Legal

Privacy Policy

How Consiliuma protects enquiry information, project material, credentials, commercial discussions and client data.

Our standard of care

Consiliuma works on websites, payment routes, hosting, customer systems and private business workflows. That work can involve commercially sensitive information, access credentials, customer records, analytics, internal processes, unpublished plans and other material that deserves disciplined handling.

We treat confidentiality, access control and data protection as part of the service, not as an afterthought. This policy is written for UK businesses and international clients who need to understand how information is handled before a conversation begins.

Who this policy applies to

This policy applies to visitors to this website, people who contact Consiliuma, prospective clients, active clients, suppliers, collaborators and authorised users of systems or materials we may help design, build, review or support.

Information we may collect

Depending on the nature of the enquiry or project, we may collect and process:

  • identity and contact details, including name, email address, company name, role and contact preferences;
  • project information, including requirements, budgets, timelines, existing website details, business objectives and technical context;
  • commercial material, including offers, pricing structures, lead flows, customer journeys, internal processes and planned launches;
  • website, hosting, domain, analytics, payment, content, advertising or software access details where a project requires them;
  • customer, lead, enquiry or operational data provided by a client for the purpose of designing, migrating, auditing or supporting a system;
  • correspondence, meeting notes, support requests, audit findings and decisions made during a project;
  • technical information generated by the website, such as device, browser, server logs and basic usage data where available.

How we use information

We use information only where there is a legitimate business reason, contractual need, legal obligation or consent where required. Typical purposes include:

  • responding to enquiries and assessing whether Consiliuma is the right fit;
  • preparing recommendations, proposals, scopes of work and project documentation;
  • designing, building, migrating, testing, hosting, maintaining or improving websites and business systems;
  • diagnosing problems, protecting security, restoring services and preserving evidence of project decisions;
  • managing payments, invoices, contracts, records and professional obligations;
  • protecting Consiliuma, our clients and authorised users from misuse, fraud, unauthorised access or avoidable loss.

Optional personalised site guide and attribution

The website may offer an optional guide that asks what to call you, your broad line of business and what you want to achieve. If you answer, those choices are stored in local storage in your browser so pages can present more relevant wording and routes. They are not sent to Consiliuma merely because you answered, and you can decline or reset the guide from the footer.

If you later submit an enquiry, the broad business type and priority you chose may be included with that enquiry to provide useful context. Campaign parameters in the page address may also be attached to an enquiry so we can understand which campaign produced a genuine conversation. Basic page and CTA events are designed to work with a configured analytics service; browser “Do Not Track” is respected by the site event helper.

Lawful bases under UK data protection law

Where UK GDPR applies, we rely on one or more lawful bases depending on the context: taking steps before entering into a contract, performing a contract, complying with legal obligations, legitimate interests, and consent where consent is the appropriate basis.

Our legitimate interests include operating a professional digital studio, responding to genuine enquiries, securing client systems, documenting project decisions, preventing misuse and improving the reliability of our services. We do not use legitimate interests as a blank cheque; it is balanced against the rights and expectations of the people concerned.

Credentials, passwords and privileged access

Where a project requires access to hosting, domains, analytics, payment providers, email systems, content systems, repositories, databases, customer systems or other business tools, access should be provided through secure, revocable and role-appropriate methods wherever possible.

Clients should avoid sending permanent master passwords in plain text. Where emergency access is unavoidable, credentials should be rotated after use. Consiliuma may recommend password managers, temporary access, least-privilege permissions, separate administrator accounts and two-factor authentication for material systems.

We do not request access for curiosity, convenience or control. Access is requested only where it is needed to perform agreed work, diagnose an issue, protect continuity or support the client’s stated objective.

Confidentiality and NDA readiness

Project discussions, commercial plans, unpublished products, client lists, internal workflows, credentials, analytics, lead information, payment-flow information and business-system material are treated as confidential by default.

Where a client requires a mutual non-disclosure agreement, supplier confidentiality terms, procurement documentation or enhanced assurance before disclosure, Consiliuma expects to review and agree those arrangements before sensitive material is exchanged.

Sharing information

We do not sell personal information. We may share information only where necessary with carefully selected service providers or professional advisers, such as hosting providers, domain registrars, payment processors, email providers, analytics tools, accountants, legal advisers or specialist contractors engaged for a defined project purpose.

Where client data is processed by third-party services, the relevant provider’s own terms, security commitments and data-processing arrangements may also apply. We aim to recommend services appropriate to the seriousness of the project and the sensitivity of the information involved.

International clients and transfers

Consiliuma may work with clients, providers or authorised users outside the United Kingdom. Where UK GDPR transfer rules apply to a restricted transfer of personal information, appropriate transfer mechanisms, safeguards or exceptions should be considered before the transfer takes place.

The ICO explains that international transfer rules can apply when personal information is sent or made accessible to a separate organisation outside the UK. We take that risk seriously and expect international data flows to be discussed openly where they are material to a project.

Retention

We keep information only for as long as reasonably necessary for the purpose for which it was collected, including enquiry handling, project delivery, support, record keeping, legal compliance, dispute prevention, security and legitimate business administration. Credentials and access details should be removed, rotated or revoked when they are no longer required.

Your rights

Depending on the circumstances and applicable law, individuals may have rights to be informed, access their personal information, correct inaccurate information, request erasure, restrict processing, object to processing, request portability and complain to the Information Commissioner’s Office.

Some rights are subject to legal limits, including confidentiality obligations, privilege, security, contractual records and the rights of others.

Security cannot be absolute

No responsible provider should promise impossible security. What we can promise is a serious professional approach: proportionate access, careful handling, sensible retention, confidentiality by default, security-minded recommendations and prompt attention where a real risk is identified.

Questions and formal requests

Questions, access requests, correction requests, deletion requests or confidentiality concerns should be sent through the contact page with enough detail for us to identify the relevant enquiry, project or data set.