Data Protection Policy
Bespoke Training & Development
71-75 Shelton Street, London
WC2H 9JQ
United Kingdom
Prepared for Bespoke Training & Development by
Professor Alan Gillies MA PhD FBCS CITP FAHE Doctor Honoris Causa
Version: 2.0
Dated: 1st May 2026
Review date: 1st May 2027
Table of Contents
1 Policy Statement
2 Schematic data flows
3 Legal basis for processing
4 Consent
5 Legitimate Interests
5.1 The purpose test
5.2 The necessity test
5.3 The balancing test
6 User rights
6.1 The right to be informed
6.2 The right of access
6.3 Right to rectification
6.4 Right to erasure
6.5 Right to restrict processing
6.6 Right to data portability
6.7 Right to object
6.8 Rights related to automated decision making including profiling
7 Accountability and governance
8 Documentation
9 Data protection impact assessments
9.1 DPIA for HR functions
9.2 DPIA for customer communications for existing customers
9.3 DPIA for Direct marketing to potential customers under legitimate interests
9.4 DPIA for Learning applications
10 Our use of AI
11 Data protection officer
12 Information Security
13 International transfers
14 In the event of a breach
15 Staff Training and Awareness
Appendix A: Privacy Notices
A.1 How we manage the personal data of employees (to be included in the staff handbook)
A.2 How we manage the personal data of customers (displayed on the website, and available on request
A.3 How we manage the personal data used in direct marketing (displayed on the website, and via a link on all marketing emails)
1. Policy Statement
Bespoke Training and Development are committed to processing all personal data in accordance with the Data Protection Act 2018 (DPA2018), incorporating the UK General Data Protection Regulations (UK-GDPR) and to respecting the rights of all data subjects whose information we process.
We undertake to process all personal data in accordance with Article 5 of the UK-GDPR. Specifically, we commit that personal data shall be:
- processed lawfully, fairly and in a transparent manner in relation to individuals;
- collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall not be considered to be incompatible with the initial purposes;
- adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed;
- accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay;
- kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes subject to implementation of the appropriate technical and organisational measures required by the DPA2018 in order to safeguard the rights and freedoms of individuals; and processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.
2 Schematic Data Flows

3. Legal basis for processing
Where we process personal information, we ensure that the processing is necessary and that we have a valid lawful basis in order to process that data. Our legal bases are recorded in Table 1.
Where we are processing special category data we have a lawful basis for general processing and an additional condition for processing this type of data.

We record our lawful basis for processing as well as the purposes of the processing in our privacy notice, recorded in Appendix A and made available on our website.
We do not process criminal conviction data or data about offences.
4. Consent
We only rely on consent for communications to those parties who wish to receive communications from us, who are not already customers. These are either sent from us or a third party, who act as information processors on our behalf.
Where we rely on consent, we:
- have checked that consent is the most appropriate lawful basis for processing.
- made the request for consent prominent and separate from our terms and conditions.
- have asked people to positively opt in, without the use of pre-ticked boxes or any other type of default consent, in clear, plain language that is easy to understand.
- have specified why we want the data and what we’re going to do with it.
- have given individual (‘granular’) options to consent separately to different purposes and types of processing.
- have named our organisation or an organisation employed to work on our behalf, who will be relying on the consent.
- tell individuals they can withdraw their consent at the foot of every email.
- ensure that individuals can refuse to consent without detriment and avoid making consent a precondition of any service from us other than the specific communication.
- keep a record of when and how we got consent from the individual and keep a record of exactly what they were told at the time.
- regularly review consents to check that the relationship, the processing and the purposes have not changed.
- make it easy for individuals to withdraw their consent at any time, by reminding them in the footer of all communications
- act on withdrawals of consent as soon as we can.
5. Legitimate Interests
We identify potential clients from social media such as LinkedIn. They are identified through their business interests.
For these potential clients, we use legitimate interests as our legal basis for processing.
We have carried out a legitimate Interests assessment in accordance with ICO best practice.
5.1 The purpose test
- Why do you want to process the data?
To provide services identified as relevant and of interest to the prospective client through their use of social media - What benefit do you expect to get from the processing?
We expect some of these prospective clients to become active clients - Do any third parties benefit from the processing?
No - Are there any wider public benefits to the processing?
Many of the prospective clients are public bodies. Developing their staff will led to improved public services - How important are those benefits?
Staff who are not able to access training may not maintain their competence leading to less effective public services - What would the impact be if you couldn’t go ahead?
The company would be significantly restricted in its ability to market its products and services. Prospective clients might be left with unmet training needs - What is the intended outcome for individuals?
The individuals whose data would be processed have roles which require them to identify appropriate training and development opportunities for staff. This will help them do this. - Are you complying with other relevant laws?
We comply with direct marketing rules and all processing is carried out in accordance with the UK-GDPR. - Are you complying with industry guidelines or codes of practice?
Yes, all communication is carried out in accordance with the regulations governing business-to-business communications for marketing purposes - Are there any ethical issues with the processing?
The amount of personal data used will be the absolute minimum to facilitate the business-to-business communication. Users who express a desire not to be contacted again will be respected, and further contacts will not be made
5.2 The necessity test
- Will the processing actually help you achieve your purpose?
Yes, it has been the practice prior to the introduction of GDPR in 2018, and has proved effective - Is the processing proportionate to that purpose, or could it be seen as using a sledgehammer to crack a nut?
Yes, very limited amounts of personal data are used - Can you achieve your purpose without processing the data, or by processing less data?
No, in other cases we use consent as a legal basis but in this case, this is not possible - Can you achieve your purpose by processing the data in another more obvious or less intrusive way?
No, in other cases we use consent as a legal basis but in this case, this is not possible
5.3 The balancing test
- The nature of the personal data
We only use contact names and emails or phone numbers. The emails and phone numbers although linked to an individual will be those linked to their professional activities. - The reasonable expectations of the individual;
We are seeking individuals who are in training and development roles and have demonstrated their interest on public forums such as LinkedIn, and as such can have a reasonable expectation of being contacted. - The likely impact of the processing on the individual and whether any safeguards can be put in place to mitigate negative impacts
We take all possible steps to contact individuals in their professional role and provide opportunities to data subjects to prevent future communications.
6. User rights
We respect the rights of all our data subjects.
