top of page

PRIVACY POLICY

Last Updated August 31, 2026

Introduction

This Privacy Policy explains our approach to any personal information that we might collect or obtain from you or which we have obtained about you from a third party, the purposes for which we process your personal information, and the rights you have in respect of our processing of your personal information, such as requesting access to, or erasure of, certain information. This Privacy Policy tells you about how we collect, use, disclose, store and protect personal information when you visit our website, communicate with us, subscribe to our communications, submit information through our website, apply for employment, attend or register for our events, or otherwise interact with Ci.

We want you to make informed decisions when it comes to your personal information, so please take some time to read and understand this document. Please also note, this privacy policy should be read in conjunction with Ci’s website Terms of Use.

For individuals in the United Kingdom, we process personal data in accordance with applicable UK data protection law, including the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“PECR”), and the Data (Use and Access) Act 2025, as applicable.

About Us

This website is operated by Ci Design, Inc. References on this website to “Ci Design”, “we”, “us” or “our” may refer to Ci Design, Inc. or Ci Design Ltd, depending on the context. This Privacy Policy relates to your access to and use of this website only and does not govern any client relationship for architectural, design, consulting or other professional services. The data controller responsible for your personal information is processed via the website is Ci Design, Inc.

For questions regarding this Privacy Policy or our handling of personal information, please contact:

info@ci-designinc.com

 

1. Information We Collect

Personal data, or personal information, means any data/information about an individual that directly or indirectly identifies them. It does not include data/information where the identity has been removed (i.e., anonymous data). Depending on how you interact with Ci, we may collect the following categories of personal information:

  • Identity information, such as your first and last names.

  • Contact information, such as your email address, telephone number, business address and other contact details.

  • Professional information, such as your company / employer, job title, professional qualifications and business interests.

  • Communications information, including information contained in correspondence, inquiries or other communications with us, including but not limited to your interests, preferences, feedback and other information.

  • Marketing information, including your preferences for receiving communications, newsletters, event invitations and other information from Ci and third parties.

  • Recruitment information, including information provided through employment inquiries or applications, such as your CV/resume, portfolio, employment history, qualifications and contact information.

  • Technical and usage information, such as internet protocol (IP) address, browser type, operating system, device information, referring URLs, pages visited, interactions with our website and dates and times of visits, and similar information.

  • Event information, such as information provided when registering for or attending Ci events.

  • Any other personal information you voluntarily provide to us.

We also collect, use, and share aggregated data. Aggregated data could be derived from your personal data but is not considered personal information in law as this data will not, directly or indirectly, reveal your identity. For example, we may aggregate your technical and usage information to gain insights into the use of our website. If any aggregated data is combined with your personal information so that it can directly or indirectly identify you, we will treat that combined data as personal information in accordance with this privacy policy.

We do not collect special category data through our website – this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data. We also do not collect any information about criminal convictions and offences.

 

2. How We Collect Personal Information

We use different methods to collect data from and about you, including through:

  • Your interactions with us: You may give us your personal information directly when you contact us by phone, email, post or otherwise, or complete a website form, subscribe to communications, provide feedback, register for an event or apply for employment;

  • Automated technologies: We will automatically collect data about your equipment, browsing actions and patterns, and other technical data. This data is collected through cookies and similar technologies;

  • Third parties: We may receive personal information about you from our clients, consultants, vendors and other business partners;

  • From publicly available professional and business sources; and

  • From service providers and other third parties where permitted by applicable law.

3. Lawful Bases for Processing

Where the UK GDPR applies, we rely on one or more lawful bases to process personal data, including:

  • Consent: Where you have given us clear consent to process your personal data for a specific purpose, including certain electronic marketing or non-essential cookies where required.

  • Performance of a Contract with You: Where processing is necessary to enter into a contract with you, or to perform a contract have already entered into with you.

  • Legitimate Interests: Where processing is necessary for Ci's legitimate business interests, including operating and improving our business, responding to professional inquiries, developing business relationships, maintaining website security and promoting our professional services, provided those interests are not overridden by your rights and interests. We make sure we consider and balance any potential impact on you and your rights (both positive and negative) before we process your personal data for our legitimate interests.

  • Legal Obligation: Where processing is necessary to comply with a legal or regulatory requirement.

 

Where we rely on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.

 

4. How and Why We Use Personal Information 

We have set out below a description of all the ways we may use your personal data, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate.

 

Please note that we may process your personal data on more than one lawful basis depending on the specific purpose for which we are using your data. The purposes for which we may use personal information are as follows:

  • Respond to inquiries and communicate with you, and to maintain appropriate business and administrative records.

