Privacy
When it comes to privacy we want you to know that it is an important topic to us. Our Privacy Policy explains our practices regarding the collection, use and disclosure of information that we receive through out our Services. This Privacy Policy does not apply to any third-party websites, services or applications, even if they are accessible through our Services or through our website.
- Application
In this Privacy Policy, we will refer to us as CSTC to our website as the “Site”. We’ll refer to all the products and services we provide, individually and collectively, as the “Services”. We’ll refer to you, the person or entity accessing our Site or using our Services, as “you” or “your” or (if you are a purchaser of our Services), our “customer”.
- Definitions
To make sure words have the same meaning to both of us, we used those definitions for the following worlds:
"Data subject" means the identified or identifiable living individual to whom personal data relates.
"Processing", in relation to information, means an operation or set of operations which is performed on information, or on sets of information, such as— (a) collection, recording, organisation, structuring or storage, (b) adaptation or alteration, (c) retrieval, consultation or use, (d) disclosure by transmission, dissemination or otherwise making available, (e) alignment or combination, or (f) restriction, erasure or destruction.
"Data Controller" means the organisation who determines the purposes and means of the processing of personal data. In our case we act as Data Controller when we provide our Services unless agreed differently.
"Data Processor” is an organisation which processes Personal Information for a Data Controller. Those are our suppliers helping us processing security your personal data. As a Data Processor, they are bound by the requirements of the UK General Data Protection Regulation (UK GDPR), tailored by the Data Protection Act 2018.
"Personal data" means any information relating to an identified or identifiable living individual. Personal data is any information which is about you, from which you can be identified. Personal Information includes information such as an individual's name, address, telephone number, or e-mail address. Personal Information also includes information about an individual's activities, such as information about his or her activity on Site or our Services, and demographic information, such as date of birth, gender, geographic area, and preferences, when any of this information is linked to personal information that identifies that individual. Personal Information does not include "aggregate" or other non-personally identifiable information. Aggregate information is information that we collect about a group or category of products, services, or users that is not personally identifiable or from which individual identities are removed.
- Collection of Personal Information
By default we act as a Data Controller, we collect Personal Information to perform our Services. This happens in several ways:
Information you provide to us directly.
Information we may receive from third parties.
We may receive information about you, including Personal information, from other third parties, and may combine this information with other personal information we maintain about you. If we do so, this Privacy Policy governs any combined information that we maintain in personally identifiable format.
We collect the following types of personal information from you:
Your first name, last name, and email address
Your organisation's name
Your organisation's address
Your IP address details
You may choose to provide us with a phone number to facilitate our communication
We may collect proof of identification, and proof of address to benefit from special discount or offers
We may collect information about your allergy and pass it, without your name, to our host in case you are taking a seminar or a training with us
We may collect information to make you comfortable during our seminar or training and be able to provide you with the best service
We may collect information you post to, or collect from, users of the Services. We use this information to operate, maintain, and provide to you the Services.
We may also collect and aggregate information about the use of our Site and our Services. That information includes browser and device data, such as IP address, device type, screen resolution, browser type, operating system name and version, language, as well as add-ons for your browser. The information may also include usage data, including the pages visited on and links clicked on our Site, the time spent on those pages, and the pages that led or referred you to our Site.
In some cases, we act as a Data Processor, in this case the processing of your data will be subject to the Data Controller policy and requirement set upon us.
- Purpose of the processing
We will use your Personal Information, in compliance with this Privacy Policy, to help us deliver the Services to you. Any of the information we collect from you may be used in the following ways:
To operate, maintain, and provide to you the Services.
To compile statistics and analysis about use of our Site and our Services.
To provide you with a special discount and offer based on your country of residence.
To personalise your experience.
To improve our Site and our Services — we continually strive to improve our site offerings based on the information and feedback we receive from you.
To improve customer service — your Personal Information helps us to more effectively respond to your customer service requests and support needs.
