Privacy Policy

1. Introduction and company information

This Privacy Policy explains how Northbridge Regional Services Ltd collects, uses, discloses, stores, and protects personal data when you interact with us, use our services, contact us, or otherwise provide personal information to us.

Northbridge Regional Services Ltd is the data controller for the personal data described in this Privacy Policy, unless we notify you otherwise in a specific case.

Company details:
Northbridge Regional Services Ltd
Northbridge Regional Services, 24 St John Street, London, EC1M 4AY, United Kingdom
Email: [email protected]
Phone: +44 20 7946 8372

This Privacy Policy applies to our regional business activities and to personal data collected through our communications, website, service delivery, administration, and related operations.

2. Data collection and processing

We may collect and process the following categories of personal data, depending on your relationship with us and the nature of your interaction:

We collect personal data directly from you, from third parties acting on your behalf, from publicly available sources where appropriate, and automatically through our systems and digital channels.

We do not intentionally collect special category data unless it is required for a lawful purpose, and only where permitted by applicable law.

3. Purpose of data processing

We process personal data for the following purposes:

4. Legal basis for processing

We process personal data only where we have a lawful basis to do so. Depending on the context, our legal bases may include:

Where we rely on legitimate interests, we assess and balance those interests against your rights. You may request further information about this balancing test where relevant.

5. Data sharing and third parties

We may share personal data where necessary with the following categories of recipients:

We require third parties to handle personal data securely and to use it only for the purposes authorised by us and permitted by law. Where required, we put appropriate contractual and organisational safeguards in place.

6. Data transfer to third countries

Where personal data is transferred outside the United Kingdom, we take steps to ensure that appropriate safeguards are in place. These may include adequacy regulations, standard contractual clauses, international transfer assessments, or other lawful transfer mechanisms permitted under applicable privacy laws.

Where required, we also implement supplementary technical, contractual, and organisational measures to protect personal data during international transfers.

7. Storage duration

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying legal, accounting, tax, regulatory, contractual, and reporting requirements.

Retention periods may vary depending on the type of data and the reason for processing. In general, we consider the following factors when determining retention periods:

When personal data is no longer required, we will delete, anonymise, or securely archive it in accordance with applicable law and our retention practices.

8. User rights

Subject to applicable law and certain limitations, you may have the following rights in relation to your personal data:

To exercise any of these rights, please contact us using the details provided in the Contact Information section. We may need to verify your identity before responding to your request. We will respond within the timeframe required by applicable law.

9. Withdrawal of consent

Where we rely on your consent to process personal data, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of processing carried out before the withdrawal.

If you withdraw consent, we may no longer be able to provide certain services or communications to you where consent is necessary for that purpose. We will inform you if this is the case.

10. Right to complain

You have the right to lodge a complaint with the relevant data protection authority if you believe that our processing of your personal data does not comply with applicable privacy laws.

In the United Kingdom, the supervisory authority is the Information Commissioner’s Office (ICO). We encourage you to contact us first so that we may try to address your concern directly.

11. Data security

We implement appropriate technical and organisational measures to protect personal data against accidental loss, unauthorised access, alteration, disclosure, or destruction. These measures may include:

Although we take reasonable steps to protect your information, no method of transmission over the internet or method of electronic storage is completely secure. We cannot guarantee absolute security.

12. Contact information

If you have any questions about this Privacy Policy or our handling of personal data, or if you wish to exercise your rights, please contact:

Northbridge Regional Services Ltd
Northbridge Regional Services, 24 St John Street, London, EC1M 4AY, United Kingdom
Email: [email protected]
Phone: +44 20 7946 8372

13. Changes to privacy policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, legal obligations, or regulatory requirements. Any updated version will be made available on our website or through other appropriate communication channels.

The date of the latest version will be indicated where appropriate. We encourage you to review this Privacy Policy periodically to stay informed about how Northbridge Regional Services Ltd protects your personal data.

7/21/2026 Home