MCR Systems Privacy Policy

MCR-Systems-Privacy-Policy-May-2026


MCR Systems Ltd, as part of the Vesta Software Group (“Vesta”, “we”, “us”, “our”), is committed to protecting your privacy. There are various ways that you might interact with MCR Systems Ltd, and the information you provide when doing so allows us to improve our services.


This website, our related websites and any mobile site or mobile application that links to this Privacy Policy (collectively, the “Site”, “Sites”) are owned and operated by MCR Systems Ltd with its principal place of business at:


MCR Systems Ltd, Stables 1, Howbery Park, Wallingford, Oxfordshire, OX10 8BA


This Privacy Policy applies to MCR Systems Ltd and its subsidiaries and affiliates and covers our processing activities as a data controller.


Our Privacy Policy explains:

  • What information we collect, and why we collect it

  • How we use that information

  • How we protect that information

  • How you can control your information, including accessing, updating, and deleting what we store

  • How we share information collected


    Acceptance

    You should review this policy carefully and be sure you understand it before using the Site. Your use of the Site is deemed acceptance of this policy. If you do not agree to this policy, you should not use, and should immediately stop using, the Site. Accessing the Site only to review this policy is not deemed to be use of the Site.


    Data Transfers from the UK

    There are no restrictions or alterations on sending or receiving personal data from the UK to the 27 EU states, 3 EEA states or the additional 12 countries who were already afforded an adequacy decision by the EU whilst the UK was still a member. This is because the UK has carried over the 42 adequacy decisions, so that personal data from the UK can continue to flow seamlessly.


    The ICO will remain the independent supervisory body regarding the UK’s data protection legislation. The UK Government will continue to work towards maintaining close working relationships between the ICO and other countries’ supervisory authorities.


    Information We Collect

    Information You Give Us

    We may collect or record basic personal information which you voluntarily provide through completing forms on our Site, through electronic mail you send to us, or through other means of communication between you and us. The categories of personal information you provide may include:

  • First and last name

  • Job title and company name

  • Email address

  • Phone number

  • Mailing address

  • Password to register with us

  • Your personal or professional interests

  • Any other identifier that permits us to make contact with you


    We do not generally seek to collect sensitive personal information (for example, social security or other government ID numbers, credit card details, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health or sex life, sexual orientation, or genetic or biometric information) through our Site. If we do, we will ask for your explicit consent at the time of collection.


    Information We Collect from You

    We collect, store, and use information about your visits to the Sites and about your computer, tablet, mobile or other device through which you access the Sites. This includes:

  • Technical information, including the Internet Protocol (IP) address, browser type, internet service provider, device identifier, your login information, time zone setting, browser plug-in types and versions, operating system and platform, and geographical location

  • Information about your visits and use of the Site, including the full Uniform Resource Locators (URL), clickstream to, through and from our Site, pages you viewed and searched for, page response times, length of visits to certain pages, referral source/exit pages, and page interaction information (such as scrolling, clicks and mouse-overs)

  • Business Contact Information in the ordinary course of our business for managing and maintaining customer relationships, including name, address, invoice information, and order information


    Employee Information

    We also collect personal information from our employees and from job applicants in connection with administration of our human resources programmes and functions, including: job applications and hiring programmes, compensation and benefit programmes, performance appraisals, training, access to our facilities and computer networks, employee profiles, employee directories, human resource recordkeeping, and other employment-related purposes.


    It is our policy to keep all past and present employee information private from disclosure to third parties. Exceptions include:

  • To comply with legal obligations

  • Third parties with whom we have contractual agreements to assist in administration of company-sponsored benefits

  • Inquiries from third parties with a signed authorisation from the employee to release the information

  • Requests from prospective employers for written verification of employment


    How We Use Information

    As a data controller, we will only use your personal information if we have a legal basis for doing so. The purpose for which we use and process your information

    and the legal basis on which we carry out each type of processing is set out in the table below.


    Purpose

    Legal Basis under UK GDPR

    To provide you with information and materials that you request from us.

    Legitimate interests: to respond to your queries and provide information requested in order to generate and develop business.

    To personalise our services, products, and the Sites to you.

    Legitimate interests: to improve the Site to enhance your experience, facilitate system administration, and better our services.

    To update you on services, products, and benefits we offer.

    Legitimate interests: to market our services and products. For direct marketing by email to new contacts, we need your consent.

    To send you information regarding changes to our policies, terms and conditions, and other administrative information.

    Legitimate interests: to ensure that any changes to our policies and other terms are communicated to you.

    To administer our Sites including troubleshooting, data analysis, testing, research, statistical and survey purposes, and to keep our Sites safe and secure.

    Legitimate interests: to continually monitor and improve our services and your experience of the Sites and to ensure network security.

    To measure or understand the effectiveness of any marketing we provide to you and others, and to deliver relevant marketing to you.