To send periodic emails — The email address you provide may be used to send you information, notifications that you request about changes to our Services, to alert you of updates, and to send periodic emails containing information relevant to your account.
If you purchase our Services, then to enable you to purchase, renew and appropriately use our Services.
We may also use Personal Information you provided us with to send you marketing emails about CSTC Services, invite you to participate in events or surveys, or otherwise communicate with you for marketing purposes. We allow you to opt-out from receiving marketing communications at any time.
If you do not want to receive such email messages, you will be given the option to opt out. We will try to comply with your request(s) as soon as reasonably practical. Additionally, even after you opt out from receiving marketing messages from us, you will continue to receive administrative messages from us regarding our Services (e.g., account verification, purchase and billing confirmations and reminders, changes/updates to features of the Service, technical and security notices).
We may also use your Personal Information where necessary for us to comply with a legal obligation, including to share information with government and regulatory authorities when required by law or in response to legal process, obligation, or request.
We cooperate with government and law enforcement officials or private parties to enforce and comply with the law. We may disclose your Personal Information to government or law enforcement officials or private parties as we believe necessary or appropriate: (i) to respond to claims, legal process (including subpoenas); (ii) to protect our property, rights and safety and the property, rights and safety of a third party or the public in general; and (iii) to stop any activity that we consider illegal, unethical or legally actionable activity.
Except as set out below, we do not sell, trade, or otherwise transfer to outside parties your Personal Information.
We may share your Personal Information with other companies owned by or under common ownership as CSTC, which also includes our subsidiaries (i.e., any organisation we own or control).
These companies will use your Personal Information in the same way as we can under this Privacy Policy, unless otherwise specified.
We may disclose your Personal Information to third-party service providers (for example, payment processing and data storage and processing facilities) that we use to provide the Services.
We limit the Personal Information provided to these service providers to that which is reasonably necessary for them to perform their functions, and we require them to agree to maintain the confidentiality of such Personal Information.
We may contract with third-party service providers to assist us in better understanding our Site visitors.
We will request your consent before we use or disclose your Personal Information for any different purpose than those set forth in this Policy.
- Protection of Personal Information
At CSTC we care about the security of your Personal Information, and we make reasonable efforts to ensure a level of security appropriate to the risk associated with the processing of your Personal Information. We maintain organisational, technical, and administrative procedures designed to protect your Personal Information against unauthorised access, deletion, loss, alteration, and misuse. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure. If you believe that your interaction with us is not secure, please contact us immediately at securityandprivacy@cstconsultancy.com.
Designated members of our staff may access Personal Information to help our customers with any questions they have, including help using our Services, investigating security issues, or following up on bug fixes with a customer. This activity is logged in our system for compliance, and we maintain different levels of access for our employees depending on their role in our company.
You are responsible for maintaining the secrecy of your unique password and account information, and for controlling access to your email communications with us. Your privacy settings may also be affected by changes to the functionality of third-party sites and services that you add to your device to access our Site. CSTC is not responsible for the functionality or security measures of any third party. Upon becoming aware of a breach of your Personal Information, we will notify you as quickly as we can and will provide timely information relating to the breach as it becomes known in accordance with any applicable laws and regulations or as is reasonably requested by you.
- Cookies
We do use essential cookies on our Site to perform our Services. Unlike persistent Cookies, session Cookies are deleted when you log off from the Services and close your browser. Although most browsers automatically accept Cookies, you can change your browser options to stop automatically accepting Cookies or to prompt you before accepting Cookies. Please note, however, that if you don’t accept Cookies, you may not be able to access all portions or features of the Site or the Service.
