Skip to main content

UK Privacy Notice & Data Protection Policy

UK GDPR & DPA 2018 Effective Date: 1 January 2026 Last Updated: August 2026 Version: v1.0 (Live)

1. Who We Are & Controller Identity

This Privacy Notice is issued on behalf of Kevron Consulting UK Limited ("we", "us", "our"), a company registered in England and Wales under Company Registration Number 16156557, having its registered office at 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, and operating facilities in Ruislip, London.

Kevron Consulting UK Limited operates as the statutory Data Controller for personal data collected through this United Kingdom regional digital portal (https://www.kevrongroup.com/uk), direct client enquiries, consultancy proposals, training registrations, and commercial engagements originating within the United Kingdom. Where services involve international group operations, Kevron Group entities process information in accordance with documented intra-group data transfer agreements and technical security safeguards.

2. Scope & Applicable Law

This notice describes how we collect, use, store, share, and protect personal data in compliance with:

  • The UK General Data Protection Regulation (UK GDPR);
  • The Data Protection Act 2018 (DPA 2018);
  • The Privacy and Electronic Communications Regulations 2003 (PECR) as amended.

This notice applies to website visitors, prospective and active consultancy clients, training course learners, procurement representatives, job applicants, and participants in our webinars and educational programmes.

3. Personal Information We Collect

We may collect and process the following categories of personal data:

A. Identity & Contact Information Full name, business title, corporate email address, telephone number, organisation name, registered business address, and operational site locations.
B. Commercial & Project Scoping Data Consultancy brief requirements, site audit specifications, quotation parameters, tender documents, contract milestones, billing contact details, and VAT registration status.
C. Learner, Training & Assessment Data Course enrolment records, Virtual Learning Environment (VLE) credentials, assessment submissions, attendance logs, exam proctoring verifications (where enrolled), and accredited certificate records.
D. Technical & Usage Data Browser user agent, IP address (hashed or anonymised for audit logging), regional market preference (`kv_market`), theme mode selection, and aggregated navigation metrics.
E. Recruitment & Applicant Data Curriculum vitae, professional certifications (e.g. IOSH, NEBOSH, CMIOSH), employment history, references, right to work verification in the UK, and candidate correspondence.

4. How We Collect Your Data

We collect personal information through several touchpoints:

  • Direct Interactions: When you complete our Contact form, Request a Quote Wizard, submit a procurement inquiry, register for a course, download a technical capability brief, or contact our support team.
  • Automated Client Technologies: As you navigate our website, strictly necessary technical cookies and preference settings are loaded. Optional performance telemetry is captured only upon explicit consent.
  • Third-Party Corporate Clients: When an employer or corporate sponsor registers you for accredited health and safety training or compliance assessment under an enterprise agreement.

5. Lawful Bases for Processing

Under UK GDPR Article 6, we process your personal data under the following approved lawful bases:

Contractual Necessity (Art 6(1)(b))

Processing necessary to provide requested consultancy proposals, execute service contracts, deliver training courses, and process professional service orders.

Legitimate Interests (Art 6(1)(f))

Operating our business securely, responding to B2B inquiries, preventing fraud, maintaining platform resilience, and managing client relationships.

Legal Obligation (Art 6(1)(c))

Fulfilling statutory requirements including accounting, tax reporting (HMRC), corporate transparency, and mandatory safety audit record retention.

Consent (Art 6(1)(a))

Where you have voluntarily opted into our technical insight newsletters, marketing communications, or non-essential analytics/marketing cookies.

6. Service-Specific Processing Activities

  • Enquiries & Quote Requests: Data submitted via our Quote Wizard or contact channels is used exclusively to evaluate your requirements and provide formal service proposals. Marketing consent is strictly optional.
  • Training & Virtual Learning (LMS): Learner details, progress metrics, and assessment evaluations are maintained to issue accredited qualification records and certificate verifications.
  • E-Commerce & Digital Downloads: Shop transactions record order items, billing addresses, and digital delivery tokens. Payment card data is processed directly by PCI-DSS Level 1 compliant processors; card details are never stored on Kevron servers.
  • Corporate Portal & B2B Governance: Client administrator and user accounts are processed under the governing enterprise agreement to manage team bookings, compliance dashboards, and service scheduling.

