Privacy

Privacy Policy

This policy explains what enquiry data Charterstead Systems collects through the website, why it is collected, how it is stored, and how to request an update or deletion.

Controller

Charterstead Systems Ltd is the controller for the public website and lead-capture forms.

This policy applies to https://chartersteadsystems.co.uk and to fit-call or Operational Systems Audit enquiries submitted through the site.

What data may be collected

  • Name, work email address, company, role, and industry.
  • Enquiry details submitted through the fit-call and Operational Systems Audit forms.
  • Limited technical and anti-spam information such as source page, UTM values, submission timing, and hashed rate-limit identifiers.

Why the data is collected

  • To assess whether there is a genuine consultancy fit.
  • To reply with the most useful next step for the enquiry.
  • To protect the site and forms from spam, repeated abuse, and obvious bot traffic.
  • To maintain a basic operational record of legitimate business enquiries and follow-up.

How enquiries are stored

Form submissions are written to the consultancy's SQLite database and sent to the owner inbox through the configured SMTP notification path. The launch hosting model is a Debian-based Linux environment running the same C++ runtime that serves the public site. The GTM container ID is treated as public browser configuration, while SMTP credentials, database paths, and other server settings remain server-only secrets.

Retention

Enquiry submissions are kept only while they remain commercially relevant and are reviewed at least every 12 months. Rate-limiting and abuse-protection records are retained for up to 30 days unless they are needed longer to investigate misuse.

Third-party support and processors

  • The founder/operator of the consultancy for review and response.
  • Hosting, backup, DNS, or email providers where that is necessary to run the website or respond to an enquiry.
  • Professional advisers or service providers where that is required to protect legitimate business, legal, or operational interests.

Analytics and booking

The launch website uses a form-first fit-call flow and does not use a public embedded booking widget. Analytics are disabled at launch, so the public site does not load a live Google Tag Manager container or analytics cookies in the public experience.

The tracked analytics events currently cover page views, CTA interactions, service-card journeys, case-study views, and safe form lifecycle measurement. When GTM is enabled, it runs only in the consent-safe mode described in the Cookie Policy: no advertising or remarketing tags, no non-essential analytics cookies before consent, and no names, email addresses, company names, or free-text problem descriptions in analytics payloads. UTM attribution is carried into form submissions and stored alongside the enquiry record in SQLite so lead source can be reviewed without sending sensitive enquiry content to analytics.

Deletion and privacy requests

Privacy, deletion, or correction requests should be sent to [email protected]. If you need to know what enquiry data is currently held about you, use that address and include enough context for the request to be matched safely.

Next step

Need to review the lead-capture flow itself?

If you want to review the actual lead-capture journey described by this policy, the fit-call page is the clearest place to start.

Book an Operational Systems Fit Call