Skip to main content

1. Introduction and Who We Are

This Privacy Policy explains how HSFCOACHING LIMITED collects, uses, stores and protects personal data in the course of running a computer integrated systems design and technology consulting business. The policy belongs to HSFCOACHING LIMITED and applies to the website at hsfcoaching.buzz, to enquiries that arrive by email or telephone, and to personal data handled while delivering professional services to client organisations. The developer and data controller responsible for the practices described here is HSF Coaching operating as HSFCOACHING LIMITED.

We are registered and operate from Flat 3, 24 Hamilton Road, FELIXSTOWE - IP11 7AN, United Kingdom (GB). Our business is centred on systems integration, custom software engineering, cloud infrastructure design, data platform engineering, cybersecurity assessment and managed IT support. Each of these activities can involve access to information that identifies a living person, and we treat that information as something held in trust rather than as an operational by-product.

We have written this policy in plain language on purpose. Legal notices are often long and difficult, and a privacy notice that cannot be understood does not help anyone make a decision. Where a term has a specific meaning we explain it near the place it first appears. You can reach us at support@hsfcoaching.buzz or on +85259218916 at any time to ask a question about this document or about the information we hold.

2. Scope of This Policy

This policy covers personal data that we control. It applies to information collected through our public website, information provided by prospective clients during sales conversations, information concerning suppliers and professional contacts, information about visitors to our premises, and information created while delivering services to clients. It also covers the limited employment and contractor records that any business must keep.

This policy does not cover the practices of other organisations, even where our services connect to their systems or where we link to their websites. When we act as a processor on behalf of a client, meaning that the client decides why and how data is used and we handle it on the instructions of that client, the privacy notice of that client governs the relationship with the individuals concerned. In that situation we act on documented instructions and refer any individual request to the client unless the law requires otherwise.

Separate agreements, statements of work and data processing terms may add to what is written here for particular engagements. Where a negotiated agreement conflicts with this general policy, the negotiated agreement takes precedence for that engagement, because it reflects the specific environment and risks involved. This policy remains the default position for everything not covered by a specific agreement.

3. Personal Data We Collect

The categories of personal data we collect depend on how you interact with us. We try to collect the minimum needed for the purpose at hand and to avoid gathering information simply because it might be interesting later. The main categories are set out below so you can see exactly what is in scope and what is not.

Identity and contact data

This includes a name, a job title, the organisation you represent, an email address, a telephone number and a postal address where relevant. This is the information required to correspond with you, prepare a proposal and maintain a record of who we have spoken to.

Enquiry and correspondence data

This includes the content of messages sent through our contact form, by email or by telephone, together with the dates of those exchanges and any attachments you choose to provide. If you describe a technical problem, this may incidentally include information about your systems.

Client project data

While delivering an engagement we may handle configuration records, system logs, user identifiers, account names and similar technical metadata. We seek to minimise personal data within these materials and to use pseudonymised or aggregated forms wherever the work allows.

Technical and website data

Our website records standard technical information such as the requested page, the time of the request and a truncated network address for security and diagnostic purposes. This information is used to keep the site available and to detect abusive traffic, not to build advertising profiles.

Financial and contractual data

Where you are a client or supplier we hold invoicing details, purchase order references, payment records and signed agreements. These are necessary to perform a contract and to meet accounting and tax obligations that apply to every trading company.

Special category data

We do not seek to collect information about health, ethnicity, political opinions, religious beliefs, trade union membership, genetic or biometric characteristics, or sexual orientation. If such information is offered to us unexpectedly we will not use it for any purpose and will delete it unless we are legally required to keep it.

4. How We Obtain Personal Data

Most personal data reaches us directly from the individual concerned. You provide it when you complete the contact form, send an email, place a telephone call, sign an agreement, attend a meeting or take part in a project workshop. In each of these cases you know that you are giving us information because the interaction is plainly about a service or a question.

We also receive personal data indirectly. A colleague may introduce you as the right technical contact, a client may provide a list of staff who need accounts configured, or a supplier may send the name of an account manager. Publicly available sources such as a company website or a professional directory may provide business contact details. Where we obtain personal data from a source other than the individual, we aim to inform that individual of the fact within a reasonable period and in any event within one month, unless an exemption applies.

