Last reviewed: 19 July 2026
1. Who is responsible for your information
ClearShield Cyber is the controller for personal information collected through this website and during enquiries. ClearShield Cyber is a trading name operated by Guntis Subrovskis. Contact: info@clearshieldcyber.co.uk. Business location: Scotland, United Kingdom.
2. Information we collect
We may collect your name, business name, work contact details, service interest, project requirements, correspondence and information reasonably needed to prepare a quote or deliver an agreed service. The secure enquiry form does not accept file uploads and instructs visitors not to submit passwords, financial credentials, authentication secrets or sensitive customer records.
3. Why we use it and lawful bases
We use enquiry information to respond, assess service fit, prepare proposals and take steps requested before entering a contract. The usual lawful bases are steps before a contract, performance of a contract, legitimate interests in operating and protecting the business, legal obligations, and consent only where consent is genuinely appropriate.
4. Data minimisation and sensitive information
Please provide only what is needed for the initial conversation. Do not submit special-category data, criminal-offence data, passwords, payment-card details, bank credentials, private keys, API keys or access tokens through the public form.
5. How the enquiry form works
The WordPress form validates and sanitises fields, applies cross-site request forgery protection, rate limiting, a spam trap and checks for common sensitive-data patterns. A private copy is saved in the restricted ClearShield Enquiries area of WordPress so that a genuine enquiry is not lost if an email notification fails. An email notification is also sent to the configured business mailbox. Enquiries are not published and are not available through the public WordPress application programming interface.
6. Service providers and sharing
Information may be processed by the website host, email provider, backup provider, accounting provider and professional advisers where necessary. We do not sell personal information. We may disclose information where legally required or necessary to establish, exercise or defend legal claims.
7. International transfers
Some providers may process information outside the UK. Where this occurs, appropriate contractual or legal safeguards should be used and provider terms should be reviewed.
8. Retention
Unsuccessful or inactive enquiries are normally reviewed for deletion within 12 months after the last meaningful contact. Client, contract, invoice and tax records may normally be retained for up to six years or longer where required for a legal claim. Security records may be retained for an appropriate shorter period based on risk.
9. Security
Reasonable measures may include MFA, access control, supported software, secure configuration, encrypted connections, backups, logging and restricted sharing. No internet transmission or storage method can be guaranteed completely secure.
10. Your rights
Depending on the circumstances, UK data-protection law may give you rights to be informed, access information, correct it, request deletion, restrict processing, object, receive portable data and withdraw consent. Some rights are subject to exemptions and the lawful basis used.
11. Complaints
Contact info@clearshieldcyber.co.uk first so the concern can be investigated. You may also complain to the Information Commissioner’s Office at ico.org.uk.
12. Legal framework and updates
This notice is intended to reflect the UK GDPR, Data Protection Act 2018, relevant changes introduced by the Data (Use and Access) Act 2025 and ICO guidance. It may be updated when services, providers or the law change.
13. Contact and service address
Email: info@clearshieldcyber.co.uk. A full business service address must be inserted before public launch where required by the Electronic Commerce Regulations and other trading-disclosure rules. Do not publish a home address if you do not wish to; obtain a suitable lawful business/service address instead.
Reference framework
- ICO UK GDPR guidance
- ICO privacy notices and cookies guidance
- Data Protection Act 2018
- Data (Use and Access) Act 2025
- Privacy and Electronic Communications Regulations 2003
- Electronic Commerce Regulations 2002
Legal review: these pages are a carefully structured starting point, not a substitute for a solicitor or data-protection professional reviewing the final business model, address, providers and processing activities.
