Privacy Notice
This document is currently under legal review and may be updated.
Last updated: 27 July 2026
1. Introduction
Fox Healey & Co respects your privacy and is committed to handling personal information lawfully, fairly and transparently.
This Privacy Notice explains how we collect, use, share, store and protect personal information when you:
- visit foxhealey.co.uk;
- apply for a Commercial Performance Snapshot;
- submit an enquiry or contact form;
- subscribe to a newsletter or market briefing;
- communicate with us;
- book or attend a meeting;
- create or use a Fox Healey client Portal account;
- contribute to an assessment or consultancy engagement;
- receive reports, recommendations or benchmarking information;
- attend an event or webinar;
- interact with our LinkedIn page or other professional content; or
- otherwise deal with Fox Healey in a business capacity.
It also explains how we may use appropriately anonymised and aggregated information to produce market benchmarks, quarterly and annual reports, website insights, newsletters and professional content.
This notice should be read alongside our:
- Website and Client Portal Terms of Use;
- Cookie and Storage Technology Policy;
- client engagement agreements;
- data-processing agreements, where applicable; and
- any additional privacy information provided when we collect particular information.
2. Who we are
For the purposes described in this notice, the data controller is normally:
Fox Healey Ltd Registered in England and Wales Company number: 17368719 Registered office: Bartle House, 9 Oxford Court, Manchester, M2 3WQ Email: hello@foxhealey.co.uk Privacy email: privacy@foxhealey.co.uk [WHEN ESTABLISHED] ICO registration number: [TO BE ADDED IF APPLICABLE]
References to “Fox Healey”, “we”, “us” or “our” mean Fox Healey Ltd.
We have not appointed a statutory Data Protection Officer unless and until stated otherwise. Responsibility for privacy matters will be assigned to an appropriate privacy lead.
3. Our role in relation to client information
Fox Healey will normally act as a controller for personal information used to:
- manage enquiries and applications;
- qualify prospective clients;
- administer client relationships;
- create and manage Portal accounts;
- secure and audit the Portal;
- communicate with users;
- issue reports and service notices;
- manage billing and contracts;
- comply with legal obligations;
- administer marketing preferences; and
- improve and protect our services.
During a consultancy engagement, a client may provide personal information about its employees, customers, prospects, suppliers or other contacts.
Depending on the circumstances, Fox Healey may act as:
- an independent controller;
- a joint controller with the client; or
- a processor acting on the client’s documented instructions.
The relevant engagement agreement or data-processing agreement will clarify the parties’ respective responsibilities where necessary.
4. Whose personal information we collect
We may collect personal information relating to:
- Website visitors;
- people submitting enquiries;
- Commercial Performance Snapshot applicants;
- prospective clients;
- client directors, owners and senior managers;
- client Portal administrators and contributors;
- employees or representatives of client organisations;
- prospective customers or customer contacts mentioned in authorised client information;
- suppliers and professional advisers;
- consultants and subcontractors;
- referral partners;
- event and webinar attendees;
- newsletter subscribers;
- people who interact with our professional or LinkedIn content;
- people whose information is available from legitimate public or business sources; and
- other business contacts.
Our services are intended for business users aged 18 or over. We do not knowingly provide Portal accounts to children.
5. Information you provide directly
5.1 Enquiries and Snapshot applications
When you contact us or apply for a Commercial Performance Snapshot, we may collect:
- name;
- work email address;
- telephone number;
- job title;
- employer or organisation;
- company website;
- location;
- sector;
- turnover band;
- employee band;
- preferred contact method;
- source of the enquiry;
- commercial challenges;
- reasons for applying;
- information entered into free-text fields;
- privacy acknowledgements;
- marketing preferences; and
- correspondence relating to the application.
5.2 Portal accounts
When a Portal account is created or used, we may collect:
- name;
- work email address;
- employer or Organisation;
- job title;
- Portal role and permissions;
- account status;
- invitation status;
- email-verification status;
- terms and privacy-notice acceptance;
- login and session records;
- authentication-provider identifier;
- last login date;
- account activity;
- security events;
- notification preferences; and
- technical information associated with access.
We do not store authentication passwords in the Portal database where authentication is managed by an external identity provider.
