Version 1.0
Effective date: 28 September 2026
1. Who we are
VYSEBROWN LTD (“we”, “us” or “our”) respects your privacy and takes the protection of your personal data seriously. This policy explains how we collect and use your personal data, and the rights you have. We are the controller of personal data we hold for our own business administration, website, marketing, client and associate relationship purposes. For personal data handled in client consultancy, advisory or technology delivery projects, we may act as controller or processor depending on the relevant client engagement and project instructions.
We provide consultancy, advisory and technology delivery services through our founders and a network of Founding Associates and associates. We are a private company limited by shares registered in England and Wales under company number 17325096, with our registered office at 71-75 Shelton Street, Covent Garden, London, United Kingdom WC2H 9JQ.
We are registered with the Information Commissioner’s Office (“ICO”) as a data controller, reference ZC201766. You can contact us using the details in section 16.
2. What this policy covers
This policy applies to clients, prospective clients, associates, prospective associates, suppliers, business contacts, visitors to our website, and individuals whose personal data may be handled in our consultancy, advisory or technology delivery projects. Our website may link to other websites. We are not responsible for, and accept no liability in connection with, how those websites handle your data, so please read their own privacy policies.
3. The personal data we collect
Depending on how you deal with us, we may collect:
identity and business contact details, such as your name, email address, telephone number, role or title, organisation and work address;
associate engagement information, such as experience, qualifications, skills, certifications, identity and right-to-work verification, insurance and due diligence information and references;
communications, project information and records relating to enquiries, proposals, statements of work, service delivery, project documentation and support requests;
billing, payment and transaction details, supplier information, website usage data and cookie data, and any other information you voluntarily provide when you contact us or use our website.
We keep the information we hold to a minimum and only collect what is relevant to our business relationship, associate onboarding, website operation or project delivery. We do not usually collect special category data, such as information about your health or ethnicity, unless it is necessary for a specific client project, legal requirement or identity and right-to-work verification process and an appropriate UK GDPR condition applies. If document-and-likeness checking is used, this may involve facial biometric data for identity verification. Where client project data contains personal data, the client engagement will determine whether we handle that data as controller or processor and any client-specific instructions or data processing agreement will apply.
4. How we collect your data
We collect most of your data directly from you, for example when you contact us, discuss a potential engagement, provide a CV or credentials as an associate, use our website, enter into a contract with us or work with us on a client project. We may also receive your details from your organisation, a client, an associate, a supplier, a professional networking site, a colleague or referrer, or from project systems and documents made available to us for consultancy, advisory or technology delivery work.
5. How we use your data and our lawful basis
The law requires us to have a lawful basis for using your personal data. The table below explains how we use it and the basis we rely on.
Assessing enquiries and providing consultancy, advisory and technology delivery services
Data we use: Identity, business contact details, communications and project information
Our lawful basis: Our legitimate interests in operating and growing our consultancy business, and performing or taking steps to enter into a contract
Engaging and managing associates and prospective associates to deliver consultancy services
Data we use: Identity, contact, role, organisation, CV, credentials, identity documents, nationality, immigration status, right-to-work, insurance, due diligence, onboarding and payment information
Our lawful basis: Contract, legitimate interests, legal obligation and, where appropriate, consent, including express consent for insurance validation and quote-related disclosures and explicit consent for any biometric identity checks
Managing client, prospective client, supplier and business contact relationships, including communications, proposals and marketing
Data we use: Identity, business contact details, communications and marketing preferences
Our lawful basis: Legitimate interests, contract and consent where required for electronic marketing
Delivering client projects and handling project data, including where we act as processor on a client’s instructions or as controller for our own project administration
Data we use: Project data, business contact details, role or title, organisation, communications and project documentation
Our lawful basis: Contract, legitimate interests and, where we act as processor, the client’s documented instructions and applicable data processing agreement or further data processing terms required by the relevant client engagement
Running our business, including invoicing, accounts, compliance, security, website operation and record keeping
Data we use: Contact, billing, payment, transaction, website usage and cookie data
Our lawful basis: Legal obligation, contract, legitimate interests and consent where required for non-essential cookies
Where we rely on legitimate interests, we have considered your interests and rights and are satisfied that our use of your data does not override them. Our legitimate interests include providing and improving our consultancy, advisory and technology delivery services, managing client and associate relationships, protecting our systems, maintaining business records and operating our website. You have the right to object to processing based on our legitimate interests, and you can ask us for more information about this.
Where we use Jove Technology Limited’s insurance validation module as part of associate onboarding, we will ask for your express consent before sharing relevant insurance details and personal data with Jove. Jove acts as an independent controller under its own privacy notice and may use the information to validate insurance cover or provide insurance quotes to you.
