Privacy & Cookie Policy
[DRAFT: have this reviewed by a solicitor before publishing, complete the bracketed items, then delete this line.]
Effective from 9 October 2026.
1. Who we are
Saltire Spaces Ltd (“Saltire Spaces”, “we”, “us”) is the controller of the personal data described in this policy. We provide office suites, virtual office, virtual mail, registered office and AI receptionist services at our business centre in Dunfermline.
- Company: Saltire Spaces Ltd, registered in Scotland, company number SC899705
- Registered office: 54a Cow Wynd, Falkirk FK1 1PU
- Email: hello@saltirespaces.co.uk
- Website: www.saltirespaces.co.uk
- ICO registration number: CSN6537651
We have not appointed a Data Protection Officer because we are not required to. Please send any questions about this policy or your personal data to the email address above.
2. The personal data we collect
We collect personal data directly from you when you enquire, sign up, use our services or visit the centre. We also collect some data from third parties and automatically through our website.
| Category | Examples |
|---|---|
| Identity | Name, title, date of birth, photo ID (passport or driving licence) |
| Contact | Postal address, email address, phone number |
| Business | Business or company name, company number, directors and persons with significant control, trading address, nature of business |
| Verification (AML) | Copies of ID and proof of address, results of electronic identity checks, sanctions and PEP screening results |
| Financial | Bank details for Direct Debit, payment records, invoices, deposits, arrears |
| Contract | Licence agreements, membership type, start and end dates, deposit records |
| Mail handling | Sender and recipient details on post received, forwarding addresses, collection records |
| Call handling | Caller names, numbers, messages, call recordings and transcripts taken by our AI receptionist service |
| Building and security | Key issue records, visitor records, incident reports, CCTV images (where installed) |
| Communications | Emails, enquiry forms, phone calls, feedback |
| Website and technical | IP address, browser and device type, pages viewed, cookie identifiers (see section 8) |
| Marketing | Your marketing preferences and newsletter sign-up |
Third-party sources include Companies House, electronic identity verification providers, credit reference agencies, and people who refer you to us.
Callers to our clients. When our AI receptionist answers calls for a client, we process the caller’s details on that client’s behalf, as their processor. The client’s own privacy notice applies to those callers.
We do not knowingly collect special category data (such as health information). Our services are not aimed at anyone under 18.
3. Why we use your data and our lawful basis
We only use your personal data where UK data protection law gives us a lawful basis.
| Purpose | Lawful basis |
|---|---|
| Answering enquiries and providing quotes | Steps before a contract; legitimate interests |
| Setting up and managing your licence or membership | Contract |
| Providing virtual office, mail handling, registered office and AI receptionist services | Contract |
| Carrying out identity, anti-money laundering and sanctions checks | Legal obligation |
| Taking payments, invoicing, collecting debts and managing deposits | Contract; legitimate interests |
| Keeping accounting and tax records | Legal obligation |
| Building access, health and safety, and fire safety | Legal obligation; legitimate interests |
| CCTV for security and crime prevention (where installed) | Legitimate interests |
| Improving our website and services | Legitimate interests; consent for non-essential cookies |
| Sending news and offers by email | Consent, or legitimate interests for existing clients (soft opt-in) |
| Dealing with complaints, disputes and legal claims | Legitimate interests; legal obligation |
Our legitimate interests are running and securing our business centre, recovering money owed, improving our services, and keeping existing clients informed. We balance these against your rights and do not use them where your interests outweigh ours.
If you do not provide the information we need for a contract or a legal obligation, such as identity documents, we may be unable to provide our services.
You can withdraw consent at any time, for example by clicking “unsubscribe” or changing your cookie settings. This does not affect anything we did before you withdrew it.
We do not make decisions about you based solely on automated processing that have a legal or similarly significant effect.
4. Identity and anti-money laundering checks
Because we provide business addresses, registered office and mail handling services, we are a trust or company service provider. We are supervised by HM Revenue & Customs under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017.
This means we must verify the identity of all virtual office, registered office and suite clients, and of the beneficial owners of company clients, before we provide a service. We may use an electronic identity verification provider, which may run a check with a credit reference agency. This leaves a soft footprint on your credit file but does not affect your credit score.
We use the information gathered for these checks only to prevent money laundering and terrorist financing, unless you have agreed otherwise or another law allows it. Where the law requires, we may report suspicions to the National Crime Agency without telling you.
