Privacy policy

CORESHIFT CONSULTING LIMITED

Last updated: 11 August 2026

This Privacy Policy explains how CORESHIFT CONSULTING LIMITED collects, uses, stores, shares and protects personal data when you visit our website, contact us, request a consultation, purchase services, sign an agreement, receive AI consulting, training, automation, implementation, prompt development, research support, AI-assisted content production or related digital services, or otherwise interact with us through https://coreshift-consulting.com/.

CORESHIFT CONSULTING LIMITED provides practical AI consulting, AI implementation, workflow automation, prompt systems, AI training, AI-assisted research, AI creative services, chatbot configuration, CRM/email/sales automation and related digital services for individuals and businesses.

Because our services may involve business systems, customer data, CRM records, email systems, chatbot submissions, website data, documents, prompts, files, credentials, API access and third-party AI platforms, we take privacy, confidentiality and information security seriously.

We process personal data in accordance with applicable data protection laws, including the UK General Data Protection Regulation, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations where applicable, and other applicable UK data protection rules.


1. Who we are

For the purposes of data protection law, the relevant data controller for our own business operations is:

CORESHIFT CONSULTING LIMITED
Company number: 17386933
Registered office: 4 Victoria Square, Wolverhampton, England, WV1 1LD, United Kingdom
Email: contact-us@coreshift-consulting.com

If you have any questions about this Privacy Policy, your personal data or your privacy rights, please email us at contact-us@coreshift-consulting.com.

2. Our role: controller, processor or service provider

Our role depends on the context in which personal data is processed.

We usually act as an independent data controller when we process personal data for our own business purposes, such as managing enquiries, communicating with clients, issuing invoices, operating our website, maintaining records, handling complaints, managing marketing communications, preventing fraud and complying with legal obligations.

For some business projects, we may act as a processor where we process personal data only on a business customer’s documented instructions. This may happen where we access or configure the customer’s CRM, email system, chatbot, website, customer database, prospect database, automation tools or other business systems as part of an agreed project.

Where we act as a processor, the business customer normally remains responsible for determining the lawful purposes and means of processing, providing required privacy notices to its own customers, employees, prospects and contacts, and ensuring that it has a lawful basis for the processing it instructs us to carry out.

Where required, specific controller/processor terms may be included in a written agreement, data processing agreement, statement of work or project documentation.

3. Personal data we collect

The personal data we collect depends on how you interact with us, what services you request and what project access or materials are required. We may collect the following categories of personal data:

3.1 Identity and contact information

  • Full name;
  • Business name, company name or organisation name;
  • Job title, department or role;
  • Email address;
  • Phone number, where provided by you;
  • Billing address, registered office, business address or postal address;
  • Country, city and other contact details supplied by you.

3.2 Enquiry and project information

  • Messages sent through our website, email or contact channels;
  • Information about the service you are interested in;
  • Project requirements, goals, problems, workflows, business processes and expected outcomes;
  • Documents, screenshots, files, examples, links or other materials you provide for review;
  • Consultation notes, project summaries, recommendations and support records;
  • Project scope, quotation, contract, invoice and delivery information.

3.3 Service and deliverable information

  • AI consulting records and consultation notes;
  • AI strategy, automation roadmap and implementation documentation;
  • Prompt libraries, prompt templates, workflow instructions and AI usage notes;
  • Training materials, learning session notes and practical exercises;
  • Research outputs, summaries, source lists and written recommendations;
  • Creative AI instructions, content briefs, image/video/text requirements and draft outputs;
  • Chatbot, CRM, email, sales, website or automation configuration details.

3.4 Customer data processed during projects

Where a project requires access to a customer’s business systems, we may process data supplied or made accessible by the customer. This may include:

  • CRM records;
  • Email records and business communications;
  • Customer, prospect, supplier or business contact details;
  • Website enquiries and chatbot submissions;
  • Sales, support, workflow or operational records;
  • Internal business documents, files, spreadsheets or databases;
  • User accounts, roles, permissions, settings, integrations, API identifiers and system logs.

The exact data processed depends on the project scope and the access provided by the customer.

3.5 Account access and technical information

  • Temporary access credentials, where strictly necessary and authorised;
  • Role-based account access, delegated permissions or API keys;
  • CRM, email, website, chatbot, automation, cloud, AI platform or software account settings;
  • Technical configuration details, integration logs, workflow settings and troubleshooting information;
  • Device, browser, IP address, system and security information connected with website use or project delivery.

