Privacy and Data Protection Policy

JNF Consultancy Ltd — jnfconsultancylimited.co.uk
Privacy & Data Protection

Privacy and Data Protection Policy

Policy Date: 8 September 2026
Review Date: 8 September 2027

1. About this policy

At JNF Consultancy Ltd, we understand that people who contact us, use our services or visit our website need to know what happens to their personal information.

This policy explains, in straightforward terms, what information we may collect, why we need it, how we look after it and what rights individuals have in relation to their information.

We take the privacy of our clients, learners, applicants, business contacts, website visitors and other individuals we deal with seriously. We will only collect and use personal information where we have a proper reason to do so and will handle it responsibly.

JNF Consultancy Ltd is committed to complying with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and other data protection and privacy requirements that apply to our work.

2. Who is responsible for your information?

JNF Consultancy Ltd is responsible for deciding how and why personal information is used for our business activities.

Organisation: JNF Consultancy Ltd
Website: jnfconsultancylimited.co.uk

If you have any questions about this policy or about the way we handle your personal information, you can contact us through the contact details provided on our website.

3. Information we may collect

The information we collect depends on the reason you are dealing with us.

For example, when someone contacts JNF Consultancy Ltd, we may receive their:

  • name;
  • email address;
  • telephone number;
  • address or other contact details;
  • information provided in an enquiry;
  • information relating to a course, service or support they are interested in;
  • information supplied as part of an application or registration;
  • correspondence between the individual and JNF Consultancy Ltd; and
  • other information the individual chooses to provide.

When people use our website, we may also receive technical information such as an IP address, browser type, device information and information about how the website is used.

We do not ask people to provide personal information that we do not reasonably need.

4. How we collect information

Most of the information we hold is provided directly by the individual.

This can happen when someone:

  • contacts us by email or telephone;
  • completes an enquiry form on our website;
  • asks about one of our services;
  • registers for a service or programme;
  • communicates with a member of our organisation;
  • submits information or documents to us; or
  • uses our website.

In some circumstances, information may also be provided by another organisation where this is necessary and lawful for us to provide a service or meet our responsibilities.

5. Why we use personal information

We use personal information for genuine business and service-related purposes.

Depending on the circumstances, this may include:

  • responding to enquiries;
  • arranging and providing services;
  • communicating with clients, learners and other contacts;
  • managing applications and registrations;
  • providing information about our services;
  • maintaining accurate business records;
  • managing appointments and correspondence;
  • improving the services we provide;
  • maintaining the security of our website and systems;
  • dealing with complaints or enquiries;
  • meeting contractual responsibilities;
  • complying with legal or regulatory requirements; and
  • protecting our organisation, staff, clients and other individuals where necessary.

We will not routinely use someone’s information for a completely unrelated purpose without considering whether there is a lawful basis for doing so and whether the individual needs to be informed.

6. Our legal basis for using information

Data protection law requires organisations to have a lawful basis for using personal information.

Depending on the circumstances, JNF Consultancy Ltd may rely on:

  • Consent – where an individual has actively agreed that we can use their information for a particular purpose.
  • Contract – where the information is necessary to provide a service or take steps at the individual’s request before entering into an agreement.
  • Legal obligation – where we are required by law to keep or provide certain information.
  • Legitimate interests – where using information is necessary for a genuine business purpose and this does not unfairly override the individual’s rights and interests.

We will consider the appropriate lawful basis for the particular processing activity rather than assuming that one basis applies to everything we do.

7. Keeping information accurate

We try to make sure that the information we hold is accurate and up to date.

If you notice that information we hold about you is incorrect, please let us know. We will consider the request and correct information where appropriate.

8. Who may receive personal information?

We do not sell personal information to other organisations.

There may, however, be occasions when information needs to be shared with another organisation or service provider.

For example, information may be shared where necessary with:

  • organisations supporting us with IT or website services;
  • professional advisers;
  • service providers working on our behalf;
  • relevant regulatory or public authorities;
  • organisations involved in delivering a service where this is necessary and lawful; or
  • law enforcement or other authorities where we are legally required to provide information.

Where another organisation processes information for us, we expect appropriate confidentiality and security arrangements to be in place.

We only share information that is appropriate for the particular purpose.

9. How we protect information

We take reasonable steps to protect personal information from being lost, misused, accessed without permission or disclosed incorrectly.

