ShervGok Ltd respects your privacy and is committed to protecting your personal information in accordance with applicable United Kingdom data-protection legislation.
1. About this privacy policy
This privacy policy applies when you visit our website, communicate with us, submit an enquiry, request information, discuss a potential instruction, engage our services, attend a training activity, work with us as a supplier or associate, or otherwise provide personal information to ShervGok Ltd.
This policy should be read together with our Cookies Policy, Website Terms and Conditions and, where applicable, any project-specific, contractual or supplementary privacy information we provide.
2. Who we are
ShervGok Ltd is an engineering consultancy and advisory business registered in England and Wales.
For the purposes of applicable data-protection law, ShervGok Ltd is generally the data controller responsible for deciding why and how personal information covered by this policy is processed.
ShervGok Ltd1 Lancaster Gardens
Coventry
England
CV6 6HF
Email: info@shervgok.co.uk
Website: www.shervgok.co.uk
3. The personal information we may collect
The personal information we collect depends on how you interact with us. It may include the following categories.
3.1 Identity and contact information
- Your name and professional title.
- Your organisation or employer.
- Your business or personal email address.
- Your telephone number.
- Your business address or correspondence address.
- Your professional role, department and organisational responsibilities.
3.2 Enquiry and correspondence information
- Information you enter into our website contact form.
- The subject and content of emails or other communications sent to us.
- Information about a proposed project, service, partnership, training requirement or other enquiry.
- Records of our communications and responses.
3.3 Client and project information
- Information needed to assess, scope and deliver a consultancy, advisory, construction-support or training commission.
- Contract, proposal, quotation, purchase-order and instruction information.
- Project contacts, stakeholders and authorised representatives.
- Technical correspondence, meeting notes and project records that identify individuals.
- Site-access, induction, competency or health-and-safety information where relevant to an assignment.
3.4 Supplier, associate and business-partner information
- Contact and organisational information.
- Professional qualifications, competencies and relevant experience.
- Insurance, compliance, contractual and due-diligence information.
- Bank and payment information where required to administer a legitimate commercial relationship.
3.5 Training and event information
- Registration and attendance information.
- Professional role, experience and learning requirements.
- Assessment, participation or completion information, where relevant.
- Feedback provided about a training activity.
3.6 Website and technical information
When you use our website, our hosting and security infrastructure may automatically process limited technical information, including:
- Internet Protocol address.
- Browser type and operating system.
- Date and time of access.
- Pages or resources requested.
- Referring website or source, where available.
- Technical error, security and server-log information.
This technical processing may be necessary to deliver the website, maintain security, diagnose faults, prevent misuse and protect our systems.
4. How we collect personal information
We may collect personal information:
- directly from you;
- through the contact form on our website;
- through email, telephone or written correspondence;
- during meetings, workshops, training activities or project delivery;
- through contracts, quotations, proposals and procurement processes;
- from your employer, colleague, client, consultant, contractor or authorised representative;
- from publicly available professional or corporate sources;
- from professional advisers, project partners or due-diligence providers where lawful and appropriate;
- through our website hosting and security systems.
5. How and why we use personal information
We may process personal information for the following purposes:
- responding to enquiries and requests;
- assessing whether we can provide requested services;
- preparing proposals, quotations, scopes and contracts;
- taking steps at your request before entering into a contract;
- delivering consultancy, advisory, technical, construction-support or training services;
- managing client, supplier, associate and partner relationships;
- administering meetings, projects, training and events;
- issuing and processing invoices and payments;
- maintaining appropriate business, contractual and project records;
- managing professional, technical, commercial and health-and-safety risks;
- obtaining professional, legal, financial, insurance or technical advice;
- establishing, exercising or defending legal claims;
- preventing fraud, misuse, cyber incidents and other unlawful activity;
- securing, maintaining and improving our website and business systems;
- complying with legal, regulatory, insurance, tax, accounting and professional obligations;
- communicating relevant business information where permitted by law.
6. Our lawful bases for processing
Data-protection law requires us to identify a lawful basis for processing personal information. Depending on the circumstances, we may rely on one or more of the following.
6.1 Contract
Processing may be necessary to perform a contract with you or to take steps at your request before entering into a contract. This may include responding to a request for services, preparing a quotation, administering an instruction or delivering an agreed service.
6.2 Legitimate interests
We may process personal information where this is necessary for our legitimate business interests or those of another organisation, provided those interests are not overridden by your rights and interests.