6.1 The right to be informed
We provide individuals with all the following privacy information:
- The name and contact details of our organisation.
- The name and contact details of our data processor, where applicable
- The purposes of the processing.
- The lawful basis for the processing.
- The recipients or categories of recipients of the personal data.
- The details of transfers of the personal data to any third countries or international organisations (if applicable in the future: not applicable at present).
- The retention periods for the personal data.
- The rights available to individuals in respect of the processing.
- The right to withdraw consent (where this is the legal basis for processing).
- The right to lodge a complaint with the ICO.
We provide individuals with privacy information at the time we collect their personal data from them, and via the privacy notice available on our website.
We provide the information in a way that is concise, transparent, intelligible, easily accessible, and uses clear and plain language.
We regularly review and, where necessary, update our privacy information. If we plan to use personal data for a new purpose, we will update our privacy information and communicate the changes to individuals before starting any new processing.
We have undertaken an information audit in March 2018 to find out what personal data we hold and what we do with it.
6.2 The right of access
We will provide a copy of the information that we hold on individuals free of charge so that they are aware of and can verify the lawfulness of the processing in accordance with Recital 63 of the UK-GDPR.
We reserve the right to charge a ‘reasonable fee’ based on the administrative cost of providing the information when a request is manifestly unfounded or excessive, particularly if it is repetitive.
We will provide the information must be provided without delay and at the latest within one month of receipt of the request.
We will take reasonable steps to verify the identity of the person making the request, using ‘reasonable means’.
Where the request is made electronically, we will provide the information in a commonly used electronic format.
6.3 Right to rectification
When we are notified that the personal information we hold is erroneous, we will respond to a request for rectification without undue delay and within one month of receipt and inform any recipients if we rectify any data we have shared with them.
Where we are satisfied that the personal data is accurate, we will tell the data subject that we will not be amending the data. We will explain our decision and inform them of their right to make a complaint to the ICO or another supervisory authority; and their ability to seek to enforce their rights through a judicial remedy.
6.4 Right to erasure
We will respect a data subjects right to erasure when required to do so under the UK-GDPR, in the following circumstances:
- the personal data is no longer necessary for the purpose which you originally collected or processed it for;
- we are relying on consent as the lawful basis for holding the data, and the individual withdraws their consent;
- we are relying on legitimate interests as our basis for processing, the individual objects to the processing of their data, and there is no overriding legitimate interest to continue this processing;
- we are processing the personal data for direct marketing purposes and the individual objects to that processing;
- we have processed the personal data unlawfully (ie in breach of the lawfulness requirement of the 1st principle);
- we have to do it to comply with a legal obligation.
In these circumstances, we will delete the data without undue delay and within one month of receipt and inform any recipients if we delete any data we have shared with them.
Where we do not believe that these circumstances apply we will tell the data subject that we will not be removing their data. We will explain our decision and inform them of their right to make a complaint to the ICO or another supervisory authority; and their ability to seek to enforce their rights through a judicial remedy.
We will review the criteria for erasure periodically, or when they are changed by the external legal environment.
6.5 Right to restrict processing
We will respond to a request for restriction without undue delay and within one month of receipt.
We will restrict the processing of personal data in the following circumstances:
- the individual contests the accuracy of their personal data and we are verifying the accuracy of the data;
- the data has been unlawfully processed (ie in breach of the lawfulness requirement of the first principle of the UK-GDPR) and the individual opposes erasure and requests restriction instead;
- we no longer need the personal data but the individual needs us to keep it in order to establish, exercise or defend a legal claim; or
- the individual has objected to us processing their data under UK-GDPR Article 21(1), and we are considering whether your legitimate grounds override those of the individual.
- whilst we are considering its accuracy or the legitimate grounds for processing the personal data in question.
6.6 Right to data portability
If an individual requests it, we will provide personal data in a structured, commonly used and machine-readable form, such as CSV files, in accordance with the criteria laid down by the UK-GDPR, ie when: they have provided the information to us directly or where the processing is based on the individual’s consent or for the performance of a contract; and when processing is carried out by automated means.
We are not aware of any circumstances currently in which these criteria are met, but if they arise in the future, we will respond without undue delay, and within one month.
6.7 Right to object
We acknowledge that data subjects have the right to object to of:
- processing based on legitimate interests or the performance of a task in the public interest/exercise of official authority (including profiling);
- processing for direct marketing (including profiling); and
- processing for purposes of scientific/historical research and statistics.
We believe that this may only arise as part of our marketing activity. In this case, we will stop processing personal data for direct marketing purposes as soon as we receive an objection, and free of charge.
We inform individuals of their right to object in our privacy notice.
6.8 Rights related to automated decision making including profiling
We do not use automated decision making including profiling.
7. Accountability and governance
Where we use data processors, we have contracts that specify:
- the subject matter and duration of the processing;
- the nature and purpose of the processing;
- the type of personal data and categories of data subject; and
- the obligations and rights of the controller.
They require the processor to:
- only act on the written instructions of the controller (unless required by law to act without such instructions);
- ensure that people processing the data are subject to a duty of confidence;
- take appropriate measures to ensure the security of processing;
- only engage a sub-processor with the prior consent of the data controller and a written contract;
- assist us in providing subject access and allowing data subjects to exercise their rights under the UK-GDPR;
- assist us in meeting our UK-GDPR obligations in relation to the security of processing, the notification of personal data breaches and data protection impact assessments;
- delete or return all personal data to the controller as requested at the end of the contract; and
- submit to audits and inspections, provide the controller with whatever information it needs to ensure that they are both meeting their Article 28 obligations, and tell the controller immediately if it is asked to do something infringing the UK-GDPR or the DPA2018
Our contracts also state that nothing within the contract relieves the processor of its own direct responsibilities and liabilities under the UK-GDPR.
8. Documentation
As a small company of less than 250 employees, we have:
- Carried out an audit of the personal information we use;
- Identified the legal basis for processing of each type of information
- Updated our data protection policy and privacy notice in accordance with the UK-GDPR
- Checked our contracts with data processors acting on our behalf in accordance with the UK-GDPR
We have included the results of the audit and the legal basis for processing in this document.
We will review this documentation either:
- When we introduce a major change in our information systems
- When we introduce a major change in our business processes
- Or annually, if the documentation has not been reviewed in the last 12 months
.
