Privacy Policy
Effective Date: 1 January 2024
We are committed to the principles of transparency, purpose limitation, and data minimization in accordance with the UK Data Protection Act 2018 and the UK General Data Protection Regulation.
1. Data Controller Identity
For the purposes of the General Data Protection Regulation and relevant UK data protection laws, the responsible entity is SterlingIQX, located at Canary Wharf, London, United Kingdom. Direct inquiries regarding data handling can be directed to [email protected].
2. Types of Data We Process
We collect information strictly required to fulfill service requests and optimize platform performance. This includes Identity Data such as your name and professional title, Contact Data including email addresses and telephone numbers provided via inquiry forms, and Technical Data comprising IP addresses, browser identifiers, and interaction logs for platform security and stability assessment.
3. Legal Bases for Processing
We process your data under the following legal frameworks: Contractual Necessity, required to fulfill your requests for consultancy services; Legitimate Interests, necessary to ensure website security and improve our operational offerings; and Consent, applied exclusively for the use of non-essential cookies and marketing communications where explicitly requested. We implement rigorous technical and organizational measures to prevent accidental loss or unauthorized access to your information, employing encryption standards aligned with current industry best practices.
4. Data Sharing and Transfers
Data may only be shared with trusted service providers acting as data processors under strict confidentiality agreements, exclusively to facilitate our consulting operations and platform maintenance. We ensure all cross-border transfers comply with UK transfer impact assessments and standard contractual clauses where applicable.
5. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy, or as required by statutory obligations. Upon expiry of retention periods, data is securely anonymized or permanently deleted from all active and backup systems.
6. Security Protocols
Our infrastructure utilizes multi-layered encryption, role-based access controls, and continuous vulnerability scanning to safeguard your information against evolving cyber threats. Regular penetration testing ensures our defensive postures meet enterprise-grade security benchmarks.
7. Your Rights Under Data Protection Law
Under applicable regulations, you possess the right to request access to your personal data, demand correction of inaccurate information, request deletion of your data, restrict processing activities, and data portability. You also retain the right to lodge a complaint with a supervisory authority, such as the Information Commissioner's Office in the United Kingdom. Our compliance officers are available to assist with all requests promptly and in full accordance with statutory deadlines.
8. Policy Updates
We reserve the right to amend this Privacy Policy to reflect legislative changes or operational shifts. Material updates will be communicated via prominent website notices. Continued use of our platforms following any modification constitutes acceptance of the revised terms.