5.3 Organisation and assessment information
During the Commercial Performance Snapshot or another engagement, we may collect information about:
- company activities;
- products and services;
- markets and sectors;
- routes to market;
- revenue and growth;
- gross margin;
- customer concentration;
- customer retention;
- account development;
- dormant and lapsed accounts;
- sales pipelines;
- opportunities;
- quotation conversion;
- forecasting;
- pricing and discounting;
- freight and cost recovery;
- product and customer profitability;
- commercial-team structure;
- roles and objectives;
- skills and capability;
- recruitment requirements;
- CRM and ERP systems;
- management reporting;
- marketing activity;
- workflow automation;
- use or readiness for artificial intelligence;
- commercial risks;
- potential financial opportunities;
- recommended actions; and
- ongoing performance measures.
Much of this is company information rather than personal information. It becomes personal information where it identifies, relates to or can reasonably be connected with an individual.
5.4 Assessment responses and contributions
We may collect:
- questionnaire responses;
- maturity selections;
- data-confidence selections;
- narrative comments;
- supporting evidence;
- uploaded files;
- data-source descriptions;
- names of contributors;
- section assignments;
- completion records;
- submission confirmations;
- clarification responses; and
- changes made to responses.
5.5 Management interviews and meetings
When you book or attend a meeting, we may collect:
- attendee names;
- work contact details;
- employer and job title;
- booking preferences;
- calendar information;
- meeting date and time;
- attendance records;
- meeting notes;
- clarification questions;
- agreed statements;
- actions; and
- follow-up correspondence.
We will not normally record audio or video meetings unless attendees are informed in advance and an appropriate lawful basis has been established.
Where transcription or recording is used, we will explain:
- that recording or transcription will take place;
- the purpose;
- the provider used;
- who will have access; and
- how long the recording or transcript will be retained.
5.6 Reports, findings and ongoing programmes
We may collect or create:
- client self-assessment scores;
- consultant-validated scores;
- data-confidence scores;
- consultant commentary;
- strengths and weaknesses;
- identified risks;
- potential financial opportunities;
- recommended actions;
- action owners;
- target dates;
- evidence;
- progress updates;
- baseline scores;
- working scores;
- target scores;
- formal reassessment scores;
- score histories; and
- report versions.
5.7 Billing and engagement administration
Where paid services are provided, we may collect:
- billing contact details;
- purchase-order information;
- contract information;
- fee and payment records;
- invoice information;
- bank-payment references;
- correspondence about payment;
- tax information; and
- records required for accounting and insurance purposes.
We do not intend to store complete payment-card details. Where card payments are introduced, they should be processed by an authorised payment provider.
5.8 Newsletter and marketing preferences
We may collect:
- name;
- work email address;
- employer;
- job title;
- topics of interest;
- subscription source;
- consent record;
- unsubscribe record;
- email-delivery status;
- engagement with marketing communications; and
- communication preferences.
Email tracking may include whether an email was delivered, opened or a link was selected, depending on the configuration of our email provider and your device settings.
5.9 Example report downloads
When you download example content from the Website, such as the example Commercial Performance Snapshot report, you may choose to provide a work email address before downloading.
Providing an email address is entirely optional. The download is never conditional on providing one, and downloads made without an email address are recorded only as anonymous, aggregated counts together with limited technical information (such as browser type).
Where you choose to provide an email address, we may collect:
- work email address;
- the page or source of the download; and
- the date and time of the download.
We use this information to follow up about the example report and our services. You can ask us to delete this information at any time using the contact details in this notice.
6. Information collected automatically
When you use the Website or Portal, we may automatically collect limited technical and usage information, including:
- IP address;
- browser type and version;
- device type;
- operating system;
- approximate location derived from IP address;
- referring page;
- requested pages;
- date and time of access;
- session identifiers;
- authentication events;
- Portal navigation;
- form-submission events;
- error and performance logs;
- security alerts;
- rate-limit events; and
- other information necessary to operate and secure the service.
Our use of cookies and related technologies is explained in our Cookie and Storage Technology Policy.
We do not currently intend to use third-party advertising pixels or cross-site behavioural tracking.
7. Information received from other sources
We may receive personal information from:
- your employer or Organisation;
- another authorised Portal user;
- colleagues who assign an assessment section to you;
- referral partners;
- professional advisers;
- public company websites;
- Companies House;
- professional directories;
- LinkedIn and other professional networks;
- event organisers;
- conference attendee lists where use is permitted;
- CRM and marketing systems;
- booking providers;
- email and calendar providers;
- authentication providers;
- fraud-prevention or security services;
- existing clients;
- suppliers; and
- publicly available business publications.
