Privacy, without the drama
NAKATOMI CONSULTING LIMITED is deliberately careful about personal information.
Our website is designed to collect as little personal information as reasonably practical. We don't sell personal data, build advertising profiles about visitors, or use behavioural tracking simply because we can.
Where we do need personal information, whether to run the website, answer an enquiry, arrange a meeting or provide consultancy services, we use it only for a clear business purpose and keep it only for as long as reasonably necessary.
This notice explains what that means in practice.
1. Who we are
NAKATOMI CONSULTING LIMITED
Registered in England and Wales
Company number: 15996610
Registered office:
86-90 Paul Street
London
EC2A 4NE
United Kingdom
Email: info@nakatomi.consulting
Telephone: 020 3488 8495
For the purposes of UK data protection law, NAKATOMI CONSULTING LIMITED is the data controller where we decide why and how personal information is processed.
You can contact us about privacy or the use of your personal information at:
2. This website
This is the public website of NAKATOMI CONSULTING LIMITED.
It has intentionally been designed to minimise the collection of personal information.
The website does not currently provide:
- visitor accounts
- an on-site contact form
- advertising
- behavioural profiling
- cross-site tracking
- marketing trackers
You do not need to provide your name, email address, telephone number or other contact information simply to browse the website.
Some technical information is necessarily processed when your browser connects to the site. This is explained below.
3. Information processed when you visit the website
Normal internet infrastructure generates technical information when a website is requested.
Depending on the systems involved, this may include:
- IP address
- browser type and version
- device and operating system information
- requested pages or URLs
- date and time of requests
- referring page or website
- network and connection information
- security and diagnostic information
We use this information where necessary to:
- deliver the website
- maintain its security
- protect against malicious or abusive traffic
- diagnose faults
- investigate technical problems
- maintain the reliability and performance of the service
Our lawful basis is our legitimate interests in operating a secure, reliable and properly functioning business website and protecting our systems from misuse and cyber threats.
We do not use website technical logs to create advertising profiles about individual visitors.
4. Hosting and Cloudflare
The website is hosted and delivered using services provided by Cloudflare.
Cloudflare provides services including website delivery, network infrastructure, DNS, security and protection against malicious traffic.
As part of providing those services, Cloudflare may process technical information such as:
- IP addresses
- HTTP requests
- browser and device information
- requested URLs
- timestamps
- network and security information
Depending on the particular service and information involved, Cloudflare may process information on our behalf or for purposes it determines itself.
Cloudflare maintains its own privacy documentation describing how it handles personal information.
Because Cloudflare operates a global network, information may be processed outside the United Kingdom. Where a restricted international transfer of personal information takes place, the transfer must be covered by an applicable legal mechanism or safeguard under UK data protection law.
5. Cookies and similar technologies
We do not currently use cookies or similar technologies for:
- behavioural advertising
- cross-site tracking
- marketing profiling
- visitor fingerprinting
Technical infrastructure used to deliver and secure the website may use cookies or similar technologies where they are strictly necessary for the operation or security of the service.
Strictly necessary technologies do not generally require consent, although information about their use should still be provided.
If we introduce non-essential cookies, analytics, marketing technologies or other tracking mechanisms in future, we will review the website before deployment and introduce consent controls where required.
This notice will also be updated to explain the change.
6. Website analytics
We do not currently use behavioural analytics or advertising analytics to profile visitors to this website.
We may introduce privacy-focused website measurement in future so that we can understand basic matters such as website usage and performance.
Before doing so, we will assess:
- what information is collected
- whether personal information is involved
- whether cookies or similar technologies are used
- the lawful basis for processing
- whether consent is required
- how long information is retained
- whether information is transferred outside the UK
Where consent is legally required, the relevant technology will not be activated for a visitor before that consent is obtained.
7. Contacting us
Although there is no contact form on the website, you can contact us directly by email or telephone.
If you do, we may receive information including:
- your name
- your email address
- your telephone number
- your organisation and job title
- the contents of your message
- information you choose to give us
- correspondence and subsequent communications relating to your enquiry
We use that information to:
- respond to you
- understand your enquiry
- provide information about our services
- discuss potential work
- maintain appropriate records of our correspondence
- manage an existing business relationship
The lawful basis will depend on why you contact us.
It will normally be one or more of the following:
Legitimate interests
Where we are dealing with normal business correspondence, enquiries, supplier relationships or professional contacts.
Contract
Where processing is necessary to perform a contract with you or to take steps at your request before entering into one.
Legal obligation
Where we need to process or retain information because the law requires us to do so.
