
Legal
Privacy Notice.
How we use personal information when Cahillbrand acts as a controller.
Last updated: 27 July 2026
1. Who we are
Cahillbrand Website Design & Development is a trading name of Cahillbrand Ltd, a company registered in England and Wales under company number 10029421. Our registered office is Arlington House, West Station Business Park, Spital Road, Maldon, Essex, England, CM9 6FF.
Cahillbrand Ltd is the controller of the personal information described in this notice. We are registered with the Information Commissioner’s Office under registration number ZB20023. You can contact us about privacy at [email protected].
VAT registration number: GB 518 2936 74.
2. What this notice covers
This notice explains how we use personal information about website visitors, CahillPulse users, people who contact us, prospective and current clients, client representatives, suppliers, collaborators and other business contacts.
When we host, maintain or develop a client’s service and handle personal information only on that client’s instructions, the client is normally the controller and Cahillbrand is a processor. That processing is governed by our agreement with the client and is not described as Cahillbrand’s own controller processing in this notice.
3. Information we collect
- Identity and contact information, such as your name, organisation, role, email address, telephone number and postal address.
- Enquiry, proposal and project information, including messages, requirements, quotations, contracts, approvals, support requests and other correspondence.
- Meeting information, including attendance details, notes and transcripts where a meeting is transcribed.
- Account and relationship information held in our client-management systems.
- Financial and transaction information, including invoices, payment status and accounting records. We do not take card payments through our website.
- Website and technical information, such as IP address, browser, device, referral page, pages viewed, security events and server logs.
- CahillPulse audit information, including the website address submitted, audit inputs, generated results and necessary technical records.
- Information from public sources, such as Companies House, business websites, professional profiles and public social-media posts.
- Any other information you choose to give us. Please avoid sending special-category, criminal-offence or other highly sensitive information unless we have agreed that it is necessary and have put suitable safeguards in place.
4. How and why we use information
| Purpose | Typical information | Lawful basis |
|---|---|---|
| Respond to enquiries and prepare proposals | Contact details, requirements and correspondence | Steps requested before a contract; or legitimate interests in developing our business and responding to organisations. |
| Enter into and deliver client contracts | Contact, project, meeting, account and transaction information | Contract where you are personally the client; otherwise legitimate interests in managing and delivering the contract with your organisation. |
| Provide hosting, support and security | Account, project, support, log and security information | Contract or legitimate interests in operating reliable and secure services. |
| Manage accounts, invoices and tax | Identity, contact, transaction and accounting information | Contract; legal obligation; and legitimate interests in debt management. |
| Manage suppliers and collaborators | Contact, contractual and payment information | Contract or legitimate interests in running our business. |
| Operate and improve our website and CahillPulse | Audit inputs, usage and technical information | Legitimate interests in providing, securing and improving our services. Consent is used where required for non-essential cookies or similar technology. |
| Keep records and resolve disputes | Relevant contracts, messages, technical and transaction records | Legal obligation and legitimate interests in establishing, exercising or defending legal claims. |
| Maintain professional relationships | Business contact and CRM information | Legitimate interests in relationship management. We do not currently send a marketing newsletter. |
| Comply with law and protect rights | Information relevant to a legal, regulatory, security or fraud matter | Legal obligation and legitimate interests in protecting Cahillbrand, clients and others. |
5. CahillPulse
If you submit a website to CahillPulse, we process the submitted URL and publicly available website information to produce an automated audit. We may store the audit, technical results and limited usage information so that the report can be delivered, protected against abuse, diagnosed and improved. Do not submit a private, restricted or third-party website unless you are entitled to do so.
6. Meetings and transcription
We use Granola to produce notes and transcripts of meetings. This is an accessibility and working-support tool and helps us keep accurate records and follow up agreed actions. We will normally make participants aware that transcription is being used. Meeting content may include personal or confidential information provided during the conversation.
Please tell us before or during a meeting if there is a particular sensitivity or if you would prefer transcription to be paused. We will consider reasonable alternatives, although we may still need to keep ordinary written notes and contractual records.
7. How we use artificial intelligence
We use selected AI-assisted tools, including business versions of ChatGPT, Claude, Cursor, local Ollama models and AI features connected to our working systems. These tools support software development, testing, research, drafting, image creation, administration, retrieval and analysis.
