Privacy Policy

1. Who I am

This website is operated by Michael Potts (“I”, “me” or “my”). “Michael Potts Consulting” is the proposed trading style used to describe the commercial growth and business improvement service presented on this website.

For the purposes of UK data-protection law, Michael Potts is the data controller for the personal information described in this policy.

Website: https://mikepotts.co.uk
Location: Lydney, Gloucestershire, United Kingdom
Privacy enquiries: Please use the contact form at https://mikepotts.co.uk/contact/

2. Information I collect

I may collect and process the following personal information:

  • your name;

  • your business or organisation name;

  • your email address;

  • your telephone number, if you choose to provide it;

  • information you include in the contact form about your business, enquiry or commercial challenge;

  • correspondence and records of communications between us;

  • information needed to prepare a proposal, provide services, manage a client relationship or issue invoices; and

  • limited technical information recorded by the website or hosting provider for security, maintenance and troubleshooting purposes, which may include an IP address, browser type, device type and access time.

Please do not include sensitive personal information in the contact form unless it is genuinely necessary for your enquiry.

3. How I collect your information

I collect information when you:

  • submit the website contact form;

  • contact me by email, telephone, LinkedIn or another agreed method;

  • ask for a proposal or enter into discussions about my services;

  • become a client or supplier; or

  • otherwise provide information to me during our business relationship.

Contact-form submissions are stored within the website’s WordPress database and may also be sent to me by email.

4. Why I use your information and my lawful bases

I use personal information only when I have a lawful reason to do so.

Responding to enquiries

I use the information you provide to understand your enquiry, respond to you and decide whether my services may be suitable. I do this because it is necessary to take steps at your request before entering into a possible contract and because I have a legitimate interest in responding to genuine business enquiries.

Preparing and delivering services

If you become a client, I use your information to prepare proposals, agree the scope of work, communicate with you and provide the agreed services. The lawful basis is normally performance of a contract or taking steps before entering into a contract.

Administration, accounting and legal obligations

I may use and retain information to issue invoices, maintain business and tax records, manage payments, establish or defend legal claims and comply with legal or regulatory requirements. The lawful bases are legal obligation and, where appropriate, my legitimate interests in managing and protecting my business.

Website security and improvement

I may process limited technical information to protect the website, prevent spam or misuse, investigate faults and maintain security. This is based on my legitimate interests in operating a secure and reliable website.

I do not currently use information collected through this website for automated decision-making or profiling.

5. Marketing

Submitting an enquiry does not subscribe you to marketing. I will not add your details to a marketing list or send regular promotional emails unless you have specifically asked or agreed to receive them.

You may ask me to stop direct marketing at any time.

6. Who I share information with

I do not sell personal information.

Where necessary, information may be shared with carefully selected service providers that support the operation of the business, such as:

  • website hosting, maintenance, security and backup providers;

  • email and communications providers;

  • accounting, bookkeeping and professional advisers;

  • IT support providers; and

  • public authorities, regulators, courts or law-enforcement bodies where disclosure is required by law.

Service providers are permitted to use information only as necessary to provide their services and must handle it securely and in accordance with applicable data-protection requirements.

7. International transfers

Some technology or communications providers may process information outside the United Kingdom. Where this happens, I will take reasonable steps to ensure that an appropriate legal safeguard is in place, such as an adequacy regulation or an approved contractual safeguard.

8. How long I keep information

I keep personal information only for as long as reasonably necessary for the purpose for which it was collected.

  • Enquiries that do not become client engagements will normally be retained for up to 12 months after the last meaningful contact.

  • If trading begins, client, supplier, contractual, invoice and accounting records may be retained for the period required by tax, accounting and legal requirements. If I operate as a sole trader, relevant business records generally need to be retained for at least five years after the 31 January Self Assessment submission deadline for the relevant tax year.

  • Information needed for an ongoing dispute, complaint or legal claim may be kept until the matter is resolved and any relevant limitation period has expired.

  • Technical and security records are retained only for the period reasonably required for security, maintenance or troubleshooting.

Information may be securely deleted or anonymised when it is no longer required.

9. How I protect information

I use reasonable technical and organisational measures designed to protect personal information against accidental loss, misuse, unauthorised access, alteration or disclosure. These measures include access controls, password protection, website security measures, software updates and the use of reputable service providers.

No internet transmission or storage system can be guaranteed to be completely secure, but I take proportionate steps to protect the information under my control.

10. Your data-protection rights

Depending on the circumstances, you may have the right to:

  • ask for a copy of the personal information I hold about you;

  • ask for inaccurate or incomplete information to be corrected;

  • ask for your information to be deleted;

  • ask me to restrict how your information is used;

  • object to processing based on legitimate interests or to direct marketing;

  • receive certain information in a portable format; and

  • withdraw consent where processing is based on consent.

These rights are not absolute and exemptions may apply. To make a request, use the contact form at https://mikepotts.co.uk/contact/. I may need to verify your identity before responding.

You also have the right to complain to the Information Commissioner’s Office. Information about raising a concern is available at https://ico.org.uk/make-a-complaint/.

11. Third-party links

The website may contain links to external websites, including LinkedIn. I am not responsible for the privacy practices or content of third-party websites. You should review their privacy information before providing personal information to them.

12. Children

This website and my services are intended for businesses and adults. They are not directed at children, and I do not knowingly collect children’s personal information through the website.

13. Changes to this policy

I may update this Privacy Policy when the website, my services or legal requirements change. The latest version will be published on this page and identified by the “Last updated” date.

14. Contact

For questions about this policy or how I use personal information, please use the contact form at https://mikepotts.co.uk/contact/.

 

Scroll to Top