Privacy Policy
Presidium (“we”, “us”, “our”) · Last updated: [DATE]
This policy explains how we collect, use, store, share and protect personal data, and the rights you have over it. We are committed to handling personal data lawfully, fairly and transparently, in accordance with the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (“PECR”).
Given the nature of our service — locating and removing our clients’ exposed personal information — we hold ourselves to a standard of data handling that exceeds our legal obligations.
1. Who we are
Presidium is the trading name of [LEGAL ENTITY NAME], a company registered in England and Wales (company number [NUMBER]) with its registered office at [ADDRESS].
We are the data controller for the personal data described in this policy, except where Section 5 states otherwise. We are registered with the Information Commissioner’s Office (“ICO”) under registration number [ZA000000].
Contact for all privacy matters: [EMAIL] / [POSTAL ADDRESS].
2. Personal data we collect
(a) Enquiry data. When you contact us or submit an enquiry through our website, we collect your name, email address, telephone number (if provided) and the contents of your message.
(b) Client engagement data. When you become a client, we collect the personal data reasonably necessary to identify you and deliver the service, which may include: full name and any former names; current and previous residential addresses; dates of birth; telephone numbers and email addresses; names of household members or relatives (where relevant to your exposure); company directorships and business interests; and identity verification documents.
(c) Exposure data. In the course of delivering the service, we collect records of where your personal data appears publicly — including data broker listings, people-search entries, search engine results, public register entries and breach datasets in which your details appear. This data is collected about you from public and third-party sources for the purpose of removing or suppressing it.
(d) Technical data. When you visit our website we may collect limited technical data (IP address, browser type, pages viewed) through server logs and any cookies described in Section 10.
(e) Payment data. Payments are processed by our payment provider; we do not store full card numbers.
We do not intentionally collect special category data (such as health, religious or political information). If such data is incidentally present in exposure data we locate, we handle it solely for the purpose of removal and delete our records of it in accordance with Section 7.
3. How we obtain personal data
We obtain personal data: directly from you; from public sources and third parties in the course of locating your exposure (data brokers, people-search sites, search engines, public registers, breach notification services); and automatically through your use of our website.
4. Purposes and lawful bases
We process personal data for the following purposes on the lawful bases indicated under UK GDPR Article 6:
- Responding to enquiries and providing quotations — legitimate interests (responding to a contact you initiated).
- Verifying your identity before acting on your behalf — legal obligation and contract (necessary to ensure removal requests are lawfully made).
- Delivering the services: locating, removing and suppressing your exposed data; monitoring for reappearance — contract (performance of our agreement with you).
- Submitting removal, suppression, objection and erasure requests to third parties on your behalf — contract; and where required, your explicit written authority.
- Keeping records of work performed and evidence of removals — contract and legitimate interests (demonstrating performance; defending legal claims).
- Invoicing, accounting and tax — legal obligation.
- Complying with law, regulation or court order — legal obligation.
- Improving and securing our website — legitimate interests.
- Sending you service communications about your engagement — contract.
- Marketing communications (only if you have opted in) — consent, withdrawable at any time.
We do not sell personal data. We do not use personal data for automated decision-making producing legal or similarly significant effects.
5. Who we share personal data with
We share personal data only where necessary and only to the extent necessary:
(a) Third parties holding your data — at your instruction. Delivering the service inherently requires disclosing certain of your personal data (typically your name and the data to be removed, and sometimes identity confirmation) to the data brokers, websites, search engines and register operators we approach on your behalf. We disclose the minimum required for each request. This disclosure is made under our contract with you and, where a recipient requires it, under your signed letter of authority. Note: when we submit requests to third parties, those third parties process your data under their own privacy policies, which we do not control.
(b) Service providers (processors). Carefully selected providers who support our operations — secure hosting, encrypted storage, email and payment processing — bound by written contracts meeting the requirements of Article 28 UK GDPR.
(c) Professional advisers. Our accountants, insurers and legal advisers, where necessary and subject to confidentiality.
(d) Authorities. Where we are required to by law, regulation or valid legal process, or to establish, exercise or defend legal claims.
We never share client identities, engagement details or exposure reports for marketing, research, case studies or any other purpose without your prior written consent.
6. International transfers
We store personal data in the United Kingdom or the European Economic Area wherever possible. Some data brokers and websites we contact on your behalf are located outside the UK; submitting a removal request to them necessarily involves transferring the relevant data to that jurisdiction. Where we transfer data to a processor outside the UK, we do so only under a UK adequacy regulation, the ICO’s International Data Transfer Agreement, or another safeguard permitted by Articles 44–49 UK GDPR.
7. Retention
We keep personal data only as long as necessary for the purposes above:
- Enquiry data (no engagement follows): deleted within 12 months of last contact.
- Client engagement and exposure data: retained for the duration of the engagement and for 6 years afterwards, solely for the purposes of evidencing the work performed and defending legal claims, then securely deleted. Clients may request earlier deletion of exposure reports at any time (see Section 9), subject to our need to retain minimal records required by law.
- Identity verification documents: deleted within 3 months of the end of the engagement unless law requires longer.
- Accounting records: 6 years, as required by law.
- Monitoring data (Private Protection clients): retained for the duration of the retainer and deleted within 3 months of its end.
8. Security
We apply technical and organisational measures appropriate to the sensitivity of the data we hold, including encryption of data in transit and at rest, access restricted to personnel who need it, strong authentication, minimal data collection by design, and secure deletion procedures. In the event of a personal data breach likely to result in a risk to your rights, we will notify the ICO within 72 hours as required by Article 33 UK GDPR and inform you without undue delay where the risk is high.
9. Your rights
Under the UK GDPR you have the right to: access the personal data we hold about you; rectify inaccurate data; erase your data (“right to be forgotten”); restrict processing; data portability; object to processing based on legitimate interests and to direct marketing; and withdraw consent at any time where processing is based on consent, without affecting prior processing.
To exercise any right, contact [EMAIL]. We will respond within one month (extendable by two months for complex requests, in which case we will tell you). We may need to verify your identity before acting. Exercising your rights is free of charge except where a request is manifestly unfounded or excessive.
Complaints. You may complain to us at [EMAIL], and you have the right to lodge a complaint with the Information Commissioner’s Office at any time: ico.org.uk / 0303 123 1113 / Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. We would appreciate the opportunity to address your concern first.
10. Cookies
Our website uses only strictly necessary cookies required for it to function. We do not use advertising or third-party tracking cookies. If this changes, we will update this section and seek your consent as required by PECR before setting non-essential cookies.
11. Children
Our services are directed at adults. We do not knowingly collect personal data from anyone under 18 except where it forms part of a client’s household exposure data, in which case it is processed solely for removal purposes under the client’s engagement.
12. Third-party links
Our website may link to third-party sites (for example, the ICO). We are not responsible for their content or privacy practices.
13. Changes to this policy
We may update this policy from time to time. The current version will always be available on our website with its “last updated” date. Material changes affecting active clients will be notified directly.
Registered office: [ADDRESS] · Company no. [NUMBER] · ICO registration [ZA000000]