Privacy Policy
This privacy policy sets out how PC Repair Leeds Ltd uses and protects any information that you give us when you are using this website.
Last updated: 11 August 2026
This notice explains what PC Repair Leeds Limited, trading as QLine IT, does with personal information — what we collect, why, who we share it with, how long we keep it, and what rights you have. It replaces our previous privacy policy in full. We have added sections on our use of artificial intelligence and on the recording of calls, and we have set out our lawful bases, our suppliers and our retention periods.
Who we are
This notice is issued by PC Repair Leeds Limited, trading as QLine IT, a company registered in England and Wales under company number 07500720, whose registered office is 6 Groundfloor, Unit 6 Killingbeck Court, Leeds, West Yorkshire, LS14 6FD.
We are registered with the Information Commissioner’s Office under registration number ZA122621.
For any data protection question, or to exercise any of the rights set out below, contact:
- Carl-Darren Marx, Director
- Email: privacy@qlineit.com
- Telephone: 0113 8000 192
- Post: Data Protection, QLine IT, 6 Groundfloor, Unit 6 Killingbeck Court, Leeds, West Yorkshire, LS14 6FD
When we are the controller and when we are the processor
This distinction matters, because it changes who you should contact.
We are the controller when you visit this website, enquire about our services, become our client, or deal with us as a supplier or job applicant. In those situations we decide how your information is used, and this notice applies to you directly.
We are the processor when we support a client’s IT systems and, in doing so, handle personal data belonging to that client’s staff, customers, patients or contacts. In those situations the client is the controller, we act only on their documented written instructions, and their privacy notice — not ours — governs the processing. If your information was given to us by an organisation whose IT we support, please contact that organisation first. If you contact us instead, we will pass your request to them and tell you that we have done so.
What information we collect
Depending on how you deal with us, we may collect:
- Identity and contact details — your name, job title, company name, email address, telephone number, and postal or site address
- Service and support information — support tickets, correspondence, device and network details, system logs, remote support session records, and notes of what was done and when
- Call recordings and transcripts — recordings of telephone calls to and from our business numbers, the written transcripts produced from them, and the summaries and flags produced from those transcripts
- Billing information — purchase orders, invoices, payment records and bank details. We do not store payment card numbers
- Website information — pages visited, referring site, approximate location, browser and device type, and anything you submit through our contact forms
- Marketing preferences — whether you have consented to, or opted out of, hearing from us
We do not ask for special category data — information about health, race, religion, sexual orientation, political opinions, trade union membership, genetics or biometrics — or information about criminal offences, and you should not send it to us unless we have specifically asked for it in writing. Please see the note about call recordings below, which is the one place this needs care.
What we use it for, and our lawful basis
| What we do | Our lawful basis |
|---|---|
| Responding to your enquiry and preparing a quotation | Taking steps at your request before entering a contract (Article 6(1)(b)), or our legitimate interests in responding to business enquiries (Article 6(1)(f)) |
| Delivering IT support, projects and managed services | Performance of our contract with you or your organisation (Article 6(1)(b)), or our legitimate interests in delivering services to our business clients (Article 6(1)(f)) |
| Invoicing, credit control and keeping accounting records | Performance of a contract (Article 6(1)(b)) and compliance with our legal obligations (Article 6(1)(c)) |
| Recording calls, transcribing them, and analysing the transcripts | Our legitimate interests in accurate record-keeping, catching promised callbacks that have not happened, resolving disputes and maintaining the quality of our service (Article 6(1)(f)). Where local law requires the agreement of everyone on the call, we ask at the start |
| Producing internal suggestion notes on support tickets | Performance of our contract, and our legitimate interests in resolving your issue accurately and quickly (Articles 6(1)(b) and 6(1)(f)) |
| Using AI tools to help us draft and summarise our own material | Our legitimate interests in working accurately and efficiently (Article 6(1)(f)) |
| Sending you information about our services | Your consent, or our legitimate interests in marketing similar services to existing customers under the soft opt-in in the Privacy and Electronic Communications Regulations. You can opt out at any time |
| Protecting our systems and yours from attack, fraud and misuse | Our legitimate interests in security (Article 6(1)(f)), and compliance with our legal obligations (Article 6(1)(c)) |
| Website analytics | Your consent, given through our cookie banner. See our Cookie Policy |
Where we rely on legitimate interests, we have balanced those interests against your rights and concluded that our processing does not override them. You can ask us for a summary of that assessment at any time.
How we use artificial intelligence
We use artificial intelligence (“AI”) in two distinct ways. They involve different systems and different safeguards, so we set them out separately.
1. Automated analysis of calls and support tickets
Two of our internal systems use AI automatically, without a member of staff choosing to run them.
