Last updated: 29 July 2026
Who we are
Niltir provides technology architecture, engineering, delivery, and operational services. Niltir is the controller responsible for the personal information described in this notice.
For privacy questions or requests, email hello@niltir.com.
Information we collect
We may collect:
- your name, work email address, company, role, phone number, and professional contact details;
- information you include in a website enquiry, email, meeting, project brief, proposal, contract, or other correspondence;
- business relationship information, including the source of an introduction, contact history, preferences, and whether you asked us not to contact you;
- publicly available professional information used for relevant business outreach, such as information published on a company website, official announcement, professional profile, supplier directory, or public business register; and
- limited technical and security information generated when you use the website, such as IP address, request metadata, timestamps, and abuse-prevention signals.
Please do not send passwords, private keys, patient data, special-category personal data, or other sensitive information through the project brief form.
How we use personal information
We use personal information to:
- review and respond to website enquiries and direct messages;
- discuss potential work and take steps before entering into a contract;
- deliver services, manage client and supplier relationships, and keep appropriate business records;
- conduct proportionate business-to-business outreach where we reasonably believe Niltir's services may be relevant;
- operate, secure, troubleshoot, and improve the website and enquiry process;
- prevent spam, fraud, misuse, and security incidents; and
- meet legal, regulatory, accounting, and contractual obligations.
The fields marked as required on the project brief form are needed to submit an enquiry through that form. If you do not provide them, use the direct email route instead. We do not use the information described in this notice to make solely automated decisions that produce legal or similarly significant effects.
Our lawful bases
Depending on the context, we rely on:
- steps before a contract and performance of a contract when you ask us to discuss or deliver work;
- legitimate interests in responding to business enquiries, developing relevant business relationships, conducting proportionate business outreach, operating the website, and protecting our systems;
- legal obligations where records or disclosures are required by law; and
- consent where the law requires it. You may withdraw consent at any time.
When we rely on legitimate interests, we consider the relevance of the contact, the reasonable expectations of the person concerned, the nature of the information, and the person's right to object.
Business outreach
We may contact people at corporate organisations using professional contact details obtained from public business sources, referrals, or previous business interactions. We keep outreach narrow, relevant to the person's professional role, and identifiable as coming from Niltir.
You may object to direct marketing at any time. Reply to the message or email hello@niltir.com with your request. We will stop the outreach and may retain the minimum information needed to maintain a suppression record and honour the request.
Who we share information with
We do not sell personal information.
We may share information only where necessary with:
- hosting, security, email, storage, and other service providers that support the website and our work, including Cloudflare and Google Workspace;
- professional advisers, insurers, auditors, or subcontractors where appropriate and subject to suitable obligations;
- a prospective buyer or successor if the business is reorganised or transferred; and
- courts, regulators, law-enforcement bodies, or other authorities where required by law or necessary to protect legal rights.
International transfers
Some service providers may process information outside the United Kingdom. Where required, we use recognised safeguards such as adequacy regulations or approved contractual protections.
Retention
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected:
- unsuccessful website enquiries and related correspondence are normally retained for up to 24 months after the last meaningful contact;
- business outreach records are reviewed at least every 12 months and removed when they are no longer relevant;
- client, contract, accounting, and legal records may be retained for longer where required by law or needed to establish or defend legal claims;
- security and abuse-prevention records are retained for a limited period appropriate to the risk; and
- suppression records may be kept for as long as necessary to ensure we do not contact someone who has objected.
We may delete or anonymise information earlier when it is no longer needed.
Security
We use proportionate technical and organisational measures intended to protect personal information against unauthorised access, loss, misuse, or alteration. No internet service is completely secure, so please use the direct email route if you need to discuss how confidential material should be transferred.
Cookies and similar technologies
The Niltir website does not currently use non-essential advertising or behavioural-tracking cookies. Essential technical storage may be used where required to provide or protect the service. If this changes, we will update this notice and provide any consent controls required by law.
Your rights
Depending on the circumstances, you may have the right to:
- request access to your personal information;
- ask us to correct inaccurate or incomplete information;
- ask us to delete information;
- ask us to restrict how information is used;
- object to processing based on legitimate interests;
- object to direct marketing at any time;
- request data portability where applicable; and
- withdraw consent where processing relies on consent.
To exercise a right, email hello@niltir.com. We may need to verify your identity before completing a request.
You may also complain to the UK Information Commissioner's Office or another data-protection authority that applies to you. We would appreciate the chance to address the concern first.
Changes to this notice
We may update this notice when our services, suppliers, or legal obligations change. The latest version will remain available at this address and will show its last-updated date.