top of page

Privacy Policy

🌿 Privacy Policy

Hindsight Sustainability Ltd

Last updated: 19.02.2026

1. Introduction

Hindsight Sustainability Ltd is committed to protecting and respecting your privacy.

This Privacy Policy explains how we collect, use, and protect personal data when you:

 

  • visit our website

  • contact us or request our services,

  • use our sustainability platform (EcoTracker Pro)

  • Interact with us through business communications.


We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Data Controller

Hindsight Sustainability Ltd
Stoke-on-Trent, United Kingdom
Email: dom@hindsightsustainability.co.uk

We are the data controller responsible for your personal data.


3. Information We Collect

A. Information You Provide Directly

We may collect personal information when you:

 

  • complete a contact form

  • book a discovery call

  • communicate with us by email or LinkedIn

  • become a client


This may include:
 

  • name

  • organisation name

  • email address

  • phone number

  • job title

  • enquiry details


B. Platform Data (EcoTracker Pro)

When clients use our sustainability platform, we may process:

 

  • sustainability and environmental performance data

  • organisational policies and reports

  • emissions and operational information

  • staff names or contact details uploaded by clients


This data is processed solely to deliver sustainability consulting and platform services.

C. Website Usage Data

Our website is hosted via Wix and may automatically collect:

 

  • IP address

  • browser type

  • device information

  • pages visited

  • cookies and analytics data


This information helps us improve website performance and user experience.

4. How We Use Your Information

We use personal data to:

 

  • respond to enquiries and provide services

  • manage client relationships

  • deliver sustainability consulting services

  • operate and maintain the EcoTracker Pro platform

  • improve our website and services

  • comply with legal obligations


We do not sell personal data.

5. Legal Basis for Processing

Under UK GDPR, we rely on the following lawful bases:

 

  • Contractual necessity – to provide agreed services

  • Legitimate interests – responding to enquiries and business communications

  • Legal obligation – regulatory or compliance requirements

  • Consent – where required (e.g. cookies)


6. Marketing Communications

We do not send marketing newsletters.

We may contact individuals who have made enquiries or engaged with us regarding relevant services or business discussions. You may request that we stop contacting you at any time.


7. Data Sharing

We only share personal data where necessary to operate our business, including with trusted service providers such as:

 

  • Wix (website hosting)

  • Google Workspace (email and document management)

  • PandaDoc (document management)

  • Stripe (payment processing)


These providers process data under appropriate security and data protection safeguards.

We do not sell or rent personal data to third parties.


8. International Data Transfers

Some service providers may store or process data outside the UK. Where this occurs, appropriate safeguards are used in accordance with UK GDPR requirements.

9. Data Retention

We retain personal data only for as long as necessary:

 

  • Enquiry data: typically up to 24 months

  • Client data: for the duration of services and required legal retention periods

  • Platform data: as agreed with clients or until account closure


10. Data Security

We take appropriate technical and organisational measures to protect personal data, including:

 

  • secure cloud-based systems

  • restricted access controls

  • encrypted service providers where available


11. Cookies

Our website uses cookies to ensure proper functionality and improve user experience.

A cookie banner allows users to manage cookie preferences. For more details, please see our Cookie Policy (if applicable).


12. Your Data Protection Rights

Under UK GDPR, you have the right to:

 

  • access your personal data

  • request correction of inaccurate data

  • request deletion of your data

  • restrict or object to processing

  • request data portability

  • withdraw consent where applicable


To exercise these rights, contact:

dom@hindsightsustainability.co.uk


13. Complaints

If you believe your data has been handled improperly, you may contact the UK supervisory authority:

Information Commissioner’s Office (ICO)
https://www.ico.org.uk


14. Changes to This Policy

We may update this Privacy Policy from time to time. Updates will be posted on this page with a revised “Last updated” date.

bottom of page