DRAFT
DATA PROTECTION · UNITED KINGDOM
Privacy Statement & Privacy Policy
How we collect, use, share and protect your personal information, and the rights you hold over it.
Controller: Joel Gustafsson Consulting Limited Effective: 23/06/26 Version: 1.0
Privacy statement (the short version)
Joel Gustafsson Consulting Limited (“we”, “us”, “our”) respects your privacy and is committed to protecting your personal data. We collect only the information we need, use it only for the purposes set out below, keep it secure, and never sell it.
You have the right to access your data, correct it, ask us to delete it, object to how we use it, and complain to us or to the Information Commissioner’s Office. The full policy below explains everything in detail. If you have any questions, contact us at dan@jgcengineers.com and contact@jgcengineers.com
CONTENTS
01 Who we are
02 Scope of this policy
03 Personal data we collect
04 How we collect it
05 How & why we use it
06 Cookies & similar technologies
07 Marketing communications
08 Who we share it with
09 International transfers
10 How long we keep it
11 How we protect it
12 Your rights
13 Automated decisions & profiling
14 Children's data
15 Changes to this policy
16 Contact & complaints
01 Who we are
Joel Gustafsson Consulting Limited is the “controller” responsible for your personal data. This means we decide how and why your data is processed.
— Registered/trading name: Joel Gustafsson Consulting Limited
— Company registration number: 12775594 (registered in England & Wales)
— Registered address: 12C King’s Parade, Cambridge, CB2 1SJ
— ICO registration reference: not required based on our company profile and services
— Data protection contact: Daniel O’Neill, dan@jgcengineers.com
Based on our company profile and services, we are not required to appoint a Data Protection Officer.
02 Scope of this policy
This policy applies to personal data we collect through our website at https://www.jgcengineers.com when you contact us, when you use our services, and through our dealings with clients, suppliers and other contacts.
Our website may contain links to third-party websites. We are not responsible for their privacy practices, and we encourage you to read their own policies before sharing any data with them.
03 Personal data we collect
We may collect and process the following categories of personal data. Amend this list to match what you actually collect.
— Identity data — name, title, job title and the organisation you represent.
— Contact data — postal address, email address and telephone number.
— Correspondence data — the content of enquiries, messages and any documents you send us.
— Transaction & contract data — details of services provided, projects, payments and invoicing where relevant.
— Technical & usage data — IP address, browser type and version, device information, pages visited and how you interact with the site.
— Marketing & communications data — your preferences for receiving communications from us.
SPECIAL CATEGORY DATA
We do not routinely collect “special category” data (such as data about health, ethnicity, religion or political views) and ask that you do not send it to us unless we have specifically requested it for a clear purpose.
04 How we collect it
— Directly from you — when you fill in a form, email or call us, engage our services, or otherwise correspond with us.
— Automatically — as you navigate our website, through cookies and similar technologies (see section 06).
— From third parties — for example publicly available sources, referrals, or service providers such as analytics and hosting providers.
05 How and why we use it
We only use your personal data when the law allows us to. Under the UK GDPR we must always have a “lawful basis” for processing. The table below sets out the main ways we use your data and the lawful basis we rely on for each. Tailor this table to your actual activities — it is the heart of a compliant policy.
PURPOSE · DATA USED · LAWFUL BASIS
PURPOSE DATA USED LAWFUL BASIS
Respond to enquiries and provide information you request Identity, contact, correspondence Legitimate interests; steps prior to a contract
Provide our services and manage our relationship with you Identity, contact, transaction/contract Performance of a contract; legitimate interests
Administration, invoicing and keeping business records Identity, contact, transaction Legal obligation; legitimate interests
Operate, secure and improve our website Technical & usage Legitimate interests; consent (non-essential cookies)
Send marketing communications Contact, marketing preferences Consent; or legitimate interests (soft opt-in)
Comply with legal and regulatory obligations As required Legal obligation
WHERE WE RELY ON LEGITIMATE INTERESTS
“Legitimate interests” means our (or a third party’s) genuine business interest in handling your data in a proportionate way that respects your rights. We carry out a balancing assessment before relying on this basis, and you can object at any time (see section 12). The Data (Use and Access) Act 2025 introduced a category of “recognised legitimate interests” for certain limited purposes; where we rely on this we will tell you.
