1. Parties and roles
The subscribing company is the controller of personal information it places in its workspace. MSG Connect is the processor for that operational information. Each party remains responsible for the obligations that apply to its role under UK data-protection law.
2. Processing details
Processing covers hosting, organising, displaying, searching, backing up, transmitting and deleting workspace records for the duration of the subscription and applicable retention period. Data subjects may include customer contacts, staff, engineers, property contacts and other people recorded by the company. Data may include identity, contact, account, location, photographic, service and audit information.
3. Documented instructions and confidentiality
MSG Connect will process operational information only to provide and secure the service, comply with documented customer actions and support requests, or meet a legal obligation. Anyone authorised to access such information must be subject to appropriate confidentiality duties.
4. Security measures
- Logical separation of company workspaces and role-based access.
- Authenticated sessions, protected forms and audit logging.
- Transport security for public connections.
- Encrypted backup bundles, retention controls and recovery procedures.
- Restricted administrative access and security monitoring.
- Processes for updates, vulnerability reduction and incident response.
5. Sub-processors and transfers
MSG Connect may use providers for network delivery, hosting, email, billing and backup services. Providers must be selected with appropriate safeguards and used only as necessary to operate the service. Customers will be informed of material changes where required. Appropriate safeguards will be used if personal information is transferred outside the United Kingdom.
6. Assistance and incidents
Taking account of the nature of processing, MSG Connect will provide reasonable assistance with data-subject requests, security assessments, breach obligations and regulator enquiries. A confirmed personal-data breach affecting customer-controlled information will be reported to the customer without undue delay.
7. Return, export and deletion
During an active account, authorised users can access and export supported records. Following cancellation, information will be returned or deleted according to the service terms and documented retention schedule, unless law requires continued storage. Expiring recovery backups are removed through normal retention cycles.
Contract status: this page records the intended processing framework. A signed or electronically accepted version should identify the legal service-provider entity, customer, approved sub-processors and any customer-specific requirements.
8. Contact
Data-processing enquiries can be submitted using the contact form.
