Policies
Policies and legal information.
Six documents, published in full. If your procurement process needs any of them as a signed PDF, ask and we will send one.
01 / Privacy
Privacy policy
Wraight Consulting Limited ("we", "us") is registered in England and Wales, company number 14949847. Our registered office is 31 Embleton Road, North Shields, England, NE29 8BB. We are registered with the Information Commissioner's Office under registration ZB708397.
We handle personal data in two roles. They carry different obligations, so they are set out separately below.
When we are the controller
We are the controller for our own business contacts: people who email us, prospective clients, and the named contacts at client organisations. We decide how that data is used. In this role we hold:
- Contact details you give us when you get in touch: name, email address, telephone number, organisation.
- Correspondence: the emails and messages we exchange, and notes from meetings and calls.
- Contract and billing records: engagement terms, invoices and payment records.
The lawful bases are legitimate interests (responding to enquiries and running the business), contract (delivering work you have engaged us for) and legal obligation (keeping accounting records).
When we are the processor
When we administer a client's Microsoft 365 or Google Workspace tenant, or operate infrastructure or a website for them, we handle personal data about that client's own staff. In education settings this extends to pupils and their parents.
That data covers names, email addresses, job titles, group memberships, and sign-in and audit records. It extends to mailbox or file content when the client has asked us to investigate a specific issue.
Where we host a website for a client, we also process the IP addresses of the people who visit it, recorded in the server access logs. For a public site that includes parents and members of the public who have no other relationship with the client. The sub-processor list below sets out who holds those logs.
In this work the client is the controller and we are the processor. We act only on the client's documented instructions, under a written data processing agreement. We do not decide what the data is used for. We do not use it for our own purposes. We do not retain it after the engagement ends.
If you are an employee, pupil or parent at one of our client organisations and you want to exercise your data rights, contact that organisation's data protection officer or privacy contact. They are the controller. We will support them in responding to you.
Website visitors
This site has no analytics, no tracking pixels and no advertising. We do not build a profile of you, and we cannot identify you from your reading of it. Delivering the page requires two third parties to process data about your request. The cookie policy below sets out what each of them receives.
The contact form
If you use the form on our contact page, we receive the name, email address, organisation and message you type. The organisation field is optional. We collect nothing else from the page, and the form sets no cookie.
The lawful basis is legitimate interests: replying to someone who has asked us to get in touch. We use what you send to reply to you and to carry out any work that follows. We do not add you to a mailing list. We do not pass it to anyone for marketing.
A Cloudflare Function handles the submission and Cloudflare's email service delivers it to our mailbox. We do not store it in a database. Once delivered, the message lives in our email, and the retention periods below apply to it.
To stop the form being abused by automated traffic, we check that the submission came from a page we served, and we count recent submissions per network connection. That count is keyed on a one-way hash rather than on your IP address. It cannot be reversed to identify you, or used to recognise you on a later visit.
Who else sees your data
We keep the supply chain short. As a controller we use:
- Google (Google Workspace): email and document storage.
- Cloudflare: DNS and hosting for this website.
- Our accountant: billing and statutory accounts.
We do not sell personal data, and we do not share it for marketing. Several of these providers process data outside the UK. Where they do, the transfer is covered by the UK's adequacy regulations or by an International Data Transfer Agreement.
How long we keep it
- Enquiries that do not become work: deleted within 12 months.
- Client correspondence: kept for the duration of the engagement and for 12 months after it ends.
- Contracts and financial records: kept for 6 years after the end of the relevant financial year, as required by the Companies Act.
- Client tenant data: we keep no copy of it after an engagement ends. Administrative access is handed back and our accounts are removed. Extracts taken during an investigation are deleted within 12 months of that investigation closing, or when any related regulatory, legal or insurance matter concludes if that is later. Where tenant data appears in our correspondence, the correspondence period above applies to it.
Your rights
Where we are the controller, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or provide it in a portable format. Ask us through the contact form. We will respond within one month.
If you are unhappy with how we have handled your data, tell us first so that we can put it right. You can also complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint, by post, or on 0303 123 1113.
Last updated 16 September 2026
02 / Cookies
Cookie policy
This website sets no cookies. It runs no analytics, no tracking, no advertising and no session state. There is nothing to ask your consent for, and no banner to dismiss. The contact form sets no cookie either. It uses no CAPTCHA and runs no third-party script.