Where we obtain personal information from another source, we will provide appropriate privacy information unless an applicable exception applies.
8. Information we ask you not to provide
The Website and initial Snapshot are not designed to collect special-category personal information or criminal-offence information.
Please do not provide unnecessary information concerning:
- health;
- disability;
- race or ethnic origin;
- political opinions;
- religious or philosophical beliefs;
- trade-union membership;
- genetic information;
- biometric identifiers;
- sexual orientation;
- sexual life;
- criminal allegations or convictions;
- medical records;
- national insurance numbers;
- private financial information;
- payment-card information;
- passwords;
- customer payment details; or
- confidential personal information unrelated to the engagement.
If such information is provided inadvertently, we may delete, redact or restrict it unless retaining and using it is necessary, lawful and appropriately protected.
9. How we use personal information
We may use personal information to:
- respond to enquiries;
- assess Snapshot applications;
- determine whether a business is within our target market;
- request additional information;
- identify possible conflicts of interest;
- create prospective-client records;
- create and administer client Organisations;
- issue Portal invitations;
- authenticate users;
- manage permissions;
- operate and secure the Portal;
- administer assessments;
- allocate questionnaire sections;
- monitor completion;
- conduct management interviews;
- request clarification;
- validate assessment scores;
- prepare findings and recommendations;
- produce client reports;
- maintain baseline and ongoing performance records;
- track actions;
- conduct formal reassessments;
- provide consultancy and implementation services;
- manage contracts, invoices and payments;
- maintain business records;
- send essential service communications;
- provide support;
- detect and prevent misuse;
- investigate security incidents;
- improve our methodology and services;
- create authorised benchmarks and market intelligence;
- produce quarterly and annual reports;
- prepare professional content;
- send newsletters or marketing communications;
- manage unsubscribe requests;
- establish, exercise or defend legal claims;
- comply with legal, tax, regulatory and insurance requirements; and
- support a business sale, investment or corporate restructuring.
10. Our lawful bases
We must have a lawful basis whenever we process personal information.
The basis used depends on the purpose and circumstances.
| Purpose | Normal lawful basis |
|---|---|
| Responding to enquiries | Legitimate interests in responding to business enquiries; or steps requested before entering a contract where the individual is a party to that contract |
| Reviewing Snapshot applications | Legitimate interests in assessing suitability, managing capacity and avoiding conflicts |
| Creating and operating Portal accounts | Performance of a contract where applicable; legitimate interests in delivering services to an Organisation and administering authorised users |
| Delivering assessments and consultancy | Performance of a contract where the individual is a contracting party; otherwise legitimate interests in delivering contracted services to the client Organisation |
| Authentication, security and fraud prevention | Legitimate interests in protecting users, information, systems and our business; legal obligation where applicable |
| Service emails and notifications | Performance of a contract or legitimate interests in administering the requested service |
| Management interviews and consultant review | Performance of a contract or legitimate interests in completing the requested assessment and advisory service |
| Financial administration and accounting | Performance of a contract, legitimate interests and legal obligations |
| Retaining evidence of agreements and transactions | Legal obligation and legitimate interests in record keeping and defending legal claims |
| Newsletter subscriptions | Consent |
| Optional email provided when downloading example content | Consent — the email field is optional, clearly explained at the point of collection, and the download is never conditional on providing it |
| Other business-to-business marketing | Consent or legitimate interests, as permitted by applicable data-protection and electronic-marketing rules |
| Suppression records | Legitimate interests and legal obligations in respecting marketing objections |
| Service improvement and internal analysis | Legitimate interests in maintaining and improving our services |
| Creating anonymised and aggregated market intelligence | Legitimate interests in improving methodology, producing useful market insight and developing services, subject to appropriate assessments and safeguards; consent may be used where specifically requested |
| Publishing identifiable case studies, quotations or testimonials | Consent or a specific written agreement |
| AI-assisted draft preparation | Performance of a contract or legitimate interests in efficiently delivering and improving services, subject to human review and appropriate safeguards |
| Legal claims and regulatory enquiries | Legal obligation and legitimate interests in protecting our legal rights |
| Corporate sale or restructuring | Legitimate interests in operating, financing or transferring the business, subject to confidentiality and data-protection safeguards |
Where we rely on legitimate interests, we consider:
- the purpose and benefit of the processing;
- whether the processing is necessary;
- the likely impact on individuals;
- what the individual would reasonably expect;
- whether less intrusive options are available; and
- the safeguards required.
