Policies
Privacy Policy
What we collect, why we collect it, how long we keep it, and what you can ask us to do about it.
1. Who we are
Steel Bridge Solutions, a trading name of STEELBRIDGE SOLUTIONS LTD of Silverstream House, 45 Fitzroy Street, London, England, W1T 6EB, is the controller of personal information collected through this website and in the course of our business relationships.
Privacy contact: info@steelbridge-solutions.com
2. Information we collect
2.1 Information you give us
- Name, business name and job title
- Email address and telephone number
- The content of your enquiry and subsequent correspondence
- Information about your business processes and systems shared during scoping
- Billing contact details and, for clients, purchase order and invoicing information
If you use the consultation form, the details you enter are emailed to us through our hosting provider and are not stored on the website itself.
2.2 Information collected automatically
- IP address, approximate location derived from it, browser and device type
- Pages viewed, referring page, and time of visit
- Server log data generated by our hosting provider for security and diagnostics
2.3 What we do not collect
We do not collect payment card numbers. Card payments are handled by our payment provider and card data is transmitted directly to them; we receive only a transaction reference, the last four digits and the amount.
We do not knowingly collect special category data (such as health, biometric or political information) through this website, and we ask that you do not send it to us in an enquiry.
3. How we use it
| Purpose | Information used |
|---|---|
| Responding to your enquiry | Contact details, enquiry content |
| Preparing a proposal or statement of work | Contact details, business and process information |
| Delivering services under a contract | Contact details, project and system information |
| Invoicing, payment and accounting records | Billing contact, transaction records |
| Providing support and handling disputes | Correspondence, project and transaction records |
| Website security, diagnostics and abuse prevention | Log data, IP address |
| Understanding how the website is used | Aggregated analytics data, where enabled |
| Meeting legal, tax and accounting obligations | Contract and transaction records |
We do not sell personal information, and we do not share it with third parties for their own marketing purposes.
4. Lawful basis
We process personal data under the UK GDPR and the Data Protection Act 2018, and, where we handle data of individuals in the EU, the EU GDPR. Where a lawful basis is required, we rely on:
- Contract — to provide services you have engaged us for, and to invoice for them.
- Legitimate interests — to respond to business enquiries, keep our website secure, understand how it is used, and maintain business records. We balance these against your interests and rights.
- Consent — for non-essential cookies and any marketing email, which you may withdraw at any time.
- Legal obligation — to retain accounting and tax records.
5. Who we share it with
We share personal information only with service providers that help us operate, and only to the extent needed:
| Category | Purpose |
|---|---|
| Website hosting | Serving this website and storing server logs |
| Email and productivity | Correspondence, documents and scheduling |
| Payment processing | Taking card payments and handling refunds |
| Accounting | Invoicing and statutory records |
| Analytics (where enabled) | Understanding aggregate website usage |
| Professional advisers | Legal and accounting advice where necessary |
We may also disclose information where required by law, to establish or defend legal claims, or as part of a business sale or reorganisation, in which case recipients are bound by equivalent obligations.
The providers we currently engage are Namecheap (website hosting), Stripe (payment processing) and Revolut (business banking). This website also loads fonts from Google Fonts, which means your browser requests them from a Google server — see our Cookie Policy. We keep this list current as providers change, and you can ask us for the up-to-date version at any time by emailing info@steelbridge-solutions.com.
6. Client data we process during projects
When we deliver an engagement, we may be given access to systems containing personal data relating to your customers, staff or suppliers. In that context you are the controller and we act as processor on your documented instructions.
Before any such access, we enter into a written data processing agreement covering the subject matter and duration of processing, the categories of data and data subjects, security measures, approved sub-processors, breach notification, and deletion or return of data at the end of the engagement.
We ask for the minimum access needed for the agreed scope, prefer time-limited and revocable credentials, and use anonymised or sample data for development and testing wherever it is workable.
7. International transfers
Some of our service providers operate outside the country in which you are located. Where personal information is transferred internationally, we rely on an adequacy decision where one applies, or on standard contractual clauses or equivalent safeguards, together with appropriate technical measures. You may request details of the safeguards in place.
8. How long we keep it
| Record | Retention |
|---|---|
| Enquiries that do not become engagements | 24 months from last contact |
| Client project records and correspondence | 6 years after the engagement ends |
| Contracts and statements of work | 6 years after the engagement ends |
| Invoices and accounting records | As required by applicable tax law, typically 6–7 years |
| Website server logs | Up to 12 months |
| Analytics data, where enabled | Up to 14 months |
| Client system data accessed during a project | Deleted or returned at the end of the engagement, per the data processing agreement |
9. Security
We apply measures proportionate to the risk, including encryption in transit, multi-factor authentication on business accounts, access limited to personnel who need it, time-limited credentials for client systems, and separation of development environments from live systems.
No system is completely secure. If a personal data breach occurs that is likely to result in a risk to individuals, we will notify the relevant supervisory authority and affected individuals without undue delay and in accordance with applicable law.
We do not hold any security certification, and we do not claim one. Where a certification is a requirement of your procurement process, please raise it before engaging us.
10. Your rights
Depending on where you are located, you may have the right to:
- Access the personal information we hold about you
- Have inaccurate information corrected
- Request erasure where we no longer have grounds to retain it
- Restrict or object to processing based on legitimate interests
- Receive information you provided in a portable format
- Withdraw consent at any time, without affecting prior processing
- Opt out of marketing communications
To exercise any of these, contact us at the address in section 15. We respond within one month, and will tell you if we need longer because a request is complex. We may ask you to verify your identity. Exercising these rights is free unless a request is manifestly unfounded or excessive.
11. Cookies
See our Cookie Policy for what this site sets and how to control it.
12. Marketing
We do not send unsolicited marketing email. If you opt in to receive updates from us, every message includes an unsubscribe link that takes effect immediately, and we do not share your address with other organisations.
13. Children
Our services are provided to businesses. This website is not directed at children and we do not knowingly collect personal information from anyone under 16. If you believe we have, contact us and we will delete it.
14. Changes to this policy
We may update this policy. The date at the top shows when it was last revised. Where changes are material and affect clients with an active engagement, we notify them directly.
15. Contact and complaints
Privacy enquiries: info@steelbridge-solutions.com
Postal: Silverstream House, 45 Fitzroy Street, London, England, W1T 6EB
If you are not satisfied with our response, you may complain to the data protection supervisory authority in your country. In the United Kingdom this is the Information Commissioner's Office; in the European Union it is the authority in your member state. We would appreciate the chance to address your concern first.