IF YOU DO NOT PROVIDE YOUR DATA
Where we need data to enter into or perform a contract with you and you do not provide it, we may be unable to provide the service in question. We will tell you if this is the case.
06 Cookies and similar technologies
Cookies are small files stored on your device. We use:
— Strictly necessary cookies — required for the site to function. These do not need your consent.
— Analytics and performance cookies — help us understand how the site is used. [Name your provider, e.g. Google Analytics.]
— Functional / marketing cookies — [describe, or delete if none.]
Under PECR we will only set non-essential cookies with your consent, which we obtain through our cookie banner. You can withdraw or change your consent at any time via [link to cookie settings] and control cookies through your browser settings. For full details, see our [Cookie Policy].
07 Marketing communications
We do not engage in marketing communications.
If we ever do so, we will only send you marketing where you have consented, or where you are an existing customer and the law permits it (“soft opt-in”). Every marketing email contains an unsubscribe link, and you can opt out at any time by contacting us at dan@jgcengineers.com and contact@jgcengineers.com. Opting out of marketing will not stop service-related messages we are required to send you.
08 Who we share it with
We do not sell your personal data. We may share it with:
— Service providers (“processors”) who act on our instructions — for example IT, hosting, email, analytics, accounting and professional advisers. They may only use your data as we direct.
— Project partners and sub-consultants where necessary to deliver our services to you.
— Regulators, authorities and law enforcement where we are legally required to do so.
— Buyers or successors if we reorganise, sell or transfer our business.
We put written contracts in place with our processors requiring them to keep your data secure and to use it only for specified purposes.
09 International transfers
We aim to keep your personal data within the UK. Where any of our providers store or process data outside the UK, we ensure a similar level of protection by relying on a UK “adequacy” decision for that country, or on an approved safeguard such as the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses. You can ask us for more detail on the safeguards in place.
10 How long we keep it
We keep personal data only for as long as necessary for the purposes we collected it for, including to satisfy legal, accounting or reporting requirements. As a general guide:
— Enquiries that don’t proceed: 12 months
— Client and contract records: 12 years after the relationship ends
— Financial and tax records: at least 6 years (HMRC requirement)
— Marketing data: until you unsubscribe, then for a short suppression period
When data is no longer needed we securely delete or anonymise it.
11 How we protect it
We use appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, misuse or alteration — including access controls, encryption where appropriate, and staff confidentiality obligations. Where we are legally required to do so, we will notify you and the ICO of a personal data breach.
12 Your rights
Under UK data protection law you have the right to:
— Be informed about how we use your data (this policy).
— Access a copy of the personal data we hold about you.
— Rectification — have inaccurate or incomplete data corrected.
— Erasure — ask us to delete your data in certain circumstances.
— Restrict our use of your data in certain circumstances.
— Data portability — receive certain data in a portable format.
— Object to processing based on legitimate interests, and to direct marketing at any time.
— Withdraw consent at any time, where we rely on consent.
— Rights relating to automated decision-making (see section 13).
— Complain — to us in the first instance, and to the ICO (see section 16).
To exercise any of these rights, contact us using the details in section 16. Exercising your rights is free, and we will respond within one month. We may ask you to verify your identity, and in some cases the law allows us to charge a fee or decline a request that is manifestly unfounded or excessive.
13 Automated decisions and profiling
We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
14 Children’s data
Our website and services are intended for adults and are not directed at children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
15 Changes to this policy
We may update this policy from time to time. The current version is always available on this page, and the “Effective” date at the top shows when it was last revised. Where changes are significant, we will take reasonable steps to bring them to your attention.
16 Contact and complaints
CONTACT US
For any question about this policy or your data, or to exercise your rights, contact:
— Daniel O’Neill, Head of Operations; Joel Gustafsson Consulting Limited
— Email: dan@jgcengineers.com and contact@jgcengineers.com
— Post: 12C King’s Parade, Cambridge, CB2 1SJ
COMPLAINTS
We hope to resolve any concern you raise. You also have the right to complain to the UK’s data protection regulator, the Information Commissioner’s Office (ICO):
— Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
— Helpline: 0303 123 1113
— Website: ico.org.uk
We would, however, appreciate the chance to address your concerns before you approach the ICO, so please contact us first.
Joel Gustafsson Consulting Limited · Registered in England & Wales no. 12775594
This Privacy Statement & Privacy Policy was last updated on 23/06/2026