Legal
Privacy notice
There is one form on this site and it sends me an email. Most of what follows is describing how little happens.
What is settled here, and what is not
The ten open questions on this notice were decided on 2 September 2026. Every supplier position below was read from that supplier's own current document, and each says the date it was read, so you can tell how fresh it is. The notice takes effect on the day this site is published.
Who is responsible for your information
Dalaric Limited, registered in England and Wales, company number 06995683. Registered office: 4 South Terrace, South Street, Dorchester, Dorset, DT1 1DE. I am the data controller and the person you would be dealing with either way.
Questions about anything here go to info@dalaric.com.
Dalaric Limited is registered with the Information Commissioner's Office, reference ZA535738. That register is public, so you can check it rather than take my word for it.
What this site collects
Nothing about you personally until you fill in the form on the contact page. Visits are counted, as totals, and the section on counting visits says exactly what that involves and how to opt out. There is no tracking pixel, no advertising tag, no embedded video and no social widget on any page.
When you do submit the form, it sends me:
- Your name
- Your company, if you give one
- Your email address
- Your phone number, if you give one
- What you wrote about your situation
- How you found me, if you say
The form also carries two things that are about the form rather than about you: a hidden field that a person never sees and a real submission leaves empty, and a signed token that records how long the page had been open. Both exist to reject automated submissions and neither identifies anybody.
What happens to it
It is sent to me as an email and becomes a ticket, which is the record. There is no database behind this site and nothing is written to one. If sending fails, the reason is logged and nothing about who sent it is.
Why I am allowed to hold it
Legitimate interests, which is Article 6(1)(f). You got in touch, you expect a reply, and the information is what you chose to type. The assessment behind that choice is written down, dated and internal rather than published, which is what the Information Commissioner expects of it.
Legitimate interests is the honest fit rather than the flattering one. The obvious alternative, steps taken before entering a contract, collapses for every enquiry that was only ever a question, and most of them are.
An enquiry is not marketing and does not put you on a list. You will not get a newsletter because you asked me something.
How long it is kept
An enquiry that does not become work is kept for twelve months from your last message, then deleted. That is long enough to recognise you if you come back, and to answer a complaint about how the enquiry itself was handled.
An enquiry that becomes work stops being an enquiry. It joins the record for that work and is kept for the length of the relationship plus six years from the final invoice. Six years is not a number I picked: it is the limitation period for a simple contract and it sits comfortably with what HMRC expects of business records.
At the end it is deleted from the ticket system and from the mailbox, rather than moved somewhere quieter. Copies of it persist in those providers' backups and age out on their cycles rather than on mine. That is true of every system of this kind, and a notice that implies otherwise is simply inaccurate.
Who else sees it
Four companies touch an enquiry between your keyboard and my mailbox, and these are all four. The law would let me describe them by category. Naming them costs nothing I value and a page arguing that nothing here is hidden cannot then hide its own supply chain.
Yes, some of it leaves the UK. That is unavoidable for a business this size and it is not a problem in itself, provided each transfer has a lawful route and that route is stated. Every position below was read from that supplier's own current document rather than remembered, and each row says when.
| Who | What they do with it | Where they are | What makes that lawful, and when I last read it |
|---|---|---|---|
| Cloudflare | Serves every page here, runs the small program behind the contact form, provides the anti-robot check on it, and counts visits | Its global network. The agreement offers no UK or European localisation and openly expects processing outside Europe | The UK Addendum to the European standard contractual clauses. Cloudflare separately states Data Privacy Framework compliance. Read from its data processing addendum version 6.4, effective 3 April 2026 |
| Postmark, legally AC PM LLC | Turns your submission into the email that reaches me | United States, in Amazon and Deft data centres | Standard contractual clauses with the UK Addendum. It is also certified to the EU-US Data Privacy Framework, which is not by itself a route out of the UK, so the Addendum is the one doing the work here. Read from its agreement effective 17 November 2025 |
| Microsoft | Holds the mailbox the email lands in, which is where your enquiry comes to rest. Also runs the booking page, keeps any call you book, and carries the call itself on Teams | The mailbox is in the United Kingdom, and that is Microsoft's committed location for it, not just where it happens to be today. Bookings are kept in a mailbox of their own in the same place. Before a message reaches either, Microsoft checks it for spam and malware in Europe, and that step carries no location commitment. Teams is in Europe today, with a commitment to the United Kingdom | Keeping the mailboxes in the UK is not a transfer at all. The check in Europe, and Teams while it is there, are covered by UK adequacy for Europe, so they need no further safeguard. Read from this account's data location settings on 3 October 2026 |
| Zoho Desk | Holds the ticket, which is the actual record of your enquiry | Zoho's European data centre, established by reading the live account rather than inferring it from anything | UK adequacy covers Europe, so storing it there needs no further safeguard. Zoho's own staff outside Europe reach it under the standard contractual clauses, and reaching data remotely is a transfer in law, so it is named rather than glossed over. Read 2 September 2026 |
One thing worth knowing about addresses. The support system answers on support.dalaric.com. It carries my name and it is not my software. A Dalaric address does not mean a Dalaric system, and you should not have to guess which is which.
The two third parties on this site
Both are Cloudflare. One is the check on the contact form and the other counts visits.
