Legal
Privacy Notice
How Belgrave & Rothford collects, uses, stores, discloses and otherwise processes personal data.
- Effective date
- 1 January 2025
- Last reviewed
- 1 October 2026
- Website
- bradvisory.co
- Privacy notice
- bradvisory.co/privacy
Introduction
This Privacy Notice explains how Belgrave & Rothford (“B&R”, “we”, “us” or “our”) collects, uses, stores, discloses and otherwise processes personal data.
It applies to personal data processed in connection with the website operated at bradvisory.co, the privacy notice published at bradvisory.co/privacy, enquiries submitted through the website contact form, prospective and existing client relationships, creator and partner relationships, supplier and consultant relationships, events, productions, campaigns and associated commercial activities.
This Notice is provided for the purposes of Articles 12 to 14 of the UK General Data Protection Regulation (“UK GDPR”), as supplemented by the Data Protection Act 2018 (“DPA 2018”). It should be read together with any additional privacy information supplied at the point at which personal data is collected.
B&R operates within the jurisdiction of England. References in this Notice to applicable data protection law include the UK GDPR, the DPA 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“PECR”), and any legislation or subordinate legislation amending, replacing or supplementing those instruments.
The Controller
For the purposes of applicable data protection law, B&R is the controller of the personal data described in this Notice.
B&R does not publish a general contact email address. Enquiries concerning privacy, data protection and individual rights should be submitted through the contact form available on bradvisory.co. Where a person is unable reasonably to use the contact form, B&R may provide an alternative means of communication upon request.
B&R may request such further information as is reasonably necessary to identify the relevant individual, verify the identity of a requester, clarify the scope of a request or protect the rights and freedoms of other individuals.
Personal data processed by B&R
The personal data processed by B&R will depend upon the nature of the relevant relationship or interaction. It may include a person’s name, contact details, professional identity, business or organisational information, correspondence, enquiry details, information concerning services or proposed engagements, contractual and transaction information, and information relating to a person’s involvement with a client, creator, supplier, partner, consultant, event, production, campaign or other commercial activity.
Where relevant, B&R may process information concerning creator suitability, availability, fees, audience information, usage rights, exclusivity and contractual requirements. In connection with events, B&R may process dietary information where reasonably necessary for administration. B&R may also process identity information where verification is required for a platform, service, transaction, contractual relationship or legal obligation.
Where B&R is involved in a production, event, campaign or publication, it may process photographs, video recordings, audio recordings, interviews and other related material. Payment-related information may also be processed where necessary to administer a transaction, although payment card details may be handled directly by a third-party payment provider.
B&R may process technical and usage information concerning access to its website, including the referring website, pages visited, approximate location, device type, browser type, IP address and other information generated through the operation and security of the website.
B&R does not intentionally collect personal data from children, and its services and website are not directed towards persons under 18 years of age.
Sources of personal data
Personal data may be provided directly by the individual concerned, including through the website contact form, correspondence or discussions concerning a proposed or existing engagement.
B&R may also receive personal data from clients, creators, partners, suppliers, consultants and professional advisers, or from persons participating in events, productions, campaigns or other commercial activities. It may obtain information from publicly available professional or commercial sources, and from third-party platforms where the relevant use or disclosure has been made known to the individual concerned.
Certain technical information may be collected automatically through server logs and essential technical technologies required to operate, secure and administer the website.
Where personal data is obtained from a source other than the individual concerned, B&R will provide the information required by Article 14 UK GDPR, subject to any applicable exemption or limitation.
Purposes of processing
B&R processes personal data for the purposes of responding to enquiries, assessing the suitability of its services, establishing and administering professional relationships, negotiating and performing contracts, preparing proposals and commercial documentation, and providing strategy, brand governance, commercial advisory, campaign, production, event and related services.
Where relevant, processing may include creator identification and suitability assessment, negotiation, contracting, management of usage rights and exclusivity, production, filming, photography, content approval, publication and reporting. B&R may also process personal data to identify suitable partners, suppliers and commercial opportunities, and to administer events and associated dietary, accessibility and identity-verification requirements.
Personal data may be used to process or facilitate payments, maintain business and professional records, operate and secure the website, monitor general website traffic and referral sources, improve the website and associated services, manage risk, comply with legal and regulatory requirements, and establish, exercise or defend legal claims.
B&R may process personal data to detect, prevent and investigate fraud, crime, misuse, security incidents and other breaches. It may disclose information to an appropriate authority where it reasonably considers that doing so is necessary or appropriate for the reporting or investigation of suspected criminal conduct, fraud or other unlawful activity.
Lawful basis
B&R processes personal data only where a lawful basis under Article 6 UK GDPR applies.
