Privacy Policy

1. Introduction and company information

This Privacy Policy explains how Northbridge Brand Communications Ltd collects, uses, discloses, stores, and protects personal data when you interact with us, including when you visit our website, contact us, request our services, subscribe to communications, or otherwise engage with our brand-communication business.

Northbridge Brand Communications Ltd is the data controller for the personal data described in this Privacy Policy, unless we tell you otherwise.

This Privacy Policy should be read together with any other privacy notices or fair processing notices we may provide on specific occasions.

2. Data collection and processing

We may collect and process the following categories of personal data:

We collect personal data directly from you, from our website and communication tools, from third parties such as clients or service providers, and from publicly available sources where lawful and appropriate.

We do not intentionally collect special category personal data unless it is necessary, lawful, and you provide it or we are otherwise entitled to process it. Where such data is processed, we will apply additional safeguards as required by applicable law.

3. Purpose of data processing

We process personal data for the following purposes:

4. Legal basis for processing

We process personal data only where we have a lawful basis to do so. Depending on the context, our legal bases may include:

Where we rely on legitimate interests, those interests may include operating and improving our services, securing our systems, managing client relationships, and developing our business.

5. Data sharing and third parties

We may share personal data with third parties where necessary and lawful, including:

We require third parties to process personal data in accordance with applicable law and to implement appropriate confidentiality and security measures. Third parties may act as processors or independent controllers depending on the service and the context.

6. Data transfer to third countries

Where personal data is transferred outside the United Kingdom, we will take steps to ensure that appropriate safeguards are in place, as required by applicable law. These safeguards may include:

By using our services or communicating with us, you acknowledge that your personal data may be processed in jurisdictions outside your country of residence, subject to the safeguards described above.

7. Storage duration

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, reporting, tax, and contractual obligations.

Retention periods vary depending on the nature of the data and the purpose of processing. In general:

When personal data is no longer required, we will delete it, anonymise it, or securely archive it as appropriate.

8. User rights (access, rectification, erasure, restriction, data portability, objection)

Subject to applicable law, you may have the following rights in relation to your personal data:

To exercise any of these rights, please contact us using the details below. We may ask for information necessary to verify your identity before responding. We will respond within the timeframes required by applicable law.

9. Withdrawal of consent

Where we rely on your consent to process personal data, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of processing carried out before the withdrawal.

If you withdraw consent, we may no longer be able to provide certain features, communications, or services where consent is required. You can withdraw consent by contacting us at [email protected].

10. Right to complain

If you have concerns about how we handle your personal data, we encourage you to contact us first so we can try to resolve the issue.

You also have the right to lodge a complaint with the relevant data protection supervisory authority. If you are located in the United Kingdom, this is generally the Information Commissioner's Office (ICO).

11. Data security

We have implemented appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures may include access controls, authentication tools, secure storage, network protections, staff confidentiality obligations, and regular review of our security practices.

However, no method of transmission over the internet or method of electronic storage is completely secure. While we strive to protect your personal data, we cannot guarantee absolute security.

12. Contact information

If you have any questions about this Privacy Policy or our data practices, or if you wish to exercise your rights, please contact:

13. Changes to privacy policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. Any updated version will be posted on our website with a revised effective date where appropriate.

We encourage you to review this Privacy Policy periodically to stay informed about how Northbridge Brand Communications Ltd processes personal data.

7/13/2026 Home