Keeping compliance simple; data protection support

Firebird Data Protection Consultancy
Firebird Data Protection Consultancy
  • Home
  • About Us
  • Our Services
  • Sectors
    • Schools and EdTech
    • Small, Medium Businesses
    • Large Organisations
  • Insights
  • Contact Us
  • Testimonials
  • FAQ's
  • Terms and Conditions
  • Our Compliance
  • Safeguarding
  • Privacy Notice
  • Equality and Diversity
  • Make a Complaint
  • More
    • Home
    • About Us
    • Our Services
    • Sectors
      • Schools and EdTech
      • Small, Medium Businesses
      • Large Organisations
    • Insights
    • Contact Us
    • Testimonials
    • FAQ's
    • Terms and Conditions
    • Our Compliance
    • Safeguarding
    • Privacy Notice
    • Equality and Diversity
    • Make a Complaint

Keeping compliance simple; data protection support


  • Home
  • About Us
  • Our Services
  • Sectors
    • Schools and EdTech
    • Small, Medium Businesses
    • Large Organisations
  • Insights
  • Contact Us
  • Testimonials
  • FAQ's
  • Terms and Conditions
  • Our Compliance
  • Safeguarding
  • Privacy Notice
  • Equality and Diversity
  • Make a Complaint

Privacy Notice

Your privacy matters to us

We are Firebird Data Protection Consultancy Limited (Firebird). We provide specialist data protection advice, guidance, training and outsourced Data Protection Officer (DPO) services to help organisations meet their obligations under the UK GDPR and Data Protection Act 2018.


Firebird is a private limited company registered in England and Wales under company number 10841251. Our registered office is 20–22 Wenlock Road, London, N1 7GU and our ICO registration number is ZA288370.


We act as the data controller for personal data we process about enquirers, customer representatives, subscribers, prospective customers, associates, website users, job applicants and employees.


We also process personal data as a data processor when we act on behalf of our customers, for example when providing an outsourced DPO service. In these circumstances, we only process personal data in accordance with our customer’s instructions and the terms of our contract with them. 


This Privacy Notice explains what you can expect from us when we process personal data as a data controller.

How we get information

Most of the personal data we process is provided to us directly by you, for example when you:

  • make an enquiry by email, phone or through our website 
  • sign up to our newsletters, blogs and promotions
  • apply to work with us
  • work with us as an associate or employee
  • use our website

We may also collect personal information about you indirectly, for example through:

  • our customers
  • public sources (e.g. websites and professional networking sites)
  • recruitment agencies

Personal data collected and how it is handled

Enquirers 

When someone contacts us asking about our services through our website, by email or over the telephone, we collect their name, contact details and the nature of their enquiry. We collect this information for our legitimate interests as a company,  ie to be able to respond to their enquiry and keep a record of our communications with them. We keep this information for 2 years from the date of the last communication.


Customers

We collect the name and contact details of our customers and information about the service they have purchased. We need this information so we can fulfil our contract with the customer, or take steps at the request of the customer, prior to entering into a contract with them. We also collect this information for our legitimate interests in maintaining records for accounting, legal and insurance purposes. We keep this information for as long as we need to, to satisfy any contractual, legal, accounting, or reporting obligations, however this is usually archived and kept for 7 years after the contract has ended. We use Stripe to take our online payments. We do not process any credit or debit card details of our customers.  For information about how Stipe handles personal data, see their Privacy Policy 


Subscribers 

We collect the name and contact details of people who want to subscribe to our newsletters, resources, blogs and promotions. We collect this information with the consent of the individual when they opt-in to receive these communications. If a person unsubscribes, we remove them from our mailing list but retain their contact details in a separate database. We need to retain this information for our legitimate interests, to ensure we do not contact them again in the future. We keep subscriber data until they unsubscribe, if the email address becomes invalid or if we no longer believe they want to receive our communications. We retain the contact details of those who have unsubscribed indefinitely.


Training delegates

We collect the name and contact details of individuals who enquire about or book onto our training sessions. We process this information to pursue our legitimate interests, ie to register the individual on the training and/or to let them know about future training events which we believe they may be interested in attending. Delegates can opt-out from receiving communications about future training events at any time by emailing DPO@firebirdltd.co.uk.  We keep delegate contact details for as long as we believe they may be interested in receiving communications about our training events, or until they unsubscribe.


