Privacy Policy of Northbridge Regional Solutions Ltd
Effective date: 21 July 2026
1. Introduction and company information
This Privacy Policy explains how Northbridge Regional Solutions Ltd collects, uses, discloses, stores, and protects personal data when you interact with us, use our services, communicate with us, or visit any website, platform, or online service we operate.
Northbridge Regional Solutions Ltd is the data controller for the personal data described in this Privacy Policy, unless we expressly state otherwise.
Company details:
- Legal name: Northbridge Regional Solutions Ltd
- Address: Northbridge Regional Solutions, 14 Featherstone Street, London EC1Y 8SL, UK
- Email: [email protected]
- Phone: +44 20 7946 8372
This Privacy Policy is intended to provide a clear overview of our data practices in relation to our regional business operations, including service delivery, client communications, administration, compliance, and related support activities.
2. Data collection and processing
We may collect and process personal data that you provide directly to us, data generated through your use of our services, and data obtained from third parties where permitted by law.
The types of personal data we may collect include:
- Identity data: name, title, company name, job title, and similar identifiers.
- Contact data: email address, telephone number, postal address, and other communication details.
- Communication data: messages, enquiries, correspondence, feedback, and records of interactions.
- Service and account data: information related to your use of our services, preferences, and account settings where applicable.
- Technical data: IP address, browser type, device information, operating system, log data, and usage statistics.
- Transactional data: billing-related information, service history, and payment records where relevant.
- Marketing data: preferences regarding marketing communications, subscriptions, and engagement with our content.
We may collect personal data through the following means:
- direct interactions such as forms, emails, phone calls, meetings, and service requests;
- automated technologies such as cookies, logs, and analytics tools;
- third-party sources such as partners, service providers, business directories, or publicly available sources where permitted.
We do not intentionally collect special category data unless it is necessary, lawful, and explicitly disclosed to you, or you voluntarily provide it in the context of a legitimate interaction with us.
3. Purpose of data processing
We process personal data for the following purposes:
- to provide, manage, and improve our services;
- to respond to enquiries and communicate with you;
- to manage customer relationships and administrative records;
- to perform contractual obligations and arrange service delivery;
- to process payments, invoicing, and related financial administration;
- to comply with legal obligations, regulatory requirements, and lawful requests;
- to protect our business, systems, users, and staff from fraud, abuse, or security incidents;
- to analyse service use and improve performance, functionality, and user experience;
- to send marketing communications where permitted and subject to your preferences;
- to establish, exercise, or defend legal claims and manage disputes.
4. Legal basis for processing
We process personal data only where we have a valid legal basis. Depending on the context and applicable law, our legal bases may include:
- Performance of a contract: where processing is necessary to enter into or perform a contract with you.
- Legitimate interests: where processing is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. These interests may include service delivery, business administration, fraud prevention, security, and improvement of our services.
- Consent: where you have given us clear consent to process your personal data for a specific purpose, such as certain marketing communications or optional cookies where required.
- Legal obligation: where processing is necessary for compliance with applicable laws, regulations, or official requests.
- Vital interests: where processing is necessary to protect someone’s life or physical safety.
- Public interest or official authority: where applicable under relevant law and only when such basis is available to us.
Where we rely on legitimate interests, we will consider and balance any potential impact on you and your rights before processing your personal data.
5. Data sharing and third parties
We may share personal data with trusted third parties where necessary for the purposes described in this Privacy Policy and where allowed by law. These third parties may include:
- IT hosting, cloud storage, and system administration providers;
- communication service providers, including email and telephony services;
- professional advisers such as accountants, auditors, insurers, lawyers, and consultants;
- payment processors, invoicing tools, and financial service providers;
- analytics, website performance, and security monitoring providers;
- regulatory authorities, courts, law enforcement, or other public bodies where required;
- business partners and subcontractors involved in delivering our services;
- third parties in connection with a corporate transaction, restructuring, or asset transfer.
We require third parties to handle personal data in accordance with applicable legal and contractual obligations. Where a third party acts as our processor, we take appropriate steps to ensure it processes data only on our instructions and with appropriate safeguards.
