Privacy & Cookies Notice
Contents
- Introduction
- Who this policy covers
- Information we collect on our website
- Legal basis for processing
- How we use your information
- Who we share your information with
- International data transfers
- How we keep you updated
- Your rights over your information
- How long we keep your information
- Security
- Data breach notification
- Your data and social networks
- Cookies
- How to contact us
- Changes to this policy
1. Introduction
Cornerstone Consulting Group is a trading name of Bridge to Cloud, LLC, registered in Dallas, Texas, USA (Registration No. 84-4045030), operating together with Cornerstone Consulting Group (UK) and CCG Partners India Private Limited, our UK and India group entities respectively.
We are committed to protecting the privacy and security of your personal information. We take care to protect the privacy of our customers and users of our products and services who communicate with us online or offline, at events, over the phone, and through our website and social media platforms. This policy explains what data we collect, what we do with it, how we keep it secure, and the rights and choices you have over it.
2. Who this policy covers
For the purposes of the EU GDPR, Bridge to Cloud, LLC (trading as Cornerstone Consulting Group) is the Data Controller of your personal information. For the purposes of the UK GDPR, Cornerstone Consulting Group (UK) is the Data Controller. For the purposes of India's Digital Personal Data Protection Act 2023 (“DPDP Act”), CCG Partners India Private Limited acts as the Data Fiduciary for personal data processed in connection with our India operations. Any third party we use to process personal data on our behalf (see Section 6) acts as our Data Processor.
3. Information we collect on our website
We only collect, process, and store personally identifiable information in accordance with the GDPR, UK Data Protection Act 2018, and India's DPDP Act 2023, and use it expressly to respond to enquiries or to send marketing information you have requested.
The data we collect includes details of your journey through our website, plus device information such as IP address, browser version, operating system, and approximate geographical location. This website does not host a contact form; enquiries are made by emailing us using the links provided across the site. When you email us, we collect your name, email address, the content of your message, and the date of your enquiry.
You are under no statutory or contractual obligation to provide your personal information; however, we need at least the information above to respond to your enquiry.
4. Legal basis for processing
The table below sets out the legal basis for each way we process personal data collected through the website.
| Processing activity | Data collected | Legal basis | Applicable regime |
|---|---|---|---|
| Email enquiry | Name, email, message, IP address | Consent / legitimate interest | GDPR, UK GDPR, DPDP |
| Marketing emails | Name, email, preferences | Consent | GDPR, UK GDPR, DPDP |
| Marketing automation (HubSpot) | Contact details, engagement data | Consent / legitimate interest | GDPR, UK GDPR, DPDP |
| Event bookings (third party) | Name, email, attendance data | Contract performance / consent | GDPR, UK GDPR, DPDP |
5. How we use your information
- To contact you following your enquiry, and to reply to questions, suggestions, or complaints
- To make available our products and services to you
- For statistical analysis and to get feedback about our website and services
- To power security measures so you can safely access our website
- To contact you about products and services from us, where you have consented
- To help answer your questions and resolve issues
7. International data transfers
As a group operating through Bridge to Cloud, LLC (USA), Cornerstone Consulting Group (UK), and CCG Partners India Private Limited (India), personal data may be transferred between these entities, as well as to the third-party providers listed in Section 6, some of whom process data outside the UK, EEA, or India — including in the United States.
Where this occurs, we ensure your personal data continues to receive a level of protection consistent with UK GDPR, EU GDPR, and DPDP Act requirements. The specific safeguards we rely on are set out below.
| Recipient / transfer | Location | Safeguard relied upon |
|---|---|---|
| Vercel Inc. | USA | Standard Contractual Clauses and the UK International Data Transfer Addendum, incorporated in Vercel's Data Processing Addendum |
| HubSpot, Inc. | USA | EU-US Data Privacy Framework (with the UK Extension and the Swiss-US DPF), supplemented by Standard Contractual Clauses in HubSpot's Data Processing Agreement |
| Sanity AS | Norway (EEA) | Located in the EEA; transfers from the UK rely on the UK's adequacy regulations for the EEA |
| Intra-group transfers | US, UK, India | Standard Contractual Clauses and the UK Addendum under an intra-group data transfer agreement |
8. How we keep you updated on our business, products and services
From time to time we may send you relevant offers and news about our business by email, but only if you have consented to receive marketing communications. You can withdraw consent at any time by unsubscribing via the link in any marketing email or by contacting us using the details in Section 15.
9. Your rights over your information
Under the UK GDPR and EU GDPR, you have the right to:
- Access the personal information we hold about you (Subject Access Request)
- Rectification — correct inaccurate or incomplete personal data
- Erasure — request deletion of your personal data (“right to be forgotten”)
- Restriction of processing in certain circumstances
- Data portability — receive your data in a portable format
- Object to processing, including for direct marketing
- Withdraw consent at any time, without affecting processing carried out before withdrawal
Under India's DPDP Act 2023, as a Data Principal you have the right to:
- Access information about how your personal data is being processed
- Correction and erasure of your personal data
- Grievance redressal
- Nominate another individual to exercise your rights on your behalf in the event of death or incapacity
- Withdraw consent as easily as it was given
We aim to respond to all rights requests within 30 days. The Information Commissioner's Office (ICO) regulates data protection in the UK, and the Data Protection Board of India performs an equivalent role under the DPDP Act; you may complain to either, though we hope you'll raise concerns with us first.
10. How long we keep your information for
We retain personal data only as long as necessary for the purpose it was collected, as set out below.
| Data category | Retention period | Basis |
|---|---|---|
| Enquiry / email contact data | 3 years from last contact | Legitimate interest in managing prospect relationships |
| Marketing / email subscription data | Until consent withdrawn, then deleted within 30 days | Consent |
| CRM records (customers) | Duration of relationship + 6 years | Contractual and legal (tax/audit) obligations |
| Cookie consent records | 12 months, then re-prompt | Accountability / audit evidence |
11. Security
Data security is of great importance to us. This website is hosted on Vercel's cloud infrastructure and served over HTTPS. We take the following measures to protect your information:
- Encryption in transit (HTTPS/TLS) across all communication between your browser and this website
- Access controls limiting who can reach our systems and administrative interfaces
- A secure, password/FTP-free code deployment process
- Two-factor authentication on administrative interfaces, where available
- Edge-level protection and traffic filtering provided by our hosting platform
- Regular monitoring and updates of the platform and its supporting dependencies
12. Data breach notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required under GDPR/UK GDPR, and will notify affected individuals and, where applicable, the Data Protection Board of India under the DPDP Act, without undue delay.
15. How to contact us
If you would like to exercise any of the rights set out in Section 9, or have a question or complaint about this policy:
- Assigned Data Protection Officer: Simon Hornby, Managing Partner
- By email: info@cornerstone-consulting.io — this address is our designated channel for all privacy rights requests, including Subject Access Requests and general enquiries
- India Grievance Officer (as required under the DPDP Act 2023): Jonathan Justus, info@cornerstone-consulting.io. Data Principals in India can direct grievance redressal requests to this contact.
- By post: 5050 Quorum Dr, Suite 700, Dallas, TX 75254, USA
16. Changes to this policy
This policy was last updated on 30 July 2026.
Bridge to Cloud, LLC
13. Your data and social networks
When using this website, you may be able to share information through social networks such as LinkedIn or Twitter/X. Please remember it is your responsibility to set appropriate privacy settings on your own social network accounts.