Privacy Policy

Our contact details
Name: Sam Barratt Business Solutions
E-mail: sam@sambarrattbusinesssolutions.co.uk 

The type of personal information we collect
We currently collect and process the following information:
  • Personal identifiers, contacts and characteristics (for example, name and contact details) 
  • Business information (company name, role, business details)
  • Communications (enquiries, messages, and correspondence)
  • Client work data (information necessary to deliver contracted services, which may include operational, HR, or business data shared by clients)
  • In the context of safeguarding consultancy services, we may process information relating to safeguarding concerns or incidents, which may include special category data.
How we get the personal information and why we have it
Most of the personal information we process is provided to us directly by you for one of the following reasons:
  • You have filled out the contact me form on the website 
  • When you contact us by email, phone, or social media
  • When you engage Sam Barratt Business Solutions for services and share information necessary to carry out that work
We use the information that you have given in order to:
  • Respond to enquiries submitted via the website contact form 
  • Deliver contracted services to clients 
  • Fulfil our legal and regulatory obligations, including those related to safeguarding 
  • Manage our business operations and client relationships 
We rely on the following lawful bases under UK GDPR, depending on the nature of the processing: 
Consent (Article 6(1)(a)) applies to website enquiries and any marketing communications. You can withdraw consent at any time by contacting sam@sambarrattbusinesssolutions.co.uk 
Contract (Article 6(1)(b)) applies where processing is necessary to deliver services under a client agreement. 
Legal obligation (Article 6(1)(c)) applies where we are required to process data to comply with UK law. 
Legitimate interests (Article 6(1)(f)) applies to business administration and maintaining client relationships, where this does not override your rights. 
Recognised legitimate interests (Article 6(1)(e1), introduced under the Data (Use and Access) Act 2025) applies where processing is necessary for safeguarding vulnerable people in the context of our safeguarding consultancy services. 
Where we process special category data in a safeguarding context, we rely on Article 9(2)(g) (substantial public interest) and the safeguarding of children and individuals at risk provisions under Schedule 1 of the Data Protection Act 2018.

How we store your personal information
Your data is stored securely using password-protected systems and encrypted platforms. We do not store personal data on unsecured devices or share it with third parties outside of the service delivery outlined in this policy.

Retention periods: 
  • Website enquiry data: 1 year from the date of enquiry 
  • Client data: for the duration of the contract and 6 years thereafter, in line with standard UK contract limitation periods 
  • Safeguarding records: in line with statutory guidance and the specific requirements of the client organisation
Third parties and data processors In delivering our services, we may use the following categories of tools and platforms, which may process personal data on our behalf:
  • Email and document platforms (such as Google Workspace)
  • Scheduling and communication tools
  • Cloud storage
All third-party processors are selected on the basis that they provide adequate data protection safeguards. We do not sell your data to any third party.

We do not use automated decision-making or profiling that produces legal or similarly significant effects in relation to any individual.

Data breaches
In the unlikely event of a personal data breach, we have procedures in place to contain and assess the impact. Where we are legally required to do so, we will notify you and the Information Commissioner's Office (ICO) without undue delay. We will always inform you if a breach is likely to result in a high risk to your rights and freedoms.

Your data protection rights Under data protection law, you have rights including: 

Your right to rectification – You have the right to ask us to rectify personal information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete. 
Your right to erasure – You have the right to ask us to erase your personal information in certain circumstances. 
Your right to restriction of processing – You have the right to ask us to restrict the processing of your personal information in certain circumstances. 
Your right to object to processing – You have the right to object to the processing of your personal information in certain circumstances. 
Your right to data portability – You have the right to ask that we transfer the personal information you gave us to another organisation, or to you, in certain circumstances. 
Your right to withdraw consent – When we use consent as our lawful basis you have the right to withdraw your consent. You are not required to pay any charge for exercising your rights. If you make a request, we have one month to respond to you. Please contact us at sam@sambarrattbusinesssolutions.co.uk if you wish to make a request. 

Your right of access (subject access request (SAR))
You have the right to ask us what personal data we hold about you and to request a copy. This is known as a subject access request (SAR).
To make a request, email sam@sambarrattbusinesssolutions.co.uk with the subject line "SAR request". You do not need to use legal language, just let us know what you would like to see or understand.
We will respond within one calendar month of receiving your request. If your request is complex or you have made several requests in a short period, we may extend this period by a further two months under proportionality provisions of the Data (Use and Access) Act 2025. We will always explain why and keep you informed of progress.
We will not charge a fee for standard requests. However, a reasonable fee may be applied if a request is clearly excessive or repetitive.
If you are unhappy with how we handle your request, you can raise a concern with the Information Commissioner's Office (ICO) 

Do we use artificial intelligence?
We integrate artificial intelligence (AI) tools into our work to support efficiency and the quality of our services. These tools may assist with drafting and reviewing documents , research, and generating visual content for marketing materials.
Where a tool is provided by a third party provider, they act as data processor. We have listed the tools we currently use below, along with links to their privacy policies.

AI Tool - ChatGPT
Provider - OpenAI
Purpose - Drafting and reviewing documents, research

AI Tool - Claude
Provider - Anthropic
Purpose - Drafting and reviewing documents, research
Privacy Policy -
anthropic.com/privacy

AI Tool - Canva AI
Provider - Canva
Purpose - Generating visual content for marketing materials
Privacy Policy - canva.com/policies/privacy-policy

We will always ask for your written permission before using AI tools to support the needs of your business. Any data processed by AI tools is handled in compliance with applicable data protection legislation.

While we take care to ensure accuracy, AI generated outputs are not infallible. You should independently verify any AI assisted work before relying on it. 

If you have any questions about our use of AI, or wish to object to automated processing, please contact sam@sambarrattbusinesssolutions.co.uk 

Do we transfer your data internationally?
Some of the tools and platforms we use to deliver our services are based outside the United Kingdom. This means that when we use these tools, your personal data may be transferred and processed outside the UK. These include, but are not limited to, cloud storage and productivity platforms (such as iCloud and Microsoft365), AI tools (such as ChatGPT and Claude), and design platforms (such as Canva). 

Whenever we transfer your personal data outside the UK, we ensure it is protected by relying on one or more of the following safeguards:
  • The country has been deemed to provide an adequate level of data protection by the UK government.
  • The service provider uses contracts approved by the Information Commissioner's Office that give your data the same protection it has in the UK.
  • The provider participates in a recognised data protection framework.
If you would like further information about the safeguards we have in place for any specific tool or transfer, please contact sam@sambarrattbusinesssolutions.co.uk
 
How to make a data protection complaint
If you have concerns about how we have handled your personal data, you have the right to raise a complaint directly with us. Under the Data (Use and Access) Act 2025, we are required to have a formal process in place for handling data protection complaints. To raise a complaint: Email sam@sambarrattbusinesssolutions.co.uk with the subject line “Data protection complaint”. Please include your name, contact details, and a description of your concern. 

What happens next: 
  • We will acknowledge your complaint within 30 days of receipt 
  • We will investigate your concern and keep you informed of progress 
  • We will provide a written outcome once the investigation is complete If you are not satisfied with our response, or if we have not resolved your complaint within a reasonable timeframe, you can escalate to the Information Commissioner’s Office (ICO): 
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline number: 0303 123 1113
ICO website: https://www.ico.org.uk/make-a-complaint

To access Sam Barratt Business Solutions Data Protection Complaints Policy and Notice please click here

Last updated 4th June 2026 

Search