9. Data protection impact assessments
We have implemented a process for carrying out Data Protection Impact Assessments in the event of new systems.
We have adopted a model based on ICO guidance (Figure 1), and a standard template for recording results.

We carried out three DPIAs in preparation for the introduction of GDPR in 2018. None of these revealed high risk activity, and therefore, did not contact the ICO.
We have reviewed the UK-GDPR criteria and do not envisage doing any of the following in the foreseeable future which would require a further DPIA. We have no plans to:
- Use systematic and extensive profiling or automated decision-making to make significant decisions about people.
- Process special category data or criminal offence data on a large scale.
- Systematically monitor a publicly accessible place on a large scale.
- Use new technologies.
- Use profiling, automated decision-making or special category data to help make decisions on someone’s access to a service, opportunity or benefit.
- Carry out profiling on a large scale.
- Process biometric or genetic data.
- Combine, compare or match data from multiple sources.
- Process personal data without providing a privacy notice directly to the individual.
- Process personal data in a way which involves tracking individuals’ online or offline location or behaviour.
- Process children’s personal data for profiling or automated decision-making or for marketing purposes or offer online services directly to them.
- Process personal data which could result in a risk of physical harm in the event of a security breach.
9.1 DPIA for HR functions
Assessor
Professor Alan Gillies
Date of Assessment
30.04.2026
Person with lead responsibility
Richard Oliver
Name of Process
Human Resources Management
Brief description of process
The processes necessary to manage staff and meet our legal obligations as an employer.
Information types to be processed
- Personal demographic data
- Job history
- Financial details necessary for payroll and taxation
- Details of current employment
- Medical information necessary for duty of care
Category of Information to be processes
Mostly Personal with some special category.
Legal Basis for Processing
- Processing this information is necessary to fulfil an (employment) contract with you; and
- Processing this information is necessary to comply with a legal obligation;
Some of the personal information is characterised as special category data under the UK-GDPR, we process this under Article 9(2) (b) of the the UK-GDPR, which permits the processing of this data where:
“processing is necessary for the purposes of carrying out the obligations and exercising specific rights of the controller or of the data subject in the field of employment and social security and social protection law.”
Where does the data come from?
The data subjects themselves or previous employers.
Do you transfer the data to a country outside the UK?
Bespoke use Microsoft as an information processor and make use of Microsoft cloud-based online services. Microsoft online services create system-generated logs as part of the regular operation of the services. These logs continuously record system activity over time to allow Microsoft to monitor whether systems are operating as expected. “Logging” (the storage and processing of logs) is essential to identify, detect, respond to, and prevent operational problems, policy violations, and fraudulent activity; optimize system, network, and application performance; assist in security investigations and resilience activities; and to comply with laws and regulations. While the focus of these logs is on how systems are operating and not on individual users, when events in Microsoft cloud services are initiated by user interaction with a cloud service, some logs directly reflecting these events will – and must in order to fulfill their purposes – contain fields that either identify or can identify specific persons. These logs contain personal data.
Examples of system-generated logs that may contain personal data include:
- Product and service usage data such as user activity logs
- Data specifically generated by the interaction of users with other systems
Some personal data may be stored on Microsoft servers outside the UK, but within the EU through the implementation of the EU Data Boundary. This is a geographically defined boundary within which Microsoft has committed to store and process Customer Data and personal data for our Microsoft enterprise online services, including Azure, Dynamics 365, Power Platform, and Microsoft 365. Professional Services Data will be stored at rest for these services.
These commitments are subject to limited circumstances where Customer Data, personal data, and Professional Services Data will continue to be transferred outside the EU Data Boundary. This documentation provides details about those transfers. The online services included in the EU Data Boundary commitment (referred to in this documentation as EU Data Boundary Services) are identified in the Microsoft Product Terms as part of the services agreements.
Under GDPR, the safeguards provided for personal information within the EU are the same as in the UK.
Do you transfer the data to a third party?
Only when legally required to do so, eg for taxation purposes, when information will be shared with the accountants or to third parties at the request of the data subject with explicit consent as an additional legal basis.
Who is impacted by the processing?
The data subjects themselves; HMRC and other statutory agencies.
How do you manage retention and disposal?
We retain personal data for the duration of the employment, and for a period of 12 months after employment, or as long as is necessary to meet our legal duties eg for taxation, whichever is the greater. In the event of job applicants for jobs, we do not retain their information unless they become employees, or give explicit consent as an alternative legal basis for retention. In this case, applicants can revoke their consent at any time, and the information will be destroyed after 12 months, unless that consent is renewed.
What are the risks to the data subjects?
Security breaches; inappropriate disclosure to a third party.
How do you rate the risk without mitigation measures?
Moderate
What measures are already in place to protect the rights of data subjects and minimise risk?
Physical security measures; Information Security Measures; Verification of users requesting personal information by phone or email.
What additional measures will you put in place to protect the rights of data subjects and minimise risk?
Refresher staff training; Periodic reviews of security measures.
Data of review
30.04.2027
How do you rate the risk after mitigation measures?
Low
9.4 DPIA for Learning applications
Assessor
Professor Alan Gillies
Date of Assessment
Richard Oliver
Name of Process
Registration of Users for Products and Services
Brief description of process
In order to control access to our products and services, we need use basic personal information about them. We may also record information on the system about what they do there eg assessment for training.
Information types to be processed
- Name & contact details
- Application specific data
Category of Information to be processes
- Personal
- Special category data (ethnicity - for monitoring purposes only)
Legal Basis for Processing
Processing this information is necessary to fulfil a contract, but the ethnicity information requires additional explicit consent.
Where does the data come from?
The data subjects themselves.
Where is the data processed?
Within our EU-hosted applications. Some personal data may be stored on Microsoft servers.
Do you transfer the data to a third party?
To accrediting bodies for qualifications where necessary. - ILM qualifications require us to gather personal details (email, address, DOB) and we act as an information processor on their behalf in accordance their regulations and the DPA 2018.
Do you transfer the data to a country outside the EU?
Bespoke use Microsoft as an information processor and make use of Microsoft cloud-based online services.