Call analysis. Calls to and from our business numbers are recorded by our telephony provider, whose systems are in the United Kingdom. Every few hours we retrieve the recordings to a server we own and control, also in the United Kingdom, and transcribe them on that server using speech recognition software that runs locally. The audio never leaves the United Kingdom and is never sent to any third party. The written transcript is then sent to Anthropic’s Claude API, which reviews it and flags customer complaints, callbacks or follow-ups we promised and have not delivered, and anything that a director ought to see — for example, a client telling us they are unhappy or considering leaving. We also use it to check the quality of our own call handling.
Support ticket suggestions. When a support ticket is created, its text is sent to the same Anthropic service, which produces an internal note for our technician suggesting the likely cause, what to try, and any relevant history. Email addresses, telephone numbers and postcodes are removed from the ticket before it is sent. The note is private to QLine staff.
For both systems:
- Anthropic PBC acts as our processor, under its Commercial Terms of Service, which incorporate a data processing agreement including Standard Contractual Clauses.
- Anthropic does not use this data to train its models, and does not retain it by default.
- The output is internal only. It never contacts you, never changes anything in your systems, and never makes a decision about you or your service.
- Access to the resulting dashboards requires a Microsoft 365 sign-in with two-factor authentication and is limited to authorised staff.
2. AI tools our staff use directly
Our staff also use AI assistants — Claude, ChatGPT and Microsoft 365 Copilot — to help draft, check and summarise our own written material, to search our internal documents, and to assist with technical work.
We are currently completing a programme of work to move every one of these onto a business plan carrying a data processing agreement, with model training disabled and retention limited. Until that programme is complete, we do not put personal data belonging to our clients or their customers into these assistants. We will update this section, and publish the full list, as soon as that work is finished. To be told when we do, email privacy@qlineit.com.
What we do not use AI for
- We do not use AI to make any decision that produces a legal effect concerning you, or that similarly significantly affects you. Decisions about your service, pricing, credit terms, employment or engagement are always made by a person.
- We do not use AI for emotion recognition, for biometric categorisation, or to build automated profiles of individuals.
- We do not identify speakers by voiceprint. Where a recording has separate channels, we label them by which line they came from, not by recognising a voice.
- We do not deliberately put health information, information about criminal offences, or payment card details into any AI tool. A transcript, however, is whatever was said out loud. If you need to discuss something sensitive with us, please see the note in the next section.
Your right to object
You have the right to object to this processing on grounds relating to your particular situation. If you object, we will handle your matter without AI analysis. Email privacy@qlineit.com and we will confirm within five working days.
Recording of calls
We record telephone calls to and from our business numbers. On incoming calls an announcement tells you so before you are connected. On outgoing calls the member of staff calling you tells you at the start of the call. Recordings are transcribed and analysed as described above.
- Why: to keep an accurate record of what was agreed, to catch follow-ups we promised and have not delivered, to investigate queries and disputes, and to maintain and improve the quality of our support.
- Our lawful basis: our legitimate interests in accurate record-keeping and service quality. Where the law of your country requires the agreement of everyone on the call, we ask for it at the start and you are free to decline.
- Who can access them: named, authorised members of QLine IT staff only, through a dashboard protected by two-factor authentication.
- Automated decisions: none. The analysis produces a flag on an internal dashboard, which a person reads. No decision about anyone’s service, or about any member of our staff, is made automatically.
- How long: our policy is that the recording and the full transcript are both deleted after 90 days, and that we keep only the short summaries and flags for 12 months so that we can see how our service is doing over time. We are currently completing the technical work to apply those periods automatically — see the retention table below for the position today.
If you would prefer a call not to be recorded, say so at the start and we will continue without recording, or arrange another way to talk. We would particularly ask you to do this if you need to discuss health, safeguarding or other sensitive matters, because a transcript records whatever is said aloud.
Who we share your information with
We do not sell, rent or trade personal information. We share it only with suppliers who process it on our instructions, and with the professional advisers and authorities listed below.
| Who | What for | Where |
|---|---|---|
| Onsim | Our telephone service, and recording of calls | United Kingdom |
| Anthropic PBC | AI analysis of call transcripts and support ticket text, as described above | United States |
| Syncro | Support ticketing and remote monitoring of the systems we look after | United States |
| Microsoft Ireland Operations Limited | Email, documents, Teams and our internal systems | EU and United States |
| Intuit (QuickBooks) | Invoicing and accounting | United States |
| DigitalOcean | The servers on which our own systems run | United Kingdom (London) |
| Netlify, Cloudflare and Fasthosts Internet Limited | Website hosting, security and domain services | United States and United Kingdom |
| Formspree | Processing messages sent through our website contact forms | United States |
| Website analytics, only where you have consented | United States | |
| Our accountants, insurers and legal advisers | Professional advice, where relevant | United Kingdom |
| Law enforcement, regulators and courts | Where we are legally required to disclose | United Kingdom |
Every supplier acting on our behalf is engaged under a written contract that requires them to keep your information confidential, to use it only for the purpose we have given them, and to protect it appropriately.
