Privacy Policy
At Glaxtons Consulting, we are committed to protecting your privacy and ensuring the security of your personal information. This comprehensive policy outlines our data practices in accordance with UK GDPR and the Data Protection Act 2018.
Quick Navigation
Last updated: 12 December 2024 | Effective from: 25 September 2024
This Privacy Policy explains how Glaxtons Consulting Limited ("we", "our", "us", "Glaxtons"), collects, uses, stores, shares, and protects your personal information when you visit our website at www.glaxtons.co.uk, engage with our services, communicate with us, or interact with our digital platforms. We are committed to maintaining the highest standards of data protection and transparency.
1. Who We Are
Glaxtons Consulting is a leading UK-based bid writing and tender consultancy firm, providing expert services to businesses seeking to win public and private sector contracts.
Company Information
- Registered Company NameGlaxtons Consulting Limited
- Trading NameGlaxtons Consulting
- Company Registration Number12065176
- Registered Office3 More London Place, London SE1 2RE
- Emailinfo@glaxtons.co.uk
- Telephone+44 20 3668 5488
We are the Data Controller for the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This means we are responsible for deciding how we hold and use personal information about you.
Our Data Protection Lead can be contacted at info@glaxtons.co.uk for any queries relating to this policy or your personal data.
2. Information We Collect
We collect and process various types of information to provide our services effectively and maintain our business relationships. The categories of data we collect include:
2.1 Personal Identification Data
- Identity Data: Full name, title, job title, professional qualifications, and employer/organisation name
- Contact Data: Business and personal email addresses, telephone numbers (landline and mobile), postal addresses, and social media handles where provided
- Professional Data: CV/resume information, professional experience, sector expertise, and relevant certifications when provided for tender submissions
2.2 Technical and Usage Data
- Device Information: IP address, browser type and version, operating system, device type, screen resolution, and unique device identifiers
- Usage Data: Pages visited, time spent on pages, navigation paths, click patterns, and scroll depth
- Location Data: Approximate geographic location derived from IP address (country and city level only)
- Referral Data: How you arrived at our website, including search terms, referring websites, and campaign sources
2.3 Transactional and Service Data
- Enquiry Data: Details of your service enquiries, requirements, tender deadlines, and project specifications
- Contract Data: Service agreements, project documentation, deliverables, and associated communications
- Financial Data: Invoicing details, payment records, and banking information necessary for payment processing
- Tender Documentation: Information provided for bid submissions, including company capabilities, past performance data, and case studies
2.4 Communication Data
- Correspondence: Emails, letters, meeting notes, and recorded communications (where consent is obtained)
- Feedback: Survey responses, testimonials, reviews, and any feedback provided about our services
- Marketing Preferences: Your choices regarding receiving newsletters, updates, sector insights, and promotional materials
2.5 Special Category Data
We do not intentionally collect special category data (such as data revealing racial or ethnic origin, political opinions, religious beliefs, health data, or sexual orientation). If such data is inadvertently provided within tender documentation, we process it only to the extent necessary for legitimate tender submission purposes and with appropriate safeguards.
How We Collect Information
We collect information through: (a) direct interactions when you contact us, complete forms, or engage our services; (b) automated technologies including cookies, server logs, and analytics tools; (c) third-party sources such as procurement portals, Companies House, credit reference agencies, and professional networking platforms; and (d) publicly available sources including your company website and professional directories.
3. How We Use Your Data
We process your personal data for the following specific purposes:
3.1 Service Delivery
- Delivering bid writing, tender management, and consultancy services as contracted
- Preparing, reviewing, and submitting tender documents on your behalf through recognised procurement portals (including Find a Tender, Contracts Finder, CCS eSourcing, Jaggaer, Delta, ProContract, and sector-specific platforms)
- Conducting research and analysis to strengthen your bid submissions
- Coordinating with your team and third-party stakeholders during the tender process
- Managing project timelines, deliverables, and quality assurance processes
3.2 Client Relationship Management
- Responding to enquiries, quotation requests, and service-related questions
- Maintaining accurate client records and communication history
- Providing ongoing account management and client support
- Processing invoices, payments, and financial administration
- Conducting client satisfaction surveys and gathering feedback
3.3 Business Operations and Improvement
- Analysing website usage to improve user experience and content relevance
- Monitoring and enhancing the performance of our digital platforms
- Developing and improving our service offerings based on market trends
- Training our team to deliver better client outcomes
- Managing internal business administration and reporting
3.4 Marketing and Communications
- Sending newsletters, sector insights, and thought leadership content (where consent is provided)
- Notifying you of relevant tender opportunities, framework openings, and procurement updates
- Inviting you to webinars, events, and networking opportunities
- Personalising our communications based on your sector and interests
3.5 Legal and Regulatory Compliance
- Complying with legal obligations, including tax, accounting, and regulatory requirements
- Responding to lawful requests from regulatory authorities and law enforcement
- Establishing, exercising, or defending legal claims
- Preventing and detecting fraud, money laundering, and other unlawful activities
4. Legal Basis for Processing
Under UK GDPR, we must have a valid legal basis for processing your personal data. We rely on the following grounds:
Contractual Necessity
Processing necessary to perform our contract with you or to take pre-contractual steps at your request. This includes delivering consultancy services, managing projects, and processing payments.
