SBS Portal Access Hub
Privacy & Cookie Notice
This notice explains how Shard Business Services uses personal information in the SBS Portal and how the portal uses cookies and browser storage.
Version 1.0 · effective 24 July 2026
1. Who we are
Shard Business Services operates the SBS Portal Access Hub. For privacy questions, requests or concerns, contact [email protected] or your usual SBS contact.
Depending on the service, SBS may act as a controller for portal accounts, security and service administration, or as a processor when handling documents and records on a client organisation’s instructions. Your organisation remains responsible for deciding what client evidence it uploads.
2. Information we use
- Account and contact details, organisation, role and access permissions.
- Authentication information, MFA configuration, trusted-device tokens and password-reset records.
- Security and audit records including sign-in events, device/browser information and IP address.
- Service records, tasks, comments, uploaded evidence and other information entered into the portal.
- Support communications and records needed to operate, secure and improve the service.
Do not upload information that is unnecessary for the relevant service. In particular, take care with children’s information, health information, safeguarding material, criminal-offence data and other sensitive records.
3. Why we use it
We use information to provide contracted services, administer accounts, control access, protect the portal, investigate errors and security events, communicate with users, meet legal obligations and establish or defend legal claims.
Our legal bases may include performance of a contract, legitimate interests in operating and securing the service, compliance with legal obligations, and—where relevant—processing carried out on a client controller’s documented instructions. We do not use portal data for advertising.
4. Sharing, processors and transfers
Information is available only to authorised SBS personnel, the user’s organisation and approved service providers where needed. Providers may include the IIS hosting provider, Microsoft 365/Entra/Graph, Cloudflare and encrypted backup storage. Access is role-based and client users are restricted to their permitted organisation scope.
Where a provider processes information outside the UK, SBS will use an appropriate UK transfer mechanism and safeguards. We do not sell portal information.
5. Retention and security
Records are retained only for as long as required for the service, legal, contractual, security and backup purposes. Exact periods depend on the record type and client agreement. Backups may retain a deleted record until the relevant protected backup expires.
The portal uses HTTPS, MFA, access controls, protected document delivery, audit logging, encrypted secrets and tested backups. No online service can eliminate every risk, so users must protect their credentials and report suspicious activity promptly.
6. Your rights
Depending on the circumstances, you may have rights to access, correct, erase or restrict personal information, object to processing, or receive portable information. Where SBS processes client evidence for your organisation, we may refer the request to that organisation as controller.
You may complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint. Please contact us first where possible so we can try to resolve the concern.
7. Cookies and browser storage
The portal does not currently use advertising or analytics cookies. It uses the following essential and preference technologies:
| Name/type | Purpose | Duration | Classification |
|---|---|---|---|
| SBS_SESSION | Maintains the secure signed-in session and role-based access. | Browser session; server session ends after 30 minutes of inactivity. | Strictly necessary |
| SBS_MFA_TRUST | Optional trusted-device token selected by the user to reduce repeated MFA prompts. | 30 days | Authentication preference |
| Local browser storage | Remembers theme, navigation layout, help progress, selected tabs and starred resources. | Until cleared in the browser or using the control below. | Appearance/functionality preference |
| Session browser storage | Temporarily remembers open dashboard panels and navigation state. | Current browser tab/session. | Functionality |
Essential cookies cannot be switched off within the portal because sign-in and access control would not work. The trusted-device cookie is created only when you select that option. Preference storage can be cleared at any time:
8. Changes to this notice
We will update this notice when the portal, its providers or applicable requirements change. Material changes will be highlighted in the portal and the version date above will be updated.

