Legal

Privacy notice

What we collect, why we collect it, how long we keep it and what you can ask us to do about it.

Last updated 2 September 2026 Controller: Aristo Networks Ltd UK & EU GDPR

Who we are

Aristo Networks Ltd is the data controller for the personal data described in this notice. We are registered in England and Wales under company number 16670241, with a registered office at 65 London Wall, London EC2M 5TU, United Kingdom.

For any question about this notice or about your data, write to privacy@aristonetworks.net.

What we collect

We are a network operator selling to businesses, so the personal data we hold is mostly business contact information rather than consumer data.

CategoryExamplesWhere it comes from
Contact dataName, business email, telephone number, job title, employerYou, when you enquire, order or correspond with us
Account dataControl panel usernames, roles, authentication eventsCreated when we set up your access
Service dataCircuit and port records, IP assignments, ASNs, cross connect and LOA detailProvisioning and operating your services
Operational dataTraffic volumes, interface counters, flow samples, routing stateOur network equipment. This concerns your services, and only incidentally identifies individuals
CorrespondenceEmails, tickets, call notes with our NOC and sales desksYou and our team
Website dataIP address, request logs, and any preference stored in your browserYour visit to this site
Billing dataBilling contacts, purchase orders, invoices, payment referencesYou and our finance processes

We do not collect special category data, and we do not ask for it. Please do not send it to us.

Why we use it, and on what basis

PurposeLawful basis
Responding to enquiries and preparing quotesLegitimate interests, and steps prior to entering a contract
Delivering, operating and supporting your servicesPerformance of a contract
Monitoring capacity, faults and security on our networkLegitimate interests in running a reliable and secure network
Investigating abuse and responding to security incidentsLegitimate interests, and legal obligation where one applies
Billing, credit control and financial record keepingPerformance of a contract, and legal obligation
Meeting regulatory, tax and law enforcement obligationsLegal obligation
Sending operational notices such as maintenance windowsPerformance of a contract
Occasional service updates to existing customersLegitimate interests, with an unsubscribe link in every message

We do not sell personal data, and we do not use it for automated decision making that produces legal or similarly significant effects.

This website

The site is deliberately light. It sets no advertising or tracking cookies. Your browser may store a single preference for the day or night theme; that value stays in your browser, is not sent to us and is not used to identify you.

Our web server keeps standard request logs, including IP address, timestamp, requested URL and user agent, for security and diagnostic purposes. Contact forms send their contents to our sales or operations mailboxes.

Who we share it with

  • Data centre and facility operators, where a cross connect or site access needs to be arranged in your name
  • Carriers and interconnection partners, where a service crosses their network
  • Suppliers who process data on our behalf, such as hosting, email and accounting providers, under written terms
  • Professional advisers, auditors and insurers where relevant
  • Regulators, courts and law enforcement where we are legally required to disclose
  • A purchaser or successor, if the business or part of it is transferred

Where it is held

Our operations and infrastructure are in Europe and the United Kingdom. Where a supplier processes data outside the UK or EEA, we rely on an adequacy decision, or on standard contractual clauses with additional safeguards where no adequacy decision applies.

How long we keep it

DataRetention
Enquiries that do not become customers24 months from the last contact
Customer contact and account recordsDuration of the contract plus 6 years
Invoices and financial records6 years, as required by UK tax law
Service and configuration recordsDuration of the service plus 12 months
Traffic statistics and flow dataRolling operational window, then aggregated
Web server logs90 days
Abuse and security incident recordsUp to 24 months, longer where a matter remains open

Your rights

Under the UK GDPR and the EU GDPR you can ask us to give you a copy of your personal data, correct it if it is wrong, delete it where we have no continuing reason to hold it, restrict or object to how we use it, or provide it in a portable form. Where we rely on consent, you can withdraw it at any time.

Write to privacy@aristonetworks.net and we will respond within one month. There is no charge unless a request is manifestly unfounded or excessive.

If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk, or to the supervisory authority in your own country. We would rather you raised it with us first.

Security

Access to customer data is limited to staff who need it, authentication to our systems is protected, and administrative access to network equipment is restricted and logged. If a breach affects your personal data and presents a risk to you, we will notify you and the relevant regulator within the statutory timescales.

Changes

We will update this notice when our processing changes. The date at the top shows the current version. Material changes affecting customers are notified by email.

At a glance
ControllerAristo Networks Ltd
Company no.16670241
Contactprivacy@
Tracking cookiesNone
Data soldNever
Response timeWithin one month
RegulatorICO, United Kingdom