Processing may be necessary for the performance of a contract or for taking steps at the request of an individual before entering into a contract, pursuant to Article 6(1)(b) UK GDPR. Processing may also be necessary for compliance with a legal obligation pursuant to Article 6(1)(c), or, in exceptional circumstances, for the protection of vital interests pursuant to Article 6(1)(d).
Where an individual has given specific, informed and unambiguous consent, processing may be carried out pursuant to Article 6(1)(a). Consent may be withdrawn at any time, although withdrawal will not affect the lawfulness of processing carried out before withdrawal.
B&R may rely upon Article 6(1)(f) where processing is necessary for its legitimate interests or those of a third party, except where those interests are overridden by the interests or fundamental rights and freedoms of the individual concerned. Those interests may include conducting and administering B&R’s business, responding to professional enquiries, maintaining client and commercial relationships, identifying suitable opportunities, protecting confidential information and systems, preventing fraud and misuse, improving services, maintaining appropriate records, and establishing, exercising or defending legal claims.
Where B&R relies upon legitimate interests, it will consider whether the proposed processing is necessary and proportionate and whether the relevant interests are outweighed by the rights and reasonable expectations of the individual concerned.
Direct marketing
B&R may send business, service, event, opportunity or other commercial communications where permitted by the UK GDPR, PECR and other applicable law.
The relevant legal basis may be consent, a relevant existing customer or business relationship, a current or previous enquiry, legitimate interests where applicable, or another lawful permission or exemption recognised by law. The submission of an enquiry will not, of itself, constitute unrestricted consent to direct marketing.
Where consent is required, it will be obtained before the relevant communication is sent. An individual may object to direct marketing at any time, and such an objection will be treated as absolute. Upon receipt of an objection, B&R will cease processing the relevant personal data for direct marketing purposes without undue delay.
Disclosure of personal data
B&R may disclose personal data where there is a lawful basis and where disclosure is reasonably necessary for the purposes described in this Notice.
Disclosure may be made to clients, creators, partners, suppliers and professional contacts involved in an agreed or disclosed activity. It may also be made to website hosting and technical service providers, contact-form and communications providers, cloud-storage and information-management providers, cybersecurity and IT support providers, payment service providers, event and production providers, and professional advisers including legal, accounting, insurance and compliance advisers.
B&R may disclose personal data to courts, tribunals, regulators, public authorities and law-enforcement bodies, and to persons or organisations involved in the investigation or prevention of fraud, crime, security incidents or other unlawful conduct.
B&R may also disclose personal data where necessary in connection with a proposed or actual sale, restructuring, merger, financing or transfer of all or part of its business, or where disclosure is necessary to protect the rights, property, security or legitimate interests of B&R or another person.
B&R does not sell personal data and does not provide personal data to unrelated third parties for their independent marketing purposes. B&R reserves the right to disclose personal data where reasonably necessary to carry out its business, comply with legal obligations, report suspected criminal activity, investigate fraud or address another breach of law, contract or security.
Processors and international transfers
B&R may appoint third-party processors to provide website hosting, contact-form processing, communications, cloud storage, cybersecurity, technical support, payment processing, event administration, content production, publication or other business services.
Where a processor is appointed, B&R will seek to ensure that the processing is governed by an appropriate written arrangement and that the processor acts only on documented instructions, maintains confidentiality and implements appropriate technical and organisational measures in accordance with Article 28 UK GDPR.
The particular providers used by B&R may change from time to time. Information concerning relevant categories of provider may be supplied upon reasonable request, subject to confidentiality, security and commercial considerations.
Some processors, professional advisers or service providers may process personal data outside the United Kingdom. Where a restricted transfer takes place, B&R will rely upon a lawful transfer mechanism under Chapter V UK GDPR, which may include UK adequacy regulations, the International Data Transfer Agreement, the International Data Transfer Addendum, binding corporate rules or another lawful mechanism recognised by applicable law.
Cookies and technical technologies
The website currently uses essential cookies only. Such cookies may be used where strictly necessary to operate the website, maintain security, prevent misuse, enable requested functionality, maintain technical sessions, process forms or preserve essential technical settings.
B&R does not currently use non-essential analytics cookies, advertising cookies, retargeting technologies, social-media tracking pixels or comparable optional technologies.
If non-essential cookies or similar technologies are introduced, B&R will provide appropriate information about their purpose and operation and will obtain consent before activating them where consent is required under PECR or other applicable law. Access to the website will not be made conditional upon consent to non-essential cookies.
Photographs, recordings and related material
B&R may process photographs, video recordings, audio recordings, interviews and related material in connection with events, productions, campaigns, publications and other commercial activities.
Before collecting or using such material, B&R will provide appropriate information concerning the purpose of the recording or production, its intended use, relevant publication channels, applicable usage rights and restrictions, and the lawful basis relied upon.
Where required, B&R will obtain consent or rely upon another lawful basis under Article 6 UK GDPR and, where relevant, an applicable condition under Article 9 UK GDPR.
