LEGAL & PRIVACY

Privacy Notice

Privacy Notice

Privacy Notice

Last updated: 25 August 2026

Richmond Statutory Consultancy Limited respects your privacy and is committed to protecting personal information. This Privacy Notice explains how we collect, use, store, disclose and protect personal information when you visit our website, submit a Confidential Review enquiry, contact us, become a client, act as a professional adviser or referral partner, correspond with us in connection with a client matter, or otherwise interact with Richmond Statutory Consultancy Limited. This notice also explains your rights under UK data protection law.

1. Who we are

Richmond Statutory Consultancy Limited is a specialist UK advisory business focused on adverse data remediation, AML/KYC screening issues, data accuracy, privacy rights and onboarding friction. Legal entity: Richmond Statutory Consultancy Limited. Company number: 17322515. Registered office: Onsite Lodge, Mansfield Road, Eastwood, United Kingdom, NG16 3AR. Website: www.richmondstatutory.co.uk. General enquiries: enquiries@richmondstatutory.co.uk. Data protection contact: privacy@richmondstatutory.co.uk. ICO registration number: [insert once issued]. For the purposes of UK data protection law, Richmond Statutory Consultancy Limited is generally the controller of the personal information described in this Privacy Notice.

2. The personal information we may collect

The information we collect depends on the nature of your relationship with us and the services you request. We may collect identity and contact information, including your full name, email address, telephone number, correspondence address, company or organisation name, job title or professional role, and preferred method of contact. We may collect enquiry and matter information, including information provided through our Confidential Review form; the nature of the issue; organisations, financial institutions or data providers involved; relevant dates and deadlines; prior complaints, DSARs, rectification requests or correspondence; professional advisers involved; and information about banking, lending, investment, payment, insurance or onboarding difficulties. Where you become a client, we may process correspondence, screening or risk-data reports, DSAR responses, adverse-media material, archived publications, corporate records, court or regulatory material, complaint responses, institutional communications, chronology and evidence documents, and material supplied by you or your professional advisers. When you use our website, we may receive limited technical and usage information through Framer’s built-in infrastructure and analytics, including aggregated or anonymised page views, pages visited, interactions, form-submission events, approximate country, device type, browser, operating system and referring source. Framer states that its analytics do not use cookies or persistent visitor identifiers. We do not currently use Google Analytics, Meta Pixel, LinkedIn Insight Tag, Microsoft Clarity, Hotjar or similar third-party behavioural-tracking technologies. Please see our Cookie Policy for further information.

3. Sensitive information

Because of the nature of our work, some matters may involve special category personal data, for example information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health information, sexual orientation, or biometric or genetic information. We may also process criminal offence data, including criminal convictions, alleged offences, prosecutions, sentences, related legal or enforcement proceedings, or information identifying an individual as an alleged or convicted offender. We do not ask prospective clients to submit unnecessary sensitive information through the initial public enquiry form. Where sensitive information is required for a matter, we process only what is reasonably necessary for the relevant purpose and apply additional safeguards where appropriate.

4. How we obtain personal information

We may obtain personal information directly from you when you submit an enquiry, complete our Confidential Review form, provide documents, speak with us, enter into an engagement or correspond with us. We may receive information from professional advisers, including solicitors, accountants, brokers, wealth advisers, compliance professionals, family offices and other advisers acting for you. During remediation work we may receive information from banks and financial institutions, screening providers, data brokers, risk-information providers, public authorities, regulators, complaint bodies and other relevant organisations. We may also use publicly available sources, including Companies House, court or tribunal records, regulatory publications, search engines, websites, online archives, press and media sources, sanctions, PEP or risk-related databases where lawfully accessible, and other legitimate public sources.

