• Names and contact details
  • Addresses
  • Occupation
  • Date of birth
  • Payment details (including card or bank information for transfers and direct debits)
  • Transaction data (including details about payments to and from you and details of products and services you have purchased)
  • Usage data (including information about how you interact with and use our website, products and services)
  • Employment details (including salary, sick pay and length of service)
  • Credit history and credit reference information
  • Information relating to compliments or complaints
  • Video and Audio recordings (e.g. Zoom Meetings)
  • Records of meetings and decisions
  • Account access information
  • Website user information
  • Addresses
  • Purchase or service history
  • Information used for security purposes
  • Marketing preferences
  • Technical data, including information about browser and operating systems
  • Client accounts and records
  • Call recordings
  • Financial information e.g. for fraud prevention or detection
  • Location data
  • Safeguarding information
  • Names and contact information
  • Emergency contact details
  • Names and contact details
  • Payment details
  • Account information
  • Call recordings
  • Witness statements and contact details
  • Relevant information from previous investigations
  • Customer or client accounts and records
  • Financial transaction information
  • Correspondence
  • Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
  • Legal obligation – we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object and the right to data portability.
  • Legitimate interests – we’re collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are:
    • Business Address – To send invoices, milestone cards and to ensure contracts are compliant.
  • Consent – we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.
  • Legal obligation – we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object and the right to data portability.
  • Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
  • Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
  • Legal obligation – we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object and the right to data portability.
  • Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
  • Legal obligation – we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object and the right to data portability.
  • Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
  • Legal obligation – we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object and the right to data portability.
  • Directly from you
  • Publicly available sources
  • Suppliers and service providers
  • Financial data (e.g. billing details, payments): 6 years from the end of the financial year they relate to.
  • Marketing data (e.g. newsletter opt-ins): Until you withdraw consent or 2 years after your last interaction with us.
  • Associate/subcontractor data (e.g. agreements, performance records): 6 years after the end of the working relationship.
  • Website visitor data (e.g. cookies, analytics): Up to 26 months, depending on the type of cookie.
  • Other financial or fraud investigation authorities
  • Regulatory authorities
  • Organisations we’re legally obliged to share personal information with
  • Suppliers and service providers

Organisation name: Bitwarden
Category of recipient: Password and Secure Document Management Software
Country the personal information is sent to: United States
How the transfer complies with UK data protection law: Addendum to the EU Standard Contractual Clauses (SCCs)

Organisation name: Google Workspace
Category of recipient: Cloud Service Provider
Country the personal information is sent to: United States
How the transfer complies with UK data protection law: Addendum to the EU Standard Contractual Clauses (SCCs)

Organisation name: Brevo
Category of recipient: Email Marketing & CRM Platform
Country the personal information is sent to: European Union (hosting servers in France, Germany and Belgium)
How the transfer complies with UK data protection law: Addendum to the EU Standard Contractual Clauses (SCCs)

Organisation name: Odoo
Category of recipient: ERP / Cloud Business Applications Platform
Country the personal information is sent to: Varied by hosting region. For example:

  • Europe region: France & Belgium (production) and backups in France, Netherlands, Sweden.
  • Americas region: USA & Canada (production), Europe (France, Netherlands) backups.

How the transfer complies with UK data protection law: Addendum to the EU Standard Contractual Clauses (SCCs)