Last updated: 24 April 2026
This Privacy Policy explains how Sustainability-Frisk ("we", "us", "our") collects, uses, stores and protects personal data when you visit sustainability-frisk.com, contact us, book a consultation, or purchase a report. We comply with the UK GDPR, the Data Protection Act 2018, and the EU GDPR where applicable.
Sustainability-Frisk, operated by Hufsa Moonis Mir
Unit 32a 227, Birmingham Road, Bromsgrove, United Kingdom, B61 0DD
Email: contact@sustainability-frisk.com
For all data-protection requests, contact the address above. We act as our own Data Protection contact.
| Category | Examples | Source |
|---|---|---|
| Identity & contact | Name, work email, company, country, phone (optional) | You — via forms, email, WhatsApp |
| Engagement | Message content, service of interest, meeting notes | You — via contact form, calls |
| Booking data | Date/time of consultation, time-zone | Calendly |
| Transaction data | Order ID, report type, billing email (we do not store card data) | Stripe / payment processor |
| Project data | Operational data you upload for CBAM, EUDR, LCA, CSRD reports (energy, supplier, product info) | You — during engagement |
| Technical | IP address, browser type, pages visited, referrer (server logs only) | Hostinger web logs |
We do not sell your data, profile you for advertising, or use it for automated decision-making.
| Data | Retention |
|---|---|
| Enquiry / contact form messages | 24 months from last contact |
| Client project files & reports | 7 years (UK statutory + audit defence) |
| Invoices & financial records | 6 years (HMRC requirement) |
| Calendly booking history | 12 months |
| Server access logs | 30 days |
We share data only with vetted processors who act on our instructions under written agreements (DPAs). Each is GDPR-compliant.
| Processor | Purpose | Location |
|---|---|---|
| Hostinger International Ltd. | Website hosting & email | EU (Lithuania) |
| Calendly LLC | Consultation scheduling | USA (SCCs in place) |
| Google LLC (Gmail / Workspace) | Business email | USA / EU (SCCs in place) |
| WhatsApp / Meta Platforms Inc. | Optional messaging channel | USA (SCCs in place) |
| Stripe Payments Europe Ltd. | Payment processing for reports | Ireland / USA (SCCs in place) |
Where data is transferred outside the UK/EEA (e.g. to US-based processors), we rely on the UK International Data Transfer Addendum, the EU Standard Contractual Clauses, and supplementary safeguards (encryption in transit and at rest). The UK is recognised as adequate by the European Commission.
Under UK and EU GDPR you have the right to:
To exercise any right, email contact@sustainability-frisk.com. We respond within 30 days at no cost.
If you believe we have mishandled your data, you can lodge a complaint with the UK supervisory authority:
Information Commissioner's Office (ICO) — ico.org.uk — Helpline 0303 123 1113.
EU residents may also complain to their local supervisory authority.
We use TLS/HTTPS site-wide, access controls on email and cloud storage, two-factor authentication on critical accounts, and encrypted backups. No transmission over the internet is 100% secure; we will notify affected users and the ICO within 72 hours of any qualifying personal-data breach.
Our services are B2B and not directed at anyone under 18. We do not knowingly collect data from children.
We do not currently send marketing newsletters. If we introduce them, they will be opt-in only with a clear unsubscribe link in every message.
We may update this policy to reflect changes in law or our services. The "Last updated" date at the top will change. Material changes affecting existing clients will be communicated by email.
Questions, requests, or complaints? Email contact@sustainability-frisk.com or write to the postal address above.