Consent
Where you have given clear, affirmative consent for specific processing activities, particularly for marketing communications and newsletters. You may withdraw consent at any time.
Legitimate Interests
Processing necessary for our legitimate business interests (or those of a third party), provided these interests do not override your fundamental rights. This includes business development, service improvement, and security measures.
Legal Obligation
Processing necessary to comply with legal or regulatory obligations, including requirements from HMRC, the Information Commissioner's Office, procurement framework regulations, and other statutory bodies.
Legitimate Interests Assessment
Where we rely on legitimate interests, we conduct a balancing test to ensure our interests do not override your rights. Our legitimate interests include:
- Maintaining and developing business relationships with clients and prospects
- Improving our services through analysis of client outcomes and feedback
- Protecting our business, employees, and clients from fraud and security threats
- Conducting business-to-business marketing to relevant organisations
- Defending our legal rights and interests
5. How We Protect Your Data
We implement comprehensive technical and organisational security measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction.
5.1 Technical Security Measures
- Encryption: All data transmitted to and from our website is protected using TLS 1.3 encryption. Sensitive data at rest is encrypted using AES-256 encryption standards
- Access Controls: Role-based access controls ensure only authorised personnel can access personal data relevant to their responsibilities
- Infrastructure Security: Our systems are hosted on secure, ISO 27001-certified cloud infrastructure within the UK and EU
- Monitoring: Continuous security monitoring, intrusion detection systems, and automated threat response mechanisms
- Backup and Recovery: Regular encrypted backups with tested disaster recovery procedures
5.2 Organisational Security Measures
- Staff Training: All employees and contractors receive mandatory data protection training upon joining and annual refresher training
- Confidentiality Agreements: All staff, contractors, and subprocessors are bound by confidentiality obligations
- Security Policies: Comprehensive information security policies governing data handling, acceptable use, and incident response
- Vendor Assessment: Third-party service providers undergo security and data protection assessments before engagement
- Regular Audits: Periodic internal audits and external penetration testing to identify and address vulnerabilities
5.3 Incident Response
We maintain a documented data breach response procedure. In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours and communicate with affected individuals without undue delay where required by law.
6. Sharing Your Information
We may share your personal data with the following categories of recipients, always ensuring appropriate safeguards are in place:
6.1 Service Delivery Partners
- Associate Bid Writers and Consultants: Independent contractors engaged on specific projects, bound by confidentiality agreements and data processing terms
- Specialist Subcontractors: Subject matter experts (e.g., social value consultants, technical writers) engaged for specific tender requirements
- Translation and Localisation Services: Where tenders require multi-language submissions
6.2 Technology and Infrastructure Providers
- Cloud Hosting Providers: Secure, UK/EU-based infrastructure providers for data storage and processing
- Email and Communication Platforms: Business email, video conferencing, and collaboration tools
- Analytics Providers: Website analytics services to understand and improve user experience
- Security Services: Providers of cybersecurity, backup, and disaster recovery services
6.3 Professional Advisers
- Legal Advisers: Solicitors and barristers providing legal counsel
- Accountants and Auditors: For financial reporting, tax compliance, and audit purposes
- Insurance Providers: For professional indemnity and business insurance purposes
6.4 Procurement Authorities
When submitting tenders on your behalf, we share necessary information with:
- Contracting authorities and public sector buyers
- Framework operators (e.g., Crown Commercial Service, Pagabo, NHS Supply Chain)
- E-procurement platform operators (e.g., Jaggaer, Delta eSourcing, ProContract)
6.5 Regulatory and Legal Authorities
We may disclose personal data to:
- HMRC for tax and accounting compliance
- The Information Commissioner's Office in response to investigations or enforcement actions
- Law enforcement agencies where required by law or court order
- Other regulatory bodies with lawful authority to request information
We Do Not Sell Your Data
We never sell, rent, or trade your personal information to third parties for their marketing purposes. Any data sharing is strictly limited to the purposes described in this policy.
