Privacy Policy
Last updated: 1 November 2024. This policy explains how Bovingdon-Gray Consultancy Limited collects, uses, stores and protects your personal data in accordance with UK GDPR and the Data Protection Act 2018.
1. Who We Are and How to Contact Us
Bovingdon-Gray Consultancy Limited ("Bovingdon-Gray", "we", "us" or "our") is a consultancy registered in Scotland, United Kingdom. Our principal place of business is 3 Fitzroy Place, 1/1 Sauchiehall Street, Glasgow, G3 7RH. We provide educational technology (EdTech) solutions, corporate training and professional development programmes, UI/UX and digital product design services, instructional design and e-learning development, management consulting services and custom computer programming services to clients across the United Kingdom and internationally.
For the purposes of UK data protection law, Bovingdon-Gray Consultancy Limited is the data controller in respect of all personal data described in this Privacy Policy. As data controller, we determine the purposes and means by which personal data is processed. If you have any questions, concerns or requests relating to our data processing activities, you can contact us using the following details:
Bovingdon-Gray Consultancy Limited
3 Fitzroy Place, 1/1 Sauchiehall Street
Glasgow, G3 7RH, Scotland, United Kingdom
Email: info@bovingdon-gray.fit
Telephone: +44 7451 234890
This Privacy Policy applies to all personal data we collect and process in connection with: our website at bovingdon-gray.fit ("the Website"); our pre-sales enquiry and brief assessment process; our client engagement and service delivery activities; our post-delivery communications and relationship management activities; and any other means by which you interact with us as an organisation. It does not apply to websites operated by third parties, even where links to those websites appear on our Website.
We encourage you to read this Privacy Policy in full before submitting a brief, entering into an engagement with us or using our Website. If you do not agree with any aspect of this Privacy Policy, you should not provide us with personal data and should not use the Website.
2. The Legal Framework Governing Our Data Processing
We process personal data in strict compliance with the UK General Data Protection Regulation (UK GDPR), as retained in domestic UK law by the European Union (Withdrawal) Act 2018, and the Data Protection Act 2018. Together, these instruments constitute the primary data protection framework applicable to our activities in the United Kingdom.
Where we collect and process personal data from individuals located within the European Economic Area (EEA), we also apply the requirements of the EU General Data Protection Regulation 2016/679 (EU GDPR) to the extent that those requirements are applicable to our processing activities. We maintain appropriate safeguards for any transfers of personal data between the United Kingdom and the EEA as described in Section 8 of this Privacy Policy.
A fundamental principle of both UK GDPR and EU GDPR is that personal data may only be processed where there is a valid and documented lawful basis for doing so. We identify and record the applicable lawful basis for each category of our processing activities. The lawful bases we rely upon are:
- Consent (Article 6(1)(a)): You have given clear, specific, informed and unambiguous consent to the processing of your personal data for one or more specific purposes. Where we rely on consent, you have the right to withdraw it at any time, and such withdrawal does not affect the lawfulness of processing that took place before the withdrawal.
- Contract performance (Article 6(1)(b)): Processing is necessary for the performance of a contract to which you are a party, or in order to take steps at your request prior to entering into a contract with you. This applies principally to our service delivery activities where you or your organisation has contracted with us.
- Legal obligation (Article 6(1)(c)): Processing is necessary for compliance with a legal obligation to which we are subject, including obligations under UK tax law, company law, employment law and data protection law itself.
- Legitimate interests (Article 6(1)(f)): Processing is necessary for the purposes of our legitimate interests or those of a third party, except where such interests are overridden by your interests or fundamental rights and freedoms. We carry out a balancing assessment before relying on this basis and can provide details of any such assessment on request.
We do not, as a general rule, process special categories of personal data (formerly known as sensitive personal data) about clients, prospective clients or website visitors. In the unlikely event that special category data is provided to us incidentally, we will treat it with the heightened protection required by Article 9 of UK GDPR. Please refer to Section 5 of this Privacy Policy for further information.