In some engagements a client supplies personal data drawn from its own systems so that we can perform integration, migration or analysis work. In those cases the client is responsible for ensuring that it has a lawful basis to share the information with us, and we handle it strictly for the agreed purpose and under the terms of the applicable agreement.

5. Purposes and Legal Bases

Data protection law requires us to identify a legal basis for each use of personal data. We rely on the following bases depending on the activity, and we do not treat this list as a menu to be applied after the fact.

Performance of a contract

We process identity, contact, project and financial data where this is necessary to enter into or perform an agreement with you, including scoping work, delivering services, raising invoices and providing support. Without this processing we could not carry out the engagement you have asked us to undertake.

Legitimate interests

We process certain data because we have a legitimate interest that is not overridden by your rights. This covers responding to enquiries that you initiate, protecting our systems from misuse, maintaining business records, pursuing or defending legal claims and improving the quality of our services. We balance those interests against your expectations and freedoms before relying on this basis, and you may object as described in the rights section below.

Legal obligation

We keep accounting records, respond to lawful requests from authorities and retain evidence where the law requires it. This processing is mandatory and we cannot remove it on request, although we will always explain the obligation that applies.

Consent

Where we rely on consent, for example if you ask to receive occasional technical notes from us, you may withdraw that consent at any time by writing to support@hsfcoaching.buzz. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal, and it does not affect processing carried out on another legal basis.

6. Client Project Data and Systems Access

Integration and support work often requires some level of access to client systems. We treat that access as a privileged position and apply strict controls around it. Access is granted to named engineers only, is limited to what the agreed task requires, is time-bound wherever the platform allows, and is removed when the task concludes or the engineer leaves the engagement.

Where we must view production data to diagnose a fault, we prefer to work with masked, sampled or synthetic copies. When real data is unavoidable we limit its use to the diagnosis in progress, avoid copying it to personal devices, and delete working copies once the task is complete and the results have been recorded. Administrative credentials supplied to us are stored in an encrypted credential store rather than in documents or message threads.

We also keep an access log for engagements involving sensitive environments. The log records who accessed what, when and for which authorised reason. This provides accountability and gives a client a clear answer if an auditor asks how privileged access was controlled during the project.

7. Data Processed on Behalf of Clients

When we process personal data on behalf of a client, we act as a processor and the client acts as a controller. In that role we process the data only on the documented instructions of the client, we do not use it for our own purposes, and we do not sell it or share it for advertising. We impose confidentiality obligations on everyone who can access it and we apply the technical and organisational measures described in this policy and in the applicable agreement.

Our processor obligations include assisting the client in responding to individual rights requests, supporting the client in meeting its security and breach notification duties, and notifying the client without undue delay if we become aware of a personal data breach affecting data the client controls. When an engagement ends we return or delete the data at the choice of the client, subject to any legal retention requirement that applies to us.

If you are an individual whose data appears in a client system that we support, your request should normally be directed to that client, because the client decides what happens to the information. If you contact us directly we will explain the position and, where we can identify the client concerned, pass the request on promptly so that it is handled in the correct place.

8. Direct Marketing and Communications

We do not operate a mass marketing programme and we do not sell contact lists. Where we send information about our services it is normally in response to a specific enquiry or as a follow-up to a conversation that you began. If we send occasional technical notes, they go to people who have asked for them or to business contacts for whom the subject is directly relevant to a role they hold.

Every marketing message we send includes a clear way to stop receiving further messages, and we act on an opt-out promptly. We do not require you to give a reason and we do not make the opt-out difficult to find. If you ask us to stop, we keep only the minimum record needed to make sure we do not contact you again by mistake.

Transactional and service messages are different from marketing. If you are a client we must be able to send invoices, service notices, security advisories and incident updates, and these are part of performing the contract rather than promotional contact. You cannot opt out of those messages while an agreement is in force, because they carry information that affects the operation of your systems.

