top of page
Privacy information

Privacy Policy

This notice explains how Bioteknik South East Ltd handles personal information when you use this website or client area, make an enquiry, book equipment into our workshop or use our collection and data-destruction services.

Last reviewed: 16 September 2026

1. Who we are

Bioteknik South East Ltd

Unit 14, Chislet Close, Lakeview International Business Park, Hersden, Canterbury, CT3 4LB

Company number: 9760697
Telephone: 01227 470007
Email: enquiries@bioteknik.net

For the personal information described in this notice, Bioteknik South East Ltd is normally the data controller. For data handled on a client’s instructions, project-specific documentation explains our role and the agreed processing. This does not limit your data-protection rights.

2. Information we collect

The information we receive depends on how you interact with us. It can include:

Contact detailsName, email address, telephone number, postal address where needed, company or organisation and job-related contact information.
Enquiry and project informationCollection postcode, equipment estimates, access details, preferred contact method, service requirements and information you choose to include in messages or forms.
Business recordsQuotes, contracts, collection records, invoices, correspondence and records required to deliver or evidence a service.
Website and device informationIP address, browser/device information, pages visited and interaction data generated through website security, analytics or advertising technologies where applicable.
Marketing interactionInformation about responses to business communications or advertising where those services are used.
Information from other sourcesBusiness contact information supplied by colleagues, clients, public business sources or service partners where relevant to an enquiry or project.

Client accounts and collection records

We hold account identifiers and contact details, the organisations or jobs an account is authorised to access, and records of that access being granted or removed. Collection records can include equipment serial numbers and asset tags, make/model, collection and receipt information, processing results and recorded outcomes. Signing up does not automatically grant access to company information.

Reports, evidence, signatures and verification

Service records may contain authorised contact and signatory names, signatures, dates, asset details, evidence references and uploaded supporting files. Approved clients can access the records and released documents permitted for their account and reporting level. Private workshop notes, internal backups and unreleased documents are not provided through the client portal.

A certificate-verification link can make limited reference, date, status and file-fingerprint information available to a holder of that link. It does not provide client names, equipment serials or the original document file. Copies already downloaded cannot be recalled by later withdrawal of a document or account access.

Workshop repair bookings and device access

Repair records include customer and equipment details, reported faults, accessories, quotations or approvals, technician findings, work, parts, test results, charges, contact notes and collection handover. Where necessary for testing, a temporary local device login or PIN can be held in a dedicated encrypted field for authorised staff. It is masked in the booking screen, excluded from receipts and contact/history logs, and cleared when the repair is marked collected or staff clear and save it earlier. Do not provide online-account passwords through ordinary enquiry forms or free-text notes.

Public environmental reporting

We use processing records to produce aggregated outcome counts and a documented potential CO₂e estimate. The public environmental display does not contain client names, locations or equipment serials. An approved client account can see its permitted contribution. The estimate has its own eligibility rules and is not a verified reduction in the client’s footprint. Staff adjustments have reasons and references retained for review.

We do not ask website visitors to provide special-category personal data through ordinary enquiry forms. Please avoid including sensitive personal information unless it is genuinely necessary for the matter you are contacting us about.

3. Why we use personal information and our lawful bases

We use personal information only where we have a lawful basis to do so. The main purposes are:

Responding to enquiriesTo understand what you need, reply, prepare a quote or take steps towards providing a service.Legitimate interests and, where relevant, steps requested before entering a contract.
Providing servicesTo arrange collections, communicate with authorised contacts, manage project requirements, complete agreed records and administer the customer relationship.Contract, legitimate interests and legal obligations where applicable.
Client accounts and reportingTo manage authorised access, show saved collection progress and provide eligible released records and environmental reporting.Legitimate interests in administering and evidencing our service, and contract where applicable.
Workshop repairsTo book in equipment, diagnose and complete agreed work, communicate with the customer and record approvals, charges and handover.Contract or steps requested before a contract where applicable; legitimate interests and legal obligations for appropriate business records.
Environmental reportingTo prepare aggregate outcome information and scenario estimates, manage eligibility and retain reasons for corrections.Legitimate interests in transparent service reporting and maintaining accurate supporting records.
Accounting and complianceTo maintain financial, tax, waste, contractual and other records that we are required or reasonably need to keep.Legal obligation and legitimate interests.
Website operation and securityTo operate the website, prevent misuse, diagnose faults and maintain appropriate security.Legitimate interests; essential technologies may also be necessary to provide the site.
Analytics and advertisingTo understand website performance and, where enabled, measure advertising or conversion activity.Consent where required for non-essential cookies or similar technologies, together with legitimate business interests in measuring and improving our services.
Business communicationsTo send relevant business-to-business information where permitted and to manage preferences or objections.Legitimate interests and consent where the law requires it.
Legal claims and riskTo establish, exercise or defend legal rights, respond to regulators and protect our business, staff and clients.Legal obligation and legitimate interests.