You can request more information about a legitimate-interests assessment relevant to your personal information.
11. Snapshot qualification and lead review
Snapshot applications are reviewed by an authorised administrator.
We may use information such as:
- sector;
- company size;
- turnover band;
- location;
- business need;
- senior-management involvement;
- implementation ability;
- conflicts of interest; and
- information completeness
to provide an indicative target-fit classification.
The classification may include:
- strong fit;
- potential fit;
- outside standard profile;
- conflict or unsuitable; or
- insufficient information.
This classification supports an administrator’s review. It does not automatically determine acceptance or rejection.
An authorised person makes the final decision.
12. Assessment scoring
The Portal may calculate maturity and data-confidence scores from questionnaire responses using defined scoring rules.
These calculations may produce:
- question scores;
- pillar scores;
- overall scores;
- self-assessment scores;
- data-confidence scores; and
- progress indicators.
A Fox Healey consultant may validate or change a score following review of the information and a management interview.
Any material consultant adjustment should record:
- the original score;
- the revised score;
- the reason;
- the person making the change; and
- the date.
Scores relate primarily to the Organisation’s commercial processes. They are not intended to make legal or similarly significant decisions about an individual.
13. Automated decision-making and profiling
We do not currently intend to make decisions about individuals based solely on automated processing where those decisions produce legal or similarly significant effects.
In particular:
- Snapshot applications are reviewed by a person;
- assessment scores are subject to consultant review;
- risks and recommendations require consultant approval;
- AI-generated content remains draft;
- reports are not published automatically; and
- client access is not refused solely because of an automated maturity score.
If we introduce qualifying solely automated decision-making in future, we will update this notice and provide any information, safeguards and rights required by law.
14. Artificial intelligence and automated tools
We may use artificial-intelligence or automated tools to assist with:
- organising responses;
- identifying missing answers;
- identifying possible inconsistencies;
- summarising information;
- drafting findings;
- drafting report wording;
- drafting action descriptions;
- analysing approved aggregate information; and
- preparing draft professional content.
Where AI tools are used:
- outputs will normally be treated as drafts;
- client-facing findings require human review;
- final scores require human oversight;
- outputs will not be automatically published;
- access should be limited to authorised users;
- only the information reasonably necessary should be processed;
- providers should be assessed before use; and
- appropriate contractual and security controls should be applied.
We will not knowingly use identifiable client information to train a publicly available or general-purpose third-party AI model without appropriate authority and transparency.
Where possible, approved aggregate or anonymised data will be used for market-content drafting instead of raw client information.
15. Client-submitted information about other people
An Organisation may provide personal information relating to employees, directors, customers, prospects, suppliers or other contacts.
The Organisation is responsible for ensuring that:
- it has authority to provide the information;
- the disclosure is lawful;
- the information is relevant and proportionate;
- unnecessary personal information is removed;
- affected individuals receive appropriate privacy information where required; and
- special-category or criminal-offence information is not submitted unless specifically agreed and lawful.
We may redact, return or delete information that appears excessive or unrelated to the engagement.
16. Market intelligence and benchmarking
Subject to applicable agreements, notices, permissions and safeguards, we may use selected assessment information to create:
- client benchmarking;
- quarterly market reports;
- annual market reports;
- sector reports;
- commercial-performance analysis;
- pricing and margin insights;
- sales-execution insights;
- CRM and data insights;
- artificial-intelligence-readiness insights;
- website articles;
- newsletter content;
- webinars;
- presentations; and
- LinkedIn or other professional content.
The processing used to create these outputs may include:
- removing direct identifiers;
- excluding free-text answers;
- removing names and contact details;
- reducing dates to quarter or year;
- converting exact values into bands;
- grouping companies by broad sector or size;
- rounding values;
- calculating medians or quartiles;
- suppressing small groups;
- excluding outliers;
- testing for dominance by one contributor; and
- aggregating multiple observations.
We do not intend to publish identifiable assessment responses or confidential company information through market reports.
17. Anonymised and pseudonymised information
Information is not necessarily anonymous merely because a name has been removed.
