Statutory Governance & Compliance

Privacy Policy & Data Protection Notice

Last Updated: 26 September 2026 • Framework: UK GDPR & Data Protection Act 2018 • ICO Registration: ZA317530

Data Controller Identity & Statutory Registration:

Legal Entity Mind Reflection Ltd
Companies House (NI) NI626017
ICO Registration Reference ZA317530 (Valid to Feb 2027)
Registered Head Office Unit 869 Moat House, 54 Bloomfield Ave, Belfast, BT5 5AD

1. Introduction & Scope

Mind Reflection Ltd ("we", "our", "us") operates as an independent B2B strategic management consultancy, digital systems integrator, and IT advisory firm. We respect your privacy and are committed to safeguarding your personal data in full compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

This Privacy Policy explains how we collect, process, store, and protect information when you visit our website (mindreflection.co.uk), communicate with our advisory team, or schedule business appointments via our embedded scheduling systems.

2. The Personal Data We Collect

We process personal data strictly necessary to facilitate corporate consulting engagements, technical audits, and administrative operations:

A. Direct Inquiries & Corporate Communications

B. Google Calendar Appointment Scheduling

When you schedule a consultation or discovery session via our embedded Google Calendar Appointment Scheduling system, we collect:

C. Technical & Log Data (Automated)

3. Lawful Bases for Processing (UK GDPR Art. 6)

Processing Purpose Data Categories UK GDPR Lawful Basis
Scheduling & hosting advisory consultations (Google Calendar / Meet) Name, Email, Meeting notes Article 6(1)(b): Performance of a contract or preliminary steps prior to entering a contract.
Responding to B2B inquiries & technical scoping Contact information, correspondence Article 6(1)(f): Legitimate interests in conducting corporate B2B consultancy.
Corporate accounting, VAT invoicing & statutory filings Billing details, business address Article 6(1)(c): Legal obligation (HMRC, Companies House statutory retention).
Server security, TLS integrity & fail2ban protection IP addresses, server logs Article 6(1)(f): Legitimate interests in maintaining cybersecurity and system integrity.

4. Third-Party Data Processors & International Transfers

We do not sell, rent, or trade your personal data. We only share data with vetted infrastructure partners who act as Data Processors under strict Data Processing Addendums (DPAs):

5. Data Retention Periods

We retain personal information only for as long as strictly necessary to fulfill business objectives or satisfy statutory obligations:

6. Cybersecurity & Technical Safeguards

As a cloud systems and infrastructure consultancy, our defensive data hygiene incorporates enterprise-grade controls:

7. Your Statutory Rights Under UK GDPR

As a data subject in the United Kingdom, you possess enforceable statutory rights:

To exercise any of these rights, contact our Data Protection Lead at: info@mindreflection.co.uk. Requests are responded to within one calendar month without administrative charge.

8. Information Commissioner's Office (Supervisory Authority)

Mind Reflection Ltd is formally registered as a Data Controller with the UK supervisory authority:

Information Commissioner’s Office (ICO) Registration:

Registration Reference: ZA317530

You have the right to lodge a complaint with the ICO at any time if you believe your data has been handled unlawfully:

Website: https://ico.org.uk/
Helpline: 0303 123 1113
Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, UK

9. Contact the Data Controller

If you have questions regarding this Privacy Policy or wish to discuss our data governance practices, please reach out directly:

Mind Reflection Ltd
Unit 869 Moat House, 54 Bloomfield Avenue
Belfast, BT5 5AD, Northern Ireland, United Kingdom
Email: info@mindreflection.co.uk
Telephone: +44 7400 992785