1Who we are
Probative Co is a company registered in England and Wales. Registration, VAT and ICO details are set out in our procurement pack, which we send on request and confirm in writing before any engagement starts. We are the controller for the personal data described in this notice.
For anything to do with this notice or your data: diin@probativeco.com. We are a small firm without a statutory data protection officer; the person who answers that address is accountable for it, and will tell you who they are.
2What this notice covers
- This website — the pages you are reading, and the forms on them.
- Enquiries and marketing — when you contact us, download a resource, or subscribe to our newsletter.
- Engagements — personal data we handle while delivering work for a client, in our capacity as controller for our own records (correspondence, billing, conflict checks) and as processor under the client's DPA for the client's data.
It does not cover the personal data inside client files, where the client is the controller and we act on their instructions.
3What we collect
| Source | What we collect | Why |
|---|---|---|
| Newsletter and free-resource forms | Work email address; optional topic preferences; the resource you asked for | To send what you asked for, and the monthly brief if you want it |
| Onboarding forms | Your name, role, work email, firm name and size, and the operational details the form asks for (systems, volumes, contacts, dates) | To scope and quote an engagement properly, and to deliver it |
| Contact and enquiry forms | Name, work email, firm, what you tell us in your message | To answer you and to run a conflict check before engagement |
| Engagement correspondence | Names, contact details, professional role information, and the content of messages and documents sent to us | To deliver the engagement and keep a professional record |
| Billing | Invoice contact, purchase-order references, payment status | To invoice and to meet accounting and tax obligations |
| Card payments | Handled entirely by our payment processor | We never see or store card numbers |
| Server logs | Standard request data processed by our hosting provider for security and availability | Security, abuse prevention and service reliability |
No cookies, no analytics, no tracking pixels. This site sets no cookies for advertising or analytics, embeds no social media trackers, and runs no third-party analytics. Web fonts are loaded from Google Fonts, which means Google sees your IP address as part of serving the file; that is the only third-party request the site makes, and a self-hosted font build removes it. We do not attempt to identify individual visitors.
4Lawful bases
| Processing | Lawful basis (UK GDPR art 6) |
|---|---|
| Sending a resource you requested, and the newsletter | Consent, which you can withdraw at any time — every email has a one-click unsubscribe |
| Answering an enquiry and quoting for work | Legitimate interests (responding to a business request), and steps preliminary to a contract |
| Delivering an engagement, including file review | Performance of a contract, or steps taken at the client's request |
| Conflict checks, independence records and professional standards | Legitimate interests (professional integrity and independence), and legal obligation where applicable |
| Invoicing, accounting and tax records | Legal obligation |
| Security monitoring of our systems | Legitimate interests (protecting client data and our systems) |
| Establishing or defending legal claims | Legitimate interests, and legal obligation where applicable |
Where we rely on legitimate interests, we have balanced those interests against your rights and expectations; you can ask us for that assessment. Where we rely on consent, you can withdraw it as easily as you gave it.
5Special category data
Some engagements involve limited special category data — for example, identity documents or information about a client's political exposure or criminal convictions where that is relevant to anti-money-laundering obligations. In those cases we process it as the client's processor under the client's instructions and their article 9 condition, on a strictly limited, need-to-know basis, for the sole purpose of the engagement. We do not use it for any other purpose, and we delete it in accordance with the engagement letter.
6AI-assisted processing, and what it does not mean
Some of our services use our own tooling to perform a structured first pass over document sets. That processing involves personal data, so it is worth being specific about it:
- A human decides every outcome. There is no solely automated decision-making with a legal or similarly significant effect on anyone; every finding is confirmed, rejected or escalated by a qualified specialist, and rejections are retained in the audit trail.
- No training on your data. Personal data in client material is not used to train any model, ours or a third party's.
- No profiling. We do not build profiles, score individuals, or make inferences about data subjects beyond the compliance question being assessed.
- Controlled environment. Processing happens in the environment agreed with the client, with access limited to the named reviewer and logged.
