LEGAL
Privacy Policy
How Systems House collects, uses and protects personal data when you use this website or work with us.
Last updated: 2026-09-22 · Version 1.2
1. Who we are
Systems House ("we", "us", "our") operates this website at systemshouse.digital.
We are the data controller for the personal data described in this policy. If you have any question about this policy or how we handle your data, contact Systems House privacy contact at privacy@systemshouse.digital.
2. The short version
- We collect the details you choose to send through the contact form or systems questionnaire so we can reply.
- Enquiries are sent by email. This website does not store enquiry records locally.
- Completed systems questionnaires are added to our Brevo contact list so we can manage and respond to the enquiry. Marketing email remains a separate choice.
- We do not run first-party stored analytics or session recordings.
- Google Analytics is optional and only loads if you accept analytics cookies.
- We do not sell personal data or share it for anyone else's marketing.
- You can ask us for a copy of your data, or ask us to delete it, at any time.
3. What we collect and why
3.1 Contact forms and the systems questionnaire
We collect the information you choose to give us: your name, work email address, business name, phone number if you provide one, and whatever you tell us about what you are trying to solve.
The form submission is emailed to us so we can respond. Completed systems questionnaires are also stored in our Brevo contact list as an operational enquiry record. The website itself does not keep a local copy.
Brevo receives the details you submit, the systems suggested by the questionnaire, submission context and your marketing choice. This processing is for the same enquiry-management purposes and lawful bases described above. Questionnaire records are normally kept for 24 months from our last contact unless you become a client.
The separate marketing email box is optional and unticked. If you select it, we record the wording and time of your consent and allow marketing email. If you do not select it, the Brevo contact is email-blocklisted and must not receive marketing campaigns.
Why: to respond to your enquiry, prepare a systems map and discuss whether we can help.
Lawful basis: Article 6(1)(b) UK GDPR - steps taken at your request before entering into a contract. Where you are enquiring on behalf of an organisation, we may rely on Article 6(1)(f) - our legitimate interest in responding to business enquiries.
Retention: enquiry emails are normally kept for 24 months from our last contact with you, unless you become a client.
3.2 Website use
This site does not store first-party analytics records or session recordings. Server logs may be created by our hosting provider as part of normal website delivery and security.
If you accept analytics cookies, we may load Google Analytics 4 to understand which pages are useful and how visitors find the site. If you reject analytics cookies, the Google tag is not loaded.
Lawful basis for Google Analytics: consent.
3.3 What you type into the search box
When you describe what you need in the search box on the home page, we store the words you typed, which services they matched and the date. We do this to understand what people are looking for, and particularly to see what is being asked for that we do not yet offer.
These records contain no name, email address, IP address, cookie or identifier of any kind, and cannot be linked back to you or to any other record we hold. They are deleted automatically after ninety days.
Please avoid typing personal details into the search box; it is only there to describe the work you need.
Lawful basis: legitimate interests — understanding demand for our services, using records that cannot identify anyone.
3.4 If you become a client
We process contact details, correspondence, contractual documents and billing information for the duration of our engagement.
Lawful basis: Article 6(1)(b) - performance of a contract; and Article 6(1)(c) - legal obligation, for tax and accounting records.
Retention: 7 years after the end of the financial year in which our engagement ends, to meet HMRC and Companies Act record-keeping requirements.
3.5 Marketing
We only send marketing email to people who have specifically asked for it, or to business contacts about services closely related to something they have already enquired about. Every message has an unsubscribe route.
Lawful basis: consent under regulation 22 PECR, or legitimate interest for existing business contacts where the soft opt-in applies.
Where you opt in through the systems questionnaire, we retain the marketing subscription until you withdraw consent or ask us to delete it. We may keep the minimum suppression record needed to ensure we honour an unsubscribe request.
4. Cookies
We use strictly necessary cookies for consent preferences and form protection. Optional analytics cookies are only used with your consent. The full list is in our Cookie Policy. You can change or withdraw your choices at any time from the "Cookie settings" link in the footer.
5. Who we share data with
We use a small number of processors who handle data on our behalf and under contract:
| Provider | What they do | Where |
|---|---|---|
| Vercel Inc. | Website hosting and content delivery | EU/UK region, with US parent |
| Email service provider | Sending and receiving email | Provider region depends on configured mail service |
| Brevo | Contact list management and marketing email for people who opt in | European Union |
| Google Ireland Ltd | Google Analytics - only if you consent | EU, with US transfers |
We do not sell personal data. We do not share it with third parties for their own marketing.
6. International transfers
Where a provider processes data outside the UK, we rely on appropriate transfer safeguards such as UK adequacy regulations or the International Data Transfer Addendum to the EU Standard Contractual Clauses.
7. How we protect data
The site is served over HTTPS. We keep the amount of personal data processed by the website deliberately small, and the public site has no editing backend to administer.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the ICO where required and tell you directly where the risk is high.
8. Your rights
Under UK GDPR you have the right to be informed, access your data, correct it, request deletion, restrict processing, receive portable data, object to legitimate-interest processing, object to direct marketing and withdraw consent where consent is the basis we rely on.
To exercise any of these, use our privacy request form or email privacy@systemshouse.digital. We will respond within one month. We may ask you to confirm your identity first.
9. Automated decision-making
We do not make decisions about you by automated means that produce legal or similarly significant effects. The systems questionnaire suggests relevant services based on the options you tick; that is a content recommendation, not a decision about you, and a person reviews every enquiry.
10. Complaints
Please raise any concern with us first at privacy@systemshouse.digital.
You also have the right to complain to the Information Commissioner's Office at any time: ico.org.uk/make-a-complaint.
11. Changes
We will update this policy when our processing changes. The version number and date at the top will change, and material changes to cookies will re-prompt you for consent.
Last updated 9 August 2026.
Make a privacy request