Effective Date: May 2026 | Next review due: May 2027
This policy explains how Mother Technologies handles personal data, both for its own business and when providing hosting and managed services to clients.
Mother Technologies is a Managed Service Provider (MSP), providing private cloud hosting and managed services to clients across Scotland and beyond. Our hosted services reside in Tier 2, ISO27001 certified datacentres in Edinburgh, Glasgow, Dundee and Aberdeen. The datacentres are owned and managed by Neos Networks, a division of the SSE Group, and connected via the UK’s biggest B2B network, designed specifically for UK critical national infrastructure.
We act in two distinct roles under UK GDPR:
In both roles, protecting data is a fundamental responsibility we take seriously.
Although the UK left the European Union, data protection law did not change in substance. The EU GDPR was incorporated into UK law as the UK General Data Protection Regulation (UK GDPR), sitting alongside the Data Protection Act 2018. The rules are substantively equivalent.
As a UK-based company processing personal data, Mother Technologies is fully subject to UK GDPR and is registered with the UK Information Commissioner’s Office (ICO), the UK’s independent authority for data protection regulation. Our primary data centres are located in Scotland (UK), meaning personal data is ordinarily stored within the United Kingdom.
In certain circumstances, personal data may be transferred outside the UK, for example where we use third-party service providers for backup, resilience, or infrastructure support. Where such transfers occur, we ensure they are carried out in compliance with UK GDPR requirements. Further details are set out in Section 4.
Mother Technologies is not required to appoint a statutory Data Protection Officer under Article 37 UK GDPR. This is because we do not carry out large‑scale systematic monitoring of individuals or large‑scale processing of special category data as a core activity. We have instead appointed a designated Data Protection Contact responsible for overseeing compliance, handling data subject requests, and acting as the point of contact with the ICO.
Our designated Data Protection Contact is responsible for overseeing compliance with this policy and handling data-related requests.
If you have a concern about how we handle your data and are not satisfied with our response, you have the right to complain to the Information Commissioner’s Office (ICO) at any time.
2.1 For our own business operations (Data Controller):
2.2. For client data we host or process (Data Processor):
Mother Technologies provides data centre colocation, hosted services, and managed IT to a wide range of clients, including those in legal, financial, professional services, charitable, educational, and other sectors. Data belonging to clients is processed strictly in accordance with:
We never access, use, or share client data for our own purposes. Clients always retain full ownership and control of their data.
We only collect and use data where we have a lawful basis to do so under UK GDPR. Our primary lawful bases are:
We do not use data for purposes beyond what it was originally collected for, and we never sell personal data to third parties.
Where we act as a data processor, lawful bases are determined by the data controller, and we process data solely in accordance with their instructions.
Mother Technologies acts as a data controller for personal data relating to its own business operations (such as client contacts, suppliers, and marketing communications) and as a data processor when providing hosted or managed services to clients under contract.
Personal data processed or hosted by Mother Technologies is stored primarily within our Scottish data centres, located in Edinburgh, Glasgow, Dundee, and Aberdeen, all within the United Kingdom.
In certain circumstances, including the use of trusted third‑party providers for backup, resilience, support services, or other managed service components, personal data may be transferred outside the UK. Any such transfers are strictly controlled and carried out in compliance with UK GDPR.
Transfers may take place to jurisdictions recognised as providing an adequate level of data protection, such as the European Economic Area (EEA), Switzerland, New Zealand, Japan, Canada (commercial organisations), and certain UK Crown Dependencies (including Jersey, Guernsey, and the Isle of Man), allowing personal data to flow without additional safeguards under GDPR. Where transfers to non-adequate countries are necessary, appropriate safeguards under GDPR are implemented, alongside appropriate technical and organisational measures.
Our private cloud hosted services reside in Tier 2, ISO 27001 certified datacentres, owned and managed by Neos Networks, a division of the SSE Group. Neos Networks provide the UK’s biggest B2B-only network designed to connect UK critical national infrastructure.
Comprehensive technical and organisational security includes:
No data is shared informally or outside of secure, authorised channels.
We do not sell personal data, nor do we share it with third parties for marketing, advertising, or other commercial purposes. Personal data is only shared where required by law, with trusted service providers acting under appropriate contractual safeguards, or where explicitly instructed under a Data Processing Agreement (DPA).
We keep personal data only for as long as necessary for the purposes for which it is processed, whether acting as a data controller or a data processor under GDPR. Our standard retention periods are:
Under UK GDPR, individuals whose data we hold have the following rights:
To exercise any of these rights, reach out to our Data Protection Contact at compliance@mother.uk.net
Mother Technologies has a documented data breach procedure which is followed in the event of a suspected or confirmed personal data breach. In such cases, we take appropriate steps in line with the relevant procedure to contain and assess the incident.
Where a personal data breach is likely to result in a risk to individuals’ rights and freedoms, we will notify the Information Commissioner’s Office (ICO) without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach. Affected clients and/or individuals will also be informed where necessary.
All personal data breaches, whether reportable or not, are recorded in our internal breach log.
Where Mother Technologies acts as a data processor, we provide advisory support and assist with containment, assessment, and recommended next steps. However, the client remains responsible for all final decisions, including notification to the ICO.
Where we act as a data controller, we are responsible for managing the breach, including decision-making and any required regulatory reporting obligations under GDPR.
We maintain internal procedures for managing personal data breaches and complying with our obligations under applicable data protection laws.
Any individual has the right to request a copy of the personal data we hold about them (a Subject Access Request, or SAR). To make a SAR:
We will not disclose data that would infringe on the rights of other individuals, or that we are legally required to withhold.
All Mother Technologies staff who handle personal data receive training on data protection as part of their induction and on an ongoing basis. Training covers:
Staff are supported to raise concerns without fear of blame in the case of accidental incidents.
Everything we do with data is guided by the seven principles of UK GDPR:
This policy will be reviewed annually, or sooner if there are significant changes to our business operations, the law, or guidance from the ICO. The Data Protection contact is responsible for ensuring the review takes place and that any updates are communicated to all staff. Where we make any material changes to the way we process personal data, we will notify affected individuals directly by email where possible and update this policy accordingly. This policy is made available to clients and other data subjects on our website and is provided to staff as part of induction and ongoing training.
