Last reviewed: 19 August 2026
1. Who is responsible for your information
GSKordeven is the controller for personal information collected through this website and during enquiries. GSKordeven is a trading name operated by Guntis Subrovskis. Contact: info@gskordeven.co.uk. Business location: Scotland, United Kingdom.
2. Information we collect
We may collect your name, business name, work contact details, service interest, project requirements, correspondence, and information reasonably needed to prepare a quote or deliver an agreed service. The secure enquiry form does not accept file uploads, and it instructs visitors not to submit passwords, financial credentials, authentication secrets or sensitive customer records.
3. Why we use it, and our lawful bases
We use enquiry information to respond, assess whether the service fits, prepare proposals, and take steps requested before entering a contract. The usual lawful bases are steps before a contract, performance of a contract, legitimate interests in operating and protecting the business, legal obligations, and consent only where consent is genuinely appropriate.
4. Data minimisation and sensitive information
Please provide only what is needed for the initial conversation. Do not submit special-category data, criminal-offence data, passwords, payment-card details, bank credentials, private keys, API keys or access tokens through the public form.
5. How the enquiry form works
The form validates and sanitises every field, and applies cross-site request forgery protection, rate limiting, a spam trap and checks for common sensitive-data patterns. A private copy is saved in the restricted GSKordeven Enquiries area of WordPress, so that a genuine enquiry is not lost if an email notification fails. An email notification is also sent to the configured business mailbox. Enquiries are not published, and are not available through the public WordPress application programming interface.
6. Service providers and sharing
Information may be processed by the website host, email provider, backup provider, accounting provider and professional advisers where necessary. We do not sell personal information. We may disclose information where legally required, or where necessary to establish, exercise or defend legal claims.
7. International transfers
Some providers may process information outside the United Kingdom. Where this happens, appropriate contractual or legal safeguards should be used, and provider terms should be reviewed.
8. Retention
Unsuccessful or inactive enquiries are normally reviewed for deletion within 12 months of the last meaningful contact. Client, contract, invoice and tax records may normally be retained for up to six years, or longer where required for a legal claim. Security records may be retained for an appropriate shorter period based on risk.
9. Security
Reasonable measures may include multi-factor authentication, access control, supported software, secure configuration, encrypted connections, backups, logging and restricted sharing. No method of transmitting or storing information over the internet can ever be guaranteed completely secure.
10. Your rights
Depending on the circumstances, United Kingdom data-protection law may give you rights to be informed, to access information, to correct it, to request deletion, to restrict processing, to object, to receive portable data, and to withdraw consent. Some rights are subject to exemptions and to the lawful basis being used.
11. Complaints
Please contact info@gskordeven.co.uk first, so the concern can be investigated. You may also complain to the Information Commissioner’s Office at ico.org.uk.
12. Legal framework and updates
This notice is intended to reflect the UK GDPR, the Data Protection Act 2018, the relevant changes introduced by the Data (Use and Access) Act 2025, and Information Commissioner’s Office guidance. It may be updated when services, providers or the law change.
13. Contact and service address
Email: info@gskordeven.co.uk. A full business service address must be added before public launch, where it is required by the Electronic Commerce Regulations and other trading-disclosure rules. You do not have to publish a home address; obtain a suitable lawful business or service address instead.
Reference framework
- Information Commissioner’s Office: UK GDPR guidance
- Information Commissioner’s Office: privacy notices and cookies
- Data Protection Act 2018
- Data (Use and Access) Act 2025
- Privacy and Electronic Communications Regulations 2003
- Electronic Commerce Regulations 2002