Legal

Privacy Policy

Last updated: 29 September 2026

This Privacy Policy explains how Steerframe collects, uses, stores, and protects personal information when you visit our website, contact us, download a guide, complete a form, book a call, or work with us.

This policy is for general transparency. It does not replace any project-specific data processing agreement, client contract, statement of work, or professional advice.

Questions? Contact hello@steerframe.co

1. Who we are

Steerframe is based in Belfast and Dungannon, County Tyrone, Northern Ireland.

Steerframe helps SME manufacturers remove waste from operational processes, systems and information through process optimisation, digital automation and business intelligence.

Steerframe works with manufacturers across Northern Ireland, with selected work across Great Britain, the Republic of Ireland, the wider UK, and the EU where appropriate.

For the purposes of UK data protection law, Steerframe is the controller of personal information collected through this website, contact forms, guide downloads, direct enquiries, and general business administration.

Where Steerframe processes personal data on behalf of a client as part of a specific project, it may act as a processor. Project-specific processing should be covered by a separate client agreement, statement of work, or data processing agreement.

Contact: hello@steerframe.co

2. Scope

This Privacy Policy applies to:

  • website visitors
  • people who download guides or resources
  • people who submit enquiry forms or book calls
  • workshop, training, or event attendees
  • clients, suppliers, subcontractors, and collaborators

This policy is for general transparency about how Steerframe handles personal information. Project-specific data processing for paid client work may be covered separately in a client agreement, statement of work, or data processing agreement.

3. Geographic scope

This Privacy Policy is written with Northern Ireland and UK data protection law in mind, including the UK GDPR and the Data Protection Act 2018.

Where Steerframe works with clients, contacts, or individuals in the Republic of Ireland, the EU, or the EEA, additional EU or Irish data protection rules may apply depending on the circumstances. Where required, Steerframe will take reasonable steps to handle personal data in line with applicable obligations.

If a specific project involves EU personal data, Republic of Ireland personal data, or cross-border processing, additional terms may be needed before work begins.

4. What information we collect

We may collect personal information when you visit the website, complete a form, download a guide, book a call, attend a session, or work with us.

Information we collect may include:

  • name
  • work email address
  • company name
  • job title or role
  • phone number, if provided
  • enquiry details and form responses
  • booking or call details
  • workshop or training attendance information
  • business workflow information and AI use case details
  • system and tool information provided during discovery
  • billing and invoice information
  • basic website analytics such as pages visited, device type, browser, referral source, and approximate location

We ask that you do not send sensitive personal information through website forms unless it is necessary for a specific purpose you have agreed with us.

5. Sensitive information

Steerframe does not need sensitive personal information for general enquiries, guide downloads, or early-stage conversations.

Sensitive personal data includes information about health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, or sexual orientation.

You should also avoid sending the following through standard forms or ordinary email:

  • passwords
  • API keys or private credentials
  • secret access tokens
  • payment card details
  • confidential staff or HR records
  • sensitive client information
  • private legal, financial, or medical information

If a project genuinely requires access to sensitive or restricted information, this should be discussed first and handled through an agreed secure process.

6. How we use your information

We may use your information to:

  • respond to enquiries and provide requested downloads
  • book calls and arrange meetings
  • deliver operational diagnostics, process improvement, automation, business intelligence, or support services
  • prepare proposals and manage client relationships
  • send relevant follow-up about our services
  • improve the website and services
  • manage invoices, tax, accounting, and business administration
  • comply with legal, regulatory, tax, or reporting obligations
  • maintain website and system security

We do not sell personal information.

7. Lawful bases

Depending on the situation, we rely on one or more of the following lawful bases under UK data protection law.

Contract: where we need your information to provide a service, fulfil an agreement, or take steps before entering a contract.

Legitimate interests: where we have a legitimate business reason and your interests and rights are not overridden. This includes responding to enquiries, managing client relationships, improving our services, and maintaining security.

Consent: where you actively opt in to receive certain communications or follow-ups. You can withdraw consent at any time.

Legal obligation: where we are required to use information to comply with a legal, tax, accounting, or regulatory obligation.

8. Guides and lead magnets

If you download a free guide or resource, such as an operational waste guide or Responsible AI Use for SMEs, we may ask for your name, work email address, and company name.

We use this information to provide the guide and may send relevant follow-up about process optimisation, operational diagnostics, AI governance, or related Steerframe services.

Free guides are provided for practical business guidance only. They are not legal, data protection, regulatory, financial, or professional advice.

