Company: Onward Shift Limited (company number 15583217)
Last updated: 25th August 2026
Website: https://onwardshift.com
Privacy contact: jo*****@*********ft.com
This Privacy Policy explains what personal information Onward Shift collects, why it is used, who it may be shared with, how long it is kept and the rights available to the people whose information we handle. It works alongside our Terms and Conditions, Cookie Policy, Data Deletion Policy, Code of Ethics, Provider Agreement and any service-specific privacy information given when information is collected.
1. About this Privacy Policy
1.1 This Privacy Policy is the privacy notice of Onward Shift Limited. It applies when we decide why and how personal information is used in connection with our Website, Services, Events, Products, Provider panel, corporate and education work and communications.
1.2 The main laws relevant to this Policy include the UK General Data Protection Regulation, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 and the Data (Use and Access) Act 2025, as amended or replaced.
1.3 This Policy is information, not a contract. We do not ask people to ‘agree’ to a privacy policy as a substitute for identifying a lawful basis for using personal information.
1.4 Different parts of this Policy apply depending on whether you are a website visitor, customer, attendee, coaching or counselling client, employee or learner of a Business Client, parent or guardian, supplier, applicant or Provider.
1.5 Where a form, Booking Confirmation, professional privacy notice or other notice gives more specific information about a particular use of data, that specific information should be read with this Policy.
2. Who we are and how to contact us
2.1 Onward Shift Limited is a company registered in England and Wales under company number 15583217. Our registered office is 167-169 Great Portland Street, Fifth Floor, London, England, W1W 5PF.
2.2 For the personal information covered by this Policy, Onward Shift is normally the controller. This means we decide the purposes and essential means of the relevant processing.
2.3 Our privacy contact is jo*****@*********ft.com. Questions, rights requests and data-protection complaints may be sent to that address. Postal requests may be sent to our registered office.
2.4 We have not described every service partner as our processor because legal roles depend on the particular processing activity. Section 4 explains how roles may differ.
3. Who this Policy applies to
3.1 This Policy applies to people who browse the Website; contact us; subscribe to communications; purchase or receive Services, Events, Physical Products or Digital Content; apply to join or work through our Provider panel; or otherwise interact with Onward Shift.
3.2 It also applies to individual contacts and attendees whose information is supplied by a company, education provider, charity, public body, event organiser, parent, guardian or other authorised person.
3.3 It does not govern information for which an independent Provider, Business Client, education provider, payment provider, event platform, social-media service or other third party is the controller. Their own privacy notice will apply to that processing.
4. Onward Shift, Providers and Business Clients
4.1 Onward Shift is the controller for its Website, general enquiries, marketing lists, customer administration, bookings made with Onward Shift, payments received by Onward Shift, Provider-panel administration, complaints and its own safeguarding records.
4.2 Where Onward Shift contracts with a customer and appoints a Provider, Onward Shift and the Provider may each be controllers for different parts of the service. For example, Onward Shift may control booking data while a counsellor controls their professional notes and clinical decisions.
4.3 Where Onward Shift only introduces a customer to a Provider and the customer contracts directly with that Provider, the Provider is normally the controller for the professional service and will provide their own privacy information.
4.4 A Business Client or education provider that gives us employee, learner or attendee information is normally a separate controller for its collection and disclosure of that information. It must have a lawful basis and give people any privacy information it is responsible for providing.
4.5 If Onward Shift processes personal information only on a Business Client’s documented instructions, the parties will put an appropriate data-processing agreement in place. The actual role is determined by what each party does, not only by the label used in a contract.
4.6 A Booking Confirmation or service-specific notice may explain the roles that apply to a particular service where they would not otherwise be clear.
5. Personal information we may collect
5.1 Identity and contact information: name, title, age or date of birth where relevant, email address, telephone number, postal or delivery address, emergency contact and preferred method of communication.
5.2 Booking and service information: enquiries, appointments, attendance, accessibility requirements, requested support, communication history, feedback, complaints and information needed to organise or deliver a Service or Event.
5.3 Transaction and account information: products or services purchased, order history, invoices, payment status, refunds, delivery details and limited payment confirmation. Payment-card information is normally handled directly by a payment provider rather than stored by Onward Shift.
