Legal

Privacy Notice

Last updated: [Date]

1. Who we are

[Your Consultancy Name] is the data controller. ICO registration: [ZAxxxxxx].

Contact: [Your Name] · info@[yourdomain].co.uk · [Phone] · [Address]

2. What personal data we collect

Enquiries: Name, email, phone, organisation, sector, size, and message content.

Clients: Contact details, organisational and compliance information provided during engagement.

Newsletter subscribers: Name and email.

Website visitors: Technical data via cookies — see our Cookie Policy.

Prospects: Name, job title, organisation, and business contact details from publicly available sources (Companies House, ICO Register, Charity Commission).

3. How we use your data and the lawful basis

Enquiries: Legitimate interests (Art. 6(1)(f)). Services: Contract performance (Art. 6(1)(b)). Marketing: Consent (Art. 6(1)(a)) for newsletters; legitimate interests for B2B marketing to corporate subscribers per PECR. Analytics: Consent via cookie mechanism.

4. Who we share data with

We do not sell personal data. We share with: hosting provider, email provider, cloud storage (Microsoft 365 / Google Workspace), and associate consultants under appropriate agreements.

5. International transfers

Where providers process data outside the UK, appropriate safeguards are in place (UK IDTA, UK Addendum to EU SCCs, or adequacy regulations).

6. Retention

Enquiries: 12 months. Clients: Duration + 7 years (Limitation Act 1980). Subscribers: Until unsubscribe. Prospects: 12 months from last contact.

7. Your rights

You have the right to access, rectify, erase, restrict, port, and object. Where processing is based on consent, you may withdraw at any time. Contact info@[yourdomain].co.uk to exercise any right. You may also complain to the ICO (ico.org.uk).

8. Complaints

See our complaints procedure, established under s.164A DPA 2018 (as amended by the DUAA 2025).

9. Changes

We may update this notice. The latest version with the date of update will always be on this page.