Legal

Privacy Policy

Effective 28 July 2026
This notice explains how Cahoot Consulting Ltd processes personal data under UK GDPR and the Data Protection Act 2018. Some placeholder items (cookie table, live sub-processor list) are completed at go-live.

1. Who we are

Cahoot Consulting Limited (“Cahoot”, “we”, “us”, “our”) provides ISO consultancy and supplier due diligence / assurance reporting under the Hume brand.

Legal entityCahoot Consulting Limited
Company number08976555 (England and Wales)
Registered office54 Frensham Close, Southall, Middlesex, UB1 2YG, United Kingdom
VAT numberGB 183 6201 17
ICO registrationZA705720 (public register)
Data protection contactCatherine Furlong — cath@cahootconsulting.com · 07506 144029

We are the data controller for personal data we collect about clients and prospective clients (people who enquire, complete intake, pay, or receive reports).

For personal data about supplier personnel — whether we collect it from public sources (OSINT) or it appears in a redacted agreement you upload — we act as your data processor on your instructions to prepare your report (see Section 8); you remain the controller of that data. Where we determine purposes independently (e.g. our own business records), we are controller.


2. Scope of this policy

This policy explains how we collect, use, store, and share personal data when you:

It does not cover third-party websites we link to (Companies House, supplier sites, Stripe checkout, etc.).


3. What personal data we process

3.1 Data you give us (clients)

CategoryExamplesWhen
Contact detailsName, business email, telephone (if provided)Intake, enquiry, invoicing
Callback requestName, company name, telephone numberWebsite chatbot — only when you ask us to call you back
Organisation inferenceEmployer name inferred from email domainIntake
Procurement contextFree-text description of what you are buying from the supplierIntake
Payment-related dataBilling name, email, transaction referencesStripe checkout — card details handled by Stripe, not stored by us
Uploaded documents (PII pack and above)Redacted executed supplier agreement, DPA, or related commercial documentsOnly where a pack requires a document upload

We ask you not to submit personal data or commercially sensitive information in intake fields or uploads except where the service explicitly requires it (PII pack and above: redacted agreement only). See Section 6.

3.2 Data you give us about suppliers (not your personal data)

To run checks we process supplier identifiers you provide:

These may contain third parties’ personal data (e.g. signatories, directors named in agreements). You are responsible for ensuring you have a lawful basis and any required consents before sharing such documents with us.

3.3 Data we collect automatically

CategoryExamplesPurpose
Technical / usageIP address, browser type, device, pages viewed, timestampsSecurity, service operation, analytics (if enabled)
Form metadataSubmission time, form version, service tier selectedOrder fulfilment, audit trail

We use no third-party analytics on our intake forms at present. If this changes, we will update this policy and cookie notice.

3.4 Data we obtain from public sources (OSINT)

Our reports are built from publicly available sources (Companies House, UK government registers, supplier public legal pages, DNS/technical records, accreditation databases, sanctions lists, etc.). That evidence may include personal data about supplier personnel already published by law (e.g. Persons with Significant Control). We do not use AI to determine findings; evidence is collected by automated and manual OSINT rules.

3.5 What we process about you, and how — by tier

At every tier (the entry report and above):

At the higher packs (PII and above), where you upload a supplier agreement for review:


4. How we use personal data (lawful bases)

PurposeDataLawful basis (UK GDPR)
Provide the report you orderedContact, supplier identifiers, uploads, payment refsContract (Art. 6(1)(b))
Verify identity, prevent abuse, invoicingContact, payment refsLegitimate interests (Art. 6(1)(f)) — balanced against your rights
Operator notifications (manual review steps)Supplier name, CH number, domainContract / Legitimate interests
Legal and tax recordsContact, paymentLegal obligation (Art. 6(1)(c))
Improve service quality (aggregated)Usage patternsLegitimate interests
Marketing about Hume (existing clients)EmailLegitimate interests or Consent where required by PECR — opt-out always available

We do not sell personal data. We do not use client data to train AI models.


5. Who we share data with (sub-processors and recipients)

Challenge to “contact details only”: In operating Hume we share data beyond client contact details. The table below reflects the current and planned stack (see Technology-Stack-and-Platform.md). Update before go-live.

RecipientRoleData sharedLocation
Google Cloud (confirm contracting entity, e.g. Google Cloud EMEA Ltd)Application hosting (Cloud Run) — serves the self-hosted intake form and runs the checksAll data processed by the intake application — intake fields, supplier identifiers, technical logsUK (London / europe-west2)
Stripe Payments UK LtdPayment processorName, email, billing, payment metadataUK / EU / US (SCCs)
Zapier Inc. (if used)Workflow automationIntake payload, file metadataUS — confirm DPA
Dropbox (or OneDrive)Secure file storageUploaded contracts, reports, evidenceUS/EU — confirm DPA
Email provider [Gmail / Postmark / SendGrid]Transactional emailContact, order detailsConfirm region
ntfy.sh (if enabled)Push notifications to operatorSupplier name, CH, domain, run statusEU (self-hosted option available)
Companies HousePublic API lookupCH number, company nameUK
IAF CertSearchCertificate verification APISupplier name, country, CH numberConfirm with IAF
Professional advisersLegal, accounting, insuranceAs neededUK
Regulators / courtsIf required by lawAs required

Public OSINT queries: When we query government registers and supplier websites, we transmit supplier identifiers in HTTP/API requests. Those third parties process data under their own policies. We do not “share” your contact details with those sources except where a register query is traceable to our IP address.

