Legal

# Privacy policy

How Cube Systems Limited collects, uses and protects personal data when you visit this website, get in touch, or use CubeMSP.

- Updated 25/09/2026
- 12 min read
- For everyone

## The short version

- Analytics only if you allow it

Google Analytics sets cookies only after you choose “Allow analytics”. There are no advertising or social media tags on this website.

- Your clients’ data stays yours

Inside CubeMSP, the MSP using it is the controller. We act as its processor, only on its instructions and under a written agreement.

- Held in the UK

Databases, files and backups are in UK data centres. AI features send limited content to named providers under UK transfer safeguards, and it is never used to train their models.

- Nothing sold, nothing passed on

We do not sell personal data or share it for anyone else’s marketing. Asking us a question does not put you on a mailing list.

A summary for convenience. The full text below is what applies.

## 1. Who we are

This policy is issued by **Cube Systems Limited**, a company registered in England and Wales under number 17220899, with its registered office at Unit 11, Olney Business Park, Osier Way, Olney, Buckinghamshire, MK46 5FP. CubeMSP is a trading name of Cube Systems Limited, which is part of Crushed Ice Group. In this policy, “we”, “us” and “our” mean Cube Systems Limited.

For the processing this policy describes we are the controller. That means we decide how and why the data is used, and we are responsible for it under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We are registered with the Information Commissioner’s Office under registration number [ZC216972](https://ico.org.uk/ESDWebPages/Entry/ZC216972).

We are not required to appoint a data protection officer. Questions about this policy or your personal data go to [hello@cubemsp.co.uk](mailto:hello@cubemsp.co.uk), by telephone on [01234 672 617](tel:+441234672617), or by post to the address above, marked for the attention of the data protection lead.

## 2. When this policy applies

We handle personal data in two different capacities, and it matters which one applies to you.

### Where we are the controller

This policy covers personal data we collect for our own purposes, about:

- people who visit this website;
- people who contact us, book a walkthrough or ask for a quote;
- contacts at our customers, prospective customers and suppliers; and
- people who sign in to CubeMSP, in respect of their account, sign-in and security records, and any support request they raise with us.

### Where we are a processor

Managed service providers use CubeMSP to hold records about their own clients: contacts, sites, services, tickets, project boards, files, devices and reviews. That data belongs to the MSP. The MSP is its controller and its own privacy notice applies. We process the data only on the MSP’s instructions, under a data processing agreement, as set out in our [data processing](/legal/data-processing) terms.

If you are a client of an MSP, for example because you have been invited to a shared project board, please contact your provider about your data first. If you contact us instead, we will tell you who to approach and pass your request on to them.

## 3. What we collect

### When you visit this website

Pages, fonts, icons and images are served from our own servers. The website sets no cookies unless you allow analytics, and it carries no advertising or social media tags.

Like any web server, ours keeps a log of each request: your IP address, the date and time, the page requested, the page that linked to it, and the browser and operating system your device reports. We use these logs only to keep the site secure and working.

Your browser also keeps a short note of your visit in its session storage, under the name `visit_journey`: the page you arrived on and when, the site that sent you, any campaign tags or ad click IDs in that first link, the previous page, and how many pages you have viewed. It stays in that browser tab, is deleted when you close it, and only reaches us if you send the enquiry form.

### If you allow analytics

When analytics is in use, a banner asks whether you allow it. If you choose “Allow analytics”, Google Analytics 4 sets its `_ga` and `_ga_<container-id>` cookies and records which pages you view, how you arrived, the type of device, browser and screen you use, your approximate location (such as the country and city, worked out by Google from your IP address), and interactions such as scrolling, following a link to another website, clicking a phone number or email address, and sending the enquiry form. GA4 does not log or store IP addresses. We see the results as reports about visits in general, and we do not use them to identify anyone. Advertising features are switched off.

The Google Analytics script only loads after you allow analytics, so if you choose “Essential only” nothing is sent to Google. If you withdraw your consent through Cookie settings, Google Analytics stops and its `_ga` cookies are removed.

### When you get in touch

If you use the contact form we collect your name and email address, your company name and telephone number if you give them, the type of enquiry, your message, and the page or form you sent it from.

With the form, your browser also sends details about your visit. They help us route your enquiry to the right person, spot misuse of the form, and understand which pages lead people to get in touch. They are:

- your IP address;
- your browser and operating system, read from the user agent your browser reports, and the type of device;
- your language, time zone and local time, your screen and window size, whether your device has a touch screen, and whether cookies are enabled;
- the note of your visit described above: the page you arrived on and when, the site that sent you, campaign tags and ad click IDs, the previous page and the number of pages viewed; and
- if you allowed analytics, your Google Analytics client ID, which lets us match the enquiry to the analytics for that visit.

The enquiry is sent by email through Amazon Simple Email Service (Amazon SES), in the AWS London region, to the Cube Systems enquiries mailbox. If you email or call us, we keep what you tell us and the details you contact us from.

Please do not send passwords, API keys or personal data about your own clients through the contact form. If we need sample data to scope a migration, we will agree a secure way to exchange it first.