9. Cookies and Similar Technologies

Our public website is deliberately simple. It does not deploy advertising cookies, it does not embed social media tracking pixels, and it does not build behavioural profiles of visitors. Any cookie or local storage mechanism we use is limited to what is needed for the site to function securely and to remember a preference you have expressed.

Strictly necessary mechanisms are used to protect forms against abuse and to keep a session consistent while you move between pages. These do not require consent because the site cannot operate safely without them. Analytics, where used at all, is configured to avoid identifying individuals and to discard or anonymise network addresses at the earliest opportunity. If we ever introduce a mechanism that requires consent, we will ask for that consent before it is set and we will explain what it does in plain terms.

You can control cookies through your browser settings, including blocking them entirely or deleting those already stored. Blocking strictly necessary mechanisms may cause parts of the site to behave incorrectly, but it will not prevent you from reading the pages or contacting us by email or telephone.

10. How We Share Personal Data

We do not sell personal data and we do not trade it. We share it only where there is a clear need and an appropriate safeguard in place. The main circumstances are described below.

Service providers

We use a small number of suppliers for hosting, email, accounting and professional advice. These providers receive only the information necessary to perform their function, are bound by written terms, and are selected with attention to their security and privacy practices. We review these relationships periodically and remove providers that no longer meet the standard we require.

Professional advisers

Accountants, auditors and legal advisers may see limited information where this is necessary for the advice they give. They are subject to professional confidentiality obligations in addition to any contract with us.

Authorities and legal requirements

We may disclose personal data where the law compels it, where a court order requires it, or where disclosure is necessary to establish, exercise or defend a legal claim. We examine each request carefully and disclose only what the request legitimately requires.

Business changes

If the business is reorganised, merged or transferred, personal data may form part of the assets involved. Any successor would be bound by this policy in respect of information collected under it, and we would inform affected individuals of any material change in control.

11. International Transfers

HSFCOACHING LIMITED is based in the United Kingdom and our primary processing takes place there. Some suppliers used for hosting, email or collaboration operate infrastructure in other countries, which means that personal data may be transferred outside the United Kingdom or the European Economic Area in the course of ordinary operation.

Where a transfer leaves the United Kingdom or the European Economic Area, we put an appropriate safeguard in place. Depending on the destination and the provider this may be an adequacy decision, an approved set of contractual clauses, or another mechanism recognised by law. We assess the circumstances of each transfer before it occurs and we keep the assessment on file.

If you would like to know which safeguards apply to a particular transfer, you can ask us using the contact details at the end of this policy. We will tell you the mechanism involved and, where relevant, how to obtain a copy of the contractual protections used.

12. Security of Personal Data

We protect personal data with technical and organisational measures proportionate to the risk involved. The specific controls vary with the sensitivity of the information and the environment, but the following principles always apply. Access is granted on a need to know basis and is reviewed when roles change. Credentials are unique, are stored in an encrypted credential store and are never shared between individuals. Multi-factor authentication is enforced on the systems that hold client or personal data.

Data in transit is encrypted, and data at rest is encrypted where the platform supports it. Backups are taken regularly, are protected to the same standard as live data, and are tested by performing real restores rather than by trusting a success message. Devices used for client work are managed, keep full disk encryption enabled and are patched on a defined cycle. We remove access promptly when an engagement ends or a person leaves.

We also protect data through the way we work. Sensitive material is not left on shared drives without access control, working copies are deleted once their purpose is complete, and discussions about client environments take place in appropriate channels rather than public ones. Our engineers receive regular briefings on security practice, and we rehearse our response to incidents so that a real event is handled calmly and quickly.

No set of measures can guarantee absolute security. If you believe that your interaction with us has been compromised, contact us immediately using the details at the end of this policy so that we can investigate and take protective steps.

13. Data Retention

We keep personal data only as long as it is needed for the purpose for which it was collected, plus any additional period required by law or justified by a legitimate interest such as defending a legal claim. Retention is managed through schedules rather than left to chance, so that information is reviewed and removed rather than accumulating indefinitely.

