1. Who we are
This policy is issued by Cube Systems Limited, a company registered in England and Wales under number 17220899, with its registered office at Unit 11, Olney Business Park, Osier Way, Olney, Buckinghamshire, MK46 5FP. CubeMSP is a trading name of Cube Systems Limited, which is part of Crushed Ice Group. In this policy, “we”, “us” and “our” mean Cube Systems Limited.
For the processing this policy describes we are the controller. That means we decide how and why the data is used, and we are responsible for it under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We are registered with the Information Commissioner’s Office under registration number ZC216972.
We are not required to appoint a data protection officer. Questions about this policy or your personal data go to hello@cubemsp.co.uk, by telephone on 01234 672 617, or by post to the address above, marked for the attention of the data protection lead.
2. When this policy applies
We handle personal data in two different capacities, and it matters which one applies to you.
Where we are the controller
This policy covers personal data we collect for our own purposes, about:
- people who visit this website;
- people who contact us, book a walkthrough or ask for a quote;
- contacts at our customers, prospective customers and suppliers; and
- people who sign in to CubeMSP, in respect of their account, sign-in and security records, and any support request they raise with us.
Where we are a processor
Managed service providers use CubeMSP to hold records about their own clients: contacts, sites, services, tickets, project boards, files, devices and reviews. That data belongs to the MSP. The MSP is its controller and its own privacy notice applies. We process the data only on the MSP’s instructions, under a data processing agreement, as set out in our data processing terms.
If you are a client of an MSP, for example because you have been invited to a shared project board, please contact your provider about your data first. If you contact us instead, we will tell you who to approach and pass your request on to them.
3. What we collect
When you visit this website
Pages, fonts, icons and images are served from our own servers. The website sets no cookies unless you allow analytics, and it carries no advertising or social media tags.
Like any web server, ours keeps a log of each request: your IP address, the date and time, the page requested, the page that linked to it, and the browser and operating system your device reports. We use these logs only to keep the site secure and working.
Your browser also keeps a short note of your visit in its session storage, under the name visit_journey: the page you arrived on and when, the site that sent you, any campaign tags or ad click IDs in that first link, the previous page, and how many pages you have viewed. It stays in that browser tab, is deleted when you close it, and only reaches us if you send the enquiry form.
If you allow analytics
When analytics is in use, a banner asks whether you allow it. If you choose “Allow analytics”, Google Analytics 4 sets its _ga and _ga_<container-id> cookies and records which pages you view, how you arrived, the type of device, browser and screen you use, your approximate location (such as the country and city, worked out by Google from your IP address), and interactions such as scrolling, following a link to another website, clicking a phone number or email address, and sending the enquiry form. GA4 does not log or store IP addresses. We see the results as reports about visits in general, and we do not use them to identify anyone. Advertising features are switched off.
The Google Analytics script only loads after you allow analytics, so if you choose “Essential only” nothing is sent to Google. If you withdraw your consent through Cookie settings, Google Analytics stops and its _ga cookies are removed.
When you get in touch
If you use the contact form we collect your name and email address, your company name and telephone number if you give them, the type of enquiry, your message, and the page or form you sent it from.
With the form, your browser also sends details about your visit. They help us route your enquiry to the right person, spot misuse of the form, and understand which pages lead people to get in touch. They are:
- your IP address;
- your browser and operating system, read from the user agent your browser reports, and the type of device;
- your language, time zone and local time, your screen and window size, whether your device has a touch screen, and whether cookies are enabled;
- the note of your visit described above: the page you arrived on and when, the site that sent you, campaign tags and ad click IDs, the previous page and the number of pages viewed; and
- if you allowed analytics, your Google Analytics client ID, which lets us match the enquiry to the analytics for that visit.
The enquiry is sent by email through Amazon Simple Email Service (Amazon SES), in the AWS London region, to the Cube Systems enquiries mailbox. If you email or call us, we keep what you tell us and the details you contact us from.
Please do not send passwords, API keys or personal data about your own clients through the contact form. If we need sample data to scope a migration, we will agree a secure way to exchange it first.
