Cloud SpectrumCloud Spectrum
    • About Us
    • Logo Story
  • Products & Services
  • Sectors
  • Case Studies

Cloud Spectrum

Privacy Policy

How we collect, use, share and protect personal information

Effective date: 26 August 2026

Flat 44, Pandora Court, 8 Robertson Road, London, United Kingdom
This policy covers the Cloud Spectrum website and initial business enquiries. Client projects involving personal data should also be governed by the applicable services agreement, statement of work and, where required, a data processing agreement.

1. Who we are

Cloud Spectrum Ltd is a private limited company registered in England and Wales. Our registered office is Flat 44, Pandora Court, 8 Robertson Road, London, United Kingdom. We provide business and technology consultancy, implementation, integration, data, automation and managed services, including work involving platforms such as Salesforce and Databricks.

For personal information collected through our website, business development activities and our own business operations, Cloud Spectrum Ltd is normally the controller. Where we process personal information solely on a client's documented instructions during a client engagement, the client will generally be the controller and we will act as its processor; the relevant contract will govern that processing.

2. Scope of this policy

This policy applies when you visit cloudspectrum.uk, submit an enquiry, request a call, communicate with us, represent a client or prospective client, apply to work with us, or otherwise interact with our business. It does not govern third-party websites or services that we do not control.

3. Personal information we collect

  • Contact and identity information, such as your name, business email address, telephone number, job title, organisation and professional profile details.
  • Enquiry and booking information, including your message, preferred meeting date and time, selected country or time zone, and records of our correspondence.
  • Business relationship information, including proposals, contracts, statements of work, service history, meeting notes, billing contacts and payment administration records.
  • Technical and usage information that may be generated when you use the website, such as IP address, browser type, device information, referring page, timestamps, security logs and diagnostic data. The precise information depends on our hosting and website configuration.
  • Recruitment information, if you apply to work with us, such as your CV, employment history, qualifications, right-to-work information and interview notes.
  • Any other personal information you choose to provide, including information contained in documents or messages you send to us.

Please do not submit special category data, criminal-offence data, passwords, production credentials or confidential client datasets through the website forms.

4. How we obtain personal information

We collect information directly from you, from your organisation or colleagues, through our website forms and communications, and from publicly available professional sources. We may also receive information from business partners, suppliers and clients where this is lawful and relevant to an engagement.

5. How and why we use personal information

  • To respond to enquiries, arrange calls and take steps requested before entering into a contract — necessary for pre-contractual steps and/or our legitimate interests in developing our business.
  • To prepare proposals, deliver contracted services, administer projects, invoice and manage our relationship with you or your organisation — necessary for contract performance, legal obligations and/or our legitimate interests.
  • To operate, secure, troubleshoot and improve our website, systems and services — our legitimate interests in providing reliable and secure services.
  • To maintain business, tax, accounting and compliance records, establish or defend legal claims, and respond to regulators or lawful requests — compliance with legal obligations and our legitimate interests.
  • To send relevant business-to-business updates or follow up on our relationship where permitted by law — our legitimate interests and, where required, your consent. You may opt out at any time.
  • To assess candidates and manage recruitment — steps before a contract, our legitimate interests and legal obligations.
  • For any other purpose explained when information is collected, where we rely on consent or another lawful basis stated at that time.

Where we rely on legitimate interests, we consider the necessity of the processing and balance our interests against your rights and reasonable expectations. Where we rely on consent, you may withdraw it at any time without affecting earlier lawful processing.

Further detail on our usual purposes and lawful bases:

Website enquiries and call requests: we use the information supplied to assess your needs, communicate with you, allocate the enquiry internally and arrange follow-up. Our bases are steps at your request before a contract and our legitimate interests in responding to prospective clients.

Client and supplier administration: we use business contact, contractual and financial information to negotiate and manage engagements, coordinate delivery, keep records, obtain services and make or receive payments. Our bases are contract, legal obligation and legitimate interests.

Service quality and relationship management: we may review correspondence, meeting notes, feedback and delivery history to improve our processes, train personnel, resolve issues and understand client needs. Our basis is legitimate interests, subject to appropriate safeguards.

Security and fraud prevention: we may analyse technical information and communications to authenticate users, protect systems, prevent misuse, investigate incidents and preserve evidence. Our bases are legitimate interests and, where applicable, legal obligation.

Corporate transactions and legal matters: information may be used for due diligence, restructuring, insurance, professional advice, claims and regulatory responses. Our bases are legitimate interests and legal obligation.

5A. Business communications and direct marketing

We may contact existing clients, prospective corporate clients and professional contacts about relevant services, insights or events where permitted by the Privacy and Electronic Communications Regulations and UK data protection law. We consider the nature of the relationship, the recipient’s role and whether the communication is reasonably expected. We do not use purchased consumer marketing lists.

Every electronic marketing message will provide a simple way to opt out. You may also object at any time by replying to the message or contacting us. We may retain a minimal suppression record so that we can respect an opt-out. Service, security and contractual messages are not marketing and may still be sent where necessary.

6. Automated decision-making

We do not use information submitted through the website to make decisions based solely on automated processing that produce legal or similarly significant effects.

7. Cookies and similar technologies

The website may use strictly necessary storage or similar technologies for security, core functionality and user preferences. It also loads Google Fonts from Google-hosted domains, which may cause your browser to connect to Google and disclose technical information such as your IP address and browser details. If we deploy analytics, advertising or other non-essential technologies, we will provide clear information and obtain any consent required under applicable law before using them. You can manage cookies through your browser and, where available, our cookie controls. Blocking essential technologies may affect website functionality.

