Privacy Policy
Last updated: 1 July 2026
Brighthaven Digital Ltd ("Brighthaven Digital", "we", "us" or "our") is committed to protecting the personal data of everyone who visits this website, enquires about our services or works with us as a client, supplier or candidate. This policy explains what we collect, why we collect it, how long we keep it and what rights you have.
For the purposes of the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018, Brighthaven Digital Ltd is the data controller for the personal data described in this policy.
On this page
1. Who we are
Brighthaven Digital Ltd is a company registered in England and Wales (company number 00000000). Our registered office and principal place of business is Brighthaven House, 12 Waterloo Street, Birmingham, B2 5TB, United Kingdom.
We are a performance marketing agency. In the course of delivering campaigns for our clients we sometimes act as a data processor on their behalf — for example when we configure advertising audiences using data a client supplies. In those cases the client is the controller and their own privacy notice governs the processing, supported by a written data processing agreement with us.
2. What personal data we collect
2.1 Information you give us
- Enquiry details — your name, company, work email address, telephone number, indicative budget and the content of your message when you complete a form or email us.
- Client relationship data — contact details of your team, contractual information, billing details and correspondence.
- Recruitment data — your CV, work history and any information you include in an application.
- Event and subscription data — your name and email address if you register for a webinar or subscribe to our insight emails.
2.2 Information we collect automatically
- Technical data — IP address (truncated where possible), browser type and version, operating system, device type, screen size and approximate location derived from your IP address.
- Usage data — pages viewed, time on page, referring URL, links clicked and the search terms that brought you here.
We collect automatic data only where you have consented to non-essential cookies, or where a cookie is strictly necessary for the site to function. See our Cookie Policy for detail.
2.3 Information from third parties
We may receive your business contact details from professional networks such as LinkedIn, from publicly available company registers, from mutual clients who refer you, or from event organisers where you have consented to your details being shared with sponsors.
We do not knowingly collect special category data (such as health, ethnicity, religious belief or biometric data) through this website, and we ask that you do not include such information in enquiry forms.
3. Why we use your personal data and our lawful bases
| Purpose | Data used | Lawful basis |
|---|---|---|
| Responding to your enquiry and preparing a proposal | Enquiry details | Legitimate interests — responding to a request you initiated |
| Delivering services under a contract | Client relationship data | Performance of a contract |
| Invoicing, accounting and tax records | Billing data | Legal obligation |
| Sending insight emails and event invitations | Name, email | Consent, withdrawable at any time |
| Measuring website performance and improving content | Technical and usage data | Consent, via our cookie banner |
| Assessing job applications | Recruitment data | Legitimate interests and, where relevant, legal obligation |
| Preventing fraud, securing our systems and enforcing our terms | Technical data, correspondence | Legitimate interests — protecting our business |
Where we rely on legitimate interests, we have carried out a balancing assessment and are satisfied that our interests do not override your rights and freedoms. You may ask us for a summary of that assessment at any time.
4. Who we share your personal data with
We do not sell personal data. We share it only with the following categories of recipient, and only to the extent necessary:
- Technology providers that host our website, email, customer relationship management and file storage systems, acting as processors under contract.
- Advertising and analytics platforms — principally Google and Microsoft — where you have consented to the relevant cookies.
- Professional advisers including our accountants, auditors, insurers and legal advisers, where they need the information to advise us.
- Regulators and law enforcement, where we are legally required to disclose information.
- An acquirer, if our business or part of it is sold or reorganised, subject to appropriate confidentiality protections.
5. International transfers
Some of our providers process data outside the United Kingdom, principally in the European Economic Area and the United States. Where personal data leaves the UK, we rely on one of the following safeguards: an adequacy decision made by the UK government (including the UK Extension to the EU–US Data Privacy Framework), the International Data Transfer Agreement, or the UK Addendum to the European Commission's Standard Contractual Clauses, in each case supported by a transfer risk assessment.
6. How long we keep your personal data
| Record type | Retention period |
|---|---|
| Unsuccessful enquiries | 24 months from last contact |
| Client contracts and correspondence | 7 years after the engagement ends |
| Accounting and tax records | 7 years, as required by HMRC |
| Marketing subscriber records | Until you unsubscribe, then 12 months of suppression data |
| Unsuccessful job applications | 12 months, unless you ask us to keep them longer |
| Website analytics | 14 months |
At the end of the applicable period we delete or irreversibly anonymise the data.
7. How we protect your personal data
We apply technical and organisational measures appropriate to the risk, including encryption in transit (TLS) and at rest, role-based access control, mandatory multi-factor authentication on all business systems, least-privilege administration, logging and monitoring, annual security awareness training for all staff, and documented supplier due diligence. We maintain an incident response procedure and will notify the Information Commissioner's Office within 72 hours of becoming aware of a reportable personal data breach, and will notify you directly where the breach is likely to result in a high risk to your rights and freedoms.
8. Your rights
Under the UK GDPR you have the right to:
- Be informed about how we use your data — this policy is part of meeting that obligation.
- Access a copy of the personal data we hold about you.
- Rectification of inaccurate or incomplete data.
- Erasure of your data where there is no continuing lawful reason for us to hold it.
- Restrict processing while a concern you have raised is investigated.
- Data portability — to receive certain data in a structured, machine-readable format.
- Object to processing based on legitimate interests, and to direct marketing at any time.
- Withdraw consent where consent is our lawful basis, without affecting the lawfulness of earlier processing.
- Not be subject to solely automated decision-making that has a legal or similarly significant effect on you. We do not carry out such decision-making.
To exercise any right, email [email protected] with the subject line "Data rights request". We respond within one month and may extend this by two further months for complex requests, telling you if we do. We do not charge a fee unless a request is manifestly unfounded or excessive.
If you are unhappy with how we have handled your data, please contact us first so we can put it right. You also have the right to complain to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF — telephone 0303 123 1113, ico.org.uk.
9. Cookies and similar technologies
We use a small number of cookies and comparable technologies. Non-essential cookies are set only after you consent, and you can change or withdraw that consent at any time. Full detail, including a category-by-category table, is in our Cookie Policy.
10. Children's data
Our services are sold business-to-business and this website is not directed at children. We do not knowingly collect personal data relating to anyone under 18. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Changes to this policy
We review this policy at least annually and whenever our processing changes materially. The date at the top of the page shows when it was last updated. Where changes are significant we will notify clients and subscribers directly.
12. How to contact us
Brighthaven Digital Ltd
Data Protection Enquiries
Brighthaven House, 12 Waterloo Street
Birmingham, B2 5TB, United Kingdom
Email: [email protected]