Two third parties are involved in delivering the page to you, and both receive your IP address as part of that. Neither sets a cookie here.
- Cloudflare hosts this site and serves it from a location near you. Cloudflare processes your IP address and request details to deliver the page and to protect the site from attack.
- Google Fonts serves the three typefaces used here. Your browser requests them from
fonts.googleapis.comandfonts.gstatic.com, which discloses your IP address to Google.
If you would rather not contact Google, block those two domains in your browser. The site stays fully readable and falls back to your system typefaces.
Last updated 16 September 2026
03 / Security
Information security
Scope
We hold privileged access to systems our clients depend on. This document summarises how we protect it.
It covers our own practice: the way we work and the systems we run. It does not cover the configuration of a client's tenant, which is governed by that client's own policies and by our engagement with them.
Controls
- Least privilege. We hold the access a task requires, for as long as it requires it, and no more.
- Strong authentication. Multi-factor authentication is required on every user account we use to reach a client system. Automation runs under its own service identity rather than a person's account, with credentials scoped to the task. We do not share credentials between people, and we do not send them in plain text.
- Separation. We keep privileged administrative accounts separate from our everyday working accounts.
- Encryption. Devices used for client work are encrypted at rest and kept up to date.
- Documented change. We preview changes to client systems before they run, and we can roll them back afterwards. Configuration is written down, and defined as code where it can be.
- Proportionate scale. We are two directors, and one specialist we bring in for larger pieces of work. The controls above apply to all three of us, and each is owned by a named person rather than by a team. Where a control would normally depend on a large team, we record what we do in its place.
Governance
Our IT Director owns this policy. We review it at least once a year, and sooner if something changes that warrants it.
Reporting a security concern
If you believe you have found a vulnerability in this website, or a security problem in something we manage, tell us through the contact form with enough detail to reproduce it. We will acknowledge it. We will not pursue anyone who reports a genuine issue in good faith.
Last updated 16 September 2026
04 / Sub-processors
Sub-processor list
A sub-processor is a third party we engage to help us carry out processing on your behalf. This list is published under Articles 28(2) and 28(4) of the UK GDPR, which require us to tell you who else handles your data under our contract and to give notice before that changes.
| Provider | Purpose | Data location |
|---|---|---|
| Our own Google Workspace, where correspondence and documents containing your data are held while we work for you | UK / EU / US | |
| Vercel | Hosting, on our own account, for the websites and web tools we build for you, including public sites and administrative portals | Global edge network |
Where we build a website or a web tool for you, Vercel serves it from our own account: the pages, styles and scripts. Vercel records a standard access log entry for every request, holding the visitor's IP address, the time, the page requested and the browser's user agent.
For an administrative tool, those are the IP addresses of the staff who use it. Your own records do not pass through Vercel. They move between the user's browser and your own Microsoft or Google tenant, on infrastructure you hold.
For a public website, they are the IP addresses of everyone who visits, including parents and members of the public who have no other relationship with you. Vercel holds nothing about those visitors beyond the log entry described above.
Providers that are not our sub-processors
Your Microsoft 365 or Google Workspace tenant is contracted directly between you and Microsoft or Google. They process your data as your processor, under your agreement with them. We administer a tenant you already hold, so they are not our sub-processors and they do not appear above. The same applies to Smoothwall and to any other platform you license in your own name.
It works the same way for cloud infrastructure. Our terms of business provide for buying third-party services in your name wherever the supplier allows it, so that you own them directly. Every engagement we currently run works that way, so Microsoft Azure, Amazon Web Services and Google Cloud are your suppliers and not ours. If an engagement ever runs on cloud infrastructure held in our own account, we will tell you and add the provider to the table above.
Cloudflare hosts this website. Anything you send us through it, we hold as the controller, so Cloudflare is our own processor in that role and not a sub-processor of yours. The privacy policy above covers it.
Our accountant processes billing records containing client contact details. They act for us as a separate controller for their own regulatory purposes, not as our sub-processor.
We use an AI coding assistant to write and maintain the scripts and tooling that administer your systems. It processes our code. We do not put your personal data through it: commands that return records from your tenant, such as a list of user accounts or an extract from an audit log, are run outside the assistant's session. It is not a sub-processor and does not appear in the table above.
Changes to this list
We publish any addition to this list here before the new provider begins processing client data, and we notify affected clients directly. To be told by email when this page changes, ask through the contact form and we will add you to the notification list.
