Privacy notice
How we handle your data
Last updated: PLACEHOLDER: set the date this notice goes live
This notice explains how Primetime Consulting collects, uses, shares and protects personal data when you visit this website, submit an enquiry, or become a client. It applies wherever you are in the world and is written to meet the requirements of the UK GDPR, the EU GDPR, and comparable data protection laws in other jurisdictions in which we operate.
1. Who we are
Primetime Consulting ("we", "us", "our") is a technology and security consulting firm. For the purposes of applicable data protection law, we are the data controller for the personal data described in this notice. Our contact details are:
- Registered name: Primetime Consulting (PLACEHOLDER: full registered legal name)
- Registered office: PLACEHOLDER (see our legal page for company details)
- Email: enquiries@primetimeconsulting.com
- Phone: +44 (0)00 0000 0000
Where we act as a data processor on behalf of a client — for example, when we have access to a client's systems in order to deliver a penetration test, configuration review, or IT support engagement — the terms of that specific engagement, not this notice, govern our handling of the personal data involved. This notice covers only data we process about you as a visitor, prospect, or contact at a client or supplier organisation.
2. What we collect and why
Website and enquiry data
When you use the contact form on this website, we collect:
- Your name and email address
- Company name and phone number, where you provide them
- The content of your message and any service you select
- Technical data such as your IP address, browser type, and submission timing, used to protect the form from spam and abuse
We use this data to:
- Respond to your enquiry and correspond with you about it
- Assess whether an engagement is a good fit for both parties
- Maintain records of business correspondence
- Detect and prevent spam, fraud, and abuse of our systems
Client and contact data
If an engagement proceeds, we collect and process additional personal data as needed to deliver, administer, invoice, and support that engagement — for example, the names and contact details of your staff we work with, and information contained in systems or documents you share with us for the purposes of an assessment. The scope of this is agreed with you at the outset of each engagement.
Recruitment data
If you apply for a role with us, we process the information in your application (CV, cover letter, references, and interview notes) to assess your candidacy, and retain it in line with our recruitment retention period below.
3. Legal basis for processing
Depending on the activity, we rely on one or more of the following legal bases:
- Legitimate interests — to respond to enquiries, maintain business records, keep our website and systems secure, and market our services to other businesses, in each case balanced against your rights and interests
- Contract — to perform, administer, and invoice an engagement you have entered into with us, or to take steps at your request before entering one
- Consent — where we ask for it explicitly, for example for optional marketing communications; you may withdraw consent at any time
- Legal obligation — to meet accounting, tax, and other regulatory requirements
4. How long we keep it
- Enquiries that do not lead to an engagement — retained for 12 months from your last contact with us, then deleted or anonymised
- Client and engagement records — retained for the duration of the engagement plus 7 years afterwards, to meet our accounting, tax, and professional liability obligations
- Recruitment records — retained for 12 months after the relevant role is filled or withdrawn, unless you ask us to keep your details on file for longer
We may retain data for longer where required by law, or where needed to establish, exercise, or defend legal claims.
5. Who we share it with
We do not sell personal data. We share it only with the following categories of recipient, each bound by contractual confidentiality and data protection obligations:
- Service providers we use to run this website and our business — including our email delivery provider (Resend), our hosting provider (Vercel), and any accounting, legal, or IT support providers we engage
- Subcontractors engaged for a specific client engagement, disclosed to you in advance where applicable
- Professional advisers such as our accountants, auditors, and legal counsel
- Regulators and law enforcement, where we are legally required to disclose information
- A buyer, in the event of a sale, merger, or restructuring of our business, subject to the same protections described in this notice
6. International transfers
As a firm that works with clients and uses service providers across multiple jurisdictions, personal data we hold may be transferred to and processed in countries outside your own, including outside the UK or European Economic Area. Where this happens, we put in place appropriate safeguards required by applicable law — such as the UK and EU Standard Contractual Clauses, or reliance on an adequacy decision — before making the transfer.
7. Security
As a security consultancy, we hold ourselves to a high standard for protecting the data entrusted to us: access controls, encryption in transit and at rest where applicable, least-privilege access to client systems and data, and regular review of our own internal security posture. No method of transmission or storage is completely secure, and we cannot guarantee absolute security, but we work continuously to reduce risk.
8. Your rights
Subject to applicable law, you have the right to:
- Request access to the personal data we hold about you
- Request correction of inaccurate or incomplete data
- Request deletion of your data, in certain circumstances
- Request that we restrict or object to certain processing
- Request a portable copy of data you provided to us
- Withdraw consent at any time, where processing is based on consent
- Lodge a complaint with your local data protection authority (in the UK, the Information Commissioner's Office)
To exercise any of these rights, contact us at enquiries@primetimeconsulting.com. We will respond within the timeframe required by applicable law (one month under the UK/EU GDPR, extendable in complex cases).
9. Cookies and analytics
This website uses only the cookies or local storage strictly necessary for it to function (for example, remembering that you have submitted the contact form). PLACEHOLDER: if a privacy-friendly analytics tool is added, describe it here, confirm whether it sets cookies, and explain how visitors can opt out.
10. Children's privacy
This website and our services are directed at businesses and professionals. We do not knowingly collect personal data from individuals under the age of 16.
11. Changes to this notice
We may update this notice from time to time to reflect changes in our practices or in applicable law. The "last updated" date at the top of this page shows when it was last revised. Material changes will be reflected here before they take effect.
12. Contact us
Questions, requests, or complaints about this notice or how we handle your data can be sent to enquiries@primetimeconsulting.com.
This notice is a template appropriate for a business-to-business consulting firm and has been drafted to be substantively complete. As with any legal document, we recommend a final review by qualified counsel in your jurisdiction before publication, particularly to confirm the retention periods and any sector-specific obligations that apply to your work.
