PRIVACY POLICY
3
privacy-policy,wp-singular,page-template-default,page,page-id-3,wp-theme-bridge,bridge-core-3.0.8,qi-blocks-1.5.2,qodef-gutenberg--no-touch,eio-default,qode-page-transition-enabled,ajax_fade,page_not_loaded,,qode-theme-ver-29.5,qode-theme-bridge,wpb-js-composer js-comp-ver-8.1,vc_responsive,elementor-default,elementor-kit-16383,elementor-page elementor-page-3

PRIVACY POLICY

WHO ARE WE?

InfoShelter Ltd. Is an independent information security and data protection consultancy operating mainly in the market research industry. We provide our clients services and solutions relating to information security, both technical and procedural, as well as data privacy services including but not limited to DPO As A Service.

We are registered in England and Wales and our Company Registration Number is 11326045. Our Registered Address is 3rd Floor 86-90 Paul Street, London, England, EC2A 4NE.


PRIVACY STATEMENT

Your privacy is very important to us. We go to great lengths to preserve your privacy and protect the personal data used in our processing activities. This Privacy Policy describes how we collect, use and disclose information, and what choices you have with respect to any personal data we may hold about you.

We are committed to meeting the requirements of applicable data protection legislation. In the UK this includes the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, each as amended by the Data (Use and Access) Act 2025 (DUAA), and the Privacy and Electronic Communications Regulations 2003 (PECR) in relation to cookies and electronic marketing. Where we process the personal data of individuals in the EU/EEA, the EU General Data Protection Regulation (EU GDPR) may also apply. 

With respect to our consultancy and DPO services we act as the Data Processor. Any personal information passed to us from a third-party data controller is done so to assist us to perform our obligations under a specific contract / project. We never determine additional purposes or means for processing this information. We would always obtain consent from you and the data controller for any additional processing activities outside those of the original purpose. In respect of our own website and marketing activities, we act as the Data Controller.


WHAT PERSONAL DATA DO WE PROCESS THOUGH OUR WEBSITE AND MARKETING ACTIVITIES?

HubSpot is our CRM system for storing existing and potential customer’s data. A customer’s data is added to HubSpot either by website visitors using forms and providing their contact information or when an InfoShelter team member adds the information. We have a legitimate business interest in processing this information. 


How will it be used?

This is crucial as it enables us to give our customers and potential customers relevant, useful and personalized marketing, sales and customer services content. We also document communications, such as emails and meetings that have been held. We can also see whether you have opened an email or not. This informs us instantly whether what we send you is interesting, allowing us to tailor our communications to best serve our audience.


Who has access to your data?

Only InfoShelter will have access to your personal data.

We will never sell or rent your information to third parties.

We will never share your information with third parties for additional marketing purposes.


How long will we keep your data?

We will only keep your data for marketing purposes for as long as we have a need for it. We review marketing records on an annual basis and remove records which are no longer needed. This data is stored by us as long as you are a customer and/or have a relationship with us.

HubSpot’s privacy Policy can be found here: HubSpot’s privacy Policy can be found here: https://legal.hubspot.com/privacy-policy


WHAT PERSONAL DATA DO WE PROCESS THOUGH OUR DPO SERVICE?

In our DPO As A Service engagements we actively monitor DPO mailboxes to respond to requests made from you (the Data Subject) to our clients – usually involving a particular market research study.  This mailbox may be connected to an application local to the InfoShelter environment, and a copy of your request is stored on our systems.  These requests would normally contain the following information:

    • Your name

    • Your email address

    • Any information provided in your email signature (e.g. telephone number / address).

    • Some details of the market research survey you have undertaken.


How will it be used?

Upon receipt, we will send an acknowledgement of your request , acting as the DPO on behalf of our client.

Your personal data is then used to identify you with our client (for example in the project) and fulfil your request (for example remove you from the database so you will not be contacted further).


Who has access to your data?

Aside from our clients, who would have contacted you initially for market research purposes, only InfoShelter will have access to your personal data.

We will never sell or rent your information to third parties.

We will never share your information with third parties for additional marketing purposes.

How long will we keep your data?

Each one of our clients has different retention periods. Personal data is kept on our systems in line with the retention period  contained in our Data Processing Agreements with our clients.  For more information please email dpo@infoshelter.co.uk.

Where your personal data is transferred outside the UK, we ensure an appropriate safeguard is in place, such as the International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or a transfer to a country covered by UK adequacy regulations.


HOW DO WE SECURE YOUR DATA?

InfoShelter is a security consultancy at heart – protecting personal data is at the centre of everything we do. The following is ingrained in our culture:

The following is now ingrained into InfoShelter’s culture:

    • Defence in depth – our security controls have been designed and implemented in a layered way.

    • Risk based approach – every decision we make around privacy and security measures is based on a risk assessment.

    • Security and Privacy by design – security and privacy is baked into each of our processes.

    • Encryption at rest and in transit – we encrypt your personal data whilst it is stored on our servers and when we transfer it to clients, sometimes through third party services.

    • Principle of least privilege – all of our systems are configured to only permit our team the necessary access they need to fulfil their job roles.


Your Choices

Under certain circumstances you will be able to activate your following rights with the data controller (our client).

    • Right of access you have the right to request a copy of the information that we hold about you.

    • Right of rectification you have a right to correct data that we hold about you that is inaccurate or incomplete.

    • Right to be forgotten in certain circumstances you can ask for the data we hold about you to be erased from our records.

    • Right to restriction of processing where certain conditions apply to have a right to restrict the processing.

    • Right to object you have the right to object to certain types of processing.

    • Right to judicial review in the event that we refuse your request under rights of access, we will provide you with a reason as to why. You have the right to complain as outlined below.

Please contact our privacy team (privacy@infoshelter.co.uk)  if you would like to exercise any of these rights .

If you are unhappy with how we have handled your personal data or a data protection request, you can make a complaint to us. Please contact our privacy team at privacy@infoshelter.co.uk (or, for matters relating to our DPO service, dpo@infoshelter.co.uk), setting out the nature of your complaint.

We will acknowledge your complaint and respond to it without undue delay. 

Where we are acting as Data Processor on behalf of one of our clients, the client is the Data Controller and is primarily responsible for handling complaints about that processing. We will support and facilitate the handling of any such complaint as the appointed DPO.

You also have the right to lodge a complaint with the supervisory authority. In the UK this is the Information Commissioner’s Office (ICO). You can contact the ICO via their website at ico.org.uk.
In addition to complaining to us or to the ICO, you have the right to an effective judicial remedy. Where we refuse a request (for example under your right of access), we will provide you with a reason for that refusal.

 

Cookies

We may also use information obtained from cookies or similar technology. Cookies are text files containing small amounts of information which we download onto your computer or device when you visit our website. We can recognise these cookies on subsequent visits and they allow us to remember you.

If you want to delete any cookies that may already be on your computer or device, please refer to the instructions for your file management software to locate the file or directory that stores cookies. If you want to stop cookies being stored on your computer in future, please refer to your browser manufacturer’s instructions by clicking “Help” in your browser menu. Further information on cookies is available at www.allaboutcookies.org. By deleting our cookies or disabling future cookies you may not be able to access certain areas or features of our website.

Please refer to our cookie banner service for full details on your choices for the cookies on our website.


Review of this policy

We keep this Policy under regular review. This Policy was last updated in June 2026.