Aspire HR Ltd logo

Call: 07703 531 687

Email: in**@************co.uk 

ASPIRE HR LTD

Website and Data Privacy Policy

Effective Date: 01 Oct 2025 | Last Reviewed: June 2026 | Version: 3.0

Policy Owner: Angela Thorburn | ICO Registration: ZA741421

1.   Introduction

Aspire HR Ltd ("we", "us", "our") is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains what personal data we collect, how we use and protect it, how long we keep it, and your rights under UK data protection law.

This policy is written in accordance with:

  • UK General Data Protection Regulation (UK GDPR)
  • Data Protection Act 2018 (DPA 2018)
  • Privacy and Electronic Communications Regulations 2003 (PECR)

We are registered with the Information Commissioner's Office (ICO). Our ICO registration number is ZA741421. We do not engage in automated decision-making or profiling of individuals.

This policy does not apply to the personal data of our own employees or contractors, which is covered by our separate internal data protection procedures.

2.   Who We Are & How to Contact Us

Aspire HR Ltd is the data controller for personal data collected through this website and in the course of providing our services.

Contact details:

If you have any questions about how we handle your personal data, or wish to exercise any of your rights (see Section 10), please contact us using the details above.

3.   Data We Collect

3.1    Information You Provide Directly

We may collect the following when you contact us, complete a form, or engage our services:

  • Name and job title
  • Email address and phone number
  • Organisation name and address
  • Information submitted via contact forms, emails, or enquiry requests
  • Information exchanged during the delivery of services (e.g. training needs, learning objectives, HR-related context)

3.2    Special Category Data

Whilst highly unlikely and not the core business we operate in, there may be some circumstances — particularly in coaching, or HR advisory work — where we may process special category personal data as defined under UK GDPR Article 9. This may include information about health, mental health, disability, or other sensitive personal characteristics.

We will only process special category data where:

  • You have given your explicit consent, or
  • Processing is necessary for a purpose listed under Schedule 1 of the Data Protection Act 2018

Special category data is handled with the highest level of care and access is strictly limited.

3.3    Automatically Collected Data

When you visit our website, we may automatically collect:

  • IP address
  • Browser type and version
  • Device type and operating system
  • Pages viewed, time spent, and navigation behaviour
  • Referring URLs

This data may be collected via analytics tools (e.g. Google Analytics, Microsoft Clarity) and/or cookies. See Section 12 (Cookie Policy) for full details.

4.   How We Use Your Data

We will only use your personal data for genuine, lawful business purposes, including:

  • Responding to enquiries and communicating with you about our services
  • Delivering training, consultancy, coaching, or other contracted services
  • Sending you relevant updates or information (only with your consent where required)
  • Maintaining business and financial records
  • Improving our website's performance and user experience
  • Complying with legal or regulatory obligations

We do not sell, rent, or share your personal data with any third party for marketing or commercial purposes.

5.   Lawful Basis for Processing

We process personal data under the following lawful bases as defined in UK GDPR Article 6:

Lawful Basis When We Rely on It Examples
Consent (Art. 6(1)(a)) When you opt in to communications Marketing emails, newsletters, analytics cookies
Contract (Art. 6(1)(b)) To deliver contracted services Client records, invoicing, service delivery communications
Legitimate Interests (Art. 6(1)(f)) Where our interests don't override your rights Website analytics, fraud prevention, business record-keeping. A Legitimate Interests Assessment (LIA) has been documented for these activities.
Legal Obligation (Art. 6(1)(c)) Required by law or regulation HMRC record-keeping, responding to lawful regulatory requests

6.   How We Store & Protect Your Data

6.1    Systems Used

We use secure, reputable cloud-based systems, including:

  • Microsoft 365 — email, documents, and client files
  • Get that Website Online as our website hosting provider
  • Active Campaign as our email marketing tool (where appropriate)
  • Zenler for People Management Academy resources
  • OneDrive / SharePoint — secure cloud file storage
  • Xero – for financial and accounting records

6.2    Security Measures

We take appropriate technical and organisational measures to protect your data, including:

  • Encrypted storage of files and emails
  • Multi-factor authentication (MFA) on key systems
  • Access control based on the principle of least privilege
  • Firewall and anti-malware protection
  • Regular software updates and security patching
  • Strong password policies and use of a password manager
  • Confidentiality agreements with all subcontractors and associates
  • Information security training for all personnel

Where subcontractors or associates are used to support service delivery, they are required to comply with the same data protection and security obligations as the Company. Data processing agreements are in place where required.

7.   Data Retention

We only keep personal data for as long as it is needed for the purpose for which it was collected, or as required by law. Our retention periods are:

Data Category Retention Period Reason / Legal Basis
Website enquiry data Up to 12 months Legitimate interests — to managefollow-up; deleted if no engagement follows
Client and project records 6–7 years f rom end of engagement Legal obligation — HMRC / Companies Act requirements
Contracts and invoices 6 years f rom date of contract Legal obligation — Limitation Act 1980
Client employee data (ie attendee lists) Max 1 week after event Legitimate interests – deleted once data transferred to client
Coaching notes (non-special category) 3 years f rom end of engagement Legitimate interests — professional records
Coaching notes (special category, e.g. health-related) 3 years f rom end of engagement, or as agreed with the individual in the consent form Explicit consent — reviewed and deleted promptly when no longer needed
HR advisory / employee-related data 6 years or as agreed with client Contract / legal obligation
Marketing contact details Until consent is withdrawn Consent — suppression list maintained after withdrawal
Website analytics data 26 months (Google Analytics default) Consent — only where cookie consent granted
Subcontractor / associate data 6 years f rom end of engagement Legal obligation / legitimate interests

After these periods, data will be securely deleted or anonymised. Deletion of digital data includes removal from cloud storage, email, and any backups where technically possible.