Special category data
B&R does not routinely seek special category data. In limited circumstances, it may process dietary information for event administration or identity information required for verification, platform access, contractual administration or legal compliance.
Where special category data is processed, B&R will rely upon both a lawful basis under Article 6 UK GDPR and an applicable condition under Article 9 UK GDPR. Where criminal offence data is processed, B&R will comply with Article 10 UK GDPR and the relevant provisions of the DPA 2018.
Retention
B&R retains personal data only for as long as reasonably necessary for the purposes for which it was collected, subject to legal, regulatory, contractual, evidential, insurance, accounting and operational requirements.
Ordinary enquiries that do not result in an engagement may be retained for up to 36 months. Client, supplier, creator, partner and business records may be retained for as long as reasonably necessary for legitimate record-keeping, historical, legal, commercial or evidential purposes. Certain records may be retained indefinitely where there is a continuing lawful justification, including legal, contractual, regulatory, insurance, evidential or historical reasons.
Relevant active or historical records will generally be reviewed or accessed for periods of up to 60 months, although this does not require the deletion of every record after that period. Financial, tax, accounting, insurance, contractual and regulatory records will be retained for the period required by the relevant legal or professional obligation.
Consent and communication-preference records will be retained for as long as necessary to demonstrate and administer those preferences. Identity-verification documents will be retained only for as long as reasonably necessary for verification, legal compliance, audit or the resolution of a related matter. Technical and security records will be retained for periods proportionate to the relevant operational, security or evidential purpose.
When personal data is no longer required, it will be securely deleted, anonymised or otherwise disposed of in accordance with appropriate internal procedures.
Data Subject rights
Subject to the conditions, restrictions and exemptions contained in the UK GDPR and the DPA 2018, an individual may have the right under Article 15 UK GDPR to obtain access to personal data and prescribed supplementary information; under Article 16 to obtain rectification of inaccurate personal data; under Article 17 to obtain erasure in specified circumstances; under Article 18 to obtain restriction of processing in specified circumstances; under Article 20 to receive certain personal data in a structured, commonly used and machine-readable format; and under Article 21 to object to processing based on legitimate interests or to direct marketing.
An individual may withdraw consent where processing is based upon consent and may lodge a complaint with the Information Commissioner’s Office. The exercise of any right remains subject to applicable statutory conditions, limitations and exemptions.
Data Subject Access Requests
A Data Subject Access Request may be submitted through the contact form on bradvisory.co.
B&R may require sufficient information to verify the identity of the requester. Identification may be provided by encrypted email or another secure method agreed with the requester.
B&R will respond without undue delay and, in principle, within one month of receiving the request and any information reasonably required for identity verification, in accordance with Article 12 UK GDPR. That period may be extended by up to two further months where necessary owing to the complexity or number of requests. B&R will notify the requester of any extension and the reasons for it within the initial one-month period.
B&R may refuse or restrict a request where permitted by the UK GDPR, the DPA 2018 or another applicable legal provision. This may include circumstances involving legal professional privilege, the rights and freedoms of other individuals, confidentiality owed to third parties, crime prevention or detection, regulatory functions, judicial or legal proceedings, or another statutory exemption.
Identity-verification material will be retained only for as long as reasonably necessary to verify and administer the request, comply with legal obligations, maintain an appropriate audit record or address a related dispute.
Security and personal data breaches
B&R will implement appropriate technical and organisational measures having regard to the risks presented by processing, in accordance with Article 32 UK GDPR.
No method of transmission or storage can be guaranteed to be entirely secure. Individuals should not submit highly sensitive information through an ordinary web form unless specifically requested and an appropriate secure method is available.
Where a personal data breach occurs, B&R will assess the breach in accordance with Articles 33 and 34 UK GDPR and applicable provisions of the DPA 2018. Where notification to the Information Commissioner’s Office is legally required, B&R will make that notification without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to the rights and freedoms of affected individuals, B&R will communicate the breach to those individuals where required by law.
Complaints
Any concern regarding the handling of personal data should first be submitted to B&R through the contact form on bradvisory.co, so that the matter may be investigated and addressed.
Nothing in this section limits an individual’s statutory right to lodge a complaint with the Information Commissioner’s Office or to pursue any other remedy available under applicable law.
Amendments
B&R may amend this Privacy Notice from time to time to reflect changes in applicable legislation, regulatory guidance, the website, its services, its business activities, its processors, its information-sharing arrangements or its retention and security procedures.
The version in force will be published at bradvisory.co/privacy. The effective date stated at the beginning of the Notice identifies the version currently in force.
Governing law
This Privacy Notice and any non-contractual obligations arising from or in connection with it shall be governed by the law of England and Wales.
The courts of England and Wales shall have exclusive jurisdiction, subject to any mandatory jurisdictional rights available to an individual under applicable data protection law.