been found by the UK government to provide an adequate level of protection for personal data;
- the recipient in the United States is certified under the UK Extension to the EU–US Data Privacy Framework; or
- we have put in place the UK International Data Transfer Agreement, or the UK Addendum to the European Commission’s standard contractual clauses, together with any additional safeguards a transfer risk assessment identifies as necessary.
You can ask us for a copy of the safeguards that apply to a particular transfer, or details of where they have been made available, using the contact details in section 15.
10. How long we keep your personal data
Our standard retention period is 7 years. Some categories are shorter, because keeping the information for that long would not be justified, or because the system it is held in applies a shorter limit. The table below sets out each category.
| Personal data | Retention period |
|---|---|
| Most business records — customer and supplier records, contracts and correspondence, enquiries and quotations, orders, invoices, accounting records, and customer account and portal records | 7 years |
| Payment card details | Not retained once your payment has been processed |
| CCTV footage | No longer than 26 weeks from recording. Where footage is needed for an investigation, insurance claim or legal proceedings, that footage is kept separately until the matter is concluded |
| Call recordings | 90 days, which is the retention period applied by our telephony provider |
| Marketing contact details and preferences | Until you unsubscribe or ask us to stop. We then keep a record of your objection permanently, so that we do not contact you again |
At the end of these periods we securely delete or anonymise the data.
We may keep information for longer where the law requires it, or where it is needed in connection with a claim, complaint, investigation or legal proceedings.
11. How we protect your personal data
We maintain appropriate organisational, technical and physical measures designed to protect personal data against loss, misuse, unauthorised access, disclosure and alteration. We hold ISO 27001 certification for our information security management system.
If a personal data breach occurs, we will report it to the Information Commission where the law requires us to do so, and we will tell affected individuals where the breach is likely to result in a high risk to their rights and freedoms.
12. Your rights
Your right to object. You have the right to object at any time to our use of your personal data for direct marketing. If you object, we will stop, and we do not need a reason. You also have the right to object to any use of your personal data that we carry out on the basis of our legitimate interests, as set out in section 5.
You have the following rights over your personal data. Apart from the right to object to direct marketing, they are not absolute, and in some cases we may be entitled to refuse a request — if so, we will explain why.
- Access — to be told whether we hold personal data about you, and to receive a copy of it.
- Rectification — to have inaccurate personal data corrected, and incomplete data completed.
- Erasure — to have your personal data deleted, where there is no good reason for us to continue holding it.
- Restriction — to ask us to limit how we use your personal data, for example while you are contesting its accuracy.
- Portability — to receive personal data you provided to us in a structured, commonly used and machine-readable format, and to have it sent to another organisation, where we process it by automated means on the basis of your consent or a contract with you.
- Objection — to object to our use of your personal data where we rely on legitimate interests. We will stop unless we have compelling grounds to continue.
- Objection to direct marketing — to object at any time to our use of your personal data for direct marketing. This right is absolute and we will always stop.
- Withdrawal of consent — where we rely on your consent, to withdraw it at any time. This does not affect processing carried out before you withdrew it.
To exercise any of these rights, contact us using the details in section 15. We do not usually charge a fee, though the law allows us to charge a reasonable one where a request is manifestly unfounded or excessive, or where you ask for further copies. We will respond within one month, and will tell you if we need longer because your request is complex — in which case we may extend by up to two further months. We may need to ask you for information to confirm your identity, or to clarify what you are asking for.
13. Complaints
If you are unhappy with how we have handled your personal data, please tell us first. You can complain to us using the contact details in section 15. You do not need to use a particular form or wording.
We will acknowledge your complaint within 30 days of receiving it, and we will begin looking into it without undue delay. How long the investigation takes will depend on how complex the complaint is. We will keep you updated on progress, and will tell you the outcome as soon as we can.
You also have the right to complain to the Information Commission, the UK’s data protection regulator (known as the Information Commissioner’s Office until 30 September 2026). You can do so at any time, and you do not have to complain to us first.
Information Commission
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
https://ico.org.uk/make-a-complaint/
14. Other websites
Our website links to websites operated by other organisations. This notice does not apply to them, and we encourage you to read their own.
15. Contact us
For any question about this notice, to exercise your rights, or to make a complaint:
- Email: dataprotection@tier1.com
- Post: Data Protection, Tier 1 Asset Management Limited, 59 Stanley Road, Whitefield, Manchester, Greater Manchester, M45 8GZ
16. Changes to this notice
We keep this notice under review and may update it from time to time. The version number and date at the top show when it was last changed. Where a change materially affects how we use your personal data, we will take reasonable steps to bring it to your attention, such as by placing a notice on our website or contacting you directly.
Reduce. Reuse. Redeploy. Recycle
Circular Approach to Sustainability
We ensure that the Lifecycle Services we provide are sustainable and circular in approach, and actively promote the reuse of all equipment where possible. We work closely with our clients to improve awareness of environmentally favourable solutions, ensuring recycling is the last option considered and making a real contribution to your ESG goals.