Thames Systems – Privacy Policy
Last updated: 27 August 2026
Thames Systems Limited respects your privacy and is committed to protecting your personal information.
This Privacy Policy explains how we collect, use, store and protect personal information when you visit our websites, contact us, request a demonstration, communicate with us or otherwise interact with Thames Systems.
It applies to thamessystems.co.uk, thamessystems.com and related Thames Systems website services unless a separate privacy notice is provided.
Please read this privacy policy carefully.
1. Who we are
Thames Systems Limited is the data controller for the personal information covered by this Privacy Policy.
Thames Systems Limited
Company number: 03251850
Registered in England and Wales
Registered office: Nightingale House, 46–48 East Street, Epsom, Surrey, United Kingdom, KT17 1HQ
Head office:
Podium Ealing Cross, 85 Uxbridge Road, London, W5 5TH
Data protection enquiries: admin@thamessystems.com
For certain services provided through the T100 platform, Thames Systems may process personal information on behalf of its clients. In those circumstances, the client will normally be the data controller and Thames Systems will act as a data processor under the relevant client agreement. This Privacy Policy primarily covers information for which Thames Systems itself acts as controller.
2. Data protection law
We process personal information in accordance with applicable UK data protection law, including:
- the UK General Data Protection Regulation (UK GDPR);
- the Data Protection Act 2018;
- the Privacy and Electronic Communications Regulations 2003 (PECR); and
- those laws as amended by the Data (Use and Access) Act 2025.
Where our activities fall within the territorial scope of other data protection legislation, including the EU GDPR, we will also comply with the applicable requirements.
3. Information we collect
Depending on how you interact with us, we may collect:
Contact and professional information
- name;
- job title;
- company or organisation;
- business email address;
- telephone number; and
- information you provide in an enquiry, contact form or demo request.
Business relationship information
- correspondence with you;
- details of enquiries, demonstrations and meetings;
- customer and supplier information;
- support communications; and
- records relating to our commercial relationship.
Technical and website information
- IP address;
- browser and device information;
- operating system;
- pages visited;
- referring pages or websites;
- date, time and duration of visits;
- interactions with website content; and
- cookie and consent information.
We do not intentionally collect special category personal data through our public website and ask that you do not provide this information unless it is necessary.
4. How and why we use personal information
We may use personal information to:
Respond to enquiries and demonstration requests
We use your contact and professional information to respond to questions, arrange demonstrations and discuss our products or services.
Our lawful basis is normally our legitimate interest in responding to business enquiries and developing commercial relationships. Where you are personally entering into a contract with us, processing may also be necessary to take steps at your request before entering into that contract.
Provide and support our services
We use information to manage customer relationships, provide support, administer contracts and communicate about our services.
Our lawful bases may include performance of a contract, compliance with legal obligations and our legitimate interests in operating and supporting our business.
Operate, secure and improve our website
We may process technical information to maintain website security, diagnose problems, prevent abuse and improve website performance and usability.
Our lawful basis is our legitimate interest in operating a secure and effective website.
Website analytics
Where permitted, we use analytics technologies to understand how visitors use our website and improve its performance and content.
Where consent is required under PECR, analytics technologies will only be activated after the appropriate consent has been provided.
Marketing and business development
We may use business contact information to communicate about Thames Systems products, services and relevant developments.
For corporate business contacts, we may rely on legitimate interests where permitted by applicable direct-marketing rules. Where consent or the PECR soft opt-in is required, we will only send electronic marketing where those requirements have been satisfied.
You can object to direct marketing at any time. We will respect your request and may retain limited information on a suppression list so that we do not contact you again.
Legal, regulatory and security purposes
We may process information where necessary to comply with legal or regulatory obligations, establish or defend legal claims, prevent fraud or protect our systems, business and users.
5. Cookies and website technologies
Our websites use cookies and similar technologies.
We provide more detailed information about the technologies in use, their purposes, providers and retention periods in our Cookie Policy and cookie preference centre.
Depending on the configuration of the website, third-party technologies may include:
- Google Tag Manager, used to manage website tags;
- Google Analytics, where enabled, to understand website usage;
- Google Maps, used to display office locations; and
- Google reCAPTCHA, where enabled, to help protect website forms from spam and abuse.
Some of these services may receive technical information such as your IP address, browser information or interactions with the relevant service.