5.4 Provider and applicant information: professional biography, photograph, contact and business details, availability, qualifications, registrations, references, insurance, experience, fees, bank details, tax information, right-to-work or identity evidence where required, DBS status where relevant, performance information and complaints.
5.5 Wellbeing and special-category information: information about physical or mental health, disability, accessibility, racial or ethnic origin, religion or beliefs, sexual orientation or other sensitive matters where a person chooses to disclose them or they are necessary for a relevant service, safety or safeguarding purpose.
5.6 Technical information: IP address, browser and device type, operating system, approximate location derived from an IP address, referral source, pages viewed, dates and times, error and security logs, cookie identifiers and consent preferences.
5.7 Marketing and content information: subscription preferences, email engagement, survey responses, competition entries, testimonials, photographs, audio, video, podcast or event contributions, and social-media interactions.
5.8 Legal, safety and complaint information: incident reports, alleged misconduct, safeguarding concerns, risk information, correspondence with advisers or authorities and information necessary to establish, exercise or defend legal claims.
6. How we collect personal information
6.1 We collect information directly when a person completes a form, contacts us, makes a Booking, purchases a Product, subscribes, attends an Event, applies to join the Provider panel, responds to a survey or communicates by email, telephone, video call, messaging service or social media.
6.2 We may receive information from a Business Client, education provider, parent, guardian, event organiser, Provider, referral partner or other person authorised to arrange a Service or Event.
6.3 We receive transaction or operational information from payment processors, booking and event platforms, delivery partners, website and email providers, analytics tools, identity or professional-verification sources and other service providers.
6.4 We may collect publicly available professional information from company websites, professional registers, Companies House, social media and other legitimate public sources when assessing a business relationship or Provider application.
6.5 Technical information may be collected automatically through server logs, cookies and similar technologies. Non-essential cookies are addressed in our Cookie Policy and consent controls.
7. Special-category and criminal-offence information
7.1 Health information and certain other sensitive information are special-category data. We must have both an Article 6 lawful basis and a separate Article 9 condition before using this information.
7.2 Depending on the service and the organisation responsible, an Article 9 condition may include explicit consent; health or social-care purposes where processing is carried out by or under the responsibility of an appropriately qualified professional subject to confidentiality; protection of vital interests where a person is physically or legally incapable of consenting; legal claims; or substantial-public-interest conditions such as safeguarding where the Data Protection Act 2018 requirements are met.
7.3 We do not treat vital interests as a general basis for collecting health information merely because our work concerns mental health. It is reserved for genuinely necessary life-protecting circumstances.
7.4 Where we rely on explicit consent, the request will be specific and separate. Consent may be withdrawn at any time, although this does not make earlier lawful processing unlawful and may affect whether a requested service can continue.
7.5 We will not use identifiable health or wellbeing information to target advertising, decide whether somebody is employable or create unrelated commercial profiles.
7.6 We process criminal-conviction or offence information, including DBS information, only where authorised by law, an appropriate lawful basis and any required Data Protection Act 2018 Schedule 1 condition. We aim to record the minimum necessary result or status rather than retain a full certificate unless there is a justified legal need.
8. Why we use personal information
8.1 We use personal information only for specified and legitimate purposes. The main purposes and typical lawful bases are set out below. More than one basis may apply to a processing activity, but we will identify and document the basis that applies before processing begins.
