Smart Risk & Compliance Ltd – Privacy Notice

Effective Date: 1st July 2026

Last Updated: 1st July 2026

Version: 1.0

1. Introduction

This Privacy Notice tells you what to expect us to do with your personal information when you use our products or services. It also outlines the steps we take to ensure that your personal data is protected and describes the rights you have in relation to the data we use.

An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.

2. About Smart Risk & Compliance Ltd

This Privacy Notice explains how Smart Risk & Compliance Ltd (“SmartRCL”, “we”, “us”, “our”) collects, uses, stores, shares and protects personal data. It also outlines the rights individuals have under UK data protection law and how to contact us.

This notice applies to:

  • visitors to our website
  • prospective clients and clients
  • suppliers and business contacts
  • training participants and event attendees
  • professional partners
  • individuals whose data may be included in materials we review during consultancy, audit, assurance or advisory work

3. Our Role: Controller and Processor

We may act as:

Controller: when we decide why and how personal data is used – for example:

  • website operation
  • enquiries
  • client relationship management
  • contracts and billing
  • marketing
  • complaints
  • supplier management
  • business administration

Processor: when we process personal data strictly on a client’s documented instructions – for example:

  • compliance consultancy
  • financial crime advisory
  • data protection support
  • audits and assurance reviews
  • training
  • policy development
  • data mapping, DPIAs and governance work

Joint or Independent Controller

In limited cases, we may act jointly with another organisation or independently. Where this applies, we will make this clear in engagement terms.

When acting as a processor, the client is responsible for providing privacy information to affected individuals. We protect that data and use it only as agreed and as required by law.

4. Personal Data We Collect

The data we collect depends on how you interact with us and the services involved. It may include:

  • identity and contact data
  • enquiry and communications data
  • client and service data
  • project materials and evidence
  • account and billing data
  • marketing and preference data
  • website and technical data
  • training and event data
  • supplier and partner data
  • recruitment or contractor data

We do not intentionally collect more personal data than we need. Please do not send special category or criminal offence data unless necessary and authorised.

5. Special Category and Criminal Offence Data

We do not usually need this type of data for general enquiries. However, it may appear in client materials during:

  • compliance reviews
  • data protection or security work
  • financial crime advisory
  • audits and assurance
  • training
  • incident or complaints handling

Where we act as processor, we follow client instructions and apply contractual and security controls.

Where we act as controller, we only process such data where legally permitted and subject to safeguards.

6. How We Collect Personal Data

We may collect data:

  • directly from you
  • from your organisation or colleagues
  • from client materials
  • through our website and cookies
  • from public sources
  • from trusted third‑party providers

7. Why We Use Personal Data and Lawful Bases

This section sets out the legal reasons we rely on, for each of the ways we may use your personal information. The law says we must have one or more of these reasons:

  • To fulfil a contract we have with you.
  • When it is our legal duty.
  • When it is in our legitimate interest.
  • When you consent to it.
  • When it is in the public interest.

When we have a business or commercial reason of our own to use your personal information, this is called a ‘legitimate interest’. We will tell you what that is, if we are going to rely on it as the reason for using your personal information. Even then, it must not unfairly go against your interests. Typical purposes include:

  • responding to enquiries
  • preparing proposals and contracts
  • delivering consultancy and advisory services
  • reviewing client evidence
  • managing client relationships
  • providing service communications
  • processing invoices and payments
  • meeting legal and regulatory obligations
  • handling complaints and rights requests
  • protecting our systems and business
  • sending marketing (with consent or soft opt‑in where applicable)
  • using cookies and analytics
  • assessing contractor or associate applications

You have the right to object to use of your personal information in this way. You can do this by telling us anything that we may need to consider, to understand if our use of your personal information is fair.

8. Marketing and Communications

We use marketing to let you know about products, services, and offers that you may want. This section tells you how we decide what marketing to show or send you. It also explains how we work out what you may be interested in.

We may use your personal information to make decisions about what products, services and offers we think you may be interested in. This is what we mean when we talk about ‘marketing.’

When we can use your personal information for marketing

We can only use your personal information to send you marketing messages if we have either your consent or a ‘legitimate interest.’ That is when we have a business or commercial reason to use your personal information and it does not conflict unfairly with your own interests.

How we decide what marketing may interest you

The personal information we have for you is made up of what you tell us, and data we collect when you use our services, or from outside organisations we work with. We study this to form a view on what we think you may want or need, or what may be of interest to you. This is how we decide which products, services and offers may be relevant for you. This is called profiling for marketing purposes.

You can contact us at any time and ask us to stop using your personal information this way.

How we send you marketing

We may show or send you marketing material online (on our own and other websites including social media), in our own and other apps, or by email, mobile phone, post or through smart devices and other digital channels.

You can also tell us not to collect data while you are using our websites or mobile apps. If you do, you may still see some marketing, but it may not be tailored to you. See our Cookies Policy for details about how we use this data to improve our websites and mobile apps.

Your marketing choices

You can tell us to stop sending you marketing at any time. Whatever you choose, we’ll still send you statements and other important information relating to your existing products and services. We do not sell the personal information we have about you to outside organisations.

We may ask you to confirm or update your choices, if you take out any new products or services with us in future. We’ll also ask you to do this if there are changes in the law, regulation, or the structure of our business.

