Legal
Privacy policy
and cookie notice
The short version, without the legal padding: what we do with the data you leave us, who helps us process it, and how to change your mind at any point.
Last updated: 1 September 2026
Who controls your data
The controller of your personal data — the party that decides what happens to it — is:
- Legal name
- QSHMOBILE LTD
- Registered office
- 85 Great Portland Street, London, England, W1W 7LT
- Company number
- 09778409
- VAT number
- GB436903191
- Data protection contact
- info@qshmobile.com
The company is registered in England, so this processing falls under the UK GDPR and the Data Protection Act 2018. If you live in the European Union, that costs you nothing: the rights set out below are yours all the same.
The contact form
When you send a message through the form, we receive exactly what you typed into it: your name, your email address, optionally a company name, the topic you picked, and the message itself. Nothing else — we don’t enrich your inquiry with data from anywhere else.
We use it to answer your question and work out whether and how we can help. The legal grounds are Article 6(1)(b) UK GDPR — steps taken at your request before entering into a contract — and Article 6(1)(f), our legitimate interest in corresponding with people who get in touch.
Giving us your details is voluntary, though without an email address we have no way to reply. There is no profiling and no automated decision-making here: a person reads what you send.
We send one automatic acknowledgement to that address confirming your message arrived. It does not quote your enquiry back to you, and we use the address for nothing else — it goes on no mailing list.
Technical data and form protection
The form is shielded from bots in four ways: a hidden trap field, a check on how quickly it was filled in, a cap on submissions from one IP address, and a computational puzzle your browser works out in the background before you send the message. That means we also process technical data when you submit — your IP address and basic request headers.
The puzzle is solved entirely on your device and checked on our own server. No third party takes part in it, we load no outside scripts for it, and we collect no behavioural data along the way — no mouse movement, no typing patterns, nothing of that kind.
The IP address does one job: counting submissions from a single source inside a ten-minute window. We store the address nowhere — not in our application logs, and never in the message that reaches us. The counter holds only a cryptographic digest of it, computed with a secret key known to our application alone. That digest lets us recognise repeat submissions from one source, but it is not an address: getting back to the address requires the key. We still treat it as personal data and describe it here on the same footing as everything else. The legal ground is Article 6(1)(f) UK GDPR — keeping the service secure.
Separately from that, our hosting provider (Microsoft) keeps its own server logs, on the terms set out in its documentation.
How long we keep it
We keep data for as long as it is doing something useful:
- Correspondence from the form — up to 24 months after our last exchange, unless you ask us to delete it sooner.
- Contract paperwork, if we end up working together — for as long as UK company and tax law requires, which is generally 6 years from the end of the accounting period.
- The form submission counter — the digest expires after 10 minutes and stops counting towards the cap from that moment. We delete the entry itself alongside later submissions, so with no traffic at all it can sit in storage until someone uses the form again.
Who processes it with us
We don’t sell data and we don’t share it for marketing. We do rely on providers who process it on our behalf:
- Microsoft — hosting for this site (Azure Static Web Apps), delivery of the notification email (Azure Communication Services), and storage for the submission counter (Azure Storage).
- Google — the typefaces are loaded from Google Fonts, so your IP address reaches Google’s servers when the page loads.
- Our email provider, which hosts the mailbox your inquiry lands in.
Transfers abroad
Our infrastructure runs in European regions, but several of the providers listed above are US companies, so data may be processed outside the United Kingdom and outside the European Economic Area.
Where that happens, it rests on UK adequacy regulations — including the UK Extension to the EU–U.S. Data Privacy Framework — or on standard contractual clauses with the UK addendum, that is an International Data Transfer Agreement or the UK Addendum.
Your rights
You have the right to access your data, to have it corrected or erased, to restrict how we process it, to receive it in a portable format, and to object to processing that rests on our legitimate interest.
To exercise any of these, write to the address above. We respond without undue delay, and within a month at the latest.
If you think we’re handling your data unlawfully, you can complain to our supervisory authority, the Information Commissioner’s Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. If you live in the European Union, you may go to the supervisory authority in your own country instead.
Changes to this policy
If the way we handle data changes — a new tool, a different provider — we’ll update this document and change the date at the top. Worth a glance before you send us another message.