Privacy Policy

Last updated: 5 June 2026

This Privacy Policy explains how HSKG LTD ("HSKG", "we", "us", or "our") collects, uses, stores, shares, and protects personal data when you visit hskg.digital, communicate with us, engage our Computer Systems Design and Related Services, or otherwise interact with our business. We are committed to handling personal information responsibly and in accordance with applicable United Kingdom data protection legislation, including the UK General Data Protection Regulation (UK GDPR) as retained in domestic law and the Data Protection Act 2018.

HSKG LTD is the data controller for the personal data described in this policy unless we expressly state otherwise in a separate written notice. Our registered office is 7 Hollywell Road, Birmingham, United Kingdom, B26 3BS. You may contact us regarding privacy matters at office@hskg.digital or by telephone on +447446968148.

Please read this Privacy Policy carefully. By using our website, submitting an enquiry, entering into a contract with us, or otherwise providing personal data, you acknowledge that you have been informed of our data practices as described below, subject to your statutory rights and any additional terms agreed in writing.

1. Scope and Application

This Privacy Policy applies to personal data processed by HSKG LTD in connection with our website, professional services, client engagements, supplier relationships, recruitment activities, marketing communications, and administrative operations conducted within the United Kingdom and, where relevant, in respect of international clients or service providers.

Personal data means any information relating to an identified or identifiable natural person. It does not include information that has been anonymised or aggregated such that individuals can no longer be identified, provided the anonymisation is irreversible or appropriately safeguarded.

Where we process personal data on behalf of a client under a written services agreement, we may act as a data processor. In those circumstances, the client's privacy documentation and data processing terms govern the processing relationship, and this Privacy Policy applies only to the extent that HSKG LTD acts as a controller, for example in relation to our own business operations, website analytics, or direct communications with individuals.

This policy should be read together with our Cookie Policy, Terms of Service, and Terms and Conditions, each of which may contain additional provisions relevant to specific interactions or contractual arrangements.

2. Personal Data We Collect

The categories of personal data we collect depend on how you interact with HSKG LTD. We aim to collect only data that is adequate, relevant, and limited to what is necessary for the purposes described in this policy.

2.1 Information You Provide Directly

We may collect personal data when you complete contact forms, request proposals, subscribe to updates, attend meetings, sign contracts, submit support requests, apply for roles, or correspond with us by email, telephone, or post. This may include your name, job title, employer name, business address, email address, telephone number, billing details, project requirements, technical specifications, credentials supplied for integration work, and any other information you choose to include in your communications.

If you provide personal data relating to other individuals, such as colleagues or authorised users, you confirm that you have appropriate authority and have informed those individuals that their data will be shared with us for legitimate business purposes.

2.2 Information Collected Automatically

When you visit hskg.digital, we and our authorised service providers may automatically collect technical and usage information through cookies, server logs, and similar technologies. This may include IP address, browser type and version, device identifiers, operating system, referring URLs, pages viewed, session duration, interaction events, approximate geographic location derived from IP data, and diagnostic information used to maintain security and performance. Further detail is provided in our Cookie Policy.

2.3 Information from Third Parties

We may receive personal data from business partners, referral sources, publicly available professional directories, event organisers, credit reference agencies where permitted, identity verification providers, and recruitment platforms. We assess the lawfulness of such receipt and limit use to compatible purposes described in this policy.

2.4 Special Category and Sensitive Data

HSKG LTD does not routinely seek special category data as defined in UK GDPR Article 9, such as health information or biometric data. If such data is incidentally included in project materials or support tickets, we will handle it only as strictly necessary, apply enhanced safeguards, and delete or anonymise it when no longer required unless a lawful basis and explicit necessity justify retention.

3. How We Use Personal Data

We process personal data only where a lawful basis under UK GDPR applies. Depending on the context, our lawful bases may include consent, performance of a contract, steps taken at your request prior to entering a contract, compliance with a legal obligation, protection of vital interests, performance of a task carried out in the public interest, or legitimate interests pursued by HSKG LTD or a third party, provided those interests are not overridden by your rights and freedoms.

3.1 Service Delivery and Client Management

We use personal data to respond to enquiries, prepare quotations, design and deliver computer systems and related services, configure environments, manage accounts, provide technical support, administer billing and payments, maintain project documentation, and fulfil contractual obligations agreed with clients and their authorised representatives.

3.2 Website Operation and Improvement

We process technical data to operate hskg.digital, authenticate sessions where applicable, detect malicious activity, troubleshoot errors, analyse aggregated usage patterns, and improve content, navigation, and service relevance. Where non-essential analytics or marketing cookies are used, we rely on consent in accordance with the Privacy and Electronic Communications Regulations.

