legal
GDPR and data protection policy.
Last updated 19 August 2026.
This policy explains how CIO Solutions LTD (Company No. 16179733) approaches data protection under the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 as amended, and the Data (Use and Access) Act 2025. It should be read alongside the privacy and cookie policy, which explains the information collected through this website.
Where the EU GDPR applies, its corresponding transparency, lawful-basis, individual-rights, processor, and international transfer requirements are applied to that processing as well.
This page is intended to give clients, prospects, suppliers, and website visitors a clear view of the way personal data is handled. It is not a substitute for any client-specific data processing agreement, statement of work, or security schedule.
Controller details
The data controller for this website and general business administration is CIO Solutions LTD. You can contact me at hello@interimcio.co.uk or write to C/O Pm+M, New Century House, Greenbank Technology Park, Challenge Way, Blackburn, Lancashire, BB1 5QB, United Kingdom.
Where client work involves personal data, the role of CIO Solutions LTD may vary. Depending on the engagement, I may act as a controller, joint controller, or processor. The relevant contract or statement of work should set this out for each project.
Data protection principles
Personal data is handled in line with the core UK GDPR principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.
In practical terms, this means I aim to collect only what is needed, explain why it is needed, keep it for no longer than is reasonable, protect it appropriately, and document decisions where the risk or sensitivity requires it.
Lawful bases
The lawful basis used depends on the context. Typical lawful bases include:
- Contract, where data is needed to discuss, deliver, or manage a service.
- Legitimate interests, where data is needed to respond to enquiries, run the business, secure systems, and produce limited aggregate statistics to improve the website, subject to a necessity and balancing assessment.
- Consent, where someone opts into marketing or accepts analytics cookies.
- Legal obligation, where records must be kept for accounting, tax, compliance, or other legal reasons.
The UK PECR rule for storing or accessing information on a device is considered separately from the UK GDPR lawful basis. Anonymous Vercel Web Analytics uses no analytics cookies or persistent visitor identifier and relies on legitimate interests in producing aggregate statistics to measure and improve this site, with a simple objection mechanism. Limited cookieless Google Analytics for UK visitors also relies on the statistical-purposes exception. That exception is used only for aggregate information about how this site is used, only to improve this site, and only while a simple and free objection mechanism is available. If Google Analytics processing goes beyond that purpose, consent is required.
Sending an enquiry asks the business to respond and does not add the sender to a marketing list. Newsletter subscriptions rely on the clear action of selecting Subscribe beside a specific email-marketing notice. Beehiiv is used to keep the subscription record and provide an unsubscribe mechanism in each issue; withdrawn addresses are not reactivated without a fresh request.
Personal data handled
The personal data handled by the business may include contact details, company details, enquiry messages, newsletter signup information, booking details, analytics data, supplier correspondence, project records, a voluntarily published game nickname and score, short-lived pseudonymous rate-limit data, and information included in client systems or documents during an engagement.
Website analytics and regional controls
Vercel Web Analytics provides anonymous page counting without cookies in every region by default. It creates a visitor hash from the incoming request that resets after 24 hours and cannot be used to follow someone across days or websites. It is disabled after a visitor selects Turn all analytics off or sends a recognised Global Privacy Control signal.
Google Analytics is configured separately by broad location. For UK and US visitors, limited cookieless Google Analytics may run for aggregate site improvement with an immediate opt-out. For EEA and Swiss visitors, Google Analytics is blocked until explicit cookie consent. Other or unknown locations use the same Google opt-in-only fallback. California visitors receive additional notice.
In limited Google mode, consent settings deny analytics storage and all advertising-related consent types. The implementation removes query parameters before sending page views, does not set a User-ID, disables Google signals and advertising personalisation in code, and does not use cross-domain tracking. Selecting Turn all analytics off prevents both Vercel and Google from sending further analytics events.
Analytics cookies are separate and require an affirmative choice. The preference expires after 180 days, can be changed through the footer at any time, and is re-evaluated when the visitor’s current region requires a stricter rule.