A live sub-processor list will be published at [URL] and updated when we add or change providers.


6. Your obligations — do not send us what we do not need

Standard and Commercial packs: We only need supplier identifiers and your business contact details. Do not include:

PII pack and above: Upload only a redacted executed agreement. Redact at minimum: personal names and direct contact details of individuals (except where necessary to show party identity), customer/patient/employee lists, pricing, trade secrets, and security configurations.

If you send us personal or sensitive data by mistake: Tell us promptly at cath@cahootconsulting.com. We will delete it as soon as reasonably practicable unless we must retain it for legal reasons, and we will tell you what we did.


7. Retention

DataTypical retention
Paid order records (intake + order details, once payment is taken)7 years (tax / legal)
Unpaid, abandoned orders (checkout started but never paid)Deleted after 7 days. With no payment there is no tax or legal basis to keep the requester email, supplier identity or terms-acceptance record, so it is automatically removed (D-066)
Reports and evidence packs90 days from delivery on client download link; up to 24 months in secure archive unless you request earlier deletion
Uploaded contracts (PII pack and above)Retained for one month, then deleted (§3.5) unless you request earlier deletion or we agree extended retention in writing
Payment recordsPer Stripe / HMRC requirements (6–7 years)
Marketing suppression listUntil you object or we cease trading

Retention may be longer if required for dispute, regulatory, or insurance purposes.


8. Processor role (supplier personal data)

Where you provide supplier identifiers or redacted agreements so we can deliver your report, you are typically the data controller for any personal data about supplier personnel contained in that material, and we act as your processor under UK GDPR Article 28.

A Data Processing Agreement (DPA) is available on request for the PII pack and above, and enterprise clients. Standard and Commercial packs: processing is limited to public OSINT and incidental personal data in public filings; many clients rely on legitimate interests / procurement necessity rather than a full DPA — your DPO should confirm.

We process supplier-related data only on your documented instructions (the order, intake, and these terms), unless required by law.


9. International transfers

Your personal data is hosted and processed primarily in the United Kingdom. Our intake application and its data are hosted on Google Cloud Platform in Google's London region (europe-west2), and Cahoot is a UK-established data controller regulated by the ICO. Your relationship with us is governed by UK data protection law (UK GDPR and the Data Protection Act 2018).

Some processing takes place outside the UK:

report, our assessor accesses and processes personal data from Spain. This is a transfer of personal data from the UK to an EEA country. The UK Government has determined that the EEA provides an adequate level of protection (UK adequacy regulations), so this transfer is made on the basis of that adequacy finding and requires no additional safeguards.

outside the UK/EEA. Where they do, we rely on UK adequacy regulations, the UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU SCCs, or the provider's Binding Corporate Rules, as appropriate.

Copies of transfer safeguards are available on request.


10. Security

We apply appropriate technical and organisational measures, including:

No method of transmission is 100% secure. We cannot guarantee absolute security.


11. Your rights

If we process your personal data as controller, you have rights under UK GDPR:

To exercise rights: cath@cahootconsulting.com. We respond within one month (extendable for complex requests).


12. Cookies and similar technologies

[Complete before publication]

CookiePurposeDuration
[Stripe session]CheckoutSession
[Form host]Form functionSession
(none at present)

We do not use non-essential cookies without consent where PECR requires it. Stripe and form-host cookies may apply during checkout / submission.


13. Children

Our services are for business users. We do not knowingly collect data from anyone under 18.


14. Changes

We may update this policy. Material changes will be posted on our website with a new “last updated” date. Continued use after changes constitutes notice; for material reductions in your rights we will seek renewed consent where required.

Last updated: 22 June 2026


Document control

VersionDateAuthorNotes
DRAFT v122 Jun 2026Cahoot / AI draftInitial draft
DRAFT v1.122 Jun 2026CahootCompany details added
DRAFT v1.222 Jun 2026CahootICO registration ZA705720
DRAFT v1.320 Jul 2026Cahoot§3.1 callback request (name, company, telephone) captured via website chatbot
IN REVIEW v1.426 Jul 2026Cahoot / AIDead-claim clearance + DP pass: T0/T1/T2 tier names → pack ladder (Standard/Commercial/PII/Critical/Hume Watch) throughout (D-018/D-034); §9 rewritten for UK processing + UK→Spain(EEA) adequacy transfer, §5 adds Google Cloud (London) sub-processor and drops the retired Tally row (D-039/D-048); §9 assessor "prepares and reviews" (not signs) the report (D-063); §1 controller/processor split aligned (D-064); status/solicitor-gate note updated to D-022
APPROVED v1.427 Jul 2026CathPromoted to APPROVED, effective 27 Jul 2026. Dead-claims gate green; §9 transfer + §1 roles accepted; external DP-adviser review of §9 waived by Cath
APPROVED v1.528 Jul 2026Cath§7 retention: split "intake and order records" into paid (7 years, tax/legal) vs unpaid abandoned orders (deleted after 7 days — no payment, no lawful basis). Propagates D-066. Dead-claims gate green