Legal
Privacypolicy
What we collect, why we collect it, how long we keep it and what you can ask us to do about it. Written to be read rather than to be defensible.
- Applies to
- stakeconsultingltd.com
- Company no.
- 14224498
- Jurisdiction
- England & Wales
- Sections
- 23
01
About this policy
This policy explains what personal data Stake Consulting Ltd collects, why we collect it, what we do with it and what rights you have in relation to it. It applies to visitors to stakeconsultingltd.com, to people who contact us, and to individuals at organisations that buy or consider buying our services.
We have written it in plain English rather than in the shortest legally sufficient form. Where a term has a specific meaning under the UK General Data Protection Regulation and the Data Protection Act 2018, we use it in that sense.
This policy does not form part of any contract for services. Where a client agreement contains data protection terms, those terms govern the personal data we process on that client's behalf, and this policy explains our own processing as a controller.
02
Who we are and how to contact us
Stake Consulting Ltd is a company registered in England and Wales under company number 14224498, with its registered office at 25 Lavender Court, Netherton, Huddersfield HD4 7LW, England, United Kingdom.
For anything in this policy, including a request to exercise your rights, write to support@stakeconsultingltd.com with "Data protection" in the subject line, or to the registered office address above marked for the attention of the data protection contact.
We are the controller for the personal data described in this policy unless we state otherwise. We have not appointed a statutory data protection officer, because we are not required to; responsibility for data protection sits with the company's directors.
03
Who this policy covers
This policy applies to the following groups of people. If you fall into more than one, more than one part may be relevant to you.
- Website visitors
- Anyone who browses stakeconsultingltd.com, whether or not they get in touch.
- Enquirers
- People who complete the contact form, email us or otherwise ask about our services.
- Client contacts
- Individuals at organisations that have engaged us, including those we work with day to day.
- Supplier and partner contacts
- Individuals at organisations that supply services to us or work alongside us on a client engagement.
04
The information we collect
We collect a deliberately small amount of personal data. In practice it falls into the following categories.
- Identity and contact data
- Your name, the organisation you work for, your job role where you tell us, your email address and any telephone number you choose to give us.
- Enquiry content
- Whatever you write in the contact form or in an email, including your website address, the situation you select, what you tell us you already have in place, and anything else you choose to describe about your business.
- Engagement data
- Correspondence, meeting notes, proposals, statements of work, reports and other records created while we are working with you or scoping work.
- Financial and transaction data
- Billing contact details, purchase order references, invoices and payment records. We do not store card details; payments are made by bank transfer.
- Technical data
- IP address, browser type and version, device type, operating system, referring page and the pages you view, collected by our hosting provider's standard logs and, if you consent, by analytics.
05
Special category data
We do not seek out special category data, meaning information about health, ethnicity, religion, political opinions, trade union membership, sex life, sexual orientation, genetics or biometrics. We also do not seek information about criminal offences or convictions.
If you send us such information unprompted, we will delete it unless there is a clear reason and lawful basis to keep it, and we will tell you if we do.
06
How we collect it
- Directly from you, when you complete our contact form, email us, speak to us or send us documents.
- Automatically, through our hosting provider's server logs when you load a page, and through analytics if you have agreed to analytics cookies.
- From your organisation, where a colleague introduces you or adds you to a project.
- From public sources, such as your company's website, Companies House or a professional network profile, where we are researching an organisation that has contacted us.
07
Why we use it, and our lawful basis
We must have a lawful basis for every use of personal data. The table below sets out what we do and why we are allowed to do it.
- Answering your enquiry
- To read what you sent, research the question and reply. Lawful basis: our legitimate interest in responding to people who contact us, and steps taken at your request before entering a contract.
- Scoping and proposing work
- To prepare an audit, proposal or statement of work. Lawful basis: steps taken at your request before entering a contract, and legitimate interests in operating our business.
- Delivering our services
- To run the engagement, produce reports and communicate with your team. Lawful basis: performance of a contract with your organisation, and legitimate interests where the contract is with your employer rather than you personally.
- Invoicing and accounts
- To issue invoices, collect payment and keep accounting records. Lawful basis: performance of a contract, and compliance with our legal obligations under tax and company law.
- Improving the website
- To understand which pages are useful and where the site is failing people. Lawful basis: your consent, given through the cookie notice.
- Occasional relevant updates
- To send an existing or former client something we think is genuinely relevant to their account. Lawful basis: legitimate interests, with an opt-out in every message.
- Protecting the business
- To keep records for insurance, to deal with a dispute, or to comply with a regulator. Lawful basis: legitimate interests and legal obligation.
08
Data we handle for our clients
When we work inside a client's advertising accounts, analytics property or customer data platform, we may access personal data for which that client is the controller. In that situation we act as a processor and only on the client's documented instructions.
Those arrangements are covered by the data processing terms in the client agreement rather than by this policy. We do not use client data for our own purposes, we do not copy it out of client systems without a specific need, and we delete or return working copies at the end of an engagement.
If you are an individual whose data sits in one of our client's systems and you want to exercise a right, please contact that organisation. We will support them in responding to you.
