Privacy Policy
Thank you for trusting me with some information about you. I take that trust seriously and I want you to know how I use your information and why.
​
1. WHO IS HOLDING YOUR INFORMATION?
Name: Kayleigh Hunter-Law
Email address: kayleigh@kayleighsgotit.com
Data Retention Period: 12 months
Our data regulator contact details are: https://ico.org.uk/
Date this Policy last updated: 28th July 2023
​
​
2. WHOSE INFORMATION DO I COLLECT?
We process information about:
"Prospects" - potential Clients, or contacts working at or connected with potential Clients
"Clients" - who have bought services
"Client Contacts" - individuals employed by or contracted to Clients;
​
3. MY POLICY
I promise respectful treatment of the personal information of everyone I have contact with.  I want it to be simple and clear.
This Policy explains how I do that – when and why I collect information, how I use it, the situations when other people can see or use it, and how I keep it secure.
But just to set the scene in case you don’t want to read through all the details just now, I can be clear up front.
I don’t sell, rent or trade email lists with anyone else.
​
I’ve split this Policy into sections, depending on who you are.
Section A is for everyone and includes information about cookies on our websites.
Section B is for you if you are or work for a business prospect.
Section C is for you if you are a Client or a Client Contact.
Section D is for you if I have information about you purely because I am providing services to a Client.
SECTION A: FOR EVERYONE
Whoever you are, my intention is to use your information to make things work smoothly for you in your experience of dealing with me. If that’s not how it turns out for you, please make sure to contact me. It’s best to put things in writing, which you can do by emailing the address above.
I keep this Policy under regular review, and I may revise it as time goes on. Please check back here from time to time to make sure you’ve got the latest information.
A.1. MY GENERAL APPROACH TO PERSONAL DATA
I'm committed to protecting your privacy and honouring your legal rights to control how I use your personal data.
I only collect and use personal data when I need to;
-
because you have asked me to do something (for example, send you newsletters);
-
so that I can reply to queries or complaints;
-
to develop and manage my business relationships;
-
to help grow my business and fulfil my contracts;
-
to provide services to clients;
-
to meet my legal obligations.
I try to make sure the information we hold is accurate and up to date and is no more than I need to have.
A.2. CATEGORIES OF DATA
The types of information that I will be processing depend on the nature of my relationship with you.
I may process information about you that you have yourself provided to me or published generally on the internet through social media or on other websites.
In all cases, I will have what identifying and communication information that is relevant and that I can sensibly obtain: that is, your name, email address, employer or business name, job title or position, contact address, social media addresses, and I may also capture some of the information published by you in your social media output to the extent that it may be relevant to our interactions.
If you are or work for a prospect, I will aim to obtain and process information that is relevant to our building a business relationship with you and doing business together, which may relate to your business and your personal interests.
If you are or work for a customer or supplier, I will also keep records of our interactions, the work I have done for you or commissioned from you, the progress of work, and financial and accounting records.
If I am processing information about you purely because I am providing services to others, please see Section D below.  Please note that your rights may be subject to applicable exemptions.
If you have any questions or concerns about my use of your information, or how I have responded to any request about your personal data, please take it up in the first instance by emailing me at the above address.
If I can’t sort it out, the official authority contact details are set out in the form above, and you can raise your concerns with them.
A.3. DOWNLOADS, NEWSLETTERS AND SERVICES
I monitor who opens what in my newsletter lists, and pre-set sequences of information I send you. I do this, so I can see if content is popular and generate more of it, or if it is not read.
There may be sub-routines that trigger if you click on links or articles. These are designed to offer you more information about things you are interested in.
You can unsubscribe from these sequences at any time.
Existing Clients may receive emails about specific offers relating to things you have already purchased. You can unsubscribe from these at any time.
I use automations (little sequences of emails that start when you ask for something in particular) to send you the information you asked for, to send you products you have bought and to administer services you have subscribed to. 
I monitor who reads my mailing and automations, how many times, and which links you choose to use and read. I use this information to increase the content’s level of interest and help me improve what we send.  You can remove your information from this monitoring by disabling cookies on your website browser before opening emails from me. From time to time, I contact individual email newsletter subscribers, but it is extremely rare.
I use anonymised data about you from time to time to target advertising campaigns based on profiling the sort of person who wants to receive information from me.
​
A.4. SOCIAL MEDIA
I have an active presence on social media. If you are using social media they are holding and using your information in accordance with their data privacy policy.
If you ‘like’ any of my posts or ‘follow’ me or contact me on social media I keep a record of that. Your replies to me, messages you send, and your other activity linked to my posts may be seen. 