We apply data-minimisation measures and use business or organisational accounts and contractual protections where available. We avoid placing passwords or access credentials into prompts; use environment variables and access controls; remove, anonymise or replace personal information with test data where practical; and require human review of AI-assisted work.
AI tools may process project source code, client communications, meeting transcripts or other project context where relevant to the service. We do not intentionally submit special-category personal data, confidential client datasets, production database contents or personal information belonging to a client’s customers to a general-purpose AI service unless this is necessary for an agreed service and appropriate safeguards and instructions are in place.
We do not use AI to make solely automated decisions about individuals that produce legal or similarly significant effects.
8. Who receives information
We disclose personal information only where reasonably necessary. Recipients may include:
- Microsoft 365 and OneDrive for email, collaboration, files, meetings and appointment administration;
- Moxie for client relationship management, proposals, contracts, scheduling and project administration;
- FreeAgent for accounting and invoicing;
- Monzo, Capital on Tap, Funding Circle and other financial providers involved in business banking, credit or payments;
- Plausible Analytics, website hosting, server, domain, security and anti-spam providers, including Google reCAPTCHA where enabled;
- GitHub and Bitbucket for source control and project collaboration;
- NordPass for controlled credential management;
- Apple iCloud where used for business-device storage or synchronisation;
- OpenAI, Anthropic, Cursor, Granola and relevant model or infrastructure providers for the AI-assisted and transcription activities described above;
- professional advisers, insurers, subcontractors and collaborators who need the information for their role; and
- public authorities, regulators, courts, law-enforcement bodies or another party where disclosure is legally required or necessary to protect legal rights.
Our providers change as technology and client requirements change. Where we process personal information for a client, the relevant maintained subprocessor list and the client agreement provide further detail.
9. International transfers
Some providers or their support teams may process information outside the United Kingdom. Where a restricted transfer is made, we rely on an applicable UK adequacy regulation or put in place an appropriate safeguard, such as the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another permitted safeguard, together with any required risk assessment. You may contact [email protected] for further information about the safeguard relevant to your information.
10. How long we keep information
We keep information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, security and dispute-resolution requirements. Our working defaults are:
| Record | Working default |
|---|---|
| Unsuccessful enquiries and proposals | Up to 24 months after the last meaningful contact. |
| Client contracts, key project correspondence and approvals | Up to 7 years after the client relationship or relevant project ends. |
| Invoices, accounts and tax records | At least 6 years after the end of the relevant financial year, or longer if legally required. |
| Working project files and source material | For the client relationship and ordinarily up to 12 months after handover or termination, unless needed for support, licensing, legal claims or an agreed archive. |
| Support records | Normally up to 3 years after closure. |
| CahillPulse reports and associated records | Normally up to 12 months, unless retained in anonymised or aggregated form. |
| Website enquiries | Normally up to 24 months, then deleted or retained in the appropriate client/project record. |
| Routine server and security logs | Normally up to 90 days, unless needed to investigate an incident. |
| Backups | Until overwritten in the ordinary backup cycle, normally within 30 days unless a different client service is agreed. |
| CRM business contacts | For the active relationship and up to 24 months after the last meaningful contact, subject to periodic review. |
These are defaults, not promises that every record will be kept for the whole period. We may delete information sooner, or retain it longer where a dispute, legal hold, security incident, client instruction or statutory obligation requires it.
11. Security
We use proportionate technical and organisational measures including access controls, multi-factor authentication where available, managed credentials, encryption provided by relevant platforms, segregated development environments, patching, logging and data minimisation. No internet service can be guaranteed completely secure.
12. Your rights
Depending on the circumstances, you may have rights to access, correct or erase your information; restrict or object to processing; receive certain information in a portable form; and withdraw consent where consent is the basis used. These rights are not absolute and exemptions may apply.
You have the right to object to processing based on legitimate interests. We will stop unless we have compelling legitimate grounds to continue or the information is needed for legal claims. You can object to direct marketing at any time; Cahillbrand does not currently operate an email-marketing list.
To exercise a right, email [email protected]. We may need to verify your identity.
13. Complaints
Please contact us first so we have an opportunity to resolve your concern. You may also complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint, by telephone on 0303 123 1113, or by post to Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
14. Changes to this notice
We may update this notice when our services, providers or legal obligations change. The current version and its update date will be published on our website. Material changes will be brought to the attention of affected people where appropriate.