serious privacy Ltd
serious privacy Ltd
  • Home
  • OUR SERVICES
  • THE BOARD GAME
  • OUR PRINCIPAL
  • OUR PODCAST
  • OUR MISSION
  • OUR BLOG
  • DATA USE NOTICE
  • CONTACT US
  • More
    • Home
    • OUR SERVICES
    • THE BOARD GAME
    • OUR PRINCIPAL
    • OUR PODCAST
    • OUR MISSION
    • OUR BLOG
    • DATA USE NOTICE
    • CONTACT US
Get in Touch

  • Home
  • OUR SERVICES
  • THE BOARD GAME
  • OUR PRINCIPAL
  • OUR PODCAST
  • OUR MISSION
  • OUR BLOG
  • DATA USE NOTICE
  • CONTACT US
Get in Touch

Data Protection Notice for Serious Privacy Ltd

Below we set out our approach to managing personal information.  We don’t have that much of note, but its worth writing down, so we can be held true to our words!


Who is Serious Privacy Ltd?

Serious Privacy Ltd was created by Ralph T O’Brien to assist companies in managing their information, by helping them to better serve the individuals who they hold information on. 


Serious Privacy also trades as REINBO Consulting Ltd, its former name!


We believe Data Protection is a fundamental human right, and is not simply about keeping secrets, but about allowing individuals the opportunity to self-determine how their data will be used (where possible) and to be transparent and ethical in all cases with its collection, use, storage, retention and transfer. We aim to do no harm when processing personal data.


Serious Privacy Ltd believes that making best use of business data and protecting people when using their personal data are complimentary, not mutually exclusive. 


Serious Privacy itself is a Limited Company registered in England and Wales as company number 10713147, with its registered address at Lytchett House, 13 Freeland Park, Wareham Road, Lytchett Matravers, Poole, England, BH16 6FA. It is legally distinct from the Serious Privacy Podcast and similarly named legal entities registered in the Netherlands and the US - although we share a common brand agreement.


It also maintains registration with the Information Commissioners Office (www.ICO.org.uk) Registration number ZA418664.   Thats' a legal requirement for most organisations that process personal data.


How can I get in touch?

If you want any further information about Serious Privacy Ltd's services, the way it manages information, or just want a good old fashioned chat, or you are not happy about anything, please use the Email and phone number on this site, or get in contact on social media.  Happy to help you!


Why do you process personal data?

We actively avoid holding personal data.  (Nasty stuff, always talking behind your back!)  Also, It’s just not our business model.  


We serve businesses not private individuals, and therefore we try not to deal with any personal data beyond Business to Business contact details unless we absolutely have to.  


We don’t advertise, carry out direct marketing or buy and sell data.  Its all word of mouth, recommendations and face to face contacts.


This is due to change with the release of the Board game, in that we are collecting email ddresses only to register interest. This will be used purely for news about the board game release, is hosted by G0Daddy, and you can remove on request, by contacting or unsubscribing to any email sent.


What about work for others?

Actually Serious Privacy delivers most of its work for other businesses where we are “white labelled” as that brand, and it is that business that sets all the rules in that case.


As an example, where we work for TrustArc (www.trustarc.com) or BSi (www.bsigroup.com), we use their systems and services and follow their privacy notices and policies.  They use things like google mail and drive, and we will access their systems and services to deliver and ensure that the data and systems remain separated.  This can mean on dedicated devices, or via software based separation.  


From time to time a direct customer might also ask us to use its own systems and technology rather than ours for security reasons, but again we will only do that upon client instruction after agreement.


Our staff may also use its technology and systems (normally limited dot email) when acting in other professional roles and capacities such as;


  • Vice chair/Management Committee of the UK Data Protection Forum,
  • Co-host Serious Privacy Podcast
  • Director of the Institute of Operational Privacy by Design
  • Serving on BSi and ISO standards Committee,


When it does so, any personal data processing will be covered by those respective organisation’s privacy notices.


On what basis do you process data?

Where we act as a processor, it's the controller that establishes legal basis.  This is most likely scenario.  

In law you are required to state what legal basis you process data upon (boring, but massively important to determine what rights an individual has).  Where we deal with individuals directly; we process under the following legal basis;


  • Necessary for Contract or pre-contract when delivering our awesome training services directly to individuals
  • Legitimate Interests when someone gives us a business card or makes and enquiry and asks us to get in touch (yes we would get permission to get in contact under PECR 2003 too!)
  • Legal Obligation or Contract, when processing staff data, such as reporting to the tax office or registering at ICO or Companies house.

The detail...

What purposes do you use data for?

Pre Contract


At Serious Privacy Ltd, we do hold business-to-business contact details. We understand the necessity of this data use notice; it’s essential for us to perform our job effectively. To enter into a contract with us, we encourage you to reach out via this website, contact one of our staff members, connect with us on social media, send us an email, or even give us a call. Some individuals have even been known to slip us a cheeky business card.