### When you become a customer

We hold names, job titles and business contact details for the people we deal with at your organisation, including account, billing and technical contacts, together with contract and order records, invoices, payment history, and the history of our support and account conversations. We do not take card payments through this website.

### When you use CubeMSP

- **Account details:** your name, email address, role and the workspace you belong to.
- **Sign-in data:** a hash of your password, never the password itself; your multi-factor authentication settings, which are encrypted; and your Microsoft account identifier if your workspace uses Microsoft single sign-on.
- **Security records:** sign-in times, IP addresses, browser details and failed sign-in attempts, which we use to protect accounts and investigate misuse.
- **Audit records:** which account created, changed or deleted a record, and when. The MSP can see these in its workspace audit log.
- **Support requests:** anything you send us when you ask for help.

We do not ask for special category data, such as health information, and CubeMSP is built for businesses, so we do not knowingly collect information about children.

## 4. How we use it, and why

Data protection law requires a lawful basis for every use of personal data. These are ours.

| Purpose | Lawful basis |
| --- | --- |
| Replying to enquiries, arranging walkthroughs and preparing quotes | Legitimate interests in responding to people who contact us, and steps you have asked us to take before entering into a contract. |
| Recording the visitor details sent with an enquiry, to route it to the right person, prevent abuse of the form and understand which pages lead to enquiries | Legitimate interests in answering enquiries promptly, protecting the form from misuse and improving the website. |
| Measuring how the website is used with Google Analytics | Consent, given in the cookie banner. You can withdraw it at any time through Cookie settings in the footer. |
| Providing CubeMSP, managing customer accounts and giving support | Performance of our contract with the customer, and legitimate interests in supporting the people who use it. |
| Keeping the website and platform secure, preventing abuse and investigating incidents | Legitimate interests in protecting our systems, our customers and their data. |
| Invoicing, accounting and tax | Legal obligation, and performance of the contract. |
| Service messages: security notices, planned maintenance, and changes to our terms or sub-processors | Performance of the contract, and legitimate interests in keeping customers informed. |
| Occasional product news to contacts at existing customers | Legitimate interests. Every message has a way to opt out, and opting out never stops service messages. |
| Improving CubeMSP using aggregated information about how features are used, such as how often AI drafts are accepted | Legitimate interests in making the product better. We use aggregated figures, not profiles of individuals. |
| Establishing, exercising or defending legal claims, and answering lawful requests from regulators | Legal obligation, and legitimate interests. |

Where we rely on legitimate interests, we have weighed them against your rights and you can ask us for that assessment. You can object at any time, as explained under [your rights](#your-rights).

## 5. AI and automated decisions

We do not make decisions about anyone based solely on automated processing that have legal or similarly significant effects.

CubeMSP includes AI features that help MSPs work faster: suggesting a category for a ticket, finding similar past incidents, drafting knowledgebase articles and review narratives, suggesting how to triage inbound email, and the CubeAI assistant. They run on data the MSP controls, and they follow rules that do not bend:

- Everything generated is a draft or a suggestion. A person reviews it before it is used, shared or acted on, and nothing is published, sent or applied automatically.
- A change the assistant proposes runs only after the user confirms it.
- AI never produces figures. Numbers in a review are calculated from the MSP’s own records and given to the model, which is instructed not to add statistics of its own.
- Content sent to an AI provider is never used to train its models.
- Every AI interaction is logged in the workspace with the model, prompt version and outcome, so the MSP can see what was generated and when.

The providers involved are named on our [sub-processors](/legal/sub-processors) page.

## 6. Who we share it with

We do not sell personal data, and we do not share it with anyone for their own marketing. We share it only with:

- **Crushed Ice Group companies**, chiefly Crushed Ice, which operates the UK data centres CubeMSP runs in and may deliver part of a project for you.
- **Service providers** who process data for us under written contracts: Amazon Web Services, for email delivery and file storage in its London region; Google, for website analytics if you allow it; and our business email and accounting providers. Those used within CubeMSP itself are named on our [sub-processors](/legal/sub-processors) page.
- **Services an MSP connects.** If an MSP connects CubeMSP to Microsoft 365, an RMM, a distributor or an accounting package, data passes between them at the MSP’s direction and under that provider’s own terms.
- **Professional advisers**, such as lawyers, accountants and insurers, who owe us a duty of confidentiality.
- **Authorities**, such as the police, HMRC or a regulator, where the law requires it. We check that a request is lawful before acting on it and, where the data belongs to a customer, we tell the customer unless the law forbids us to.
- **A buyer or successor**, if all or part of our business is sold or reorganised, on condition that they honour this policy.

## 7. Where it is held

We hold personal data in the United Kingdom. CubeMSP databases, file storage and backups are in UK data centres, and the email and storage services we use from Amazon Web Services run in its London region.

The exception is AI processing. When an MSP uses an AI feature, the content that feature needs is sent to the relevant provider, processed in the United States, and the result returned to the workspace in the UK. Those transfers are covered by the International Data Transfer Addendum to the European Commission’s standard contractual clauses or, where the provider is certified, by the UK Extension to the EU-US Data Privacy Framework.