9. AI tools and automation

Steerframe may use AI and automation tools to support drafting, research, summarisation, workflow mapping, documentation, and service delivery.

Where client information is used with AI tools, Steerframe will aim to apply reasonable safeguards, including limiting the personal data involved, using appropriate business tools, applying human review before outputs are relied on, and respecting client confidentiality.

Steerframe does not intentionally place client confidential information, sensitive personal data, passwords, credentials, or restricted data into public AI tools unless there is a clear lawful basis, suitable safeguards, and client agreement or instruction.

AI-assisted outputs are reviewed before being relied on for client-facing work.

10. Sharing your information

We may share personal information with trusted third parties where necessary. This may include:

  • website hosting providers
  • email and calendar providers
  • CRM and form tools
  • analytics providers
  • payment processors
  • accountants and bookkeepers
  • professional advisers
  • subcontractors or technical collaborators where needed for service delivery
  • legal, regulatory, tax, or public authority bodies where required by law

We only share information where there is a legitimate reason to do so and, where appropriate, with suitable confidentiality or data protection safeguards in place.

11. Subcontractors and collaborators

Steerframe may work with subcontractors, technical collaborators, or specialist providers where needed to deliver services.

They are given access to information only where needed for the relevant work and, where appropriate, under confidentiality or data protection obligations.

Steerframe does not give subcontractors or collaborators unnecessary access to client information.

12. International transfers

Some tools or service providers used by Steerframe may store or process information outside the UK.

Where this happens, Steerframe aims to use providers that apply appropriate safeguards, such as recognised transfer mechanisms or contractual protections required by applicable data protection law.

If a specific project involves transfer of personal data outside the UK, EU, or EEA, additional terms may be needed depending on the nature of the project.

13. Retention

We keep personal information only for as long as necessary. As a general guide:

  • Enquiry records: up to 24 months
  • Guide download records: up to 24 months, unless ongoing engagement continues
  • Marketing records: until you unsubscribe or request deletion
  • Client records: up to 7 years for legal, tax, accounting, contractual, or insurance reasons
  • Project records: duration of the project plus a reasonable period afterwards
  • Website analytics: according to the settings of the analytics tool used

These periods may vary where we need to keep information for legal, regulatory, dispute, audit, or business continuity reasons.

14. Security

We take reasonable steps to protect personal information against loss, misuse, unauthorised access, disclosure, or destruction. This includes access controls, secure cloud services, limited access to client information, and reasonable care when using AI and automation tools.

No website, cloud service, AI tool, or digital system can be guaranteed completely secure.

You should avoid sending highly sensitive information through standard website forms or ordinary email unless a secure process has been agreed.

15. Security incidents

If Steerframe becomes aware of a personal data security incident that requires action under applicable data protection law, we will take reasonable steps to assess the issue, reduce harm, and notify affected clients, individuals, or authorities where required.

Clients should notify us promptly if they become aware of any issue that may affect personal data, system access, AI tool use, credentials, or project security.

16. Cookies and analytics

The website may use cookies or similar technologies to help it work properly, understand how visitors use the site, and measure performance.

This may include collecting information such as device type, browser, pages visited, time on site, referral source, and approximate location.

Non-essential cookies may require consent where applicable. You can usually control cookies through your browser settings.

17. Your data protection rights

Depending on the circumstances, you may have rights under UK data protection law, including the right to:

  • access your personal information
  • correct inaccurate information
  • ask for information to be deleted
  • restrict how information is used
  • object to certain uses of information
  • request data portability
  • withdraw consent, where consent is the lawful basis
  • complain to the Information Commissioner's Office (ICO)

Where EU data protection law applies, similar rights may apply under EU GDPR, and you may also have the right to complain to the relevant EU supervisory authority, such as the Data Protection Commission in the Republic of Ireland.

To exercise your rights, contact hello@steerframe.co. We may need to verify your identity before responding.

18. Contact

For questions about this Privacy Policy or how your information is used, contact:

hello@steerframe.co

Contact

For questions about this Privacy Policy, contact hello@steerframe.co

Steerframe

Process optimisation, digital automation and business intelligence for manufacturers.

Navigate

Contact

Based in Belfast and Dungannon, County Tyrone, supporting selected clients across Northern Ireland, Ireland and the UK.

© 2026 Steerframe Ltd. Registered in Northern Ireland. Company No. NI741882.

Registered office: Aisling House, 50 Stranmillis Embankment, Belfast, BT9 5FL.