STHEER Logo
Legal Info

Privacy Policy

Effective Date: 10 July 2026

STHEER LTD ("STHEER", "we", "us", "our") is committed to protecting your privacy and handling your personal data transparently and lawfully.

This Privacy Policy explains what personal data we collect, why we collect it, how we use it, who we share it with, and what rights you have in relation to it.

We are the data controller in respect of the personal data described in this policy.


1. Who We Are

STHEER LTD Registered in England and Wales, company number 17241557.

Registered office: 217 A, Streatfield Road, Harrow HA3 9DA and Trading Office: Unit -2/21, Spring Field Road, Harrow HA1 1QF.

Contact for data protection matters: info@stheer.co.uk


2. Personal Data We Collect

Depending on how you interact with us, we may collect:

  • Contact and identity data: Name, job title or role, business name, email address, telephone number.
  • Enquiry and brief data: Information you provide when completing an enquiry form, intake questionnaire or project brief. This may include details about your business, objectives, budget ranges, marketing history and, where relevant to the services requested, regulatory identifiers such as a professional registration number.
  • Correspondence data: The content of emails, messages and calls between us.
  • Client and contractual data: Where you engage us, information necessary to deliver the services and administer the relationship, including billing contact details and account access credentials you choose to provide.
  • Technical data: IP address, browser type and version, device type, operating system, and information about your visit to our website. The extent of this collection depends on the cookies and analytics tools in use at the time (see Section 7).

We do not intentionally collect special category personal data (such as health, religious or political data) and ask that you do not submit it to us.


3. How We Collect It

  • Directly from you, when you complete a form, email us, call us, or engage our services.
  • Automatically, through cookies and similar technologies when you visit our website, where such technologies are in use and where you have consented to them.
  • From third parties, such as advertising and analytics platforms, where you have engaged us to manage advertising accounts on your behalf.

4. Why We Use It, and Our Lawful Basis

Under UK GDPR we must have a lawful basis for each purpose for which we process personal data. Ours are as follows:

PurposeLawful basis
Responding to your enquiry and assessing whether we can assistLegitimate interests; responding to a request you have made and assessing prospective business
Preparing proposals, quotations and strategy documentsLegitimate interests; pursuing prospective business you have invited
Delivering services under a signed agreementPerformance of a contract
Invoicing, payment and financial record-keepingPerformance of a contract; and legal obligation
Sending marketing communicationsConsent; or legitimate interests whereas permitted for existing business contacts
Website analytics and advertising cookiesConsent
Maintaining security of our systemsLegitimate interests; protecting our business and our clients
Complying with legal, accounting and regulatory obligationsLegal obligation

Where we rely on legitimate interests, we have assessed that our interests do not override your rights and freedoms. You may object to such processing at any time (see Section 9).


5. Who We Share It With

We do not sell your personal data.

We may share it with:

  • Service providers acting on our behalf, including website hosting, email and cloud storage providers, customer relationship management systems, and accounting software providers. These act as processors on our instructions.
  • Advertising and analytics platforms, where you have engaged us to deliver campaigns, or where such platforms operate on our own website with your consent.
  • Professional advisers, including accountants, insurers and legal advisers, where necessary.
  • Regulators, law enforcement or other authorities, where we are required to do so by law.
  • A purchaser or successor, in the event of a sale, merger or reorganisation of our business.

Where we engage processors, we put in place contractual terms requiring them to protect your data and to process it only on our instructions.


6. International Transfers

Some of the service providers and advertising platforms we use are located outside the United Kingdom, including in the United States.

Where personal data is transferred outside the UK, we ensure an appropriate safeguard is in place, such as an adequacy decision or the International Data Transfer Agreement or Addendum approved by the UK Government.

You may request further information about the safeguards applied by contacting us.


7. Cookies and Similar Technologies

Cookies are small files placed on your device when you visit a website.

Strictly necessary cookies are required for the website to function and do not require your consent.

Analytics and advertising cookies (including those used by Google Analytics and the Meta Pixel) are only placed on your device where you have given consent, which you may withdraw at any time. Where such technologies are in use, a consent banner will be presented on your first visit, and your preferences will be recorded.

At the Effective Date of this policy, STHEER does not operate analytics or advertising cookies on its website. This policy will be updated, and a consent mechanism introduced, before any such technology is deployed.

Disabling cookies through your browser settings does not, on its own, constitute withdrawal of consent for the purposes of UK law, and we do not rely on browser settings as a consent mechanism.


8. How Long We Keep It

We retain personal data only for as long as necessary for the purposes for which it was collected.

Our standard retention periods are:

  • Enquiries that do not result in an engagement: 12 months from last contact.
  • Client records and correspondence: 6 years from the end of the engagement, reflecting the statutory limitation period for contractual claims.
  • Financial and accounting records: 6 years from the end of the relevant financial year, as required by law.
  • Marketing consent records: until consent is withdrawn, plus 2 years to evidence the withdrawal.

Where data is no longer required, we securely delete or anonymise it.


9. Your Rights

Under UK GDPR you have the right to:

  • Access: obtain a copy of the personal data we hold about you.
  • Rectification: have inaccurate or incomplete data corrected.
  • Erasure: request deletion of your data in certain circumstances.
  • Restriction: request that we limit how we use your data in certain circumstances.
  • Portability: receive your data in a structured, commonly used, machine-readable format.
  • Object: object to processing carried out on the basis of legitimate interests, and to direct marketing at any time.
  • Withdraw consent: where we rely on consent, withdraw it at any time. This does not affect the lawfulness of processing carried out before withdrawal.

To exercise any of these rights, contact us at info@stheer.co.uk. We will respond within one month. There is no fee, although we may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive.

We may ask you to verify your identity before acting on a request.


10. Complaints

If you have a concern about how we handle your personal data, please contact us first so that we can address it.

You also have the right to lodge a complaint with the Information Commissioner's Office, the UK supervisory authority for data protection:

Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
ico.org.uk


11. Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration or disclosure. These include encrypted connections, access controls, and restricting access to personal data to those who need it.

No method of transmission over the internet is entirely secure. While we take reasonable steps to protect your data, we cannot guarantee absolute security.


12. Children

Our website and services are directed at businesses and are not intended for individuals under 18. We do not knowingly collect personal data from children.


13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, our technology, or the law. The revised version will be posted on this page with an updated Effective Date.

Where changes are material, we will take reasonable steps to notify you.


14. Contact

STHEER LTD
Email: info@stheer.co.uk