Privacy Policy
1. Introduction and company information
This Privacy Policy explains how Northbridge Regional Services Ltd collects, uses, discloses, stores, and protects personal data when you interact with us, use our services, contact us, or otherwise provide personal information to us.
Northbridge Regional Services Ltd is the data controller for the personal data described in this Privacy Policy, unless we notify you otherwise in a specific case.
Company details:
Northbridge Regional Services Ltd
Northbridge Regional Services, 24 St John Street, London, EC1M 4AY, United Kingdom
Email: [email protected]
Phone: +44 20 7946 8372
This Privacy Policy applies to our regional business activities and to personal data collected through our communications, website, service delivery, administration, and related operations.
2. Data collection and processing
We may collect and process the following categories of personal data, depending on your relationship with us and the nature of your interaction:
- Identity data: name, title, date of birth, and similar identifiers.
- Contact data: postal address, email address, telephone number, and other contact details.
- Business and professional data: employer, job title, professional role, business correspondence, and service-related information.
- Contract and transaction data: details relating to services requested, provided, or invoiced.
- Communication data: enquiries, complaints, feedback, correspondence, and call records where applicable.
- Technical data: IP address, browser type, device information, log files, and usage data collected through our digital services.
- Payment and financial data: payment-related information, billing details, and transaction records where necessary.
- Compliance data: identification data and records required for legal, regulatory, accounting, or audit purposes.
We collect personal data directly from you, from third parties acting on your behalf, from publicly available sources where appropriate, and automatically through our systems and digital channels.
We do not intentionally collect special category data unless it is required for a lawful purpose, and only where permitted by applicable law.
3. Purpose of data processing
We process personal data for the following purposes:
- to provide and manage our services;
- to communicate with clients, prospective clients, suppliers, and other contacts;
- to respond to enquiries, requests, and complaints;
- to enter into and perform contracts;
- to manage billing, payments, and financial administration;
- to maintain business records and internal operations;
- to comply with legal, regulatory, tax, accounting, and reporting obligations;
- to protect our rights, property, personnel, and users;
- to improve our services, processes, website functionality, and customer experience;
- to conduct analytics, business planning, and service development;
- to send service-related notices and, where permitted, relevant communications;
- to prevent fraud, misuse, and security incidents.
4. Legal basis for processing
We process personal data only where we have a lawful basis to do so. Depending on the context, our legal bases may include:
- Performance of a contract: where processing is necessary to provide services, fulfil an agreement, or take steps at your request before entering into a contract.
- Legal obligation: where processing is required to comply with applicable laws, regulations, court orders, or regulatory obligations.
- Legitimate interests: where processing is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. Such interests may include service provision, business administration, security, fraud prevention, and internal record keeping.
- Consent: where you have given clear consent for a specific purpose, such as certain marketing or optional communications, and where consent is the appropriate lawful basis.
- Vital interests: in rare circumstances where processing is necessary to protect someone’s life.
- Public interest or official authority: where applicable and permitted by law.
Where we rely on legitimate interests, we assess and balance those interests against your rights. You may request further information about this balancing test where relevant.
5. Data sharing and third parties
We may share personal data where necessary with the following categories of recipients:
- Service providers: IT hosting, software, communications, analytics, payment processing, document management, customer support, and other operational providers.
- Professional advisers: lawyers, accountants, auditors, insurers, consultants, and similar advisers.
- Regulators and public authorities: law enforcement, tax authorities, courts, and other governmental or supervisory bodies where required or permitted by law.
- Business partners and contractors: parties involved in delivering or supporting our services.
- Affiliates or successor entities: where necessary for internal administration, restructuring, or a transaction involving our business.
We require third parties to handle personal data securely and to use it only for the purposes authorised by us and permitted by law. Where required, we put appropriate contractual and organisational safeguards in place.
6. Data transfer to third countries
Where personal data is transferred outside the United Kingdom, we take steps to ensure that appropriate safeguards are in place. These may include adequacy regulations, standard contractual clauses, international transfer assessments, or other lawful transfer mechanisms permitted under applicable privacy laws.
Where required, we also implement supplementary technical, contractual, and organisational measures to protect personal data during international transfers.
7. Storage duration
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying legal, accounting, tax, regulatory, contractual, and reporting requirements.
Retention periods may vary depending on the type of data and the reason for processing. In general, we consider the following factors when determining retention periods:
- the nature and sensitivity of the personal data;
- the potential risk of harm from unauthorised use or disclosure;
- the purposes for which we process the data;
- the availability of alternative means to achieve those purposes;
- legal, regulatory, and contractual obligations;
- the need to resolve disputes or enforce agreements.
When personal data is no longer required, we will delete, anonymise, or securely archive it in accordance with applicable law and our retention practices.
8. User rights
Subject to applicable law and certain limitations, you may have the following rights in relation to your personal data:
- Right of access: to request confirmation of whether we process your personal data and to obtain a copy of that data.
- Right to rectification: to request correction of inaccurate or incomplete personal data.
- Right to erasure: to request deletion of personal data in certain circumstances.
- Right to restriction: to request limitation of processing in certain circumstances.
- Right to data portability: to request your personal data in a structured, commonly used, machine-readable format and, where technically feasible, transfer to another controller.
- Right to object: to object to processing based on legitimate interests and to object to direct marketing at any time.
To exercise any of these rights, please contact us using the details provided in the Contact Information section. We may need to verify your identity before responding to your request. We will respond within the timeframe required by applicable law.
9. Withdrawal of consent
Where we rely on your consent to process personal data, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of processing carried out before the withdrawal.
If you withdraw consent, we may no longer be able to provide certain services or communications to you where consent is necessary for that purpose. We will inform you if this is the case.
10. Right to complain
You have the right to lodge a complaint with the relevant data protection authority if you believe that our processing of your personal data does not comply with applicable privacy laws.
In the United Kingdom, the supervisory authority is the Information Commissioner’s Office (ICO). We encourage you to contact us first so that we may try to address your concern directly.
11. Data security
We implement appropriate technical and organisational measures to protect personal data against accidental loss, unauthorised access, alteration, disclosure, or destruction. These measures may include:
- access controls and authentication measures;
- secure storage and transmission protocols;
- staff confidentiality and privacy training;
- monitoring and logging of relevant systems;
- backup, recovery, and business continuity procedures;
- vendor due diligence and contractual safeguards;
- periodic reviews of security practices.
Although we take reasonable steps to protect your information, no method of transmission over the internet or method of electronic storage is completely secure. We cannot guarantee absolute security.
12. Contact information
If you have any questions about this Privacy Policy or our handling of personal data, or if you wish to exercise your rights, please contact:
Northbridge Regional Services Ltd
Northbridge Regional Services, 24 St John Street, London, EC1M 4AY, United Kingdom
Email: [email protected]
Phone: +44 20 7946 8372
13. Changes to privacy policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, legal obligations, or regulatory requirements. Any updated version will be made available on our website or through other appropriate communication channels.
The date of the latest version will be indicated where appropriate. We encourage you to review this Privacy Policy periodically to stay informed about how Northbridge Regional Services Ltd protects your personal data.