Privacy Policy
Effective Date: November 4, 2025 | Last Updated: September 17, 2026
Scope of This Policy
This Privacy Policy applies only to information collected through our website and general marketing communications. Client data handling during contracted cybersecurity services is governed by separate Service Agreements and Data Processing Agreements executed with each client.
Our Commitment
Montshield provides technology, security and AI services to family offices, trusts, law firms and private clients, for whom confidentiality is a professional obligation rather than a preference. We handle all personal information with the same confidentiality standards we apply to client engagements. We collect only the data required to provide services, respond to inquiries, and improve site performance. We do not sell, rent, or trade personal data.
Information We Collect
Information You Provide Directly
- Contact form: the name, email address, and any role, organization and preferred time you enter, together with your message. This is sent to us by email and is not stored in a database on this website.
- Document requests: when you request a guide or toolkit, we record your work email address, the document requested, the date, and the IP address the request came from, so that we can issue a time-limited download link and keep a record of who received which document. These records are stored on our web server and copied to a private spreadsheet we use to manage enquiries.
- Job applications: if you write to cv@montshield.com, we receive your email and whatever you choose to attach, normally a CV and a covering note. It is read by the people who would work with you, is not shared outside Montshield, and is not used for anything other than considering you for work here.
- Consultation bookings: if you book a meeting, the booking is handled by Cal.com, and the details you enter there (including any notes) are processed by Cal.com on our behalf.
Information Collected Automatically
- Server logs: our hosting provider records standard web server data for each request, including IP address, browser and operating system, the page requested, and the date and time.
- Anti-abuse records: to limit automated submissions we keep short-lived counters against a one-way hash of your IP address and, for document requests, of your email address. The original values cannot be recovered from them.
- Spam protection: our forms use hCaptcha, which runs its own checks in your browser and receives your IP address as part of that process.
Information We Do Not Collect
This website uses no analytics, advertising or social media tracking, and sets no cookies of its own. We do not collect sensitive personal data (health, financial details, biometric data) through the website, do not track precise location, do not buy information from data brokers, and do not collect social media profile information unless you send it to us.
How We Use Your Information
Service Delivery and Communication
- Responding to your inquiries and consultation requests
- Scheduling and managing meetings or consultations
- Sending the documents you request
- Providing customer support
Website Operation and Improvement
- Maintaining website functionality and security
- Preventing automated abuse of our forms
- Detecting and preventing fraud, abuse, or security incidents
We do not: Sell, rent, or trade personal information; use data for advertising without consent; or share information with third parties for their marketing purposes.
Cookies and Tracking Technologies
Cookies are small text files a website can store on your device. This website sets no cookies of its own, and uses no analytics, advertising or social media tracking. There is therefore no cookie consent banner.
Cookies set by services we embed
- hCaptcha (Intuition Machines, Inc.): protects our contact and document request forms against automated abuse, and may set cookies or similar browser storage when a form is shown.
- Cal.com: provides the consultation booking window. It loads only when you choose to book a meeting, and may set its own cookies at that point.
Each service acts under its own privacy terms for the data it collects in your browser. The rest of this website works without either of them loading.
Managing cookies
Most browsers let you refuse or delete cookies and site data. This does not affect the information pages on this site; it may prevent the booking window or the form verification step from working.
How We Share Information
We share personal information only in the following limited circumstances:
Service Providers
We engage carefully selected third-party service providers who process data on our behalf under strict confidentiality obligations:
- Website hosting: our hosting provider operates the servers for this website and its email.
- hCaptcha (Intuition Machines, Inc.): form abuse prevention.
- Cal.com: consultation scheduling, when you choose to book a meeting.
- Google Sheets (Google): the private spreadsheet in which we record document requests. We do not use Google Analytics or any other analytics service.
Legal Requirements
We may disclose information when required by law: in response to valid legal process (subpoenas, court orders); to comply with regulatory obligations; to protect our rights, property, or safety, or those of others; or in connection with fraud prevention or security investigations.
International Data Transfers
Montshield operates globally and may transfer personal data across borders for processing and storage. When transferring data internationally, we implement appropriate safeguards including Standard Contractual Clauses and data processing agreements with explicit security requirements.