Purpose | Typical information | Typical lawful basis |
Respond to enquiries and prepare a requested proposal or Booking | Identity, contact, organisation and enquiry details | Steps requested before a contract; legitimate interests in responding to business enquiries |
Administer and deliver Services, Events, Products and Digital Content | Booking, contact, attendance, delivery and service information | Contract; legitimate interests for business contacts and operational administration |
Take payment, issue invoices, process refunds and keep financial records | Transaction, payment status, invoice, tax and order information | Contract; legal obligation; legitimate interests in debt recovery and accounting |
Match customers with Providers and manage the Provider panel | Profile, availability, competence, vetting, booking and performance information | Steps before a contract; contract; legitimate interests; legal obligation where applicable |
Tailor wellbeing, coaching, counselling or accessibility support | Service information and relevant health or other special-category data | Contract or legitimate interests, plus an applicable Article 9 condition described in Section 7 |
Protect safety, respond to safeguarding concerns and manage incidents | Contact, risk, health, incident and communication information | Legal obligation; vital interests; recognised or ordinary legitimate interests; applicable Article 9 or DPA 2018 condition |
Improve services, understand demand and produce reporting | Feedback, usage, booking and engagement information | Legitimate interests; consent where required; anonymous information where identification is unnecessary |
Send newsletters and marketing | Name, email, organisation, preferences and engagement | Consent where required; legitimate interests only where electronic-marketing law permits, including a valid soft opt-in |
Operate, secure and troubleshoot the Website and systems | Technical, device, log, fraud and security information | Legitimate interests in security and service operation; legal obligation where applicable |
Use analytics and non-essential cookies | Cookie identifiers, device, usage and preference information | Consent for Google Analytics and other non-essential Website technologies. |
Publish agreed testimonials, profiles, photographs, podcasts or recordings | Name, image, voice, role, biography and contribution | Consent, contract or legitimate interests depending on the agreed use and the person’s reasonable expectations |
Handle rights requests, complaints, disputes and legal claims | Identity, contact, request, complaint, evidence and correspondence | Legal obligation; legitimate interests; legal claims and other relevant special-category conditions |
8.2 Where we rely on legitimate interests, those interests may include running and protecting the business, administering professional relationships, responding to corporate contacts, improving services, preventing misuse and establishing or defending legal claims. We consider necessity, reasonable expectations and the possible impact on the individual before relying on this basis.
8.3 Where the law provides a recognised legitimate interest, including certain safeguarding, emergency, crime-prevention purposes or disclosures requested for public tasks, we will rely on it only where the statutory conditions are met.
9. When information is required
9.1 Some information is needed to enter into or perform a contract, verify a Provider, comply with law, deliver an order, arrange accessibility or manage safety. We will aim to identify required fields at the point of collection.
9.2 If required information is not provided, we may be unable to respond fully, confirm a Booking, make payment, deliver a Product, provide a Service safely or accept a Provider onto the panel.
9.3 Information requested for optional marketing, a testimonial, public profile enhancement, survey or unrelated research is voluntary. Refusing it will not remove a separate service a person is otherwise entitled to receive.
10. Coaching, counselling and professional confidentiality
10.1 Onward Shift normally keeps the booking, payment, matching, complaint and safeguarding information needed to administer a professional service. We do not need routine access to detailed counselling or coaching notes merely because a booking was made through us.
10.2 A counsellor, coach or other regulated or professionally accountable Provider may keep their own notes and records as an independent controller. Their privacy notice, professional duties, insurer requirements and retention policy will apply to those records.
10.3 We do not routinely give an employer, education provider or funding organisation the content of an individual’s coaching or counselling sessions, their health information or detailed reasons for seeking support.
10.4 Where an organisation funds a service, we may provide clearly explained administrative information necessary to operate the arrangement, such as eligibility, booking usage or attendance status, and aggregated or anonymised reporting. Identifiable information will not be included in wellbeing reporting unless there is a separate lawful and transparent reason.
10.5 Confidentiality may be limited where information must be used or shared to address a serious risk of harm, a safeguarding concern, professional or regulatory duties, a legal requirement or a legal claim. Only relevant information should be shared and the person will normally be informed unless doing so would be unsafe, unlawful or undermine the purpose.
11. Corporate and education Services
11.1 A Business Client or education provider should provide only the minimum attendee information needed for delivery and should avoid sending health information unless it is necessary for accessibility, safety or an agreed service.
11.2 The organisation supplying information is responsible for ensuring that its disclosure is lawful and for giving employees, learners, parents, guardians or attendees any privacy information it is required to provide.
11.3 Attendance lists, evaluation forms and feedback will be used only for the stated delivery, safety, reporting and improvement purposes. Reports should normally use aggregated or anonymised information where individual identification is unnecessary.
11.4 Where services involve people under 18 or vulnerable adults, the Business Client or education provider remains responsible for its own consent, supervision and safeguarding arrangements, while Onward Shift and Providers remain responsible for their own lawful processing and safeguarding actions.
12. Provider applications and public profiles
12.1 We use Provider information to assess suitability, verify relevant credentials, manage availability and fees, arrange work, make payments, publish an agreed profile, handle feedback and protect customers and the Onward Shift platform.
12.2 Information intended for a public profile, such as a biography, photograph, specialist areas, qualifications and professional links, will be identified before publication. Private contact, payment, vetting and complaint information will not be included in the public profile.
