Privacy policy
This policy explains what personal data XM Consulting Ltd collects, why we collect it, how long we keep it, who we share it with, and the rights you have over it.
1Who we are and how to contact us
XM Consulting Ltd is a company registered in England and Wales under company number 16716131, with its registered office at 6 Burton Close, Thornton Heath CR7 8SU, England, United Kingdom. In this policy, "we", "us" and "our" refer to that company.
For the personal data described in this policy, we act as the data controller. That means we decide why and how the data is used, and we are responsible for it under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
We have not appointed a statutory Data Protection Officer, because we are not required to. Questions, requests and complaints about data protection go to contact@xmconsultingltd.com and are handled by a company director.
2Who this policy covers
This policy applies to people whose personal data we handle in the course of running our business.
- Visitors to this website.
- People who contact us through the enquiry form, by email, or through a social media profile.
- Prospective clients we are in discussions with, and the individual staff of those organisations.
- Clients and their staff, for the duration of an engagement and afterwards.
- Suppliers, contractors and other business contacts.
- People who apply to work with us.
3The personal data we collect
We try to collect as little as possible, and we do not ask for information we have no use for. Depending on your relationship with us, the categories are as follows.
- Enquiry data
- Your name, email address, the company you work for if you tell us, an indicative monthly budget range if you select one, and whatever you write in the message field. This is the data submitted through the contact form on this site.
- Correspondence data
- Emails, meeting notes, call notes and messages exchanged with you, kept as a record of what was discussed and agreed.
- Client relationship data
- For clients: the names, job titles, work email addresses and work phone numbers of the individuals we deal with, plus contractual and billing information such as purchase order references and invoice history.
- Technical and usage data
- If, and only if, you consent to analytics cookies: pages viewed, approximate location derived from IP address, device and browser type, referring source, and how you moved through the site. We do not receive your full IP address in a form we can use to identify you.
- Recruitment data
- If you apply to work with us: your CV, covering message, work history and any information you choose to share during the process.
4Special category data
We do not seek out special category data, which under the UK GDPR means information about racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health, sex life or sexual orientation. We also do not collect criminal offence data.
Please do not include information of this kind in an enquiry form or an email to us. If you do send it, we will delete it unless we have a clear legal basis to keep it.
5How we collect your data
- Directly from you, when you complete the enquiry form, email us, speak to us on a call, or hand us a business card.
- Automatically from your device, through cookies and similar technologies, but only within the limits of the consent you give.
- From your employer, where a client provides the contact details of staff we will be working with.
- From publicly available sources, such as a company website or Companies House, when we are preparing for a conversation with a prospective client.
6Why we use your data and our lawful basis
The UK GDPR requires a lawful basis for every use of personal data. Ours are set out below.
- Responding to enquiries
- We use enquiry and correspondence data to reply to you, prepare for a call, and answer your questions. Lawful basis: our legitimate interest in responding to people who contact us about our services.
- Delivering our services
- We use client relationship data to carry out the engagement, communicate with your team, report on performance and manage the account. Lawful basis: performance of a contract with your organisation, or our legitimate interest where the contract is with your employer rather than you personally.
- Invoicing, accounting and tax
- We keep records of what was agreed, what was delivered and what was paid. Lawful basis: compliance with a legal obligation, principally under the Companies Act 2006 and HMRC record-keeping rules.
- Improving this website
- We use technical and usage data in aggregate to understand which pages are useful and where the site is confusing. Lawful basis: your consent, given through the cookie banner and withdrawable at any time.
- Direct marketing
- If you ask to hear from us, or you are an existing client, we may occasionally email you about relevant services. Lawful basis: your consent, or our legitimate interest in marketing similar services to existing clients. Every message contains a one-click way to stop them.
- Protecting the business
- We may use correspondence and contractual data to establish, exercise or defend legal claims, and to prevent fraud. Lawful basis: our legitimate interest in protecting the company, and compliance with legal obligations.
7Data we handle on behalf of clients
There is an important distinction to be aware of. Everything above concerns data for which we are the controller. Separately, when we manage advertising accounts, analytics properties or tag management for a client, we may access personal data that belongs to that client, for example enquiry records in their CRM or user data in their Google Analytics property.
For that data we act as a processor, not a controller. We use it only to carry out the instructions in the engagement, we do not use it for our own purposes, and the client's own privacy notice governs how it may be used. Where required, this arrangement is documented in a data processing agreement forming part of the statement of work.
If you are an end customer of one of our clients and want to exercise rights over your data, please contact that company directly. We will support them in responding, but we cannot act on their data without their instruction.
8Marketing and how to opt out
We do not buy marketing lists, and we do not add people to a mailing list simply because they submitted an enquiry. Any marketing email we send will make clear who it is from and will include an unsubscribe link that works immediately.
