Skip to content
CapitalSea LTDInfrastructure & Security

Privacy Policy

This policy explains how CapitalSea LTD collects, uses, stores and protects personal data in connection with this website and the services we provide to our business clients.

Last updated: 28 August 2026

01Who we are

CapitalSea LTD (“CapitalSea”, “we”, “us” or “our”) is a company registered in England and Wales under company number 17425986, with its registered office at 128 City Road, London, EC1V 2NX, United Kingdom.

We are the data controller in respect of personal data collected through this website and through our commercial correspondence with prospective and existing clients. Where we process personal data on behalf of a client in the course of delivering contracted services, we act as a data processor and the applicable terms are set out in the data processing agreement forming part of that contract.

For any question about this policy or about how we handle personal data, contact us at contact@capitalsealtd.com.

02Scope of this policy

This policy applies to personal data processed in the context of a business-to-business relationship, including data relating to representatives, employees and contractors of our clients, suppliers and prospective clients. Our website is not directed at consumers or at children, and we do not knowingly collect personal data from individuals under the age of 18.

03Personal data we collect

We may collect and process the following categories of data:

  • Contact data — name, job title, employer, business email address, business telephone number and postal address.
  • Correspondence data — the content of enquiries, proposals, statements of work and other communications exchanged with us.
  • Contractual data — records relating to services requested or supplied, service credentials issued, and account administration.
  • Technical data — IP address, browser type and version, device type, operating system and referring pages, where collected by our hosting infrastructure for security and diagnostic purposes.
  • Access and log data — connection, authentication and audit records generated by services we operate for a client, processed in accordance with the relevant service contract.

We do not intentionally collect special category data, and we ask that you do not submit such data to us through this website.

04How we collect personal data

We collect personal data when you contact us by email or through the enquiry form on this website, when you enter into or negotiate a contract with us, when you are named as a representative or authorised user by a client organisation, and automatically through server logs when you visit this website.

05Purposes and lawful bases for processing

Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we rely on the following lawful bases:

  • Legitimate interests — to respond to business enquiries, to manage and develop client relationships, to secure and administer our website and infrastructure, and to protect our legal rights. We balance these interests against your rights and freedoms.
  • Performance of a contract — to negotiate, enter into and perform contracts for the supply of our services, including provisioning and administering service access.
  • Legal obligation — to comply with statutory accounting, tax, regulatory and record-keeping duties.
  • Consent — where we rely on your consent, such as for certain optional communications, you may withdraw it at any time without affecting the lawfulness of prior processing.

06Disclosure of personal data

We do not sell personal data. We may disclose personal data to:

  • service providers and sub-processors who support our operations, including hosting, communications, security and professional advisory services, each bound by written confidentiality and data protection obligations;
  • professional advisers, insurers, auditors and regulators where reasonably required;
  • law enforcement or other authorities where disclosure is required by law or necessary to establish, exercise or defend legal claims;
  • a purchaser or successor entity in connection with a reorganisation, merger or sale of our business or assets.

07International transfers

Where personal data is transferred outside the United Kingdom, we ensure an appropriate safeguard is in place, such as an adequacy decision made by the UK government, the International Data Transfer Agreement, or the UK Addendum to the European Commission standard contractual clauses. Details of the safeguards applicable to a specific engagement are available on request.

08Retention

We retain personal data only for as long as necessary for the purposes for which it was collected. Enquiry correspondence that does not lead to a contract is generally retained for up to 24 months. Contractual, accounting and tax records are retained for a minimum of six years from the end of the relevant financial year, or longer where required by law or necessary for the defence of legal claims. Service access and audit logs are retained in accordance with the applicable client contract.

09Security

We maintain technical and organisational measures appropriate to the risk, including encryption of data in transit, access control on a least-privilege basis, network segmentation, logging and monitoring, supplier due diligence, and staff confidentiality obligations. No method of transmission or storage is entirely secure, and we cannot guarantee absolute security; we will notify affected parties and the relevant supervisory authority of a personal data breach where legally required to do so.

10Cookies and analytics

This website is designed to operate without non-essential cookies. Any cookies used are strictly necessary for the operation and security of the site. Should we introduce analytics or other non-essential cookies, we will present a consent mechanism and update this policy accordingly. Your browser can be configured to block or delete cookies, though this may affect site functionality.

11Your rights

Subject to the conditions and exemptions in applicable law, you have the right to:

  • request access to the personal data we hold about you;
  • request rectification of inaccurate or incomplete data;
  • request erasure of your personal data;
  • request restriction of processing;
  • object to processing based on our legitimate interests;
  • request data portability;
  • withdraw consent where processing is based on consent.

To exercise any of these rights, contact contact@capitalsealtd.com. We will respond within one month, and may extend that period by two further months for complex requests. We may request proof of identity before acting on a request. Where we act as a processor for a client, we will refer your request to that client as the controller.

12Complaints

If you are not satisfied with how we have handled your personal data, you may lodge a complaint with the Information Commissioner’s Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom. We would appreciate the opportunity to address your concern before you approach the ICO.

13Third-party websites

This website may link to third-party sites. We are not responsible for the content or privacy practices of those sites, and we encourage you to review their privacy notices.

14Changes to this policy

We may update this policy from time to time to reflect changes in law or in our operations. The current version is always published on this page with the date it was last updated. Material changes affecting contracted clients will be notified in accordance with the relevant agreement.

Company details

Registered name
CapitalSea LTD
Company number
17425986
Registered office
128 City Road, London, EC1V 2NX, United Kingdom