GOLDCRESTCODE LTD is the controller of personal information described in this notice. We use enquiry information to respond and, where appropriate, prepare or perform a contract. We do not sell personal information.
1. Who we are and how to contact us
GOLDCRESTCODE LTD (company number SC810777) is registered in Scotland at Belmont Road, Aberdeen, Scotland, AB25 3SR. For privacy questions or to exercise your rights, use our contact form and mark the message “Privacy request”, or write to the registered office.
2. Information we collect
- Enquiry information: name, email address, organisation, service interest and the content of your message.
- Client and supplier information: business contact details, role, correspondence, proposals, contracts, invoicing and payment records.
- Project information: requirements, feedback, account identifiers, access information and other data needed to deliver agreed services. Credentials should be shared only through an agreed secure method.
- Technical information: basic connection, device, security and server-log data such as IP address, browser type, request time and page requested, processed by our hosting and content-delivery providers.
- Compliance information: records needed to establish, exercise or defend legal claims, manage security incidents, prevent fraud or meet legal duties.
Please do not send special-category data, criminal-offence data or confidential client information through the general enquiry form unless we have agreed a suitable secure route and it is necessary.
3. Why we use information and our lawful bases
| Purpose | Typical information | Lawful basis |
|---|---|---|
| Respond to enquiries and prepare a proposal | Contact and enquiry details | Legitimate interests in responding to business enquiries; steps at your request before entering a contract |
| Deliver, support and administer services | Client, project, account and billing information | Performance of a contract; legitimate interests where the Client is an organisation |
| Maintain security, diagnose faults and prevent misuse | Technical logs and account activity | Legitimate interests in protecting our services, clients and systems; legal obligation where applicable |
| Manage finance, tax, company records and disputes | Contracts, invoices, payments and correspondence | Legal obligation; legitimate interests in running and protecting our business |
| Send marketing where permitted | Business contact and preference information | Consent where required; otherwise legitimate interests subject to PECR and your right to object |
Where we rely on legitimate interests, we consider the necessity and impact of the processing and do not use that basis where your interests or fundamental rights override ours. Where we rely on consent, you may withdraw it at any time without affecting earlier lawful processing.
4. Where information comes from
We obtain information directly from you, from your organisation or colleagues, from service providers used for a project, and from public professional or company sources where reasonably necessary for business-to-business due diligence or communication.
5. Who receives information
We disclose information only where reasonably necessary to personnel and professional advisers; hosting, form-processing, email, collaboration, accounting, payment, security and cloud providers; approved subcontractors; or public authorities and other parties where required by law or necessary to protect legal rights. Providers are required to protect information and use it only for authorised purposes.
This static website is designed for Netlify hosting and uses Netlify form handling. It also loads type and interface assets from Fontshare and jsDelivr. Those providers may receive basic connection data when your browser requests their resources. Their own notices govern processing for which they act independently.
6. International transfers
Some providers may process information outside the United Kingdom. Where restricted transfers apply, we use an adequacy regulation, the UK International Data Transfer Agreement or UK Addendum to approved contractual clauses, or another lawful safeguard, together with supplementary measures where appropriate.
7. Retention
We retain information only as long as needed for the relevant purpose, taking account of contract, tax, company-record, limitation, security and dispute requirements. As a working guide: unsuccessful general enquiries are normally reviewed for deletion after 12 months; project and contractual records are generally retained for up to 7 years after the relationship ends; security logs are retained for shorter operational periods unless needed to investigate an incident. Project-specific schedules may differ and will be documented where necessary.
8. Security
We use proportionate organisational and technical controls, including access restriction, secure development practices, managed hosting, backups where applicable and supplier review. No internet transmission or storage system can be guaranteed completely secure. If we become aware of a personal-data breach, we will assess and notify affected people and the regulator where required.
9. Your rights
Depending on the circumstances, UK data-protection law may give you rights to be informed; access your information; correct inaccurate information; erase information; restrict processing; receive portable information; object to processing based on legitimate interests or direct marketing; and obtain safeguards concerning solely automated decisions with legal or similarly significant effects.
Rights are not absolute and exemptions may apply. We may need to verify your identity. We normally respond within one month, subject to lawful extensions for complex or multiple requests.
10. Complaints
Please contact us first so we can try to resolve your concern. You may also complain to the Information Commissioner’s Office. Current contact details and guidance are available at ico.org.uk/make-a-complaint.
11. Children
Our digital-solutions website and services are directed to organisations and adult business contacts. We do not knowingly collect information from children through this site.
12. Changes
We may update this notice when our services, suppliers or legal obligations change. The effective and review dates above identify the current version. Material changes will be highlighted where reasonably practicable.