This Privacy Policy explains how SHE ADVISORY SERVICES LTD handles personal information. It applies to our website, our written communications, our advisory engagements and any service we deliver to a client. The policy is written in plain language so that a reader can understand what happens to personal information without needing a legal background. The developer and operator of this website is SHE Advisory, trading as SHE ADVISORY SERVICES LTD, a company established in the United Kingdom.
Who We Are And The Scope Of This Policy
SHE ADVISORY SERVICES LTD is a computer systems design and advisory practice registered in the United Kingdom. The company operates from Heathfield, Mansfield Road, Heath, CHESTERFIELD - S44 5SE, United Kingdom (GB), and delivers digital transformation advisory, systems integration, enterprise architecture reviews, cloud migration, data platform engineering and cyber security assessments.
This policy covers every situation in which the company handles personal information. That includes browsing this website, sending an enquiry, entering into a client engagement, receiving a proposal, attending a workshop, participating in a review, and receiving support after a project has been delivered. It also covers information gathered when a person applies to work with the company, supplies a service to the company, or communicates with the company for any reason.
Where the company acts on the instructions of a client and processes information belonging to that client, the client remains responsible for the information and the company acts as a processor. Where the company decides why and how information is used, most commonly for its own website, enquiries and business records, the company acts as the controller. This policy describes both situations and explains how a person can exercise rights in either case.
Information We Collect
The company collects only the information it genuinely needs. The categories below describe what is typically involved across the full range of communication and delivery.
Identity information includes a name, a job title, an employer name and, where relevant, the capacity in which a person contacts the company. Contact information includes an email address, a telephone number, a postal address and any other channel a person chooses to use. Correspondence information includes the content of enquiries, proposals, meeting notes and the record of decisions that follows an engagement.
Engagement information includes the details needed to deliver advisory and design work, such as project roles, access arrangements, meeting attendance and approval records. Technical information includes the internet protocol address from which a website visit originates, the browser type, the device category, the referring page and the pages viewed during a visit. Financial information includes invoicing details, purchase order references and payment confirmations where a person or organisation is party to a commercial relationship with the company.
The company does not seek information that is special or sensitive in nature, such as information about health, ethnicity, religion or political opinion. If such information is ever volunteered in correspondence, the company will handle it carefully and will not use it for any purpose beyond responding to the person who provided it.
How We Collect Information
Most information reaches the company directly from the person concerned. A visitor may complete the contact form, send an email to help@sheadvisory.lat, telephone +14407451674, or reply to a message the company has sent. A client contact may be included in an engagement so that project communication can proceed. A supplier may provide invoicing details so that payment can be made.
Some information is collected automatically when the website is used. Server logs record the internet protocol address, the time of the request, the resource requested and the outcome of the request. This information is standard for websites and is used for security, capacity planning and fault diagnosis. The company does not attempt to identify an individual from server logs except where a security investigation makes that necessary.
Some information is received from third parties. A client may introduce a colleague to an engagement. A professional adviser may share correspondence relevant to a common matter. A public source may be consulted during due diligence before a commercial relationship begins. In every case the company uses the information only for the purpose for which it was provided.
Why We Use Personal Information
The company uses personal information to respond to enquiries, to prepare proposals, to deliver advisory and design engagements, to manage projects and approvals, to issue and settle invoices, to keep accurate business records, and to meet legal and regulatory obligations. These purposes are the core of the use and cover the great majority of situations.
The company also uses information to improve its services. Feedback from an engagement may inform the methodology the company applies to later work, and aggregated, non identifying statistics may be reviewed to understand which services are of most interest. The company uses information to protect its systems and clients from fraud, unauthorised access and abuse, and to investigate any incident that occurs.
Where a person has agreed, the company may send occasional updates about services, publications or events. A person can withdraw that agreement at any time and the company will stop sending updates promptly. The company never sells personal information and never trades it for value with any third party.
The Lawful Bases For Processing
Data protection law requires a lawful basis for every use of personal information. The company relies on the basis that fits each situation and records which basis applies.
Where a person asks the company to do something before a contract exists, such as answering an enquiry or preparing a proposal, the company relies on steps taken at the request of the person. Where the company delivers a service under a signed agreement, the company relies on the performance of that contract. Where the company keeps accounting records or verifies identity as required by law, the company relies on a legal obligation.
Where the company protects its systems, improves its services, or pursues the ordinary administration of its business, the company relies on its legitimate interests. The company balances those interests against the rights of the individual and does not use the basis where the individual would be unfairly affected. Where the company sends marketing updates, the company relies on consent or on the soft opt in recognised for existing business relationships, and provides an easy way to opt out every time.
Client Project Data
During an engagement the company frequently encounters information that belongs to a client. This may include system documentation, configuration details, data models, user records and security findings. The company treats this information as confidential and processes it only on the client instructions and only for the purpose of the engagement.