6. Criminal offence information
We do not routinely collect criminal offence information. If an engagement, associate onboarding process or client project requires us to handle criminal offence information, we will do so only where it is relevant and lawful, where an appropriate condition under the Data Protection Act 2018 applies, and where suitable safeguards are in place. Where we act as processor for a client, we will handle such information only on the client’s documented instructions and in accordance with the relevant data processing terms.
7. Marketing
We may contact clients, prospective clients, associates, prospective associates and business contacts with information about our services, insights, events or opportunities to work with us. You can ask us to stop at any time, by using the unsubscribe link in our emails or by contacting us. We follow the rules on electronic marketing in the Privacy and Electronic Communications Regulations 2003, and we will not pass your details to other organisations for their own marketing without your consent.
8. Who we share your data with
We share your data only where we need to:
with clients, associates and project team members where needed to scope, manage and deliver consultancy, advisory or technology delivery services;
with service providers who help us run our business, such as Microsoft 365, hosting, accounting, professional advisory, security and website providers, who process your data under a written contract that meets UK data protection requirements;
where we are required to do so by law, for compliance, tax, audit, insurance, security or to establish, exercise or defend legal claims; and
with a buyer or prospective buyer, if we sell or reorganise our business, subject to appropriate confidentiality obligations, who may continue to use your data as described in this policy.
We may share associate onboarding data with TrustID for identity and right-to-work verification, and with Jove Technology Limited for insurance validation and, where you consent, insurance quote purposes. Jove acts as an independent controller for the information it receives and processes it under its own privacy notice.
We do not sell your personal data. Associates are given access only to project-specific information they need for an engagement, normally through restricted project folders, and do not have broad access to our CRM or wider business records. Access is reviewed and revoked when it is no longer needed.
9. Sending data outside the UK
Our standard approach is to store personal data in the United Kingdom. Some service providers, clients or project requirements may involve storing or processing data outside the United Kingdom. Where this happens, we make sure the transfer is protected by a UK adequacy decision or a valid safeguard recognised under UK data protection law, such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses or another approved mechanism, so that your data is given a level of protection that is not materially lower than it would receive in the UK. You can ask us for more detail about this.
10. How long we keep your data
We keep your data no longer than we need to. As a general guide, we keep client, associate, supplier and business contact records for as long as we have an active relationship with you and then for up to six years afterwards for legal, tax, audit, insurance and record-keeping purposes. We normally keep financial records for about six years to meet tax requirements. Right-to-work check records are kept for the duration of the relevant engagement and for two years after it ends. Project data is kept in line with the relevant client engagement, data processing agreement, project retention instructions and any legal or regulatory requirements. You can ask us for more detail about our retention periods.
11. Your rights
Under data protection law you have the following rights, which we will always work to uphold:
the right to be informed about how we use your data;
the right to access the data we hold about you;
the right to have inaccurate data corrected;
the right to have your data erased in certain circumstances;
the right to restrict how we use your data;
the right to object to our use of your data;
the right to data portability; and
the right to withdraw your consent at any time, where we rely on consent.
We do not make solely automated decisions about you that produce legal or similarly significant effects. To exercise any of your rights, please contact us using the details in section 16.
12. How to access your data
You can ask us for a copy of the personal data we hold about you. This is called a subject access request. There is no charge unless your request is manifestly unfounded or excessive. We will respond within one month. We may ask you to confirm your identity, or to help us understand what you are looking for, in which case the time may be paused until you reply. If your request is complex, we may extend the time by up to two further months, and we will tell you if we do.
13. Complaints
If you are unhappy with how we have handled your personal data, please contact us first, using the details in section 16, so that we can try to put things right. We will acknowledge your complaint promptly and aim to let you know the outcome within one month. You also have the right to complain to the Information Commissioner’s Office. Its website is ico.org.uk. We would, though, welcome the chance to resolve your concerns ourselves first.
14. Cookies
Our website uses only cookies that are strictly necessary for it to work, such as those that keep the site secure and running properly. These do not require your consent, and we do not use cookies for advertising or to track you across other websites. You can control cookies through your browser settings, though the site may not work fully if you block them. If we introduce any non-essential cookies in future, we will update this policy and ask for your consent first. If you would like more detail, please contact us using the details in section 16.
15. Changes to this policy
We may update this policy from time to time, for example if the law changes or we change how we work. Any changes will be posted on our website, and where practicable we will take reasonable steps to notify you of material changes. We recommend that you check the policy from time to time. This policy was last updated on 28 September 2026.
16. How to contact us
For anything to do with your personal data, including to make a request or a complaint, please contact:
Jacob Brown
VYSEBROWN LTD
71-75 Shelton Street, Covent Garden, London, United Kingdom WC2H 9JQ
Email: info@vysebrown.com