Where consent is legally required, these technologies will not be activated until consent has been obtained.
6. Contact forms
When you submit a contact form or request a demonstration, we may collect your name, job title, company, email address, telephone number and the content of your message.
This information is processed so that we can respond to your enquiry and manage any subsequent business relationship.
Form submissions may be processed through our website hosting, form-processing and email-delivery infrastructure. Access is limited to authorised personnel and service providers that require the information to perform services for us.
7. Who we share personal information with
We may share personal information where necessary with:
- authorised Thames Systems employees and personnel;
- website hosting, infrastructure, email and communication providers;
- analytics, security and website technology providers;
- professional advisers such as accountants, lawyers and auditors;
- regulators, law-enforcement agencies or public authorities where required by law; and
- prospective purchasers or advisers in connection with a merger, acquisition or restructuring of our business.
We require service providers that process personal information for us to protect it appropriately and use it only for authorised purposes.
We do not sell personal information.
8. International transfers
Some of our service providers, technology providers or authorised personnel may process personal information outside the United Kingdom, including in the United States.
Where a transfer is subject to UK international-transfer restrictions, we will use an appropriate lawful transfer mechanism.
This may include UK adequacy regulations, including the UK Extension to the EU-US Data Privacy Framework where applicable, or approved contractual safeguards such as the UK International Data Transfer Agreement or UK Addendum together with any required transfer assessment.
9. How long we keep information
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, regulatory, accounting and security requirements.
As a general retention framework:
| Information | Typical retention |
|---|---|
| General enquiries and demo requests that do not become customers | Up to 24 months after the last meaningful interaction |
| Customer and contractual records | Normally for the duration of the relationship and up to 6 years afterwards |
| Marketing information | Until you opt out or the information is no longer required for marketing purposes |
| Marketing suppression records | As long as reasonably necessary to ensure your opt-out continues to be respected |
| Website analytics | According to the retention period configured within the relevant analytics service |
| Security and server records | According to our operational and security retention requirements |
We may keep information for longer where required by law or where necessary to establish, exercise or defend legal claims.
10. How we protect personal information
We use appropriate technical and organisational measures designed to protect personal information against unauthorised access, loss, alteration or disclosure.
These measures include access controls, encryption in transit using TLS/HTTPS, appropriate system security, restricted administrative access and processes for identifying and responding to security incidents.
Further information about our approach to security is available on our Trust & Security page.
No internet-based system can be guaranteed to be completely secure, but we regularly review our security measures in light of the nature of the information we process and the risks involved.
11. Your rights
Depending on the circumstances and the lawful basis being relied upon, you may have the right to:
- request access to your personal information;
- request correction of inaccurate or incomplete information;
- request deletion of your personal information;
- request restriction of processing;
- object to processing based on legitimate interests;
- object to direct marketing at any time;
- request transfer of certain information to you or another organisation; and
- withdraw consent where processing is based on consent.
These rights are not absolute and exemptions may apply.
To exercise your rights, contact admin@thamessystems.com.
12. Automated decision-making
Thames Systems does not use personal information collected through its public website to make solely automated decisions that produce legal or similarly significant effects on individuals.
Where T100 customers use automated monitoring or risk-assessment functionality within their own systems, the relevant customer will generally determine the purpose and manner of that processing.
13. Data protection complaints
If you are concerned about how we have handled your personal information, please contact us at admin@thamessystems.com.
We will provide a clear process for raising data protection complaints, acknowledge a complaint within 30 days and investigate and respond without undue delay.
You also have the right to raise a complaint with the Information Commissioner’s Office (ICO), the UK’s data protection regulator.
We would appreciate the opportunity to address your concerns directly before you approach the ICO.
14. Third-party websites
Our website may contain links to websites operated by third parties.
We are not responsible for the privacy practices of those organisations. We recommend reviewing their privacy information before providing them with personal information.
15. Children
Our website and services are intended for businesses and professional users and are not directed at children.
We do not knowingly use the website to collect personal information from children.
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to our services, technology or legal obligations.
The latest version will be published on this page and the date at the top of the policy will be updated accordingly.
17. Contact us
For questions about this Privacy Policy, your personal information or your data protection rights, contact:
Thames Systems Limited
Nightingale House
46–48 East Street
Epsom
Surrey
KT17 1HQ
United Kingdom
Email: admin@thamessystems.com