1. Introduction
Clarendum Consulting ("Clarendum", "we", "our", or "us") is committed to protecting the privacy of everyone who visits our website, contacts us, or engages our services. This Privacy Policy explains what personal information we collect, how we use it, and the rights you have in relation to your information.
This policy applies to personal information collected through clarendumconsulting.com and through our wider business activities. Please read it carefully. By using our website or corresponding with us, you confirm that you have read and understood this policy.
2. Who we are
Clarendum Consulting is a UK-based management consultancy providing healthcare strategy, operational improvement, and growth advisory services to healthcare, healthtech, and behavioural health organisations.
For the purposes of the UK GDPR and the Data Protection Act 2018, Clarendum Consulting is the data controller for the personal information we hold about you.
- Trading name
- Clarendum Consulting
- Registered address
- [Insert registered address]
- Company registration number
- [Insert company number]
- ICO registration number
- [Insert ICO registration number]
- Privacy contact email
- hello@clarendumconsulting.com
3. Personal information we collect
We may collect and process the following categories of personal information:
- Identity and contact details — name, job title, employer, email address, telephone number, and postal address.
- Enquiry information — the content of messages you send us through our contact form, by email, or by phone, including details about your organisation and the support you are seeking.
- Engagement information — information exchanged during consulting engagements, including notes, correspondence, and documents you share with us.
- Marketing preferences — your choices about receiving updates, insights, or newsletters from us.
- Technical and usage information — IP address, browser type, device information, referring URLs, pages viewed, and time spent on the site (collected through cookies and analytics tools).
We do not intentionally collect special category personal data (such as health, racial, religious, or biometric information) through this website. Please do not submit such information via our contact form.
4. How we collect your information
We collect personal information in the following ways:
- Directly from you — when you complete our contact form, book an introductory call, sign up to receive updates, or email or call us.
- During the course of an engagement — when you or your organisation share information with us to enable us to deliver our services.
- Automatically, when you use our website — through cookies, server logs, and analytics tools such as Google Analytics.
- From publicly available sources — such as LinkedIn, corporate websites, or Companies House, where relevant to a legitimate business enquiry or engagement.
5. How we use your information
We use personal information for the following purposes:
- To respond to enquiries and provide requested information.
- To arrange and hold introductory calls, meetings, and consultations.
- To deliver, manage, and administer consulting engagements and related contracts.
- To issue invoices and manage payments.
- To send occasional insights, updates, or newsletters where you have opted in or where we have a legitimate interest to do so.
- To operate, maintain, secure, and improve our website and services.
- To comply with legal, regulatory, tax, accounting, and professional obligations.
6. Our lawful basis for processing
Under the UK GDPR, we must have a lawful basis to process personal information. We rely on the following bases:
- Contract — where processing is necessary to enter into or perform a contract with you or your organisation (for example, delivering an agreed consulting engagement).
- Legitimate interests — where processing is necessary for our legitimate business interests, such as responding to enquiries, managing client relationships, promoting our services to relevant business contacts, keeping records, and securing our website. We balance these interests against your rights and freedoms.
- Consent — where you have provided clear, specific consent, for example when subscribing to marketing communications or accepting non-essential cookies. You may withdraw consent at any time.
- Legal obligation — where processing is necessary to comply with our legal, regulatory, or tax obligations.
7. How we store and protect your data
We take the security of personal information seriously and apply appropriate technical and organisational measures to protect it against unauthorised access, loss, alteration, or disclosure. These measures include:
- Access controls, authentication, and role-based permissions.
- Encryption of data in transit (HTTPS/TLS).
- Use of reputable, security-vetted service providers (including Microsoft 365).
- Ongoing review of our processes, tools, and vendors to maintain appropriate safeguards.
While we take reasonable steps to protect personal information, no method of transmission over the internet is entirely secure. If you believe your interaction with us is no longer secure, please contact us immediately.
8. How long we keep your information
We keep personal information only for as long as necessary for the purposes for which it was collected, including satisfying any legal, tax, accounting, or reporting requirements. Typical retention periods are:
- Website enquiries that do not lead to an engagement — up to 24 months from last contact.
- Client and engagement records — for the duration of the engagement and typically up to 7 years afterwards, to meet contractual, legal, and tax obligations.
- Marketing contacts — until you unsubscribe or ask us to remove your details, and reviewed periodically for continued relevance.
When information is no longer required, it is securely deleted or anonymised.
10. International transfers of data
Some of the service providers we use (such as Google and Microsoft) may process personal information outside the United Kingdom, including in the European Economic Area and the United States.
Where personal information is transferred outside the UK, we rely on appropriate safeguards recognised under the UK GDPR, such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or adequacy regulations (including the UK Extension to the EU-US Data Privacy Framework, where applicable). We take reasonable steps to ensure your information continues to be protected to a standard equivalent to that required in the UK.
12. Marketing communications
We may occasionally send you insights, updates, or information about our services where you have opted in, or where we have a legitimate business interest to do so (for example, existing or prospective clients in a professional context).
You can opt out of marketing communications at any time by clicking the "unsubscribe" link in any marketing email, or by contacting us at hello@clarendumconsulting.com. Opting out of marketing does not affect essential communications relating to an active engagement.
13. Your rights under UK GDPR
Subject to certain conditions and exemptions, you have the following rights in relation to your personal information:
- Right of access — to request a copy of the personal information we hold about you.
- Right to rectification — to ask us to correct inaccurate or incomplete information.
- Right to erasure — to ask us to delete personal information in certain circumstances.
- Right to restrict processing — to ask us to limit how we use your information.
- Right to data portability — to ask us to transfer certain information to you or another organisation in a structured, commonly used format.
- Right to object — to object to processing based on our legitimate interests or for direct marketing.
- Right to withdraw consent — where we rely on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us using the details in section 15. We may need to verify your identity before responding. We will normally respond within one month.
14. How to make a complaint
We aim to handle any concerns about your privacy fairly and promptly. If you are unhappy with how we have handled your personal information, please contact us first so we can try to resolve the issue.
You also have the right to complain to the UK Information Commissioner's Office (ICO), the UK's supervisory authority for data protection matters:
15. Contact us about privacy
If you have any questions about this Privacy Policy, or would like to exercise any of your rights, please contact us:
- By email
- hello@clarendumconsulting.com
We keep this Privacy Policy under review and may update it from time to time to reflect changes in law, technology, or our business practices. The date at the top of this page shows when it was last updated.