10
Marketing and how to opt out
We do not buy contact lists, and we do not send unsolicited bulk email. Any marketing message we send goes to someone who has asked us for information or who is an existing or former client.
Every message includes a way to stop receiving them, and you can also ask us directly at any time. Opting out of marketing does not stop administrative messages about work in progress.
12
Service providers we rely on
We keep our supplier list short on purpose. The following categories of provider may process personal data on our behalf, each under a written contract that restricts what they can do with it.
- Website hosting and delivery
- Our hosting and content delivery providers process server logs, including IP addresses, in order to serve pages and protect the site from abuse.
- Email and productivity
- Our business email, calendar and document storage provider processes correspondence and files created during an engagement.
- Analytics
- If you consent to analytics, an analytics provider processes technical and usage data about your visit on our behalf.
- Accounting and payments
- Our accounting software and bank process invoicing and payment records.
13
Transfers outside the United Kingdom
Some of our providers are based outside the UK or store data outside it, most commonly in the European Economic Area or the United States.
Where personal data leaves the UK we rely on an approved safeguard: adequacy regulations made by the UK government, or the International Data Transfer Agreement or Addendum to the European Commission's standard contractual clauses, together with an assessment of the risks in the destination country.
You can ask us which safeguard applies to a particular transfer and we will tell you.
14
How long we keep information
We keep personal data only for as long as there is a reason to. In practice that means the following periods, unless a legal claim or obligation requires longer.
- Enquiries that do not proceed
- Kept for up to 24 months from the last contact, then deleted, so that we recognise you if you return.
- Client records and correspondence
- Kept for the duration of the engagement and for six years afterwards, which matches the limitation period for contractual claims in England and Wales.
- Financial and accounting records
- Kept for at least six years after the end of the accounting period, as required by UK tax and company law.
- Website analytics
- Retained for no longer than 14 months in an identifiable form, where analytics is in use.
- Marketing opt-outs
- Kept indefinitely, because we need a record of your objection in order to honour it.
15
How we keep it secure
- Access to systems is protected by strong, unique credentials and multi-factor authentication.
- Devices used for client work are encrypted at rest and kept up to date.
- Access to client advertising and analytics accounts is granted through named user permissions, never shared logins, and is requested at the lowest level that allows the work to be done.
- Personal data is shared internally only where a person needs it for a specific task.
- Suppliers are assessed before we use them and are engaged under written data processing terms.
16
Personal data breaches
If a breach occurs that is likely to result in a risk to people's rights and freedoms, we will report it to the Information Commissioner's Office without undue delay and within 72 hours of becoming aware of it where feasible.
Where the risk is high, we will also tell the individuals affected directly and explain what has happened, what we are doing about it and what they may wish to do.
Where we are acting as a processor for a client, we will notify that client without undue delay so that they can meet their own obligations.
17
Your rights
Under UK data protection law you have the following rights. Some apply only in certain circumstances, and we will explain if one of them does not apply to your situation.
- Access
- To be told whether we hold personal data about you and to receive a copy of it, along with information about how we use it.
- Rectification
- To have inaccurate data corrected and incomplete data completed.
- Erasure
- To have data deleted where we no longer have a good reason to keep it. This right is not absolute and does not override our legal record-keeping duties.
- Restriction
- To ask us to pause our use of your data, for example while we investigate a challenge to its accuracy.
- Objection
- To object to processing based on legitimate interests, and to object at any time to direct marketing, which we will always honour.
- Portability
- To receive data you provided to us in a structured, commonly used, machine-readable format, where processing is based on consent or contract and carried out by automated means.
- Withdrawing consent
- To withdraw consent at any time where consent is the basis we rely on. Withdrawal does not affect anything done before you withdrew it.
18
Making a request
Write to support@stakeconsultingltd.com and tell us which right you want to exercise. There is no fee. We may ask for enough information to be confident of your identity, which protects you as much as us.
We respond within one month. If a request is complex or you have made several, we may extend that by up to two further months and will tell you within the first month if we need to.
19
Automated decision-making
We do not make decisions about you by automated means that produce legal effects or similarly significant effects.
The advertising platforms we operate on our clients' behalf use automated systems to decide which advertisements to show to which people. Those decisions are made by the platforms under their own terms and privacy policies, and they do not produce legal or similarly significant effects on the people who see the advertisements.
20
Children
Our services are sold to businesses and this website is not aimed at children. We do not knowingly collect personal data from anyone under 18.
If you believe a child has given us personal data, contact us and we will delete it.
21
Other websites
This site links to other organisations' websites, including platform documentation and the Companies House register. We are not responsible for their content or their privacy practices.
Following an external link means their policy governs what happens next, so it is worth reading it.
22
Complaints
If you are unhappy with how we have handled your personal data, please tell us first so that we have a chance to put it right.
You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority for data protection, at ico.org.uk, by telephone on 0303 123 1113, or by writing to Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
23
Changes to this policy
We review this policy whenever our processing changes, and periodically in any case. The version published here is always the one in force.
If we make a change that materially affects how we use your personal data, we will take reasonable steps to tell the people affected directly rather than relying on you re-reading this page.