A.5. NO SALE OR EXCHANGE OF YOUR DATA
I do not sell or exchange your personal data with organisations who may want to sell you something or use your data for research or other purposes.
​
A.6. DATA LOCATION AND PLATFORMS
Like most small businesses, I do not have any tailor-made software – I use mainstream packages for everything from our Client records, to email, to accounting.
This means that some of your data may be held in the EEA, and some may be held in services in the USA or elsewhere. I have picked mainstream suppliers with appropriate security standards.
A.9. HOW LONG DO I KEEP YOUR DATA FOR?
Your information will be kept for the length of time set out in my retention period (see Section 1, above).
If you subscribed to a newsletter or updates list, you will remain on the list(s) you joined until you unsubscribe from that list.
​
A.10. WANT TO SEE WHAT I HOLD ON YOU?
If you want to know what information I have about you (if any) email the address above and give us your name and email address(es). I may require you to confirm your identity before proceeding.
Provided I can legitimately disclose the information to you (see Section D), I will happily do a search and send you what I have.
​
A.11. WHAT ARE YOUR RIGHTS?
You have the right to know what information I am collecting on you, and to amend it if it is inaccurate.
If you feel for some reason I have information I should not be keeping, or it is out of date or otherwise wrong, please let me know and I will take appropriate action.
Most of the information I hold is not based on your individual consent but is based on needing the information to run my business and provide my services.
You have a "right to be forgotten" - but that does have some legal limits to it. If you want me to remove information about you, let me know. If you have been a Client, I may not be able to remove all data as I will have to ensure that I can continue to comply with legal, accounting, taxation and my insurer’s requirements.
​
A.12. MY LEGAL BASIS FOR PROCESSING YOUR DATA
Signing onto my newsletter list is by your consent – and when you withdraw your consent I stop that processing of your data.
Apart from that, the information I hold is based on needing the information to run my business and provide my services – either so I can perform my contract with you, or because I have a legitimate business interest in processing your data.
In a few situations I am processing personal data because I am under a legal obligation to do so.  This principally relates to my business, accounting and tax records.
SECTION B: PROSPECTS
Most of the information I process comes from you. I process it so I can reply to you, and when you contact me again I know what you asked before, what you were sent, and what you told me.
Typically, I am collecting name, contact details, how I came across you, and background information from you or published by you on social media or freely accessible on the internet, on why you might be interested in my services.
If you sign up to a newsletter list, you will be sent what you asked for. You can unsubscribe at any time by clicking the unsubscribe button on any email.
You are not automatically subscribed to any other lists but may be invited to join an appropriate one.
If I email you individually using my own email system or respond to an email sent to me at my business email address, a copy of that email will also be stored.
If you make an enquiry via my website, I will keep details of that enquiry and response for our data retention period (Section 1, above).
I do not routinely keep special category data. To the extent I hold this, it was supplied or made publicly available by you.
SECTION C: CLIENTS
Once you buy something from me, I will collect information from you.
This will include the information I collect from Prospects (above). I collect your email address, phone number and postal address so I can provide what I have contracted to, invoice you and keep proper records of our business relationship.
I process your data to support the delivery of the services you have bought. I keep records of the services provided to you, and information you give me, so I can support you when needed and advise you of any additional services you may need.
​
C.1. THIRD PARTY DATA
As well as your own personal data, I understand that you may need to provide me with personal data relating to your employees, your workers, or third parties (often your clients or suppliers) – depending on the services I am providing to you.  I hold all such information under strict confidentiality obligations, as set out in my terms of business.
C.2. FINANCIAL AND CREDIT CARD DETAILS
Credit card payments are handled by an external secure processor in accordance with their data security policies (see Section 1, above).
I receive limited information from my processor for me to tie up your payment with your invoice.
If you pay me by BACS or direct transfer, I know only what the bank tells me, which is usually the name of the person who paid me, how much, and the reference number.
I do not routinely keep credit scores nor use credit reference agencies.
SECTION D: THIRD PARTY INFORMATION
I will act in accordance with your statutory rights, subject to the exclusions and exemptions that may apply.
When I am processing data about you on behalf of a Client, I am operating under the banner of our Client’s data privacy policy. I will refer any enquiry from you to them, as they are the ‘data controller’ responsible for dealing with your query. But I will support that by providing relevant information to my Client for passing to you.
When I am processing data about you because of a direct connection between you and my business we are acting as a ‘data controller’ (and operating under this policy).
4.COMPLAINTS
If you have a complaint about the way I am handling your information or how I have responded to a request for information or removal, you can take this up in the first instance by emailing me at the email address set out above.
If I can’t sort it out, the relevant supervisory authority details can be found in Section 1, above.