Privacy Policy
Contents
1. Who We Are
EnterpriseTek (“we”, “us”, “our”) operates an enterprise marketing and print fulfilment platform available at enterprisetek.net. We act as a data controller for the personal data described in this policy.
For privacy inquiries, contact: user@enterprisetek.net
2. Data We Collect
Customer & User Account Data
- Full name, email address, phone number, job title
- Organisation name, billing and shipping addresses
- Username, hashed password or SSO token
- Role assignments and permission groups
Product & Order Telemetry
- Orders placed, product selections, quantity and fulfilment status
- Print asset uploads and version history
- Shipment tracking events
Usage & Technical Data
- IP address, browser type, operating system
- Pages visited, session duration, click paths
- Application logs and error traces (retained for operational diagnosis)
Communications Data
- Emails and support tickets you send to us
- In-platform messages and notifications
3. How We Use Your Data
- Service delivery — processing orders, generating print files, managing fulfilment
- Account management — authentication, role-based access, password resets
- Customer support — responding to inquiries, resolving incidents
- Billing — invoicing, payment processing, charge reconciliation
- Security & compliance — fraud detection, audit logging, regulatory obligations
- Product improvement — aggregate usage analytics (no individual profiling for marketing)
- Communications — transactional emails (order confirmations, status updates)
We do not sell personal data to third parties, nor use it for behavioural advertising.
4. Third-Party Subprocessors
We engage the following subprocessors to deliver our service. Each is bound by appropriate data processing agreements:
- Microsoft Azure — cloud hosting, SQL database, storage, Key Vault, Azure Active Directory (EU and US regions)
- Vanta — security compliance monitoring and evidence collection
- GitHub / Azure DevOps — source code repository and CI/CD pipelines
- Auth0 / Okta — identity and single sign-on services
- Mailchimp — transactional and marketing email delivery
- Shippo / FedEx / UPS / USPS — shipment label generation and tracking
- Veeva Vault — regulated content management (for applicable clients)
5. Data Sharing
We share personal data only in the following circumstances:
- With subprocessors listed in §4 strictly to deliver the service
- Legal obligation — where required by law, court order, or regulatory authority
- Business transfer — in the event of a merger, acquisition, or sale of assets (you will be notified in advance)
- With your consent — for any purpose not covered above
6. Retention Windows
- Active account data — retained for the lifetime of the customer relationship
- Order & fulfilment records — 7 years (financial and audit requirements)
- Application & security logs — 90 days rolling
- Support tickets — 3 years
- Closed accounts — anonymised within 90 days of account closure; legal-hold data retained as required
7. Your Rights (Access & Deletion)
Depending on your jurisdiction, you may have the right to:
- Access — request a copy of the personal data we hold about you
- Correction — request correction of inaccurate data
- Deletion — request erasure of your personal data (“right to be forgotten”)
- Portability — receive your data in a structured, machine-readable format
- Objection — object to processing based on legitimate interests
- Restriction — request that we restrict processing while a complaint is resolved
To exercise any right, email user@enterprisetek.net with “Data Request” in the subject line. We will respond within 30 days.
8. Cookies & Tracking
We use the following categories of cookies:
- Strictly necessary — session management, authentication tokens. Cannot be disabled.
- Functional — user preferences (theme, language). Stored locally.
- Analytics — aggregate page-view statistics. Anonymised; no cross-site tracking.
You can manage cookie preferences at any time using the Cookie Settings link in the footer. Disabling non-essential cookies will not affect core service functionality.
9. Security
We protect your data using industry-standard controls including:
- Encryption in transit (TLS 1.2+) and at rest (Azure Storage Service Encryption)
- Role-based access control with least-privilege principles
- Azure Key Vault for secret management (no plaintext credentials in code)
- Managed Identity for service-to-service authentication (no shared passwords)
- Annual penetration testing and continuous vulnerability scanning via Vanta
- Audit logging retained for 90 days and forwarded to a centralised SIEM
10. Contact for Privacy Inquiries
Privacy Officer
EnterpriseTek
Email: user@enterprisetek.net
Trust Portal: Trust.EnterpriseTek.net
11. Changes to This Policy
We review and update this policy at least annually, or whenever there is a material change to how we process personal data. The “Last reviewed” date at the top of this page reflects the most recent review. Material changes will be communicated via email to account holders.
