Effective Date: September 14, 2026
Last Updated: September 14, 2026
1. Introduction
Welcome to One EPOS (“we,” “our,” or “us”). We are committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our website at https://oneepos.uk/ or purchase our EPOS systems and related services.
This policy applies under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Data Controller Information
For the purposes of applicable data protection law, the data controller is:
- Company Name: One EPOS
- Website: https://oneepos.uk/
- Email: support@oneepos.uk
- Jurisdiction: England and Wales, United Kingdom
3. Personal Data We Collect
We may collect and process the following categories of personal information:
- Identity Data: Name, business name, job title.
- Contact Data: Billing address, delivery address, email address, telephone numbers.
- Financial Data: Payment card details, bank account details (processed securely through PCI-DSS compliant third-party payment gateways).
- Transaction Data: Details of products, software subscriptions, and hardware purchased from us.
- Technical Data: IP address, browser type, time zone setting, operating system, and analytical data regarding your visit.
- Communication Data: Inquiries submitted via online forms, email correspondence, or customer support channels.
4. How We Collect Your Data
We collect personal data directly when you:
- Fill out inquiry or quote request forms on our website.
- Purchase EPOS equipment, software, or support packages.
- Subscribe to our newsletters or marketing communications.
- Contact our customer service team.
- Accept non-essential cookies on our site.
5. Legal Basis for Processing
We only process your personal data where we have a lawful basis under UK GDPR:
- Contractual Necessity: Processing required to fulfill orders or provide software/hardware services.
- Legitimate Interests: Operations necessary for fraud prevention, service improvement, and direct marketing to business contacts.
- Legal Obligation: Maintaining accounting records for HM Revenue & Customs (HMRC).
- Consent: When you explicitly opt into non-essential cookies or direct marketing communications.
6. Data Sharing and Third Parties
We do not sell your personal data. We share data only with trusted service providers necessary to operate our business:
- Payment processors (e.g., Stripe, PayPal, bank networks).
- Logistics and courier partners for hardware delivery.
- Cloud hosting and IT infrastructure providers within the UK/EEA.
- Analytics providers (e.g., Google Analytics).
All third parties are contractually bound to process data securely in compliance with UK GDPR.
7. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, or statutory reporting obligations (typically up to 6 years post-transaction for UK tax purposes).
8. Your Data Protection Rights
Under UK GDPR, you have the following rights:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your personal data (“right to be forgotten”).
- Right to Restrict Processing: Request restriction of processing under certain conditions.
- Right to Data Portability: Request transfer of your data to another provider.
- Right to Object: Object to processing based on legitimate interests or direct marketing.
To exercise any of these rights, contact us at support@oneepos.uk. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at www.ico.org.uk.