    Legitimate interests: to continually improve our offering and develop our business.

    To enforce the terms and conditions and any contracts entered into with you.

    Legitimate interests: to enforce our terms and conditions of service.


    Where we rely on legitimate interests as a lawful basis, we carry out a balancing test to ensure that your interests, rights, and freedoms do not override our legitimate interests. You can request details of this balancing test by contacting us using the details below.


    Marketing

    We do not share personal data with any company outside the Vesta Software Group for marketing purposes. You can ask us to stop sending you marketing messages at any time by contacting us or clicking the Unsubscribe link in any marketing email.


    MCR Systems Ltd as Data Processor

    In certain cases, we also operate as a data processor and we collect and process personal information on behalf of our business customers in the provision of our services and products. In these circumstances, MCR Systems Ltd is acting as a data processor and our business customers remain the data controller in respect of personal information they provide to us.


    We will only use such personal information for the purposes of providing the services and products for which our business customers have engaged us. Where MCR Systems Ltd is acting as a data processor, we will refer any request from an individual for access to personal information to our customer. We will not respond directly to the request.


    Disclosure of Your Personal Data to Third Parties

    We will not sell, rent, lease, or otherwise share your personal information other than as outlined in this Privacy Policy or without obtaining your consent beforehand.


    We may share your personal data with Vesta Software Group companies, affiliates, or contractors as appropriate to carry out the purposes for which the information was supplied or collected. Personal data will also be shared with our third-party service providers and business partners who assist with the running of the Sites and our services and products (including hosting providers and email service providers). Our third-party service providers and business partners are subject to security and confidentiality obligations and are only permitted to process your personal data for specified purposes and in accordance with our instructions.


    We may also disclose personal data about you when we believe that such disclosure is reasonably appropriate to:

  • Comply with any legal or regulatory obligation

  • Enforce the terms of our agreements

  • Establish, exercise, or defend the rights of MCR Systems Ltd, our staff, customers, or others

  • Protect our rights, property, safety, or vital interests

  • Implement the purchase of all or substantially all of our assets, a merger, or other similar transaction that results in a change of control


    Security of Your Personal Data

    The security of your personal data is important to us. We follow generally accepted industry standards to protect the personal data received by us. We use commercially reasonable measures to safeguard personal data, which are appropriate to the type of information maintained and follow applicable laws.


    No method of transmission over the Internet, or method of electronic storage, can be 100% secure. Therefore, we cannot guarantee the absolute security of your personal data. You are responsible for protecting your username and password from third-party access and for selecting passwords that are secure.


    Data Retention: How Long We Keep Your Personal Data

    We will retain personal data which we process on behalf of our customers for as long as appropriate to provide services and products to our customers, in accordance with any agreement in place and for other legitimate purposes.


    When you contact us, we may keep a record of your communication to help solve any issues you might be facing. Your personal data may be retained for as long as necessary to fulfil the purposes for which we collected it, including to satisfy any legal, accounting, or reporting requirement.


    Your Rights

    Subject to certain limitations and exceptions, if you are in the United Kingdom you have the following rights under the UK GDPR:

  • Access to personal data: to receive a copy of the personal data we hold about you and to check that we are lawfully processing it

  • Correction of personal data: to have any incomplete or inaccurate data we hold about you corrected

  • Request erasure of personal data: to ask us to delete personal data where there is no good reason for us continuing to process it

  • Restriction of processing: to ask us to suspend the processing of your personal data in certain scenarios

  • Request transfer of personal data: to receive your personal data in a structured, commonly used, machine-readable format

  • Right to withdraw consent: you can withdraw your consent at any time where we are relying on consent to process your personal data. This will not affect the lawfulness of any processing carried out before you withdraw your consent

  • Right to object: you have the right to object to processing based on legitimate interests or for direct marketing purposes


Responding to Requests

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data under applicable law. We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.


You will not have to pay a fee to access your personal data (or to exercise any of your other rights) under applicable law. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive.


Use of Cookies

We may collect data in connection with your use of the Sites using small files commonly known as “cookies”. A cookie is a small amount of data which often includes a unique identifier that is sent to your computer, mobile phone, or other device from the Sites and is stored on your device’s browser or hard drive.


By continuing to browse the Sites, you are agreeing to our use of cookies. If you do not want us to use cookies when you use the Sites, you can set your browser to not accept cookies or to notify you when you receive a cookie. However, if you block cookies, some features on the Sites may not function as a result.

You can find more information about how to manage cookies for all commonly used internet browsers by visiting www.allaboutcookies.org.


We currently use the following cookies across our Sites:


Category

Site

Cookie Name(s)

Purpose

Strictly necessary

mcr-systems.co.uk

cookieyes-consent

Records the visitor’s cookie consent preferences so the correct cookies are loaded on subsequent visits.

