Privacy Policy
This notice explains how Cahoot Consulting Ltd processes personal data under UK GDPR and the Data Protection Act 2018. Some placeholder items (cookie table, live sub-processor list) are completed at go-live.
1. Who we are
Cahoot Consulting Limited (“Cahoot”, “we”, “us”, “our”) provides ISO consultancy and supplier due diligence / assurance reporting under the Hume brand.
| Legal entity | Cahoot Consulting Limited |
| Company number | 08976555 (England and Wales) |
| Registered office | 54 Frensham Close, Southall, Middlesex, UB1 2YG, United Kingdom |
| VAT number | GB 183 6201 17 |
| ICO registration | ZA705720 (public register) |
| Data protection contact | Catherine Furlong — cath@cahootconsulting.com · 07506 144029 |
We are the data controller for personal data we collect about clients and prospective clients (people who enquire, complete intake, pay, or receive reports).
For personal data about supplier personnel — whether we collect it from public sources (OSINT) or it appears in a redacted agreement you upload — we act as your data processor on your instructions to prepare your report (see Section 8); you remain the controller of that data. Where we determine purposes independently (e.g. our own business records), we are controller.
2. Scope of this policy
This policy explains how we collect, use, store, and share personal data when you:
- visit our website or intake forms;
- purchase or receive a Hume report or a Hume Watch subscription;
- communicate with us by email or otherwise.
It does not cover third-party websites we link to (Companies House, supplier sites, Stripe checkout, etc.).
3. What personal data we process
3.1 Data you give us (clients)
| Category | Examples | When |
|---|---|---|
| Contact details | Name, business email, telephone (if provided) | Intake, enquiry, invoicing |
| Callback request | Name, company name, telephone number | Website chatbot — only when you ask us to call you back |
| Organisation inference | Employer name inferred from email domain | Intake |
| Procurement context | Free-text description of what you are buying from the supplier | Intake |
| Payment-related data | Billing name, email, transaction references | Stripe checkout — card details handled by Stripe, not stored by us |
| Uploaded documents (PII pack and above) | Redacted executed supplier agreement, DPA, or related commercial documents | Only where a pack requires a document upload |
We ask you not to submit personal data or commercially sensitive information in intake fields or uploads except where the service explicitly requires it (PII pack and above: redacted agreement only). See Section 6.
3.2 Data you give us about suppliers (not your personal data)
To run checks we process supplier identifiers you provide:
- legal entity name;
- Companies House number (UK);
- primary domain / website;
- (T1+) redacted contractual documents.
These may contain third parties’ personal data (e.g. signatories, directors named in agreements). You are responsible for ensuring you have a lawful basis and any required consents before sharing such documents with us.
3.3 Data we collect automatically
| Category | Examples | Purpose |
|---|---|---|
| Technical / usage | IP address, browser type, device, pages viewed, timestamps | Security, service operation, analytics (if enabled) |
| Form metadata | Submission time, form version, service tier selected | Order fulfilment, audit trail |
We use no third-party analytics on our intake forms at present. If this changes, we will update this policy and cookie notice.
3.4 Data we obtain from public sources (OSINT)
Our reports are built from publicly available sources (Companies House, UK government registers, supplier public legal pages, DNS/technical records, accreditation databases, sanctions lists, etc.). That evidence may include personal data about supplier personnel already published by law (e.g. Persons with Significant Control). We do not use AI to determine findings; evidence is collected by automated and manual OSINT rules.
3.5 What we process about you, and how — by tier
At every tier (the entry report and above):
- You can keep it non-identifying. You may ask us to return your report to a generic, role-based email address (for example
info@yourcompany.org). If you do, we process no personal data identifying an individual — only your organisation (inferred from the email domain) and the procurement context described below. - If you give us your name — whether in your email address or separately — we process it only to: (a) return your report and provide related after-sales service; and (b) send you marketing about Hume. You may opt out of marketing at any time, and opting out does not affect delivery of your report.
- The one commercially sensitive fact. The only potentially commercially sensitive information you give us is that your organisation is considering procuring a particular product or service from a particular supplier. We process that information solely to prepare your report and to maintain the audit and accounting records we are required to keep (see Section 7). We do not disclose it to the supplier, and we do not share it except as set out in Section 5.
At the higher packs (PII and above), where you upload a supplier agreement for review:
- We parse the document, extract only the information relevant to the checks you have ordered, and redact everything else.
- The uploaded document is retained for one month and then deleted (see Section 7). Relevant extracted information is kept with your report under Section 7.
