Privacy Policy
This policy explains how Torsik Ltd handles your personal data. Read it alongside our Cookie Policy and Terms & Conditions.
01. Who we are
Torsik Ltd (Company No. 16864103), registered in England and Wales. Registered office: Bartle House, Oxford Court, Manchester, England, M2 3WQ. Email: info@torsik.co.uk.
Torsik Ltd is the data controller under UK GDPR. We are registered with the Information Commissioner's Office (ICO), registration number ZC138992.
02. The data we collect
We collect:
- Name.
- Email address.
- Company.
- Job title.
- Phone number.
- The content of any message, enquiry, form, scorecard response, email or application you send us.
- Newsletter subscription, unsubscribe and suppression records.
- Website, form, scorecard, campaign, landing-page, attribution, consent and event records where they relate to a named person or company.
- Privacy-limited first-party website statistics, such as page path, event type, source fields, referrer domain, device type, browser family, viewport size, scroll depth, clicks and form attempts.
- Candidate or applicant information where someone applies for, or is introduced for, a Torsik role.
- Client, prospect and project information shared with us during commercial discussions or delivery.
We do not intentionally collect special category data through the website. Please do not send us sensitive personal information through the website.
03. Why we use it
We process personal data to:
- Respond to enquiries.
- Arrange and hold clarity calls.
- Assess whether our services suit your needs.
- Enter into and perform consulting agreements.
- Maintain our client, prospect, supplier, applicant and operational records.
- Send marketing communications where you have asked us to or where we are otherwise permitted.
- Run diagnostic scorecards, form routes, newsletter flows and related follow-up.
- Review candidates and manage recruitment routes.
- Prepare internal research, analysis, drafts, transcripts and operational records.
- Measure and improve how the website and related routes perform, including privacy-limited first-party aggregate statistics where the cookie rules allow this and you have not objected, and consented analytics such as GA4 and Microsoft Clarity heatmaps or session replay where analytics cookies are accepted.
- Preserve audit trails, consent records, source-system records, contract records and compliance evidence.
04. Our lawful basis
We rely on:
- Legitimate interests, for business-to-business communication, responding to enquiries, running and improving our service, privacy-limited first-party aggregate website statistics where the cookie rules allow this and you have not objected, preserving business records, handling recruitment routes and keeping evidence of how records entered our systems.
- Contractual necessity, where we are entering into or performing an agreement with you.
- Consent, for marketing where consent is required, and for any non-essential cookies that require it.
- Legal obligation, where we need to keep records for tax, accounting, regulatory or legal reasons.
Where we rely on legitimate interests, we have weighed our interests against your rights. You can ask us about that assessment at any time.
05. Service providers we use
We share personal data with trusted providers who process it on our behalf, under written terms that require them to protect it and use it only as we instruct:
- Website hosting, staging, rollback and domains: Hostinger, Squarespace and GoDaddy.
- Website operational database, consent, form, event and outbox records: PostgreSQL.
- Website analytics, statistics and reporting: Torsik first-party website analytics, Google Analytics 4, Microsoft Clarity and Google Cloud BigQuery.
- Customer relationship management (CRM): Zoho CRM.
- Invoicing and accounting: Zoho Books.
- Email, calendar and file storage: Google Workspace (Gmail, Drive and Calendar) and Apple iCloud.
- Project management, documents and knowledge base: Notion.
- Email and newsletters: MailerLite.
- Scorecards and diagnostics: ScoreApp.
- Automation and handoff routes: Zapier.
- Video conferencing: Google Meet, Microsoft Teams and Zoom, whichever a client prefers.
- Artificial intelligence tools: see section 6.
- Audio, transcription, text-to-speech and workstation productivity: Speechify API, Speechify and Wispr Flow.
- Documents and notes: Obsidian and Obsidian Sync.
- Recruitment and candidate sourcing: SalesAgents.uk.
- Social media: LinkedIn, Instagram (Meta) and X, where you interact with our pages or embedded content.
We do not sell your personal data.
Some retired, rollback or transitional systems may still hold historic records while we preserve audit trails, export records or complete deletion checks. ClickUp is retired as a current task system, but historic data has not yet been deleted. HubSpot, SurveyMonkey, Teamwork and Zoho Inventory are not current operating systems. Mailchimp is not a current email platform and is treated as a retired test system unless later evidence shows real customer or prospect data remains there.
06. How we use AI
We use artificial intelligence tools to help prepare internal research, analysis, draft materials, transcripts, operational records and delivery support. Current AI providers may include OpenAI, Anthropic (Claude) and Google systems, including Gemini and NotebookLM. xAI (Grok) and Perplexity are not treated as adopted operational processors unless later evidence confirms use.
Where these tools process personal data:
- We use them on business terms that do not allow the provider to train its models on our data.
- Providers retain prompts and outputs only for the limited periods set out in their own business terms.
- AI-assisted output is reviewed by a person before it is delivered to a client.
Please do not submit confidential material through the website. Confidential information should only be shared once a written agreement is in place.
07. Sending data outside the UK
Some of our providers, including some of the AI tools above, are based outside the UK, including in the United States. Where we transfer personal data abroad, we rely on a recognised safeguard:
- UK adequacy regulations, where the destination country is covered.
- The UK Extension to the EU-US Data Privacy Framework (the "UK-US data bridge"), where the US provider is certified under it.
- The UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, in other cases.
We take reasonable steps to make sure your data is protected to a UK standard wherever it is processed.
08. How long we keep it
We keep personal data:
- For the duration of our relationship with you.
- For up to six years after that, where we may need it to defend a legal claim, meet a legal obligation, keep accounting records or preserve a business audit trail.
- Marketing data, until you withdraw consent or ask us to stop.
- Candidate and applicant data only for as long as needed for the recruitment purpose, unless we need to keep a limited record for legal, accounting or audit reasons.
- Retired-system records only while we need to preserve evidence, complete an export or deletion check, or keep a lawful audit trail.
- First-party website event records only for the period needed to produce aggregate statistics and keep necessary consent, audit and security evidence.
09. Your rights
Under UK GDPR you have the right to:
- Access your data.
- Correct inaccurate data.
- Erase data, where the law allows.
- Restrict how we use it.
- Object to processing.
- Data portability.
- Withdraw consent at any time, where we rely on it.
To exercise any of these, email info@torsik.co.uk. We will respond within one month.
10. Complaints
If you are unhappy with how we have handled your personal data, please tell us first so we can put it right. Email info@torsik.co.uk. We operate a formal complaints procedure: we will acknowledge your complaint promptly and respond within one month.
If you remain dissatisfied, you have the right to complain to the ICO. You do not have to come to us first, but it often resolves things faster.
ICO: ico.org.uk, or 0303 123 1113.
11. Cookies
We use cookies and similar technologies on this website. How they work, which ones we use, and how to manage them are set out in our Cookie Policy.
12. Security
We protect your data with secure hosting, access controls and other commercially reasonable safeguards. No system is ever completely secure, but we take the protection of your data seriously.
13. Changes to this policy
We may update this Privacy Policy from time to time. The latest version will always appear on this page, with the date at the top.
Start a conversation.
Bring us a market question the leadership team cannot yet answer. We will tell you whether it fits a defined product, what evidence it needs, and what the fixed fee would be. If it does not fit, we will say so.