1. Introduction
Wesson & Co is a trading name of Launch IT Solutions Ltd (“we”, “us” or “our”), a company registered in England and Wales under company number 16339624.
We are committed to protecting personal data and handling it in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and, where applicable, the Privacy and Electronic Communications Regulations (PECR).
This Privacy Policy explains how we collect, use, store and share personal data when you visit our website, contact us, enquire about our services, become a client, supplier or business contact, or otherwise interact with Wesson & Co.
For privacy enquiries, please use our Contact Us page.
2. Who Is Responsible for Your Data?
For personal data collected for our own business purposes, Launch IT Solutions Ltd is generally the data controller.
When we provide managed IT support, Microsoft 365 administration, cyber security, technical support or other IT services to clients, we may also process personal data on behalf of those clients.
In those circumstances, the client will normally be the data controller and Launch IT Solutions Ltd will act as a data processor. The processing of that information will be governed by the relevant client agreement and data processing terms.
3. Personal Data We May Collect
Depending on how you interact with us, we may collect and process:
Identity and Contact Information
This may include:
- name;
- job title;
- employer or organisation;
- business address;
- business email address;
- telephone or mobile number; and
- other contact information you provide to us.
Enquiry and Service Information
This may include:
- information submitted through our website forms;
- details about your organisation;
- number of users or devices;
- current IT arrangements;
- technology requirements;
- support requests;
- project requirements; and
- information contained within communications with us.
Client and Supplier Information
Where you become a client, supplier or business partner, we may process:
- contact details;
- contractual information;
- billing and transaction information;
- account information;
- correspondence;
- service records;
- support information; and
- information necessary to administer our business relationship.
Technical and Website Information
When you use our website, we may collect technical information such as:
- IP address;
- browser type and version;
- device information;
- operating system;
- pages visited;
- date and time of access;
- referral source; and
- information collected through cookies or similar technologies.
Further information about cookies may be provided through our cookie notice or consent management system.
IT Support and Technical Data
When providing IT services to clients, our engineers may have authorised access to systems, devices, accounts, logs, configuration data and other information required to investigate faults, provide support or manage agreed technology services.
This may occasionally include personal data relating to a client’s employees, customers or other individuals.
Where we process this information on behalf of a client, we do so in accordance with our contractual obligations and the client’s documented instructions.
4. How We Collect Personal Data
We may collect personal data directly from you when you:
- contact us;
- submit an enquiry;
- complete a website form;
- request a quotation;
- become a client;
- raise a support request;
- attend a meeting with us;
- correspond with us;
- enter into a contract with us; or
- otherwise provide information to us.
We may also receive business contact information from publicly available or commercial sources, including:
- company websites;
- professional networking platforms;
- Companies House;
- business directories;
- publicly available industry information;
- professional publications;
- event or industry information; and
- business contact or prospecting services.
Where we obtain personal data from another source for business-to-business marketing, we will process it in accordance with applicable data protection and direct marketing laws. Individuals have the right to object to the use of their personal data for direct marketing at any time. The ICO confirms that UK GDPR still applies where named business contacts are used for B2B marketing, including where those details come from public sources.
5. How We Use Personal Data
We may use personal data to:
- respond to enquiries;
- prepare quotations and proposals;
- provide IT support and managed services;
- administer Microsoft 365 and other agreed technology platforms;
- deliver IT projects and installations;
- provide cyber security services;
- manage client and supplier relationships;
- process invoices and payments;
- maintain business and support records;
- investigate technical issues;
- maintain the security of our systems and services;
- communicate service information;
- manage contracts;
- meet legal, regulatory and insurance requirements;
- prevent fraud, misuse and security incidents;
- improve our website and services; and
- conduct appropriate business-to-business marketing.
6. Our Lawful Bases for Processing
Under UK GDPR, we must have a lawful basis for processing personal data.
Depending on the circumstances, we may rely on:
Contract
Where processing is necessary to:
- enter into a contract with you; or
- perform our obligations under a contract.
Legitimate Interests
We may process personal data where it is reasonably necessary for our legitimate business interests and those interests are not overridden by your rights and freedoms.
Examples may include:
- operating and improving our business;
- managing client and supplier relationships;
- protecting our systems;
- preventing fraud;
- maintaining business records;
- responding to business enquiries; and
- carrying out proportionate business-to-business marketing.
Where legitimate interests are relied upon for direct marketing, we consider whether the activity is necessary and proportionate and whether it could reasonably be expected by the individual. The ICO describes this as a three-part legitimate interests assessment covering purpose, necessity and balancing individual rights.
Legal Obligation
We may process personal data where necessary to comply with legal or regulatory requirements.
Consent
Where we rely on consent, you may withdraw that consent at any time.
Withdrawal of consent will not affect processing that took place before consent was withdrawn.
7. Business-to-Business Marketing
We may contact businesses and business representatives where we reasonably believe our services may be relevant to their organisation.
This may include information obtained from publicly available business sources or reputable business data providers.
Where personal data is used for business-to-business marketing, we process that information in accordance with UK GDPR and PECR where applicable.
The rules differ depending on whether the recipient is a corporate body, sole trader, partnership or individual subscriber. We will apply the appropriate rules to the type of contact involved. The ICO confirms that electronic marketing to corporate subscribers is treated differently under PECR, although UK GDPR still applies where personal data such as an employee’s name or individual business contact details are being processed.