Our legitimate interests may include:
- operating and developing a professional engineering consultancy;
- responding to business enquiries;
- managing professional relationships;
- delivering, administering and improving our services;
- maintaining accurate business and project records;
- protecting our organisation, clients, systems and reputation;
- preventing fraud, security incidents and misuse;
- establishing, exercising or defending legal rights;
- communicating with existing professional contacts about relevant services, where lawful.
6.3 Legal obligation
We may process personal information where necessary to comply with a legal obligation, including applicable taxation, accounting, company, employment, health-and-safety, anti-fraud or regulatory requirements.
6.4 Consent
We may rely on consent where the law specifically requires it or where consent is the most appropriate lawful basis. Where processing is based on consent, you may withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing carried out before consent was withdrawn.
6.5 Legal claims and vital interests
In limited circumstances, we may process information where necessary to protect a person's vital interests or for the establishment, exercise or defence of legal claims.
7. Website contact form
Our website contact form is used to send an enquiry directly to:
The form may request your name, organisation, email address, telephone number, enquiry subject and message.
The website is not designed to write contact-form submissions to a website database, spreadsheet or local enquiry file. However:
- the submitted information is transmitted through the website server so that the email can be generated;
- the resulting email is retained within our email system and mailbox;
- hosting, network and security providers may process limited technical logs as part of operating and protecting their services;
- temporary server memory or session information may be used to validate and secure the submission.
You should not use the general contact form to send highly sensitive personal information, passwords, payment-card information, confidential medical information or unnecessary special-category information.
Where sensitive or confidential project material needs to be transferred, please contact us first so that an appropriate transfer method can be agreed.
8. Special-category and criminal-offence information
We do not normally seek to collect special-category information through our public website. Special-category information includes information concerning health, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade-union membership, genetic or biometric identification, sex life or sexual orientation.
Where it is necessary for us to process special-category or criminal-offence information, we will identify an appropriate legal basis and any additional condition required by law. We will apply additional safeguards where appropriate.
9. Cookies and similar technologies
Our website may use essential technologies required for security and functionality. For example, the secure contact form may use a temporary session cookie to help protect the form against unauthorised or fraudulent submissions.
Essential cookies and technologies are used only where necessary to provide or secure a service requested by the user.
We will not knowingly deploy non-essential analytics, advertising or tracking cookies without providing appropriate information and obtaining consent where the law requires it.
Further information is available in our Cookies Policy.
10. Who we may share personal information with
We do not sell personal information to third parties.
Where necessary and lawful, we may share relevant personal information with:
- our directors, authorised personnel and professional associates;
- specialist consultants, subcontractors and project partners involved in an agreed assignment;
- clients, contractors, consultants and infrastructure stakeholders where required for project delivery;
- website hosting, email, information-technology, cybersecurity and communications providers;
- accounting, banking, payment and financial-service providers;
- insurers, insurance brokers and professional-indemnity advisers;
- solicitors, accountants, auditors and other professional advisers;
- public authorities, courts, regulators, law-enforcement bodies or other organisations where disclosure is required or permitted by law;
- a prospective purchaser, investor or successor in the context of a genuine business restructuring, investment, merger, acquisition or transfer, subject to appropriate safeguards.
We aim to share only the information reasonably required for the relevant purpose.
Where an external organisation processes personal information on our behalf, we seek to use providers offering appropriate contractual, organisational and technical protections.
11. International transfers
ShervGok may work with clients, advisers, associates, suppliers or project partners outside the United Kingdom. Some technology, hosting, communications or cloud-service providers may also process information using infrastructure located outside the United Kingdom.
Where personal information is transferred internationally, we will take reasonable steps to ensure the transfer is lawful and that appropriate protections are applied. These may include:
- transfer to a country covered by a United Kingdom adequacy regulation;
- use of approved contractual safeguards;
- appropriate transfer-risk assessment and supplementary protections;
- another transfer mechanism permitted by applicable law.
12. How long we retain personal information
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including any legal, accounting, insurance, contractual, professional and reporting requirements.
Retention periods may vary depending on the nature of the information and relationship. Our general approach is as follows:
- Unsuccessful or preliminary enquiries: normally reviewed for deletion within 24 months after the last meaningful communication, unless a longer period is justified.
- Client and project records: normally retained for the duration of the commission and for an appropriate period afterwards, taking account of contractual limitation periods, professional obligations, insurance requirements and potential claims.
- Contracts, invoices and accounting records: retained for the period required by applicable company, tax and accounting rules.
- Supplier and associate records: retained for the duration of the relationship and for an appropriate period afterwards for contractual, accounting, assurance and legal purposes.
- Training and attendance records: retained for a period proportionate to certification, contractual, quality-assurance and professional development requirements.
