Who controls your data
ICTech Direct Ltd is intended to be the controller for the BuySellRAM.co.uk service. Final company number, registered office, privacy email and ICO registration details must be inserted before launch.
Draft v0.1 · compliance review required
A plain-English data map for quotes, parcel evidence, testing, disputes and payment records. Supplier details and retention periods must be finalised before launch.
ICTech Direct Ltd is intended to be the controller for the BuySellRAM.co.uk service. Final company number, registered office, privacy email and ICO registration details must be inserted before launch.
Contact and identity details, seller type, quote and module details, correspondence, delivery and tracking records, parcel evidence, inspection and testing records, revised-offer decisions, payment record and audit/security events. Bank details must be collected through a restricted operational route, never the general contact form.
To prepare and administer quotes and purchases, arrange eligible postage, inspect goods, prevent and investigate fraud, resolve disputes, make and evidence payments, meet legal duties, secure the service and answer enquiries. The final notice must map each purpose to an appropriate UK GDPR lawful basis.
Seller uploads and parcel-opening evidence are stored privately in R2. They are not public assets. Access is authorised through the application, logged and limited to operational need. Short-lived access links or authenticated streaming should be used.
Data may be shared where necessary with delivery providers, the receiving address provider, email and hosting suppliers, professional advisers, insurers, payment providers used outside this system, law enforcement or regulators. The final list must reflect the suppliers actually appointed.
Each record class needs an approved schedule before launch. Quotes that do not proceed, completed purchases, payment evidence, disputes, private media, audit logs and contact enquiries should not all use the same retention period. R2 lifecycle rules should support approved deletion.
Depending on the circumstances, people may have rights of access, correction, deletion, restriction, objection, portability and complaint to the UK Information Commissioner’s Office. The final notice must explain how to exercise them and include the correct response route.
The launch build should use essential storage only unless and until optional analytics are configured. Non-essential analytics or advertising technologies require an appropriate consent mechanism and updated disclosure.