Privacy notice
What we collect, why we collect it, how long we keep it and what you can ask us to do about it.
Who we are
Aristo Networks Ltd is the data controller for the personal data described in this notice. We are registered in England and Wales under company number 16670241, with a registered office at 65 London Wall, London EC2M 5TU, United Kingdom.
For any question about this notice or about your data, write to privacy@aristonetworks.net.
What we collect
We are a network operator selling to businesses, so the personal data we hold is mostly business contact information rather than consumer data.
| Category | Examples | Where it comes from |
|---|---|---|
| Contact data | Name, business email, telephone number, job title, employer | You, when you enquire, order or correspond with us |
| Account data | Control panel usernames, roles, authentication events | Created when we set up your access |
| Service data | Circuit and port records, IP assignments, ASNs, cross connect and LOA detail | Provisioning and operating your services |
| Operational data | Traffic volumes, interface counters, flow samples, routing state | Our network equipment. This concerns your services, and only incidentally identifies individuals |
| Correspondence | Emails, tickets, call notes with our NOC and sales desks | You and our team |
| Website data | IP address, request logs, and any preference stored in your browser | Your visit to this site |
| Billing data | Billing contacts, purchase orders, invoices, payment references | You and our finance processes |
We do not collect special category data, and we do not ask for it. Please do not send it to us.
Why we use it, and on what basis
| Purpose | Lawful basis |
|---|---|
| Responding to enquiries and preparing quotes | Legitimate interests, and steps prior to entering a contract |
| Delivering, operating and supporting your services | Performance of a contract |
| Monitoring capacity, faults and security on our network | Legitimate interests in running a reliable and secure network |
| Investigating abuse and responding to security incidents | Legitimate interests, and legal obligation where one applies |
| Billing, credit control and financial record keeping | Performance of a contract, and legal obligation |
| Meeting regulatory, tax and law enforcement obligations | Legal obligation |
| Sending operational notices such as maintenance windows | Performance of a contract |
| Occasional service updates to existing customers | Legitimate interests, with an unsubscribe link in every message |
We do not sell personal data, and we do not use it for automated decision making that produces legal or similarly significant effects.
This website
The site is deliberately light. It sets no advertising or tracking cookies. Your browser may store a single preference for the day or night theme; that value stays in your browser, is not sent to us and is not used to identify you.
Our web server keeps standard request logs, including IP address, timestamp, requested URL and user agent, for security and diagnostic purposes. Contact forms send their contents to our sales or operations mailboxes.
Who we share it with
- Data centre and facility operators, where a cross connect or site access needs to be arranged in your name
- Carriers and interconnection partners, where a service crosses their network
- Suppliers who process data on our behalf, such as hosting, email and accounting providers, under written terms
- Professional advisers, auditors and insurers where relevant
- Regulators, courts and law enforcement where we are legally required to disclose
- A purchaser or successor, if the business or part of it is transferred
Where it is held
Our operations and infrastructure are in Europe and the United Kingdom. Where a supplier processes data outside the UK or EEA, we rely on an adequacy decision, or on standard contractual clauses with additional safeguards where no adequacy decision applies.
How long we keep it
| Data | Retention |
|---|---|
| Enquiries that do not become customers | 24 months from the last contact |
| Customer contact and account records | Duration of the contract plus 6 years |
| Invoices and financial records | 6 years, as required by UK tax law |
| Service and configuration records | Duration of the service plus 12 months |
| Traffic statistics and flow data | Rolling operational window, then aggregated |
| Web server logs | 90 days |
| Abuse and security incident records | Up to 24 months, longer where a matter remains open |
Your rights
Under the UK GDPR and the EU GDPR you can ask us to give you a copy of your personal data, correct it if it is wrong, delete it where we have no continuing reason to hold it, restrict or object to how we use it, or provide it in a portable form. Where we rely on consent, you can withdraw it at any time.
Write to privacy@aristonetworks.net and we will respond within one month. There is no charge unless a request is manifestly unfounded or excessive.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk, or to the supervisory authority in your own country. We would rather you raised it with us first.
Security
Access to customer data is limited to staff who need it, authentication to our systems is protected, and administrative access to network equipment is restricted and logged. If a breach affects your personal data and presents a risk to you, we will notify you and the relevant regulator within the statutory timescales.
Changes
We will update this notice when our processing changes. The date at the top shows the current version. Material changes affecting customers are notified by email.