- Recorded and reproducible. We record the ruleset and model versions used, so any output can be traced and challenged.
Where we use a third-party AI tool in delivery, it is named in our subprocessor list below before it is used, and the client is told before the engagement begins.
7Who we share personal data with
We do not sell, rent or trade personal data, and we do not share it for marketing. We share it only with the service providers we need to run the business and deliver engagements, and only as necessary:
| Subprocessor | Purpose | Location | Status |
|---|---|---|---|
| Cloudflare, Inc. | Website hosting and content delivery (Pages), form submission storage (KV) | Global edge network; KV data stored in the region configured for the account | in use |
| Google Fonts | Web font delivery for this website | EU/US | in use |
| Stripe Payments UK Ltd | Card payments, where a client chooses to pay by card | UK/EU | pending |
| Secure file transfer provider | Encrypted transfer of client files | To be confirmed at launch | pending |
| Email provider | Transactional and newsletter email | To be confirmed at launch | pending |
We may also disclose personal data where we are required to by law, by a court order, or by a regulator, and to our professional advisers and insurers where necessary. Where disclosure is compelled, we will tell you unless we are prohibited from doing so.
8International transfers
Our website and forms are hosted on a global content network, and some providers process data outside the UK. Where personal data is transferred outside the UK, we rely on an adequacy regulation or on the International Data Transfer Agreement / the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment where required. You can ask us which mechanism applies to a particular provider.
9How long we keep it
| Record | Retention |
|---|---|
| Enquiries and correspondence | 24 months from last contact |
| Newsletter subscriptions | Until you unsubscribe, then deleted within 5 working days |
| Onboarding form submissions | 12 months |
| Client files provided for review | Deleted on completion of the engagement, with written confirmation |
| Engagement records and deliverables | 6 years after the engagement ends, for professional indemnity and accounting purposes |
| Website logs, cookies and analytics | Not retained: the site sets no cookies and runs no analytics |
When a retention period ends we delete the data or, where deletion is not immediately possible (for example, in an encrypted backup cycle), we isolate it and delete it on the next cycle. Deletion is confirmed in writing on request.
10Your rights
You have the right to:
- be informed — this notice, and answers to any question about it;
- access the personal data we hold about you, and receive a copy;
- rectify anything inaccurate or incomplete;
- erase data where there is no good reason for us to keep it;
- restrict processing while a question about accuracy or lawfulness is resolved;
- object to processing based on legitimate interests, and to direct marketing at any time;
- portability — receive data you gave us in a structured, machine-readable format, or have it sent to another controller; and
- withdraw consent at any time where consent is the basis, without affecting processing already carried out.
To exercise any of these, email diin@probativeco.com. We will respond within one month, and there is no charge unless a request is manifestly unfounded or excessive. We may ask for proof of identity where there is doubt — a reasonable precaution, not an obstacle. If we cannot do what you ask (for example, because we must keep an invoice for tax purposes), we will explain why and tell you what we can do instead.
11Security
We keep personal data secure: encryption in transit and at rest, access limited to those who need it, multi-factor authentication on the accounts that matter, logged access to client material, encrypted transfer rather than email attachments, and deletion on completion. Our controls, certifications and subprocessors are set out on our security page.
12If something goes wrong
If we become aware of a personal data breach affecting your data, we will notify affected clients without undue delay and within 48 hours, with the information they need to meet their own obligations to the ICO and to data subjects. Where we are the controller and the breach is reportable, we will notify the ICO within 72 hours and tell you if you are affected.
13Complaints
Tell us first: diin@probativeco.com. We would rather fix it than have you escalate it, and we will tell you honestly what happened. You also have the right to complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint or on 0303 123 1113. We will not treat a complaint to the ICO as a reason to stop dealing with you.
14Children
Our services are provided to businesses and professionals. We do not knowingly collect personal data from children through this website, and we do not market to children.
15Changes to this notice
If we change how we use personal data, we update this page and the version number above. Material changes affecting newsletter subscribers are also emailed to them. Previous versions are available on request.