Privacy Policy

Effective Date: 10 July 2025

Beyond P4C (“we”, “us”, or “our”) is committed to protecting your personal data and privacy. This Privacy Policy explains how we collect, use, share, and store personal information through our website www.beyondp4c.co.uk, during the provision of our services, and in our business relationships with clients, suppliers, consultants, contractors, and applicants.

We process your data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.


 

1. Who We Are

Beyond P4C is a UK based digital consultancy supporting charities and non profits with digital transformation and innovation.

Company name: Beyond P4C Ltd
Company number: 16348263
Registered office address:
2nd Floor College House, 17, King Edwards Road, Ruislip, London, United Kingdom, HA4 7AE

Contact us:
Email: hello@beyondp4c.co.uk
Data Controller: Beyond P4C Ltd


 

2. What Information We Collect

We may collect and process the following types of personal data:

  • Contact information: Name, email address, phone number, job title, organisation

  • Technical data: IP address, browser type, operating system, pages visited (via cookies and analytics tools)

  • Marketing preferences: Communication preferences, opt-in status

  • Financial information: Invoicing details, bank account information, payment history (for clients and suppliers)

  • Employment/consultancy data: CVs, references, right to work documents, contracts, payment information

  • Sensitive data: Where strictly necessary, we may process special category data on behalf of clients (e.g. safeguarding, health-related data)


 

3. How We Use Your Information

We use your personal data to:

  • Provide and manage services to clients

  • Respond to enquiries and communicate with you

  • Manage contracts with clients, suppliers, and consultants

  • Process payments and issue invoices

  • Evaluate applications for employment or consultancy

  • Monitor and improve our website performance

  • Comply with legal and regulatory obligations

  • Carry out Data Protection Impact Assessments (DPIAs) where required


 

4. Legal Basis for Processing

We process your data under the following lawful bases:

  • Consent – for marketing and non-essential cookies

  • Contractual necessity – to fulfil a contract or take steps at your request

  • Legitimate interests – to operate and grow our business (e.g., analytics, business development)

  • Legal obligation – for record-keeping, tax, or safeguarding compliance


 

5. Cookies and Tracking

We use cookies and similar technologies to enhance your browsing experience, monitor website performance, and deliver relevant content.

Cookie usage on our site includes:

  • Essential cookies – to ensure the site functions properly

  • Analytics cookies – to understand user behaviour (via Google Analytics and Microsoft Clarity)

  • Marketing cookies – for tracking interactions and enabling targeted communications (e.g. via HubSpot and Bing Ads)

Our cookie preferences and consent banner are managed by HubSpot. When you first visit our website, you will be presented with a cookie consent notice where you can choose to accept all cookies or manage your preferences.

You can update or withdraw your consent at any time by clicking the “Cookie Settings” link in the footer of our site or adjusting your browser settings.


 

6. Who We Share Data With

We only share your personal data with trusted third parties, where necessary:

  • CRM & marketing platforms: HubSpot

  • Analytics tools: Google, Microsoft (Clarity/Bing)

  • Finance & invoicing software: [e.g., Xero, QuickBooks, or “accounting systems”]

  • Freelancers/consultants: under contract and NDA, if needed to deliver services

  • Payroll or HR platforms: if you are engaged by us

  • Legal or government authorities: such as HMRC or Companies House, if required

We do not sell your personal data. All third-party processors comply with GDPR or equivalent safeguards.


 

7. How We Store and Protect Your Data

All data is securely stored using encrypted, access-controlled platforms.
We only use services hosted within the United Kingdom or the European Economic Area (EEA), ensuring all data remains under UK/EU data protection laws.

Where data is transferred outside these regions, we ensure appropriate safeguards such as Standard Contractual Clauses (SCCs) are in place.


 

8. How Long We Keep Your Data

We only retain data for as long as necessary:

  • Client and contract data: Up to 7 years for legal/accounting purposes

  • Financial data: Minimum 6 years (as required by UK tax law)

  • Recruitment/consultancy applications: Up to 12 months if unsuccessful

  • Marketing data: Until you unsubscribe or withdraw consent

  • Sensitive or special category data: Only for the duration and purpose of the client agreement, then securely deleted


 

9. Your Rights Under UK GDPR

You have the following rights under UK GDPR:

  • Access the personal data we hold about you

  • Correct inaccurate or incomplete data

  • Request erasure of your data

  • Restrict or object to certain types of processing

  • Receive your data in a portable format

  • Withdraw your consent (where processing is based on consent)

  • Lodge a complaint with the Information Commissioner’s Office (ICO)

To exercise your rights, contact:
Telephone Number: 0303 123 1113 
ICO website: https://ico.org.uk


 

10. Recruitment and Consultants

If you apply to work with Beyond P4C as an employee or consultant, we may collect and process your personal data to assess your suitability and manage onboarding if successful. This may include references, proof of eligibility to work in the UK, and payment information.

Unsuccessful applications will be deleted after 12 months unless you consent to a longer retention period.


 

11. Sensitive and Confidential Information

In our work with charities and public interest organisations, we may be required to process confidential or sensitive client data  including health, safeguarding, or special category information.

We only process this information:

  • When strictly necessary and agreed with the client

  • Under a valid lawful basis (e.g., contract, legal obligation, public interest)

  • With appropriate security and confidentiality protocols

We can provide the following documents to clients on request:

  • Data Protection Impact Assessments (DPIAs)

  • Data Sharing Agreements (DSAs)

  • Confidentiality or Data Processing Agreements (DPAs)


 

12. Data Location and Hosting

All data collected and processed by Beyond P4C is hosted in the United Kingdom or European Economic Area (EEA).
We do not store data in or transfer data to third countries unless agreed with a client, and only with appropriate legal safeguards in place.


 

13. Changes to This Policy

We may update this Privacy Policy at any time. The latest version will always be available on our website with an updated effective date.


 

14. Contact Us

Beyond P4C Ltd
Email: hello@beyondp4c.co.uk
Address: 2nd Floor College House, 17, King Edwards Road, Ruislip, London, United Kingdom, HA4 7AE
Company number: 16348263