3. Personal Data We Collect and the Sources From Which We Collect It
3.1 Data You Provide Directly to Us
When you interact with Bovingdon-Gray Consultancy Limited — whether through our Website contact form, by email, by telephone, at a meeting or in the course of a contracted engagement — you may provide us with personal data. The categories of personal data you may provide include, but are not limited to, the following:
- Identity data: your full name, professional title and job role
- Contact data: your business email address, telephone number, business postal address and, where provided, your personal contact details
- Organisational data: the name of your employer or the organisation on whose behalf you are acting, and relevant details about that organisation's structure, sector and operations
- Brief and requirements data: information about your organisation's learning and development environment, training needs, existing technology infrastructure, performance gaps, digital capability requirements and the specific problems you are seeking our assistance to resolve
- Contractual data: data contained in proposals, statements of work, engagement letters, service agreements and related contractual documentation
- Communications data: the content of any emails, correspondence, meeting notes, messages or other communications between us
- Financial and billing data: information necessary to raise and issue invoices, receive payment and maintain compliant financial records, including billing address, purchase order references and, where applicable, bank account details for direct payment purposes
- Feedback and assessment data: responses to any post-delivery surveys, satisfaction assessments or review processes we conduct as part of our standard engagement process
We aim to collect only the personal data that is genuinely necessary for the purpose for which it is collected. If you choose not to provide certain personal data, we will explain whether and how this affects our ability to respond to your enquiry or deliver the services you require.
3.2 Data Collected Automatically Through Our Website
When you visit our Website at bovingdon-gray.fit, certain technical and usage data is collected automatically through our web server infrastructure and, where applicable, through cookies and similar tracking technologies. This automatically collected data may include the following categories:
- Network and device data: your Internet Protocol (IP) address, device type, device operating system and version, and browser type and version
- Usage data: the pages you visit on our Website, the order in which you visit them, the time spent on each page, the date and time of your visit, and the referring website or search engine from which you arrived at our Website
- Interaction data: how you interact with the Website, including which links you click, which forms you partially or fully complete, and how you scroll or navigate through page content
- Technical performance data: page load times, errors encountered during your visit, and other technical data that helps us identify and resolve problems with Website performance and functionality
- Exit data: the last page you viewed before leaving our Website
This automatically collected data is used primarily for legitimate Website operation, security monitoring, performance analysis and improvement purposes. Where this data is processed in connection with cookies or similar technologies, please refer to our Cookie Policy, which provides detailed information about the specific technologies in use and your options for managing them.
3.3 Data Received From Third Parties
In certain circumstances, we may receive personal data about you from third parties rather than directly from you. Examples include:
- Where a professional contact, colleague or existing client refers you to us and provides your contact details when doing so
- Where your employer or another organisation that has engaged us provides us with contact information and role information about individuals who will participate in or be affected by the services we are delivering
- Where publicly available professional information — for example, details published on a company website or professional networking platform — is used to support our client relationship activities
- Where background verification or professional credential checks are relevant to an engagement and lawfully conducted
When we receive personal data about you from a third party source, we will process it in accordance with this Privacy Policy. Where required by applicable law, we will inform you that we hold your personal data and provide you with a copy of this Privacy Policy within a reasonable time of receiving your data, and in any event no later than one month after receipt.
4. How We Use Your Personal Data and Why
4.1 Responding to Enquiries and Briefs
When you submit a brief, enquiry or other communication to us, we use the personal data you provide to review the requirements you have described, to assess whether we are well placed to assist you, to prepare an appropriate initial response and to follow up with you as necessary. The lawful basis for this processing is our legitimate interest in responding to genuine business enquiries and, where you have made an enquiry about services with a view to potentially engaging us, the pre-contractual steps we are required to take at your request.
4.2 Delivering Contracted Services
Where you or your organisation enters into a contract with us for the provision of EdTech solutions, corporate training, instructional design, digital product design, management consulting or custom development services, we process personal data that is necessary for the performance of that contract. This includes, as relevant to the particular service module engaged: the personal data of individuals who participate in training programmes; the contact details and role information of stakeholders involved in project governance; data provided as part of the discovery and diagnostic process; and financial data required for billing and payment. The lawful basis for processing that is strictly necessary for contract performance is Article 6(1)(b). Where processing serves other purposes in connection with the engagement, we identify and apply the appropriate lawful basis.
4.3 Managing Our Client Relationship
We maintain records of communications, proposals, deliverables, meeting notes, approval records and engagement outcomes for the purpose of managing our client relationships effectively and consistently over time. This includes records that allow us to maintain continuity of service where relationships span multiple engagements, to conduct post-delivery stability reviews, to respond to queries arising after delivery has concluded and to maintain the quality standards our operating model requires. The primary lawful basis for this category of processing is our legitimate interest in maintaining accurate, complete and consistent business records and in providing a service of measurable and sustained quality.