We distinguish between:
- anonymised information, which cannot reasonably be used to identify an individual; and
- pseudonymised information, where identifiers have been replaced or separated but re-identification remains possible using other information.
Pseudonymised personal information remains subject to this Privacy Notice and applicable data-protection law.
Where information has been assessed as effectively anonymised, it may no longer constitute personal information. However, the process used to create the anonymised information is itself a use of the original personal information and must have an appropriate lawful basis.
18. Market-data separation and controls
Where implemented, the market-intelligence system will be separated from the operational client database.
The market-intelligence records should not contain:
- company names;
- trading names;
- websites;
- email domains;
- names;
- email addresses;
- telephone numbers;
- exact addresses;
- postcodes;
- user IDs;
- operational Organisation IDs;
- raw interview notes;
- free-text questionnaire responses;
- uploaded files;
- file names;
- customer names;
- product names; or
- other direct identifiers.
A restricted operational mapping may be retained separately where necessary to:
- correct information;
- recompute a contribution;
- honour an applicable withdrawal;
- investigate an error;
- manage retention; or
- maintain an audit trail.
Access to this mapping will be restricted.
19. Benchmark disclosure controls
We may withhold or combine benchmark results where:
- the number of contributing Organisations is too small;
- one Organisation would dominate the result;
- an outlier could be recognisable;
- a narrow combination of factors creates identification risk;
- the information could reveal confidential business activity; or
- the methodology would produce an unreliable comparison.
Public reports will normally use a minimum cohort threshold determined by our approved disclosure-control policy.
Benchmark reports may show:
- cohort size;
- reporting period;
- median;
- quartile range;
- distribution;
- broad sector;
- turnover band;
- employee band;
- route-to-market category; and
- methodology limitations.
We will not publish a named league table of participating clients without specific permission.
20. Market-data permissions and withdrawal
Where a separate market-data authorisation is required, we will record:
- the notice version;
- the permitted purposes;
- the person providing authorisation;
- the date;
- the Organisation concerned;
- any withdrawal; and
- any restrictions.
Withdrawal will prevent future processing based on that authorisation where applicable.
It may not be possible to remove information from:
- reports already lawfully published;
- statistics that have been irreversibly aggregated;
- information that has been effectively anonymised; or
- records we are legally required to retain.
Where a published report is materially affected by a correction or withdrawal, we will consider whether a correction, replacement or withdrawal notice is appropriate.
21. Marketing communications
We may send:
- newsletters;
- manufacturing-market insights;
- invitations to events or webinars;
- information about Commercial Performance Snapshots;
- information about relevant Fox Healey services; and
- other professional business communications.
Newsletter subscribers may unsubscribe at any time.
For other business-to-business communications, we will use consent or legitimate interests where permitted by applicable law.
We will take particular care where an address belongs to:
- a sole trader;
- an unincorporated partnership; or
- an individual subscriber.
You have an absolute right to object to the use of your personal information for direct marketing.
We may retain limited suppression information after an unsubscribe request so that we can avoid contacting you again.
22. Essential service communications
We may send essential messages about:
- Portal invitations;
- email verification;
- account security;
- password resets;
- assessment access;
- assigned sections;
- completion reminders;
- booking links;
- meeting confirmation;
- clarification requests;
- report publication;
- action assignments;
- policy changes;
- system maintenance; and
- security incidents.
These messages are part of operating the service and are not necessarily marketing communications.
23. How we share personal information
We do not sell personal information to advertisers or data brokers.
We may share personal information with:
- authorised Fox Healey employees;
- consultants and subcontractors;
- the client Organisation and its authorised users;
- hosting and cloud-infrastructure providers;
- authentication providers;
- CRM providers;
- email-delivery providers;
- Microsoft 365 or Google Workspace;
- meeting and booking providers;
- video-conferencing providers;
- secure file-storage providers;
- document and PDF providers;
- accounting and payment providers;
- e-signature providers;
- analytics providers where approved;
- security, backup and anti-spam providers;
- legal advisers;
- accountants;
- auditors;
- insurers;
- lenders or investors subject to confidentiality controls;
- regulators;
- courts;
- law-enforcement bodies; and
- prospective buyers or investors in connection with a business transaction.
Service providers should receive only the information reasonably necessary for their function and should be subject to appropriate contractual and security requirements.
