Privacy notice and terms of service
What personal information we collect, why we collect it, how long we keep it, and the standard terms on which we provide services. Written to be read by people rather than by lawyers.
Quick links: Privacy notice · Cookies · Retention · Your rights · Terms of service
Privacy notice
Last reviewed: January 2026
This notice explains what personal information Northvale Systems collects, why we collect it, how long we keep it, and what you can ask us to do with it. If anything here is unclear, email hello@northvale-systems.example.com and we will explain it in plainer words.
Who we are
Northvale Systems is a small business providing managed backup and IT support services. Our registered office is Suite 210, Building C, Northvale Business Park. For the purposes of data protection law we act as a controller for the information we hold about our own enquirers, clients and staff, and as a processor for the information we handle on behalf of client businesses. Any privacy question can be sent to the address above and will reach one of the directors.
What we collect from visitors to this website
This site does not use tracking cookies, analytics services, embedded social media widgets or advertising networks. Nothing on these pages loads from a third party — every image is drawn in the page itself and there are no external fonts or scripts. Our web host keeps a standard access log containing the requesting address, the time of the request, the page requested and the browser identifier. Those logs are kept for fourteen days and are used only to diagnose faults and identify abuse.
What we collect when you contact us
If you telephone, email us, or use the message form on our contact page, we keep a record of the exchange: your name, the business you represent, your contact details, and a note of what was discussed. The contact form asks only for your name, email address and message, and we use what you send solely to reply to you. For enquiries that do not become clients, we keep that record for twelve months in case you get back in touch, and then delete it.
What we hold about clients
For businesses that engage us we hold contact details for the people we are authorised to deal with, a record of the equipment we manage, a history of support requests and the work done on them, and our own billing records. Support ticket histories are kept for six years because they are frequently the only account of why a decision was made. Billing records are kept for the period our accountants and the relevant tax authority require.
Client data we handle on your behalf
In the course of providing backup services we necessarily hold copies of files belonging to our clients, and those files may contain personal information about our clients' own customers, patients, tenants or staff. We do not read that material, we do not index its contents beyond what is needed to make a restore work, and we do not use it for any purpose other than delivering the service. Our engagement terms include a written processing agreement setting out exactly what we may and may not do with it.
Remote support sessions
When an engineer helps you through a shared browser session, we see only what you choose to share and only while the session is open. We ask you to close anything personal before you begin. We do not record the session, and the only lasting record is the short written note of what was done that we email you afterwards. You can read how these sessions work on the remote support page.
Who we share information with
We do not sell information to anybody and we do not pass client contact details to other suppliers for marketing. We share information only where it is necessary to do the work — for example giving a delivery address to a hardware supplier, or raising a support case with a software vendor on a client's behalf with their authority. Our accountants and, if it ever became necessary, our legal advisers may see billing records.
Cookies and tracking
We will keep this section short because there is very little to say: this website sets no cookies at all. There is no analytics, no advertising pixel, no consent banner to click away, and nothing that follows you to another site. The pages work identically whether or not your browser accepts cookies, because they never try to set one. If we ever add a feature that needs a cookie — a client login, say — we will ask you first and explain exactly what it does.
How long we keep things, at a glance
| Information | Kept for | Why |
|---|---|---|
| Website access logs | 14 days | Fault diagnosis and abuse detection |
| Enquiries that do not become clients | 12 months | In case you get back in touch |
| Support ticket history | 6 years | Record of why decisions were made |
| Billing records | As tax rules require | Legal and accounting obligation |
| Client backup copies | The plan's retention period | To be able to restore your data |
| After you leave us | 30 days, then deleted | Safety margin before secure deletion |
Where information is kept
Client backup copies are held on equipment at your own premises and at our facility. Business records such as tickets and invoices are held in systems operated on our behalf under written contract. We do not move client backup material outside the country in which the client operates without asking first, and we keep the number of third parties involved deliberately small so that we always know where your information sits.
Your rights
You can ask us what we hold about you, ask for it to be corrected if it is wrong, ask for it to be deleted where we do not have a legal reason to keep it, and object to particular uses. Write to the address above or email us and we will respond within one calendar month. There is no charge for a reasonable request. If you are unhappy with how we handle it you are entitled to complain to the relevant supervisory authority, and we will give you their details on request.