7. International Data Transfers
We primarily store and process personal data within the United Kingdom and European Economic Area. Where we transfer data to countries outside the UK/EEA, we ensure appropriate safeguards are in place:
- UK Adequacy Regulations: Transfers to countries deemed adequate by the UK government under the Data Protection Act 2018
- Standard Contractual Clauses: International Data Transfer Agreement (IDTA) or UK Addendum to EU SCCs approved by the ICO
- Binding Corporate Rules: Where applicable, transfers to organisations with approved binding corporate rules
- Supplementary Measures: Additional technical and organisational safeguards where required by transfer impact assessments
You may request information about the specific safeguards applied to international transfers by contacting us at info@glaxtons.co.uk.
8. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, comply with legal obligations, and protect our legitimate interests.
| Data Category | Retention Period | Basis |
|---|---|---|
| Client contracts and project records | 7 years from contract completion | Limitation Act 1980; tax and accounting requirements |
| Financial and accounting records | 7 years from transaction date | Companies Act 2006; HMRC requirements |
| Tender submissions and bid documentation | 6 years from submission date | Potential legal claims; framework compliance |
| Enquiries (not converted to contracts) | 24 months from last contact | Legitimate business interest |
| Marketing consent records | Duration of consent plus 3 years | Evidence of lawful processing |
| Website analytics data | 26 months (anonymised thereafter) | Legitimate business interest |
| CCTV and security footage | 30 days (unless incident occurs) | Security and safety |
At the end of the retention period, personal data is securely deleted or anonymised. Where data is retained in anonymised form for statistical or research purposes, it is no longer considered personal data.
9. Your Data Protection Rights
Under UK GDPR, you have the following rights regarding your personal data. These rights are not absolute and may be subject to legal exemptions:
Right of Access
Request a copy of the personal data we hold about you, along with information about how we process it.
Right to Rectification
Request correction of inaccurate or incomplete personal data we hold about you.
Right to Erasure
Request deletion of your personal data in certain circumstances (e.g., when data is no longer necessary).
Right to Restrict Processing
Request that we limit how we use your data while we address your concerns or verify its accuracy.
Right to Data Portability
Receive your data in a structured, commonly used, machine-readable format and transfer it to another controller.
Right to Object
Object to processing based on legitimate interests or direct marketing at any time.
Right to Withdraw Consent
Withdraw consent at any time where processing is based on consent. This does not affect prior lawful processing.
Rights Related to Automated Decisions
Not be subject to decisions based solely on automated processing that significantly affect you.
How to Exercise Your Rights
To exercise any of these rights, please contact us at:
- Email: info@glaxtons.co.uk
- Post: Data Protection Lead, Glaxtons Consulting, 3 More London Place, London SE1 2RE
- Telephone: +44 20 3668 5488
We will respond to your request within one month. This period may be extended by two further months where requests are complex or numerous, in which case we will inform you of the extension and reasons.
We may request proof of identity before processing your request to ensure the security of your data. There is no fee for most requests, but we may charge a reasonable fee for manifestly unfounded, repetitive, or excessive requests.
11. Third-Party Links
Our website may contain links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you.
We do not control these third-party websites and are not responsible for their privacy practices. When you leave our website, we encourage you to read the privacy policy of every website you visit.
12. Children's Privacy
Our services are designed for businesses and professionals. We do not knowingly collect personal data from children under 16 years of age. If we become aware that we have collected personal data from a child without appropriate consent, we will take steps to delete that information promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will:
- Update the "Last updated" date at the top of this policy
- Post a prominent notice on our website
- Where appropriate, notify you directly by email
We encourage you to review this policy periodically to stay informed about how we protect your data. Continued use of our website and services after changes constitutes acceptance of the updated policy.
14. Complaints
We take data protection concerns seriously and will endeavour to resolve any issues promptly. If you have concerns about how we handle your personal data:
- Contact us first: Email info@glaxtons.co.uk or call +44 20 3668 5488. We aim to resolve complaints within 28 days.
- Escalate if needed: If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).
Information Commissioner's Office
- Website: www.ico.org.uk
- Helpline: 0303 123 1113
- Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
15. Contact Us
If you have any questions about this Privacy Policy, your personal data, or wish to exercise your data protection rights, please contact us:
Glaxtons Consulting
Registered Office
3 More London Place
Bank, London
SE1 2RE
Contact Details
Email: info@glaxtons.co.uk
Telephone: +44 20 3668 5488
This Privacy Policy was last reviewed and updated on 12 December 2024.