naked Agility Limited is committed to protecting your privacy and handling your personal data responsibly. This policy explains what we collect, why we collect it, who we share it with, how long we keep it, and your rights under UK GDPR and the Data Protection Act 2018.

We follow a fit-for-purpose information security model tailored to the nature and scale of a small consulting practice. Our privacy and security practices align with the intent of ISO/IEC 27001 and NIST CSF as they apply to that model.

Please also refer to our Terms of Business for the conditions governing engagements and bookings.

Who We Are

naked Agility Limited is registered in Scotland, company number SC451660, with its registered office at 47 Ballantrae Crescent, Newton Mearns, Glasgow, G77 5TX. naked Agility Limited is the data controller for the personal data described in this policy. Martin Hinshelwood, Managing Director, is responsible for information security and privacy.

Contact: clientservices@nkdagility.com

Data We Collect

Consulting Engagements

When you enquire about or engage us for consulting we collect and process:

Payment details are processed by our invoicing provider; we do not store card numbers.

Website Visits and Measurement

Our websites count how their pages are found, read and returned to. When you view a page we record the view, how far down the page you scrolled, how long you were actively reading, whether you copied anything, whether you followed a link to another of our sites, and playback progress on pages that carry a video. These are statistics about pages, not about you. No IP address, no browser fingerprint, no full referring URL, only the referring site’s hostname, and nothing you type is ever recorded. Each site describes this on its own /measurement/ page, where a single button switches it off.

Enquiry and Contact Forms

If you use an enquiry form we collect your name, email address, organisation, the content of your message, and any context the form asks for. The form is protected by Cloudflare Turnstile, which checks that a request came from a person; Cloudflare processes your request to do that. We do not store your IP address. The submission is delivered to us by email and also held in the website’s own store, which deletes it automatically after twelve months. Only operators holding a specific clearance can read that store.

Accounts, Hearts, Bookmarks and Notifications

You can use every site without an account. If you choose to sign in we hold the email addresses you sign in with, a profile photo if you add one, and the features that are yours: your hearts, bookmarks, votes and a viewing history you can clear or turn off from your account pages. If you subscribe to email notifications we hold your address and the topics you chose. Your account and your notification preferences are never joined to website measurement. You can heart a page without an account; that adds one to the page’s count and records nothing about you.

Comments

Comments on our content are provided by giscus and stored as GitHub Discussions in a public GitHub repository. Commenting needs a GitHub account and is governed by GitHub’s own terms and privacy policy. We receive nothing about you beyond what is public in that discussion.

Why We Use Your Data

Purpose Lawful basis
Scope and contract an engagement or booking, and issue an invoice Contract
Deliver the engagement or training, and register a credential with the certifying body Contract
Send engagement, course and booking communications Contract
Respond to enquiries Legitimate interest
Send the email notifications you subscribed to, and occasional updates about relevant services or content, which you can stop at any time Consent
Provide the account features you signed up for Contract
Comply with tax and accounting obligations Legal obligation
Improve our websites and understand how they are used Legitimate interest

We do not use your data for automated decision-making or profiling, and we never sell it.

Cookies and Measurement

Our websites set no advertising or tracking cookies and load no third-party trackers or pixels. Measurement uses one first-party cookie, nkda_mid, a random identifier that means nothing outside the site, kept for thirteen months, whose only job is to tell one person returning apart from many people visiting once. There is no cookie banner because there is nothing to trade consent for: the measurement is statistics about the site, used only to improve it, under the statistical exception in the UK Privacy and Electronic Communications Regulations. Every site pairs the cookie with a plain-language /measurement/ page and a one-click opt-out toggle in its footer; opting out removes the cookie and stops all measurement for you. When an operator signs in, measurement is switched off for that browser so our own visits do not distort the numbers.

A second first-party cookie, nkda_appearance, remembers the colour mode and text font you chose. If you sign in, the sign-in provider sets the cookies it needs to keep you signed in, and your appearance choices are also saved to your account.

Third-Party Services

We share personal data only with the services we need to operate. Every provider is bound by an appropriate data processing agreement.

Consulting Practice Tooling

Service Purpose Data region
Microsoft 365 Email, calendar, document storage, meeting recordings and transcriptions, including Copilot United States
FreshBooks Invoicing, billing and customer management United States
Remarkable Note-taking and documentation Norway
Azure DevOps Software development, work item management and migration activities European Union and United States
GitHub Software development and collaboration, including GitHub Copilot Global, primarily United States
1Password Secure storage of passwords, keys and sensitive information Global
ChatGPT, OpenAI Enterprise Structured analysis, summarisation and AI-supported engineering insight. Prompts and responses are excluded from training and are not retained European Union

We do not use free-tier or consumer-grade AI services. All AI tools used in our practice are enterprise-grade and configured for privacy, security and data sovereignty.

Website Services

Service Purpose Data region
Microsoft Entra External ID Sign-in to your account by email one-time code, Google, or a Microsoft work account European Union
Cloudflare Turnstile Checking that a form submission came from a person Global
Microsoft Azure Communication Services Sending the email notifications you subscribed to United Kingdom
GitHub Discussions, via giscus Comments on our content Global, primarily United States

To support efficient and accurate legal and policy comparison, naked Agility Limited may use OpenAI’s Enterprise platform to review and analyse customer-submitted legal documents, for example Data Processing Agreements, information security questionnaires and Master Service Agreements. This includes comparing customer terms to our published Terms of Business, Privacy Policy and engagement model, identifying potential conflicts, gaps or redlines for discussion, and drafting suggested responses to customer-supplied clauses. We use OpenAI Enterprise hosted in the European Union: no data is used for training, no inputs or outputs are retained by OpenAI, data is encrypted in transit, and we do not share these inputs with any unauthorised party. We do not process sensitive personal data, such as health, financial or identity documents, through AI, and we redact or anonymise sensitive content before use.

Data Retention

Data type Retention period
Contract and invoice records 7 years, UK tax law
Consulting and migration engagement records 5 years
Training attendance records 5 years
Enquiry form submissions 12 months in the website’s store, deleted automatically; the email copy 2 years from last contact
Website measurement records Indefinitely, because a library is judged over years. They are anonymous and identify no one
Account data Until you delete your account
Notification subscriptions Until you unsubscribe
Notification suppression list Permanently. When you unsubscribe or complain, your address is kept so that we never email you again

Your Rights

Under UK GDPR you have the right to:

To exercise any of these rights, contact us. We will respond within 30 days. If you are not satisfied with our response you have the right to lodge a complaint with the Information Commissioner’s Office at ico.org.uk.

Security

All our infrastructure uses encryption at rest on hardware equipped with Trusted Platform Module technology, and every system is kept current with operating system and application patches. We rely on automatic patching, Microsoft Defender for real-time threat protection, and ongoing security hygiene: system health monitoring, access review and secure configuration baselines. Our websites use HTTPS throughout. Engagement and booking administration data is held within Microsoft 365 and FreshBooks, both of which provide encryption at rest and in transit, and access is restricted to authorised personnel.

Changes to This Policy

We review this policy periodically. The date at the top of this page reflects the most recent update, and the latest version is always available on our websites. Significant changes will be communicated by email to active customers.

Contact

For privacy questions or data requests, email clientservices@nkdagility.com or use our contact form.