Trust centre
Security and data protection
UK GDPR summary, access control, breach notification, and technical measures for NLCRC services.
What you get
Clear scope before work begins
We confirm the fault, business requirement, or recycling inventory so you can approve the plan with confidence.
- RBAC and audit logging in LIVEUXI ERP
- Portal verification and optional 2FA
- NIST/IEEE quarantine until wipe completes
UK GDPR and accountability
NLCRC processes personal data as a controller for our own clients, donors, and portal users, and as a processor where B2B agreements require it. We maintain a Data Protection Policy (version 1.0, June 2026) reviewed annually.
Lawful bases include contract, legal obligation, and legitimate interests for B2B support. We apply data minimisation — especially for community device programmes where referrers, not NLCRC, gate beneficiary eligibility.
Technical and organisational measures
LIVEUXI ERP enforces role-based access control, authenticated staff sessions, and segregated permissions (e.g. sanitisation technicians vs general workshop staff).
Client portal accounts use verified email sign-in with two-factor authentication available for booking, shop, and repair tracking.
Storage media in our reuse pipeline is quarantined until NIST SP 800-88 / IEEE 2883 Purge completes. Immutable audit logs link certificates to chain-of-custody events.
Breach notification
We maintain internal incident procedures. Where we act as processor, we notify controllers without undue delay when we become aware of a personal data breach affecting your data, in line with our DPA and UK GDPR Article 33 obligations.
Clients should report suspected incidents via agreed contacts promptly so we can contain, investigate, and document impact.
Sub-processors and hosting
We use sub-processors for hosting, email, payments, and identity where required to deliver services. A summary is available on request with our DPA. We prefer UK/EEA hosting for client systems where contractually agreed.
Questions
Common questions
Is the full Data Protection Policy public?
Our privacy policy covers website and portal users. The full internal policy is available to partners on due diligence request; a public summary lives on this page and our DPA page.
Do you hold Cyber Essentials?
Not yet certified. Application is planned as a priority for MSP credibility. Verify any future certificate on the IASME register — we will not display a badge until listed.
Ready to get started?
Book online where a verified link is available, or contact National Laptop Computer Repair Centre for business support and recycling scope.