Privacy Policy
1. Introduction and company information
This Privacy Policy explains how Northshore Customer Experience Solutions Ltd collects, uses, stores, discloses, and protects personal data in connection with its customer-experience services and related business operations. It also explains the rights of individuals whose personal data we process.
For the purposes of applicable privacy laws, the data controller is:
- Company name: Northshore Customer Experience Solutions Ltd
- Address: Northshore CX, 14 Bloomsbury Street, London WC1B 3QJ, United Kingdom
- Email: [email protected]
- Phone: +44 20 7946 8372
This Privacy Policy applies to personal data processed through our websites, communications, service delivery activities, client support activities, marketing activities, and any other interaction where Northshore Customer Experience Solutions Ltd acts as a controller or, where applicable, as a processor on behalf of a client.
2. Data collection and processing
We may collect and process the following categories of personal data:
- Identity data: name, title, username, and similar identifiers.
- Contact data: email address, telephone number, postal address, company name, and job title.
- Communication data: correspondence, enquiries, support requests, call records, chat transcripts, and meeting notes.
- Technical data: IP address, browser type, device identifiers, operating system, log data, and website interaction data.
- Usage data: information about how you use our website, services, and communications.
- Service-related data: information provided to us in connection with customer-experience projects, feedback programmes, surveys, complaints, or support interactions.
- Marketing data: preferences regarding marketing communications and engagement with such communications.
- Contract and billing data: payment-related details, invoicing information, and transaction records where applicable.
We collect personal data directly from you, from our clients where necessary for service delivery, from your organisation, from publicly available sources, and from third-party providers such as analytics, communications, and IT service providers. We may also generate data through our interactions with you, including notes, service records, and performance or quality assurance records.
We do not intentionally collect special category personal data unless it is necessary and lawful to do so, for example where you choose to provide such information in correspondence or feedback. If we process special category data, we will do so only where permitted by law and subject to appropriate safeguards.
3. Purpose of data processing
We process personal data for the following purposes:
- to provide and manage our customer-experience services;
- to respond to enquiries, complaints, and support requests;
- to communicate with clients, prospects, suppliers, and website users;
- to manage contractual and pre-contractual relationships;
- to operate, maintain, and improve our website, systems, and services;
- to analyse service performance, customer feedback, and user experience;
- to conduct quality assurance, training, and internal administration;
- to send marketing communications where permitted by law and, where required, with consent;
- to detect, prevent, and investigate fraud, security incidents, and misuse;
- to comply with legal, regulatory, tax, accounting, and record-keeping obligations;
- to establish, exercise, or defend legal claims.
Where personal data is processed on behalf of a client as a processor, we process that data only in accordance with the client’s instructions and applicable data processing agreements.
4. Legal basis for processing
We process personal data only where we have a lawful basis to do so. Depending on the context, our lawful bases may include:
- Performance of a contract: where processing is necessary to enter into or perform a contract with you or your organisation;
- Legitimate interests: where processing is necessary for our legitimate business interests or those of a third party, provided such interests are not overridden by your rights and freedoms;
- Consent: where you have given clear consent for a specific purpose, such as certain marketing activities or optional cookies where applicable;
- Legal obligation: where processing is necessary to comply with applicable laws or regulatory requirements;
- Vital interests: where processing is necessary to protect someone’s life in an emergency;
- Public task or official authority: where applicable under law, though this is generally not relevant to our ordinary commercial operations.
Where we rely on legitimate interests, we consider the impact of the processing on your rights and freedoms and implement appropriate safeguards.
5. Data sharing and third parties
We may share personal data with the following categories of recipients where necessary and lawful:
- group or affiliated entities, if any, for internal administration and service support;
- clients, where we act as a processor or where disclosure is otherwise required to deliver services;
- service providers and processors such as hosting providers, cloud service providers, IT support, communication tools, analytics providers, CRM systems, payment providers, and professional advisers;
- professional advisers including lawyers, accountants, auditors, insurers, and consultants;
- regulators, law enforcement agencies, courts, and other authorities where required by law;
- third parties involved in a business transaction, such as a merger, acquisition, or reorganisation.