3.3 Communications and Marketing

With appropriate consent or where a soft opt-in or legitimate interest assessment supports business-to-business communications, we may send service updates, event invitations, newsletters, or information about capabilities aligned with your professional role. You may opt out of marketing communications at any time by following unsubscribe instructions or contacting office@hskg.digital.

3.4 Legal, Regulatory, and Risk Management

We may process personal data to establish, exercise, or defend legal claims; comply with tax, accounting, and regulatory obligations; conduct audits; manage information security incidents; and prevent fraud or misuse of our systems.

3.5 Recruitment

If you apply for employment or contract roles with HSKG LTD, we use application data to evaluate suitability, conduct interviews, verify references where appropriate, and maintain records required by employment law.

4. Automated Decision-Making and Profiling

HSKG LTD does not generally make decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects concerning individuals. Where automated tools assist with security monitoring, spam filtering, or aggregated website analytics, human oversight remains in place and outcomes do not determine contractual access or professional opportunities without manual review.

If we introduce automated decision-making that materially affects you, we will provide meaningful information about the logic involved, the significance, and the envisaged consequences, together with an explanation of your rights to obtain human intervention, express your point of view, and contest the decision, unless disclosure is prohibited by law or would undermine security measures.

5. Data Sharing and Recipients

We do not sell personal data. We share personal data only where necessary, subject to appropriate safeguards, and in line with the purposes described in this policy.

5.1 Service Providers and Processors

We engage trusted third parties to support hosting, content delivery, email delivery, customer relationship management, accounting, backup, monitoring, collaboration, and professional advisory services. These providers process data under written contracts requiring confidentiality, security measures, and processing instructions consistent with UK GDPR Article 28 where they act as processors.

5.2 Professional Advisers and Authorities

We may disclose personal data to solicitors, accountants, insurers, auditors, and regulators where necessary for compliance, corporate governance, or the protection of legal rights. Disclosures to law enforcement or public authorities occur only where required by applicable law or valid legal process.

5.3 Corporate Transactions

If HSKG LTD undergoes restructuring, merger, acquisition, or asset transfer, personal data may be transferred to successor entities subject to continuity of protection and notice where required by law.

5.4 International Transfers

Some service providers may process personal data outside the United Kingdom. Where transfers occur to countries without an adequacy decision, we implement appropriate safeguards such as UK International Data Transfer Agreements, standard contractual clauses approved for UK use, or binding corporate rules, and we conduct transfer risk assessments where appropriate.

6. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying legal, regulatory, tax, accounting, or reporting requirements. Retention periods vary depending on data category, contractual terms, and statutory limitation periods applicable in England and Wales.

Indicative retention practices include: enquiry records retained for up to twenty-four months unless a commercial relationship develops; client and project records retained for the duration of the engagement and up to seven years thereafter for contractual, tax, and dispute resolution purposes; marketing suppression lists retained indefinitely where necessary to honour opt-out requests; website logs retained for up to twelve months unless required for security investigations; and recruitment records retained for up to twelve months following a decision unless a longer period is agreed or required by law.

When retention periods expire, we securely delete or anonymise personal data using methods appropriate to the media involved. Backup copies may persist for a limited technical window before automatic purging.

7. Security Measures

HSKG LTD implements technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Measures are proportionate to the nature of our services and the sensitivity of data processed, and are reviewed periodically.

Our security practices may include access controls based on role and need-to-know principles, multi-factor authentication for administrative systems, encryption in transit using current industry protocols, hardened server configurations, patch management, logging and monitoring, secure development practices, vendor due diligence, staff confidentiality obligations, and incident response procedures aligned with recognised frameworks.

No method of transmission or storage is completely secure. While we strive to protect personal data, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of credentials issued to you and for notifying us promptly if you suspect unauthorised access.

8. Your Rights Under UK Data Protection Law

Subject to applicable exceptions, individuals whose personal data we process may have the following rights:

To exercise your rights, contact office@hskg.digital with sufficient information to verify your identity and specify the request. We respond within one month, extendable by two further months for complex or numerous requests with explanation. We do not charge a fee unless a request is manifestly unfounded or excessive.

You have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection. We encourage you to contact us first so we may address your concerns promptly.

9. Children's Privacy

Our website and professional services are directed at businesses and adults acting in a professional capacity. We do not knowingly collect personal data from children under eighteen without appropriate parental or guardian authority. If you believe we have inadvertently collected such data, please contact us and we will take steps to delete it without undue delay.

