Northbridge
  • Home
  • Capabilities
  • Firm
  • Evidence
  • FAQ
  • Book a call
Legal

Privacy Policy

Version 3.0 — last updated 1 July 2026

Northbridge Marketing Ltd ("Northbridge", "we", "us", "our") handles personal data for people who visit this website, enquire about our services, work with us as clients or suppliers, or apply to join us. This policy explains what we do with that data and what you can require of us.

Under the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018, Northbridge Marketing Ltd is the data controller for the processing described below.

Contents

  1. Who we are, and when we are a processor
  2. Data we collect
  3. Purposes and lawful bases
  4. Recipients
  5. International transfers
  6. Retention
  7. Security
  8. Your rights
  9. Cookies and tracking
  10. Marketing
  11. Automated decision-making
  12. Changes and contact

1. Who we are, and when we are a processor

Northbridge Marketing Ltd is registered in England and Wales, company number 00000000, registered office Northbridge House, 8 Wellington Street, Leeds, LS1 2DH, United Kingdom.

A significant part of our work involves configuring and operating systems that hold our clients' data — CRM platforms, marketing automation tools, data warehouses. In that work we act as the client's data processor: the client determines the purposes, the client's privacy notice governs the processing, and we operate under a written data processing agreement meeting Article 28 of the UK GDPR, including obligations on confidentiality, sub-processors, security, assistance with data subject requests, breach notification and deletion on termination.

If you have received marketing from one of our clients and want to exercise your rights, contact that organisation directly — they are the controller. If you contact us instead, we will forward your request to them promptly and tell you that we have done so.

2. Data we collect

2.1 Data you give us

  • Enquiry data — name, company, work email, telephone number, sales cycle length, CRM platform, the nature of your requirement and anything else you write.
  • Client records — contact details of your team, contractual documents, project correspondence and billing information.
  • Supplier and contractor records — contact and payment details, and right-to-work documentation where relevant.
  • Recruitment data — CV, work history, technical assessment results, interview notes and references.
  • Subscription data — name, company and email where you subscribe to our research notes.

2.2 Data collected automatically

  • Technical data — IP address, browser and device characteristics, operating system, viewport size and approximate region.
  • Usage data — pages viewed, referrer, internal navigation path and engagement duration.

We collect nothing beyond what is strictly necessary unless you consent through the cookie banner. Details are in our Cookie Policy.

2.3 Data from third parties

We may obtain business contact information from professional networks, public registers such as Companies House, business information providers, conference organisers where you consented to sponsor contact, and referrals. Where we use a business data provider we satisfy ourselves that it has a lawful basis for supplying the data to us.

We do not collect special category data via this website. Please do not include health, ethnicity, political, religious or similar information in an enquiry.

3. Purposes and lawful bases

PurposeDataLawful basis
Responding to enquiries, scoping and proposalsEnquiry dataLegitimate interests — acting on your request
Delivering services under an engagement letterClient recordsPerformance of a contract
Managing suppliers and contractorsSupplier recordsPerformance of a contract; legal obligation
Invoicing, credit control, statutory accountsBilling dataLegal obligation
Sending research notes and event invitationsName, company, emailConsent, or PECR soft opt-in for existing contacts
Understanding how this site is usedTechnical, usage dataConsent
Recruitment and technical assessmentApplication dataLegitimate interests; legal obligation
Information security, fraud prevention, enforcing termsTechnical data, logsLegitimate interests

Where we rely on legitimate interests we have documented a balancing assessment, available in summary on request.

4. Recipients

We do not sell personal data. We disclose it to: processors operating our website hosting, email, CRM, warehouse, project management and file storage systems, each under written contract and subject to due diligence; advertising and analytics providers, only with your consent; professional advisers including accountants, auditors, insurers and solicitors; regulators, courts and law enforcement where legally obliged; and a successor entity in the event of a sale or reorganisation, under confidentiality undertakings. A current list of our sub-processors is available to clients on request.

5. International transfers

Our core systems are hosted in the United Kingdom and the European Economic Area. Where a provider processes data elsewhere — principally the United States — we rely on a UK adequacy regulation (including the UK Extension to the EU–US Data Privacy Framework), the International Data Transfer Agreement, or the UK Addendum to the European Commission's Standard Contractual Clauses, each supported by a documented transfer risk assessment. We will provide details of the mechanism applying to any specific transfer on request.

6. Retention

RecordPeriod
Enquiries that do not proceed24 months from last contact
Engagement letters and project records7 years after the engagement ends
Accounting and tax records7 years (HMRC requirement)
Research note subscribersUntil you unsubscribe, plus 12 months suppression
Unsuccessful applications12 months, or longer with your consent
Website analytics14 months
Security and access logs13 months

Client data we process on a client's behalf is deleted or returned in accordance with the relevant data processing agreement, normally within 30 days of termination.

7. Security

Our controls include TLS in transit and encryption at rest, single sign-on with enforced multi-factor authentication, role-based least-privilege access with quarterly review, centrally managed and encrypted endpoints, segregated client environments, secrets management, code review on all changes to client systems, annual penetration testing, documented supplier assessment, and annual security training for every consultant. We maintain a written incident response plan, and will notify the Information Commissioner's Office of a notifiable breach within 72 hours of becoming aware of it and inform affected individuals directly where the risk to them is high.

8. Your rights

You have the rights to be informed, of access, to rectification, to erasure, to restriction of processing, to data portability, to object to processing based on legitimate interests, to object to direct marketing at any time, and to withdraw consent where consent is our basis.

Email [email protected] with "Data rights request" in the subject line, or write to us at the address in section 12. We reply within one calendar month, extendable by up to two further months for complex requests, and we will tell you if we extend. We may ask for proof of identity where we cannot otherwise verify it.

Please raise concerns with us first. You may also complain to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF — 0303 123 1113, ico.org.uk.

9. Cookies and tracking

Non-essential cookies are set only after consent. Full detail is in our Cookie Policy. Note that when we build measurement systems for clients we configure them to require consent and to operate under Consent Mode v2 or an equivalent mechanism.

10. Marketing

We send a monthly research note only to people who requested it, and to existing business contacts under the soft opt-in permitted by the Privacy and Electronic Communications Regulations 2003 for closely related services. Every message carries a working one-click unsubscribe link, honoured immediately. We do not share our subscriber list with anyone.

11. Automated decision-making

We do not make decisions about you by solely automated means that produce legal or similarly significant effects. Lead scoring models we build for clients are used to prioritise human follow-up, not to make automated decisions about individuals, and we advise clients accordingly.

12. Changes and contact

We review this policy annually and whenever processing changes materially. The version and date at the head of the page identify the current text.

Northbridge Marketing Ltd
Data Protection
Northbridge House, 8 Wellington Street
Leeds, LS1 2DH, United Kingdom

Email [email protected]

Northbridge

A B2B demand generation firm. We build pipeline systems for companies with long sales cycles and sceptical finance teams.

Northbridge Marketing Ltd
Northbridge House, 8 Wellington Street
Leeds, LS1 2DH, United Kingdom
[email protected]

Capabilities

  • Demand Generation
  • Technical & Content SEO
  • Account-Based Marketing
  • Automation & RevOps
  • Paid Media for Pipeline
  • Attribution & Analytics

Firm

  • About Northbridge
  • Engagement model
  • Evidence
  • FAQ
  • Contact

Legal

  • Privacy Policy
  • Cookie Policy
  • Terms of Service
  • Accessibility
© 2026 Northbridge Marketing Ltd — all rights reserved