Privacy Policy
NobleShield Risk
Version 1.0 | Effective: 24 September 2026
This Privacy Policy explains how NobleShield Risk ("NSR", "we", "us" or "our") collects, uses, stores and shares personal information when you visit our website, contact us, purchase a service, submit contract documents, or otherwise interact with us.
1. Who We Are and How to Contact Us
NobleShield Risk is a UK-based construction contract risk review business currently operated as a sole trader.
For privacy questions, requests or concerns, contact:
Email: welcome@nobleshieldrisk.com
We do not currently publish a separate business postal address in this notice. If our business structure or contact arrangements change, we will update this policy.
2. Information We Collect
Information you provide directly
We may collect:
Your name, company name, job title, email address and telephone number.
Order and service information, including your order number, package purchased, project name, approximate contract value, notes and correspondence.
Contract documents and supporting materials that you upload or send to us for review.
Information contained within those documents. This may include personal information about directors, employees, consultants, subcontractors, clients, signatories or other individuals.
Communications you send to NSR, including enquiries, instructions, corrections, complaints and feedback.
Payment information
NSR uses Squarespace Payments to accept website payments.
Payment processing is provided through the Squarespace Payments ecosystem and its payment and fraud-prevention service providers.
NSR does not need to receive or store your full payment card number or card security code in order to provide our contract review service.
We may receive transaction information needed to administer an order, such as payment status, amount, date, order details and limited payment-related information made available through the platform.
Website and technical information
When you use our website, Squarespace and related website technologies may collect technical and usage information such as your IP address, browser or device information, pages visited, timestamps, cookies and similar identifiers.
Our Cookie Policy provides further information about cookies and similar technologies used on the website.
Special category and other sensitive information
NSR does not intentionally request special category personal data or criminal-offence data as part of its standard service.
However, a contract or supporting document supplied by a client may incidentally contain sensitive personal information.
Clients should avoid supplying unnecessary personal information and should redact information that NSR does not need for the commercial review where reasonably possible.
3. Why We Use Your Personal Information
We may process personal information for the following purposes:
Enquiries
To respond to enquiries and take steps requested by you before purchasing a service.
Typical lawful basis: taking steps at your request before entering into a contract and, where appropriate, our legitimate interests.
Providing NSR services
To process your order, receive contract documents, conduct the purchased contract review, communicate with you and deliver your final report.
Typical lawful basis: performance of a contract.
Where documents supplied by a client contain personal information about other individuals, NSR may rely on legitimate interests where appropriate to provide the requested business service.
Payments and fraud prevention
To administer payments, refunds, transaction disputes and fraud prevention.
Typical lawful basis: performance of a contract, legal obligations and/or legitimate interests.
Business records, security and claims
To maintain appropriate records of services performed, protect our systems, conduct quality assurance and handle complaints, disputes or potential claims.
Typical lawful basis: our legitimate interests in operating, protecting and defending the business and, where applicable, legal obligations.
Tax and accounting
To maintain records required for tax, accounting and regulatory purposes.
Typical lawful basis: legal obligation.
Marketing
Where NSR conducts direct marketing, we may use business contact information to communicate about relevant NSR services.
We will rely on consent where required or legitimate interests where permitted by law.
You may object to direct marketing at any time.
4. Contract Documents and Information About Other People
A client may provide a construction contract or supporting document containing personal information about individuals who did not submit the document themselves.
NSR receives this information from the client for the limited purpose of carrying out the requested commercial contract review and related administration.
The client is responsible for ensuring that it is entitled to provide documents and information to NSR.
NSR will not intentionally use personal information contained within client contracts for unrelated marketing or profiling.
5. Service Providers and Sharing
NSR uses service providers to operate and deliver its services.
These may include:
Squarespace — website hosting, forms, order management and Squarespace Payments.
Payment and fraud-prevention providers used within Squarespace Payments.
Google Workspace — business email and restricted cloud file storage.
Anthropic / Claude — technology used as part of NSR's internal review workflow.