10. Third-Party Websites and Integrations

hskg.digital may contain links to third-party websites, platforms, or embedded content. This Privacy Policy does not apply to those external services, which maintain their own privacy practices. We recommend reviewing third-party policies before submitting personal data. Where we integrate client systems with external APIs or SaaS products as part of commissioned work, data handling by those products is governed by the client's agreements with the relevant providers unless HSKG LTD is expressly appointed as processor under a data processing addendum.

11. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in law, regulatory guidance, technology, or business practices. Material changes will be communicated by posting the revised policy on hskg.digital with an updated "Last updated" date and, where appropriate, by direct notice to active clients or subscribers. Continued use of our website or services after changes take effect constitutes acknowledgement of the updated policy, except where further consent is required by law.

12. Contact and Data Protection Enquiries

For questions about this Privacy Policy, our data practices, or to exercise your rights, contact:

HSKG LTD
7 Hollywell Road
Birmingham, United Kingdom
B26 3BS
Email: office@hskg.digital
Telephone: +447446968148

We will endeavour to resolve privacy enquiries fairly, transparently, and without undue delay.

13. Lawful Basis Summary Table

The following summary describes typical lawful bases relied upon by HSKG LTD. It is provided for transparency and does not replace the detailed explanations above or any contract-specific terms.

Where multiple bases could apply, we identify the most appropriate primary basis and document our assessments internally.

14. Records of Processing Activities

As a responsible controller, HSKG LTD maintains internal records of processing activities as required by UK GDPR Article 30. These records describe processing purposes, data categories, recipient categories, retention schedules, security measures, and international transfer safeguards. They are reviewed at least annually and updated upon material changes to systems or services.

Clients may request high-level confirmation that appropriate records are maintained in connection with processor activities performed on their behalf, subject to confidentiality and security constraints.

15. Data Protection by Design and Default

We embed privacy considerations into project planning, architecture decisions, access model design, and vendor selection. This includes minimising data collection in custom solutions, configuring role-based permissions, enabling audit trails where appropriate, and documenting data flows for client environments we build or maintain.

Default settings in solutions we deliver aim to limit exposure of personal data to what is necessary for agreed functionality, though client-controlled configurations after handover remain the client's responsibility unless managed services are expressly contracted.

16. Processor Obligations and Client Systems

When HSKG LTD processes personal data strictly on a client's instructions, we implement appropriate technical and organisational measures, assist with data subject requests where feasible, notify clients of personal data breaches without undue delay, support impact assessments where required, and delete or return data at contract termination subject to legal retention needs.

Clients remain responsible for determining lawful bases, providing privacy notices to their users, and ensuring that instructions to HSKG LTD comply with applicable law.

17. Marketing and Business Contact Preferences

We respect communication preferences for business contacts. If you receive an unsolicited marketing message in error, notify office@hskg.digital and we will correct our records. We maintain suppression lists to honour opt-out requests across future campaigns.

Transactional and service-related messages necessary to perform contracts, such as invoices, security alerts, or project updates, may still be sent where permitted by law irrespective of marketing opt-out status.

18. Complaints Handling Procedure

Privacy complaints are logged, acknowledged promptly, and investigated by an appropriate member of our team. We aim to provide a substantive response within thirty days, including remedial steps where failures are identified. Unresolved concerns may be referred to the ICO as noted in Section 8.

19. Identity Verification for Requests

To protect personal data from unauthorised disclosure, we may request reasonable evidence of identity before fulfilling access or erasure requests. We accept government-issued identification, corporate email verification for business contacts, or other proportionate methods depending on risk. We minimise data collected for verification and delete verification artefacts when no longer needed.

20. Statistical and Aggregated Reporting

We may create aggregated statistics about website usage, service performance, or sector trends that do not identify individuals. Such reports may be used internally or shared commercially provided re-identification risk is negligible and contractual confidentiality obligations are respected.

21. Additional Transparency Statement

We document data flows for major client engagements during discovery phases, identifying systems that store personal data, expected volumes, retention needs, and access roles. This supports accurate privacy notices and security architecture.

22. Additional Transparency Statement

Where clients request penetration testing or vulnerability assessments, personal data in non-production environments should be synthetic or anonymised unless explicit written authorisation covers live data subsets.

23. Additional Transparency Statement

Email correspondence may be archived in secure mailboxes with litigation hold procedures applied when disputes are reasonably anticipated.