- Website security and server logs: retained according to the operational and security settings of our hosting and technology providers and normally for a limited period.
Information may be retained for longer where reasonably necessary in relation to an actual or anticipated dispute, legal claim, regulatory matter, fraud investigation or statutory requirement.
When personal information is no longer required, we will take reasonable steps to delete it, securely destroy it or anonymise it.
13. Information security
We apply reasonable technical and organisational measures intended to protect personal information against accidental or unlawful loss, misuse, alteration, unauthorised access, disclosure or destruction.
These measures may include:
- HTTPS encryption for the website;
- server-side form validation and security controls;
- restricted access to business systems and mailboxes;
- authentication and password-management controls;
- appropriate device and software security measures;
- secure backup and recovery arrangements where appropriate;
- confidentiality obligations for authorised personnel and advisers;
- due diligence when engaging relevant service providers;
- review and management of suspected personal-data incidents.
No internet transmission, email system or digital-storage method can be guaranteed to be completely secure. You should therefore take appropriate care when deciding what information to send electronically.
14. Your data-protection rights
Depending on the circumstances and applicable law, you may have the following rights:
14.1 Right of access
You may ask whether we process your personal information and request a copy of the information we hold about you.
14.2 Right to rectification
You may ask us to correct inaccurate personal information or complete information that is incomplete.
14.3 Right to erasure
You may ask us to delete your personal information in circumstances where the law provides this right. The right is not absolute, and we may need to retain information where there is a lawful reason to do so.
14.4 Right to restrict processing
You may ask us to restrict the processing of your information in certain circumstances.
14.5 Right to object
You may object to processing based on legitimate interests. We will consider your objection and stop the processing unless we have compelling legitimate grounds to continue or the information is required for legal claims.
You have an absolute right to object to the use of your personal information for direct marketing.
14.6 Right to data portability
Where applicable, you may request that certain information provided by you be supplied in a structured, commonly used and machine-readable format or transferred to another controller.
14.7 Right to withdraw consent
Where we rely on consent, you may withdraw it at any time.
14.8 Rights relating to automated decision-making
You may have rights where a decision producing legal or similarly significant effects is made solely by automated means.
ShervGok does not currently use solely automated decision-making through this website to make decisions that have legal or similarly significant effects on individuals.
15. Exercising your rights
To exercise a data-protection right, contact:
Please include sufficient information to help us identify the relevant records and understand your request. We may need to ask for appropriate evidence of identity before disclosing or changing personal information.
We will respond within the time required by applicable law. In some circumstances, the law permits the response period to be extended or a request to be refused. Where this applies, we will explain the position.
Data-protection requests are generally handled without a fee. However, the law may permit a reasonable fee or refusal where a request is manifestly unfounded or excessive.
16. Direct marketing
We do not currently use the website contact form to enrol individuals automatically in marketing communications.
Where we send direct marketing, professional updates or information about services, we will do so only where permitted by applicable data-protection and electronic communications law.
You may ask us to stop direct marketing at any time by emailing:
17. Links to external websites
Our website may contain links to websites operated by third parties. We do not control those websites and are not responsible for their privacy practices, security or content.
You should review the privacy information provided by the relevant third party before submitting personal information to an external website.
18. Children's information
Our website and services are primarily intended for organisations, engineering professionals, adult learners and business contacts. They are not directed at children.
We do not knowingly use the public website to collect personal information from children. If you believe a child has provided personal information to us through the website, please contact us so that the circumstances can be reviewed.
19. Data breaches
We take suspected personal-data breaches seriously. Where a breach occurs, we will assess the nature, scope and potential consequences and take proportionate steps to contain and investigate it.
Where required by law, we will notify the Information Commissioner's Office and affected individuals within the applicable timescales.
20. Complaints
We encourage you to contact us first if you have a concern about how we have handled your personal information. We will seek to investigate and respond appropriately.
You also have the right to complain to the United Kingdom's data-protection regulator:
Information Commissioner's OfficeWycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
Website: https://ico.org.uk/make-a-complaint/
21. Changes to this privacy policy
We may update this privacy policy periodically to reflect changes to our services, systems, legal obligations, operating arrangements or data-processing activities.
The current version will be published on this page and the date at the top will be updated. Where a change is material, we may take additional reasonable steps to bring it to the attention of affected individuals.
22. Contact us
Questions, requests and concerns relating to this privacy policy or our use of personal information should be sent to:
ShervGok Ltd1 Lancaster Gardens
Coventry
England
CV6 6HF
Email: info@shervgok.co.uk
Have a privacy or data-protection question?
Contact ShervGok and provide sufficient information for us to understand and respond to your request.