Privacy & UK GDPR Policy

Social Value Consultancy Ltd (registered in England & Wales, Company No. 11325322) 
Policy owner: Data Protection Lead 
Approved by: Managing Director 
Version: 1.0 
Last updated: 16 September 2025 
Next review: 16 September 2026 
Contact: info@socialvalueconsultancy.co.uk 

1) Who we are and how to contact us 

Social Value Consultancy Ltd (“we”, “us”, “our”) is the controller for the personal data described in this policy. 
Questions or requests about your data rights: info@socialvalueconsultancy.co.uk (please include “FAO: Data Protection Lead” in the subject for privacy queries). 

2) Scope 

This notice explains how we process personal data about: website visitors, prospective and current clients, suppliers/partners, event attendees, and job applicants. 

3) What data we collect 

  • Identity & contact data: name, job title, employer, email, phone. 
  • Business relationship data: proposals, contracts, statements of work, billing details. 
  • Communications: emails, meeting notes, support tickets. 
  • Usage/technical (website/platforms): IP address, device/browser, pages viewed, time on page. 
  • Marketing preferences: opt-in/opt-out, topics of interest. 
  • Recruitment data: CV, cover letter, interview notes, referees. 
    We do not routinely collect special category data. If we must (e.g., accessibility needs for events), we’ll explain why and how it’s protected. 

4) Purposes and lawful bases 

  • Provide and manage services (proposals, delivery, support): Contract; Legitimate interests for account management. 
  • Billing, tax and compliance: Legal obligation. 
  • Business development & B2B marketing (relevant updates to business contacts): Legitimate interests; you can opt out at any time. 
  • Events & webinars (registration, joining details, follow-ups): Contract or Legitimate interests; where required, Consent. 
  • Recruitment: Legitimate interests; where appropriate, Consent. 
  • Website analytics & security: Legitimate interests (performance and security). 
    Where we rely on legitimate interests, we assess and balance those interests against your rights and expectations. 

5) Cookies & PECR 

We use cookies and similar technologies for functionality, analytics, and security. See our Cookies Policy (available on our website) for details and controls. We comply with the UK Privacy and Electronic Communications Regulations (PECR) for cookies and electronic marketing. 

6) Who we share data with (recipients) 

We share personal data only as needed with: 

  • Service providers (processors): secure hosting, email, CRM, analytics, event platforms, IT support. 
  • Professional advisers: accountants, auditors, legal counsel. 
  • Authorities: law enforcement/regulators where required by law. 
  • Transaction partners: if we restructure, merge, or sell parts of the business (we’ll notify you where appropriate). 
    We do not sell personal data. 

 

7) International transfers 

We primarily process data in the UK. Where data is transferred outside the UK (e.g., to cloud providers), we use approved safeguards such as the UK IDTA and/or Standard Contractual Clauses, and conduct transfer risk assessments to ensure equivalent protection. 

8) Retention periods 

We keep data only for as long as needed for the stated purposes. Our Data Retention Schedule (available on request) sets specific periods. Summary: 

  • Client records & contracts: up to 6 years after the end of the relationship (to meet tax/limitation obligations). 
  • General enquiries & CRM leads: 24 months from last meaningful contact. 
  • Support tickets & project comms: 3 years from closure. 
  • Recruitment (unsuccessful): 12 months from decision (unless you consent to longer). 
  • Marketing lists: until you opt out or after 24 months of inactivity. 
  • Website analytics & security logs: typically 12–26 months. 

9) Your rights 

You have rights to access, rectify, erase, restrict, object, and portability, and rights related to automated decision-making. 
To exercise rights, email info@socialvalueconsultancy.co.uk. We will verify your identity and respond within one month (extendable for complex requests). 

10) Automated decision-making 

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects. 

11) Security 

We apply technical and organisational measures appropriate to the risk, including access controls, encryption, and staff training. See our Data Security & IT Policy for more detail. 

 

12) Complaints 

If you’re unhappy with our handling of personal data, please contact us first at info@socialvalueconsultancy.co.uk. You can also complain to the Information Commissioner’s Office (ICO) at ico.org.uk. 

13) Changes to this notice 

We may update this notice; significant changes will be communicated where appropriate. Last updated: 16 September 2025.