Data Security
We implement comprehensive security measures to protect your information:
Technical Safeguards
- Encryption: TLS/SSL encryption for all data in transit
- Access Controls: Role-based access with multi-factor authentication
- Monitoring: Continuous security monitoring and intrusion detection
- Backup Systems: Encrypted backups with geographic redundancy
Organizational Safeguards
- Strict internal access policies (need-to-know basis)
- Confidentiality agreements for all personnel
- Regular security awareness training
Data Breach Response: If there is a data breach, we will assess the incident immediately, notify affected individuals within 72 hours (or as required by law), and provide guidance on protective measures you can take.
Data Retention
We retain personal information only as long as necessary for legitimate purposes:
- Contact form emails: 2 years from our last exchange with you, unless you ask us to delete them sooner.
- Document request records: 2 years, in the server records and the enquiry spreadsheet.
- Job applications: 2 years from our last exchange with you, so we can come back to you if something suitable appears. Ask us and we will delete it sooner.
- Download links and anti-abuse counters: download links expire after 24 hours; abuse counters reset within an hour.
- Server logs: retained by our hosting provider for its standard period, and used only for security and troubleshooting.
After retention periods expire, we securely delete or anonymize personal information through secure deletion protocols, cryptographic erasure, and removal from backup systems within standard backup rotation cycles.
Your Rights and Choices
You have the following rights regarding your personal information:
Access and Portability
- Right to Access: Request confirmation of what personal data we hold about you
- Right to Data Portability: Receive your data in structured, machine-readable format
Correction and Deletion
- Right to Rectification: Request correction of inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data, subject to legal retention requirements
Processing Controls
- Right to Restrict Processing: Request limitation of how we process your data
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw previously given consent at any time (e.g., unsubscribe from emails)
Exercising Your Rights
To exercise any of these rights, contact us using the information below. Include your full name, email address, specific right you wish to exercise, and details to help us locate your information. We will respond within 30 days (or as required by applicable law). We do not charge fees for legitimate requests.
Supervisory Authority: If you are located in the EEA, Switzerland, or UK, you have the right to lodge a complaint with your local data protection supervisory authority if you believe we have processed your data unlawfully.
Additional Privacy Rights
Legal Basis for Processing (EEA/UK/Swiss Visitors)
If you are located in the European Economic Area, United Kingdom, or Switzerland, we process your personal data under the following legal bases:
- Consent: Where you have given it explicitly — for example, by sending us a document request or booking a consultation
- Contract Performance: To deliver services you have requested
- Legitimate Interests: To operate our business, improve services, and ensure security
- Legal Obligations: To comply with laws and regulations
California Privacy Rights (CCPA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act:
- Right to Know: Request disclosure of personal information collected, used, or sold
- Right to Delete: Request deletion of personal information
- Right to Opt-Out: We do not sell personal information
- Right to Non-Discrimination: Not be discriminated against for exercising CCPA rights
Other Important Information
Children's Privacy
Montshield's services are directed to businesses and adults. We do not knowingly collect personal information from individuals under 18 years of age. If we learn we have collected information from a minor without parental consent, we will delete it immediately.
Third-Party Links
Our website may contain links to third-party websites or resources. We are not responsible for the privacy practices of these external sites. We recommend reviewing the privacy policies of any third-party sites you visit. This Privacy Policy applies only to information collected by Montshield.
Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, services, legal requirements, or technological developments. When we make material changes, we will update the "Last Updated" date at the top of this policy, so you can see at a glance whether it has changed since you last read it. For significant changes affecting your rights, we will notify you by email if we have your address. Continued use of our services after changes take effect constitutes acceptance of the updated policy.
Contact Us
If you have questions about this Privacy Policy, our data practices, or wish to exercise your privacy rights, please contact us:
Privacy Inquiries: privacy@montshield.com
Response Time: We will respond to all privacy requests within 30 days
Questions or Concerns? We are committed to addressing your privacy concerns promptly and transparently. If we have handled your information in a way you did not expect, we would rather hear it from you than not.