6. Data transfer to third countries
Where personal data is transferred outside the United Kingdom or, if applicable, outside the European Economic Area, we will take appropriate measures to ensure that your personal data receives an adequate level of protection.
These measures may include:
- transfers to countries recognised as providing an adequate level of protection;
- use of appropriate contractual safeguards such as standard contractual clauses or equivalent mechanisms;
- implementation of additional technical, organisational, and legal safeguards where needed.
You may contact us using the details below if you would like more information about the safeguards we use for international transfers.
7. Storage duration
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, reporting, tax, audit, and dispute-resolution requirements.
Retention periods depend on the type of data and the context in which it was collected. In general:
- client and service records are retained for the duration of the relationship and for a reasonable period thereafter;
- financial and tax records are retained for the period required by applicable law;
- correspondence and enquiry records are retained for as long as reasonably necessary to manage our relationship and resolve issues;
- marketing data is retained until you opt out, unsubscribe, or we no longer require it for the relevant purpose;
- technical logs and analytics data are retained for a limited period consistent with security, performance, and operational needs.
When personal data is no longer required, we will securely delete, anonymise, or otherwise irreversibly de-identify it, subject to legal retention obligations.
8. User rights
Subject to applicable law, you may have the following rights in relation to your personal data:
- Right of access: to request confirmation of whether we process your personal data and obtain a copy of it.
- Right to rectification: to request correction of inaccurate or incomplete personal data.
- Right to erasure: to request deletion of your personal data in certain circumstances.
- Right to restriction: to request that we restrict the processing of your personal data in certain situations.
- Right to data portability: to request receipt of certain data in a structured, commonly used, machine-readable format and, where technically feasible, to request transfer to another controller.
- Right to object: to object to processing based on legitimate interests and to object at any time to direct marketing.
You may also have rights related to automated decision-making and profiling where applicable under law. We do not currently make decisions based solely on automated processing that produce legal or similarly significant effects without appropriate safeguards, unless we notify you otherwise.
To exercise any of your rights, please contact us using the details provided in this Privacy Policy. We may need to verify your identity before responding to your request. We will respond within the timeframe required by applicable law.
9. Withdrawal of consent
Where we rely on your consent to process personal data, you may withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of processing carried out before the withdrawal.
If you withdraw consent, we may still process your personal data where we have another valid legal basis to do so. To withdraw consent, please contact us at [email protected] or use any unsubscribe or preference-management option provided in our communications.
10. Right to complain
If you have concerns about how we handle your personal data, please contact us first so that we may address your concern directly and promptly.
You also have the right to lodge a complaint with the relevant data protection supervisory authority. In the United Kingdom, this is the Information Commissioner's Office (ICO). You may contact the ICO via its website or through its published contact channels.
If you are located in another jurisdiction, you may have the right to contact your local data protection authority.
11. Data security
We implement appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
These measures may include:
- access controls and role-based permissions;
- encryption where appropriate;
- secure storage and transmission methods;
- network and system monitoring;
- staff confidentiality obligations and training;
- regular review of internal procedures and security practices;
- vendor due diligence and contractual safeguards.
While we take reasonable steps to protect personal data, no system can be guaranteed to be completely secure. You should also take appropriate steps to protect your own information, including using secure passwords and keeping account credentials confidential where relevant.
12. Contact information
If you have questions about this Privacy Policy or about how Northbridge Regional Solutions Ltd processes your personal data, please contact us:
- Email: [email protected]
- Phone: +44 20 7946 8372
- Postal address: Northbridge Regional Solutions, 14 Featherstone Street, London EC1Y 8SL, UK
We encourage you to include sufficient detail in your request so that we can respond efficiently and accurately.
13. Changes to privacy policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, legal obligations, or operational requirements.
Any updated version will be posted on our website or otherwise made available to you where appropriate. The revised policy will take effect from the date specified in the updated version unless stated otherwise.
We encourage you to review this Privacy Policy periodically to stay informed about how Northbridge Regional Solutions Ltd handles personal data.