top of page

Privacy policy

Last updated: 29th May 2026
 

Adams People & Culture Consulting (“we”, “us”, “our”) is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, store and protect personal data when providing HR consultancy services or when you interact with our website.
 

1. Who we are
 

Adams People & Culture Consulting [Add business address] [Add email address for data protection queries]

We are the data controller for the personal data we process in connection with our consultancy services.


2. What personal data we collect
 

We may collect and process the following types of personal data:

  • Contact information — name, job title, email address, telephone number.

  • Employment‑related information — case details, investigation notes, HR records, appraisal information.

  • Special category data — health information, safeguarding concerns, trade union membership, or other sensitive data relevant to HR or ER matters.

  • Website and technical data — IP address, browser type, cookies and analytics.

  • Information you provide directly — through enquiries, meetings, email correspondence or document sharing.


3. How we collect personal data
 

We collect data in the following ways:

  • Directly from you when you contact us or engage our services

  • From your organisation when we are acting as a consultant

  • Through documentation shared for casework, investigations or audits

  • Through our website (forms, cookies, analytics)

  • From third parties where appropriate (e.g., legal advisors, safeguarding authorities)


4. Why we use personal data
 

We process personal data for the following purposes:

  • To deliver HR consultancy services

  • To manage contracts and client relationships

  • To conduct investigations, casework and safeguarding duties

  • To meet legal and regulatory obligations

  • To maintain business records and financial administration

  • To respond to enquiries

  • To improve our website and services
     

5. Lawful bases for processing
 

We rely on the following lawful bases under UK GDPR:

  • Contract — where processing is necessary to deliver our services.

  • Legitimate interests — for running and developing our business, ensuring service quality and managing risk.

  • Legal obligation — particularly in relation to safeguarding, employment law and record‑keeping.

  • Consent — for optional communications or where required for specific types of data.

  • Vital interests — where safeguarding concerns require urgent action.


For special category data, we rely on:
 

  • Employment law obligations

  • Substantial public interest (e.g., safeguarding)

  • Explicit consent (where appropriate)


6. How we store and protect personal data
 

We take appropriate technical and organisational measures to protect personal data, including:

  • Encrypted systems and secure cloud storage

  • Access controls and password protection

  • Restricted access to sensitive information

  • Secure transfer of documents

  • Regular review of data security practices


7. Who we share personal data with
 

We may share data with:

  • Your organisation’s leadership or HR team (where appropriate)

  • Legal advisors or professional experts

  • Safeguarding authorities or regulators (where required)

  • IT and system providers who support our business operations

  • Other third parties where legally required


We do not sell personal data.


8. International transfers

If any data is stored or processed outside the UK, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or equivalent protections.


9. How long we keep personal data
 

We retain personal data only for as long as necessary for the purposes for which it was collected. Typical retention periods include:

  • Enquiries: 12 months

  • Casework and investigations: 6–7 years

  • Safeguarding records: in line with statutory guidance

  • Contractual and financial records: 6 years

Retention periods may vary depending on legal requirements.


10. Your rights
 

Under UK GDPR, you have the right to:

  • Access your data

  • Request correction

  • Request deletion

  • Restrict processing

  • Object to processing

  • Request data portability

  • Withdraw consent where consent is the lawful basis


To exercise your rights, please contact us using the details above.


11. Cookies and website analytics
 

Our website uses cookies to improve functionality and understand how visitors use the site. You can manage or disable cookies through your browser settings.


12. How to complain
 

If you have concerns about how we handle your data, please contact us in the first instance. You also have the right to complain to the Information Commissioner’s Office (ICO): www.ico.org.uk


13. Updates to this policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date.

bottom of page