Microsoft online services create system-generated logs as part of the regular operation of the services. These logs continuously record system activity over time to allow Microsoft to monitor whether systems are operating as expected. “Logging” (the storage and processing of logs) is essential to identify, detect, respond to, and prevent operational problems, policy violations, and fraudulent activity; optimize system, network, and application performance; assist in security investigations and resilience activities; and to comply with laws and regulations. While the focus of these logs is on how systems are operating and not on individual users, when events in Microsoft cloud services are initiated by user interaction with a cloud service, some logs directly reflecting these events will – and must in order to fulfill their purposes – contain fields that either identify or can identify specific persons. These logs contain personal data.
Examples of system-generated logs that may contain personal data include:
- Product and service usage data such as user activity logs
- Data specifically generated by the interaction of users with other systems
Some personal data may be stored on Microsoft servers outside the UK, but within the EU through the implementation of the EU Data Boundary. This is a geographically defined boundary within which Microsoft has committed to store and process Customer Data and personal data for our Microsoft enterprise online services, including Azure, Dynamics 365, Power Platform, and Microsoft 365. Professional Services Data will be stored at rest for these services. These commitments are subject to limited circumstances where Customer Data, personal data, and Professional Services Data will continue to be transferred outside the EU Data Boundary. This documentation provides details about those transfers. The online services included in the EU Data Boundary commitment (referred to in this documentation as EU Data Boundary Services) are identified in the Microsoft Product Terms as part of the services agreements.
Under GDPR, the safeguards provided for personal information within the EU are the same as in the UK.
Who is impacted by the processing?
The data subjects themselves.
How do you manage retention and disposal?
We retain personal data for the duration of the contract, and for a period of 12 months after the contract or as long as is necessary to meet our contractual obligations e.g. data about learners registered with the ILM must be kept for 4 years from registration on an ILM qualification.
What are the risks to the data subjects?
Security breaches; inappropriate disclosure to a third party.
How do you rate the risk without mitigation measures?
Moderate
What measures are already in place to protect the rights of data subjects and minimise risk?
hysical security measures; Information Security Measures; Verification of users requesting personal information by phone or email.
What additional measures will you put in place to protect the rights of data subjects and minimise risk?
Formalisation of the responsibilities of Bespoke as a data processor. Periodic reviews of security measures.
How do you rate the risk after mitigation measures?
Low
Data of review
30.04.2027
Additional information
None
10. Our use of AI
Bespoke does not use AI to process personal information internally.
Bespoke use Microsoft as an information processor and they may use AI for processing personal information.
They provide the following information regarding the way in which they use personal information:
Microsoft leverages the power of artificial intelligence (AI) in many of our products and services, including by incorporating generative AI “Copilot” capabilities.
Microsoft’s deployment and use of AI is subject to Microsoft’s AI Principles and Microsoft’s Responsible AI Standard, and Microsoft’s collection and use of personal data in developing and deploying AI features is consistent with the commitments outlined in this privacy statement. Product-specific details provide additional relevant information.
Microsoft publishes information about the tools, practices, and policies hit as created to uphold its responsible AI principles.
“Copilot” is a family of services, products, and solutions that leverage generative AI technologies to generate outputs. Microsoft’s collection and use of data may differ depending on the service and the intended functionality in a given scenario. Learn more below.
The Microsoft Copilot website and app (available on Windows, iOS and Android) is the core of the consumer Copilot experience. Within this core experience, you can search the web, create text, images, songs, or other outputs, engage with other features like Copilot Vision, and let Copilot interact with other apps, services, and websites to take Actions on your behalf.
When interacting with Microsoft Copilot, users enter “prompts” that provide instructions to Copilot (e.g. “Give me recommendations for a restaurant that accommodates parties of 10 near me”). To provide a relevant response, Microsoft Copilot will use this prompt, along with the users’ location, language, and similar settings, as well as other data you might input into the service (for example, files, images and visual media) to formulate a helpful response.
In some markets, Microsoft Copilot can use users’ prior conversation history to better personalise the product based on the information shared – such as interests and goals. Users can opt-out of personalisation at any time. Microsoft Copilot also uses prompts and related information (like location and language) to provide and improve the Copilot services, including to provide relevant advertising. Users can manage their prompt history in product and on the Microsoft Privacy Dashboard (if signed in), and can adjust location, language, and other settings (including additional privacy choices) in the product.
Microsoft will only use Microsoft Copilot conversations to monitor performance, troubleshoot problems, diagnose bugs, prevent abuse, and to provide and improve
Microsoft Copilot. In certain markets, we use conversation data to train the generative AI models in Copilot, unless users choose to opt-out of such training. More information about how this data is protected and the controls we offer in Microsoft Copilot is available from Microsoft.
We [Microsoft] leverage the power of artificial intelligence (AI) in many of our products and services, including by incorporating generative AI “Copilot” capabilities.
Microsoft’s deployment and use of AI is subject to Microsoft’s AI Principles and Microsoft’s Responsible AI Standard, and Microsoft’s collection and use of personal data in developing and deploying AI features is consistent with the commitments outlined in this privacy statement. Product-specific details provide additional relevant information. You can find out more about the tools, practices, and policies Microsoft has created to uphold our responsible AI principles here.
“Copilot” is a family of services, products, and solutions that leverage generative AI technologies to generate outputs. Microsoft’s collection and use of data may differ depending on the service and the intended functionality in a given scenario. Learn more below.
The Microsoft Copilot website and app (available on Windows, iOS and Android) is the core of the consumer Copilot experience. Within this core experience, users can search the web, create text, images, songs, or other outputs, engage with other features like Copilot Vision, and let Copilot interact with other apps, services, and websites to take Actions on your behalf. When interacting with Microsoft Copilot, users enter “prompts” that provide instructions to Copilot.
To provide a relevant response, Microsoft Copilot will use this prompt, along with location, language, and similar settings, as well as other data that might be input into the service (for example, files, images and visual media) to formulate a helpful response.
In some markets, Microsoft Copilot can use prior conversation histories to better personalise the product based on the information shared – such as your interests and goals. Users can opt-out of personalisation at any time. Microsoft Copilot also uses prompts and related information (like location and language) to provide and improve the Copilot services, including to provide relevant advertising.
Users can manage their prompt history in-product and on the Microsoft Privacy Dashboard (if signed in), and can adjust their location, language, and other settings (including additional privacy choices) in the product. For more information about these capabilities and your choices, see the Microsoft Copilot FAQ.