    • Lawful basis: Necessary to comply with a legal obligation; Necessary for our legitimate interests (to keep our records updated, to manage our relationship with you, and to communicate with you); Necessary to comply with a legal obligation.

    • Type of data: Identity, Contact, Professional, Communications, Marketing, Recruitment, Event.

  • Provide architectural, planning, design and related professional services.

    •  Lawful basis: Performance of a contract with you; Necessary for our legitimate interests (for running our business, provision of administration)

    • Type of data: Identity, Contact, Professional, Communications.

  • Establish and manage client, consultant, vendor and other business relationships.

    • Lawful basis: Performance of a contract with you; Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise); Necessary to comply with a legal obligation.

    • Type of data: Identity, Contact, Professional, Communications, Marketing, Technical and usage, Recruitment, Event.

  • Administer contracts and take steps requested before entering into a contract.

    • Lawful basis: Performance of a contract with you; Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise); Necessary to comply with a legal obligation.

    • Type of data: Identity, Contact, Professional, Communications, Marketing, Technical and usage, Recruitment, Event.

  • Manage event registrations and related communications.

    • Lawful basis: Necessary for our legitimate interests (for running our business, to communicate with you about events, and to manage our business); Performance of a contract with you.

    • Type of data: Identity, Contact, Professional, Communications, Marketing, Technical and usage, Event.

  • Process employment inquiries and applications.

    • Lawful basis: Necessary for our legitimate interests (to keep our records updated, to manage our relationship with you and to communicate with you about recruitment inquiries and applications); Performance of a contract with you.

    • Type of data: Identity, Contact, Professional, Communications, Technical and usage, Recruitment, Event.

  • Send newsletters, firm news, project updates, event invitations and other marketing communications where permitted by law.

    • Lawful basis: Consent, where you have provided your consent to receiving direct marketing communications; Necessary for our legitimate interests (to carry out direct marketing and to grow our business).

    • Type of data: Identity, Contact, Professional, Communications, Technical and usage, Event.

  • Operate, maintain, secure and improve our website and protect our systems, personnel, clients and business from security threats, fraud or unlawful activity.

    •  Lawful basis: Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, and to prevent fraud); Necessary to comply with a legal obligation.

    • Type of data: Identity, Contact, Professional, Technical and usage.

  • Understand how visitors interact with our website and communications.

    • Lawful basis: Necessary for our legitimate interests (for running our business, to manage our relationship with you, and to study how site visitors use the website).

    • Type of data: Identity, Contact, Professional, Communications, Marketing, Technical and usage.

  • Comply with legal, professional, regulatory and contractual requirements, and to establish, exercise or defend legal claims.

    • Lawful basis: Necessary to comply with a legal obligation; Necessary for our legitimate interests (for managing and administering our business).

    • Type of data: Identity, Contact, Professional, Communications, Technical and usage.

 

Please contact us if you need details about the specific lawful basis we are relying on to process your personal data where more than one ground has been set out above.

 

We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us.

 

If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.

 

Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.

 

5. Marketing Communications

We may use your contact information to provide information about Ci, our projects, services, research, events, publications and other business developments where permitted by applicable law.

 

In relation to sending you marketing communications by email, we will use your name and email address to send such communications where you have consented to receive them (for example, by subscribing to insights and project updates via our website), or where we have another lawful basis and right to do so.

 

You may unsubscribe from, or opt-out of, marketing communications at any time by using the unsubscribe link included in an email or by contacting us at info@ci-designinc.com.

 

Opting out of marketing communications will not prevent us from contacting you regarding an existing business relationship, contract or other non-marketing matter.

6. Cookies and Similar Technologies

Our website may use cookies and similar technologies (such as pixels, beacons and log files) to operate the website, remember preferences, understand website usage, measure performance and improve the user experience.

Please refer to our Cookie Policy and cookie consent settings for more information.

7. Sharing Personal Information

We may share your personal data with the parties set out below for the purposes set out in the table above and where appropriate and lawful to do so. Where we share your personal data, recipients will only process it on our behalf and at our direction.

Parties with whom we may share your information:

  • Ci Design subsidiaries, affiliates and offices;

  • website hosting, IT, cloud storage and cybersecurity providers;

  • analytics and communications providers;

  • marketing and event service providers;

  • professional advisers, including lawyers, accountants and insurers, and other professionals or consultancies providing banking, accounting and administrative services;

  • consultants, contractors and other parties involved in providing our professional services;

  • recruitment and employment service providers;

  • public authorities, regulators or law enforcement agencies where required by law; and

  • parties involved in a merger, acquisition, financing, restructuring, sale or transfer of all or part of our business, or parties in relation to a business we seek to acquire or merge with.