We will obviously use this data to:


- send you emails or make calls (but never for direct marketing mailings or targeted advertising - Yuck!),

- assist you with your inquiry,

- negotiate or enter into a contract with you.


As part of our personal data management practices, we may also add contact lists of the organization’s staff members we have interacted with, such as attendees at a training session or interviewees included in a report appendix.


Since you’ve approached us in these cases, we believe we have a legitimate interest in using those contact details to, um… contact you. However, this will only be to facilitate the service you have requested. If you no longer wish for us to do that, just let us know, and we’ll take care of it.


Delivery


During the delivery of our services on the client site, we may come into contact with additional personal data. We strive, wherever possible, to review data onsite and avoid taking it away or processing it ourselves. If the customer requests it (and after a robust discussion regarding their needs), we can agree on the best way to handle this, including implementing appropriate security measures during the process and deleting the data as soon as we are finished!


Post Contract


Once you have signed a contract with Serious Privacy Ltd, it is our policy to retain all relevant information in case there are future issues and you need us to explain why and how we made certain decisions. We believe it is reasonable to hold this information based on our contact, retaining it for up to 7 years after the contract concludes, in case of any legal challenges. After that period, we will dispose of the data.

Any of that horrific tracking stuff going on?

Good question, but NO! We are really against that icky tracking stuff.  Passively collecting your personal data without your knowledge is just not ethical and it's not something we want to be doing.  We do use GoDaddy as our website provider, and they have informed us that they won’t put cookies on your machine unless we ask them to (www.allaboutcookies.org). If they do, it wouldn’t be to chase you around the internet or serve you adverts for little blue pills, but simply to understand how many people are visiting which pages on the website.   As part of our data use notice, Serious Privacy would never look at this data that GoDaddy holds anyway - we’re too busy delivering!  

How can I get in touch?

If you need any further information about Serious Privacy Ltd, its services, or how it manages personal data, or if you simply want to have a good old-fashioned chat, please feel free to use the email and phone number provided on this site. We are always happy to help you with your inquiries, including questions about our data use notice.


You have the right to complain at any time. Just drop a line to hello@seriousprivacy.co.uk and we'll see how we can help you!

How long do you keep data?

As little time as we can get away with! If we can store as little personal data as possible for the shortest duration, it lowers our (and your) risks. This approach aligns with our data use notice and commitment to effective personal data management at Serious Privacy Ltd. Generally speaking, we keep: Contracts, financial records, and contract deliverables for up to 7 years after contract completion; project notes for up to 7 years after project completion in case of challenge; business contacts on email, where we have set up for our emails to be deleted after 4 years. In cases where we have ongoing relationships that may outlast these retention periods, we may hold on to data to manage that relationship as necessary. Additionally, we hold data on other parties' systems according to their own retention rules when conducting work for others.

What rights do I have?

In law, you have several rights regarding your personal data management. However, since we only retain business-to-business contact details and occasionally a list of interviewees or attendees, it would be quite unusual for you to be asserting them. 


Nevertheless, if you truly wish to exercise your rights, simply send us an email, and we will provide you with your rights as outlined in our data use notice:


- **Opt-out of further contact**: If you've fallen out of love with us, that's perfectly fine. We'll shed a tear, indulge in a tub of ice cream, and hit the delete button.  

- **Access to a copy of the data**: We don’t hold much, but you are welcome to request a copy.  

- **Complaint**: We strive to ensure that this scenario never arises, but if you're dissatisfied, let us know, and we’ll do our utmost to assist. If we’ve let you down, you can also contact the UK regulator, the Information Commissioner’s Office (www.ico.org.uk), to lodge a complaint, which would certainly break our hearts.  

- **Accuracy**: If we've made an error (like misspelling a name or job title), please inform us, and we'll correct it. However, we won't alter historical data that was accurate at the time, such as updating point-in-time reports.  

- **Restriction**: If we find ourselves in a dispute regarding your data, you can request that we temporarily refrain from using it while we resolve our differences.  


We believe you probably don’t have the right to:


- **Automated decision-making rights**: We don’t use computer algorithms to make decisions about individuals.  

- **Portability**: Since we operate on a business-to-business basis, it's unlikely that you would want us to transfer your data to another provider.  

- **Erasure**: This right only applies when processing data based on consent (which we do not utilize) or if we’ve mishandled data collection outside of what we’ve stated here.  

- **Objection**: We don’t think we process data for any other reasons where the right of objection applies, such as direct marketing.

What Cookies are on the Website?

None that we are aware of! If our provider starts to use Cookies, we’ll update our data use notice to inform you. At Serious Privacy Ltd, our Marketing Consulting services assist small businesses in developing a marketing plan that fosters growth and enhances revenue. We collaborate with you to identify your target audience, create effective marketing strategies, and measure your success while ensuring proper personal data management.

