Legal

Privacy Policy

Consult First Ltd (trading as “onionio.com”) · Version 1.0

The full text of our privacy policy is below. The signed PDF says exactly the same thing and is here to download if you need it for your records.

Download the signed policyPDF, 3.8 MB

Who We Are

Consult First Limited ("CFL", "we", "us", "our") is a company registered in England and Wales (Company No. 14503858) with its registered office at:

71–75 Shelton Street
Covent Garden
London
WC2H 9JQ
United Kingdom

We trade in the UK under the name onionio.com.

For the purposes of UK data protection law, we are the Data Controller of personal data collected through this website and in connection with our business operations, unless otherwise stated.

If you have any questions about this Privacy Policy, you may contact us at:

info@onionio.com

Our Commitment to Data Protection

We are committed to protecting your personal data and handling it transparently and lawfully in accordance with:

  • UK GDPR
  • Data Protection Act 2018
  • Privacy and Electronic Communications Regulations (PECR)

We operate in regulated and security-sensitive environments and align our information security practices to ISO/IEC 27001 standards.

What Personal Data We Collect

We may collect and process the following categories of personal data:

A. Website Visitors

  • IP address
  • Browser type and version
  • Device information
  • Pages visited
  • Referring website
  • Date/time of visit

B. Enquiries & Contact Forms

  • Name
  • Organisation
  • Job title
  • Email address
  • Telephone number
  • Message content

C. Clients & Business Contacts

  • Business contact details
  • Contractual information
  • Correspondence
  • Billing information

D. Suppliers & Partners

  • Contact details
  • Contract information
  • Financial details

E. Recruitment

  • CVs
  • Employment history
  • Professional qualifications
  • References
  • Right-to-work documentation

We do not intentionally collect special category data via our website.

How We Collect Data

We collect personal data:

  • When you complete forms on our website
  • When you contact us by email or telephone
  • When you engage us for services
  • Through cookies and analytics tools
  • During recruitment processes
  • Through business networking and professional interactions

Lawful Bases for Processing

We rely on the following lawful bases under UK GDPR:

  • Legitimate Interests – responding to enquiries, managing client relationships, improving services
  • Contractual Necessity – delivering services and fulfilling contractual obligations
  • Legal Obligation – compliance with tax, regulatory and statutory requirements
  • Consent – where required (e.g., certain marketing communications)

Where processing is based on consent, you may withdraw consent at any time.

How We Use Your Information

We use personal data to:

  • Respond to enquiries
  • Deliver consultancy and project services
  • Manage contracts and commercial relationships
  • Improve website performance and security
  • Comply with legal and regulatory requirements
  • Manage recruitment processes
  • Protect our systems and prevent fraud

We do not sell personal data.

Sharing of Personal Data

We may share personal data with:

  • Professional advisers (legal, financial, auditors)
  • IT and cloud service providers
  • Sub-contractors engaged in service delivery
  • Regulatory authorities where required
  • Group companies (if applicable)

All third parties are required to respect the security of your data and process it lawfully.

International Transfers

We do not routinely transfer personal data outside the UK.

Where international transfers are necessary (for example, via cloud service providers), we ensure appropriate safeguards are in place, such as:

  • UK International Data Transfer Agreements (IDTA)
  • Adequacy decisions
  • Standard contractual clauses

Data Security

We implement appropriate technical and organisational measures to protect personal data, including:

  • Access controls
  • Encryption where appropriate
  • Secure cloud infrastructure
  • Role-based access management
  • Supplier due diligence
  • Incident response procedures

We maintain documented information security controls aligned to ISO 27001 principles.

Use of Artificial Intelligence (AI)

We may use AI-enabled tools in the course of delivering services and supporting business operations.

Where AI tools are used:

  • They are subject to confidentiality and data protection controls
  • Personal data is processed lawfully and securely
  • AI use complies with our internal Acceptable Use and Information Security policies

We do not use AI for automated decision-making that produces legal or similarly significant effects on individuals.

Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, including:

  • Contractual duration plus statutory limitation periods
  • Legal and regulatory requirements
  • Financial record-keeping obligations

When data is no longer required, it is securely deleted or anonymised.

Your Rights

Under UK GDPR, you have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Request erasure (“right to be forgotten”)
  • Restrict processing
  • Object to processing
  • Data portability
  • Withdraw consent (where applicable)

To exercise your rights, please contact:

info@onionio.com

We will respond within one calendar month.

Complaints

If you are unhappy with how we handle your data, you may lodge a complaint with the Information Commissioner’s Office (ICO):

Information Commissioner’s Office

www.ico.org.uk

We would however welcome the opportunity to resolve any concerns directly.

Cookies

Our website may use cookies and similar technologies to:

  • Improve user experience
  • Analyse traffic
  • Enhance website security

You can control cookie settings through your browser.

Where required, we will obtain consent before placing non-essential cookies.

(A separate Cookie Policy may apply.)

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in legal requirements or business practices.

The latest version will always be published on our website.

Accelerated resilience and trusted AI solutions

Registered office: 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom

Services

Company

Cyber Essentials certifiedCyber Essentials Plus certifiedBSI ISO/IEC 27001 Information Security Management certifiedCrown Commercial Service supplier
© 2026 onionio.com. All rights reserved.