Microsoft will only use Microsoft Copilot conversations to monitor performance, troubleshoot problems, diagnose bugs, prevent abuse, and to provide and improve
Microsoft Copilot. In certain markets, we [Microsoft] use conversation data to train the generative AI models in Copilot, unless users choose to opt-out of such training.
We [Microsoft] also take measures to ensure that content that we [Microsoft] show users is safe to view.
Microsoft Copilot also appears as an assistant within certain third-party products and services, including several consumer chat and messaging platforms. In those situations, We [Microsoft] process data in line with our privacy statement. Additionally, your interactions with Microsoft Copilot via a third-party product or service may also be subject to the third party’s privacy policies and data processing activities.
Microsoft 365 Copilot, available in Microsoft 365 enterprise offerings, provides enterprise-grade data protection along with access to the corporate graph, Copilot within Microsoft 365 and Teams, and additional customisation features. Data collection and use in Microsoft 365 Copilot is consistent with the practices described in the Enterprise and Developer Products section of Microsoft’s privacy statement. We [Microsoft] also take measures to ensure that content shown is safe.
Microsoft leverages the power of artificial intelligence (AI) in many of our products and services, including by incorporating generative AI “Copilot” capabilities.
Microsoft’s deployment and use of AI is subject to Microsoft’s AI Principles and Microsoft’s Responsible AI Standard, and Microsoft’s collection and use of personal data in developing and deploying AI features is consistent with the commitments outlined in this privacy statement. Product-specific details provide additional relevant information. You can find out more about the tools, practices, and policies Microsoft has created to uphold our responsible AI principles here.
“Copilot” is a family of services, products, and solutions that leverage generative AI technologies to generate outputs. Microsoft’s collection and use of data may differ depending on the service and the intended functionality in a given scenario. Learn more below.
The Microsoft Copilot website and app (available on Windows, iOS and Android) is the core of the consumer Copilot experience. Within this core experience, you can search the web, create text, images, songs, or other outputs, engage with other features like Copilot Vision, and let Copilot interact with other apps, services, and websites to take Actions on your behalf. When interacting with Microsoft Copilot, you enter “prompts” that provide instructions to Copilot (e.g. “Give me recommendations for a restaurant that accommodates parties of 10 near me”). To provide a relevant response, Microsoft Copilot will use this prompt, along with your location, language, and similar settings, as well as other data you might input into the service (for example, files, images and visual media) to formulate a helpful response.
In some markets, Microsoft Copilot can use your prior conversation history to better personalise the product for you based on the information you shared – such as your interests and goals. You can opt-out of personalisation at any time. Microsoft Copilot also uses your prompts and related information (like location and language) to provide and improve the Copilot services, including to provide relevant advertising. You can manage your prompt history in product and on the
Microsoft Privacy Dashboard (if signed in), and can adjust your location, language, and other settings (including additional privacy choices) in the product. For more information about these capabilities and your choices, see the Microsoft Copilot FAQ.
Microsoft will only use your Microsoft Copilot conversations to monitor performance, troubleshoot problems, diagnose bugs, prevent abuse, and to provide and improve Microsoft Copilot. In certain markets, We [Microsoft] use conversation data to train the generative AI models in Copilot, unless you choose to opt-out of such training. More information about how your data is protected and the controls We [Microsoft] offer in Microsoft Copilot is available here.
We [Microsoft] also take measures to ensure that content We [Microsoft] show you is safe. You can learn more about our approach to safety in our Transparency.
Note for Microsoft Copilot.
Microsoft Copilot also appears as an assistant within other Microsoft consumer products, such as Microsoft Edge and Xbox. In those situations, data processing activities generally align with those products’ primary uses. See the Microsoft Edge and Xbox sections of this privacy statement to learn more about Copilot features within those products.
Microsoft Copilot also appears as an assistant within certain third-party products and services, including several consumer chat and messaging platforms. In those situations, We [Microsoft] process data in line with our privacy statement. Additionally, your interactions with Microsoft Copilot via a third-party product or service may also be subject to the third party’s privacy policies and data processing activities.
Microsoft 365 Copilot is a consumer Copilot offering that provides access to the very latest models, improved image creation abilities, and access to Copilot in
Microsoft 365. Copilot functionality is included in Microsoft 365 Family and Microsoft 365 Personal subscriptions. When Copilot is integrated with Microsoft 365 products, Copilot data collection is consistent with how data collection and use is described in the Productivity and Communications section of this privacy statement.
Microsoft 365 Copilot, also available for Microsoft 365 enterprise offerings, provides enterprise-grade data protection along with access to the corporate graph, Copilot within Microsoft 365 and Teams, and additional customisation features. Data collection and use in Microsoft 365 Copilot is consistent with the practices described in the Enterprise and Developer Products section of this privacy statement.Copilot also appears as an assistant within other Microsoft consumer products, such as Microsoft Edge and Xbox. In those situations, data processing activities generally align with those products’ primary uses. See the Microsoft Edge and Xbox sections of this privacy statement to learn more about Copilot features within those products.
Microsoft Copilot also appears as an assistant within certain third-party products and services, including several consumer chat and messaging platforms. In those situations, We [Microsoft] process data in line with our privacy statement. Additionally, your interactions with Microsoft Copilot via a third-party product or service may also be subject to the third party’s privacy policies and data processing activities.
Microsoft 365 Copilot is a consumer Copilot offering that provides access to the very latest models, improved image creation abilities, and access to Copilot in
Microsoft 365. Copilot functionality is included in Microsoft 365 Family and Microsoft 365 Personal subscriptions. When Copilot is integrated with Microsoft 365 products, Copilot data collection is consistent with how data collection and use is described in the Productivity and Communications section of this privacy statement.
Microsoft 365 Copilot, also available for Microsoft 365 enterprise offerings, provides enterprise-grade data protection along with access to the corporate graph, Copilot within Microsoft 365 and Teams, and additional customisation features. Data collection and use in Microsoft 365 Copilot is consistent with the practices described in the Enterprise and Developer Products section of this privacy statement.
11. Data protection officer
We are not a public authority and the nature of our processing activities does not require the appointment of a Data protection officer (DPO) and therefore have not appointed a DPO.
We have designated Richard Oliver as having day-to-day responsibility for data protection.
12. Information Security
We have undertaken an analysis of the risks presented by our processing and use this to assess the appropriate level of security we need to put in place.
We have implemented measures taking into the account of the state of the art and costs of implementation.