5. How we use personal information

We use information submitted through the Confidential Review process to understand the issue, assess urgency, determine whether the matter falls within our area of work, decide whether we can assist and contact you regarding next steps. Where you engage us, we may investigate adverse-data or AML/KYC friction; build chronologies and evidence records; conduct source mapping; prepare data-rights requests, complaints and escalation materials; correspond with relevant organisations; review responses; prepare institutional explanation packs; and provide remediation strategy and ongoing support. We use contact details to respond to enquiries, provide updates, request information, arrange consultations and communicate about your matter. We also maintain records, issue invoices, manage accounts, protect legal rights, manage complaints, comply with legal and regulatory obligations, maintain security and prevent misuse. Aggregated and anonymised website-usage information may be used to improve website structure and content, monitor performance and diagnose technical issues. We do not use website analytics for behavioural advertising or individual visitor profiling.

6. Our lawful bases for processing

Depending on the circumstances, we may rely on contract and steps prior to contract to assess a request for services, take steps at your request before engagement, or perform contractual obligations. We may rely on legitimate interests where necessary to operate and administer our consultancy, assess enquiries, communicate with professional advisers, maintain records, protect our business and systems, deal with complaints, establish and defend rights, and improve services and the website, provided those interests are not overridden by your rights and interests. We may process information where necessary to comply with legal obligations. In limited circumstances we may rely on consent; where processing is based on consent, you may withdraw it at any time without affecting prior lawful processing.

7. Special category personal data

Where we process special category personal data, we must have both an Article 6 lawful basis and an additional condition under Article 9 UK GDPR. Depending on the circumstances, this may include processing necessary for the establishment, exercise or defence of legal claims or legal rights; reasons of substantial public interest where a relevant Data Protection Act 2018 condition applies; or your explicit consent where appropriate. The appropriate condition depends on the specific purpose and circumstances. We will not process special category information merely because it is available.

8. Criminal offence data

Some Clean Slate matters may involve criminal conviction or offence information. Where we process criminal offence data, we must have an Article 6 lawful basis and a relevant condition under Schedule 1 of the Data Protection Act 2018, unless processing is under official authority. Depending on the circumstances, relevant conditions may include your consent, processing necessary for legal claims or rights, or another applicable Schedule 1 condition. We assess the appropriate condition case by case. Where required, we will maintain an Appropriate Policy Document describing safeguards, retention and procedures. We apply particular care to the minimisation, security and retention of criminal offence data.

9. Information about other people

You may sometimes provide information about another person, for example a director, business associate, family member, professional adviser, employee or person mentioned in relevant correspondence. Please provide another person’s information only where relevant and appropriate for the matter. Where required by law, we may provide privacy information directly to that individual.

10. Who we may share personal information with

We do not sell personal information. We may share information where reasonably necessary with organisations relevant to a client matter, including screening and risk-data providers, data controllers, banks, lenders, investment platforms, insurers, payment providers, public authorities, regulators, complaint-handling bodies, search engines or archive operators and other relevant organisations. Where appropriate, information may be shared with solicitors, barristers, accountants, compliance specialists and other professional advisers. We may use trusted service providers including website hosting, email, secure cloud storage, case-management, IT and cyber-security, communications, accounting and business-administration providers. Our website is built and hosted using Framer, which also provides native form functionality and built-in analytics. We may disclose information to courts, regulators, law enforcement, government bodies, professional advisers and parties in legal proceedings where required or permitted by law.

11. International transfers

Some technology and service providers may process or store personal information outside the United Kingdom. Where information is transferred internationally, we take reasonable steps to ensure appropriate safeguards are used where required by UK data protection law. These may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or other lawful safeguards. Contact us for information about safeguards relevant to a particular transfer.

12. How long we keep personal information

We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, taking into account sensitivity, the purpose of the matter, legal and contractual requirements, complaint or dispute risks, limitation periods and security considerations. An enquiry that does not result in engagement will normally be retained for up to 12 months after the last substantive contact, unless longer retention is justified or earlier deletion is requested where applicable. Client matter information will normally be retained for six years after closing, unless a different legal or contractual period applies, the matter requires longer retention, a dispute or issue is unresolved, or another lawful reason applies. Marketing contact information is retained until you unsubscribe or it is no longer required. Aggregated or anonymised website analytics may be retained in accordance with Framer’s configuration and operational requirements. Sensitive information may be deleted earlier where it is no longer required.