8.   Sharing Your Data

We may share limited personal data with trusted third parties only where absolutely necessary:

  • Service providers (e.g. website hosting, IT support, cloud storage) — under data processing agreements
  • Professional advisers (e.g. accountant, solicitor) — under confidentiality obligations
  • Subcontractors or associates supporting service delivery — under confidentiality and data processing agreements
  • Legal or regulatory authorities — where required by law

We never sell your data, and we never share it with third parties for marketing purposes.

8.1    International Transfers

Some of our third-party service providers (e.g. Microsoft, Google) may process data outside the UK. Where this occurs, we ensure appropriate safeguards are in place, such as:

  • UK adequacy regulations (where the destination country has been deemed adequate by the UK Government)
  • UK International Data Transfer Agreement (IDTA)
  • Approved Standard Contractual Clauses (SCCs) adapted for UK use

9.   Children's Data

Our website and professional services are not directed at children under the age of 13, and we do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately and we will delete it promptly.

Where our services involve training or coaching programmes that may include participants under 18 (e.g. apprenticeship schemes), we will agree appropriate safeguards with the commissioning client before any data is processed.

10.   Your Rights

Under UK GDPR, you have the following rights in relation to your personal data:

Right What It Means
Right of Access (Art. 15) You can request a copy of the personal data we hold about you (a Subject Access Request or SAR).
Right to Rectification (Art. 16) You can ask us to correct inaccurate or incomplete data.
Right to Erasure (Art. 17) You can ask us to delete your data ('right to be forgotten'), subject to legal retention obligations.
Right to Restrict Processing (Art. 18) You can ask us to limit how we use your data in certain circumstances.
Right to Data Portability (Art. 20) You can ask us to provide your data in a portable, machine-readable format (where processing is automated and based on consent or contract).
Right to Object (Art. 21) You can object to processing based on legitimate interests or for direct marketing purposes.
Right to Withdraw Consent Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of prior processing.
Rights re. Automated Decisions (Art. 22) We do not carry out automated decision-making or profiling. If this changes, you will be notified and have the right to human review.

To exercise any of these rights, please contact us in writing using the details in Section 2. We will respond within one calendar month of receiving your request. In complex cases, we may extend this by a further two months, in which case we will notify you.

11.   Right to Complain

If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

  • Website: ico.org.uk/concerns
  • Telephone: 0303 123 1113
  • Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

We would, however, appreciate the opportunity to address your concerns before you contact the ICO. Please contact us first using the details in Section 2.

12.   Data Breach Procedure

In the event of a personal data breach, we will:

  • Contain the breach as quickly as possible
  • Assess the nature, scope, and likely impact of the breach
  • Notify the ICO within 72 hours where the breach is likely to result in a risk to individuals' rights and freedoms (UK GDPR Article 33)
  • Notify affected individuals without undue delay where the breach presents a high risk to their rights and freedoms (UK GDPR Article 34)
  • Document all breaches in our internal Breach Log, including those not reported to the ICO
  • Review the cause and implement corrective measures

13.   Cookies Policy

13.1    What Are Cookies?

Cookies are small text files stored on your device when you visit a website. They help improve your browsing experience, enable certain website functions, and allow us to understand how visitors interact with our site.

13.2    Types of Cookies We Use

Cookie Type Consent Required? Purpose / Examples
Strictly Necessary No — exempt under PECR Essential for the website to function. E.g. session cookies, security cookies, cookie consent record.
Performance / Analytics Yes — prior consent required Help us understand how the site is used. E.g. Google Analytics, Microsoft Clarity. Only activated after consent is given.
Functionality Yes — prior consent required Remember your preferences. E.g. language settings, cookie consent choices.
Targeting / Advertising Yes — prior consent required We do not currently use targeting or advertising cookies.
Third-Party Yes — prior consent required Set by embedded third-party content such as YouTube videos or LinkedIn share buttons.These providers have their own cookie policies.

13.3    Cookie Consent

Under PECR, we are required to obtain your active, informed consent before placing any non-essential cookies on your device. When you first visit our website, a cookie consent banner will allow you to:

  • Accept all cookies
  • Reject non-essential cookies
  • Customise your cookie preferences by category

Your preferences are saved and can be changed at any time via the cookie settings link in the website footer. Consent is recorded and stored to demonstrate compliance.

13.4    Managing Cookies via Your Browser

You can also manage or disable cookies through your browser settings. Guidance is available from the ICO at: https://ico.org.uk/for-the-public/online/cookies/. Please note: disabling certain cookies may affect website functionality.

13.5    Cookie Retention

  • Session cookies expire when your browser is closed
  • Persistent cookies expire after a defined period (typically up to 26 months for analytics cookies)
  • You can delete cookies at any time via your browser settings

14.   Updates to This Policy

This policy will be reviewed and updated where necessary to reflect changes in legislation, ICO guidance, our services, or our processing activities. The effective date at the top of this document will be updated accordingly.

We encourage you to review this policy periodically. The latest version will always be available on our website.