If you change your mind, you can contact us to update your choices at any time.

9. Cookies and Website Use

Our website uses cookies and similar technologies. Some are necessary; others depend on your choices.

See our Cookie Policy for details.

10. Responsible Use of AI and Automation

  • We apply practical safeguards to our use of AI:
  • no solely automated decisions with legal or significant effects
  • no use of client confidential data to train public AI models
  • no input of client personal data into public AI tools unless authorised and lawful
  • human review and proportionate controls for AI‑assisted internal work

11. Who We Share Personal Data With

We may share data with:

  • IT, hosting and cyber security providers
  • CRM, project and document management platforms
  • payment processors and accountants
  • professional advisers and insurers
  • associates or subcontractors supporting service delivery
  • clients or authorised third parties
  • regulators or authorities where required
  • potential buyers or successors (with safeguards)

Processors must protect data and use it only for authorised purposes.

12. International Transfers

Your personal information may be transferred to or stored in locations outside of the EEA. We will only transfer your data when:

  • we’re required or permitted to by law or regulatory requirements.
  • we’re sharing data with a third party to support us in the management of your account.
  • the transfer is compliant with the UK GDPR (General Data Protection Regulations).

When transferring information, we make sure that suitable protection is maintained by ensuring appropriate safeguards are in place. This could be by:

  • only transferring information to countries that the Information Commissioner’s Office (ICO) has deemed to provide an adequate level of protection under Article 45 of the UK GDPR.
  • putting suitable clauses in our contracts so that organisations take appropriate steps to give information equivalent protection as it has in the UK.

13. How Long We Keep Personal Data

We keep data only as long as necessary. Typical retention periods include:

  • enquiries: up to 24 months
  • client records: usually 6 years
  • processor project materials: returned or deleted per contract
  • accounting records: 6 years
  • marketing records: until you unsubscribe
  • complaints and disputes: usually up to 6 years

14. How We Keep Personal Data Secure

The security of your information is very important to us. We maintain physical, electronic, and procedural safeguards in relation to the collection, storage, and disclosure of personal data to prevent unauthorised access, accidental loss, disclosure, or destruction.

15. Your Data Protection Rights

Under data protection law, you have rights we need to make you aware of. The rights available to you depend on the reason we use your information:

  1. You have the right to access your personal data. This is commonly referred to as data subject access. You can make a data subject access request verbally or in writing. We have one month to respond to a request and cannot charge a fee to deal with a request in most circumstances.
  2. You have the right to ask us to rectify information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete.
  3. You may request that we erase your personal information if you believe that: we no longer need to use your information for the purposes for which it was provided; we have requested your permission to use your personal information and you wish to withdraw your consent; or we are not using your information in a lawful manner.
  4. You have the right to object if we are using information based on our legitimate interests. Legitimate interests are when we have a business or commercial reason to use your personal information but our interests must not conflict unfairly with your interests. Please be aware that we can still use information where there are compelling grounds, or it is necessary for us to defend legal claims.
  5. You have the right to ask us to restrict the use of your information in certain circumstances. You may request to restrict the use of your personal information if you believe that: any of the information that we hold about you is inaccurate; we no longer need to use your information, but you want us to keep it to create, exercise or defend legal claims; we are not using your information in a
    lawful manner.
  6. You have the right to ask that we transfer the information you gave us from one organisation to another or give it to you. This right only applies to information you have given us which we are processing information based on your consent. This is known as the right to data portability.

You can withdraw your consent for us to use your personal information at any time (when our reason for using your personal information is that we have your consent). If you withdraw your consent, we may not be able to provide certain products or services to you. If this is so, we will tell you.

16. Complaints

We work to high standards when it comes to using your personal information. If you have any queries or concerns, please contact us at:

  • By e-mail: kim@smartrcl.co.uk
  • By post: Smart Risk & Compliance Ltd, 70 Carr Lane, Dronfield, S18 8XG.

If you remain dissatisfied, you can make a complaint to the Information Commissioner’s Office which regulates the use of personal data, by visiting ico.org.uk/make-a-complaint.

17. Children

Our website and services are intended for organisations and business contacts, not children.

18. Third‑Party Websites

Where we provide links to websites of other organisations, this Privacy Notice does not cover how that organisation processes personal information. We encourage you to read the Privacy Notices on the other websites you visit.

19. Profiling and Automated Decision‑Making

We do not carry out profiling or solely automated decision making that produces legal or similarly significant effects on individuals.

Where client materials include profiling (for example, risk scoring or analytics), we review that information only as part of the agreed consultancy work and only on the client’s documented instructions.

20. Updates to This Notice

We keep this Notice under regular review and may change it from time to time. When we make changes, the date at the top of this Notice will be updated accordingly. Any modification or amendment to this Notice will be applied as of that revision date. We encourage you to check this from time to time for any updates or changes.

However, if changes to this Notice will have a major effect on what we do with your personal data or on you personally, we will give you enough notice to allow you to exercise your rights (for example, to object to the processing).

21. Contact Us

Smart Risk & Compliance Ltd

70 Carr Lane, Dronfield, S18 8XG

📧 kim@smartrcl.co.uk

🔗 www.smartrcl.co.uk