Customer leads

We sometimes collect the name, job role and work contact details of employees working for potential customers, who we think would be interested in receiving information about our company’s services; this is known as ‘B2B’ or ‘business to business’ marketing. This information is only collected from public sources, such as company or school websites or where the employee has published their name, work profile and contact details on a networking site for professionals, (such as LinkedIn) and therefore would have a reasonable expectation that companies like us, may contact them to make introductions and market their services. 


We collect this information to pursue our legitimate interests, ie to be able to promote and market our services to potential new customers. Contact leads can opt-out from receiving communications from us at any time by emailing DPO@firebirdltd.co.uk We keep this information for 2 years from the date of our last communication where the communication does not lead to a sale. If the communication does lead to a sale, this information will be retained in line with our retention period for customers (7 years after the contract has ended).


Associates

We collect information about our business associates, such as their name, contact details, experience, outcome of their criminal record check (DBS) (where required), service contract and bank details. We collect this information for our legitimate interests, to be able to assess the suitability of the individual and to enable us to fulfil our contract with them or to take steps at their request, prior to entering into a contract with them. We keep associate files for 7 years after their contract has ended.


Job applicants

We receive Curriculum Vitae (CVs) from people who apply for jobs with us. This will often include the individual’s name, contact details, experience, education and a personal statement to support their application. We collect this information for our legitimate interests ie to  assess the suitability of the individual and where relevant invite them to interview.  We also process this information in order to take steps at the request of the applicant prior to entering  into a contract with them. Applicants who are not successful, prior to or after interview, their CV and application will be destroyed after 6 months, unless the applicant gives us their permission to retain this information for longer.  Information relating to successful applicants, will be retained on their employee file and held for the duration of their employment, plus a further 7 years after their contract has ended. 


Employees

We collect information about our employees, such as their name, date of birth, contact details, recruitment information, evidence of their right to work, outcome of their criminal record check (DBS), references, contract, bank details and other employment information. We collect this information to enable us to fulfil our contract with the employee or to take steps at the request of the employee, prior to entering into a contract with them. For example, to ensure they are paid; make pension and tax contributions on their behalf and provide employee services and benefits to them. We also collect this information to pursue our legitimate interests, for example to recruit employees, maintain a register of our employees (past and present) for insurance, legal, tax and pension purposes and to assist in the prevention or detection of crime (including fraud).


We sometimes collect ‘special category data’ about our employees, for example information about their disabilities, health and dietary needs or religious beliefs. We process this information to fulfil our contract  with the employee (or in order to take steps at the request of the data subject prior to entering into a contract with them) and to carry out our obligations or exercise our or our employees' rights in relation to employment, social security or social protection. We keep employee files for 7 years after the contract has ended.  


Website users

When you visit our website, we collect limited technical information about how the website is accessed and used. We use cookies and similar technologies that are necessary for the website to operate. If you choose Accept on our cookie banner, we also use optional tracking technologies to help us understand website traffic, measure website performance and assess the effectiveness of our advertising, including Google Ads.


Depending on the technology used, this information may include your browser or device information, online identifiers, pages visited, how you arrived at our website and your interaction with our website or advertising.  We use this information to operate and improve our website and, where you have consented, to measure the effectiveness of our advertising. Where optional cookies or similar technologies require consent, we rely on your consent. Essential website technologies are used where they are needed for the website to function. 


We do not use this information to identify you by name.


The length of time cookies remain on your device varies depending on the technology used. Further information about the cookies and similar technologies we use, their purposes and duration is available in our Cookie Policy

Who we share information with

We do not share your data with other organisations, unless it is necessary for our legitimate interests, legal, contractual, regulatory or law enforcement purposes. Where we use 'data processors’ to help us manage and store our data (cloud storage providers); promote our services (advertising/marketing companies) or help us deliver our services (business associates), we have Data Processing Agreements  in place, to protect any personal data they may have access to on our behalf.


Our data processors only act on our instructions and are carefully selected to ensure they have robust security measures in place and comply with the UK data protection legislation when processing personal data. 


Where we process your personal data as a 'data processor’ for our customers, your personal data (eg communications with us) may be shared with that customer, to enable us to fulfil our contract with them.