This includes appropriate controls around:

  • access to information;
  • passwords and accounts;
  • electronic systems;
  • physical documents;
  • staff access to personal information; and
  • the secure disposal of information when it is no longer required.

Not everyone working with JNF Consultancy Ltd will have access to all personal information. Access is limited according to what is reasonably required for someone’s role.

10. How long we keep information

We do not keep personal information indefinitely.

The length of time information is kept depends on what it is and why we collected it.

For example, some information may need to be retained for longer because of accounting, contractual, regulatory or legal requirements. Other information may only need to be kept while an enquiry or service is being dealt with.

When information is no longer needed, we will arrange for it to be securely deleted, destroyed or otherwise disposed of where appropriate.

11. Your rights

People have important rights over their personal information under UK data protection law.

Depending on the circumstances, you may have the right to:

  • ask what personal information we hold about you;
  • request a copy of your information;
  • ask us to correct information that is inaccurate;
  • ask us to delete information in certain circumstances;
  • ask us to restrict how we use information in certain circumstances;
  • object to certain uses of your information;
  • request transfer of information in certain circumstances; and
  • withdraw consent where we are relying on consent.

These rights are subject to certain legal conditions and exemptions, so not every request will apply in every situation.

12. Making a request

If you would like to exercise one of your data protection rights, please contact JNF Consultancy Ltd using the contact details on our website.

We may need to ask for enough information to confirm your identity before providing personal information or making changes to our records.

We will deal with requests within the timescale required by data protection legislation.

13. Website privacy

Our website may collect limited information when people visit or use it.

For example, our website may receive technical information about the device and browser being used and information about how the website is accessed.

If you voluntarily complete a contact or enquiry form, the information you provide will be used to respond to your request and deal with the matter you have contacted us about.

We do not use information submitted through our website for purposes unrelated to the enquiry without a lawful basis for doing so.

14. Cookies

Our website does not currently use cookies or similar tracking technologies.

This means we do not set analytics, advertising, preference or other non-essential cookies, and there is no cookie consent banner or separate Cookie Policy.

If this changes in the future, we will update this policy and, where the law requires consent before using a particular cookie or similar technology, we will provide appropriate information and ask for consent first.

15. Marketing communications

If we send information about our services or other communications that amount to direct marketing, we will do so in accordance with applicable privacy and electronic communications requirements.

Where an individual has the right to opt out, we will provide a straightforward way to do so.

You can also contact us if you no longer wish to receive marketing communications from us.

16. Information relating to children and young people

Because our work may involve education, training and support services, we may sometimes handle information relating to children or young people.

Where this occurs, we recognise that additional care may be appropriate.

We will only collect and use information about children where there is a legitimate reason to do so and will apply appropriate safeguards to protect that information.

Where consent is required, we will follow the relevant legal requirements.

17. Third-party websites

Our website may contain links to websites operated by other organisations.

Once you leave the JNF Consultancy Ltd website, the other organisation’s privacy arrangements will apply.

We recommend that you read the privacy and cookie information of any external website before providing personal information.

18. Data breaches and security incidents

If we become aware of a personal data breach, we will assess what has happened and take appropriate action to contain and investigate the incident.

Where the law requires us to notify the Information Commissioner’s Office or affected individuals, we will do so within the applicable legal timescales.

We will also take reasonable steps to prevent the same type of incident happening again.

19. Complaints

We hope that anyone with a concern about their personal information will contact us first so that we have an opportunity to understand and resolve the issue.

If you are not satisfied with how we have handled your personal information, you have the right to complain to the Information Commissioner’s Office (ICO).

The ICO is the UK’s independent data protection regulator.

20. Changes to this policy

We may update this policy from time to time.

For example, we may update it when our services change, when we introduce new website functionality or when data protection requirements change.

The latest version will be published on our website and will show the date it was last updated.

21. Contacting us

If you have a question about this Privacy and Data Protection Policy, want to exercise a data protection right, or have a concern about how we have handled your information, please contact:

JNF Consultancy Ltd
Website: jnfconsultancylimited.co.uk
Contact details are available on our website.

Policy owner: JNF Consultancy Ltd
Effective date: 8 September 2026
Next review: 8 September 2027

Are you ready to take your career to new heights?

Our team of experienced professionals is here to help you achieve your goals.

Get in Touch