Simor

Simor Consulting

Privacy

Last updated: 4 November 2025

Simor Consulting (“we”, “us”, “our”) respects your privacy. This Privacy Policy explains what personal information we collect, how we use it, and your choices. It applies to our website, communications, and any services that link to this Policy.

This Policy is designed to meet requirements of UK and EU data protection laws (UK GDPR and EU GDPR) and to provide additional disclosures for certain U.S. laws (including the CCPA/CPRA for California residents).

Controller

Simor Consulting is the controller of your personal information.

If you contact us by email about your privacy rights, we may ask for information to verify your identity before acting on your request.

Information We Collect

  • Contact details: name, work email, phone, company, role.
  • Business information: project details, interests, and messages you send via forms or email.
  • Usage data: pages viewed, links clicked, referring pages, approximate location, device/browser information.
  • Cookies and similar technologies: used for site functionality, analytics, and performance. See “Cookies & Analytics” below.

We collect information directly from you (for example, through contact and workshop request forms) and automatically when you use our site.

How We Use Information

We use personal information to:

  • Provide, operate, and improve our website and services.
  • Respond to inquiries, schedule workshops, and communicate with you.
  • Send service-related messages and updates you request.
  • Maintain security, prevent fraud/abuse, and troubleshoot.
  • Analyse site performance and usage trends.
  • Comply with legal obligations and enforce our terms.

Where UK/EU data protection law applies, we rely on these bases: (i) performance of a contract or taking steps at your request; (ii) legitimate interests (for example, to operate and improve the site, secure our services, and communicate with business contacts); (iii) consent (where required, e.g., certain cookies/marketing); and (iv) legal obligations.

Cookies & Analytics

We use essential cookies to make the site work and, where implemented, analytics cookies to understand traffic and improve performance. Where required, we will obtain your consent for non‑essential cookies. You can adjust your browser settings to refuse cookies; some features may not work without them.

If we enable analytics via Google Tag Manager (for example, a Google Analytics 4 tag), we configure tags to avoid sending personally identifiable information and, where available, to anonymise IP addresses. Analytics tags will not run until you consent to non‑essential cookies.

Sharing Your Information

We do not sell your personal information. We may share it with:

  • Service providers that help us host, operate, analyse, or secure the site and deliver communications (under contractual confidentiality and security commitments).
  • Professional advisors, and authorities where required by law or to protect rights, safety, and security.
  • Successors in the event of a merger, acquisition, or business reorganisation.

Named processors and recipients (where used):

  • Web3Forms (form handling for contact/workshop requests) – receives the data you submit via our forms so we can process your request.
  • Google (Google Tag Manager; tags such as Google Analytics 4 if enabled) – website analytics, only if you consent to analytics cookies.
  • Email and hosting/infrastructure providers – to deliver our services and communications.

International Transfers

If we transfer personal information outside the UK/EU (for example, to service providers), we use appropriate safeguards required by law, such as UK/EU Standard Contractual Clauses or an adequacy decision. You can contact us for more information about these safeguards.

Data Retention

We keep personal information only as long as necessary for the purposes described above, to comply with legal obligations, and to resolve disputes. Typical retention periods are:

  • Contact and workshop requests: up to 24 months from last interaction.
  • Website analytics (if enabled): per tag/provider settings (for example, GA4 event‑level retention) and longer in aggregate form.
  • Server and security logs: up to 12 months, unless needed to investigate an issue.

Your Rights

  • UK/EU: You may have rights to access, correct, delete, restrict or object to processing, and data portability. Where we rely on consent, you may withdraw it at any time.
  • California: You may have rights to know/access, delete, correct, and opt out of certain data sharing. We do not sell personal information or share it for cross‑context behavioural advertising.

To exercise rights, contact us using the details below. We may need to verify your identity before fulfilling a request.

Automated Decision‑Making

We do not use personal information for automated decision‑making that produces legal or similarly significant effects.

Security

We implement reasonable technical and organisational measures to protect personal information. No method of transmission or storage is completely secure.

Children

Our site and services are intended for business users and are not directed to children under 16. We do not knowingly collect personal information from children.

Changes to This Policy

We may update this Policy from time to time. The “Last updated” date shows when changes were made. Material changes will be highlighted on this page.

Contact Us

If you have questions about this Policy or wish to exercise your rights:

Simor Consulting

If you are located in the UK, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO): ico.org.uk or 0303 123 1113. You can also contact your local data protection authority if you are in the EU.