Privacy Policy
How DS Risk Group collects, uses, stores and protects personal information.
Last updated: 25 July 2026
This Privacy Policy explains how DS Risk Group Ltd collects, uses, stores and protects personal data. It is intended to provide the information required by Articles 13 and 14 of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and, where applicable, the Privacy and Electronic Communications Regulations 2003 (PECR).
1. Who we are and how to contact us
DS Risk Group Ltd is the controller of the personal data described in this policy. We are an independent risk, compliance and operational consultancy based in North Yorkshire and providing services across the United Kingdom.
- Company: DS Risk Group Ltd
- Company number: 17225084
- Email: info@dsriskgroup.co.uk
We have not appointed a Data Protection Officer because our current activities do not require one. Privacy enquiries should be sent to the email address above.
2. Personal data we may collect
Depending on how you interact with us, we may collect and process:
- identity and contact data, including your name, job title, organisation, email address and telephone number;
- enquiry and correspondence data, including messages, attachments, call notes and service requirements;
- contract and transaction data, including quotations, instructions, invoices, payment status and project records;
- service-delivery data supplied by you or created during an assignment, which may include information about employees, contractors, witnesses, incidents, sites or business operations;
- marketing preferences and records of consent;
- technical and usage data, such as IP address, browser type, device information, pages requested, timestamps, referral data and security logs; and
- any other information you choose to provide.
Please avoid sending special category data, criminal offence data or unnecessary personal information through the general contact form. Where an assignment requires sensitive information, we will agree an appropriate and secure method of transfer.
3. How we collect personal data
We collect personal data directly from you when you contact us, request a quotation, enter into a contract, provide project information, subscribe to updates or otherwise communicate with us. We may also receive information from your employer, colleagues, professional advisers, publicly available business sources, service providers or another person involved in an assignment.
4. Purposes and lawful bases
We use personal data only where we have a lawful basis. The principal purposes and bases are:
- Responding to enquiries and preparing quotations: taking steps at your request before entering into a contract, and our legitimate interests in developing and administering our business.
- Providing services and managing client relationships: performance of a contract, taking pre-contract steps and our legitimate interests in delivering, documenting and improving our services.
- Managing payments, accounts and records: performance of a contract, compliance with legal obligations and our legitimate interests in financial administration and debt recovery.
- Protecting our systems, website and business: our legitimate interests in security, fraud prevention, service continuity, legal claims and misuse prevention.
- Meeting legal, regulatory or insurance requirements: compliance with legal obligations and, where applicable, our legitimate interests in establishing, exercising or defending legal claims.
- Sending electronic marketing: consent where PECR requires it, or the limited business-contact and existing-customer rules available under applicable law. You can opt out at any time.
Where we rely on legitimate interests, we consider whether our interests are necessary and proportionate and whether your rights override them.
5. Special category and criminal offence data
Some consultancy assignments, particularly incident reviews, may contain health, equality, trade union, biometric or criminal allegation information. We will process such data only where necessary, with an additional condition under Articles 9 or 10 UK GDPR and the Data Protection Act 2018. This may include explicit consent, employment and social protection law, substantial public interest conditions, or the establishment, exercise or defence of legal claims. The applicable condition will depend on the assignment and the client’s instructions.
6. Where we act as a processor
For some client assignments, the client determines why and how personal data is used and DS Risk Group acts as its processor. In those cases, we process the information only on documented instructions, subject to the contract and any required data-processing terms. Requests concerning that information may need to be referred to the relevant client as controller.
7. Sharing personal data
We do not sell personal data. We may share it where reasonably necessary with:
- hosting, email, cloud storage, form-processing, payment, accounting and IT providers;
- professional advisers, insurers, auditors and debt-recovery providers;
- approved associates or subcontractors involved in delivering an agreed service;
- courts, regulators, law-enforcement bodies or public authorities where disclosure is required or permitted by law; and
- a purchaser, investor or successor in connection with a genuine business sale, restructuring or transfer.
Recipients are limited to the information they need and are required to protect it through contract, professional duty or law.
8. International transfers
Some technology providers may process information outside the United Kingdom. Where restricted transfers occur, we will use a lawful transfer mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another permitted safeguard. Additional technical or contractual measures will be considered where appropriate.
9. Data security
We use proportionate technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, loss or destruction. Measures may include access controls, strong authentication, restricted permissions, secure transfer methods, backups, device security and confidentiality obligations. No internet-based system is completely secure, so information should not be sent through the website where a more secure agreed channel is appropriate.
10. Retention
We keep personal data only for as long as necessary for the relevant purpose. In setting periods, we consider contractual requirements, the nature and sensitivity of the information, limitation periods, insurance requirements and legal or accounting duties.
- Unsuccessful or routine enquiries will normally be retained for up to 24 months after the last meaningful contact.
- Client, contract, invoice and core project records will normally be retained for up to seven years after completion or termination.
- Marketing records will be retained until consent is withdrawn or the contact is no longer relevant, with a minimal suppression record retained to respect opt-outs.
- Server and security logs will normally be retained for a shorter period unless needed to investigate an incident.
Different periods may apply where the law, a dispute, an insurer or the assignment reasonably requires it.
11. Your rights
Subject to legal conditions and exemptions, you may have the right to:
- be informed about processing;
- request access to your personal data;
- request correction of inaccurate or incomplete data;
- request erasure;
- request restriction of processing;
- object to processing based on legitimate interests or to direct marketing;
- receive certain data in a portable format;
- withdraw consent at any time where processing relies on consent; and
- not be subject to a solely automated decision producing legal or similarly significant effects.
To exercise a right, email info@dsriskgroup.co.uk. We may need to verify your identity. We normally respond within one month, although the UK GDPR permits an extension for complex or multiple requests. Rights are not absolute and we will explain any lawful refusal or limitation.
12. Marketing communications
Marketing consent is separate from permission to respond to an enquiry. Where you opt in, we may send occasional service updates, resources or business information. Every marketing email will provide a clear means to unsubscribe. Withdrawing marketing consent does not affect service communications or processing already carried out lawfully.
13. Cookies and similar technologies
The website is intended to launch without non-essential analytics or advertising cookies. Essential technologies may be used for security, administration, form operation or session management. If non-essential cookies or tracking tools are introduced, we will provide appropriate information and consent controls before they are activated.
14. Third-party links
The website may link to third-party websites, including Instagram. Those organisations operate under their own privacy notices and DS Risk Group is not responsible for their processing practices.
15. Children
Our website and services are directed at businesses and are not intended for children. We do not knowingly use the website to collect information from children.
16. Complaints
Please contact us first so we can try to resolve any concern. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection. Current contact and complaint information is available through the ICO’s official website.
17. Changes to this policy
We may update this policy to reflect changes in our services, technology or legal obligations. The current version and revision date will be published on this page. Material changes may also be brought to the attention of affected individuals where appropriate.