Professional advisers, insurers, regulators, courts or law-enforcement bodies where disclosure is reasonably necessary or legally required.
NSR does not sell client contract documents or personal information.
We share information only where reasonably necessary to operate the service, fulfil the purposes described in this policy, or where required or permitted by law.
6. Use of Technology and Human Review
NSR uses modern technology, including AI-assisted tools, as part of its internal contract review workflow.
Client documents or relevant extracts may therefore be processed through technology service providers used by NSR.
Technology-generated analysis is not treated as the final client deliverable without human review.
NSR performs human quality assurance before issuing the final report.
NSR does not use solely automated decision-making about individuals that produces legal or similarly significant effects as part of its standard contract review service.
7. International Processing
Some of our technology and cloud service providers may process or store personal information outside the United Kingdom.
Where UK data-protection law requires safeguards for an international transfer, we expect the relevant provider arrangements to use an applicable lawful transfer mechanism or other permitted safeguard.
You may contact us for further information about the categories of providers involved in processing your information.
8. How Long We Keep Information
NSR maintains a documented retention and deletion schedule.
Our current standard periods include:
Squarespace contract uploads: normally deleted around 30 days after final report delivery.
Working contract documents in restricted Google Drive storage: normally deleted around 90 days after final report delivery.
Client-specific Claude working material: normally deleted around 30 days after final report delivery when no longer required.
Draft reports and temporary working material: normally deleted within 90 days after final report delivery.
Final NSR report, completed human QA record and necessary client instructions/correspondence: normally retained for up to 6 years from final delivery, subject to review.
Tax, accounting and transaction records: retained for the period required by applicable tax and accounting obligations.
Unconverted enquiries: normally retained for up to 12 months after the last meaningful contact, unless there is a reason to retain them longer.
These are standard periods rather than absolute guarantees.
We may retain relevant records for longer where reasonably necessary because of a complaint, dispute, threatened or actual claim, insurance matter, regulatory enquiry, legal obligation or another documented reason.
We may also delete information earlier where it is no longer required.
9. How We Protect Your Information
NSR uses technical and organisational measures intended to protect personal information against unauthorised access, loss, misuse or disclosure.
These measures include:
Restricted cloud storage.
Account access controls.
Multi-factor authentication on key services.
Device access controls.
Limited administrative access.
Documented retention and deletion practices.
No method of electronic storage or transmission can be guaranteed to be completely secure.
If we become aware of a personal data breach, we will assess and respond to it in accordance with applicable legal requirements.
10. Your Data Protection Rights
Depending on the circumstances and the lawful basis involved, you may have rights to:
Request access to your personal information.
Request correction of inaccurate information.
Request erasure of personal information.
Request restriction of processing.
Receive certain personal information in a portable format.
Object to certain processing.
Where processing is based on consent, you may withdraw your consent without affecting processing that was lawful before withdrawal.
Where NSR relies on legitimate interests, you may have the right to object to that processing.
You have an absolute right to object to the use of your personal information for direct marketing.
To exercise a privacy right, contact:
We may need to verify your identity before acting on a request.
11. Complaints
If you have concerns about how NSR handles your personal information, please contact us first at:
You also have the right to complain to the UK Information Commissioner's Office (ICO).
12. Cookies
Our website uses cookies and similar technologies for purposes such as website operation, security, preferences and, where enabled, analytics.
Please see the NSR Cookie Policy and the cookie controls presented on our website for further information and available choices.
13. Children's Information
NSR provides business-to-business construction contract review services and is not directed at children.
We do not knowingly seek personal information from children through our standard service.
14. Changes to This Privacy Policy
We may update this Privacy Policy when our services, providers, legal obligations or data practices change.
The latest version will be published on the NSR website with an updated effective or revised date.
Where required, material new uses of personal information will be communicated appropriately.
15. Contact
NobleShield Risk
Privacy contact: welcome@nobleshieldrisk.com
United Kingdom