Privacy policy
How we handle personal data, and what your rights are.
The short version. This website uses no analytics and tracks nobody. Every page but one sets no cookies at all; the exception is the booking page, which shows Cal.com's calendar so you can pick a time. If you send us an enquiry we use your details to reply to it, and for nothing else. We never sell personal data, and we never put client information into public AI models. You can ask us what we hold about you at any time and we will tell you.
Who we are
Northridge Systems is a trading name of New Media Solutions Ltd (“we”, “us”), a technology consultancy registered in England and Wales under company number 15898572 and based in Buckinghamshire, United Kingdom. New Media Solutions Ltd is the data controller for the personal data described in this policy, which means we decide why and how it is used.
You can reach us about anything in this policy by email or phone:
New Media Solutions Ltd, trading as Northridge Systems
Registered in England and Wales, company no. 15898572
Buckinghamshire, United Kingdom
contact@northridgesystems.co.uk
01844 899165
What we collect, and why
When you contact us
The contact form asks for your name and email address, and optionally your business name, phone number and a description of what you would like help with. If you reached the form from one of the pages about a particular problem, the enquiry also records which of the three it was, so we know what you want to talk about before we reply. If you email us directly, we hold whatever you choose to put in the email. We use these details to reply to your enquiry, to arrange and carry out the conversation, and to follow up on it.
We do not add enquirers to a mailing list, and we do not send marketing you have not asked for.
When you book a review
The booking page shows a calendar provided by Cal.com, embedded in the page. It loads from Cal.com when you reach the calendar, so Cal.com receives your IP address and browser details at that point, and it may set cookies of its own in order to work. When you book, the name, email address and anything else you type into it go to Cal.com, which sends us the booking and puts it in our diary. We use those details to hold the meeting and to follow it up, and for nothing else.
If you would rather not use it, the same page carries a plain link, and the contact form and our email address and phone number reach us just as well. Cal.com's own privacy notice covers what they do with it.
When you become a client
During an engagement we hold the contact details of the people we work with, notes and documents about the work, and the records we need for invoicing and accounts. Our work sometimes gives us access to systems containing personal data about your customers or staff. Where that happens we are acting on your instructions as a processor, not as the controller of that data, and it is covered by the terms of the engagement rather than by this policy.
When you visit this website
The web server keeps standard access logs - IP address, date and time, the page requested, and the browser's user-agent string. These exist to keep the site running securely and to diagnose faults. They are not used to build a profile of you or to identify individual visitors.
The client portal sign-in form does not currently authenticate anyone: it displays a message telling existing clients to email us. Nothing typed into it is transmitted or stored.
Cookies and tracking
This website sets no cookies of its own, anywhere. There is no analytics, no advertising, no tracking pixels and no social media embeds. Web fonts are served from this site rather than from a font provider, so reading these pages does not tell any third party that you were here.
One page is different. The booking page embeds Cal.com's calendar, and that embed is Cal.com's software running in a frame inside our page: it can set cookies and it sees your IP address and browser. Nothing else on this site does, and the embed does not follow you to any other page. We have taken the view that a visitor who has opened the booking page in order to book has asked for the calendar, which is why you are not stopped by a banner first. If you would rather not load it, do not open that page: the contact form, our email address and our phone number are on every other page and reach us the same way.
Our legal bases for using it
Under UK GDPR we need a lawful basis for each use of personal data. Ours are:
- Legitimate interests - replying to enquiries, running our business, and keeping this website secure. Our interest is in answering people who contact us; the data involved is minimal and it is what you would expect us to do with it.
- Steps taken before entering a contract, and performance of a contract - quoting for work, and then delivering it.
- Legal obligation - keeping accounting and tax records.
Who else sees your information
We do not sell personal data, we do not share it for anyone else's marketing, and we never use client information to train public AI models.
A small number of suppliers process data on our behalf, under contract and only on our instructions:
- the service that delivers contact-form submissions to our inbox;
- Cal.com, which runs the booking calendar and holds the bookings made through it;
- our email and business software providers;
- the hosting provider that runs this website;
- our accountant, for invoicing and tax records.
We will name any of these on request. We also disclose information where the law requires it.
Some of these suppliers operate outside the UK. Where personal data is transferred abroad, we rely on the UK government's adequacy regulations or on the International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses) to keep it protected to a UK standard.
How long we keep it
- Enquiries that do not lead to work - up to 12 months, then deleted.
- Client records - for the engagement and for six years afterwards, which is the period HMRC requires for financial records and roughly the period in which a contract claim can be brought.
- Website access logs - a short rolling window, typically no more than 30 days.
If you ask us to delete something sooner, we will unless we are legally required to keep it.
How we protect it
Access is limited to the people who need it and is removed when an engagement ends. Accounts are protected with multi-factor authentication where the service supports it, this website is served only over HTTPS, and we keep the systems we control patched. No system is perfectly secure, but we take this seriously and will tell you promptly if something goes wrong that affects you.
Your rights
You have the right to ask us to:
- tell you what personal data we hold about you, and give you a copy;
- correct anything inaccurate, or complete anything incomplete;
- delete it, where we have no continuing reason to keep it;
- restrict or stop a particular use of it, including any use based on legitimate interests;
- provide it in a portable format, where it was given to us electronically.
Email contact@northridgesystems.co.uk and we will respond within one month. There is no charge.
If you are unhappy with how we have handled your data, please tell us first so we can put it right. You can also complain to the Information Commissioner's Office, the UK's data protection regulator, at ico.org.uk/make-a-complaint or on 0303 123 1113.
Changes to this policy
If we change how we use personal data we will update this page and the date below. This is version 1.0.
Last updated: 14 August 2026