Wherever practicable, customers should provide temporary, role-based or delegated access rather than sharing primary passwords.

3.6 Payment and transaction information

  • Invoice details;
  • Payment status;
  • Transaction references;
  • Bank transfer references;
  • Billing details;
  • Accounting and tax records.

We do not intentionally store full payment card details on our own systems. Where card or online payment services are used, payment information is processed by the relevant third-party payment provider.

3.7 Marketing and communication information

  • Email subscription status;
  • Marketing preferences;
  • Responses to newsletters, updates or business communications;
  • Consent records where required;
  • Unsubscribe and suppression records.

3.8 Sensitive information

We do not usually need special category data, criminal-offence data, health data, highly sensitive personal data or unnecessary confidential information to provide ordinary AI consulting and automation services.

You should avoid sending unnecessary sensitive information to us. If a project may require processing sensitive data, this should be discussed in advance and appropriate safeguards should be agreed before the processing begins.

4. How we collect personal data

We may collect personal data in the following ways:

  • Directly from you when you contact us, request a consultation, send an enquiry, sign an agreement, provide project materials, attend a session, request support, request a refund or communicate with us.
  • Through our website when you browse pages, submit forms, interact with website tools or use cookies and similar technologies.
  • From business customers where a customer provides data, files, system access, CRM records, email records, chatbot records, customer/prospect records or business contact data for a project.
  • From third-party services such as AI platforms, CRM systems, website platforms, email providers, automation tools, analytics tools, payment providers, cloud tools, customer support tools and communication platforms.
  • From public sources where research support, business research, job-search support, source review or market research requires use of publicly available information.

5. Why we use personal data

We use personal data only where we have a lawful reason to do so. The main purposes are described below.

Purpose Examples Lawful basis
Responding to enquiries Answering questions, discussing requirements, recommending next steps Pre-contract steps; legitimate interests
Providing services AI consulting, training, implementation, automation, prompt development, research support and creative AI services Performance of a contract; legitimate interests
Project delivery and configuration Configuring AI tools, CRM systems, chatbots, email workflows, automation tools and website integrations Performance of a contract; customer instructions; legitimate interests
Processing customer data as processor Accessing CRM, email, chatbot, website or customer/prospect data solely to deliver an agreed business project Customer’s documented instructions; contract; legal obligations applicable to processor role
Billing and payment Issuing invoices, recording payments, managing accounting records and payment queries Performance of a contract; legal obligation; legitimate interests
Security and fraud prevention Protecting accounts, systems, credentials, project materials and website security Legitimate interests; legal obligation
Legal and compliance records Maintaining contracts, invoices, project records, correspondence and tax/accounting records Legal obligation; legitimate interests
Service improvement Improving our website, service structure, support process, templates and internal workflow Legitimate interests
Marketing communications Sending service updates, AI insights, business updates or relevant offers where permitted Consent or legitimate interests, depending on the communication
Analytics and website operation Understanding website performance, page use, form activity and user experience Consent where required; legitimate interests where permitted

6. AI tools and use of personal data

Our services may involve the use of third-party AI tools, large language models, automation platforms, research tools, creative tools, APIs and other software. These may include tools such as ChatGPT, Gemini, Claude, Copilot, Perplexity, NotebookLM, Make, Zapier, n8n, Midjourney, Adobe Firefly, Runway, Canva AI, DaVinci Resolve or other platforms selected for a particular project.

We select tools according to the project requirement and aim to use only what is necessary and proportionate for the agreed work.

We do not intentionally submit client confidential information or personal data to a publicly available general-purpose AI model for the purpose of training that model without a lawful basis and, where required, informed permission from the relevant customer.

Where reasonably available and appropriate, we use privacy, retention and data-control settings that reduce unnecessary use, storage or disclosure of customer content by third-party platforms.

However, third-party platforms may have their own terms, privacy policies, data controls, retention settings, account rules, availability limits and technical restrictions. Customers should not provide unnecessary sensitive information for AI-assisted work.

7. Human review and automated decision-making

AI-assisted outputs should be treated as assistive material rather than independently verified professional advice.

We do not use solely automated decision-making that produces legal or similarly significant effects on individuals through our website.

Where we configure AI systems, chatbots, workflows or automation for a business customer, the customer remains responsible for deciding how those systems are used in its own business and for ensuring appropriate human review before relying on AI-assisted output for material commercial, financial, legal, regulatory, employment, safety, customer-impacting or other significant decisions.