24. Client administrators and other users
A Client Administrator may be able to view:
- users associated with the Organisation;
- user names and work email addresses;
- role and permissions;
- section assignments;
- completion status;
- submitted responses;
- published reports;
- client-visible actions; and
- other information relevant to administering the Organisation’s account.
Client Contributors may have more limited access.
Private Fox Healey notes and internal commentary should not be visible to client users.
25. Service-provider register
Before launch, Fox Healey should maintain an internal register identifying:
- each service provider;
- the service provided;
- whether the provider acts as processor or controller;
- information processed;
- location of processing;
- retention arrangements;
- sub-processors;
- security review;
- contractual terms; and
- international-transfer mechanism.
A public list of key service providers may be published in future and, if so, will be linked from this notice.
Likely provider categories include:
- Website hosting;
- Portal hosting;
- database hosting;
- authentication;
- CRM;
- email and calendar;
- transactional email;
- booking;
- file storage;
- PDF generation;
- accounting;
- electronic signatures;
- monitoring and security; and
- approved AI services.
26. International transfers
Some service providers may process personal information outside the United Kingdom.
Where a restricted international transfer takes place, we will use an appropriate mechanism where required, which may include:
- UK adequacy regulations;
- the UK Extension to an approved data-privacy framework where applicable;
- the UK International Data Transfer Agreement;
- the UK Addendum to approved EU standard contractual clauses;
- binding corporate rules;
- another approved safeguard; or
- a permitted exception in limited circumstances.
Where required, we will assess whether the standard of protection remains appropriate and implement additional technical, organisational or contractual measures.
You may contact us for further information about safeguards relevant to your personal information.
27. Data security
We use reasonable technical and organisational measures designed to protect personal information against:
- unauthorised access;
- accidental loss;
- unlawful use;
- alteration;
- disclosure;
- destruction; and
- misuse.
Measures may include:
- invite-only Portal access;
- role-based permissions;
- server-side tenant isolation;
- email verification;
- secure authentication;
- encryption in transit;
- encryption at rest where supported;
- secure cookies;
- rate limiting;
- input validation;
- access logging;
- audit records;
- secure backups;
- restricted administrative access;
- vulnerability management;
- file-type and size controls;
- account suspension;
- session expiry;
- security monitoring; and
- staff and contractor confidentiality obligations.
No system can be guaranteed to be entirely secure. You should notify us promptly if you believe your account or information has been compromised.
28. Data retention
We retain personal information only for as long as reasonably necessary for the relevant purpose, including legal, contractual, accounting, insurance and dispute-management requirements.
Our intended initial retention periods are set out below. These periods must be confirmed against the final systems, engagement terms and professional advice before launch.
| Information | Intended retention |
|---|---|
| Unconverted general enquiries and Snapshot applications left in a non-terminal status (for example, "new", "under review", "further information required" or "on hold") | Automatically flagged for review after 24 months of no activity; automatically deleted after a further 3 months (27 months total) if still untouched. Approved applications and records converted to a client relationship are never automatically deleted. |
| Declined or unsuitable Snapshot applications | Automatically deleted 24 months after the last update to the record, unless a shorter or longer period is justified |
| Approved applications and client-conversion records | Retained with the client relationship and engagement records |
| Expired invitations | Normally up to 12 months after expiry for security and audit purposes |
| Portal account records | While the account is active and normally for up to 24 months after deactivation, subject to client-record requirements |
| Assessment responses and published reports | Normally for the engagement period and up to seven years afterwards |
| Contracts, invoices and financial records | Normally seven years or another period required by applicable law |
| Consultant interview notes | Normally for the engagement period and up to seven years afterwards where they form part of the professional record |
| Audio or video recordings, if used | Normally deleted after transcription or review and no later than the period notified before recording |
| Security and access logs | Normally between 12 and 24 months, subject to investigation or security requirements |
| Marketing subscriptions | Until unsubscribe, invalidity or prolonged inactivity |
| Marketing suppression records | Minimum information may be retained as long as necessary to respect the objection |
| Service-provider and consent records | For as long as necessary to demonstrate compliance |
| Market contribution mapping | Only as long as required for correction, withdrawal, audit and governance |
| Effectively anonymised market information | May be retained for research, comparison and historical reporting because it no longer identifies an individual |
| Anonymous website analytics events | Automatically deleted 24 months after the event was recorded |
| Example report download records | Any volunteered email address is automatically removed 6 months after the download; the remaining anonymous record is automatically deleted after 24 months |
| Backups | Deleted or overwritten according to the applicable backup cycle |
We may retain information longer where:
- required by law;
- required by an insurer;
- relevant to an active dispute;
- necessary to establish or defend a legal claim;
- subject to a regulatory investigation;
- required to protect system security; or
- agreed in a client engagement.