You can also opt out at any time by emailing contact@xmconsultingltd.com with the word "unsubscribe" in the subject line. Opting out of marketing does not stop service messages such as invoices, reports or contractual notices while an engagement is running.
11Transfers outside the United Kingdom
Some of the providers listed above are based outside the UK, or store data outside the UK. Where personal data is transferred internationally, we make sure one of the following applies: the destination country is covered by UK adequacy regulations, or the transfer is governed by the International Data Transfer Agreement or the UK Addendum to the European Commission's standard contractual clauses, together with any additional safeguards a risk assessment identifies as necessary.
You can ask us for details of the safeguards applying to a specific transfer by emailing contact@xmconsultingltd.com.
12How long we keep it
We keep personal data only as long as we have a reason to, then delete it. Our standard periods are below, and we will keep data for longer only where the law requires it or where it is needed for a live legal claim.
- Enquiries that do not become clients
- Up to 24 months from our last contact with you, then deleted.
- Client records and correspondence
- For the duration of the engagement and six years afterwards, matching the limitation period for contractual claims and HMRC requirements.
- Invoices and accounting records
- Six years from the end of the relevant accounting period, as required by UK tax law.
- Marketing consents and opt-outs
- Opt-out records are kept indefinitely, because that is the only reliable way to make sure we do not contact you again.
- Recruitment data
- Six months after a decision is made, unless you agree to us keeping it longer for future roles.
- Analytics data
- Retained inside Google Analytics for 14 months, then automatically deleted.
13How we keep it secure
No system is perfectly secure, but we take practical measures proportionate to the data we hold.
- Multi-factor authentication on every business account that supports it.
- Access limited to the people who need it to do their work, and removed promptly when it is no longer needed.
- Encryption in transit across this website and our business systems, and encryption at rest with our providers.
- Reputable providers with recognised security standards, rather than self-managed infrastructure.
- A policy of requesting read-only access to client systems first, and the minimum level of access needed thereafter.
14Personal data breaches
If a breach occurs that is likely to result in a risk to people's rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it. Where the risk is high, we will also tell the affected individuals directly and explain what has happened and what we are doing about it.
Where we are acting as a processor for a client, we will notify that client without undue delay so they can meet their own obligations.
15Your rights
Under UK data protection law you have the following rights. They are not absolute, and some apply only in particular circumstances, but we will always explain our reasoning if we cannot act on a request.
- Access
- You can ask for a copy of the personal data we hold about you, along with information about how we use it.
- Rectification
- You can ask us to correct data that is inaccurate, or to complete data that is incomplete.
- Erasure
- You can ask us to delete your data where we no longer need it, where you withdraw consent that was our only basis, or where it has been processed unlawfully.
- Restriction
- You can ask us to pause our use of your data, for example while we investigate a challenge to its accuracy.
- Objection
- You can object to processing based on legitimate interests. Where you object to direct marketing, we will stop without exception.
- Portability
- Where processing is based on consent or a contract and is automated, you can ask for your data in a structured, commonly used, machine-readable format.
- Withdrawing consent
- Where we rely on consent, you can withdraw it at any time. This does not affect anything done before you withdrew it.
16Making a request
To exercise any right, email contact@xmconsultingltd.com and tell us which right you want to use. We may ask for information to confirm your identity, so that we do not disclose your data to someone else.
We respond within one month. If a request is particularly complex, or you have made several, we may extend that by up to two further months, and we will tell you within the first month if that happens. There is no charge, unless a request is manifestly unfounded or excessive.
17Automated decision-making
We do not make decisions about you that produce legal or similarly significant effects using automated processing alone, and we do not carry out profiling of that kind.
Advertising platforms we operate on your behalf, such as Google Ads, use automated systems to decide which adverts to show to which audiences. That processing is carried out by the platform under its own terms and privacy policy, and it does not make decisions about individuals in the sense the UK GDPR restricts.
18Children
Our services are aimed at businesses, and this website is not directed at children. We do not knowingly collect personal data relating to anyone under 18. If you believe a child has given us personal data, contact us and we will delete it.
19Other websites
This site links to third-party websites, including platform documentation and industry resources. Following a link takes you outside our control, and we are not responsible for the privacy practices of those sites. Read their own policies before providing them with personal data.
20Complaints
If you are unhappy with how we have handled your personal data, please tell us first at contact@xmconsultingltd.com so we have a chance to put it right.
You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority for data protection. The ICO can be reached at ico.org.uk, on 0303 123 1113, or at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
21Changes to this policy
We review this policy at least annually and whenever we change how personal data is handled. The version published here is the one in force, and previous versions are available on request.
Where a change materially affects how we use data about existing clients or subscribers, we will tell them by email rather than relying on this page alone.