The check on the contact form
The contact page carries a Cloudflare Turnstile widget, which is what establishes that a form submission came from a person. It appears on that one page and is not present anywhere else.
Loading it means your browser makes a request to Cloudflare, which necessarily means Cloudflare receives your IP address, as any server does when you connect to it. Checked on the running site: it stores nothing on your device. No cookie, no local storage, no session storage. The cookies page sets out how to confirm that yourself.
Cloudflare wears two hats here and only one of them is mine. As my supplier it runs the check on my instructions. It also uses the same signals to improve the check for everybody who uses it, and that second part is its own decision made for its own reasons, not something I asked for or can switch off. Describing Cloudflare only as a supplier would quietly leave that out.
What the check collects, in Cloudflare's own words: your IP address, a fingerprint of how your browser negotiates its connection, the identifier your browser sends saying what it is, and the key for this site and the address it was loaded from.
Cloudflare publishes no retention period for any of it. So there is no figure here, rather than a figure I cannot show you the source of. Read from its Turnstile privacy addendum, last updated 18 June 2025, and its general privacy documentation is at cloudflare.com/privacypolicy if you would rather check than take my word.
Counting visits
Every page counts visits with Cloudflare Web Analytics. What I see are totals: how many visits each page had, which sites sent people here, roughly which countries they came from, which browsers and kinds of device they used, and how quickly pages loaded. I do not see who you are, and Cloudflare says the product "does not collect or use your visitors' personal data".
To do that, your browser loads a small script from Cloudflare and sends it a short report when the page has loaded and again when you leave. Cloudflare receives your IP address, as with any connection, and it does not record anything after a question mark in a page address. It keeps the detailed reports for seven days and then reduces them to a sample of around one in ten. Nothing is stored on your device, which is why there is still no banner.
Why: knowing which pages are read and which are slow is how the site gets better, and the law allows counting of this kind for statistics provided you are told about it and can say no simply and for free. Both are on this page.
How to say no. If your browser sends Global Privacy Control or Do Not Track, the counting script is never loaded. Firefox sends Global Privacy Control if you tick it under Privacy and Security in its settings, and Brave sends it already. Chrome and Edge can send Do Not Track from their privacy settings. Safari offers neither, so there a content blocker that blocks cloudflareinsights.com does the same job, and so does turning JavaScript off. None of this stores anything on your device, and none of it changes how the rest of the site works.
Read from Cloudflare's Web Analytics documentation and product page on 4 October 2026. Cloudflare's own privacy policy is at cloudflare.com/privacypolicy.
Other ways you might contact me
Email, phone, WhatsApp and a booked video call all reach me, and each carries whatever you choose to put in it. Anything that turns into real work is moved into a ticket so that it is written down, and you are told when that happens.
WhatsApp is Meta's service and not mine. What you write is encrypted on its way, but Meta still holds the fact that we spoke, when, and the numbers involved. None of that is under my control or covered by any agreement between you and me. I use WhatsApp Business, where the company I contract with is WhatsApp Ireland Limited and I am the one responsible for what is done with your information. Read from their business terms on 2 September 2026.
So do not send me anything confidential over WhatsApp. Use the support address instead: it raises a ticket, the ticket is the record, and having a record is the whole point.
Booking a call
The booking page is Microsoft Bookings, at bookings.cloud.microsoft. It takes your name and email address, and your phone number, postal address and whatever you write in the box if you choose to give them. The booking is kept by Microsoft in the United Kingdom, as the table above sets out. What the page itself stores on your device is Microsoft's decision rather than mine, and the cookies page says more about it.
The call itself is on Microsoft Teams, or the phone if you would rather.
Your rights
Under UK data protection law you can ask me to give you a copy of what I hold about you, correct it if it is wrong, delete it, restrict what I do with it, hand it over in a portable form, or object to my handling it at all. Ask at info@dalaric.com and you will get an answer rather than a form to fill in.
If you think I have handled your information badly, you can complain to the Information Commissioner's Office at ico.org.uk. You are entitled to do that whether or not you raise it with me first, though I would rather you gave me the chance to put it right.
I acknowledge a request within five working days and answer it in full within a month, which is the limit the law sets. That limit can be extended by a further two months where a request is genuinely complicated, and if that ever applies to yours I will tell you inside the first month and say why.
I am not going to promise seventy two hours on a public page. One holiday would make it false, and a commitment I can always keep is worth more than a faster one I cannot.
Client systems, which are a separate matter
When I work on your infrastructure I may have access to systems holding your customers' information. That relationship is governed by the agreement covering that work rather than by this notice, which is about the information you send me through this site.
Where that work means handling information about your customers, a data processing agreement forms part of the agreement for it as standard, rather than being something to ask for, negotiate or pay extra for. The law requires it in writing and it protects you rather than me, so there is nothing to argue about.
Changes
The version you are reading took effect on the day this site was published, and the list below says what has changed since then, most recent first. This site is kept in version control, so that history exists whether or not the list does; the list is only there to save you reading a repository.
If something changes what actually happens to your information, I will email clients about it. A corrected typo does not get an email. Saying where that line falls is what makes the promise worth anything.
- 2 September 2026. The ten open questions on this notice were settled, and every supplier position in it was read from that supplier's own current document rather than assumed.