Privacy Policy
Version 3.0 — last updated 1 July 2026
Northbridge Marketing Ltd ("Northbridge", "we", "us", "our") handles personal data for people who visit this website, enquire about our services, work with us as clients or suppliers, or apply to join us. This policy explains what we do with that data and what you can require of us.
Under the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018, Northbridge Marketing Ltd is the data controller for the processing described below.
Contents
1. Who we are, and when we are a processor
Northbridge Marketing Ltd is registered in England and Wales, company number 00000000, registered office Northbridge House, 8 Wellington Street, Leeds, LS1 2DH, United Kingdom.
A significant part of our work involves configuring and operating systems that hold our clients' data — CRM platforms, marketing automation tools, data warehouses. In that work we act as the client's data processor: the client determines the purposes, the client's privacy notice governs the processing, and we operate under a written data processing agreement meeting Article 28 of the UK GDPR, including obligations on confidentiality, sub-processors, security, assistance with data subject requests, breach notification and deletion on termination.
If you have received marketing from one of our clients and want to exercise your rights, contact that organisation directly — they are the controller. If you contact us instead, we will forward your request to them promptly and tell you that we have done so.
2. Data we collect
2.1 Data you give us
- Enquiry data — name, company, work email, telephone number, sales cycle length, CRM platform, the nature of your requirement and anything else you write.
- Client records — contact details of your team, contractual documents, project correspondence and billing information.
- Supplier and contractor records — contact and payment details, and right-to-work documentation where relevant.
- Recruitment data — CV, work history, technical assessment results, interview notes and references.
- Subscription data — name, company and email where you subscribe to our research notes.
2.2 Data collected automatically
- Technical data — IP address, browser and device characteristics, operating system, viewport size and approximate region.
- Usage data — pages viewed, referrer, internal navigation path and engagement duration.
We collect nothing beyond what is strictly necessary unless you consent through the cookie banner. Details are in our Cookie Policy.
2.3 Data from third parties
We may obtain business contact information from professional networks, public registers such as Companies House, business information providers, conference organisers where you consented to sponsor contact, and referrals. Where we use a business data provider we satisfy ourselves that it has a lawful basis for supplying the data to us.
We do not collect special category data via this website. Please do not include health, ethnicity, political, religious or similar information in an enquiry.
3. Purposes and lawful bases
| Purpose | Data | Lawful basis |
|---|---|---|
| Responding to enquiries, scoping and proposals | Enquiry data | Legitimate interests — acting on your request |
| Delivering services under an engagement letter | Client records | Performance of a contract |
| Managing suppliers and contractors | Supplier records | Performance of a contract; legal obligation |
| Invoicing, credit control, statutory accounts | Billing data | Legal obligation |
| Sending research notes and event invitations | Name, company, email | Consent, or PECR soft opt-in for existing contacts |
| Understanding how this site is used | Technical, usage data | Consent |
| Recruitment and technical assessment | Application data | Legitimate interests; legal obligation |
| Information security, fraud prevention, enforcing terms | Technical data, logs | Legitimate interests |
Where we rely on legitimate interests we have documented a balancing assessment, available in summary on request.
4. Recipients
We do not sell personal data. We disclose it to: processors operating our website hosting, email, CRM, warehouse, project management and file storage systems, each under written contract and subject to due diligence; advertising and analytics providers, only with your consent; professional advisers including accountants, auditors, insurers and solicitors; regulators, courts and law enforcement where legally obliged; and a successor entity in the event of a sale or reorganisation, under confidentiality undertakings. A current list of our sub-processors is available to clients on request.
5. International transfers
Our core systems are hosted in the United Kingdom and the European Economic Area. Where a provider processes data elsewhere — principally the United States — we rely on a UK adequacy regulation (including the UK Extension to the EU–US Data Privacy Framework), the International Data Transfer Agreement, or the UK Addendum to the European Commission's Standard Contractual Clauses, each supported by a documented transfer risk assessment. We will provide details of the mechanism applying to any specific transfer on request.
6. Retention
| Record | Period |
|---|---|
| Enquiries that do not proceed | 24 months from last contact |
| Engagement letters and project records | 7 years after the engagement ends |
| Accounting and tax records | 7 years (HMRC requirement) |
| Research note subscribers | Until you unsubscribe, plus 12 months suppression |
| Unsuccessful applications | 12 months, or longer with your consent |
| Website analytics | 14 months |
| Security and access logs | 13 months |
Client data we process on a client's behalf is deleted or returned in accordance with the relevant data processing agreement, normally within 30 days of termination.
7. Security
Our controls include TLS in transit and encryption at rest, single sign-on with enforced multi-factor authentication, role-based least-privilege access with quarterly review, centrally managed and encrypted endpoints, segregated client environments, secrets management, code review on all changes to client systems, annual penetration testing, documented supplier assessment, and annual security training for every consultant. We maintain a written incident response plan, and will notify the Information Commissioner's Office of a notifiable breach within 72 hours of becoming aware of it and inform affected individuals directly where the risk to them is high.
8. Your rights
You have the rights to be informed, of access, to rectification, to erasure, to restriction of processing, to data portability, to object to processing based on legitimate interests, to object to direct marketing at any time, and to withdraw consent where consent is our basis.
Email [email protected] with "Data rights request" in the subject line, or write to us at the address in section 12. We reply within one calendar month, extendable by up to two further months for complex requests, and we will tell you if we extend. We may ask for proof of identity where we cannot otherwise verify it.
Please raise concerns with us first. You may also complain to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF — 0303 123 1113, ico.org.uk.
9. Cookies and tracking
Non-essential cookies are set only after consent. Full detail is in our Cookie Policy. Note that when we build measurement systems for clients we configure them to require consent and to operate under Consent Mode v2 or an equivalent mechanism.
10. Marketing
We send a monthly research note only to people who requested it, and to existing business contacts under the soft opt-in permitted by the Privacy and Electronic Communications Regulations 2003 for closely related services. Every message carries a working one-click unsubscribe link, honoured immediately. We do not share our subscriber list with anyone.
11. Automated decision-making
We do not make decisions about you by solely automated means that produce legal or similarly significant effects. Lead scoring models we build for clients are used to prioritise human follow-up, not to make automated decisions about individuals, and we advise clients accordingly.
12. Changes and contact
We review this policy annually and whenever processing changes materially. The version and date at the head of the page identify the current text.
Northbridge Marketing Ltd
Data Protection
Northbridge House, 8 Wellington Street
Leeds, LS1 2DH, United Kingdom
Email [email protected]