You have the right to object to direct marketing at any time.
Where somebody asks us not to contact them for marketing purposes, we may retain limited information on a suppression list so that we can respect that request in the future.
8. Sharing Personal Data
We do not sell personal data.
We may share information with trusted third parties where necessary to operate our business or deliver services.
These may include:
- cloud service providers;
- Microsoft and Microsoft-related service providers;
- IT management and security platform providers;
- cyber security providers;
- telecommunications providers;
- customer relationship management providers;
- professional advisers;
- accountants;
- insurers;
- payment or financial service providers;
- software vendors;
- subcontractors;
- hosting providers; and
- other technology suppliers used in delivering agreed services.
We may also disclose information where required by:
- law;
- a court;
- law enforcement;
- regulators; or
- another competent authority.
Where a third party processes personal data on our behalf, we require appropriate contractual and security arrangements.
9. Sub-Processors and Client Data
As a managed IT service provider, we may use third-party technology providers to help deliver services to our clients.
Where we act as a processor for client personal data, the use of relevant sub-processors will be governed by our contractual arrangements with that client.
We take reasonable steps to ensure that organisations processing personal data on our behalf provide appropriate data protection and security commitments.
Where required, our client agreements or data processing terms will set out further information about processing, confidentiality, security, sub-processors, data deletion and assistance with data protection obligations.
10. International Data Transfers
Some of the technology providers we use may process or store information outside the United Kingdom.
Where personal data is transferred internationally, we take appropriate steps to ensure that the transfer complies with UK data protection law.
Depending on the circumstances, this may include relying on:
- UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to the EU Standard Contractual Clauses; or
- another lawful transfer mechanism.
Where we act as a processor for a client, international transfers relating to client data may also be governed by our contractual arrangements with that client.
11. Data Security
We use appropriate technical and organisational measures designed to protect personal data against:
- unauthorised access;
- accidental loss;
- alteration;
- disclosure;
- destruction; and
- misuse.
Access to personal data is limited to people and service providers who have a legitimate business need to access it.
No system can guarantee absolute security, but we regularly consider the security measures appropriate to the nature of the information we process and the services we provide.
12. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected.
Retention periods vary depending on:
- the nature of the information;
- whether there is an ongoing client or supplier relationship;
- contractual requirements;
- legal and regulatory obligations;
- accounting and tax requirements;
- insurance requirements;
- security requirements; and
- whether information may be required to establish, exercise or defend legal claims.
Where personal data is processed on behalf of a client, retention and deletion may also be governed by the relevant client agreement and the client’s instructions.
Where information is no longer required, we will delete, anonymise or securely dispose of it where appropriate.
13. Your Data Protection Rights
Depending on the circumstances, UK data protection law may give you the right to:
Access
Request information about the personal data we hold about you and obtain a copy.
Rectification
Ask us to correct personal data that is inaccurate or incomplete.
Erasure
Ask us to delete personal data where there is no longer a lawful reason for us to retain it.
Restriction
Ask us to restrict how your personal data is processed in certain circumstances.
Objection
Object to processing based on legitimate interests.
You have an absolute right to object to the use of your personal data for direct marketing.
Data Portability
Request that certain personal data be transferred to you or another organisation where the legal requirements for portability apply.
Withdraw Consent
Where we rely on consent, you may withdraw that consent at any time.
Some rights are subject to legal conditions and exemptions, and we may need to verify your identity before acting on a request.
14. Data Relating to Our Clients’ Employees or Customers
Where Wesson & Co processes personal data on behalf of one of our clients, the client will normally remain responsible for determining how and why that information is used.
If your personal data is held within a client’s systems and your request relates to that information, you should normally contact the relevant client organisation directly.
We will assist our clients with data protection requests where required under our contractual and legal obligations.
15. Cookies and Website Technologies
Our website may use cookies and similar technologies for purposes such as:
- essential website functionality;
- security;
- remembering preferences;
- website analytics;
- measuring website performance; and
- understanding how visitors interact with our website.
Where consent is legally required before placing a cookie or similar technology on your device, we will seek that consent through the website’s cookie management system.
You can change your cookie preferences using the controls provided on the website.
16. Links to Other Websites
Our website may contain links to websites operated by third parties.
We are not responsible for the privacy practices of those organisations.
We recommend reviewing the privacy information provided by any external website before providing personal data.
17. Children’s Data
Our services are intended for businesses and professional users and are not directed at children.
We do not knowingly use our website to collect personal data from children for marketing purposes.
18. Complaints
If you have concerns about how we handle your personal data, please contact us first so that we have an opportunity to investigate.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK’s supervisory authority for data protection.
Further information about your rights and how to make a complaint is available from the Information Commissioner’s Office. The ICO specifically identifies the right to complain to it as part of the privacy information organisations should provide.
19. Contacting Us About Privacy
For questions about this Privacy Policy, requests relating to your personal data, or other privacy matters, please use our:
Our business address is:
Launch IT Solutions Ltd trading as Wesson & Co
Highcross Business Centre
18 Lancaster Road
Hinckley
Leicestershire
LE10 0AW
United Kingdom
20. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes to:
- our services;
- the technology providers we use;
- our data processing activities; or
- applicable law and regulatory guidance.
The latest version will always be published on this website.
Last updated: September 2026