13. How we protect information

We take reasonable technical and organisational measures designed to protect personal information against unauthorised access, loss, misuse, alteration, disclosure and destruction. Measures may include access controls, multi-factor authentication, secure business email, controlled document storage, restricted access to client files, secure sharing methods, supplier due diligence, data minimisation, and retention and deletion procedures. No electronic transmission or storage method is completely secure, but we seek to use measures proportionate to the sensitivity of the information we handle.

14. Confidential Review enquiries

Submitting the Confidential Review form does not create a client relationship, constitute legal advice or guarantee acceptance of your matter. We ask prospective clients not to submit identity documents, bank statements, criminal-record documents or large evidence bundles through the initial public form unless specifically requested. Where a matter proceeds, we may provide a more appropriate method for exchanging sensitive information. The form is provided using Framer’s native functionality. We do not use information submitted through it for behavioural advertising or visitor profiling.

15. Marketing communications

We may send Richmond insights or updates only where permitted by law. Where consent is requested, it is separate from the provision of our services and will not be pre-selected. You may unsubscribe from marketing communications at any time. Service-related communications concerning an enquiry or live matter are not marketing.

16. Website analytics, cookies and tracking

Our website currently uses Framer’s built-in analytics to understand general website usage. Framer states that its analytics do not use cookies, do not create persistent visitor identifiers, and use anonymised website-usage information. We do not currently use Google Analytics, Google Tag Manager, Meta Pixel, LinkedIn Insight Tag, Microsoft Clarity, Hotjar, behavioural advertising, remarketing pixels or similar third-party marketing or profiling technologies. Accordingly, we do not currently use a cookie-consent banner solely for Framer Analytics. If we introduce non-essential cookies or tracking technologies, we will review consent requirements and update controls and policies before activation where required. Please see our separate Cookie Policy.

17. Automated decision-making

Richmond Statutory Consultancy Limited does not currently make decisions about accepting or providing services solely by automated means where those decisions produce legal or similarly significant effects. Enquiries and client matters are reviewed by a person.

18. Your data protection rights

Depending on the circumstances, you may have rights of access, rectification, erasure, restriction, objection, data portability, withdrawal of consent and rights relating to significant automated decisions. To exercise a data protection right, contact privacy@richmondstatutory.co.uk. We may need to verify your identity before acting on a request. Some rights are subject to exemptions and limitations under data protection law.

19. Complaints

If you have concerns about how Richmond Statutory Consultancy Limited handles personal information, please contact us first so that we can try to resolve the issue. Contact: privacy@richmondstatutory.co.uk. You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority for data protection. Information about making a complaint is available at www.ico.org.uk.

20. Third-party websites

Our website may contain links to third-party websites. Richmond Statutory Consultancy Limited is not responsible for their privacy practices. Review the privacy information provided by those organisations before submitting personal information to them.

21. Changes to this Privacy Notice

We may update this Privacy Notice to reflect changes in our services, law or regulatory guidance, technology or service providers, or the way we process personal information. The latest version will be published with an updated revision date. Where a change materially affects how we use existing personal information, we will take reasonable steps to bring it to affected individuals’ attention where required.

22. Contact us

For privacy enquiries or to exercise your data protection rights, contact Richmond Statutory Consultancy Limited. Website: www.richmondstatutory.co.uk. Data protection: privacy@richmondstatutory.co.uk. General enquiries: enquiries@richmondstatutory.co.uk. Registered office: Onsite Lodge, Mansfield Road, Eastwood, United Kingdom, NG16 3AR. Company number: 17322515. ICO registration number: [insert once issued].

RICHMOND STATUTORY CONSULTANCY

Evidence-led adverse data and AML/KYC remediation.

RICHMOND STATUTORY CONSULTANCY

Evidence-led adverse data and AML/KYC remediation.

Company number: 17322515
Registered office: Onsite Lodge, Mansfield Road, Eastwood, Nottinghamshire, NG16 3AR

Richmond Statutory Consultancy is not a law firm and does not provide reserved legal services.