The information security policy is included here in Appendix B and take steps to make sure the policy is implemented.
We review this policy either:
- In the event of a security breach or “near miss”
- When we introduce a major change in our information systems
- When we introduce a major change in our business processes
- Or annually, if the policy has not been reviewed in the last 12 months
We understand that we may also need to put other technical measures in place depending on our circumstances and the type of personal data we process.
We use encryption where it is appropriate to do so.
We understand the requirements of confidentiality, integrity and availability for the personal data we process.
We make sure that we can restore access to personal data in the event of any incidents, such as by establishing an appropriate backup process.
We conduct regular testing and reviews of our measures to ensure they remain effective, and act on the results of those tests where they highlight areas for improvement.
Where appropriate, we implement measures that adhere to an approved code of conduct or certification mechanism.
We ensure that any data processor we use also implements appropriate technical and organisational measures.
13. International transfers
Internally, Bespoke process personal information within the UK.
Bespoke use Microsoft as an information processor and make use of Microsoft cloud-based online services.
Microsoft online services create system-generated logs as part of the regular operation of the services. These logs continuously record system activity over time to allow Microsoft to monitor whether systems are operating as expected. “Logging” (the storage and processing of logs) is essential to identify, detect, respond to, and prevent operational problems, policy violations, and fraudulent activity; optimize system, network, and application performance; assist in security investigations and resilience activities; and to comply with laws and regulations. While the focus of these logs is on how systems are operating and not on individual users, when events in Microsoft cloud services are initiated by user interaction with a cloud service, some logs directly reflecting these events will – and must in order to fulfill their purposes – contain fields that either identify or can identify specific persons. These logs contain personal data. Examples of system-generated logs that may contain personal data include:
- Product and service usage data such as user activity logs
- Data specifically generated by the interaction of users with other systems
Some personal data may be stored on Microsoft servers outside the UK, but within the EU through the implementation of the EU Data Boundary. This is a geographically defined boundary within which Microsoft has committed to store and process Customer Data and personal data for our Microsoft enterprise online services, including Azure, Dynamics 365, Power Platform, and Microsoft 365. Professional Services Data will be stored at rest for these services. These commitments are subject to limited circumstances where Customer Data, personal data, and Professional Services Data will continue to be transferred outside the EU Data Boundary. This documentation provides details about those transfers. The online services included in the EU Data Boundary commitment (referred to in this documentation as EU Data Boundary Services) are identified in the Microsoft Product Terms as part of the services agreements.
Under GDPR, the safeguards provided for personal information within the EU are the same as in the UK
14. In the event of a breach
In the event of a breach, such as:
- access by an unauthorised third party;
- deliberate or accidental action (or inaction) by a controller or processor;
- sending personal data to an incorrect recipient;
- computing devices containing personal data being lost or stolen;
- alteration of personal data without permission; and
- loss of availability of personal data.
We will assess the likelihood and severity of the resulting risk to people’s rights and freedoms.
Where the likelihood and severity are low, we will:
- Take steps to mitigate the impact
- Take steps to prevent a repetition
- Review our policies and procedures to consider any wider lessons that may be learnt.
Where the likelihood or severity is higher, or has the potential to escalate, we will, in addition:
- Notify the ICO within 72 hours, and provide them with:
- a description of the nature of the personal data breach including, where possible:
- the categories and approximate number of individuals concerned; and
- the categories and approximate number of personal data records concerned;
- the name and contact details of our data protection lead where more information can be obtained;
- a description of the likely consequences of the personal data breach; and
- a description of the measures taken, or proposed to be taken, to deal with the personal data breach, including, where appropriate, the measures taken to mitigate any possible adverse effects.
Where a breach is likely to result in a high risk to the rights and freedoms of individuals, we will inform those concerned directly and without undue delay. If in doubt, we will seek advice from the ICO when notifying them of a breach.
When notifying individuals, we will seek to help them take steps to protect themselves from the effects of a breach and will remind them of their right to complain to the ICO, and their right to legal redress if we are unable to resolve the matter to their satisfaction.
15. Staff Training and Awareness
We have distributed this policy to all staff and information processors on adoption and at each review.
It forms part of the induction process for new staff.
In the event of staff raising concerns over training needs, we will take reasonable steps to address them as part of their staff development.
The directors undertake annual refresher training on data protection.
Appendix A: Privacy Notices
A.1 How we manage the personal data of employees (to be included in the staff handbook)
The identity and contact details of the controller
The Data Controller is Bespoke Training & Development, 71-75 Shelton Street, London, WC2H 9JQ, United Kingdom
To contact the Data Controller, please email info@bespoke.ltd
We are not required to have a designated data protection officer under the UK-GDPR.
Purpose of the processing and the lawful basis for the processing
We are collecting your personal information to carry out our duties as an employer
Our basis for processing is:
- Processing this information is necessary for us to fulfil our (employment) contract with you; and
- Processing this information is necessary for us to comply with a legal obligation;
Some of the personal information is characterised as special category data under the UK-GDPR, we process this under Article 9(2) (b) of the UK-GDPR, which permits the processing of this data where:
- “processing is necessary for the purposes of carrying out the obligations and exercising specific rights of the controller or of the data subject in the field of employment and social security and social protection law.”