We require third parties that process personal data on our behalf to protect the data, process it only for specified purposes, and implement appropriate technical and organisational safeguards. Where we disclose personal data to independent third parties, they are responsible for their own privacy practices.
6. Data transfer to third countries
Where personal data is transferred outside the United Kingdom or other applicable jurisdiction, we take steps to ensure that the transfer is lawful and that the data receives an appropriate level of protection. Such measures may include:
- transferring data to countries recognised as providing adequate protection;
- using appropriate contractual safeguards, such as standard contractual clauses or equivalent mechanisms;
- implementing supplementary technical and organisational measures where necessary;
- carrying out transfer risk assessments where required by law.
Further information about international transfers may be provided upon request where legally permitted.
7. Storage duration
We retain personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, regulatory, accounting, or reporting requirements.
In determining retention periods, we consider:
- the nature and sensitivity of the personal data;
- the purposes of processing;
- the legal basis for processing;
- the likelihood and impact of potential risks;
- applicable limitation periods and legal obligations.
When personal data is no longer required, we will delete it securely or anonymise it where appropriate. If we process data on behalf of a client, retention and deletion will generally follow the client’s instructions and the relevant contract.
8. User rights (access, rectification, erasure, restriction, data portability, objection)
Subject to applicable law, you may have the following rights in relation to your personal data:
- Access: to request confirmation of whether we process your personal data and obtain a copy of it;
- Rectification: to request correction of inaccurate or incomplete personal data;
- Erasure: to request deletion of your personal data in certain circumstances;
- Restriction: to request that we limit the processing of your personal data in certain circumstances;
- Data portability: to receive certain personal data in a structured, commonly used, machine-readable format and transmit it to another controller where technically feasible;
- Objection: to object to processing based on legitimate interests and to object at any time to direct marketing;
- Right not to be subject to solely automated decision-making: where applicable under law, to request human intervention and challenge decisions made solely by automated means.
To exercise any of these rights, please contact us using the details below. We may need to verify your identity before responding. We will respond within the time period required by applicable law and may refuse or limit a request where permitted by law.
9. Withdrawal of consent
Where we rely on your consent to process personal data, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of processing carried out before the withdrawal, nor will it affect processing based on other lawful grounds.
You can withdraw consent by contacting us at [email protected] or by using any unsubscribe mechanism included in our communications, where available.
10. Right to complain
If you have concerns about how we process your personal data, we encourage you to contact us first so we can try to resolve the issue.
You also have the right to lodge a complaint with the relevant data protection supervisory authority. In the United Kingdom, this is the Information Commissioner’s Office (ICO). You can find more information on the ICO’s website.
11. Data security
We implement appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures may include:
- access controls and authentication measures;
- encryption in transit and, where appropriate, at rest;
- secure storage and backup procedures;
- staff training and confidentiality obligations;
- regular monitoring, vulnerability management, and security reviews;
- incident response and breach management processes.
While we take reasonable steps to protect personal data, no system can be guaranteed to be completely secure. You are responsible for keeping any credentials or passwords confidential where applicable.
12. Contact information
If you have any questions about this Privacy Policy or our handling of personal data, or if you wish to exercise your rights, please contact:
- Northshore Customer Experience Solutions Ltd
- Northshore CX, 14 Bloomsbury Street, London WC1B 3QJ, United Kingdom
- Email: [email protected]
- Phone: +44 20 7946 8372
13. Changes to privacy policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, technology, or business operations. Any updated version will be posted on our website with a revised effective date where appropriate.
We encourage you to review this Privacy Policy periodically to stay informed about how Northshore Customer Experience Solutions Ltd processes personal data.