Where the company acts as a processor, the client is the controller. The company will assist the client in responding to any request from an individual whose information forms part of the project data, and will not respond to such a request independently unless the client has asked it to do so or the law requires it. The company applies appropriate technical and organisational measures to protect project data and will notify the client without undue delay if a breach occurs.
When an engagement ends, project data is returned or deleted according to the written agreement with the client. Where the company must retain a copy for its own professional records, it keeps the minimum necessary and protects it to the same standard described in this policy. Access to project data is limited to the consultants working on the engagement and to any colleague who must cover for them.
Cookies And Similar Technologies
This website is deliberately simple and is built to work without unnecessary tracking. It does not place advertising cookies and does not embed third party tracking scripts that follow a visitor across other websites. Where a cookie or a similar technology is used, it is used to make the site function correctly or to remember a preference that a visitor has chosen.
If essential cookies are used, they support basic functions such as remembering that a navigation menu has been opened during a session, and they do not identify an individual. Where a browser is configured to block cookies, the site should continue to work, though a small number of convenience features may behave differently.
A visitor can control cookies through the browser settings. Clearing cookies removes any stored preference. The company recommends reviewing the browser help pages for guidance on blocking, deleting and managing cookies. Enquiries about cookies can be sent to help@sheadvisory.lat and will receive a written reply.
Analytics And Website Measurement
The company may use privacy respecting measurement to understand how the website is used. Such measurement records aggregate information such as the number of visits, the pages viewed and the broad region from which a visit originates. It is used to confirm that the site is reachable, to identify pages that fail to load and to understand which services visitors seek.
Where measurement is used, the company configures it to minimise the information collected. Internet protocol addresses are truncated or not stored, cross site tracking is disabled, and the resulting reports are reviewed in aggregate rather than at the level of an identifiable person. The company does not build individual profiles from website behaviour and does not combine website measurement with client records.
If the company ever introduces a measurement tool that changes these commitments, this policy will be updated before the change takes effect, and the updated position will be published on this page. Visitors who prefer not to be measured in aggregate can use browser controls to limit scripts and can contact the company for clarification at any time.
How We Share Information
The company does not sell personal information and does not share it for the marketing purposes of others. Information is shared only where it is necessary for the delivery of a service, where the law requires it, or where a person has asked the company to do so.
Trusted suppliers may receive information where they support the company operations. Examples include the provider that hosts the website, the provider that handles business email, and the accountant who maintains statutory records. Each supplier is chosen with care, is bound by written terms that require confidentiality and security, and is permitted to use the information only to provide the agreed service.
Information may be shared with professional advisers such as solicitors or insurers where that is necessary to obtain advice or to manage a claim. Information may be shared with a public authority where the company is required by law to do so, or where disclosure is necessary to prevent harm or to investigate a criminal offence. Where a business is sold or reorganised, information may transfer as part of that transaction, and the company will ensure that the receiving organisation honours this policy or provides an equally protective one.
International Transfers Of Information
SHE ADVISORY SERVICES LTD is based in the United Kingdom and normally stores information within the United Kingdom and the European Economic Area. Some suppliers, however, operate infrastructure in other countries, and a transfer outside those areas may occur as a result of the services they provide.
Where information is transferred outside the United Kingdom or the European Economic Area, the company ensures that an appropriate safeguard is in place. This is usually a written contract that includes the standard contractual clauses approved for the purpose, supported by a transfer risk assessment that considers the law and practice of the destination country. Where a supplier cannot meet the required standard, the company will change supplier rather than accept a weaker position.
A person may ask for more detail about the safeguards that apply to a particular transfer by writing to help@sheadvisory.lat. The company will explain the mechanism in place and, where possible, provide a copy of the relevant terms in a form that does not compromise the confidentiality of other parties.
How Long We Keep Information
The company keeps personal information only for as long as it is needed for the purpose for which it was collected, and for as long afterwards as the law requires. Retention is reviewed rather than assumed, and records that are no longer needed are deleted or anonymised.
Enquiries that do not lead to an engagement are normally kept for a period that allows the company to respond properly and to demonstrate fair treatment, after which they are removed. Client engagement records are kept for the duration of the relationship and for a defined period afterwards, because the company must be able to answer questions about work it has performed. Financial and tax records are kept for the statutory period required by United Kingdom law.
Website server logs are kept for a short period sufficient for security and fault diagnosis, after which they are removed or aggregated. Where information is held only because it appears in a backup, the backup is cycled on a fixed schedule and the information is removed when the cycle completes. A person may ask for more detail about the retention period that applies to a particular category by contacting the company.