- You remain the controller for any third-party personal data in the document (Section 8); please redact any personal data we do not need before uploading.
4. How we use personal data (lawful bases)
| Purpose | Data | Lawful basis (UK GDPR) |
|---|---|---|
| Provide the report you ordered | Contact, supplier identifiers, uploads, payment refs | Contract (Art. 6(1)(b)) |
| Verify identity, prevent abuse, invoicing | Contact, payment refs | Legitimate interests (Art. 6(1)(f)) — balanced against your rights |
| Operator notifications (manual review steps) | Supplier name, CH number, domain | Contract / Legitimate interests |
| Legal and tax records | Contact, payment | Legal obligation (Art. 6(1)(c)) |
| Improve service quality (aggregated) | Usage patterns | Legitimate interests |
| Marketing about Hume (existing clients) | Legitimate interests or Consent where required by PECR — opt-out always available |
We do not sell personal data. We do not use client data to train AI models.
5. Who we share data with (sub-processors and recipients)
Challenge to “contact details only”: In operating Hume we share data beyond client contact details. The table below reflects the current and planned stack (see Technology-Stack-and-Platform.md). Update before go-live.
| Recipient | Role | Data shared | Location |
|---|---|---|---|
| Google Cloud (confirm contracting entity, e.g. Google Cloud EMEA Ltd) | Application hosting (Cloud Run) — serves the self-hosted intake form and runs the checks | All data processed by the intake application — intake fields, supplier identifiers, technical logs | UK (London / europe-west2) |
| Stripe Payments UK Ltd | Payment processor | Name, email, billing, payment metadata | UK / EU / US (SCCs) |
| Zapier Inc. (if used) | Workflow automation | Intake payload, file metadata | US — confirm DPA |
| Dropbox (or OneDrive) | Secure file storage | Uploaded contracts, reports, evidence | US/EU — confirm DPA |
| Email provider [Gmail / Postmark / SendGrid] | Transactional email | Contact, order details | Confirm region |
| ntfy.sh (if enabled) | Push notifications to operator | Supplier name, CH, domain, run status | EU (self-hosted option available) |
| Companies House | Public API lookup | CH number, company name | UK |
| IAF CertSearch | Certificate verification API | Supplier name, country, CH number | Confirm with IAF |
| Professional advisers | Legal, accounting, insurance | As needed | UK |
| Regulators / courts | If required by law | As required | — |
Public OSINT queries: When we query government registers and supplier websites, we transmit supplier identifiers in HTTP/API requests. Those third parties process data under their own policies. We do not “share” your contact details with those sources except where a register query is traceable to our IP address.
A live sub-processor list will be published at [URL] and updated when we add or change providers.
6. Your obligations — do not send us what we do not need
Standard and Commercial packs: We only need supplier identifiers and your business contact details. Do not include:
- personal data about your staff, customers, or patients in free-text fields;
- unredacted commercial terms, pricing, or trade secrets;
- special category data (health, ethnicity, etc.) or criminal offence data.
PII pack and above: Upload only a redacted executed agreement. Redact at minimum: personal names and direct contact details of individuals (except where necessary to show party identity), customer/patient/employee lists, pricing, trade secrets, and security configurations.
If you send us personal or sensitive data by mistake: Tell us promptly at cath@cahootconsulting.com. We will delete it as soon as reasonably practicable unless we must retain it for legal reasons, and we will tell you what we did.
7. Retention
| Data | Typical retention |
|---|---|
| Paid order records (intake + order details, once payment is taken) | 7 years (tax / legal) |
| Unpaid, abandoned orders (checkout started but never paid) | Deleted after 7 days. With no payment there is no tax or legal basis to keep the requester email, supplier identity or terms-acceptance record, so it is automatically removed (D-066) |
| Reports and evidence packs | 90 days from delivery on client download link; up to 24 months in secure archive unless you request earlier deletion |
| Uploaded contracts (PII pack and above) | Retained for one month, then deleted (§3.5) unless you request earlier deletion or we agree extended retention in writing |
| Payment records | Per Stripe / HMRC requirements (6–7 years) |
| Marketing suppression list | Until you object or we cease trading |
Retention may be longer if required for dispute, regulatory, or insurance purposes.
8. Processor role (supplier personal data)
Where you provide supplier identifiers or redacted agreements so we can deliver your report, you are typically the data controller for any personal data about supplier personnel contained in that material, and we act as your processor under UK GDPR Article 28.