- Global transfers and processing of your Personal Information
Personal Information may be stored and processed in any country where we have operations, or where we engage service providers. This means that we may collect your Personal Information from, transfer it to, and store and process it in the United States and other countries outside of where you live. For example, some of our third-party providers may be located in different countries. Where this is the case, we will take steps to make sure the right security measures are taken so that your privacy rights continue to be protected as outlined in this Privacy Policy. Any transfer will be based on an “adequacy decision” as referred to in Article 45 of the GDPR or the UK GDPR. Or based on a Standard Contractual Clauses (also known as "model contract clauses", “model clauses” or “MCCs”) set by the European Commission and adopted by the ICO. Below is the current list of Data Processors authorised to process customer data on behalf of CSTC.
- Entities
Google Ireland Limited
Entity Type: Cloud Service Provider
Location: Ireland
INTUIT Limited (QuickBooks)
Entity Type: Cloud Accounting Service Provider
Location: UK
TAX ADVISER ACCOUNTANTS LTD (TaxAssist Accountants)
Entity type: Accountant
Location: UK
PayPal UK Ltd
Entity type: Payment System Provider
Location: UK
This list may be updated by CSTC from time to time. If we do so, we’ll let you know either by posting, or through other communications the modified Privacy Policy on the Site. If you continue to use the Site and the Services after we’ve let you know that the list have been modified, you are indicating to us that you agree to be bound by the modified Privacy Policy.
- Retention of your Personal Information
We retain your Personal Information for as long as we need to fulfil our Services. In addition, we retain Personal Information after we cease providing Services to you for a period of 12 months, and to the extent necessary to comply with our legal and contractual obligations. Where we retain data, we do so in accordance with any limitation periods and records retention obligations that are imposed by applicable law or by contractual agreement on us.
- Third-party Links
The Services may provide the ability to connect to other websites. These websites may operate independently from us and have their own privacy policies and notices, which we suggest you review. If the linked website is not owned or controlled by us, we are not responsible for its content, or the privacy practices.
- Your Consent
By using our Site, you consent to this Privacy Policy.
- Minors
These Services are not directed to individuals under the age of twenty-five (25), and we kindly request they do not provide any Personal Information through the Services.
- Your Rights
Other rights you have include the rights to:
Ask for a copy of your Personal Information
Ask us to correct your Personal Information that is inaccurate, incomplete, or outdated
Ask us to erase certain categories or types of information, or your Personal Information. If you choose to remove your Personal Information, you acknowledge that we may retain archived copies of your Personal Information in order to satisfy our legal obligations, or where we reasonably believe that we have a legitimate reason to do so
Ask us to restrict of processing
You have the right to be notified about any rectification or erasure of your personal data or restriction of processing, therefore you will receive an email confirming any action you took or we took on your behalf
Ask us to transfer your Personal Information to other organisations
Object to processing of Personal Information. Where we have asked for your consent to process information, you have the right to withdraw this consent at any time
Not to be subject to a decision based solely on automated processing, including profiling, this shall not apply to the entrance and performance of the contract between you and us
Lodge a complaint with the supervisory authority of your country or if you live in the UK with the Information Commissioner’s Office available on www.ICO.org.uk
- Changes to our Privacy Policy
If we decide to change our privacy policy, we will post those changes on this page. If we are going to use Personal Data collected through the Site in a manner materially different from that stated at the time of collection, then we will notify users via email and/or by posting a notice on our Site for 30 days prior to such use or by other means as required by law.
- Claim, Dispute, Complaints
We work to high standards when it comes to processing your personal information. If you have queries or concerns, please contact us at dpo@cstonsultancy.com and we will respond. If you remain dissatisfied, you can make a complaint about the way we process your personal information to ICO as the UK supervisory authority. Please follow this link to see how to do that.
- Contacting Us
If you have any questions, comments, or concerns about this privacy policy, please contact us using the following contact information:
CyberSecurity & Technology Consultancy LTD
Attn: Security and Privacy
Suite 263, 23 King Street, Cambridge, England, CB1 1AH
securityandprivacy@cstconsultancy.com
Publication date: 01 January 2024
Revision date: 15 March 2024