Effective date: 14 April 2026
Last updated: 10 August 2026
1. Introduction
Welcome to Revolve ITAD Solutions Ltd (“we”, “our” or “us”).
We are committed to protecting your personal data and respecting your privacy. This privacy
policy explains how we collect, use, process and safeguard your information when you use our
website or engage our IT Asset Disposal (ITAD) services.
2. Our role in data protection
Due to the nature of our business, we handle data in two distinct ways:
- As a data controller: when we collect your contact information, billing
details or website usage data to manage our business relationship with you.
- As a data processor: when we handle, wipe or physically destroy IT assets
(such as hard drives, laptops and servers) on your behalf. The data residing on those
assets belongs to you (the data controller), and we process it strictly in accordance with
your instructions and our secure data destruction protocols.
3. Information we collect
We may collect and process the following types of data:
- Identity and contact data: names, business email addresses, phone numbers
and job titles of our clients and business partners.
- Financial and transaction data: billing addresses, payment details and
records of services purchased.
- Asset documentation: asset serial numbers, collection manifests and data
destruction certificates.
- Technical and usage data: IP addresses and browser information, where a
third-party service we use records it. See section 8 for what our website does and does
not collect.
4. How we use your data
We use your personal data as a data controller for the following purposes:
- To provide and manage our ITAD, collection and logistics services.
- To issue asset tracking reports and certificates of data destruction.
- To process payments and manage billing.
- To communicate with you regarding service updates, compliance or customer support.
- To comply with our legal, environmental and regulatory obligations.
5. Legal basis for processing (UK GDPR)
We rely on the following legal bases to process your personal data:
- Performance of a contract: to deliver the IT asset disposal services you
have requested.
- Legal obligation: to retain records required for tax, environmental or
compliance audits.
- Legitimate interests: to improve our services, manage our business
efficiently and market relevant business services to you (which you can opt out of at any
time).
- Consent: for any non-essential cookies, as described in section 8.
6. Data destruction and IT asset processing
When you entrust us with data-bearing devices, we process them strictly in accordance with
your instructions.
- No access policy: we do not access, copy, review or use the personal or
corporate data stored on your end-of-life assets for our own purposes.
- Data erasure standards: all data is permanently and irreversibly
destroyed. We offer flexible data destruction tiers to meet varying compliance and budget
requirements:
- Standard erasure (default): data-bearing devices undergo a secure wipe
using industry-leading software. This process is fully compatible with the
industry-recognised NIST SP 800-88 Rev 2 (Purge) standard, ensuring data cannot be
recovered.
- Certified erasure: for clients requiring advanced compliance reporting
and verifiable audit trails, we offer certified data wiping using industry-leading
Blancco software (available for an additional fee). This also conforms to the NIST
800-88 standard, but provides tamper-proof, serialised certificates for each
individual asset.
- Custom erasure standards: if your organisation requires compliance
with a different specific data destruction standard (for example DoD 5220.22-M), we
can accommodate these requests. Pricing for custom standards varies based on the
specific requirements.
- Physical destruction: where software wiping is not possible (for example
heavily damaged or failed drives), or if explicitly requested and paid for by the client,
we utilise secure physical destruction methods.
- Audit trail: on completion of our data destruction processes, we provide
formal documentation or a Certificate of Destruction (depending on the chosen service
tier) for your compliance and data protection records.
7. Data sharing and third parties
We do not sell your personal data. To operate our business efficiently and securely, we may
share necessary information with trusted third-party data processors who act on our behalf.
These include:
- Novafox ERP: our Enterprise Resource Planning system, used to manage
customer relationships, logistics and asset tracking, and to generate your audit reports
and certificates.
- HubSpot: our Customer Relationship Management (CRM) platform, used to
manage communications, client onboarding and marketing. Our website booking form is
provided by HubSpot — see section 8.
- Microsoft 365: our internal infrastructure for secure email communications
and document management.
- Our website hosting provider: which stores the website files and keeps
standard server access logs.
- Approved downstream partners: specialised recycling facilities for
processing end-of-life materials. We ensure these partners are strictly vetted and
compliant with environmental and data protection standards.
- Regulatory authorities: we may disclose your data if required by law,
court order or environmental auditing bodies (for example the Environment Agency).
All third-party service providers are bound by data processing agreements to ensure your data
is kept secure and is only used for the purposes we specify.
8. Cookies and our website
Our website is hand-built and served as pre-rendered static HTML. It does not run WordPress or
any other third-party content management system, and it has no user accounts, logins or
comment features. We do not use analytics or advertising cookies, and we do not track you
across other websites.
Only two things store anything in your browser:
- Your cookie choice (essential). When you accept or decline below, we store
that preference in your browser so we do not ask again. This is stored locally on your
device and is never sent to us.
- The HubSpot booking form (requires consent). Our “Book a
Collection” form is embedded from HubSpot. When it loads, HubSpot sets cookies
(including
hubspotutk) that link your form submission to your enquiry record
in our CRM. Because these are not strictly necessary to view the site, the form is only
loaded once you have accepted. If you decline, the form is not loaded and no HubSpot
cookies are set — you can still contact us by phone or email, and we will book your
collection that way.
You can change your choice at any time using the
cookie settings link in our
footer, and you can delete cookies through your browser settings at any point.
9. Data security
We implement robust technical and organisational measures to protect both your corporate
contact data and the IT assets in our custody. Assets are handled securely from the point of
collection through to final processing, refurbishment or recycling, ensuring unauthorised
access is prevented.
10. Data retention
We retain your contact and transaction data only for as long as necessary to fulfil the
purposes we collected it for, including satisfying any legal, accounting or reporting
requirements. Certificates of destruction and audit trails are kept for 7 years to support
your compliance needs.
11. Your rights
Under the UK GDPR, you have the right to:
- Request access to the personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request erasure of your personal data (subject to legal retention requirements).
- Object to, or restrict, the processing of your data.
- Request the transfer of your data to another party.
- Withdraw consent at any time, where we rely on consent to process your data.
To exercise any of these rights, contact us using the details below. We will respond within
one month.
You also have the right to lodge a complaint with the Information Commissioner's Office, the
UK supervisory authority for data protection. You can do so at
ico.org.uk/make-a-complaint
or by calling 0303 123 1113. We would appreciate the chance to deal with your concerns
first, so please do come to us before you approach the ICO.
12. Contact us
If you have any questions about this privacy policy or how we handle your data, please contact
us at:
Revolve ITAD Solutions Ltd
Unit 4, Copley Valley Business Park, Copley Valley Road, Sowerby Bridge, West Yorkshire, HX6 2WA
Email: info@revolveitad.co.uk
Telephone: 01422 416821
ICO registration: ZC107193