 

We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.

 

Ci does not sell personal information for monetary consideration.

8. International Data Transfers

Ci operates internationally, including in the United States and United Kingdom. Accordingly, personal data collected in the UK may be transferred to, accessed from or stored in countries outside the UK, including the United States.

Where UK personal data is transferred internationally, Ci will ensure that an appropriate mechanism is used to protect your data appropriately as required by law. Depending on the circumstances, such a mechanism may include:

  • transferring information to a country that has been deemed to provide an adequate level of protection for personal data;

  • use of specific contracts approved for use in the UK, which give personal data the same protection as it has in the UK, such as the UK International Data Transfer Agreement (IDTA), or the UK International Data Transfer Addendum alongside the European Commission's Standard Contractual Clauses;

  • another legally recognised safeguard; or

  • an applicable statutory exception.

 

Where required, Ci will assess whether the relevant transfer mechanism provides an appropriate level of protection and implement additional safeguards where necessary.

You may contact us for additional information about safeguards used for international transfers of your personal data.

9. Data Retention

We will only retain personal information only for as long as reasonably necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, contractual, professional and regulatory requirements.

Retention periods may vary depending on the amount, nature and sensitivity of the information, the purpose for which it is processed, the nature of our relationship with you, the potential risk of harm from unauthorised use or disclosure, and applicable legal requirements. By law, we may be required to keep basic information in relation to contact, identity, financial and transactional data for tax and other similar purposes.

In some cases, you can ask us to delete your personal data.

When personal information is no longer required, we will securely delete or anonymise it in accordance with our applicable policies and legal obligations.

10. Data Security

Ci maintains appropriate technical, administrative and organisational measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed.

These measures may include administrative, physical and technological safeguards appropriate to the nature of the information and risks involved. However, no internet transmission, electronic storage system or security measure can be guaranteed to be completely secure. In addition, we limit access to your personal data to those employees, agents, contractors and other third-parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

11. Your UK Data Protection Rights

If UK data protection law applies to your personal data, you may have rights including the right to:

  • access personal data we hold about you;

  • rectify inaccurate or incomplete personal data;

  • request erasure of personal data in certain circumstances;

  • restrict processing in certain circumstances;

  • object to processing, including certain processing based on legitimate interests and processing for direct marketing;

  • data portability in circumstances where that right applies;

  • withdraw consent where processing is based on consent;

  • make a compliant to us in relation to our processing of your personal data; and

  • exercise rights relating to certain forms of automated decision-making and profiling, where applicable.

These rights are subject to limitations and exemptions under applicable law. To exercise a data protection right, please contact us at info@ci-designinc.com. We may need to verify your identity before processing your request.

We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

12. Complaints

If you have a complaint in relation to our handling of your personal data, please contact us at info@ci-designinc.com with the subject line ‘Data Complaint’. We will acknowledge such a complaint within 30 days of receipt and will take steps to investigate it fairly and free of charge. We will inform you of the complaint outcome without undue delay.

If our response does not resolve your concerns regarding our use of your personal information, you also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) where your concern relates to Ci Design Ltd. You can find details about how to do this on the ICO website at https://ico.org.uk/make-a-complaint/  or by calling their office on 0303 123 1113.  Please note you can go direct to the ICO without making a complaint to us first, but they may direct you back to us as an initial action.

13. Children's Privacy

Our website and professional services are not directed toward children, and we do not knowingly collect personal information from children.

If we become aware that personal information relating to a child has been collected inappropriately, we will take reasonable steps to delete it.

14. Third-Party Websites

Our website may contain links to websites, plugins and applications operated by third parties. Clicking on those links or enabling those connections may allow third parties to collect or share personal data about you. Ci does not control and is not responsible for the privacy, security, content or practices of third-party websites.

We encourage you to review the privacy policies applicable to any third-party websites you visit.

15. Changes to this Privacy Policy

To ensure that you are always aware of how we use your personal data, we may update this Privacy Policy from time to time to reflect changes in our practices, technologies, services or legal obligations. Please review this Privacy Policy periodically to be informed of how we use your personal information.

When changes are made, we will update the "Last Updated" date at the top of this Privacy Policy. Where required by law, we will provide additional notice.

 

16. Contact Us

For questions, requests or concerns regarding this Privacy Policy or Ci's processing of personal information, please contact:

 

US / Worldwide 

Ci Design, Inc.
1000 Lancaster Street, Suite 430

Baltimore, Maryland 21202

 

UK

Ci Design, Ltd.

1 Fore Street Avenue

Suite 02157

London, EC2Y 9DT, UK


Email: info@ci-designinc.com
 

bottom of page