4. Cookies, analytics and advertising technologies

The website uses technologies that are necessary for core site operation and security. It may also use analytics or advertising technologies, including services supplied by Wix and Google, where those features are enabled.

Non-essential analytics or advertising cookies and similar technologies should only be used where the applicable consent settings allow them. You can use the website's cookie or consent controls, where displayed, to manage non-essential choices.

The technologies used depend on the features enabled. Contact us if you need help understanding or changing a cookie choice. This notice does not itself activate analytics or advertising.

5. Who we share information with

We do not sell personal information. We may share it where necessary with:

  • website, hosting, form and technology providers, including Wix;
  • email, communications and IT service providers;
  • analytics and advertising providers, including Google where those services are enabled;
  • payment, accounting or professional advisers where relevant;
  • couriers, logistics providers, contractors or service partners where needed to deliver an agreed project;
  • public authorities, regulators, law-enforcement bodies or courts where disclosure is required or legally justified; and
  • a purchaser, investor or professional adviser in connection with a genuine business reorganisation or transaction, subject to appropriate confidentiality safeguards.

Where another organisation processes personal information for us, we expect it to use the information only for the agreed purpose and to apply appropriate security and contractual safeguards.

6. International transfers

Some technology providers may process personal information outside the United Kingdom. Where a restricted international transfer takes place, we use or rely on a lawful transfer mechanism appropriate to the circumstances, such as UK adequacy regulations or recognised contractual safeguards.

You can contact us if you want more information about the safeguards relevant to a particular service provider or transfer.

7. How long we keep personal information

We keep information only for as long as it is needed for the purpose for which it was collected, and where necessary to meet legal, accounting, contractual, security or dispute-resolution requirements.

  • Enquiry information is reviewed according to whether the enquiry progresses and whether there is a continuing business reason to retain the correspondence.
  • Customer, contractual, collection and financial records may need to be kept for longer periods to meet legal, tax, accounting, warranty, audit or claims requirements.
  • Client access is reviewed when a role, company relationship or job authorisation changes. Removing access does not automatically erase the underlying collection, accounting or evidence records.
  • Repair records are assessed against completion of the work, customer queries, applicable warranty or claims periods, and accounting or other legal requirements. Temporary local device credentials have the shorter clearing process described above.
  • Reports, evidence, signatures and adjustment records are retained according to the relevant service, audit, legal and claims requirements. Corrections or withdrawal of a document do not necessarily mean its audit record can be deleted.
  • Technical website and security logs are generally retained according to the operational and security settings of the relevant platform or provider.
  • Marketing preference and suppression information may be retained where necessary to respect an opt-out or objection.

We review retention needs periodically and remove or anonymise information when there is no longer a justified reason to keep it.

8. Your data protection rights

Depending on the circumstances and lawful basis, you may have rights to:

  • ask for access to your personal information;
  • ask us to correct inaccurate or incomplete information;
  • ask us to erase information in certain circumstances;
  • ask us to restrict how information is used;
  • object to processing based on legitimate interests;
  • receive certain information in a portable format where the right applies; and
  • withdraw consent at any time where processing is based on consent.
Your right to object

You can object to our use of your personal information where we rely on legitimate interests. You also have an absolute right to object to the use of your personal information for direct marketing.

These rights are not absolute in every situation. We may need to verify your identity before acting on a request, and we will explain if a legal exception applies.

9. Marketing and business communications

We may send relevant business-to-business communications where permitted by law. Where consent is required, we will rely on consent. You can ask us to stop direct marketing at any time by using an unsubscribe facility where provided or by contacting us.

Stopping marketing does not prevent us from sending service, contractual, compliance or administrative communications that are necessary for an existing business relationship.

10. How we protect personal information

We use organisational and technical measures designed to protect personal information against unauthorised access, loss, misuse, alteration or disclosure. Access to business systems and information is limited according to operational need.

No online service can guarantee absolute security. If we identify a personal-data breach, we assess it and take the steps required by applicable data-protection law.

11. Children

This website and our business IT collection services are not directed at children. We do not intentionally use the website to collect personal information from children for marketing or consumer profiling.

12. Changes to this notice

We may update this Privacy Policy when our website, services, suppliers, legal obligations or data-processing activities change. The review date at the top of the page shows when the notice was last materially checked.

13. Contact us and make a complaint

If you have a privacy question, want to exercise a right or are unhappy with how we have handled your information, please contact us first so we can investigate.

Bioteknik South East LtdUnit 14, Chislet Close, Lakeview International Business Park, Hersden, Canterbury, CT3 4LB01227 470007enquiries@bioteknik.net

You also have the right to complain to the UK Information Commissioner's Office (ICO). Current contact and complaint information is available from the ICO's official website at ico.org.uk.

Need to discuss how your information is being used?

Contact Bioteknik and identify the enquiry, project or communication you are asking about so we can locate the relevant records efficiently.

Contact Bioteknik →
bottom of page