Privacy Policy
Data Controller
Juliet Kelly
Collected Personal Data
This Privacy Policy explains how Horizon Risk & Assurance (“we”, “us”, “our”) collects, uses, stores, and protects personal information when you visit our website or interact with our services. We are committed to safeguarding your privacy and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Data We Collect
We collect only the information necessary to operate our website, respond to enquiries, and deliver our consultancy services.
2.1 Information You Provide Directly
Contact form submissions – name, email address, phone number, organisation, and any information you include in your message.
Email enquiries – any information you voluntarily provide when contacting us.
Service engagement information – if you become a client, we may collect additional business contact details and documentation relevant to the consultancy work.
2.2 Information Collected Automatically
When you visit our website, certain technical data may be collected automatically:
IP address
Browser type and version
Device information
Pages visited and time spent on the site
Referring website or search engine
This information is typically collected through standard server logs or analytics tools.
2.3 Cookies and Tracking Technologies
If cookies are used on your site, they may collect:
Website usage analytics
Preferences (e.g., language settings)
Session information
You can manage cookies through your browser settings.
Purpose for Collecting Data
We collect and process personal data for the following purposes:
Responding to enquiries submitted through the website or email.
Providing consultancy services and maintaining client relationships.
Improving website functionality, security, and user experience.
Maintaining internal records for business administration.
Complying with legal or regulatory obligations, including risk, compliance, and assurance requirements.
We do not sell or share your personal data with third parties for marketing purposes.
3. Legal Basis for Processing
We process personal data under the following lawful bases:
Consent – when you submit a contact form or sign up for communications.
Contract – when we need information to deliver consultancy services.
Legitimate interests – website analytics, security monitoring, and business administration.
Legal obligation – where required for regulatory compliance.
4. Data Sharing
We may share personal data only with:
Service providers who support website hosting, email services, or analytics (all bound by GDPR-compliant agreements).
Regulators or authorities where legally required.
We do not share data with third parties for advertising or commercial resale.
5. Data Storage and Security
We implement appropriate technical and organisational measures to protect your data, including:
Secure hosting environments
Access controls
Encryption where appropriate
Regular security reviews
Data is stored within the UK or EEA unless otherwise stated, and any international transfers will follow GDPR safeguards.
6. Data Retention
We retain personal data only for as long as necessary:
Contact enquiries: typically 12 months
Client records: retained in line with professional, regulatory, and legal requirements
Analytics data: retained according to the settings of the analytics provider
7. Your Rights
Under UK GDPR, you have the right to:
Access your personal data
Request correction of inaccurate data
Request deletion of your data
Object to processing
Request restriction of processing
Withdraw consent at any time
Lodge a complaint with the Information Commissioner’s Office (ICO)
8. Third‑Party Links
Our website may contain links to external sites. We are not responsible for the privacy practices or content of those websites.
9. Contact Us
For questions about this Privacy Policy or to exercise your rights, contact:
Horizon Risk & Assurance Email: info@horizonriskassurance.co.uk Address: 20 Reedmace Walk, Morecambe, Lancashire UK LA32 3QW