Privacy policy
Privacy policy
How Kirosconsult .co.uk handles personal information, under UK GDPR and the Data Protection Act 2018.
Last reviewed 23 August 2026
1. Who we are
Kirosconsult .co.uk, London, United Kingdom. For anything in this policy, write to privacy@kirosconsult.co.uk.
2. What we collect
Only what you send us: your name, business name, email address, telephone number and whatever you type into the enquiry form. If you become a client we also hold the contract, invoices and the technical details of your site.
3. Why we hold it
To answer your enquiry, to quote, and — if you engage us — to deliver and support the work. That is the whole list. We do not profile you and we do not build an advertising audience from you.
5. Who else sees it
Our hosting provider (20i, in the United Kingdom) and our email provider, both as processors under contract. We do not sell your data, and we do not share it with anyone for marketing.
6. How long we keep it
Enquiries that do not become work are deleted after 12 months. Client records are kept for seven years, because tax law requires it, and then deleted.
7. Your rights
You may ask what we hold, ask us to correct it, or ask us to delete it. Write to privacy@kirosconsult.co.uk and we will answer within 30 days. If you are not satisfied you may complain to the Information Commissioner's Office.
8. Security
Data in transit is encrypted over TLS. Access to client systems requires two-factor authentication. Backups are encrypted and held off-site.