Marketing
We send an occasional service notice to existing clients — things like a change of office hours or a scheduled maintenance window. That is part of delivering the service and it is not marketing. We do not run a newsletter, we do not send promotional email to people who have not asked for it, and we do not buy contact lists.
Information about children
Our services are provided to businesses, and this website is not aimed at children. We do not knowingly collect personal information from anyone under the age at which they can give their own consent. If a client's backup happens to contain records about young people — a clinic's patient records, for instance — we handle that material under the same processing agreement as any other client data, and only ever to make a restore work.
Terms of service
Applicable to engagements from January 2026
These are the standard terms on which Northvale Systems provides services. Where a signed engagement letter says something different, the engagement letter takes precedence. Nothing here is intended to remove any right you have under consumer or commercial law.
1. The agreement
Our agreement consists of the engagement letter you sign, the service schedule attached to it listing the sites and devices covered, and these terms. The engagement letter records the monthly fee, the plan chosen, and anything specific that has been agreed for your business.
2. Term and notice
The initial term is three months from the date service commences. After that the agreement continues month to month until either party gives thirty days' written notice. Notice may be given by email. On termination we will provide a copy of your data and your site documentation at no charge.
3. Fees and payment
Fees are invoiced monthly in advance and are due within fourteen days. Device counts are taken on the first working day of the month; a device added mid-month is charged pro rata from the following month rather than immediately. Fees may be reviewed once a year with effect from April, notified in writing no later than the preceding January. Late payment may attract interest at the statutory rate, though in practice we ring you first.
4. What we undertake to do
We will perform the services described in your service schedule with reasonable skill and care, using appropriately trained people. We will monitor scheduled backup jobs on every working day and investigate failures. We will test restores at the frequency set out in your plan and report the results to you in writing. We will respond to support requests within the times published on our contact page.
5. What we ask of you
For the service to work, we need reasonable access to your premises and equipment at agreed times, an accurate list of the people authorised to request work, prompt notice of changes such as new equipment or a new office, and current licences for the third-party software you use. If you make significant changes without telling us and additional work results, we may charge for that work at the standard hourly rate.
6. Remote support sessions
Where we help you through a shared browser session, the session runs only with your active consent and only for as long as you keep it open. You control what is shared and can end the session at any time. We will not record a session, and a restore begun during a session may, with your agreement, continue on our side if the session ends before it finishes. Sessions are part of the support included in your plan as set out in your service schedule.
7. Limits of the service
Backup protects against loss of data. It does not protect against every possible business interruption, and no reputable supplier would claim otherwise. Restoring a large volume of information takes time, and the realistic figures for your business are set out in your service schedule. We cannot guarantee recovery of data that was never included in the agreed scope, that was corrupted before a copy was taken, or that was created after the most recent successful run.
8. Liability
Our liability to you in any twelve-month period is limited to the fees you paid us in that period, except where the law does not permit such a limit — for example in cases of death or personal injury caused by negligence, or fraud. We are not liable for indirect or consequential losses such as lost profit or lost business opportunity. We carry professional indemnity and public liability insurance and will provide certificates on request.
9. Confidentiality
Each party will keep the other's confidential information confidential, will use it only for the purpose of the agreement, and will not disclose it except to people who need it to do the work and who are under equivalent obligations. This continues for five years after the agreement ends. Our engineers sign individual confidentiality undertakings on joining and are reminded of them annually, and we are happy to sign a client's own non-disclosure agreement where their circumstances call for one.
10. Subcontracting and general terms
We occasionally use trusted subcontractors for specific tasks, most often cabling work and equipment disposal. We remain responsible to you for anything they do, we tell you in advance when a subcontractor will attend your site, and they work under the same confidentiality obligations we do. Neither party is liable for failure to perform caused by events genuinely outside its control. If any part of these terms is found to be unenforceable, the rest continues to apply. These terms are governed by the law of the jurisdiction in which our registered office sits.
Northvale Systems is a fictional trading name used for illustrative purposes on this page. Telephone numbers and email addresses shown are reserved examples and are not in service.
Back to the home page, or read about remote support, who we are and how to reach us.