There may be times when we need to disclose personal data to other data controllers, for example:

  • In the event that we sell our company or its assets
  • If you provide us with your consent
  • If we are under a duty to disclose your personal data, for example in response to a court order, request from law enforcement agencies or to report safeguarding concerns.
  • To enforce or apply our terms and conditions and other agreements.
  • To protect the rights, property, or safety of Firebird and its employees, our customers, or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection.

Website and advertising providers

We use third-party service providers to operate our website and, where you have consented, to measure website usage and advertising performance. These include GoDaddy, which provides our website platform and related website services, and Google, which provides advertising and measurement services in connection with Google Ads.


These providers may receive technical information and online identifiers generated when you use our website, depending on the services enabled and the choices you make through our cookie banner. Further information about the specific cookies and technologies used is available in our Cookie Policy.

Where we store data

Our core business records are stored within the UK or EEA. Some of our website and advertising providers, GoDaddy and Google, may process personal data outside the UK. Where this happens, appropriate international transfer safeguards are built into our contractual arrangements with those providers, including recognised adequacy arrangements and approved contractual transfer mechanisms where required. 


GoDaddy - Data Processing Addendum

Google Advertising and Analytics - International Data Transfers

How we protect your information

We take the security of personal data seriously and use appropriate technical and organisational measures to protect it against accidental or unlawful access, disclosure, loss, alteration or destruction.

These measures include:

  • restricting access to personal data to those who need it for their role; 
  • requiring employees, associates and service providers to maintain confidentiality; 
  • providing appropriate data protection and security training; 
  • maintaining procedures for identifying, managing and reporting personal data breaches; 
  • carrying out proportionate due diligence on service providers that process personal data on our behalf and putting appropriate contractual safeguards in place; 
  • using appropriate technical security measures to protect our systems and information; and 
  • keeping our security arrangements under review and updating them where necessary.

Your data protection rights

You have the following rights under the data protection laws:


Right to know

You have the right to be told how your personal data is being processed. This privacy notice tells you how we handle your personal data.


Right of access

You have the right to ask us for a copy of your personal data.


Right to rectification 

You have the right to ask us to rectify information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete. 


Right to erasure

You can ask us to delete your personal data where we no longer need it, you withdraw consent, you successfully object, or we have no lawful reason to keep it. 


Right to restriction of processing

You can ask us to limit how we use your personal data while we check its accuracy, our lawful basis, or whether it should continue to be processed. 


Right to object to processing

You have the right to object to us processing your personal data where we rely on legitimate interests as our lawful basis for processing. You also have an absolute right to object to us using your personal data for direct marketing purposes.


Right to data portability

You have the right to ask that your personal data is transferred (ported) from us to another organisation or given to you.  This applies to information you have given to us where we are processing your information based on your consent or for contractual purposes and the processing is automated.


Right to complain

We work to high standards when it comes to processing your personal data. We hope you will always be happy with the way we handle your information, however if we have not met your expectations, please let us know so we can put things right. If you remain dissatisfied, you have the right to complain to the Information Commissioner’s Office.


To exercise any of these rights, please contact us by emailing DPO@firebirdltd.co.uk  You are not usually required to pay a fee and can expect to receive a response within one calendar month. 

Contact Us

If you have any queries about this privacy notice or want to exercise any of your data protection rights, please email us at  DPO@firebirdltd.co.uk 

Changes to this privacy notice

This version was last updated on the 21 September 2026.

We may update this Privacy Notice from time to time to reflect changes in our services, how we use personal data, or changes in the law. We recommend checking this page periodically for the latest version. 

Copyright ©2026 Firebird Data Protection Consultancy Limited - All Rights Reserved.

Firebird is a private limited company registered in England & Wales (10841251) .  

Registered address 20-22 Wenlock Road. London, N1 7GU. Telephone: 01392 344392


  • About Us
  • Our Services
  • Schools and EdTech
  • Small, Medium Businesses
  • Large Organisations
  • Insights
  • Contact Us
  • Testimonials
  • FAQ's
  • Terms and Conditions
  • Cookies
  • Our Compliance
  • Safeguarding
  • Privacy Notice
  • Equality and Diversity
  • Make a Complaint

Powered by

Cookies on this website

We use essential cookies to make our website work. If you choose Accept, we will also use cookies to help us understand website traffic and measure the performance of our website and advertising.

You can choose Accept or Decline. You can find out more in our Cookie Policy

DeclineAccept