8. Customer access, credentials and system security

Some projects may require access to customer systems, such as CRM platforms, email systems, websites, chatbot platforms, cloud tools, API dashboards, AI workspaces or automation platforms.

Customers should provide the minimum access reasonably necessary for the project. Where practicable, access should use dedicated user accounts, role-based permissions, temporary credentials, restricted API keys and multi-factor authentication rather than shared master credentials.

We use access credentials solely for the relevant project and do not knowingly disclose them except to authorised personnel, professional advisers or approved subcontractors who reasonably need access and are subject to appropriate confidentiality or security obligations.

When access is no longer reasonably required, we will cease using it and, where appropriate, return, delete or securely dispose of stored credentials, subject to lawful record-keeping, security and backup requirements.

9. Who we share personal data with

We may share personal data with trusted third parties where necessary for the purposes described in this Privacy Policy, including:

  • AI platforms, model providers, automation platforms and API providers used for project delivery;
  • CRM, email, chatbot, website, hosting, cloud and software providers;
  • Payment processors, banks and accounting service providers;
  • Communication, email, scheduling and customer support tools;
  • Analytics, cookie and website performance tools, where permitted;
  • Professional advisers, including accountants, legal advisers, auditors and compliance consultants;
  • Subcontractors, developers, technical specialists or support providers reasonably required for a project;
  • Government authorities, regulators, courts, law enforcement or tax authorities where required by law;
  • Potential buyers, investors or advisers in connection with a business sale, restructuring, merger or similar transaction.

We do not sell personal data for money. We also do not authorise third-party service providers to use customer project data for unrelated marketing purposes.

10. Sub-processors for business projects

Where we act as processor for a business customer, we may use sub-processors reasonably required to provide the services. These may include cloud, hosting, AI, development, integration, support, communication, automation and software providers.

Where required by data protection law or a written agreement, we will impose data protection obligations on sub-processors that are materially equivalent to those applicable to us as processor.

If a specific written agreement gives the customer a right to object to new or replacement sub-processors, we will follow the notice and objection process set out in that agreement.

11. International transfers

Some of our service providers, including AI platforms, automation tools, cloud providers, hosting services, communication tools, payment providers and technical service providers, may process personal data outside the United Kingdom.

Where personal data is transferred internationally, we rely on appropriate safeguards where required by law. These may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, standard contractual clauses or another lawful transfer mechanism recognised by applicable data protection law.

Where a business customer independently selects a third-party provider or instructs us to configure a specific platform, that provider may process data internationally under its own terms and privacy arrangements.

12. Marketing communications

If you subscribe to our updates, request information, purchase services or provide business contact details, we may send you relevant communications about our services, AI consulting, automation, training, prompt systems, practical AI use, business updates or related content where permitted by law.

You can unsubscribe from marketing emails at any time by using the unsubscribe link in the email or by contacting us at: contact-us@coreshift-consulting.com.

Even if you opt out of marketing, we may still send service-related messages, such as responses to enquiries, quotations, invoices, project updates, delivery notices, support messages, cancellation information, legal notices or important changes to our terms.

13. Cookies and similar technologies

Our website may use cookies and similar technologies to operate the website, remember preferences, support security, improve functionality, analyse performance and, where enabled, support marketing or advertising.

Some cookies are strictly necessary for the website to function properly. These may help load pages, maintain security, support form functionality or remember basic settings.

Other cookies, such as analytics, advertising, personalisation or tracking cookies, may require consent depending on the technology used and applicable law. Where required, we will ask for consent before placing non-essential cookies on your device.

You can manage cookies through your browser settings or through any cookie preference tool available on our website. Blocking some cookies may affect website functionality.

14. How long we keep personal data

We keep personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide services, manage projects, maintain records, comply with legal obligations, resolve disputes, prevent fraud and protect our legal interests.

In general:

  • Enquiry records may be kept for as long as reasonably necessary to manage the enquiry and maintain business records;
  • Contracts, invoices, payment records and accounting records may be kept for up to 6 years or longer where required by law;
  • Project records, deliverables, support records and correspondence may be kept for as long as necessary to perform the project, support the customer and protect legal rights;
  • Customer Data processed as processor is normally kept only for the period required for the project or agreed support, unless law or a written agreement requires otherwise;
  • Credentials and access details should be deleted, returned, disabled or ceased when no longer needed, subject to lawful retention and security requirements;
  • Marketing records are kept until you unsubscribe or withdraw consent, unless we need to keep a suppression record to respect your opt-out;
  • Technical, analytics and cookie data may be kept for shorter periods depending on the tool and cookie duration;
  • Dispute, complaint, legal claim and fraud prevention records may be kept for as long as necessary to protect our legal rights.