Security and Data Transfer

Who might you give data to?

To be cost effective, work efficiently, and ensure we can recover in the event of a disaster, we utilize other companies for our data management. While we could establish our own email server or website, these providers, such as Serious Privacy Ltd, have far greater resources dedicated to security and efficiency than we would. Therefore, we believe it's more prudent to store our information with these companies rather than attempting to manage it ourselves. We prefer these providers over local storage options for our personal data management. Although we must rely on them, we trust they will do their best, and we will hold them accountable if any issues arise.


These companies include:


- Microsoft: Our primary "cloud-based" email provider, offering an app and web portal for accessing electronic mail from various devices. We also utilize Microsoft software such as Word, Excel, and PowerPoint. www.microsoft.com

- Apple: This company provides our hardware (laptops and phones), software (operating systems), and cloud storage for documents, including reports, notes, and research. www.apple.com

- GoDaddy: They host our website, but we do not store any personal data here. Our website mainly serves to hold the domain name and provide basic information about our services and biographies. www.godaddy.com

- UK Postbox: This service scans our mail; if you send us a letter, they likely scan it into their system. They provide an app and portal that allows us to read our mail from anywhere, enabling us to respond more quickly to you. www.ukpostbox.com

- LinkedIn and Bluesky: While not strictly a REINBO Consulting relationship, members of our Principal's professional network often use these social networks to make business inquiries. We may transfer contact details to integrate into our systems as outlined above. www.linkedin.com and www.bsky.app


We don’t utilize any advanced customer relationship management platforms or direct marketing tools; we strive to keep things simple, minimizing the potential for errors. Additionally, we adhere to our data use notice to ensure transparency in our data handling practices.

Where might the data end up?

We’d love to say that all the data stays in Europe, where privacy laws are strong. Serious Privacy Ltd has made efforts to select providers that offer options for EU personal data storage only. 


However, our customer base is often global, and sometimes travel is required to Asia, Africa, or North America. 


In cases where we believe a country poses a high risk, we will take 'clean' devices with no personal data on them to these locations. This minimizes the chance of any serious issues arising, and if a malicious actor does gain access to the device, it won’t jeopardize any other data. In countries considered to be of lower risk, the devices may be taken, and access to data may be processed locally over the internet, while still ensuring that the data remains stored with the EU-based cloud technology providers mentioned above. 


Of course, the data we handle is limited to minimal B2B contacts only. Even though we believe this makes us an unlikely target for rogue security services, we still want to prioritize safety and adhere to our data use notice regarding personal data management.

How do you keep data secure?

We can’t. 


Wait, no, please don’t leave yet! We just know that there’s no such thing as 100% secure. 


There’s always a risk, and we would be pretty silly to guarantee that accidents can’t or won’t happen. However, we can promise to do our best to protect the information entrusted to us, as outlined in our data use notice. As stated, we tend to rely on our external providers for security, but we will ensure that when we have off-the-shelf options they provide, such as encryption and 2-factor authentication, we will use what we can to provide reasonable guarantees of safety. 


Some common sense security arrangements include: 


Mobile phones - locked with a code, individual app access set to require login every time, or 2-factor authentication, remote wipe solutions, and device encryption where available. 

Laptop - full hard disk encryption, access controls, customer data separation, and minimized local storage. 

Communications - email is not used to send or store personal data outside of business-to-business contact details, and we will provide industry-standard encryption for documents where this is unavoidable. 

Cloud Storage - utilize the chosen providers where possible to ensure data is recoverable in the event of a lost device. Ensure access controls are the highest the provider allows (such as multi-factor authentication, for example). 

Staff - only to have on staff long-standing experienced data privacy and security personnel from Serious Privacy Ltd, who are quite frankly paranoid about this kind of thing and will be under strict duties of confidentiality. 

Physical - as a rule, we try not to print out data or have hard copies filed, as it stops us from being able to work in a mobile manner. Where we do have hard copy data (such as unstructured meeting notes in daybooks), these are destroyed and shredded when no longer required. In most cases, this is limited to business cards given to us!

What if things change?

Laws change, technology changes, and the way we operate may occasionally change too. We like to think of this document as a 'live' data use notice regarding our approach to personal data management. We may make small adjustments from time to time while retaining older versions to ensure we know what was in place previously. When we implement large or significant changes, we at Serious Privacy Ltd will do our best to proactively inform you. This version is dated 19 June 2026.

Copyright © 2026 Serious Privacy Ltd - All Rights Reserved.

Powered by

  • Home
  • OUR SERVICES
  • THE BOARD GAME
  • OUR PODCAST
  • OUR MISSION
  • OUR BLOG
  • DATA USE NOTICE
  • CONTACT US