24. Additional Transparency Statement

Telephone enquiries may be logged in customer relationship systems with notes limited to business-relevant content.

25. Additional Transparency Statement

If you attend webinars or events hosted by HSKG LTD, registration data is used for attendance management and follow-up aligned with stated event purposes.

26. Additional Transparency Statement

We do not use personal data for purposes materially incompatible with original collection without notice and, where required, fresh consent.

27. Additional Transparency Statement

Personnel with access to personal data receive orientation on confidentiality, phishing awareness, and incident reporting obligations.

28. Additional Transparency Statement

Subprocessors are reviewed for security certifications, data handling practices, and geographic processing locations before engagement.

29. Additional Transparency Statement

Clients may request schedules of categories of processors used in connection with their projects where commercially reasonable and not unduly burdensome.

30. Additional Transparency Statement

Backup encryption keys are managed separately from backup media to reduce compromise risk.

31. Additional Transparency Statement

Development and staging environments use masked datasets where feasible to limit exposure during testing.

32. Additional Transparency Statement

Access reviews for administrative accounts occur periodically and upon role changes.

33. Additional Transparency Statement

Personal data in printed form, though minimised, is stored securely and shredded when discarded.

34. Additional Transparency Statement

We assess new legislation and ICO guidance to update practices proactively rather than reactively after enforcement action.

35. Additional Transparency Statement

Data minimisation extends to web forms, which request only fields necessary to respond effectively to enquiries.

36. Additional Transparency Statement

If you are a supplier contact, we process your business contact details to manage procurement, invoicing, and performance reviews.

37. Additional Transparency Statement

Cookies that are strictly necessary for site operation do not require consent; details appear in our Cookie Policy.

38. Additional Transparency Statement

We may record metrics on proposal conversion and service uptake using aggregated internal reporting without identifying individual prospects beyond sales pipeline records.

39. Additional Transparency Statement

Where video conferencing is used for meetings, participants should review platform privacy settings; HSKG LTD does not routinely record calls without notice and lawful basis.

40. Additional Transparency Statement

Project repositories may contain configuration secrets; clients must avoid committing live personal datasets to version control without safeguards.

41. Additional Transparency Statement

Disaster recovery exercises test restoration procedures while protecting confidentiality of restored content.

42. Additional Transparency Statement

We reject requests to process personal data for unlawful surveillance or discriminatory profiling.

43. Additional Transparency Statement

If law enforcement requests data, we verify authority and scope before disclosure, documenting decisions internally.

44. Additional Transparency Statement

Personal data relating to failed payment disputes is retained only as long as needed to resolve financial matters.

45. Additional Transparency Statement

You may appoint an authorised representative to communicate with us on your behalf by providing written evidence of authority.

46. Additional Transparency Statement

We do not publish client personal data in marketing case studies without explicit approval of quoted individuals.

47. Additional Transparency Statement

Security incidents involving personal data are assessed for breach notification duties to clients, individuals, and the ICO as applicable.

48. Additional Transparency Statement

Remote access to client systems requires approved methods such as VPN or zero-trust access aligned with engagement terms.

49. Additional Transparency Statement

We maintain versioning of this policy to support audit trails of historical practices upon request where feasible.

50. Additional Transparency Statement

Questions about international data transfer mechanisms may be directed to office@hskg.digital with engagement references where relevant.

51. Additional Transparency Statement

Personal data processed for accounting is shared with our accountants under confidentiality obligations and used solely for statutory filings and management accounts.

52. Operational Privacy Note

HSKG LTD maintains internal checklists aligning daily operations with UK data protection expectations. This includes verifying that new software deployments affecting personal data receive privacy review, that data exports from client systems are encrypted in transit, that obsolete hardware is sanitised before disposal, and that third-party integrations are documented in client-facing materials where those integrations touch end-user data. We train team members to recognise personal data in logs and support tickets, redacting identifiers where full retention is unnecessary. Contract templates include data protection clauses appropriate to processor and controller roles. When clients request data return at project closure, we provide structured exports within agreed timeframes and confirm deletion of residual copies except where law mandates retention. We periodically test restoration of encrypted backups containing personal data to ensure availability without undermining confidentiality controls. Vendor contracts are renewed with reassessment of subprocessors and transfer tools. If you require a written summary of safeguards for a specific engagement, contact office@hskg.digital with your project reference and we will respond within a reasonable period subject to confidentiality obligations.

