Privacy Policy
Effective date: 20 July 2026
1. Introduction and company information
This Privacy Policy explains how Harbourline Regional Services Ltd collects, uses, stores, shares, and protects personal data in connection with its regional business operations and services. It also explains your rights in relation to your personal data and how you can exercise them.
Harbourline Regional Services Ltd acts as the data controller for the personal data described in this Privacy Policy, meaning it determines the purposes and means of processing such data.
Company details:
- Company name: Harbourline Regional Services Ltd
- Address: Harbourline Regional Services, 24 Queen Street, Cardiff, CF10 2AG, UK
- Email: [email protected]
- Phone: +44 29 2046 7831
This Privacy Policy applies to personal data collected through our website, communications, service enquiries, client and supplier relationships, and any other interactions with Harbourline Regional Services Ltd.
2. Data collection and processing
We may collect and process the following categories of personal data:
- Identity data: name, title, and similar identifiers.
- Contact data: address, email address, telephone number, and other communication details.
- Business and service data: information relating to enquiries, requests, contracts, service preferences, correspondence, and records of interactions.
- Technical data: IP address, browser type, device information, operating system, and website usage data.
- Usage data: information about how you use our website, forms, email communications, or services.
- Transaction data: billing and payment-related information where relevant.
- Compliance data: data required for legal, regulatory, tax, accounting, or record-keeping purposes.
We may collect personal data directly from you, through your organisation, from our website, from communications with us, from service providers, and from publicly available sources where appropriate and permitted by law.
We process personal data using both automated and manual methods, depending on the nature of the interaction and the service provided.
3. Purpose of data processing
Harbourline Regional Services Ltd processes personal data for the following purposes:
- to respond to enquiries and provide information about our services;
- to enter into and perform contracts;
- to manage customer, supplier, and business relationships;
- to process invoices, payments, and related administrative functions;
- to communicate with you about our services, updates, and support matters;
- to operate, maintain, and improve our website, systems, and business processes;
- to ensure security, prevent fraud, and protect our rights and interests;
- to comply with legal, regulatory, and accounting obligations;
- to manage complaints, disputes, and legal claims;
- to send marketing communications where permitted by law and where you have not opted out, or where your consent has been obtained where required.
4. Legal basis for processing
We only process personal data where we have a lawful basis to do so. Depending on the circumstances, our legal bases may include:
- Performance of a contract: where processing is necessary to provide services, respond to requests, or fulfil contractual obligations.
- Legitimate interests: where processing is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. This may include administering our business, improving services, ensuring security, and managing communications.
- Legal obligation: where processing is required to comply with applicable laws, regulations, court orders, or lawful requests from public authorities.
- Consent: where you have given clear consent for a specific purpose, such as certain marketing communications where required by law.
- Vital interests: where processing is necessary to protect someone’s life or physical safety in exceptional circumstances.
Where we rely on legitimate interests, we will consider and balance any potential impact on your rights before processing your personal data.
5. Data sharing and third parties
We may share personal data with selected third parties where reasonably necessary for the purposes described in this Privacy Policy. These may include:
- IT and hosting providers;
- email, communication, and customer management service providers;
- payment processors and banking partners;
- professional advisers such as accountants, auditors, lawyers, and insurers;
- subcontractors and service partners involved in delivering our services;
- regulators, government bodies, law enforcement agencies, or courts where required by law;
- business transfer parties in connection with a merger, sale, restructuring, or transfer of assets.
We require third parties to handle personal data appropriately and to use it only for the specified purposes, subject to confidentiality and security obligations where applicable.
6. Data transfer to third countries
Some of our service providers or business partners may be located outside the United Kingdom or may process data in other countries. Where personal data is transferred internationally, Harbourline Regional Services Ltd will take appropriate steps to ensure an adequate level of protection in accordance with applicable privacy law.
These measures may include:
- transferring data to countries recognised as providing an adequate level of protection;
- using contractual safeguards such as standard contractual clauses or equivalent protections;
- implementing additional technical and organisational safeguards where necessary.
For more information about international transfers and the safeguards in place, you may contact us using the details below.
7. Storage duration
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, tax, regulatory, and reporting requirements.
The retention period depends on the nature of the data and the context of processing. In general:
- enquiry and correspondence data may be retained for a reasonable period after the last contact;
- contractual and transactional data may be retained for the duration of the relationship and for a further period required by law or for dispute resolution;
- marketing preference data is retained until you withdraw consent or object, or until it is no longer needed;
- technical and security logs are retained for a limited period unless longer retention is required for security, investigation, or legal reasons.
When personal data is no longer needed, we will securely delete, anonymise, or archive it where appropriate.
8. User rights
Subject to applicable law, you may have the following rights in relation to your personal data:
- Access: the right to request confirmation of whether we process your personal data and to receive a copy of that data.
- Rectification: the right to request correction of inaccurate or incomplete personal data.
- Erasure: the right to request deletion of your personal data in certain circumstances.
- Restriction: the right to request that we restrict processing in certain situations.
- Data portability: the right to receive certain personal data in a structured, commonly used, machine-readable format and to request transfer to another controller where technically feasible.
- Objection: the right to object to processing based on legitimate interests, and to object at any time to direct marketing.
We may need to verify your identity before responding to a request. If a request is clearly unfounded, repetitive, or excessive, we may be entitled to refuse it or charge a reasonable fee where permitted by law.
9. Withdrawal of consent
Where we rely on your consent to process personal data, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of processing carried out before the withdrawal.
You can withdraw consent by contacting us using the details provided in this Privacy Policy or by using any available unsubscribe or preference-management option included in our communications.
If you withdraw consent, we may still process your personal data where another lawful basis applies.
10. Right to complain
If you have concerns about how Harbourline Regional Services Ltd handles your personal data, we encourage you to contact us first so we can try to resolve the matter.
You also have the right to lodge a complaint with the relevant data protection supervisory authority in your jurisdiction. If you are in the UK, this will usually be the Information Commissioner’s Office (ICO).
We would appreciate the opportunity to address your concerns directly before you make a formal complaint.
11. Data security
We implement appropriate technical and organisational measures designed to protect personal data against accidental loss, unauthorised access, disclosure, alteration, or destruction.
These measures may include, where appropriate:
- access controls and authentication measures;
- secure storage and transmission methods;
- staff confidentiality obligations and training;
- system monitoring and regular security reviews;
- backup and recovery procedures;
- procedures for handling suspected data breaches.
While we take reasonable steps to protect your personal data, no method of transmission or storage is completely secure. We cannot guarantee absolute security.
12. Contact information
If you have any questions about this Privacy Policy, our data practices, or your rights, please contact:
- Harbourline Regional Services Ltd
- Address: Harbourline Regional Services, 24 Queen Street, Cardiff, CF10 2AG, UK
- Email: [email protected]
- Phone: +44 29 2046 7831
13. Changes to privacy policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. Any revised version will be published with an updated effective date where appropriate.
We encourage you to review this Privacy Policy periodically to stay informed about how Harbourline Regional Services Ltd processes personal data.
Where required by law, we will take reasonable steps to notify you of material changes.