Legal

Privacy Policy

This policy explains how Clarendum Consulting collects, uses, stores, and protects personal information in line with the UK GDPR and the Data Protection Act 2018.

Last updated: 22 July 2026

1. Introduction

Clarendum Consulting ("Clarendum", "we", "our", or "us") is committed to protecting the privacy of everyone who visits our website, contacts us, or engages our services. This Privacy Policy explains what personal information we collect, how we use it, and the rights you have in relation to your information.

This policy applies to personal information collected through clarendumconsulting.com and through our wider business activities. Please read it carefully. By using our website or corresponding with us, you confirm that you have read and understood this policy.

2. Who we are

Clarendum Consulting is a UK-based management consultancy providing healthcare strategy, operational improvement, and growth advisory services to healthcare, healthtech, and behavioural health organisations.

For the purposes of the UK GDPR and the Data Protection Act 2018, Clarendum Consulting is the data controller for the personal information we hold about you.

Trading name
Clarendum Consulting
Registered address
[Insert registered address]
Company registration number
[Insert company number]
ICO registration number
[Insert ICO registration number]
Privacy contact email
hello@clarendumconsulting.com

3. Personal information we collect

We may collect and process the following categories of personal information:

  • Identity and contact details — name, job title, employer, email address, telephone number, and postal address.
  • Enquiry information — the content of messages you send us through our contact form, by email, or by phone, including details about your organisation and the support you are seeking.
  • Engagement information — information exchanged during consulting engagements, including notes, correspondence, and documents you share with us.
  • Marketing preferences — your choices about receiving updates, insights, or newsletters from us.
  • Technical and usage information — IP address, browser type, device information, referring URLs, pages viewed, and time spent on the site (collected through cookies and analytics tools).

We do not intentionally collect special category personal data (such as health, racial, religious, or biometric information) through this website. Please do not submit such information via our contact form.

4. How we collect your information

We collect personal information in the following ways:

  • Directly from you — when you complete our contact form, book an introductory call, sign up to receive updates, or email or call us.
  • During the course of an engagement — when you or your organisation share information with us to enable us to deliver our services.
  • Automatically, when you use our website — through cookies, server logs, and analytics tools such as Google Analytics.
  • From publicly available sources — such as LinkedIn, corporate websites, or Companies House, where relevant to a legitimate business enquiry or engagement.

5. How we use your information

We use personal information for the following purposes:

  • To respond to enquiries and provide requested information.
  • To arrange and hold introductory calls, meetings, and consultations.
  • To deliver, manage, and administer consulting engagements and related contracts.
  • To issue invoices and manage payments.
  • To send occasional insights, updates, or newsletters where you have opted in or where we have a legitimate interest to do so.
  • To operate, maintain, secure, and improve our website and services.
  • To comply with legal, regulatory, tax, accounting, and professional obligations.

6. Our lawful basis for processing

Under the UK GDPR, we must have a lawful basis to process personal information. We rely on the following bases:

  • Contract — where processing is necessary to enter into or perform a contract with you or your organisation (for example, delivering an agreed consulting engagement).
  • Legitimate interests — where processing is necessary for our legitimate business interests, such as responding to enquiries, managing client relationships, promoting our services to relevant business contacts, keeping records, and securing our website. We balance these interests against your rights and freedoms.
  • Consent — where you have provided clear, specific consent, for example when subscribing to marketing communications or accepting non-essential cookies. You may withdraw consent at any time.
  • Legal obligation — where processing is necessary to comply with our legal, regulatory, or tax obligations.

7. How we store and protect your data

We take the security of personal information seriously and apply appropriate technical and organisational measures to protect it against unauthorised access, loss, alteration, or disclosure. These measures include:

  • Access controls, authentication, and role-based permissions.
  • Encryption of data in transit (HTTPS/TLS).
  • Use of reputable, security-vetted service providers (including Microsoft 365).
  • Ongoing review of our processes, tools, and vendors to maintain appropriate safeguards.

While we take reasonable steps to protect personal information, no method of transmission over the internet is entirely secure. If you believe your interaction with us is no longer secure, please contact us immediately.