When you become a customer
We hold names, job titles and business contact details for the people we deal with at your organisation, including account, billing and technical contacts, together with contract and order records, invoices, payment history, and the history of our support and account conversations. We do not take card payments through this website.
When you use CubeMSP
- Account details: your name, email address, role and the workspace you belong to.
- Sign-in data: a hash of your password, never the password itself; your multi-factor authentication settings, which are encrypted; and your Microsoft account identifier if your workspace uses Microsoft single sign-on.
- Security records: sign-in times, IP addresses, browser details and failed sign-in attempts, which we use to protect accounts and investigate misuse.
- Audit records: which account created, changed or deleted a record, and when. The MSP can see these in its workspace audit log.
- Support requests: anything you send us when you ask for help.
We do not ask for special category data, such as health information, and CubeMSP is built for businesses, so we do not knowingly collect information about children.
4. How we use it, and why
Data protection law requires a lawful basis for every use of personal data. These are ours.
| Purpose | Lawful basis |
|---|---|
| Replying to enquiries, arranging walkthroughs and preparing quotes | Legitimate interests in responding to people who contact us, and steps you have asked us to take before entering into a contract. |
| Recording the visitor details sent with an enquiry, to route it to the right person, prevent abuse of the form and understand which pages lead to enquiries | Legitimate interests in answering enquiries promptly, protecting the form from misuse and improving the website. |
| Measuring how the website is used with Google Analytics | Consent, given in the cookie banner. You can withdraw it at any time through Cookie settings in the footer. |
| Providing CubeMSP, managing customer accounts and giving support | Performance of our contract with the customer, and legitimate interests in supporting the people who use it. |
| Keeping the website and platform secure, preventing abuse and investigating incidents | Legitimate interests in protecting our systems, our customers and their data. |
| Invoicing, accounting and tax | Legal obligation, and performance of the contract. |
| Service messages: security notices, planned maintenance, and changes to our terms or sub-processors | Performance of the contract, and legitimate interests in keeping customers informed. |
| Occasional product news to contacts at existing customers | Legitimate interests. Every message has a way to opt out, and opting out never stops service messages. |
| Improving CubeMSP using aggregated information about how features are used, such as how often AI drafts are accepted | Legitimate interests in making the product better. We use aggregated figures, not profiles of individuals. |
| Establishing, exercising or defending legal claims, and answering lawful requests from regulators | Legal obligation, and legitimate interests. |
Where we rely on legitimate interests, we have weighed them against your rights and you can ask us for that assessment. You can object at any time, as explained under your rights.
5. AI and automated decisions
We do not make decisions about anyone based solely on automated processing that have legal or similarly significant effects.
CubeMSP includes AI features that help MSPs work faster: suggesting a category for a ticket, finding similar past incidents, drafting knowledgebase articles and review narratives, suggesting how to triage inbound email, and the CubeAI assistant. They run on data the MSP controls, and they follow rules that do not bend:
- Everything generated is a draft or a suggestion. A person reviews it before it is used, shared or acted on, and nothing is published, sent or applied automatically.
- A change the assistant proposes runs only after the user confirms it.
- AI never produces figures. Numbers in a review are calculated from the MSP’s own records and given to the model, which is instructed not to add statistics of its own.
- Content sent to an AI provider is never used to train its models.
- Every AI interaction is logged in the workspace with the model, prompt version and outcome, so the MSP can see what was generated and when.
The providers involved are named on our sub-processors page.
7. Where it is held
We hold personal data in the United Kingdom. CubeMSP databases, file storage and backups are in UK data centres, and the email and storage services we use from Amazon Web Services run in its London region.
The exception is AI processing. When an MSP uses an AI feature, the content that feature needs is sent to the relevant provider, processed in the United States, and the result returned to the workspace in the UK. Those transfers are covered by the International Data Transfer Addendum to the European Commission’s standard contractual clauses or, where the provider is certified, by the UK Extension to the EU-US Data Privacy Framework.