I do not intentionally collect special category personal data through this website. If a client project may involve sensitive data, the scope, controls, access rights, and lawful basis should be agreed before that work starts.
Client systems and AI work
Some engagements may involve reviewing business systems, workflows, documents, datasets, or AI tooling. Where personal data is involved, access should be limited to what is necessary for the agreed work.
For AI-related projects, I aim to avoid using personal data where anonymised, pseudonymised, synthetic, or sampled data would be sufficient. Where external AI services are used, the data flow, vendor position, retention settings, and relevant safeguards should be agreed as part of the engagement.
Processors and service providers
I use a small number of service providers to operate the website and business. These may include hosting, analytics, email, newsletter, booking, cloud, and professional-services providers. The current website privacy policy names the main providers used for this site, including Upstash for rate limiting and the optional game leaderboard.
Where a provider processes personal data on behalf of CIO Solutions LTD, I aim to use providers that offer appropriate contractual, technical, and organisational safeguards.
Google Analytics must remain configured as a processor for this site. Google products-and-services data sharing, Google signals, user-provided data collection, advertising personalisation, and advertising-product links must remain disabled. Vercel and Google are used only to provide aggregate website measurement and site improvement information. No analytics data is sold or shared for cross-context behavioural advertising.
International transfers
Some providers may process or store data outside the UK or EEA. Where this happens, I aim to rely on an appropriate transfer mechanism, such as an adequacy arrangement, the EU standard contractual clauses, the UK addendum, or equivalent safeguards offered by the provider. Provider roles, transfer terms, and data-sharing settings should be reviewed when a service or its configuration changes.
Retention
Personal data is kept only for as long as it is needed for the purpose it was collected, including any legal, accounting, security, or dispute-resolution requirements. Website enquiries that do not become client relationships are normally reviewed for deletion after 24 months. Project records may be retained where needed to manage the relationship and keep an accurate business record. A minimal newsletter suppression record may be retained after unsubscribe to ensure the opt-out continues to be honoured.
Google Analytics user-level and event-level retention is set to the shortest standard option of two months; aggregate reports may remain available for longer. Vercel’s analytics visitor hash is discarded after 24 hours and its current free-plan aggregate reporting window is 30 days. The local privacy preference is treated as valid for no more than 180 days. Website rate-limit records last about one hour or less, unused game runs last 30 minutes, and published leaderboard names and scores last no more than 12 months.
Security
I use proportionate technical and organisational measures to protect personal data. These may include access controls, multi-factor authentication, least-privilege access, secure cloud services, device security, encrypted transport, and limiting access to client data to the people and systems that need it.
No website, cloud service, or email system can be guaranteed to be completely secure. If I become aware of a personal data breach, I will assess the risk and, where required, notify the affected client, individual, or the Information Commissioner’s Office within the relevant legal timeframe.
Your rights
Individuals have rights under the UK GDPR. These may include the right to be informed, access personal data, correct inaccurate data, request erasure, restrict processing, object to processing, request portability, and challenge certain automated decisions.
To exercise a right, email hello@interimcio.co.uk. I may need to verify your identity before acting on a request. If the request relates to data processed on behalf of a client, I may need to refer the request to that client as the relevant controller. Valid requests are normally answered within one month, subject to a permitted extension or legal exception.
Where applicable US state privacy law applies, residents may also have rights to know, correct, delete, obtain a copy, and opt out of sale, sharing, targeted advertising, or certain profiling. The business does not sell personal information or share it for cross-context behavioural advertising. These requests can be sent to the same email address and will not result in discriminatory treatment.
Complaints
To make a data-protection complaint, email hello@interimcio.co.uk with “Privacy complaint” in the subject, or write to the controller address above. I will acknowledge it within 30 days, make appropriate enquiries without undue delay, keep you informed, and explain the outcome. I will keep a proportionate record of the complaint, acknowledgement, investigation, outcome, and any action taken. You also have the right to complain to the UK Information Commissioner’s Office at ico.org.uk or, where the EU GDPR applies, the competent EEA supervisory authority.
Review
This policy will be reviewed periodically and updated when the website, services, providers, or legal requirements change.