12.3 We may contact referees, professional bodies, insurers or public registers where this is necessary and proportionate. The Provider should tell a referee before giving us their details.
12.4 Providers receive customer or attendee information only to the extent reasonably necessary for the engagement, professional responsibilities, accessibility, safety, safeguarding or legal compliance. They must not reuse it for unrelated marketing or private solicitation.
13. Children and young people
13.1 Onward Shift coaching, counselling and therapy Services are available only to people aged 18 or over. People under 18 may still take part in suitable education talks, workshops or Events arranged by a parent, guardian, school, college, employer or authorised organisation.
13.2 For education talks, workshops and Events, we aim to collect as little identifiable learner information as possible. An attendance list may be managed by the education provider rather than Onward Shift where individual details are unnecessary.
13.3 Where we give privacy information directly to a child or young person, it should be clear and age appropriate. Their best interests, vulnerability and reasonable expectations will be considered when deciding whether and how to use their information.
13.4 We do not knowingly rely on the online consent of a child under 13 for an information-society service. If such processing becomes relevant, verified parental authorisation and the Children’s Code requirements will be considered before the service is offered.
13.5 If we learn that a child’s information was provided without appropriate authority, we will assess the position and delete, restrict or otherwise handle it in accordance with law and safeguarding responsibilities.
14. Who we may share personal information with
14.1 Providers and delivery partners: speakers, facilitators, coaches, counsellors, trainers, event staff, delivery companies and others who need information to fulfil a Booking or Product order.
14.2 Technology and administration providers: website and cloud-hosting providers, email and messaging services, booking and event platforms, payment processors, accounting systems, customer-management tools, analytics services, form providers, document storage, IT support and security providers.
14.3 Business Clients and education providers: limited administration, attendance, eligibility or reporting information where this is part of the transparent service arrangement, subject to the confidentiality safeguards in Sections 10 and 11.
14.4 Professional advisers and insurers: accountants, lawyers, auditors, insurers, clinical or safeguarding consultants and other advisers where reasonably necessary and subject to appropriate duties of confidentiality.
14.5 Authorities and protective services: emergency services, safeguarding bodies, regulators, courts, law-enforcement agencies, tax authorities or other competent bodies where disclosure is necessary, lawful and proportionate.
14.6 Business changes: a prospective buyer, investor, funder or successor where relevant to a genuine restructuring, investment or sale, subject to confidentiality and data-protection safeguards.
14.7 We do not sell personal information. We do not give identifiable health or counselling information to data brokers or advertisers.
14.8 Where a supplier acts as our processor, it must process information on documented instructions under a suitable contract and provide appropriate security and confidentiality commitments.
15. International transfers
15.1 Some technology, payment, communications or platform providers may store personal information, or allow it to be accessed, outside the United Kingdom.
15.2 Where a restricted transfer occurs, we will use a lawful transfer mechanism and apply the current UK data-protection test. Depending on the destination and provider, this may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved contractual clauses or another mechanism recognised by UK law.
15.3 Where required, we will carry out a proportionate transfer risk assessment and use supplementary contractual, organisational or technical measures. Information about the relevant safeguard may be requested from jo*****@*********ft.com, subject to necessary redactions.
16. Security and personal-data breaches
16.1 We use proportionate technical and organisational measures designed to protect personal information against unauthorised access, loss, misuse, alteration or disclosure. Measures may include access controls, multi-factor authentication, encryption in transit, secure cloud storage, confidentiality obligations, backups, updates and supplier review.
16.2 Access is limited according to role and need. Providers and staff must handle personal information confidentially and report suspected loss, misuse or unauthorised access promptly.
16.3 No system is completely secure. We maintain a process to assess and respond to suspected personal-data breaches, notify the Information Commissioner’s Office where required and inform affected people without undue delay where a breach is likely to create a high risk to their rights and freedoms.
17. How long we keep personal information
17.1 We keep identifiable information only for as long as reasonably necessary for the purpose for which it was collected, including service delivery, safety, safeguarding, insurance, professional standards, complaints, tax, accounting and legal claims. Our standard retention periods are set out below. We may keep information for a shorter or longer period where the circumstances, the law or a professional requirement justify it.
