Laura Todd Advisory Ltd

About this policy

Laura Todd Advisory Ltd is a founder-led UK management consultancy. This policy explains how I use personal information through the website and in connection with enquiries, professional contacts, suppliers and consultancy engagements. I collect only what I need to run the business and deliver agreed services. I do not sell or rent personal information.

It is provided under UK data protection and electronic privacy law. Visiting the website does not create consent; where consent is required, I will ask for it separately.

Who is responsible for your information

Laura Todd Advisory Ltd is the data controller. References to ‘I’, ‘me’ and ‘my’ mean the company acting through its founder, Laura Todd.

Legal entity: Laura Todd Advisory Ltd
Company number: 17301349
ICO registration: Registered with the Information Commissioner’s Office
Privacy contact: laura@ltadvisory.co.uk

Personal information I may collect

Depending on how you interact with Laura Todd Advisory, I may collect:

  • Contact and professional information: name, job title, organisation, business contact details and professional profile information.
  • Enquiry and service information: contact form entries, correspondence, meeting notes, proposals, contracts, project communications, feedback and deliverables.
  • Financial and administration information: billing details, purchase orders, invoices, payment status and accounting or tax records. I do not collect payment card details through the website.
  • Website and technical information: IP address, browser or device details, server logs, cookie data and information generated by the contact form’s anti-spam service.
  • Marketing preferences: your preferences and any record of consent or objection.

The services are intended for organisations and business professionals. I do not knowingly collect children’s personal information through the website.

Sensitive information

Please do not include sensitive or criminal offence information in the website contact form unless it is necessary for your enquiry.

Some responsible business, inclusion, culture or responsible AI projects may involve sensitive information provided by a client. Where this occurs, I will clarify responsibilities in the contract, minimise the information used and apply the additional legal and security safeguards required.

How I collect personal information

I may collect information:

  • directly from you through the contact form, email, calls, meetings, events or contracts;
  • from your employer, colleagues, advisers, clients or mutual contacts;
  • from public professional sources, such as company websites, LinkedIn, directories or Companies House; and
  • through service providers and necessary website or security technology.
How and why I use personal information

The main lawful bases I use are contract, steps taken before a contract, legal obligation, legitimate interests and, where appropriate, consent. I use personal information:

  • To respond to enquiries and prepare proposals. This is based on steps before a contract and legitimate interests in developing the business.
  • To agree and deliver consultancy services. This is based on contract and legitimate interests where the contract is with an organisation rather than the individual contact.
  • To administer the business. This includes invoicing, accounting, tax, insurance and appropriate records, based on contract, legal obligation and legitimate interests.
  • To maintain relevant professional relationships. This is normally based on legitimate interests, with consent used where electronic marketing rules require it.
  • To protect systems and legal rights. This includes security, preventing misuse, handling disputes and meeting regulatory requirements, based on legal obligation and legitimate interests.
If you do not provide information

You can browse the public website without providing personal information. If information is needed to respond to an enquiry, enter into a contract, deliver services or meet a legal requirement, I may be unable to proceed without it.

Client project data and data protection roles

During client work I may process information about a client’s employees, candidates, customers, suppliers or other stakeholders. Where I act only on the client’s documented instructions, the client is the controller and Laura Todd Advisory is its processor. The contract will address responsibilities, security and deletion. For my own engagement administration, professional records or legal claims, Laura Todd Advisory acts as a controller and this policy applies. Client project data is not used for unrelated marketing.

Business communications and marketing

I may send relevant one-to-one communications to professional contacts where this is lawful and reasonably expected. I will obtain consent where required. You can stop direct marketing at any time by replying or emailing laura@ltadvisory.co.uk. I may keep a minimal suppression record to respect your preference.

Cookies and website technology

Necessary website technology

The website uses technology needed to operate securely and deliver the contact form. The host may create basic server logs for security and troubleshooting. These uses are based on legitimate interests.

Google reCAPTCHA

The contact form uses Google reCAPTCHA to prevent spam. Google may receive technical and interaction information, including an IP address and browser or device characteristics, and may set the necessary _GRECAPTCHA cookie. It is used for security, not advertising. See the Google Privacy Policy.

Analytics and advertising cookies

The website currently uses no separate analytics service and no advertising or behavioural profiling cookies. If non-essential cookies are introduced, this policy will be updated and consent requested where required. Browser settings can be used to control or delete cookies; blocking security technology may prevent the contact form from working.

Who I may share personal information with

I share personal information only where necessary, including with:

  • Associates and subcontractors: specialists supporting an agreed engagement, subject to confidentiality and data protection obligations.
  • Technology and administration providers: such as website, email, cloud storage, meetings, accounting, backup and IT support providers.
  • Professional advisers and insurers: where needed for advice, compliance or claims.
  • Clients and relevant stakeholders: where necessary to deliver agreed services or outputs.
  • Authorities and legal recipients: where disclosure is required by law or needed to protect rights or security.

Service providers acting as processors must use information only for the agreed service and protect it appropriately.

International transfers

Some service providers, including Google in connection with reCAPTCHA, may store or access information outside the UK. Where I am responsible for the transfer, I will use a safeguard permitted by UK law, such as an adequacy regulation or approved contractual terms. Contact me for more information about relevant safeguards.

How I protect personal information

I use proportionate measures for a small consultancy, including access controls, secure accounts, reputable cloud services, backups, confidentiality and secure disposal. I will investigate any personal data breach and make legally required notifications.

How long I keep personal information

I keep information only for as long as it is reasonably needed. My normal guide periods are:

  • Enquiries and proposals that do not proceed: up to 24 months after the last meaningful contact.
  • Client engagement and contract records: normally six years after the engagement ends.
  • Invoices, accounts and tax records: normally six years after the relevant financial year, or longer if required by law.
  • Marketing records: until you object, withdraw consent or the information is no longer relevant; a minimal suppression record may be retained.
  • Website security records: normally no longer than 12 months, unless an incident requires longer.
  • Client project data processed on instructions: as stated in the client contract, then returned or securely deleted unless retention is legally required.

Information no longer required is deleted, anonymised or securely destroyed. I do not use solely automated decision-making with legal or similarly significant effects.

Your data protection rights

Depending on the circumstances and the lawful basis used, you may have the right to:

  • ask for access to your personal information or for inaccurate information to be corrected;
  • ask for information to be erased or its use restricted in certain circumstances;
  • receive certain information in a portable format where applicable;
  • object to processing based on legitimate interests, and at any time to direct marketing;
  • withdraw consent at any time where processing relies on consent, without affecting earlier lawful use; and
  • complain to the Information Commissioner’s Office.

These rights are not all absolute. To exercise one, email laura@ltadvisory.co.uk. I may ask for information to confirm your identity and will normally respond within one month. There is usually no fee.

Questions and complaints

Please contact laura@ltadvisory.co.uk first if you have a question or concern.
You also have the right to complain to the Information Commissioner’s Office (ICO). See ico.org.uk/make-a-complaint or call 0303 123 1113.

Changes to this policy

I may update this policy when the business, website, service providers or law changes. The current version and its last updated date will be published on ltadvisory.co.uk.

Contact Laura Todd Advisory

Laura Todd Advisory Ltd | Company number 17301349
Email: laura@ltadvisory.co.uk | Website: ltadvisory.co.uk