We may delete information earlier where it is no longer needed.
29. Whether you must provide information
Some information is optional.
However, we may be unable to:
- respond meaningfully to an enquiry;
- assess a Snapshot application;
- create a Portal account;
- authenticate a user;
- complete an assessment;
- validate scores;
- prepare a report;
- book an interview;
- deliver consultancy services; or
- meet legal obligations
if required information is not provided.
Optional questions should be identified where practical.
Where commercial data is unavailable, the Portal may allow you to select “not known” rather than provide an inaccurate value.
30. Your rights
Depending on the circumstances and lawful basis, you may have the right to:
- be informed about how your personal information is used;
- request access to your personal information;
- request correction of inaccurate or incomplete information;
- request erasure;
- request restriction of processing;
- object to processing based on legitimate interests;
- object to direct marketing;
- request data portability;
- withdraw consent;
- challenge certain automated decisions; and
- complain to a supervisory authority.
These rights are not all absolute and may not apply to every processing activity.
For example:
- information may need to be retained for legal claims;
- another person’s rights may limit disclosure;
- data portability applies only in specified circumstances;
- erasure may not apply where retention is legally required; and
- withdrawal of consent does not make earlier lawful processing unlawful.
31. Exercising your rights
To exercise a right or ask a privacy question, contact:
privacy@foxhealey.co.uk [WHEN ESTABLISHED]
or:
Please include enough information for us to:
- identify you;
- understand your request;
- locate the relevant records; and
- verify your authority where you act for another person.
We may request proof of identity where reasonably necessary.
We will normally respond within the period required by applicable law. Complex or multiple requests may take longer where the law permits.
We do not normally charge a fee. A reasonable fee may be charged, or a request may be refused, where permitted by law because it is manifestly unfounded or excessive.
32. Right to object to direct marketing
You have an absolute right to object to the use of your personal information for direct marketing.
You can object by:
- selecting the unsubscribe link in a marketing email;
- changing an available communication preference;
- replying to the communication where appropriate; or
- emailing us.
We may retain your email address or other minimum identifier on a suppression list to ensure that your objection continues to be respected.
33. Complaints
Please contact us first if you have concerns about how we use personal information. We will investigate the issue and attempt to resolve it.
You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority for data protection.
Information about making a complaint is available through the ICO’s official website.
You may also have the right to seek a judicial remedy.
34. Third-party websites and services
The Website and Portal may link to third-party websites or services.
Those organisations may use personal information for their own purposes and apply their own privacy notices.
We are not responsible for another organisation’s privacy practices merely because we provide a link to its service.
You should review the relevant third-party notice before providing personal information.
35. Corporate transactions
If Fox Healey is involved in:
- a sale;
- merger;
- acquisition;
- investment;
- financing;
- corporate reorganisation;
- insolvency process; or
- transfer of business assets,
personal information may be disclosed to professional advisers, prospective counterparties, funders or a successor organisation.
Such disclosure will be limited where practical and subject to confidentiality and data-protection safeguards.
36. Changes to this Privacy Notice
We may update this notice to reflect:
- changes to our services;
- changes to the Portal;
- new service providers;
- new processing purposes;
- changes to market-intelligence activities;
- legal or regulatory developments;
- security improvements; or
- changes to our business.
The current version will show its last-updated date.
Where a change materially affects registered users or changes how existing information will be used, we may provide additional notice through:
- email;
- the Portal;
- a just-in-time notice;
- an updated consent or acknowledgement; or
- another appropriate method.
Where required, we will provide information about a new purpose before beginning the new processing.
37. Contact details
Questions, requests or concerns about this notice should be sent to:
Fox Healey Ltd Email: hello@foxhealey.co.uk Privacy email: privacy@foxhealey.co.uk [WHEN ESTABLISHED] Registered office: Bartle House, 9 Oxford Court, Manchester, M2 3WQ ICO registration number: [TO BE ADDED IF APPLICABLE]