How We Protect Information
The company applies technical and organisational measures appropriate to the risk. Access to systems is controlled by individual accounts, strong authentication and the principle that a person receives only the access needed to perform a role. Devices are encrypted, kept updated and protected against unauthorised use. Networks are segmented so that a problem in one area does not spread to another.
Staff and consultants are bound by confidentiality obligations and receive guidance on handling information safely. Access is removed promptly when a person leaves a role or finishes an engagement. Physical records, where any are held, are stored securely and disposed of by a method that makes recovery impossible.
The company maintains a procedure for responding to a personal data breach. Where a breach is likely to result in a risk to the rights of individuals, the company will notify the relevant supervisory authority without undue delay and will inform affected individuals where the risk is high. The company reviews its security arrangements regularly and treats protection of client and personal information as a core obligation rather than an administrative task.
Privacy For Children
The services of SHE ADVISORY SERVICES LTD are intended for businesses and organisations, not for children. The company does not knowingly collect personal information from a child, and the website is not designed to attract children. Where a child does contact the company, and the company becomes aware of it, the information will be removed unless there is a legal reason to keep it.
If a parent or guardian believes that a child has provided personal information to the company, they should contact help@sheadvisory.lat so that the matter can be investigated and the information removed. The company will act promptly and will confirm the outcome in writing.
Automated Decisions And Profiling
The company does not make decisions about individuals by automated means alone, and does not build profiles of website visitors for marketing or any other purpose. Any decision that affects a person, whether it concerns an enquiry, a proposal or an engagement, is made by a person who is able to consider the circumstances.
Where the company uses software to help organise information, such as a customer relationship record or a document management system, the software supports human judgement rather than replacing it. The company does not use information to predict behaviour in a way that produces legal or similarly significant effects.
Rights Of Individuals
Data protection law gives individuals a set of rights. The company respects those rights and makes them straightforward to exercise. A person may ask for a copy of the personal information the company holds about them, and the company will respond within the period required by law.
A person may ask the company to correct information that is inaccurate, to complete information that is incomplete, to delete information that is no longer needed, to restrict how information is used while a question is resolved, and to object to a use based on legitimate interests. Where the company processed information with consent, a person may withdraw that consent at any time.
A person may ask to receive information in a portable format where the right to portability applies, and may object to direct marketing at any time. To exercise a right, write to help@sheadvisory.lat with enough detail for the company to understand the request and to verify identity. The company will not charge a fee for a reasonable request, and will explain if a request cannot be met and why.
Marketing And How To Opt Out
The company sends business updates only where it has a lawful basis to do so, and it keeps those updates relevant and infrequent. A person who no longer wishes to receive them can opt out using the link in the message or by writing to help@sheadvisory.lat. The company will honour the request promptly and will keep only the minimum record needed to ensure the preference is respected.
Opting out of marketing does not affect communications that are necessary for a contract, such as project notices, invoices or security information. Those communications continue for as long as the relationship requires. The company does not share contact details with other organisations for their marketing, so an opt out with the company is sufficient.
Complaints And Regulatory Contact
The company takes privacy concerns seriously and would rather resolve a concern directly and quickly. A person who is unhappy with how information has been handled should contact help@sheadvisory.lat first, providing enough detail to investigate. The company will acknowledge the concern and respond within the period required by law.
If a person remains dissatisfied, they have the right to complain to the Information Commissioner Office, which is the supervisory authority for data protection in the United Kingdom. The company will cooperate fully with any investigation and will provide the information the regulator requires.
Where an individual is located in another jurisdiction that gives them the right to complain to a local authority, that right is unaffected. The company will always attempt to resolve the matter at source before it escalates, because a direct conversation is usually faster and more useful for everyone involved.
Changes To This Privacy Policy
The company reviews this policy regularly and updates it when the services, the law or the suppliers change. The current version is always the one published on this page, and the effective date appears with it. Where a change is significant, the company will take reasonable steps to make it prominent, such as placing a notice on the homepage or contacting clients directly.
Continuing to use the website or to work with the company after a change takes effect means that the updated policy applies. A person who does not agree with a change should contact the company to discuss the position. Previous versions are available on request for a reasonable period after a change.
How To Contact The Company
SHE ADVISORY SERVICES LTD welcomes questions about this policy and about the handling of personal information. Written enquiries reach the bench directly and are answered by the senior consultants who run the engagements.
The registered office is Heathfield, Mansfield Road, Heath, CHESTERFIELD - S44 5SE, United Kingdom (GB). The contact email address is help@sheadvisory.lat, and the telephone number is +14407451674. Business hours are Monday to Friday, 09:00 to 17:30.
Please include enough detail in the message for the company to understand the question and to respond usefully. Where a request relates to a specific right described in this policy, stating the right will help the company to route the request correctly and to meet the required timescale.