If you do not accept this basis, then you may object to us or to the ICO as described below
Categories of personal data
The categories of personal data we hold are:
- Personal demographic data eg name & contact details, emergency contact details, DOB etc
- Job history
- Financial details necessary for payroll and taxation including expenses
- Details of current employment
- Medical information necessary for duty of care
Any recipient or categories of recipients of the personal data
We do not routinely share this information with anyone else. If we did we would do so because we had a legal duty to do so, or because you have provided explicit consent as an alternative legal basis for processing
Details of transfers to third country and safeguards
Internally, Bespoke process personal information within the UK. Bespoke use Microsoft as an information processor and make use of Microsoft cloud-based online services. Microsoft online services create system-generated logs as part of the regular operation of the services. These logs continuously record system activity over time to allow Microsoft to monitor whether systems are operating as expected. “Logging” (the storage and processing of logs) is essential to identify, detect, respond to, and prevent operational problems, policy violations, and fraudulent activity; optimize system, network, and application performance; assist in security investigations and resilience activities; and to comply with laws and regulations. While the focus of these logs is on how systems are operating and not on individual users, when events in Microsoft cloud services are initiated by user interaction with a cloud service, some logs directly reflecting these events will – and must in order to fulfill their purposes – contain fields that either identify or can identify specific persons. These logs contain personal data. Examples of system-generated logs that may contain personal data include:
- Product and service usage data such as user activity logs
- Data specifically generated by the interaction of users with other systems
Some personal data may be stored on Microsoft servers outside the UK, but within the EU through the implementation of the EU Data Boundary. This is a geographically defined boundary within which Microsoft has committed to store and process Customer Data and personal data for our Microsoft enterprise online services, including Azure, Dynamics 365, Power Platform, and Microsoft 365. Professional Services Data will be stored at rest for these services. These commitments are subject to limited circumstances where Customer Data, personal data, and Professional Services Data will continue to be transferred outside the EU Data Boundary. This documentation provides details about those transfers. The online services included in the EU Data Boundary commitment (referred to in this documentation as EU Data Boundary Services) are identified in the Microsoft Product Terms as part of the services agreements. Under GDPR, the safeguards provided for personal information within the EU are the same as in the UK
Retention period or criteria used to determine the retention period
We will retain your personal data for the duration of your employment, and for a period of 12 months after your employment, or as long as is necessary to meet our legal duties eg for taxation, whichever is the greater.
In the event of applicants for jobs, we do not retain their information unless they become employees or give explicit consent as an alternative legal basis for retention. In this case, applicants can revoke their consent at any time, and the information will be destroyed after 12 months, unless that consent is renewed
The existence of each of the data subject’s rights
You have the following rights about the use of your personal information:
- Where the basis for processing is your consent, you may withdraw that consent at any time by contacting us.
- If your personal information is incorrect, you may request that errors or incomplete entries be rectified
- In certain circumstances, you may have the right to be forgotten and your data erased. Please contact if you wish to exercise this right.
- Whilst any request is being investigated, you have the right to restrict processing, so that your information will simply be stored.
- You can request the return of transfer of any personal data you have given to us in a portable electronic format
- We do not use automated decision making and profiling of your personal information without human intervention.
To exercise any of these rights, please contact us in writing at Bespoke Training & Development, 71-75 Shelton Street, London, WC2H 9JQ, United Kingdom
The source the personal data originates from and whether it came from publicly accessible sources
Your personal information is collected either directly from you, or in limited cases from previous employers as part of the recruitment process
Whether the provision of personal data part of a statutory or contractual requirement or obligation and possible consequences of failing to provide the personal data
Your personal information is processed as part of our statutory requirements an employer and as part of your employment contract
The existence of automated decision making, including profiling and information about how decisions are made, the significance and the consequences.
We do not use automated decision making or profiling of any kind.
The right to lodge a complaint with a supervisory authority
You have the right to complain to the Information Commissioners Office by
- Helpline. Call them on 0303 123 1113, Monday to Friday between 9am and 5pm.
- Live chat. Have an online conversation with someone at the ICO at https://ico.org.uk/global/contact-us/live-chat/.
- Email. Use the form at https://ico.org.uk/global/contact-us/email/
You also the right to seek legal redress in the event of suffering harm which you do not feel has been sufficiently addressed by us or by the ICO.
A.2 How we manage the personal data of customers (displayed on the website, and available on request)
The identity and contact details of the controller
The Data Controller is Bespoke Training & Development, 71-75 Shelton Street, London, WC2H 9JQ, United Kingdom
To contact the Data Controller, please email info@bespoke.ltd
We are not required to have a designated data protection officer under the UK-GDPR.
Purpose of the processing and the lawful basis for the processing
We are collecting your personal information to carry provide you with products and services
Our basis for processing is:
- Processing this information is necessary for us to fulfil our contract with you; and
- Processing this information is necessary for us to comply with a legal obligation;
In addition, we collect some special category data e.g. ethnicity data collected for monitoring purposes of ILM qualifications only. In this case, we seek additional explicit consent. If you do not accept this basis, then you may object to us or to the ICO as described below
Categories of personal data
The categories of personal data we hold are:
Personal demographic data eg name email addresses of individuals registered with us as participants on courses or as registered users of our applications
Special category data e.g. ethnicity data collected for monitoring purposes of ILM qualifications only)
Any recipient or categories of recipients of the personal data
We do not routinely share this information with anyone else. If we did we would do so because we had a legal duty to do so, or because you have provided explicit consent as an alternative legal basis for processing
Details of transfers to third country and safeguards
Internally, Bespoke process personal information within the UK. Bespoke use Microsoft as an information processor and make use of Microsoft cloud-based online services.
Microsoft online services create system-generated logs as part of the regular operation of the services. These logs continuously record system activity over time to allow Microsoft to monitor whether systems are operating as expected. “Logging” (the storage and processing of logs) is essential to identify, detect, respond to, and prevent operational problems, policy violations, and fraudulent activity; optimize system, network, and application performance; assist in security investigations and resilience activities; and to comply with laws and regulations. While the focus of these logs is on how systems are operating and not on individual users, when events in Microsoft cloud services are initiated by user interaction with a cloud service, some logs directly reflecting these events will – and must in order to fulfill their purposes – contain fields that either identify or can identify specific persons. These logs contain personal data. Examples of system-generated logs that may contain personal data include:
- Product and service usage data such as user activity logs
- Data specifically generated by the interaction of users with other systems
Some personal data may be stored on Microsoft servers outside the UK, but within the EU through the implementation of the EU Data Boundary. This is a geographically defined boundary within which Microsoft has committed to store and process Customer Data and personal data for our Microsoft enterprise online services, including Azure, Dynamics 365, Power Platform, and Microsoft 365. Professional Services Data will be stored at rest for these services. These commitments are subject to limited circumstances where Customer Data, personal data, and Professional Services Data will continue to be transferred outside the EU Data Boundary. This documentation provides details about those transfers. The online services included in the EU Data Boundary commitment (referred to in this documentation as EU Data Boundary Services) are identified in the Microsoft Product Terms as part of the services agreements. Under GDPR, the safeguards provided for personal information within the EU are the same as in the UK
Retention period or criteria used to determine the retention period
We will retain your personal data for the duration of your contract with us, and for a period of 12 months after your contract has ended, or as long as is necessary to meet our legal duties, whichever is the greater. For example, the ILM require us to retain personal information about candidates for four years from registration on an ILM qualification.