A Data Processing Agreement (DPA) is available on request for the PII pack and above, and enterprise clients. Standard and Commercial packs: processing is limited to public OSINT and incidental personal data in public filings; many clients rely on legitimate interests / procurement necessity rather than a full DPA — your DPO should confirm.
We process supplier-related data only on your documented instructions (the order, intake, and these terms), unless required by law.
9. International transfers
Your personal data is hosted and processed primarily in the United Kingdom. Our intake application and its data are hosted on Google Cloud Platform in Google's London region (europe-west2), and Cahoot is a UK-established data controller regulated by the ICO. Your relationship with us is governed by UK data protection law (UK GDPR and the Data Protection Act 2018).
Some processing takes place outside the UK:
report, our assessor accesses and processes personal data from Spain. This is a transfer of personal data from the UK to an EEA country. The UK Government has determined that the EEA provides an adequate level of protection (UK adequacy regulations), so this transfer is made on the basis of that adequacy finding and requires no additional safeguards.
outside the UK/EEA. Where they do, we rely on UK adequacy regulations, the UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU SCCs, or the provider's Binding Corporate Rules, as appropriate.
- Our assessor operates from Spain (EEA). To prepare and review your
- Certain sub-processors (see Section 5) may process limited personal data
Copies of transfer safeguards are available on request.
10. Security
We apply appropriate technical and organisational measures, including:
- access controls and least-privilege for operator accounts;
- encryption in transit (HTTPS/TLS);
- password-protected or tokenised report delivery;
- secure storage for uploaded contracts;
- no storage of card details (Stripe handles payments).
No method of transmission is 100% secure. We cannot guarantee absolute security.
11. Your rights
If we process your personal data as controller, you have rights under UK GDPR:
- Access — copy of your personal data;
- Rectification — correct inaccurate data;
- Erasure — in certain circumstances;
- Restriction — limit processing in certain circumstances;
- Object — to processing based on legitimate interests (including direct marketing);
- Data portability — where processing is by automated means under contract/consent;
- Withdraw consent — where processing is based on consent;
- Complain to the ICO: https://ico.org.uk/make-a-complaint/
To exercise rights: cath@cahootconsulting.com. We respond within one month (extendable for complex requests).
12. Cookies and similar technologies
[Complete before publication]
| Cookie | Purpose | Duration |
|---|---|---|
| [Stripe session] | Checkout | Session |
| [Form host] | Form function | Session |
| (none at present) | — | — |
We do not use non-essential cookies without consent where PECR requires it. Stripe and form-host cookies may apply during checkout / submission.
13. Children
Our services are for business users. We do not knowingly collect data from anyone under 18.
14. Changes
We may update this policy. Material changes will be posted on our website with a new “last updated” date. Continued use after changes constitutes notice; for material reductions in your rights we will seek renewed consent where required.
Last updated: 22 June 2026
Document control
| Version | Date | Author | Notes |
|---|---|---|---|
| DRAFT v1 | 22 Jun 2026 | Cahoot / AI draft | Initial draft |
| DRAFT v1.1 | 22 Jun 2026 | Cahoot | Company details added |
| DRAFT v1.2 | 22 Jun 2026 | Cahoot | ICO registration ZA705720 |
| DRAFT v1.3 | 20 Jul 2026 | Cahoot | §3.1 callback request (name, company, telephone) captured via website chatbot |
| IN REVIEW v1.4 | 26 Jul 2026 | Cahoot / AI | Dead-claim clearance + DP pass: T0/T1/T2 tier names → pack ladder (Standard/Commercial/PII/Critical/Hume Watch) throughout (D-018/D-034); §9 rewritten for UK processing + UK→Spain(EEA) adequacy transfer, §5 adds Google Cloud (London) sub-processor and drops the retired Tally row (D-039/D-048); §9 assessor "prepares and reviews" (not signs) the report (D-063); §1 controller/processor split aligned (D-064); status/solicitor-gate note updated to D-022 |
| APPROVED v1.4 | 27 Jul 2026 | Cath | Promoted to APPROVED, effective 27 Jul 2026. Dead-claims gate green; §9 transfer + §1 roles accepted; external DP-adviser review of §9 waived by Cath |
| APPROVED v1.5 | 28 Jul 2026 | Cath | §7 retention: split "intake and order records" into paid (7 years, tax/legal) vs unpaid abandoned orders (deleted after 7 days — no payment, no lawful basis). Propagates D-066. Dead-claims gate green |