Speech recognition is not on this list, and that is deliberate. Call recordings are held in the United Kingdom by our telephony provider, and are transcribed by software running on a server we own and control, also in the United Kingdom. The audio is never sent to a transcription company, and never leaves the country. Only the written transcript is sent outside the United Kingdom, to Anthropic, as described in the artificial intelligence section above.
Sending information outside the UK
Some of our suppliers are based in the United States or process information there. When we transfer personal information outside the UK we rely on one of the following:
- A finding of adequacy by the UK Government, including the UK Extension to the EU–US Data Privacy Framework where the receiving organisation is certified under it; or
- The International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment.
For transfers of EU personal data we rely on the corresponding EU mechanisms, including the EU–US Data Privacy Framework and the Standard Contractual Clauses.
You can ask us which safeguard applies to a particular supplier by emailing privacy@qlineit.com.
How long we keep your information
| Information | How long |
|---|---|
| Enquiries that do not become work | 12 months from the last contact |
| Client records, tickets and correspondence | For the life of the contract, then 6 years |
| Invoices and accounting records | 6 years from the end of the financial year, as required by the Companies Act 2006 |
| Call recordings — our own copy | 90 days, then automatically deleted |
| Call recordings — the copy held by our telephony provider | 90 days, then automatically deleted |
| Call transcripts — the full written record of what was said | 90 days, in line with the recording. We are implementing automatic deletion; until it is running, transcripts may be held for longer |
| Summaries, flags and call statistics produced from a transcript | 12 months. These are short structured notes, not a full record of the conversation |
| Marketing contacts | Until you opt out, reviewed every 2 years |
| Website analytics | 14 months |
| Website contact form messages | 12 months, unless they become a client record |
Where we hold information as a processor for one of our clients, we keep it for as long as that client instructs us to, and we return or delete it when our contract with them ends.
We may keep a specific record for longer than the period above where it relates to an open query, complaint, dispute or legal claim, or where we are required by law to keep it. Where we do, we keep only that record, and only for as long as the matter is live.
Security
We take the security of your information seriously. Our measures include multi-factor authentication on our cloud services, encryption of data in transit and at rest, role-based access so that staff see only what they need, our internal dashboards protected behind Cloudflare Access with Microsoft 365 sign-in, monitored and filtered internet access, patching and endpoint protection, and written procedures for handling security incidents.
No system is completely secure. If we suffer a personal data breach that is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner’s Office within 72 hours and, where the risk is high, tell you directly.
Cookies and website analytics
We use strictly necessary cookies to make this website work, and analytics cookies only where you have agreed through our cookie banner. You can change your choice at any time. Full details are in our Cookie Policy.
Your rights
Under UK data protection law, and under the EU General Data Protection Regulation where it applies to you, you have the right to:
- Be told how we use your information — which is what this notice is for
- Ask for a copy of the personal information we hold about you, including a recording or transcript of a call you took part in (a subject access request)
- Have inaccurate or incomplete information corrected
- Ask us to delete your information, where there is no good reason for us to keep it
- Ask us to restrict how we use your information while a query about it is resolved
- Object to our use of your information where we rely on legitimate interests, including our recording of calls and our use of AI
- Object to direct marketing at any time, with no reason needed — we will always stop
- Receive information you gave us in a portable electronic format, where we hold it on the basis of your consent or a contract
- Withdraw consent at any time, where we rely on it
- Not be subject to a decision made solely by automated means that has a legal or similarly significant effect on you. We do not make such decisions
To exercise any of these rights, email privacy@qlineit.com. We will respond within one month. If your request is complex, or if you have made several requests, we may extend that by up to two further months and will tell you if we do. There is no charge, unless a request is manifestly unfounded or excessive.
We may need to confirm your identity before we act on a request.
How to complain
If you are unhappy with how we have handled your information, please tell us first at privacy@qlineit.com so that we can put it right.
You also have the right to complain to the Information Commissioner’s Office at any time:
- Website: ico.org.uk/make-a-complaint
- Helpline: 0303 123 1113
- Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
If you are in the EU or EEA, you may instead complain to the supervisory authority in your own country.
Children
This website is not intended for, or directed at, children under 13, and we do not knowingly collect their information. If you are under 13 and want to contact us, please ask a parent or guardian to do so on your behalf. If you believe we hold information about a child, tell us and we will delete it.
Links to other websites
Our website contains links to other organisations’ websites. Once you follow a link and leave our site, we have no control over that website and are not responsible for how it handles your information. This notice does not apply to it, so please read the privacy notice on any site you visit.
Changes to this notice
We review this notice at least once a year, and whenever we change how we use personal information. When we make a significant change we will update the date at the top of this page and, where the change materially affects you, tell you directly.
This notice was last updated on 11 August 2026
Related policies: End User Licence Agreement (EULA)