4.4 Legal, Regulatory and Compliance Obligations
We process and retain certain personal data to the extent required or permitted by our legal and regulatory obligations. This includes obligations arising under UK tax legislation administered by HM Revenue and Customs, accounting and financial record-keeping obligations, the Companies Act 2006, employment law where applicable, and data protection law itself — including our obligation to maintain records of processing activities under Article 30 of UK GDPR. Data processed under this purpose is retained for the period specified by the relevant legal obligation and is not used for any other purpose.
4.5 Marketing and Business Development Communications
From time to time, we may send you relevant information about our services, professional commentary, industry insight or updates that we believe may be of genuine interest to you in your professional capacity. Where you are an existing client contact, we rely on our legitimate interest in maintaining productive professional relationships as the lawful basis for such communications, provided that our assessment concludes that your interests do not override this basis. Where you are not an existing client contact, we will only send marketing communications where you have given your explicit prior consent to receiving them.
You have the right to opt out of receiving marketing communications at any time by contacting us at info@bovingdon-gray.fit with the subject line "Marketing Opt-Out" and providing your name and the email address to which communications have been sent. We will action opt-out requests promptly and in all cases within five working days of receipt. Opting out of marketing communications does not affect any other aspect of our relationship with you.
4.6 Website Operation, Security and Improvement
We use technical data collected automatically through our Website to operate and maintain the Website, to monitor for security threats and incidents, to diagnose and resolve technical problems, and to analyse and improve the user experience the Website provides. This processing is carried out on the basis of our legitimate interest in maintaining a functional, secure and efficient online presence that serves the reasonable expectations of visitors.
4.7 Protecting Our Legal Position
We may process personal data where necessary to establish, exercise or defend legal claims arising in connection with our business activities, including claims relating to the performance of our services, contractual disputes, intellectual property matters or regulatory investigations. The lawful basis for this category of processing is our legitimate interest in protecting our legal rights and those of third parties, or, where applicable, compliance with a legal obligation.
5. Special Category Personal Data
Special category personal data comprises data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data processed for identification purposes, data concerning health, data concerning a person's sex life, and data concerning a person's sexual orientation. Article 9 of UK GDPR imposes additional and more stringent conditions on the processing of such data.
Bovingdon-Gray Consultancy Limited does not seek to collect or process special category personal data in the ordinary course of its business activities. Our services are directed at organisations and their professional representatives, and the nature of those services does not ordinarily require the collection of personal data of a sensitive or special category nature.
In exceptional circumstances, special category data may be provided to us incidentally — for example, where health information is relevant to accessibility requirements for a training programme participant, or where data relating to a protected characteristic is included in a brief without being solicited. Where this occurs, we will: handle the data with the heightened level of care and protection required by Article 9; identify and document an applicable condition for processing under Article 9(2); and not process such data for any purpose beyond that for which it was provided without seeking explicit consent or establishing another applicable condition.
If you believe that special category personal data about you or another individual has been provided to us in error, please contact us immediately at info@bovingdon-gray.fit and we will review the data and take appropriate action, which may include deletion.
6. How Long We Retain Your Personal Data
We do not retain personal data for longer than is necessary for the purpose or purposes for which it was collected, taking into account the nature of the data, the purpose for which it was collected, any legal or regulatory retention requirements, and our legitimate operational needs. Our standard retention periods are as follows:
- Enquiry data where no engagement was contracted: Personal data submitted through the contact form or by any other means in connection with an enquiry that did not result in a contracted engagement will be retained for a period of twelve months from the date of the last communication relating to that enquiry. At the end of this period, the data will be securely and permanently deleted unless there is a specific and documented reason for extended retention.
- Pre-contractual data: Data generated during the assessment, proposal and negotiation stages preceding a contracted engagement, which is not incorporated into the contract itself, will be retained for twelve months following the conclusion of that pre-contractual process. Where a contract is formed, pre-contractual records that form part of the documented basis of the engagement will be retained in accordance with the client engagement data retention period.
- Client engagement data: Personal data processed in connection with a contracted engagement — including proposals, statements of work, communications, deliverables, approvals, meeting notes and post-delivery review records — will be retained for a period of seven years from the date on which the relevant engagement is formally concluded. This period reflects our obligations under UK tax law and company law and our operational need to maintain complete engagement records for the purposes of quality assurance, dispute resolution and post-delivery support.
- Financial and invoicing data: Records relating to invoicing, billing, payment and financial transactions are retained for a minimum period of seven years from the end of the financial year in which the transaction was recorded, as required by HM Revenue and Customs under the Taxes Management Act 1970 and related legislation.