8. Booking a meeting
The website provides access to our Fantastical scheduling service so that you can arrange a meeting with us.
When you follow the booking link, you leave the Nakatomi Consulting website and interact with Fantastical's service.
Information processed through the booking process may include:
- your name
- email address
- meeting date and time
- meeting title or subject
- information you choose to provide in connection with the meeting
Fantastical processes information through its own systems and under its own privacy terms.
Information required to arrange the meeting may then be made available to NAKATOMI CONSULTING LIMITED.
We use that information to arrange and manage the meeting and any resulting business relationship.
Our lawful basis will normally be:
- taking steps at your request before entering into a contract
- performing an existing contract, where applicable
- our legitimate interest in managing professional meetings and business enquiries
9. LinkedIn and other external websites
The website contains links to third-party websites and services, including LinkedIn and Fantastical.
When you follow an external link, you leave our website.
The organisation operating the destination website determines how information is processed through its own service and its own privacy notice will apply.
We do not control the privacy practices of third-party websites merely because we provide a link to them.
10. Prospective clients and clients
If you enquire about our consultancy services or become a client, we will normally need to process more information than is collected through ordinary website use.
This may include:
- names
- business contact details
- job titles
- employer or organisation details
- correspondence
- meeting notes
- proposals and quotations
- contracts and statements of work
- project information
- service and support records
- technical information supplied to us
- invoices and payment information
- records necessary to manage the commercial relationship
We use this information to:
- understand requirements
- prepare proposals and quotations
- agree work
- deliver consultancy and technical services
- communicate with clients
- manage projects
- provide support
- manage changes and service requests
- invoice for services
- maintain contractual records
- resolve disputes
- establish, exercise or defend legal rights
Our lawful basis will usually be contract, legitimate interests, legal obligation, or a combination of these depending on the circumstances.
Where our client is a company rather than an individual, legitimate interests will often apply to the processing of the business contact information of people acting on that organisation's behalf.
11. Information we process while providing consultancy services
As an IT consultancy, our work can involve access to systems, networks, cloud platforms, configuration information, logs, accounts or other technical environments belonging to clients.
Those systems may contain personal information.
Where we process personal information solely on a client's instructions as part of delivering services, the client will normally remain the data controller and NAKATOMI CONSULTING LIMITED will act as a data processor.
The exact responsibilities will depend on the particular engagement and any applicable contractual or data-processing terms.
We do not acquire ownership of client information merely because access to it is necessary to perform our work.
We expect access to client systems and information to be limited to what is reasonably necessary to provide the agreed services.
12. Suppliers, professional advisers and other business contacts
We may also process ordinary business contact information relating to:
- suppliers
- contractors
- professional advisers
- service providers
- insurers
- accountants
- legal advisers
- technology vendors
- other professional contacts
This may include names, work contact details, job titles, correspondence, contractual information and financial records.
We process this information where necessary to operate the company, obtain professional services, purchase goods or services, manage contractual relationships and maintain appropriate business records.
Our lawful basis will normally be contract, legitimate interests or legal obligation, depending on the circumstances.
13. Where personal information comes from
Most personal information we process is provided directly by the person concerned or by the organisation they represent.
We may also receive business information from:
- clients
- suppliers
- professional advisers
- publicly available company information
- professional networking services
- organisations introducing or referring a business contact
- technical systems we are authorised to administer or review
Where we receive personal information from someone other than the individual concerned, we use it only where there is an appropriate reason and lawful basis for doing so.
14. Who we may share information with
We do not sell or rent personal information.
Where reasonably necessary, information may be shared with organisations that help us operate the business or provide services.
These may include:
- website and cloud infrastructure providers
- email and communications providers
- scheduling and collaboration platforms
- IT and security service providers
- banks and payment providers
- accountants
- insurers
- legal advisers
- other professional advisers
- subcontractors engaged to assist with an agreed service
- government or regulatory authorities where legally required
Where another organisation processes personal information on our behalf, we expect appropriate contractual and security arrangements to be in place.
We may also disclose information where reasonably necessary to establish, exercise or defend legal rights, prevent fraud or crime, protect systems or individuals, or comply with a lawful requirement.
15. International transfers
Some technology providers we use operate internationally or use infrastructure in more than one country.
This means personal information may sometimes be transferred to, accessed from or processed in a country outside the United Kingdom.
Where UK data protection law treats this as a restricted international transfer, we use an appropriate transfer mechanism where required.
