Last Updated: 8 September 2026.This policy tells you what personal information Ferrio Limited holds about you, why we hold it, who we share it with, how long we keep it, and what rights you have. We may update it from time to time, and the date above is the date of the current version.
1. Information About Us
We are Ferrio Limited ("Ferrio", "we", "us"), a limited company registered in England and Wales under company number 13561269. Our registered address is Cooper Buildings, Arundel Street, Sheffield S1 2NS, United Kingdom which is also our trading address. Our VAT number is GB 388 6641 40.
We provide Ferrio Connect, a platform that integrates business systems for our customers.
2. Our two roles, and which one applies to you
Ferrio Limited handles personal information in two capacities. Your rights, and who you should contact, differ between them.
2.1 Where we are the controller. For personal information we collect and use for our own purposes — visitors to our website, people who contact us, our marketing contacts, our customers' billing and administrative contacts, and the users registered on the platform — we decide how it is used and we are accountable to you for it. This policy describes that processing, and you may exercise your rights directly with us.
2.2 Where we are the processor. The Ferrio Connect platform holds and moves information on behalf of our customers, under their instructions and under a contract with them. Where that information includes personal information, our customer is the controller and we are the processor. We do not decide what is collected or why, and we do not use it for our own purposes.
If your personal information appears in the data a customer processes through Ferrio Connect, that customer's privacy notice governs it and that customer is who you should contact. If you contact us instead, we will pass your request to them without delay and will help them respond to it.
2.3 Our employees and applicants. Here too we are the controller, but that processing is not described in this policy. Employees and job applicants are given a separate privacy notice directly.
3. What personal information we collect as controller
3.1 Enquiries and support. Your name, email address and the content of your message when you contact us.
3.2 Marketing. Your email address, where you have asked to hear from us. Every marketing message includes a means of unsubscribing.
3.3 Account information. Where a user is registered on the Ferrio Connect platform by our customer or by us, your name, email address and an optional profile picture.
3.4 Authentication information. We do not hold the credentials you sign in with; authentication is handled by our identity provider. We hold the identifier linking an authenticated user to their account.
3.5 Usage information. Device and browser information, timestamps, and a record of the actions taken when you use the platform.
We treat IP addresses and device identifiers as personal information where they can identify an individual. Our own application logs do not record IP addresses, though services we use to run and protect the platform may record them in their own security logs.
3.6 Billing information. The contact and billing details of our customers' administrative contacts, and a record of transactions. Card details are collected and held by our payment provider and are not held by us.
We do not knowingly collect special category personal information as controller, and we do not ask for it.
4. Where we obtain it
The personal information we hold comes from you, or from the organisation you work for where you are acting on its behalf. It may also be provided to us by one of our customers, where they register you as a user of their Ferrio Connect environment.
We do not obtain personal information from any other source.
5. Why we use it, and our lawful basis
● To provide, operate and secure the platform, including logging and monitoring — our legitimate interests in delivering and protecting a service to our customers and their users.● To respond to your enquiries — our legitimate interest in responding to you.● To send you marketing — your consent, which you may withdraw at any time.● To meet our legal and regulatory obligations, including accounting and tax record keeping — compliance with a legal obligation.
6. Who we share it with
6.1 Service providers who process personal information on our behalf, under a contract that limits them to our instructions. These fall into the following categories:
● hosting and infrastructure;● identity, authentication and platform security;● payment processing and financial administration;● communications, contract management and our public website.
We will name the providers in these categories to a customer or prospective customer on request. Our customer contracts govern how we notify changes to the providers who process information on their behalf.
6.2 Professional advisers — our accountants, lawyers and auditors — where they need it to advise us.
6.3 Legal and regulatory authorities, where we are required to disclose or where disclosure is necessary to prevent or detect crime.
6.4 An acquirer, in the event of a merger, acquisition or sale of the business or part of it. You would be told before your information became subject to a different privacy policy.
We do not sell personal information, and we do not share it for advertising purposes.
7. Where your information is held, and transfers outside the UK
Ferrio Connect is hosted in Microsoft Azure in the United Kingdom, and platform data is held there.
Some of the service providers in the categories above process information outside the United Kingdom. Where they do, we rely on a transfer mechanism permitted by UK data protection law: a UK adequacy regulation covering the destination country, or the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. Details of a specific transfer are available on request.
8. How long we keep it
We keep personal information only as long as we need it for the purpose we collected it, or as long as the law requires.
● Account and contact information: for the duration of the customer relationship, after which we keep it only while we have a reason to.● Enquiries and correspondence: 3 years.● Marketing contacts: until you unsubscribe, and then only the record needed to honour that.● Platform log data: up to 400 days.● Accounting and tax records: 6 years, as UK law requires.
Where we delete information, it may remain recoverable in backups for a short period before passing out of them.
9. Security
Personal information we hold is encrypted in transit and at rest. Access to it is limited to the employees who need it, is controlled through named individual accounts, and requires multi-factor authentication.
We hold ISO/IEC 27001 certification for our information security management system, and Cyber Essentials Plus certification. Details of both certificates, including the certifying body, are available on request.
We commission independent penetration testing of the platform at least once a year.
If a personal data breach occurs, we will notify the ICO within 72 hours of becoming aware of it where the breach is likely to result in a risk to people's rights and freedoms, and we will notify the individuals affected without undue delay where the risk to them is high. Where we are the processor, we will notify our customer without undue delay so that they can meet their own obligations.
10. Your rights
You have the right to:
● be told how we use your personal information, which is the purpose of this policy;● ask for a copy of the personal information we hold about you;● have inaccurate personal information corrected;● ask us to delete your personal information, where we no longer have a reason to keep it;● ask us to restrict how we use it, or object to our using it, including for marketing;● receive your personal information in a portable form, where we hold it on the basis of your consent;● withdraw your consent at any time, where consent is the basis we rely on;● complain to the ICO, whose details are in section 14.
10.1 Limits on these rights.
We cannot delete records the law requires us to keep, such as accounting records within their statutory period. Where we refuse a request for that reason we will tell you why.
Where we hold your information as a processor for one of our customers, the decision is theirs to make. We will pass your request to them promptly and help them respond to it, as described in section 2.2.
To exercise a right, email .moc.oirref%40troppus We will respond within one month, and will tell you if we need longer, which we may where a request is complex.
11. Cookies
Our platform uses only the cookies and equivalent browser storage necessary for it to function, such as keeping you signed in and remembering your preferences. We do not use advertising cookies, and we do not use third-party analytics or tracking on the platform.
You can block or delete cookies through your browser, but the platform will not work properly without the necessary ones.
Our public website is hosted separately from the platform. It uses cookieless tracking to record traffic volumes. Any information that could be used to identify you, including your IP address, location and user agent, is anonymised through an irreversible hashing algorithm on your device before logging, and no information is stored between browser sessions, so we do not operate a cookie consent banner on it.
12. Other websites
Where our website contains links to other websites, we are not responsible for the privacy policies or practices of those websites.
13. Changes to this policy
We may update this policy. Where a change is significant we will tell our customers by email and will post the updated policy here with the date it took effect.
14. Contact us
● Email: moc.oirref%40troppus● Telephone: 0114 321 2685● Post: Privacy, Ferrio Limited, Cooper Buildings, Arundel Street, Sheffield S1 2NS
If you are not satisfied with our response you may complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.