Information | Standard retention period or criterion |
General enquiries not leading to a Booking | Normally up to 12 months after the last meaningful contact, unless an ongoing relationship, complaint or legal issue justifies longer retention. |
Bookings, contracts, orders, invoices and payment records | Normally up to 6 years after the relationship, transaction or relevant accounting period, subject to tax, accounting and limitation requirements. |
Coaching, counselling or therapy administration held by Onward Shift | Normally up to 6 years after the last Service. A Provider’s professional notes are kept under the Provider’s own privacy notice and retention policy. |
Event registration and ordinary attendance data | Normally up to 12 months after the Event. Incident, complaint or safeguarding information may be kept longer under the relevant category below. |
Consent, opt-out and suppression records | Normally up to 6 years for consent evidence. A minimal suppression record may be kept for as long as needed to prevent unwanted contact. |
Unsuccessful Provider applications | Normally up to 12 months after the decision, unless a longer talent-pool period was agreed or a complaint or legal issue requires retention. |
Successful Provider, supplier and due-diligence records | Normally up to 6 years after the relationship ends. Identity and vetting evidence is kept for the shortest justified period. |
Complaints, safeguarding, incidents and legal claims | Normally up to 6 years after closure, or longer where necessary for a child or vulnerable person, regulator, insurer, or active or anticipated legal proceedings. |
Marketing contacts | Until consent is withdrawn, the person objects, or the record is removed after an appropriate inactivity review. A minimal suppression record may remain. |
Website logs, analytics and technology identifiers | For the period stated in the Cookie Policy or relevant tool setting, normally no longer than 24 months unless a shorter setting or a justified security need applies. |
Photographs, recordings, podcasts and testimonials | For the agreed publication or archive period. Withdrawal normally stops new consent-based use but may not require recall of material already lawfully published where recall is not reasonably practicable. |
Protected backups | Deleted information may remain beyond ordinary use until it is overwritten through the normal backup cycle, normally within 90 days, unless it must be isolated for security or legal reasons. |
17.2 We review retained information and securely delete or anonymise it when it is no longer needed. A specific legal, safeguarding, insurance or professional requirement may justify a different period, which should be documented.
17.3 Erasure from live systems may not remove information immediately from encrypted backups. Backup information is not restored for ordinary use and will be overwritten in the normal cycle unless it must be retained for a lawful reason.
18. Anonymisation, statistics and research
18.1 Where we do not need to identify a person, we aim to use aggregated or genuinely anonymised information. Information that can still be linked to a person using additional data is pseudonymised, not anonymous, and remains protected as personal information.
18.2 Genuinely anonymised information may be kept for longer, including indefinitely, because it is no longer personal data. We may use it to understand demand, evaluate services, identify broad wellbeing trends and improve mental-health support in construction and education.
18.3 We will not describe data as anonymised merely because names have been removed. We will consider whether individuals could reasonably be reidentified from small groups, free-text responses, rare characteristics or other available information.
18.4 If identifiable or pseudonymised information is used for research or statistics, we will identify an appropriate lawful basis, meet any special-category conditions, apply safeguards and provide additional information where required.
19. Marketing communications
19.1 We may send newsletters, event information, resources and promotional communications where a person has given valid consent or where another rule lawfully permits the communication.
19.2 For electronic marketing to individuals, we normally require consent unless every requirement of a valid products-and-services soft opt-in is met. The soft opt-in does not apply merely because somebody made an enquiry or is a new prospect.
19.3 Different rules may apply to corporate subscribers and business contacts, but individuals may still object to direct marketing and we will respect that objection.
19.4 Every marketing email should provide a clear way to unsubscribe. A person may also contact jo*****@*********ft.com. Opting out of marketing does not stop essential service, booking, safety or legal communications.
19.5 We do not use identifiable health or counselling information to select people for marketing.
20. Cookies and similar technologies
20.1 The Website uses cookies and similar technologies for essential functionality, security, preferences, analytics and, where enabled, marketing or embedded third-party content.
20.2 Strictly necessary technologies may be used without consent where the law permits. Google Analytics, advertising technologies and optional embedded content will not be used before valid consent.
20.3 The services and Website technologies we use, their purposes, typical storage periods and available controls are explained in our Cookie Policy at https://onwardshift.com/cookies-policy/.