15. How we protect personal data

We use reasonable technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure.

Depending on the nature of the project, these measures may include access control, least privilege access, credential protection, secure transmission, controlled sharing, reasonable endpoint security, secure development practices, deletion or revocation of access when no longer required, confidentiality obligations and appropriate provider controls.

However, no website, online service, email system, AI platform, cloud tool or internet transmission is completely secure. You should avoid sending unnecessary sensitive information through insecure channels.

16. Confidentiality

We may receive confidential business information, project materials, internal processes, CRM data, customer databases, prompts, automation workflows, technical architecture, access credentials, commercial information, financial information or other non-public information during a project.

We use confidential information only to provide services, administer agreements, comply with law, protect legitimate legal interests or for another purpose authorised by the disclosing party.

We may disclose confidential information only to personnel, professional advisers, subcontractors or service providers who reasonably need it for the permitted purpose and are subject to appropriate obligations, or where required by law, court order or competent authority.

17. Your rights

Depending on applicable law and the context of processing, you may have the following rights in relation to your personal data:

  • The right to be informed about how we use your personal data;
  • The right to access the personal data we hold about you;
  • The right to correct inaccurate or incomplete personal data;
  • The right to request deletion of your personal data;
  • The right to restrict certain processing;
  • The right to object to certain processing, including direct marketing;
  • The right to data portability in certain circumstances;
  • The right to withdraw consent where processing is based on consent;
  • The right not to be subject to certain decisions based solely on automated processing where those decisions have legal or similarly significant effects;
  • The right to complain to a data protection supervisory authority.

Your right to object: you have the right to object to processing based on legitimate interests in certain circumstances. You also have an absolute right to object to direct marketing.

To exercise your rights, please email us at: contact-us@coreshift-consulting.com.

We may need to verify your identity before responding to a request. If your data is processed by us as processor on behalf of a business customer, we may need to refer your request to that customer as the controller.

18. When you must provide personal data

Some personal data is necessary for us to respond to enquiries, provide quotations, enter into contracts, issue invoices, deliver services, configure systems, provide support and comply with legal obligations.

If you do not provide information that is reasonably required for a service, we may be unable to provide that service, start the project, complete the work, verify payment, respond to your request or comply with our legal obligations.

19. Complaints

If you are unhappy with how we handle personal data, please contact us first so we can try to resolve the issue: contact-us@coreshift-consulting.com.

You also have the right to complain to the UK data protection supervisory authority:

Information Commissioner’s Office
Website: https://ico.org.uk/make-a-complaint/

20. Children’s privacy

Our website and services are intended for adults, businesses, organisations and individuals seeking professional AI consulting or digital support. We do not knowingly collect personal data from children under the age of 13. If you believe that a child has provided personal data to us, please contact us and we will take appropriate steps to delete it where required.

21. Third-party links and services

Our website and project work may involve links to third-party websites, AI platforms, payment services, software tools, cloud services, communication tools, documentation platforms, recruitment websites, research sources or other external services.

We are not responsible for the privacy practices, content, terms, security or availability of third-party websites or services. You should review the relevant third-party privacy policy and terms before using those services or providing personal data to them.

22. Business, legal and regulatory checks

We may keep and process business records, transaction data, invoices, contracts, project records, supplier records, customer correspondence and compliance documents where necessary for accounting, tax, legal, banking, payment provider, fraud prevention, dispute resolution, regulatory or business verification purposes.

This may include sharing limited information with banks, payment processors, professional advisers, auditors or compliance reviewers where reasonably required to verify our business activity, investigate transactions, respond to lawful requests or maintain our business relationship with service providers.

23. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, website, AI tools, project delivery methods, legal requirements, service providers or data handling practices.

When we update this Privacy Policy, we will change the “Last updated” date at the top of this page. Where required by law, we may also provide additional notice.

24. Contact us

If you have any questions about this Privacy Policy, your personal data, project data, data protection arrangements or your privacy rights, please email us at: contact-us@coreshift-consulting.com.

CORESHIFT CONSULTING LIMITED
Company number: 17386933
4 Victoria Square, Wolverhampton, England, WV1 1LD, United Kingdom
Email: contact-us@coreshift-consulting.com