The existence of each of the data subject’s rights
You have the following rights about the use of your personal information:
- Where the basis for processing is your consent, you may withdraw that consent at any time by contacting us.
- If your personal information is incorrect, you may request that errors or incomplete entries be rectified
- In certain circumstances, you may have the right to be forgotten and your data erased. Please contact if you wish to exercise this right.
- Whilst any request is being investigated, you have the right to restrict processing, so that your information will simply be stored.
- You can request the return of transfer of any personal data you have given to us in a portable electronic format
- We do not use automated decision making and profiling of your personal information without human intervention.
To exercise any of these rights, please contact us in writing at Bespoke Training & Development, 71-75 Shelton Street, London, WC2H 9JQ, United Kingdom
The source the personal data originates from and whether it came from publicly accessible sources
Your personal information is collected ether directly from you, or from your employer if they have a contract with us to provide product and services
Whether the provision of personal data part of a statutory or contractual requirement or obligation and possible consequences of failing to provide the personal data
Your personal information is processed as part of our contract to provide product and services
The existence of automated decision making, including profiling and information about how decisions are made, the significance and the consequences.
We do not use automated decision making or profiling of any kind.
The right to lodge a complaint with a supervisory authority
You have the right to complain to the Information Commissioners Office by
- Helpline. Call them on 0303 123 1113, Monday to Friday between 9am and 5pm.
- Live chat. Have an online conversation with someone at the ICO at https://ico.org.uk/global/contact-us/live-chat/.
- Email. Use the form at https://ico.org.uk/global/contact-us/email/
You also the right to seek legal redress in the event of suffering harm which you do not feel has been sufficiently addressed by us or by the ICO.
A.3 How we manage the personal data used in direct marketing (displayed on the website, and via a link on all marketing emails)
The identity and contact details of the controller
The Data Controller is Bespoke Training & Development, 71-75 Shelton Street, London, WC2H 9JQ, United Kingdom
To contact the Data Controller, please email info@bespoke.ltd
We are not required to have a designated data protection officer under the UK-GDPR.
Purpose of the processing and the lawful basis for the processing
We are using your personal information to carry out our direct marketing activities for those individuals or organisations that are not already customers.
Our basis for processing is your consent to the processing of this personal data for the specific purposes of direct marketing, or the use of information not identified with an individual.
Alternatively, we may use legitimate interests as a legal basis for processing based on your role and interests evidenced through information provided to public forums such as LinkedIn.
In either case, if you no longer wish to receive communications, you may contact us, and we will desist.
If you are still unhappy, you may object to us or to the ICO as described below
Categories of personal data
The categories of personal data we hold are:
Name & contact details
Any recipient or categories of recipients of the personal data
We may share this information with other organisations employed to work on our behalf, as they carry out much of our telemarketing activity on our behalf.
Details of transfers to third country and safeguards
Internally, Bespoke process personal information within the UK. Bespoke use Microsoft as an information processor and make use of Microsoft cloud-based online services. Microsoft online services create system-generated logs as part of the regular operation of the services. These logs continuously record system activity over time to allow Microsoft to monitor whether systems are operating as expected. “Logging” (the storage and processing of logs) is essential to identify, detect, respond to, and prevent operational problems, policy violations, and fraudulent activity; optimize system, network, and application performance; assist in security investigations and resilience activities; and to comply with laws and regulations. While the focus of these logs is on how systems are operating and not on individual users, when events in Microsoft cloud services are initiated by user interaction with a cloud service, some logs directly reflecting these events will – and must in order to fulfil their purposes – contain fields that either identify or can identify specific persons. These logs contain personal data. Examples of system-generated logs that may contain personal data include:
- Product and service usage data such as user activity logs
- Data specifically generated by the interaction of users with other systems
Some personal data may be stored on Microsoft servers outside the UK, but within the EU through the implementation of the EU Data Boundary. This is a geographically defined boundary within which Microsoft has committed to store and process Customer Data and personal data for our Microsoft enterprise online services, including Azure, Dynamics 365, Power Platform, and Microsoft 365. Professional Services Data will be stored at rest for these services. These commitments are subject to limited circumstances where Customer Data, personal data, and Professional Services Data will continue to be transferred outside the EU Data Boundary. This documentation provides details about those transfers. The online services included in the EU Data Boundary commitment (referred to in this documentation as EU Data Boundary Services) are identified in the Microsoft Product Terms as part of the services agreements. Under GDPR, the safeguards provided for personal information within the EU are the same as in the UK
Retention period or criteria used to determine the retention period
We will retain your personal data whilst we have a legal basis for doing so, either your consent, which may be withdrawn at any time, or legitimate interests, in which case you may ask us to cease processing your information at any time.
The existence of each of the data subject’s rights
You have the following rights about the use of your personal information:
- As the basis for processing is your consent, you may withdraw that consent at any time by contacting us.
- If your personal information is incorrect, you may request that errors or incomplete entries be rectified
- In certain circumstances, you may have the right to be forgotten and your data erased. Please contact if you wish to exercise this right.
- Whilst any request is being investigated, you have the right to restrict processing, so that your information will simply be stored.
- You can request the return of transfer of any personal data you have given to us in a portable electronic format
- We do not use automated decision making and profiling of your personal information without human intervention.
To exercise any of these rights, please contact us in writing at Bespoke Training & Development, 71-75 Shelton Street, London, WC2H 9JQ, United Kingdom
The source the personal data originates from and whether it came from publicly accessible sources
Your personal information is collected directly from you.
Whether the provision of personal data part of a statutory or contractual requirement or obligation and possible consequences of failing to provide the personal data
Your personal information is not part of any statutory requirements
The existence of automated decision making, including profiling and information about how decisions are made, the significance and the consequences.
We do not use automated decision making or profiling of any kind.
The right to lodge a complaint with a supervisory authority
You have the right to complain to the Information Commissioners Office by
- Helpline. Call them on 0303 123 1113, Monday to Friday between 9am and 5pm.
- Live chat. Have an online conversation with someone at the ICO at https://ico.org.uk/global/contact-us/live-chat/.
- Email. Use the form at https://ico.org.uk/global/contact-us/email/
You also the right to seek legal redress in the event of suffering harm which you do not feel has been sufficiently addressed by us or by the ICO.