Clients can object to a new sub-processor on reasonable data protection grounds. Their engagement documentation sets out how.
Last updated 16 September 2026
05 / Terms
Terms of business
These terms apply to work carried out by Wraight Consulting Limited unless we have signed something that says otherwise. Where a signed engagement letter or contract conflicts with this page, that document takes precedence.
Engagement
Work begins when you accept a written proposal or statement of work by email. The proposal sets out what is included, what is not, and what it costs. We quote anything outside that scope separately, before it starts.
Fees and payment
We agree commercial terms with each client, and do not publish them here. Your proposal or engagement letter sets out the basis of the fee, the billing frequency and the payment terms.
Most engagements are a monthly contract that includes an agreed number of hours. Those hours are split between time worked during normal working hours and time worked outside them. Your engagement letter defines both periods and sets the allowance for each. Unused hours do not carry forward to the following month.
We agree any work that will take you beyond the monthly allowance before we start it. Either you ask us for that work, or we tell you that the allowance is about to run out. We invoice the time separately from the monthly fee, at the rate set out in your engagement letter.
Fixed-term projects are quoted as a fixed price before the work starts.
Late payment may attract statutory interest under the Late Payment of Commercial Debts (Interest) Act 1998.
Wraight Consulting Limited is not registered for VAT, so we charge no VAT on our fees.
Third-party costs are yours: software licences, cloud consumption, domain registrations and hardware. We buy them in your name where the supplier allows it, so that you own them directly. We do not resell you infrastructure at a markup.
Your responsibilities
- Give us the access we need to do the work, and tell us promptly when it changes.
- Make sure you have the right to grant that access, and that your own privacy notices cover our involvement.
- Nominate someone who can make decisions and approve changes.
Confidentiality
We treat everything we see in your systems as confidential, with no time limit. We will not disclose it except where the law requires it, or where you have asked us to. We expect the same of you in respect of our proposals and rates.
Data protection
Where we process personal data for you, we do so as your processor under Article 28 of the UK GDPR, governed by a written data processing agreement. The privacy policy above sets out what that covers.
Intellectual property
Scripts, documentation and configuration written specifically for you, and paid for by you, are yours to keep and use. We retain ownership of general-purpose tools, methods and know-how developed before or outside your engagement, and we grant you a perpetual licence to use any of it embedded in your deliverables. Nothing here stops us applying the same general knowledge for other clients.
Liability
Nothing in these terms limits liability for death or personal injury caused by negligence, for fraud, or for anything else that cannot lawfully be limited.
Subject to that, our total liability arising from an engagement is limited to the amount stated in your engagement letter. Where it states no figure, the limit is the total fees paid under that engagement in the twelve months before the claim arose. We are not liable for loss of profit, loss of business, or indirect or consequential loss.
We are not liable for failures in third-party services outside our control, including those of Microsoft, Google, Amazon Web Services, Cloudflare and Smoothwall.
Ending the engagement
A monthly contract has no minimum term. Your engagement letter sets out the notice period. Where none is agreed, either of us can end the arrangement with 30 days' written notice. Either of us can end it immediately if the other materially breaches these terms and does not fix the breach within 14 days of being asked.
On termination you pay for work done up to that point. We hand over documentation, credentials and access, then remove our own administrative accounts from your systems.
Governing law
The law of England and Wales governs these terms. The courts of England and Wales have exclusive jurisdiction.
Last updated 16 September 2026
06 / Accessibility
Accessibility statement
Several of our clients are schools, including SEND settings, where we are asked to get accessibility right on their behalf. We hold this site to the same standard.
This site is built to meet WCAG 2.2 level AA. In practice:
- It works without JavaScript, and with images or custom fonts blocked.
- Every interactive element is reachable by keyboard and shows a visible focus outline.
- Text contrast meets or exceeds the AA threshold, and text resizes to 200% without loss of content.
- Animation is minimal, and switches off entirely if your device is set to reduce motion.
- Headings and landmarks are structured for screen readers, and there is a skip link to the main content.
Known limitations
The twelve-month planner on the home page is a visual layout. It reads correctly in order with a screen reader, but it is a dense read. Nothing in it appears only there: the same points are set out as prose elsewhere on that page.
Telling us about a problem
If you cannot use part of this site, tell us through the contact form. Say what you were trying to do and what got in the way. We will reply within two working days, and fix it if we can.
Last updated 16 September 2026