Enquiries that do not lead to an engagement are normally kept for twelve months so that we can pick up a conversation if you return, and are then removed. Contractual and financial records are kept for six years after the end of the relevant financial year, in line with the accounting and tax obligations that apply to a United Kingdom company. Project documentation containing technical detail is kept for the life of the client relationship and for a short period afterwards, so that support and warranty obligations can be honoured.

Data handled on behalf of a client is retained according to the terms of the applicable agreement and the instructions of that client. When the engagement ends we return that data or delete it as the client directs, unless a legal requirement obliges us to keep a copy. Where data is deleted from live systems we also remove it from backups within the normal backup rotation cycle, and we record the deletion so that the action can be evidenced.

14. Privacy Rights

Depending on where you live, you may hold a set of rights over the personal data we control. We honour these rights for everyone who contacts us, regardless of jurisdiction, because they reflect basic fairness rather than a regional privilege.

To exercise a right, write to support@hsfcoaching.buzz and describe what you would like us to do. We will confirm your identity where necessary, respond within one month, and explain our reasoning clearly if we are unable to act as you have asked. There is no charge for a reasonable request, although we may charge a proportionate fee for requests that are manifestly unfounded or excessive.

You also have the right to lodge a complaint with the data protection authority in your country. In the United Kingdom the authority is the Information Commissioner Office. We would prefer the chance to resolve a concern directly before you escalate it, and we will engage with any enquiry you bring to us in good faith.

15. Privacy for Children

Our services are designed for organisations and are not directed at children. We do not knowingly collect personal data from anyone under the age of thirteen, and we do not use information of that kind for any purpose. If a client system that we support contains records relating to children, we handle those records only on the documented instructions of the client and with the additional care that such information deserves.

If you believe that we have collected information about a child without appropriate consent, please contact us at support@hsfcoaching.buzz. We will investigate promptly, delete the information where the law permits, and explain what we have done. Where a request relates to records that a client controls, we will refer it to that client and support the client in responding correctly.

16. Data Breach Response

A personal data breach is any incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. We treat any suspected breach as a priority, whether it affects our own systems or those of a client, and we do not wait for certainty before beginning to investigate.

Our response follows a defined sequence. We contain the incident to stop further loss, assess the nature and scope of the data involved, evaluate the risk to the individuals concerned and record everything in a structured incident log. Where the law requires notification, we inform the relevant supervisory authority without undue delay and, where the risk to individuals is high, we inform those individuals directly with a clear explanation of what happened and what they should do.

Where we act as a processor, we notify the client controller without undue delay and provide the information the client needs to meet its own notification duties. After the incident is closed we carry out a review covering cause and prevention, and we implement the changes it identifies. We keep the record of the incident and the remedial action so that the handling of the event can be examined later.

17. Third Party Websites and Services

Our website may link to external sites, and our services may connect to platforms operated by other companies. We do not control those destinations and we are not responsible for their privacy practices. When you follow a link away from our site, you should read the privacy notice of the organisation you are visiting before providing any personal data.

Where we integrate a third party service into a client environment, the terms and privacy practices of that provider apply to the data it handles. We help clients understand those practices during design work and we prefer providers that offer clear contractual protections, recognised security certifications and transparent data handling terms.

18. Changes to This Policy

We review this policy periodically and update it when our practices, the services we offer or the law change. When an update is material we will make that clear on this page and, where the change significantly affects how we use personal data, we will take reasonable steps to bring it to the attention of the people concerned.

The version published on this page is the current version and replaces all earlier versions. Continuing to use our website or services after an update indicates that you accept the revised policy. If you do not agree with a change, you may contact us to discuss it or ask us to stop processing your information where the law allows.

19. How to Contact Us

We welcome questions, requests and concerns about privacy. The fastest route is email, and we aim to respond within one business day. You can also write to us by post or telephone during our normal business hours.

Please include enough detail for us to understand your request, such as the nature of your relationship with us and the outcome you are seeking. If your request concerns data held on behalf of a client, we will explain that position and pass the request to the client so that it is handled by the organisation that decides how the data is used.

Back to homepage