5. Who we share your data with
We never sell your personal data. We share it only with service providers who act on our instructions, and with others where the law requires.
| Recipient | Why |
|---|---|
| Xero | Accounting and invoicing |
| GoCardless | Direct Debit payments |
| Stripe | Card payments |
| PayPal | Online payments |
| Microsoft 365 | Email, calendar and file storage |
| Parthian Systems and WordPress plugin providers | Running our website and enquiry forms |
| CookieYes | Showing our cookie banner and keeping a record of your cookie choices |
| Google (Google Analytics) | Website statistics, only with your cookie consent |
| Our AI receptionist provider | Answering and recording calls for AI receptionist clients |
| [ID verification provider] | Identity, AML and sanctions checks |
| [Email marketing provider] | Sending newsletters, if you have signed up |
| Royal Mail and couriers | Forwarding your post |
| Our accountants, solicitors and insurers | Professional advice, claims and insurance |
| HMRC, the National Crime Agency, the police, courts and other authorities | Where we are legally required to |
If we sell or transfer our business, your data may pass to the new owner, who must use it in line with this policy.
International transfers. Some providers, such as Google, Stripe, PayPal and Microsoft, may process data outside the UK, including in the United States. Where they do, we rely on UK adequacy regulations (including the UK–US Data Bridge) or the International Data Transfer Agreement and the UK Addendum to standard contractual clauses.
6. How long we keep your data
We keep personal data only as long as we need it, then delete it securely or anonymise it.
| Data | How long we keep it |
|---|---|
| ID and AML check records | 5 years after our business relationship ends |
| Records of individual transactions | 5 years from the date of the transaction |
| Licence agreements, contracts and client correspondence | 6 years after our relationship ends |
| Invoices, payment and accounting records | 6 years from the end of the financial year they relate to |
| Deposit records | 6 years after the deposit is returned |
| Mail handling and forwarding logs | 12 months after the item is handled |
| AI receptionist call recordings and messages | [90 days], unless the client asks us to delete them sooner |
| Enquiries that do not become a booking | 12 months from the last contact |
| Marketing list | Until you unsubscribe; reviewed every 2 years |
| CCTV footage (where installed) | 30 days, unless needed to investigate an incident |
| Key issue and visitor records | 12 months |
| Accident and incident reports | At least 3 years |
| Website analytics data | 14 months (set in Google Analytics) |
After the AML retention period, we must delete the personal data from those checks. The only exceptions are where another law requires us to keep it, where it is needed for legal proceedings, or where you have agreed to us keeping it.
We may keep data for longer if there is a complaint, dispute or legal claim, until it is resolved.
7. Security, your rights and complaints
Security. We protect your data with access controls, password protection and multi-factor authentication on our systems, encrypted payment providers, and secure storage of paper records. Only people who need your data can access it. If a data breach is likely to put you at risk, we will tell you and the ICO as the law requires.
Your rights. Under UK data protection law you have the right to:
- access a copy of your personal data
- have inaccurate data corrected
- have your data deleted, where there is no good reason for us to keep it
- restrict how we use your data
- object to processing based on legitimate interests, and to direct marketing at any time
- receive your data in a portable format, or have it sent to another organisation
- withdraw consent at any time
Some rights do not apply in every case. For example, we cannot delete AML records before the legal retention period ends.
To exercise a right, email hello@saltirespaces.co.uk. We may ask you to confirm your identity. We will respond within one month, and there is usually no charge.
Complaints. Please contact us first so we can try to put things right. You also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk or on 0303 123 1113.
8. Cookie Policy
Cookies are small text files a website stores on your device. We use only essential cookies unless you choose to accept others through our cookie banner.
Types of cookies we use
- Strictly necessary. These are needed for the website to work and remember your cookie choices. They cannot be switched off.
- Analytics. We use Google Analytics to count visits and see which pages are popular, so we can improve the site. Google’s advertising features and data sharing are switched off, and data is kept for 14 months. These cookies are set only if you accept them.
- Marketing. We do not currently use advertising or tracking cookies. If we add them, we will ask for your consent first.
Cookies on our website
| Cookie | Provider | Type | Purpose | Duration |
|---|---|---|---|---|
| cookieyes-consent | Saltire Spaces (set by CookieYes) | Strictly necessary | Remembers your cookie choices | 1 year |
| wordpress_test_cookie | Saltire Spaces | Strictly necessary | Checks your browser accepts cookies | Session |
| _ga | Analytics | Distinguishes unique visitors | 2 years | |
| _ga_[ID] | Analytics | Keeps track of your session | 2 years |
Third-party content such as embedded Google Maps or YouTube videos may set their own cookies. We load these only after you consent.
Managing cookies. You can accept or reject non-essential cookies when you first visit the site, and change your choice at any time using the cookie settings button at the bottom of every page. You can also block or delete cookies in your browser settings, though some parts of the site may then not work. To opt out of Google Analytics on all websites, you can install the Google Analytics opt-out browser add-on.
9. Changes to this policy
We may update this policy from time to time, for example when we add new services or providers. The latest version will always be on our website, with the date it took effect. If we make significant changes, we will let current clients know by email.