8. How long we keep your information

We keep personal information only for as long as necessary for the purposes for which it was collected, including satisfying any legal, tax, accounting, or reporting requirements. Typical retention periods are:

  • Website enquiries that do not lead to an engagement — up to 24 months from last contact.
  • Client and engagement records — for the duration of the engagement and typically up to 7 years afterwards, to meet contractual, legal, and tax obligations.
  • Marketing contacts — until you unsubscribe or ask us to remove your details, and reviewed periodically for continued relevance.

When information is no longer required, it is securely deleted or anonymised.

9. Sharing your information with third parties

We do not sell your personal information. We only share it where necessary to operate our business or where required by law. Categories of third parties include:

  • Website hosting and infrastructure providers that host our site and its underlying services.
  • Email and productivity providers — Microsoft 365 for email, file storage, and collaboration.
  • Analytics providers — Google Analytics, to understand how the website is used.
  • CRM and enquiry management tools, where used to record and manage enquiries and client relationships.
  • Scheduling tools — such as Google Calendar appointment scheduling, to book introductory calls.
  • Professional advisers — such as accountants, insurers, and lawyers, where required.
  • Regulatory or law enforcement bodies, where we are legally obliged to disclose information.

Where third parties process personal information on our behalf, they act as data processors and are contractually required to protect the information in line with UK data protection law.

10. International transfers of data

Some of the service providers we use (such as Google and Microsoft) may process personal information outside the United Kingdom, including in the European Economic Area and the United States.

Where personal information is transferred outside the UK, we rely on appropriate safeguards recognised under the UK GDPR, such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or adequacy regulations (including the UK Extension to the EU-US Data Privacy Framework, where applicable). We take reasonable steps to ensure your information continues to be protected to a standard equivalent to that required in the UK.

11. Cookies and website analytics

Our website uses cookies and similar technologies to make the site work, to understand how it is used, and to improve the user experience. Cookies are small text files stored on your device.

We use the following categories of cookies:

  • Strictly necessary cookies — required for the website to function.
  • Analytics cookies — set by Google Analytics to help us understand aggregated visitor behaviour, such as which pages are viewed and how visitors reach the site. This data is used in aggregate form and is not used to identify you personally.

You can control or disable cookies through your browser settings. Blocking some cookies may impact your experience of the website. For more information about cookies, visit ico.org.uk.

12. Marketing communications

We may occasionally send you insights, updates, or information about our services where you have opted in, or where we have a legitimate business interest to do so (for example, existing or prospective clients in a professional context).

You can opt out of marketing communications at any time by clicking the "unsubscribe" link in any marketing email, or by contacting us at hello@clarendumconsulting.com. Opting out of marketing does not affect essential communications relating to an active engagement.

13. Your rights under UK GDPR

Subject to certain conditions and exemptions, you have the following rights in relation to your personal information:

  • Right of access — to request a copy of the personal information we hold about you.
  • Right to rectification — to ask us to correct inaccurate or incomplete information.
  • Right to erasure — to ask us to delete personal information in certain circumstances.
  • Right to restrict processing — to ask us to limit how we use your information.
  • Right to data portability — to ask us to transfer certain information to you or another organisation in a structured, commonly used format.
  • Right to object — to object to processing based on our legitimate interests or for direct marketing.
  • Right to withdraw consent — where we rely on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, please contact us using the details in section 15. We may need to verify your identity before responding. We will normally respond within one month.

14. How to make a complaint

We aim to handle any concerns about your privacy fairly and promptly. If you are unhappy with how we have handled your personal information, please contact us first so we can try to resolve the issue.

You also have the right to complain to the UK Information Commissioner's Office (ICO), the UK's supervisory authority for data protection matters:

Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113

15. Contact us about privacy

If you have any questions about this Privacy Policy, or would like to exercise any of your rights, please contact us:

We keep this Privacy Policy under review and may update it from time to time to reflect changes in law, technology, or our business practices. The date at the top of this page shows when it was last updated.