Privacy Policy

1. Who We Are

Regis Palmer Group Ltd (“RPG”) is an operational consultancy based in the United Kingdom.

We are committed to protecting the privacy and security of personal data.

For any questions about this policy, contact:

Email: ben@regispalmer.co.uk

 

2. What This Policy Covers

This Privacy Policy explains:

  • what personal data we collect

  • how we use it

  • how we store and protect it

  • your rights under data protection law

  • how to contact us

This policy applies to:

  • clients

  • prospective clients

  • website visitors

  • individuals who interact with RPG in any capacity

3. What Personal Data We Collect

We may collect the following categories of personal data:

  • Identity data: name, job title, organisation

  • Contact data: email address, phone number

  • Operational data: information shared during consultancy engagements

  • Website data: IP address, browser type, usage analytics

  • Communication data: emails, meeting notes, enquiries

We do not intentionally collect:

  • special category data

  • criminal offence data

  • financial account information

If such data is provided, it will be handled in accordance with our Data Processing Agreement.

4. How We Use Personal Data

We use personal data for:

  • delivering consultancy services

  • managing client relationships

  • responding to enquiries

  • improving our services and website

  • meeting legal or regulatory obligations

We do not sell or share personal data with third parties for marketing.

5. Legal Basis for Processing

We process personal data under the following lawful bases:

  • Contract: to deliver services under an Engagement Letter or Agreement

  • Legitimate interests: to operate and improve our business

  • Consent: where you have explicitly provided it (e.g., newsletter sign‑ups)

  • Legal obligation: where required by law or regulation

6. How We Store and Protect Data

We use appropriate technical and organisational measures, including:

  • secure cloud storage

  • encryption in transit and at rest

  • access controls

  • device security

  • data minimisation

  • regular review of security practices

Data is stored in the UK or in jurisdictions with adequate protection.

7. How Long We Keep Data

We retain personal data only for as long as necessary to:

  • deliver services

  • meet legal obligations

  • maintain business records

Retention periods are defined in our Data Retention & Disposal Policy.

8. Sharing Personal Data

We may share data with:

  • trusted sub‑processors (e.g., cloud storage providers)

  • professional advisers (e.g., legal or accounting)

  • regulators or authorities where legally required

All sub‑processors are bound by equivalent data protection obligations.

 

9. International Transfers

If personal data is transferred outside the UK, we ensure:

  • an adequacy decision exists, or

  • appropriate safeguards (e.g., SCCs) are in place

This aligns with our Data Processing Agreement.

 

10. Your Rights

Under UK GDPR, individuals have the right to:

  • access their data

  • correct inaccurate data

  • erase data (“right to be forgotten”)

  • restrict processing

  • object to processing

  • data portability

  • withdraw consent at any time

To exercise these rights, contact us using the details above.

 

11. Cookies

Our website may use cookies to:

  • improve user experience

  • analyse website traffic

  • remember preferences

Details are provided in our Cookie Policy.

 

12. Changes to This Policy

We may update this Privacy Policy from time to time.

The latest version will always be available on our website.