Last updated: April 15, 2026

What is the scope of this Privacy Statement?

This is the Privacy Statement of the ePlus inc. corporate group (the "Group") which is made up of different legal entities, including those set out below. This Privacy Statement is issued on behalf of the Group so when we mention "we", "us" or "our" in this Privacy Statement, we are referring to the relevant company in the Group responsible for processing your data. This Privacy Statement only applies to a company in the Group if that company processes personal data to which European Union or United Kingdom data protection law applies.

The controller of the website this Privacy Statement links to or appears on will be named on the relevant website. This will be:

If you require clarification as to the identity of the relevant controller, please contact us using the contact details set out below.

This Privacy Statement sets out how we collect and use your personal data including when you use our websites, mobile applications, digital services, and when we provide other services. In this Privacy Statement, we will collectively refer to the websites, applications, and digital services that link to or post this Privacy Statement as “websites”.

This Privacy Statement does not apply to personal data that we process as a data processor. For further information about how such data is processed, please contact (or refer to the privacy notice of) the relevant data controller.

If you have any questions about this Privacy Statement, including any requests to exercise your legal rights, please contact us using the information set out below.

What personal data do we collect about you?

The personal data we process about you includes the following categories of personal data:

 How is your personal data collected?

How will we use your personal data?

A legitimate interest is when we (or a third party) have a business or commercial reason to use your personal data, so long as this is not overridden by your own rights and interests. We will carry out an assessment when relying on legitimate interests, to balance our interests (or those of the relevant third party) against your own.

The table below explains what we use your personal data for and why.

  • Row 1

    • Purpose/Use
    • Legal Basis
  • Row 2

    • To permit you to install mobile applications and to register as a user on our websites
    • Legitimate interests (to deliver our mobile applications and to enable us to provide services and register users)
  • Row 3

    • To provide services to our clients
    • Legitimate interests (to enable us to provide services)
  • Row 4

    • To contact you and communicate with you regarding our services
    • Necessary for our legitimate interests (to enable us to provide information about our services and to communicate with you)
  • Row 5

    • To manage our relationship with you and/or your employer which will include:
      (a) Notifying you about changes to our terms or Privacy Statement
      (b) Dealing with your requests, complaints and queries
    • (a) Necessary to comply with a legal obligation
      (b) Necessary for our legitimate interests (to keep our records updated and manage our relationship with you and/or your employer)
  • Row 6

    • To enable you to complete a survey
    • Necessary for our legitimate interests (to study how our services are used, to develop them and grow our business)
  • Row 7

    • To administer and protect our business, websites (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data)
    • (a) Necessary for our legitimate interests (for running our business, the provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise)
      (b) Necessary to comply with a legal obligation
  • Row 8

    • To deliver relevant content on our websites and online advertisements to you and measure or understand the effectiveness of the advertising we serve to you
    • Necessary for our legitimate interests (to study how our services are used, to develop them, to grow our business and to inform our marketing strategy)
  • Row 9

    • To use data analytics to improve our websites, services, client relationships and experiences and to measure the effectiveness of our communications and marketing
    • Necessary for our legitimate interests (to define types of clients for our services, to keep our websites updated and relevant, to develop our business and to inform our marketing strategy)
  • Row 10

    • To send you relevant marketing communications and make personalised suggestions and recommendations to you about services that may be of interest to you
    • Depending on the circumstances:

      (a) Consent, having obtained your prior consent to receiving direct marketing communications
      (b) Necessary for our legitimate interests (to carry out direct marketing, develop our services and grow our business)
      Please see 'Direct marketing' below for further information about our legal basis for marketing communications.
  • Row 11

    • To carry out market research through your voluntary participation in surveys
    • Necessary for our legitimate interests (to study how our services, and websites are used and to help us improve and develop our services).
  • Row 12

    • To fulfil our legal obligations, and to establish, exercise or defend legal claims
    • (a) Necessary for our legitimate interests (to allow us to fulfil our legal obligations and to protect and defend legal claims)
      (b) Necessary to comply with a legal obligation
  • Row 13

    • Disclosures and other activities necessary to comply with legal and regulatory obligations that apply to our business, including to record and demonstrate evidence of your consents where relevant
    • To comply with our legal and regulatory obligations
  • Row 14

    • To share your personal data with members of the Group and third parties that will or may take control or ownership of some or all of our business (and professional advisors acting on our or their behalf) in connection with a corporate transaction or restructuring, including a merger, acquisition, asset sale, initial public offering or in the event of our insolvency

      In such cases information will be anonymised where possible and only shared where necessary
    • Depending on the circumstances:

      (a) to comply with our legal and regulatory obligations
      (b) in other cases, for our legitimate interests (to protect, realise or grow the value in our business and assets)

Direct marketing

We may ask for your consent for direct marketing communications. If we ask for your consent and you provide consent, this will be our lawful basis for marketing communications. In other cases, and provided we are able to do so under applicable data protection law, we may rely on legitimate interests to send marketing communications.

In either case, you can opt out of marketing. Please see below for further information.

We may also analyze your personal data to form a view which services may be of interest to you so that we can then send you relevant marketing communications.

Third-party marketing

Where we are required to do so under applicable data protection law, we will get your express consent before we share your personal data with any third party for their own direct marketing purposes.

