GDPR Policy
UK GDPR Policy
Formal information for customers, suppliers, website users and other parties engaging with Mill Tech Limited.
Last updated: 13 August 2026
1. Data controller
For the purposes of UK data protection law, Mill Tech Limited acts as data controller for personal information processed through this website and through direct business communications. Our registered company number is 16841044 and our business address is Unit 4, Carr Wood Road, P K P Trading Estate, Castleford, WF10 4SB.
2. Scope of this policy
This policy applies to website users, prospective customers, customers, suppliers, contractors, trade contacts, professional advisers and other individuals whose personal information may be processed by us during normal business activity. It covers enquiry handling, quotation discussions, supplier and customer administration, delivery coordination, record keeping, website operation and legal compliance.
3. Data protection principles
We aim to process personal information lawfully, fairly and transparently. We use information for specified and legitimate purposes, keep information relevant and proportionate, take reasonable steps to keep it accurate, retain it only where there is a reason to do so, protect it using appropriate safeguards and handle accountability requirements through clear internal responsibility.
4. Categories of data
The categories of data we may process include contact details, company information, role or job title, enquiry content, quotation details, product or service interest, delivery information, accounting and billing records, correspondence history, technical website data, security logs and consent or communication preferences.
5. Lawful basis table
| Processing activity | Likely lawful basis | Purpose |
|---|---|---|
| Responding to enquiries | Legitimate interests or steps before contract | To answer questions and provide quotation information |
| Managing orders and supply | Contract performance or legitimate interests | To supply agreed goods or services and coordinate delivery |
| Accounting and tax records | Legal obligation | To maintain required business and financial records |
| Website security | Legitimate interests | To protect the website and prevent misuse |
| Optional communications | Consent or legitimate interests depending on context | To provide relevant updates where lawful |
6. Individual rights process
Requests relating to personal information can be sent to imtiaz@milltech.tech. We will review each request, verify identity where required, identify the relevant records and respond within the applicable timeframe unless an extension is permitted by law. Rights may be subject to exemptions, including where records must be kept for legal claims, accounting or compliance.
7. Right of access
Individuals may ask whether we process their personal information and request a copy of that information. Where a valid access request is made, we will provide the information required by law, subject to identity checks and applicable exemptions.
8. Rectification and erasure
If information is inaccurate or incomplete, an individual may request correction. Individuals may also request deletion where information is no longer required, consent has been withdrawn where relevant, processing is unlawful, or deletion is otherwise required by law. We may retain information where necessary for legal obligations, contractual records, accounting, dispute handling or legitimate business reasons.
9. Restriction, objection and portability
Individuals may request restriction of processing in certain circumstances, object to processing based on legitimate interests, and request data portability where the legal conditions apply. We will assess each request based on the information involved, the lawful basis, the purpose of processing and any overriding legitimate grounds.
10. Data security
We use proportionate safeguards to protect personal information. These may include restricted access, secure passwords, business email controls, hosting security, malware protection, system updates, supplier review and practical record handling procedures. Staff or authorised representatives with access to personal information are expected to handle it responsibly and only for relevant business purposes.
11. Breach management
If a personal data breach is suspected, we will assess the nature of the incident, the information involved, the likely impact on individuals, containment steps and reporting obligations. Where a breach is likely to result in a risk to rights and freedoms, we will consider notification to the Information Commissioner’s Office and affected individuals in line with legal requirements.
12. Processors and suppliers
Where we use service providers that process personal information on our behalf, we expect them to apply appropriate security and confidentiality standards. Providers may include hosting, email, IT, accounting, delivery, professional advisory and website service providers.