1. Who is responsible
3NT Solutions LLP, company number OC363382, is the controller for personal information it uses to operate this website, handle enquiries, administer customer relationships and meet its own security and legal responsibilities. Its registered office is 22 Brondesbury Park, Willesden, London, England, NW6 7DL. Privacy requests may be sent to legal@3nt.com.
Where we process personal data inside a customer's hosted environment on that customer's instructions, the relevant service agreement and Data Processing Addendum govern that processing. These roles must be assessed for the actual activity; outsourcing a task does not automatically remove our responsibilities.
2. Information we use
Enquiries may include your name, email address, organisation, requested service, preferred region, workload, budget and timing. Abuse or legal correspondence may include resource identifiers, timestamps, evidence and contact information. Account administration may involve contract, billing, payment-reference and support records. Risk-based verification may involve the information specifically requested under the Customer Verification Policy.
Our website and administrative systems process technical information needed for delivery and security, such as network identifiers, request and error information, authentication records and actions in the content desk. Technical records can contain personal data. Do not send unnecessary sensitive information, identity documents or account secrets through public forms.
3. Purposes and legal bases
We use relevant information to respond to a request and take steps towards a contract with an individual, or perform that contract where appropriate. For business contacts, protecting systems, preventing fraud and managing ordinary enquiries, we may rely on legitimate interests after considering necessity and the individual's rights. Legal obligations are used as a basis only where an identifiable obligation actually applies.
Consent is used where legally required for a particular activity and may be withdrawn without affecting earlier lawful processing. Accepting service terms or continuing to use a website is not general consent to every use of personal data. Special-category information requires an additional applicable condition; a contract clause alone does not supply it. We do not use the sales form to subscribe you automatically to marketing.
4. Sources and decisions
Most enquiry information comes from you. Other relevant information may come from an authorised representative, payment provider, reporting party, public corporate or sanctions records, or a security source where lawful and necessary. We assess the reliability and relevance of information rather than treating an allegation as established fact.
You may request human consideration of a disputed verification or restriction decision. We do not use this website enquiry form to make a solely automated decision with legal or similarly significant effects about you.
5. Recipients and service providers
Authorised personnel receive information necessary for their role. Infrastructure, security, communications, payment and verification providers may process information to perform the relevant task under appropriate arrangements. Cloudflare provides website hosting and security infrastructure. A transactional email provider processes the information needed to notify the designated team when that integration is enabled. Before a verification provider is used, the applicable processing information is supplied.
Information may be shared with professional advisers or competent authorities where required or otherwise lawfully justified, and in a legitimate business transfer subject to appropriate safeguards. We do not sell enquiry information. Ordinary reports sent to abuse@3nt.com, including the sender’s email address, are automatically forwarded to the customer responsible for the resource. Use security@3nt.com for confidential reports. We do not accept abuse, security or law-enforcement submissions through the sales enquiry form.
6. International processing
The location of your service does not necessarily determine where every account, support or communications record is processed. Where a restricted international transfer takes place, we use an applicable adequacy arrangement or appropriate safeguards, such as the relevant contractual transfer mechanism, and assess supplementary measures where required. You may ask about the safeguards relevant to your data. A country is not assumed adequate simply because a supplier operates there.
7. Retention
Information is kept only for as long as needed for its documented purpose, legal duties and legitimate claims. Closed, unconverted website enquiries are reviewed for deletion at twelve months after the last substantive exchange about the proposed service. They are deleted unless a continuing purpose or necessary hold is documented with a further review date. Routine administrative edits do not restart that period. Open matters are reviewed for continuing need. Routine anti-spam counters expire separately and contain pseudonymous keys rather than a copy of the enquiry.
Contract, invoice and payment records follow the applicable accounting and claims requirements. Identity documents, verification outcomes, access records and hosted content may require different periods. We do not apply an automatic seven-year period to every passport or adopt financial-sector retention rules without assessing whether they apply. The service agreement defines return and deletion of hosted data; a valid preservation requirement may temporarily override a routine schedule.
8. Security and cookies
We apply measures appropriate to the information and risks, including restricted access and secure transmission. No service can promise absolute security. Administrative access and necessary security functions may use cookies. This website does not use advertising pixels or optional analytics. The Cookies Notice explains the website’s use of necessary technology and your choices.
9. Your rights and complaints
Depending on the applicable law and circumstances, you may request access, correction, erasure, restriction, portability or object to processing, and withdraw consent where relied on. Rights are subject to applicable exceptions. We make proportionate identity checks where necessary and respond within the legally applicable period. A complaint or rights request does not require unnecessary identification documents.
Contact legal@3nt.com to make a request. You may complain to the UK Information Commissioner's Office at ico.org.uk or another competent supervisory authority. We welcome an opportunity to address a concern but do not require you to contact us first as a condition of exercising a statutory right.
10. Changes
The version and publication date appear with this notice. Material changes are communicated appropriately. A revised notice describes processing; it does not, by itself, create consent or retrospectively authorise a new purpose.
11. Information received through a provider
Where you obtain a service through a reseller or hosting provider, that provider may supply relevant account, resource-attribution or verification information to us for a specific support, security, compliance or legal purpose. Each party must establish its role and lawful basis, provide appropriate privacy information, minimise the information and use a secure route. The Downstream Customer Verification Standard does not authorise routine transfer of full identity-document archives.
Where we receive information about you from a provider and act as a controller, we provide our privacy information within the applicable period. For information governed by UK GDPR, this is within a reasonable time and at most one month, or earlier at our first communication with you or first disclosure where required. A provider may deliver that information on our behalf with evidence of delivery. Any lawful exception is assessed and recorded for the particular case; the provider’s own notice does not automatically discharge our obligations.
3NT Solutions LLP · OC363382