Depending on the circumstances, this may include:
- UK adequacy regulations
- the UK International Data Transfer Agreement
- the UK Addendum to approved EU Standard Contractual Clauses
- another safeguard or exception permitted by UK data protection law
The appropriate mechanism depends on the service provider and destination involved.
16. How long we keep information
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected and for any legitimate legal, contractual, tax, accounting, insurance or evidential requirements that follow.
Retention periods therefore vary depending on the type of information.
Website technical information
Technical and security information is retained only for as long as reasonably necessary for security, operational, diagnostic or abuse-prevention purposes, taking account of the retention arrangements of the infrastructure providers involved.
General enquiries
Information relating to enquiries that do not lead to an engagement will normally be retained only for as long as it remains reasonably relevant to the enquiry or potential business relationship.
Client and contractual records
Where an enquiry becomes a commercial engagement, relevant correspondence and records may form part of the client's contractual and business record.
Core contractual, financial and project records will normally be retained for up to six years after the end of the relevant relationship or transaction, unless a longer period is reasonably required for legal, tax, regulatory, insurance or evidential purposes.
Accounting and tax records
Records required for accounting, taxation or statutory purposes will be kept for the period required by applicable law.
When information is no longer required, it will be deleted, anonymised or securely disposed of where reasonably practicable.
17. Security
We take the security of personal information seriously.
Appropriate technical and organisational measures are used according to the nature of the information and the risks involved.
These may include:
- access controls
- strong authentication
- encryption
- secure cloud services
- network and application security controls
- logging and monitoring
- backup and recovery arrangements
- software and security updates
- least-privilege access
- controlled administrative access
- appropriate contractual controls with service providers
No system connected to the internet can be guaranteed to be completely secure.
Our approach is therefore to reduce risk, limit unnecessary collection and access, monitor appropriately, and respond to security issues when they arise.
18. Personal data breaches
If we become aware of a security incident involving personal information, we will assess the nature and likely consequences of the incident and take appropriate action.
Where UK data protection law requires notification to the Information Commissioner's Office or to affected individuals, we will make that notification within the applicable legal requirements.
19. Automated decision-making and profiling
We do not currently use personal information collected through this website to make decisions about individuals solely by automated means that produce legal or similarly significant effects.
We also do not use the website to behaviourally profile visitors for advertising purposes.
If that changes materially, this notice will be updated before the relevant processing is introduced.
20. Your rights
UK data protection law gives individuals a number of rights in relation to their personal information.
Depending on the circumstances and the lawful basis for processing, these may include the right to:
- ask whether we hold personal information about you
- obtain a copy of personal information we hold about you
- have inaccurate information corrected
- have incomplete information completed
- request deletion of personal information
- ask us to restrict the way information is used
- object to certain processing
- receive personal information in a portable format in certain circumstances
- withdraw consent where processing is based on consent
- object to direct marketing
- raise concerns about automated decision-making where relevant
These rights are not absolute and some are subject to legal exemptions.
For example, we may be entitled or required to retain information despite a deletion request where it is needed to comply with law or establish, exercise or defend legal claims.
You will not normally have to pay a fee to exercise your rights.
We may ask for information necessary to confirm your identity before disclosing personal information.
To exercise any of these rights, contact:
21. Direct marketing
We do not use information collected from ordinary website visitors for behavioural advertising.
If we send direct marketing communications in future, we will do so only where permitted by applicable law.
You can object to the use of your personal information for direct marketing at any time.
If you tell us to stop sending marketing communications, we may retain limited information necessary to record and respect that preference.
22. Children
This website and our consultancy services are intended for organisations and adults acting in a professional or business capacity.
They are not designed as services for children and we do not intentionally use the website to collect personal information from children.
23. Complaints
If you have a concern about how NAKATOMI CONSULTING LIMITED has used your personal information, please contact us first.
We would rather understand and resolve the problem directly where we can.
Email: info@nakatomi.consulting
You also have the right to complain to the Information Commissioner's Office (ICO), the independent regulator responsible for data protection in the United Kingdom.
Information about making a complaint and exercising your data protection rights is available at ico.org.uk.
You do not have to contact us before making a complaint to the ICO.
24. Changes to this notice
Technology changes, suppliers change and businesses evolve.
We will review this privacy notice when there is a material change to:
- the website
- the personal information we process
- the purposes for which we use it
- our key service providers
- analytics or tracking technologies
- applicable data protection requirements
The current version will be published on this page.
The Last updated date at the top of the page identifies the version currently in force.
Where we intend to introduce a materially different use of personal information, we will provide appropriate privacy information before that processing begins.