53. Operational Privacy Note

HSKG LTD maintains internal checklists aligning daily operations with UK data protection expectations. This includes verifying that new software deployments affecting personal data receive privacy review, that data exports from client systems are encrypted in transit, that obsolete hardware is sanitised before disposal, and that third-party integrations are documented in client-facing materials where those integrations touch end-user data. We train team members to recognise personal data in logs and support tickets, redacting identifiers where full retention is unnecessary. Contract templates include data protection clauses appropriate to processor and controller roles. When clients request data return at project closure, we provide structured exports within agreed timeframes and confirm deletion of residual copies except where law mandates retention. We periodically test restoration of encrypted backups containing personal data to ensure availability without undermining confidentiality controls. Vendor contracts are renewed with reassessment of subprocessors and transfer tools. If you require a written summary of safeguards for a specific engagement, contact office@hskg.digital with your project reference and we will respond within a reasonable period subject to confidentiality obligations.

54. Operational Privacy Note

HSKG LTD maintains internal checklists aligning daily operations with UK data protection expectations. This includes verifying that new software deployments affecting personal data receive privacy review, that data exports from client systems are encrypted in transit, that obsolete hardware is sanitised before disposal, and that third-party integrations are documented in client-facing materials where those integrations touch end-user data. We train team members to recognise personal data in logs and support tickets, redacting identifiers where full retention is unnecessary. Contract templates include data protection clauses appropriate to processor and controller roles. When clients request data return at project closure, we provide structured exports within agreed timeframes and confirm deletion of residual copies except where law mandates retention. We periodically test restoration of encrypted backups containing personal data to ensure availability without undermining confidentiality controls. Vendor contracts are renewed with reassessment of subprocessors and transfer tools. If you require a written summary of safeguards for a specific engagement, contact office@hskg.digital with your project reference and we will respond within a reasonable period subject to confidentiality obligations.

55. Operational Privacy Note

HSKG LTD maintains internal checklists aligning daily operations with UK data protection expectations. This includes verifying that new software deployments affecting personal data receive privacy review, that data exports from client systems are encrypted in transit, that obsolete hardware is sanitised before disposal, and that third-party integrations are documented in client-facing materials where those integrations touch end-user data. We train team members to recognise personal data in logs and support tickets, redacting identifiers where full retention is unnecessary. Contract templates include data protection clauses appropriate to processor and controller roles. When clients request data return at project closure, we provide structured exports within agreed timeframes and confirm deletion of residual copies except where law mandates retention. We periodically test restoration of encrypted backups containing personal data to ensure availability without undermining confidentiality controls. Vendor contracts are renewed with reassessment of subprocessors and transfer tools. If you require a written summary of safeguards for a specific engagement, contact office@hskg.digital with your project reference and we will respond within a reasonable period subject to confidentiality obligations.

56. Operational Privacy Note

HSKG LTD maintains internal checklists aligning daily operations with UK data protection expectations. This includes verifying that new software deployments affecting personal data receive privacy review, that data exports from client systems are encrypted in transit, that obsolete hardware is sanitised before disposal, and that third-party integrations are documented in client-facing materials where those integrations touch end-user data. We train team members to recognise personal data in logs and support tickets, redacting identifiers where full retention is unnecessary. Contract templates include data protection clauses appropriate to processor and controller roles. When clients request data return at project closure, we provide structured exports within agreed timeframes and confirm deletion of residual copies except where law mandates retention. We periodically test restoration of encrypted backups containing personal data to ensure availability without undermining confidentiality controls. Vendor contracts are renewed with reassessment of subprocessors and transfer tools. If you require a written summary of safeguards for a specific engagement, contact office@hskg.digital with your project reference and we will respond within a reasonable period subject to confidentiality obligations.

57. Operational Privacy Note

HSKG LTD maintains internal checklists aligning daily operations with UK data protection expectations. This includes verifying that new software deployments affecting personal data receive privacy review, that data exports from client systems are encrypted in transit, that obsolete hardware is sanitised before disposal, and that third-party integrations are documented in client-facing materials where those integrations touch end-user data. We train team members to recognise personal data in logs and support tickets, redacting identifiers where full retention is unnecessary. Contract templates include data protection clauses appropriate to processor and controller roles. When clients request data return at project closure, we provide structured exports within agreed timeframes and confirm deletion of residual copies except where law mandates retention. We periodically test restoration of encrypted backups containing personal data to ensure availability without undermining confidentiality controls. Vendor contracts are renewed with reassessment of subprocessors and transfer tools. If you require a written summary of safeguards for a specific engagement, contact office@hskg.digital with your project reference and we will respond within a reasonable period subject to confidentiality obligations.