Opting out of marketing

You can ask to stop sending you marketing communications at any time by following the opt-out links within any marketing communication sent to you or by contacting us using the contact details set out below.

If you opt out of receiving marketing communications, you will still receive service-related communications that are essential for administrative or customer service purposes.

Cookies

Our websites use a technology called cookies. A cookie is a small data file that a website can place on your computer’s hard drive, where your internet browser files are kept. Cookies serve purposes including saving you the trouble of re-entering certain information in some registration areas because cookies can be used to enable a site to “remember” information a visitor has previously inputted. A cookie also helps deliver content user-specific information to you and track how sections of the website are used. Cookies can be placed on your computer both by us and by third parties with whom we have a contractual relationship, such as web analytic services and advertising network services. With most Internet browsers or other software, you can change your browser settings to erase cookies from your computer hard drive, block all cookies, or receive a warning before a cookie is stored. Please check your browser instructions to learn more about these functions. If you reject all cookies (including essential cookies), functionality of the site may be limited, and you may not be able to take advantage of many of the site's features. You may also change your cookie preferences on our website. For more information about the cookies we use and how to change your cookie preferences, please review our cookie policy.

Web beacons

Our websites and emails use a technology known as web beacons (also known as an “action tag” or “clear GIF technology”) that allows the collection of web log information. A web beacon is a tiny graphic on a web page or in an e-mail message designed to track pages viewed or messages opened. Web log information is gathered when you visit one of our websites by the computer that hosts our website (called a "webserver").

Web beacons also help analyze the effectiveness of websites by measuring the number of visitors to a website or how many visitors clicked on key elements of a website.

Children’s personal data

This website is not intended for or designed for children. We do not knowingly collect personal data relating to children.

How do we protect your personal data?

We maintain numerous security standards and procedures to help prevent unauthorised access to your personal data. Our site uses a combination of encryption technology and authentication to protect your personal data. As long as the web browser you are using supports Secure Sockets Layer (SSL), your information will be submitted to us with a high level of security. We update and test our security technology on an ongoing basis. We have procedures limiting employee access to personal data to those employees who have a business reason to know such information about you. We will only transfer your personal data to third parties acting on our behalf where we have received written assurances that your personal data will be protected in a manner consistent with this Privacy Statement and our privacy policies and procedures.

How long do we retain your personal data?

We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you and/or your employer.

To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.

In some circumstances you can ask us to delete your data: see below for further information.

In some circumstances we will anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.

What automated decisions are made using your personal data?

You will not be subject to decisions that will have a significant impact on you based solely on automated decision-making, unless we have a lawful basis for doing so and we have notified you.

Who do we share your personal data with?

We may share your personal data where necessary with the parties set out below for the purposes set out in the table above.

We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.

Will we transfer your information internationally?

Some of the parties listed above are located or process personal data outside the UK and EU. This may involve transferring your data (if you are in the UK or EU) to the United States and to other countries outside the UK or EU.

Whenever we transfer your personal data out of the UK or EU to countries which have laws that do not provide the same level of data protection as UK or EU law, we always ensure that a similar degree of protection is afforded to it by ensuring that the appropriate safeguards are implemented (unless an exception applies).

We use specific standard contractual terms approved for use in the UK (for transfers from the UK) and EU (for transfers from the EU) and the which give the transferred personal data the same protection as it has in the UK and EU, namely the European Commission’s standard contractual clauses for international data transfers and the UK International Data Transfer Addendum to it or the UK International Data Transfer Agreement. For further information about the mechanism used or to obtain a copy, please contact us using the contact details set out below.

As a convenience to our visitors, our websites may contain links to other sites owned and operated by third parties that we believe may offer useful information. The policies and procedures we describe here do not apply to those sites. We are not responsible for the collection or use of personal data by or on any third-party sites. Therefore, we disclaim any liability for any third party's use of personal data obtained through using the third-party site. We suggest contacting those sites directly for information on their privacy, security, data collection, and distribution policies.

What are your rights?

You have the right to request access to your personal data as well as to ask us to make any corrections to inaccurate or incomplete personal data we have about you.  You can also request that we erase your personal data in certain circumstances, restrict how we process your personal data to certain limited purposes, or object to our processing of your personal data where we are relying on legitimate interests or if we are processing your personal data for marketing purposes. In certain circumstances, you are able to request that we send a copy of your personal data to a third party of your choosing.

To exercise any of these rights, please contact us using the contact details set out below. You also have the right to lodge a complaint with the supervisory authority (see details under “remedies” below) where you believe that your rights have been violated.

What if we revise this Privacy Statement or if there are changes to your personal data?

From time to time, we may make changes to this Privacy Statement. Any changes to this Privacy Statement will be posted on this website.

It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us, for example, a new address or email address.

How do you contact us if you have any questions or concerns?

Please contact us using the information that follows to:

ePlus Privacy Team
ePlus Technology, inc.
13595 Dulles Technology Drive
Herndon, VA 20171, USA
privacy@eplus.com

What remedies do you have available?

For more information about your privacy and data protection rights, or if you are not able to resolve a problem directly with us and wish to make a complaint, you may contact your country-specific data protection authority.  In the UK, this is the Information Commissioner's Office https://ico.org.uk/global/contact-us/.