Google Analytics runs only if you allow it. It is provided by Google Ireland Limited, with Google LLC, and the data may be processed in the United States under the UK Extension to the EU-US Data Privacy Framework.
If any other provider can access personal data from outside the UK, for example to give technical support, the same safeguards or UK adequacy regulations apply. You can ask us for a copy of the relevant safeguards.
8. How long we keep it
We keep personal data only for as long as we need it for the purpose it was collected for, then delete or anonymise it.
| Record | How long |
|---|---|
| Enquiries that do not lead to a customer relationship | 24 months from our last contact |
| Web server logs | 90 days |
| Google Analytics data, if you allowed analytics | Up to 14 months, then deleted by Google |
| Customer account, contract and support records | The life of the contract, then six years |
| Invoices and financial records | Six years from the end of the financial year they relate to |
| CubeMSP user accounts and sign-in history | While the account is active. Removed when the user is deleted or the contract ends, except where it forms part of the workspace audit log |
| Data an MSP holds in its workspace | Decided by the MSP, and deleted at the end of the contract as set out in our data processing terms |
The note of your visit kept in your browser is deleted when you close the tab, unless you send it to us with an enquiry. Where a legal claim or investigation is under way, we may keep the relevant records until it is resolved.
9. How we protect it
Security is part of how CubeMSP is designed rather than something added afterwards. The measures that protect personal data include:
- encryption in transit on every connection, encryption at rest, and encrypted off-site backups with a tested recovery process;
- isolation between customers enforced at the data layer, with an automated test for every route proving that one customer cannot reach another’s records;
- anything an MSP marks as internal removed on the server, so a client invited to a shared board never receives it;
- passwords stored only as hashes, multi-factor authentication, Microsoft single sign-on, and encryption of the credentials used to connect other services;
- role-based permissions, and an audit log that cannot be edited; and
- staff access limited to the people who need it to run and support the service.
If a personal data breach is likely to put people’s rights at risk, we will report it to the ICO within 72 hours of becoming aware of it and, where the risk is high, tell the people affected without undue delay. Customers are notified as set out in our data processing terms.
10. Your rights
Under UK GDPR you have the right to:
- be informed about how your data is used, which is what this policy is for;
- access a copy of the personal data we hold about you;
- rectification of data that is inaccurate or incomplete;
- erasure of your data where there is no good reason for us to keep it;
- restrict how we use it, for example while a question about its accuracy is resolved;
- object to processing based on legitimate interests, and to direct marketing at any time;
- data portability, receiving data you gave us in a machine-readable format; and
- withdraw consent, where we rely on it, without affecting anything done before. For analytics, use Cookie settings in the footer of any page.
To use any of these rights, email hello@cubemsp.co.uk. You do not need a form or any particular wording. We may ask you to confirm your identity before we act, so that we never hand your data to someone else. We respond within one month, and there is normally no charge. If a request is complex we may extend that by up to two further months, and we will tell you why within the first month.
If your request concerns data an MSP holds in its CubeMSP workspace, we will pass it to that MSP, which is responsible for answering it, and help it do so.
11. Complaints
If you are unhappy with how we have handled your data, please tell us first at hello@cubemsp.co.uk and we will try to put it right.
You also have the right to complain to the Information Commissioner’s Office, the UK regulator for data protection, with whom we are registered under number ZC216972:
- online at ico.org.uk/make-a-complaint;
- by telephone on 0303 123 1113; or
- by post to Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
13. Changes to this policy
We review this policy at least once a year, and whenever the way we handle personal data changes. The date at the top shows when it was last updated. If a change materially affects customers, we will email their nominated contacts before it takes effect. Previous versions are available on request.
Contact
Questions about this document
Email us and a person will reply. For anything about data held in an MSP’s workspace, please contact that MSP first, as it decides how the data is used.
- Company
- Cube Systems Limited, trading as CubeMSP
- Company number
- 17220899, registered in England and Wales
- Registered office
- Unit 11, Olney Business Park, Osier Way, Olney, Buckinghamshire, MK46 5FP
- hello@cubemsp.co.uk
- Telephone
- 01234 672 617
- ICO registration
- ZC216972