Google Analytics runs only if you allow it. It is provided by Google Ireland Limited, with Google LLC, and the data may be processed in the United States under the UK Extension to the EU-US Data Privacy Framework.

If any other provider can access personal data from outside the UK, for example to give technical support, the same safeguards or UK adequacy regulations apply. You can ask us for a copy of the relevant safeguards.

## 8. How long we keep it

We keep personal data only for as long as we need it for the purpose it was collected for, then delete or anonymise it.

| Record | How long |
| --- | --- |
| Enquiries that do not lead to a customer relationship | 24 months from our last contact |
| Web server logs | 90 days |
| Google Analytics data, if you allowed analytics | Up to 14 months, then deleted by Google |
| Customer account, contract and support records | The life of the contract, then six years |
| Invoices and financial records | Six years from the end of the financial year they relate to |
| CubeMSP user accounts and sign-in history | While the account is active. Removed when the user is deleted or the contract ends, except where it forms part of the workspace audit log |
| Data an MSP holds in its workspace | Decided by the MSP, and deleted at the end of the contract as set out in our data processing terms |

The note of your visit kept in your browser is deleted when you close the tab, unless you send it to us with an enquiry. Where a legal claim or investigation is under way, we may keep the relevant records until it is resolved.

## 9. How we protect it

Security is part of how CubeMSP is designed rather than something added afterwards. The measures that protect personal data include:

- encryption in transit on every connection, encryption at rest, and encrypted off-site backups with a tested recovery process;
- isolation between customers enforced at the data layer, with an automated test for every route proving that one customer cannot reach another’s records;
- anything an MSP marks as internal removed on the server, so a client invited to a shared board never receives it;
- passwords stored only as hashes, multi-factor authentication, Microsoft single sign-on, and encryption of the credentials used to connect other services;
- role-based permissions, and an audit log that cannot be edited; and
- staff access limited to the people who need it to run and support the service.

If a personal data breach is likely to put people’s rights at risk, we will report it to the ICO within 72 hours of becoming aware of it and, where the risk is high, tell the people affected without undue delay. Customers are notified as set out in our [data processing](/legal/data-processing#security-incidents) terms.

## 10. Your rights

Under UK GDPR you have the right to:

- **be informed** about how your data is used, which is what this policy is for;
- **access** a copy of the personal data we hold about you;
- **rectification** of data that is inaccurate or incomplete;
- **erasure** of your data where there is no good reason for us to keep it;
- **restrict** how we use it, for example while a question about its accuracy is resolved;
- **object** to processing based on legitimate interests, and to direct marketing at any time;
- **data portability**, receiving data you gave us in a machine-readable format; and
- **withdraw consent**, where we rely on it, without affecting anything done before. For analytics, use Cookie settings in the footer of any page.

To use any of these rights, email [hello@cubemsp.co.uk](mailto:hello@cubemsp.co.uk). You do not need a form or any particular wording. We may ask you to confirm your identity before we act, so that we never hand your data to someone else. We respond within one month, and there is normally no charge. If a request is complex we may extend that by up to two further months, and we will tell you why within the first month.

If your request concerns data an MSP holds in its CubeMSP workspace, we will pass it to that MSP, which is responsible for answering it, and help it do so.

## 11. Complaints

If you are unhappy with how we have handled your data, please tell us first at [hello@cubemsp.co.uk](mailto:hello@cubemsp.co.uk) and we will try to put it right.

You also have the right to complain to the Information Commissioner’s Office, the UK regulator for data protection, with whom we are registered under number [ZC216972](https://ico.org.uk/ESDWebPages/Entry/ZC216972):

- online at [ico.org.uk/make-a-complaint](https://ico.org.uk/make-a-complaint/);
- by telephone on 0303 123 1113; or
- by post to Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.

## 12. Cookies

This website sets no cookies unless you allow Google Analytics, which then sets two. CubeMSP itself uses only what it needs to keep you signed in and to remember a theme you chose. Everything is listed in our [cookie policy](/legal/cookies), and you can change your analytics choice at any time using Cookie settings in the footer.

## 13. Changes to this policy

We review this policy at least once a year, and whenever the way we handle personal data changes. The date at the top shows when it was last updated. If a change materially affects customers, we will email their nominated contacts before it takes effect. Previous versions are available on request.

Contact

## Questions about this document

Email us and a person will reply. For anything about data held in an MSP’s workspace, please contact that MSP first, as it decides how the data is used.

[Email us](mailto:hello@cubemsp.co.uk)
- **Company:** Cube Systems Limited, trading as CubeMSP

- **Company number:** [17220899](https://find-and-update.company-information.service.gov.uk/company/17220899), registered in England and Wales

- **Registered office:** Unit 11, Olney Business Park, Osier Way, Olney, Buckinghamshire, MK46 5FP

- **Email:** [hello@cubemsp.co.uk](mailto:hello@cubemsp.co.uk)

- **Telephone:** [01234 672 617](tel:+441234672617)

- **ICO registration:** [ZC216972](https://ico.org.uk/ESDWebPages/Entry/ZC216972)

---

**URL:** https://cubemsp.co.uk/legal/privacy-policy