7. Cookies & Storage Access Technologies

We govern our client-side storage technologies in strict accordance with PECR Regulation 6 and UK GDPR. We categorise technologies into Strictly Necessary, Functional & Preferences, Performance & Analytics, and Marketing.

For complete details regarding individual cookies, providers, retention periods, and statutory exemptions, please review our dedicated Cookie Policy & Technology Inventory. You can adjust your consent choices at any time via the .

8. Direct Marketing & Preference Management

We respect your communication choices. In accordance with PECR and UK GDPR:

  • Marketing consent is never a pre-condition for requesting a quotation, submitting an operational enquiry, or accessing client support.
  • All email bulletins contain an instant, single-click unsubscribe link.
  • You can manage your subscribed technical topics (e.g. CDM Regulations, ISO Systems, ESG) in our dedicated Email Preference Centre.

9. Data Sharing & Third-Party Processors

We do not sell, rent, or trade your personal data. We disclose personal information only to vetted third-party data processors operating under binding Data Processing Agreements (DPAs) that enforce UK GDPR standard obligations:

  • Accreditation Bodies: Where you complete certified training courses (e.g. IOSH, NEBOSH), candidate information is submitted for official qualification registration.
  • Cloud Infrastructure & Hosting: Secure enterprise cloud hosting facilities operating with ISO 27001 certification.
  • Transactional Email & CRM: Specialized communication platforms delivering operational service confirmations and quote schedules.
  • Professional Advisors & Regulators: Legal, financial, and insurance advisors, or law enforcement bodies where strictly required by statutory obligation.

10. International Data Transfers

Where personal data is transferred outside the United Kingdom or the European Economic Area (EEA), we ensure adequate safeguards are in place pursuant to UK GDPR Chapter V:

  • Transfers to countries recognised by the UK Government as providing an adequate level of data protection;
  • Execution of the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (SCCs);
  • Implementation of supplementary technical controls including end-to-end encryption.

11. Data Retention Criteria

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying legal, accounting, audit, and reporting obligations:

Processing Category Retention Period Retention Basis
General Enquiries & Quotes 24 months from last interaction Commercial follow-up and relationship management
Executed Client Contracts & Safety Audits 6 years from project completion Limitation Act 1980 / Statutory commercial liability
Financial & VAT Records 6 years + current financial year HMRC statutory accounting compliance
Accredited Learner Certifications Permanent / Awarding Body requirement Qualification verification for employers and learners
Marketing Subscriptions Until consent withdrawal / unsubscribe Immediate suppression upon preference update

12. Technical & Data Security

We implement appropriate technical and organisational security measures to protect personal data against accidental loss, unauthorised access, alteration, or disclosure. These include TLS 1.3 encryption in transit, encrypted storage volumes, role-based access control (RBAC), automated threat logging, and routine vulnerability assessments.

13. Your Statutory Privacy Rights

Under UK data protection law, you hold statutory rights regarding your personal information:

  • Right of Access: Request a copy of the personal data we hold about you (Data Subject Access Request).
  • Right to Rectification: Request correction of inaccurate or incomplete personal information.
  • Right to Erasure (Right to be Forgotten): Request deletion of your personal data where no overriding legal basis for retention exists.
  • Right to Restriction: Request suspension of processing while an accuracy or lawful basis dispute is resolved.
  • Right to Data Portability: Obtain personal data you provided to us in a structured, machine-readable format.
  • Right to Object: Object to processing based on legitimate interests or direct marketing at any time.
  • Right to Withdraw Consent: Where processing relies on consent, you may withdraw consent at any time without affecting prior lawful processing.

14. Complaints & Supervisory Authority Escalation

If you have any concerns regarding our data processing, we encourage you to contact our Privacy Team directly so we can resolve the matter promptly.

You also have the statutory right to lodge a complaint with the UK data protection supervisory authority:

Information Commissioner's Office (ICO) Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113 | Website: ico.org.uk

15. Contact Our Privacy Team

To exercise your data protection rights, submit a privacy inquiry, or update your information, please contact our designated Privacy Team:

Privacy & Data Protection Contact: Kevron Consulting UK Limited
Postal Address: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ

Ready to Strengthen Your Safety Systems, CDM Governance & ESG Compliance?

Speak with Kevron Consulting UK Limited about ISO 45001 systems, CDM compliance, workplace risk audits, and tailored competence programmes.