Skip to content

Legal

Privacy policy
and cookie notice

The short version, without the legal padding: what we do with the data you leave us, who helps us process it, and how to change your mind at any point.

Last updated: 1 September 2026

Who controls your data

The controller of your personal data — the party that decides what happens to it — is:

Legal name
QSHMOBILE LTD
Registered office
85 Great Portland Street, London, England, W1W 7LT
Company number
09778409
VAT number
GB436903191
Data protection contact
info@qshmobile.com

The company is registered in England, so this processing falls under the UK GDPR and the Data Protection Act 2018. If you live in the European Union, that costs you nothing: the rights set out below are yours all the same.

The contact form

When you send a message through the form, we receive exactly what you typed into it: your name, your email address, optionally a company name, the topic you picked, and the message itself. Nothing else — we don’t enrich your inquiry with data from anywhere else.

We use it to answer your question and work out whether and how we can help. The legal grounds are Article 6(1)(b) UK GDPR — steps taken at your request before entering into a contract — and Article 6(1)(f), our legitimate interest in corresponding with people who get in touch.

Giving us your details is voluntary, though without an email address we have no way to reply. There is no profiling and no automated decision-making here: a person reads what you send.

We send one automatic acknowledgement to that address confirming your message arrived. It does not quote your enquiry back to you, and we use the address for nothing else — it goes on no mailing list.

Technical data and form protection

The form is shielded from bots in four ways: a hidden trap field, a check on how quickly it was filled in, a cap on submissions from one IP address, and a computational puzzle your browser works out in the background before you send the message. That means we also process technical data when you submit — your IP address and basic request headers.

The puzzle is solved entirely on your device and checked on our own server. No third party takes part in it, we load no outside scripts for it, and we collect no behavioural data along the way — no mouse movement, no typing patterns, nothing of that kind.

The IP address does one job: counting submissions from a single source inside a ten-minute window. We store the address nowhere — not in our application logs, and never in the message that reaches us. The counter holds only a cryptographic digest of it, computed with a secret key known to our application alone. That digest lets us recognise repeat submissions from one source, but it is not an address: getting back to the address requires the key. We still treat it as personal data and describe it here on the same footing as everything else. The legal ground is Article 6(1)(f) UK GDPR — keeping the service secure.

Separately from that, our hosting provider (Microsoft) keeps its own server logs, on the terms set out in its documentation.

How long we keep it

We keep data for as long as it is doing something useful:

  • Correspondence from the form — up to 24 months after our last exchange, unless you ask us to delete it sooner.
  • Contract paperwork, if we end up working together — for as long as UK company and tax law requires, which is generally 6 years from the end of the accounting period.
  • The form submission counter — the digest expires after 10 minutes and stops counting towards the cap from that moment. We delete the entry itself alongside later submissions, so with no traffic at all it can sit in storage until someone uses the form again.

Who processes it with us

We don’t sell data and we don’t share it for marketing. We do rely on providers who process it on our behalf:

  • Microsoft — hosting for this site (Azure Static Web Apps), delivery of the notification email (Azure Communication Services), and storage for the submission counter (Azure Storage).
  • Google — the typefaces are loaded from Google Fonts, so your IP address reaches Google’s servers when the page loads.
  • Our email provider, which hosts the mailbox your inquiry lands in.

Transfers abroad

Our infrastructure runs in European regions, but several of the providers listed above are US companies, so data may be processed outside the United Kingdom and outside the European Economic Area.

Where that happens, it rests on UK adequacy regulations — including the UK Extension to the EU–U.S. Data Privacy Framework — or on standard contractual clauses with the UK addendum, that is an International Data Transfer Agreement or the UK Addendum.

Your rights

You have the right to access your data, to have it corrected or erased, to restrict how we process it, to receive it in a portable format, and to object to processing that rests on our legitimate interest.

To exercise any of these, write to the address above. We respond without undue delay, and within a month at the latest.

If you think we’re handling your data unlawfully, you can complain to our supervisory authority, the Information Commissioner’s Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. If you live in the European Union, you may go to the supervisory authority in your own country instead.

Cookies and browser storage

This site sets no cookies of its own, collects no visitor analytics, and runs no advertising trackers. That’s why there is no consent banner here: there is nothing to consent to.

We do save three things in your browser’s local storage, and only once you’ve asked us to:

  • qsh-theme — whether you prefer the light or the dark version of the site.
  • qsh-lang — which language you picked in the footer.
  • qsh-notice — that you’ve closed the cookie notice, so it stays closed.

A little more detail

All three values stay in your browser. They never reach our server and they can’t identify you. Clearing site data in your browser settings removes them, as does opening the page in a private window.

The form protection adds nothing to that list. Its puzzle is solved in the memory of the open tab, and once you close it nothing of the sort remains in your browser — no cookie, no local storage entry.

UK electronic privacy rules (PECR) require consent before storing anything on your device, but they exempt whatever is strictly necessary to provide the service you asked for. Our three values sit inside that exemption, which is why you get a notice rather than a consent request.

If we ever add analytics or marketing tools, a consent request will appear here. As things stand, none is needed.

Changes to this policy

If the way we handle data changes — a new tool, a different provider — we’ll update this document and change the date at the top. Worth a glance before you send us another message.