8. Who we share personal information with

  • Hosting, infrastructure, email and IT service providers that help operate and secure the website and our business systems.
  • Professional advisers, insurers, auditors and finance providers where reasonably necessary.
  • Clients, implementation partners, subcontractors and platform providers where needed for an agreed engagement and subject to appropriate contractual controls.
  • Public authorities, courts, regulators, law-enforcement bodies or other parties where disclosure is required by law or necessary to protect legal rights, safety or security.
  • A buyer, investor or successor in connection with a proposed or completed merger, reorganisation, financing or sale of all or part of our business, subject to appropriate confidentiality protections.

We do not sell personal information.

8A. Processors and service-provider oversight

Where another organisation processes personal information for us, we select providers with regard to the nature and risk of the processing and put appropriate contractual protections in place. Providers are permitted to process information only for agreed purposes, must apply suitable security measures and must assist with relevant data protection obligations. We periodically review material providers and access rights. A current list of material processors may be provided where appropriate, subject to confidentiality and security considerations.

9. International transfers

Cloud Spectrum works with a distributed team and service providers that may operate outside the United Kingdom, including in Sri Lanka. Some technology providers may also process information internationally. When restricted transfers of personal information occur, we use a lawful transfer mechanism and appropriate safeguards, such as adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, and supplementary security measures where appropriate. You may contact us for more information about relevant safeguards.

10. Retention

We retain personal information only for as long as reasonably necessary for the purpose collected, including to meet legal, accounting, tax, security and dispute-resolution requirements. As a general guide, we keep unsuccessful website enquiries for up to 24 months after the last meaningful interaction; client and supplier contract, project and financial records are normally kept for up to 7 years after the relationship ends; recruitment records for unsuccessful candidates are normally kept for up to 12 months; and security or diagnostic logs are retained for a shorter period appropriate to their purpose. We may keep information longer where required by law, litigation, a regulatory hold or an applicable client contract, and may delete it sooner where it is no longer needed.

11. Security

We use reasonable technical and organisational measures designed to protect personal information against unauthorised access, loss, alteration or disclosure. These measures may include access controls, secure configuration, encryption where appropriate, backups, supplier due diligence and confidentiality obligations. No internet transmission or storage system is completely secure, so we cannot guarantee absolute security.

Access to personal information is limited according to business need and role. Personnel and contractors with access are expected to protect confidentiality and follow applicable policies. We review permissions, maintain appropriate records, and assess incidents so that containment, remediation, notification and lessons learned can be addressed. If a personal data breach creates a risk requiring notification, we will notify the ICO and affected individuals within the periods required by law.

12. Your data protection rights

Depending on the circumstances, UK data protection law may give you rights to be informed; obtain access to your personal information; correct inaccurate information; request erasure or restriction; object to processing based on legitimate interests or to direct marketing; receive certain information in a portable format; withdraw consent; and ask for human review of certain automated decisions. These rights are not absolute and exemptions may apply.

To exercise a right, use the contact details in section 15. We may ask for information needed to confirm your identity and understand your request. You will not normally be charged.

We normally respond without undue delay and within one month after receiving a valid request. The law permits an extension for complex or numerous requests, in which case we will explain the reason and expected timing. We may refuse or charge a reasonable fee for a request only where the law permits, including where it is manifestly unfounded or excessive.

12A. Information relating to other people

If you provide personal information about another person, you must have authority or another lawful basis to do so and, where appropriate, make this policy available to them. Organisations that provide business contact information to us are responsible for ensuring that the disclosure is lawful. We may contact the individual directly to provide privacy information where required.

13. Children

Our website and services are intended for businesses and professionals and are not directed to children. We do not knowingly collect personal information from children through the website.

14. Complaints

Please contact us first so that we can try to resolve your concern. You also have the right to complain to the UK Information Commissioner’s Office (ICO). Current contact and complaint details are available at ico.org.uk. If you are outside the United Kingdom, you may also have the right to contact your local data protection authority.

15. Contact us

Address privacy enquiries to: The Data Protection Contact, Cloud Spectrum Ltd, Flat 44, Pandora Court, 8 Robertson Road, London, United Kingdom. You may also use the contact form at cloudspectrum.uk and state that your message concerns privacy or data protection.

15A. External links and social media

Our Website may contain links to third-party websites and professional profiles. Following a link may allow the third party to collect information under its own terms and privacy notice. We do not control those third parties and encourage you to review their notices before providing information. Interactions with our pages or personnel on social media may also be visible to the platform operator and other users.

15B. Questions about client-project data

If your request concerns information processed by Cloud Spectrum on behalf of one of our clients, please contact that client in the first instance. We will assist the client as required by our contract and applicable law. We may need to refer your request to the relevant client because it determines the purposes and means of that processing.

16. Changes to this policy

We may update this policy to reflect changes in our services, technology or legal obligations. We will publish the revised version with a new effective date and, where appropriate, provide additional notice.

Cloud Spectrum Ltd.
Flat 44, Pandora Court, 8 Robertson Road, London, United Kingdom
  • About
  • Case Studies
  • Products & Services
  • Sectors
2026 Cloud Spectrum. All rights reserved.|Terms of Service|Privacy Policy

Your CRM journey starts with a conversation.

Cloud Spectrum