- Website server log data: Automatically collected technical data relating to visits to our Website is retained for a period of ninety days, after which it is automatically overwritten or deleted. Where there is a specific security incident or legal reason requiring extended retention of server log data, it will be retained for the minimum period necessary to address the relevant matter.
- Marketing communications data: Where you have consented to receive marketing communications, your contact details will be retained on our marketing communications list until you withdraw your consent or until we determine that the data is no longer accurate, current or relevant. We review our marketing lists at least annually.
- Data subject rights records: Records of rights requests made under UK GDPR and our responses to them will be retained for three years from the date of the response, for the purpose of demonstrating compliance with our obligations.
At the expiry of the applicable retention period, personal data will be securely and permanently deleted, de-identified or anonymised in accordance with a process that renders it incapable of being attributed to an identified or identifiable natural person.
7. Who We Share Your Personal Data With
Bovingdon-Gray Consultancy Limited does not sell, rent, trade or otherwise disclose personal data to third parties for commercial gain. We do not share personal data with third parties for their own marketing purposes. We may share your personal data with the following categories of recipients, but only where there is a specific, documented and proportionate reason for doing so:
- Technology and infrastructure service providers: Third-party suppliers whose products or services we use in connection with the operation of our business, including cloud-based document management and storage services, email infrastructure providers, project management software providers, accounting and invoicing software providers and, where relevant to a specific engagement, learning management system providers. All such suppliers are engaged as data processors under written data processing agreements that require them to process personal data only on our documented instructions, to implement appropriate technical and organisational security measures, and to assist us in meeting our UK GDPR obligations.
- Specialist contractors engaged on client projects: Where a specific client engagement requires specialist technical expertise that is engaged on a contract basis, we may share relevant personal data with such contractors to the extent necessary for their work on that engagement. All such contractors are engaged under written agreements that include data protection obligations consistent with our own.
- Professional advisers: Solicitors, barristers, accountants, auditors and other regulated professional advisers who require access to personal data in the course of providing professional services to Bovingdon-Gray Consultancy Limited. Such advisers are subject to professional duties of confidentiality.
- Regulatory and governmental authorities: HM Revenue and Customs, Companies House, the Information Commissioner's Office and other regulatory or governmental bodies to which we have a legal obligation to report or disclose information. Disclosure in such circumstances is made only to the extent required by law.
- Successors in title: In the event that Bovingdon-Gray Consultancy Limited undergoes a merger, acquisition, restructuring, sale of business assets or other corporate transaction, personal data held by us may be transferred as part of that transaction. In such circumstances, we will take all reasonable steps to notify affected individuals prior to any transfer or change of data controller, and to ensure that the receiving entity provides equivalent protections under an appropriate privacy policy.
- Other parties with your consent: Where we have obtained your specific, informed consent to share your personal data with an identified third party for a stated purpose, we may make such disclosure in accordance with the terms of that consent.
8. International Transfers of Personal Data
Bovingdon-Gray Consultancy Limited is headquartered in Scotland and conducts its principal data processing activities within the United Kingdom. The majority of personal data we process is stored on UK-based infrastructure or infrastructure located within countries that benefit from UK adequacy regulations.
Where we engage third-party service providers whose data processing infrastructure is located outside the United Kingdom — including within the United States of America or other third countries not covered by a UK adequacy decision — we take steps to ensure that appropriate safeguards are in place as required by Chapter V of UK GDPR and the international transfer provisions of the Data Protection Act 2018. These safeguards may include:
- The use of UK International Data Transfer Agreements (IDTAs) as approved by the Secretary of State under section 119A of the Data Protection Act 2018
- The use of the UK Addendum to the EU Standard Contractual Clauses as approved by the Information Commissioner's Office
- Reliance on adequacy regulations made under section 17A of the Data Protection Act 2018 where the relevant country or territory has been assessed as providing an adequate level of protection for personal data
- Such other safeguards as may be recognised and permitted under UK GDPR and applicable guidance from the Information Commissioner's Office
If you would like specific information about the safeguards we have in place in relation to any particular international transfer, or if you wish to obtain a copy of the relevant transfer mechanism, please contact us at info@bovingdon-gray.fit.
9. Your Rights Under UK GDPR
Subject to applicable law, the conditions specified in UK GDPR and any applicable exemptions, you have the following rights in relation to your personal data. We explain each right and how to exercise it below.