Strictly necessary

SymLive, SymHub, C&C

ASP.NET_SessionId,

   AntiXsrfRequestToken,

   RequestVerificationToken,

.AspNetCore.Antiforgery.I3OyJ6zYUFI

Necessary to offer the basic functionalities of our Sites, to deliver the services requested, and to protect against cross-site request forgery.

Strictly necessary

SymLive, SymHub, C&C

_GRECAPTCHA

Set by Google reCAPTCHA to distinguish humans from bots and protect our Sites from spam and abuse.

Strictly necessary

Both

   cf_bm

Set by Cloudflare to identify and mitigate automated bot traffic.

Analytics

mcr-systems.co.uk

_ga, _ga_2T9RWXT582,

_ga_DZ56ME64SV

Set by Google Analytics to collect




anonymous data on pages visited and sessions, to help us understand and improve the Site.

Analytics

SymLive, SymHub, C&C

_ga, _ga_4K7MD1ZT94, _gid, _gat

Set by Google Analytics to collect anonymous data on pages visited and sessions, to help us understand and improve the Sites.

Advertising

mcr-systems.co.uk

bcookie, lidc, li_sugr, ar_debug, UserMatchHistory, AnalyticsSyncHistory, bscookie

Set by LinkedIn to track visitors for advertising and audience matching purposes, and to analyse the performance of our LinkedIn campaigns.


This site uses Google Analytics, a web analytics service provided by Google LLC. Google Analytics uses cookies to collect anonymous data about how visitors use the site, including pages visited, session duration, and general location. IP addresses are anonymised by default. For more information on how Google uses this data, visit google.com/policies/privacy/partners. You can opt out using the Google Analytics Opt-out Browser Add-on.


IP Addresses and Aggregate Information

An Internet Protocol (“IP”) address is associated with your computer’s connection to the internet. We may use your IP address to help diagnose problems with our server, to administer the Site, and to maintain contact with you as you navigate through the Site.

Aggregate information does not identify you. We use this statistical and navigational information to analyse visitor behaviours and characteristics. Although we may share this aggregate information with third parties, none of it will allow anyone to identify you.


Links to Third Parties

Our Sites may contain links to third-party websites. These are operated by companies outside of our control, and your activities at those websites will be governed by the policies and practices of those third parties. MCR Systems Ltd is not responsible for the privacy practices or content of such third-party websites. We encourage you to review all third-party site privacy policies before submitting any of your personal data.


Social Media and Online Engagement

We occasionally use a variety of technologies and social media options to communicate and interact with customers, potential customers, employees, and potential employees, including Facebook, X, and LinkedIn. When interacting on those websites, you may reveal certain personal information to us or to third parties. Other than when used by our employees for the purpose of responding to a specific message or request, we will not use, share, or retain your personal information.



Age

We do not sell our services to children, and the Site is not intended for or directed at children under the age of 16 years. We do not intentionally collect personal data from children under the age of 16. If you believe that we may have collected personal data from someone under the age of 16 without proper consent, please let us know using the contact details in this policy.

General Data Protection Regulation

Subject to certain limitations and exceptions, if you are in the United Kingdom you have rights under the UK GDPR as set out in the Your Rights section above. The ICO is the supervisory authority for the UK and may be contacted at https://ico.org.uk/concerns/ or by telephone on 0303 123 1113.


Complaints

If we receive formal written requests or complaints, we will follow up with the party making the request or complaint. To the extent required by applicable law, where we would not properly address your request, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO).


Any complaint regarding personal data or otherwise relating to this policy must first be submitted to MCR Systems Ltd as set out in the Contacting Us section. We must be given a reasonable opportunity of not less than 30 days to investigate and respond to your complaint. Upon our completing such investigation and responding, we must then, in good faith, attempt to promptly resolve any remaining aspects of your complaint.


Customers in the UK can also make contact by phone on 0116 299 7000 or by email: dataprotection@mcr-systems.co.uk


Contacting Us

We have appointed a Data Protection Contact who you can reach out to about any queries in relation to this policy. If you have any questions about this policy or your information, or to exercise any of your rights, you can contact us as follows:


MCR Systems Ltd

Vantage House, Vantage Park Leicester, LE4 9LJ

United Kingdom

Phone: 0116 299 7000

Email: dataprotection@mcr-systems.co.uk


Changes to This Policy

We may change this policy from time to time. If this policy changes, the revised policy will be posted at the “Privacy Policy” link on the Site’s home page. In the event that the change is significant or material, we will notify you by revising the link on the home page to read “Newly Revised Privacy Policy”. Please check this policy frequently. Your continued use of the Site constitutes acceptance of such changes, except where further steps are required by applicable law.


This policy was last updated: May 2026

Our customers

We supply technology that makes business better. Let us show you how...
Scroll to Top