21. Automated decision-making and profiling
21.1 We may use ordinary automation to send confirmations, record preferences, organise enquiries or detect technical misuse.
21.2 We do not currently make solely automated decisions using personal information that have a legal or similarly significant effect on an individual. We do not make such decisions using special-category information.
21.3 If this changes, we will update this Policy, explain the logic and likely consequences as required, and apply safeguards including a route for human review, representations and challenge.
22. Your data-protection rights
22.1 Depending on the circumstances, you may have the right to be informed; obtain access to your personal information; correct inaccurate information; have incomplete information completed; request erasure; restrict processing; object to processing; receive certain information in a portable format; and exercise rights relating to significant automated decisions.
22.2 Where processing is based on consent, you may withdraw consent at any time. Where processing is based on legitimate interests or direct marketing, you may object. An objection to direct marketing will be honoured.
22.3 These rights are not absolute. For example, we may need to retain information to comply with law, protect safeguarding interests, maintain a suppression record, establish or defend legal claims, or preserve another person’s rights.
22.4 To make a request, email jo*****@*********ft.com with enough information to identify the relevant records and right. You do not have to use a particular form.
22.5 We may request proportionate evidence of identity or authority where reasonably necessary. We will not ask for more identity information than needed.
22.6 We normally respond without undue delay and within one month after receiving a valid request or any necessary identity information. The period may be extended where the law allows for a complex or numerous request, and we will explain the extension.
22.7 A request is normally free. A reasonable fee or refusal may apply only where the law permits, such as a manifestly unfounded or excessive request.
23. Data-protection complaints
23.1 A person who believes we have used their personal information unlawfully or handled a rights request poorly may complain by emailing jo*****@*********ft.com or through another reasonable contact route. A complaint does not need a particular form or legal wording. Where possible, it should identify the person, the issue and the outcome sought.
23.2 We aim to acknowledge a data-protection complaint within three working days and will always acknowledge it within 30 days. We aim to give a clear outcome within 14 working days where reasonably possible. If more time is needed, we will explain why and keep the person informed. Complaints will be handled fairly and without undue delay.
23.3 We will take appropriate steps to investigate, may ask for further information and will inform the complainant of the outcome. We will keep an internal record sufficient to demonstrate how the complaint was handled.
23.4 A person may also complain to the Information Commissioner’s Office at https://ico.org.uk/make-a-complaint/ or by calling 0303 123 1113. We would appreciate the opportunity to address a concern first, but contacting us before the ICO is not a condition of the right to complain.
24. Third-party websites, platforms and social media
24.1 The Website may link to external websites, payment pages, booking services, video platforms, social networks or embedded content. Those organisations may collect information as separate controllers under their own privacy notices and cookie controls.
24.2 A link, embed or social-media interaction does not make Onward Shift responsible for the third party’s privacy practices. People should review the relevant notice before providing information.
24.3 Messages sent through a social-media or messaging platform are also processed by the platform provider. Sensitive wellbeing information should not be sent through a public post or insecure channel.
25. Changes to this Policy
25.1 We may update this Policy to reflect changes in law, guidance, Services, Providers, systems, processors or how we use information. The latest version will be published on the Website with a revised date.
25.2 Where a change materially affects an ongoing Service or creates an unexpected new use of personal information, we will provide additional notice and obtain consent where consent is required.
25.3 We will not use an update to this Policy to retrospectively replace the lawful basis that applied when information was collected.
26. Related policies
26.1 Our Cookie Policy explains the Website technologies and consent controls: https://onwardshift.com/cookies-policy/.
26.2 Our Data Deletion Policy gives further information about how to request the deletion of personal information: https://onwardshift.com/data-deletion/.
26.3 Our Terms and Conditions explain the contractual arrangements for Website use, Services, Events and Products: https://onwardshift.com/terms-of-use/.
26.4 Our Code of Ethics sets privacy, confidentiality and record-handling standards for Providers: https://onwardshift.com/code-of-ethics/.
27. Contact
27.1 Privacy questions, rights requests, consent withdrawals, objections and complaints may be sent to jo*****@*********ft.com.
27.2 Please do not send detailed health or safeguarding information by post or through an insecure public channel unless it is necessary. Contact us first if you need an appropriate method for sensitive information.
We use cookies to make our website work properly, improve performance and personalise your experience. You can accept all cookies or manage your preferences.