9.1 Right of Access (Subject Access Request)
You have the right to request confirmation of whether we process personal data about you and, where we do, to receive a copy of that data together with supplementary information about our processing, including the purposes of processing, the categories of data held, the recipients or categories of recipients with whom data has been shared, the anticipated retention period, and information about your other rights. This is commonly referred to as a Subject Access Request (SAR). We will respond to a valid SAR within one calendar month of receipt. Where the request is complex or we receive a number of requests simultaneously, we may extend this period by a further two months, in which case we will notify you of the extension within the initial one-month period and explain the reason for the extension. There is no charge for making a SAR unless the request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to respond.
9.2 Right to Rectification
You have the right to request that we correct any personal data we hold about you that is inaccurate or incomplete. We will take reasonable steps to verify the accuracy of any correction you request before making it. Where we have shared the data with a third party and it requires correction, we will inform that third party of the correction.
9.3 Right to Erasure
You have the right to request that we delete personal data we hold about you in certain circumstances. These include where the data is no longer necessary for the purpose for which it was collected; where you withdraw consent on which processing was based and there is no other lawful basis; where you object to processing based on legitimate interests and we cannot demonstrate compelling grounds that override your interests; where the data has been unlawfully processed; or where erasure is required by a legal obligation. The right to erasure does not apply where we need to retain the data to comply with a legal obligation, or for the establishment, exercise or defence of legal claims.
9.4 Right to Restrict Processing
You have the right to request that we restrict our processing of your personal data in certain defined circumstances: where you contest the accuracy of the data, for a period that allows us to verify it; where processing is unlawful and you oppose erasure but request restriction instead; where we no longer need the data but you require it for the establishment, exercise or defence of legal claims; or where you have objected to processing based on legitimate interests, pending verification of whether our grounds override yours. During a period of restriction, we will continue to store the data but will not process it for any other purpose without your consent or as permitted by law.
9.5 Right to Data Portability
Where processing is based on your consent or on contract performance and is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format and to transmit that data to another controller. This right does not apply to processing that is necessary for the performance of a task carried out in the public interest.
9.6 Right to Object
You have the right to object, on grounds relating to your particular situation, to our processing of your personal data where that processing is based on our legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds for continuing that override your interests, rights and freedoms, or unless processing is necessary for the establishment, exercise or defence of legal claims. You have an unconditional right to object to processing for direct marketing purposes at any time.
9.7 Rights Relating to Automated Decision-Making and Profiling
You have the right not to be subject to a decision based solely on automated processing — including profiling — that produces legal or similarly significant effects. Bovingdon-Gray Consultancy Limited does not make decisions of this nature about individuals using solely automated means. All significant decisions in our engagement and delivery process involve human review and judgement.
10. How to Exercise Your Rights
To exercise any of the rights described in Section 9 of this Privacy Policy, please contact us in writing by email to info@bovingdon-gray.fit or by post to 3 Fitzroy Place, 1/1 Sauchiehall Street, Glasgow, G3 7RH. Your communication should clearly state which right you wish to exercise and, where relevant, provide sufficient information to allow us to identify the personal data to which your request relates. Where we are unable to identify your data from the information provided, we may ask you for additional information to help us locate it.
We take the security of rights requests seriously and will take reasonable steps to verify your identity before processing any request, in order to protect against unauthorised access to or erasure of personal data. Identity verification will typically involve checking your name and contact details against our records. In cases of higher risk, we may ask for a copy of a suitable identification document.
We will respond to all rights requests within one calendar month of receipt. We will not charge for processing a rights request unless it is manifestly unfounded or excessive. Where we consider a request to be unfounded or excessive, we will notify you and explain our reasoning before taking any further action, including any decision to charge a fee or decline the request.
11. Data Security Measures
Bovingdon-Gray Consultancy Limited maintains a programme of technical and organisational security measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Our security measures are proportionate to the nature, scope and context of our processing activities and to the risks presented to the rights and freedoms of individuals. Measures in place include, but are not limited to, the following:
- Use of password-protected access controls with strong password policies across all systems holding personal data
- Encryption of personal data at rest and in transit using industry-standard protocols
- Role-based access controls that restrict personal data access to members of staff and contractors who have a genuine operational need for it
- Regular review and audit of access permissions to ensure they remain appropriate
- Use of reputable, security-assessed third-party cloud infrastructure and service providers
- Regular backup procedures to protect against data loss, combined with tested restoration procedures
- A documented incident response procedure for data security incidents
- Staff awareness of their data protection responsibilities
Notwithstanding the above, no method of transmission over the internet or method of electronic storage can be guaranteed to be completely secure. We therefore cannot warrant the absolute security of any personal data transmitted to or stored by us. If you have reason to believe that your interaction with us has been compromised, please contact us immediately at info@bovingdon-gray.fit.
12. Data Breach Notification
A personal data breach is a security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data. We have in place a documented data breach response procedure that governs how we identify, escalate, assess, contain and report such incidents.
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the Information Commissioner's Office (ICO) without undue delay and in all cases within 72 hours of becoming aware of the breach, as required by Article 33 of UK GDPR. Where the breach is likely to result in a high risk to the rights and freedoms of the individuals whose data is affected, we will also notify those individuals directly without undue delay, as required by Article 34.
If you believe that a personal data breach has occurred and that your personal data has been compromised as a result, please contact us immediately at info@bovingdon-gray.fit so that we can investigate and take appropriate action.
13. Cookies and Similar Technologies
Our Website uses cookies and similar tracking technologies to support its operation, to analyse how visitors use the Website and, where applicable, to support third-party content such as maps. For comprehensive information about the types of cookies we use, the purposes for which we use them, the specific cookies that may be present on our Website and your options for managing your cookie preferences, please read our Cookie Policy, which is available at bovingdon-gray.fit/cookie-policy.html and which forms part of our overall data privacy framework.
14. Children's Personal Data
The services provided by Bovingdon-Gray Consultancy Limited are directed at organisations and their professional representatives. Our Website is not directed at children under the age of 18, and we do not knowingly collect personal data from children. If we become aware that we have inadvertently received personal data from a person under the age of 18, we will take immediate steps to delete that data from our records.
If you believe that a child under the age of 18 has provided personal data to us through our Website or in any other way, please contact us immediately at info@bovingdon-gray.fit with details of your concern and we will investigate and take appropriate action without delay.
15. Links to Third-Party Websites
Our Website may contain links to websites operated by third parties, including websites of professional associations, industry bodies, technology partners and other organisations. The existence of such a link does not constitute an endorsement of the linked website or its operator by Bovingdon-Gray Consultancy Limited. We have no control over the content, privacy practices or security standards of third-party websites and are not responsible for the personal data that those websites collect about you or for how they use it.
We encourage you to read the privacy policies of any third-party websites you visit, including websites to which links appear on our Website. This Privacy Policy applies exclusively to personal data processed by Bovingdon-Gray Consultancy Limited in connection with its own website and business activities.
16. Legitimate Interests Assessments
Where we rely on our legitimate interests as the lawful basis for processing your personal data, we conduct and document a three-part assessment to ensure that reliance on this basis is appropriate. This assessment considers: the purpose of the processing and whether it constitutes a legitimate interest; whether the processing is necessary for that purpose and whether a less intrusive alternative would achieve the same result; and whether the legitimate interest is overridden by the interests, rights and freedoms of the individuals whose data is being processed, having regard in particular to the nature of the data, the reasonable expectations of the individuals and the safeguards in place.
If you would like to see a copy of any legitimate interests assessment we have conducted in respect of processing that affects you, please contact us at info@bovingdon-gray.fit.
17. Changes to This Privacy Policy
We review and update this Privacy Policy at least annually and whenever there is a material change to our data processing activities, to the applicable legal framework or to best practice guidance from the Information Commissioner's Office. When we update this Privacy Policy, we will publish the updated version on this page and revise the "last updated" date at the top of the page.
Where changes to this Privacy Policy are material in nature — for example, where we introduce a new purpose of processing or a new category of recipient — we will take additional steps to bring the updated policy to your attention. This may include displaying a notice on our Website, sending an email notification to clients whose data we hold or including reference to the updated policy in our next substantive communication with you.
Your continued use of our Website or services following the publication of an updated Privacy Policy constitutes your acknowledgement of the updated terms. If you do not agree with any update to this Privacy Policy, you should contact us to discuss the implications and, where relevant, to exercise any applicable data protection rights.
18. Complaints
If you are dissatisfied with how we have handled your personal data, with our response to a rights request or with any other aspect of our data protection compliance, we encourage you to contact us in the first instance at info@bovingdon-gray.fit or by post at 3 Fitzroy Place, 1/1 Sauchiehall Street, Glasgow, G3 7RH. We take all data protection concerns seriously and will endeavour to resolve any complaint promptly and fairly.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), which is the supervisory authority for data protection matters in the United Kingdom. The ICO may be contacted using the following details:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk
Where you are located in an EEA member state and your complaint relates to processing that falls within the scope of EU GDPR, you may also have the right to lodge a complaint with the relevant data protection supervisory authority in your country of residence or habitual location.