Privacy Policy

Privacy Policy

PRIVACY NOTICE

Last updated: 16 July 2026

1. Who we are

Pheon Agency Ltd provides consultancy, commissioning, recruitment, training, governance, compliance, HR and business-support services to organisations operating within the health and social care sector.

For the purposes of UK data-protection law, Pheon Agency Ltd is the data controller responsible for deciding how and why your personal information is used.

Data controller: Pheon Agency Ltd
Registered office: 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
Website: www.pheonagency.co.uk
Privacy enquiries: help@pheonagency.co.uk

2. The information we collect

We may collect and process the following personal information:

your name;

your email address;

your telephone number;

your organisation or employer;

your job title or professional role;

information contained in enquiries, correspondence or consultation requests;

details about services you have requested or purchased;

records of meetings, telephone calls and business communications;

invoicing, payment and transaction information;

feedback, complaints and service-review information;

marketing preferences;

information you provide when applying for a role or subcontracting opportunity;

technical information such as your IP address, browser type, device type and website usage data;

information collected through essential cookies and, where permitted, analytics cookies.

Please do not submit confidential information about service users, patients, employees or other third parties through a general website contact form unless we have specifically asked you to do so and an appropriate secure method has been agreed.

3. How we collect personal information

We may collect personal information:

directly from you when you complete a website form;

when you telephone, email or otherwise contact us;

when you request a consultation, proposal or service;

when you become a client, supplier, contractor or business contact;

when you attend a meeting, event, training session or conference;

through professional networking and publicly available business sources;

through referrals from existing clients or professional contacts;

through website cookies and analytics tools;

from organisations that instruct us or work with us in delivering services.

Where another person or organisation provides your details to us, we will only use them where there is a lawful reason to do so.

4. Why we use personal information

We may use personal information to:

respond to enquiries and requests for information;

arrange consultations, meetings and demonstrations;

prepare quotations, proposals and contracts;

provide consultancy, commissioning, recruitment, training, HR, governance or compliance services;

manage client, supplier and subcontractor relationships;

communicate about ongoing work and agreed actions;

maintain service, financial and business records;

issue and process invoices and payments;

manage complaints, concerns and feedback;

recruit employees, consultants or subcontractors;

meet legal, regulatory, insurance and professional obligations;

protect our systems, website, staff, clients and business;

improve our website and services;

send relevant business information or marketing communications where permitted;

establish, exercise or defend legal claims.

We will not use personal information for purposes that are incompatible with the reason it was originally collected unless this is permitted or required by law.

5. Our lawful bases for processing

We rely on one or more of the following lawful bases:

Contract

We may process your information where this is necessary to:

take steps at your request before entering into a contract;

provide services under a contract;

manage a client, supplier or subcontractor relationship;

process payments or fulfil agreed obligations.

Legal obligation

We may process information where necessary to comply with legal duties relating to matters such as:

taxation and accounting;

company administration;

employment;

health and safety;

safeguarding;

regulatory requirements;

fraud prevention;

responding to lawful requests from authorities.

Legitimate interests

We may process information where this is necessary for our legitimate business interests and where those interests are not overridden by your rights.

These interests may include:

responding to business enquiries;

developing and managing professional relationships;

improving and promoting our services;

protecting our business and systems;

maintaining appropriate records;

managing disputes and legal claims;

understanding how our website is used;

communicating with existing clients and relevant business contacts.

Where we rely on legitimate interests, we consider the necessity and proportionality of the processing and its possible effect on the individual.

Consent

We may rely on your consent where:

you have agreed to receive certain marketing communications;

you have accepted non-essential website cookies;

consent is otherwise the most appropriate lawful basis.

You may withdraw consent at any time. Withdrawal will not affect processing that took place before consent was withdrawn.

Vital interests

In rare circumstances, we may use personal information where this is necessary to protect someone’s life.

6. Special-category and sensitive information

We do not normally seek to collect health information, racial or ethnic information, religious beliefs, trade-union membership, sexual-orientation information or other special-category data through this website.

Such information may occasionally be processed where it is relevant to a consultancy, employment, recruitment, safeguarding or legal matter. Where this occurs, we will identify both an appropriate lawful basis and an additional condition for processing special-category information.

We will only process criminal-offence information where this is lawful, necessary and subject to appropriate safeguards.

7. Marketing communications

We may send relevant business-to-business information to existing clients, prospective organisational clients or professional contacts where permitted by law.

Where consent is required, we will obtain it before sending marketing communications.

You may ask us to stop sending marketing communications at any time by:

using the unsubscribe option in the communication; or

contacting us using the privacy contact details above.

Stopping marketing communications will not prevent us from sending service, contractual, financial or legal messages where these remain necessary.

8. Cookies and website analytics

Our website may use cookies and similar technologies.

Essential cookies may be used to:

enable the website to function;

maintain security;

remember necessary settings;

support forms and website navigation.

Non-essential cookies, including analytics or marketing cookies, should only be used where you have provided the required consent.

Analytics information may help us understand:

how visitors reach the website;

which pages are viewed;

how long visitors remain on the website;

which devices or browsers are used;

whether website errors occur.

You can manage non-essential cookies through the website’s cookie settings and may also change your browser settings. Disabling some cookies may affect how the website operates.

9. Who we may share information with

We may share personal information where necessary with:

employees, authorised consultants and subcontractors;

website, hosting, email and IT-service providers;

cloud-storage and business-software providers;

professional advisers, including accountants, solicitors and insurers;

payment, banking and financial-service providers;

training, recruitment and compliance-service providers;

clients or commissioning organisations where this is required to deliver an agreed service;

government departments, regulators, courts, law-enforcement bodies or local authorities where required or permitted by law;

a purchaser, investor or adviser involved in a proposed sale, merger, restructuring or transfer of the business.

We require service providers acting on our behalf to protect personal information and to use it only for the agreed purpose.

We do not sell personal information to advertisers or unrelated third parties.

10. International transfers

Some technology or cloud-service providers may store or process information outside the United Kingdom.

Where personal information is transferred internationally, we will take reasonable steps to ensure that an appropriate legal safeguard is in place. This may include:

transferring information to a country recognised as providing adequate protection;

using approved contractual safeguards;

relying on another lawful transfer mechanism;

carrying out a transfer-risk assessment where required.

Further information about relevant safeguards may be requested using the contact details above.

11. How long we keep information

We keep personal information only for as long as reasonably necessary for the purpose for which it was collected and to meet legal, contractual, regulatory, insurance and professional requirements.

Our usual retention periods are:

General website enquiries: up to 24 months after the last meaningful contact;

Unsuccessful quotations or proposals: normally up to 24 months after the proposal closes;

Client and contract records: normally six years after the end of the contractual relationship;

Invoices, payments and accounting records: normally six years after the end of the relevant financial year;

Supplier and subcontractor records: normally six years after the relationship ends;

Routine business correspondence: normally up to six years where it relates to contracted services or legal obligations;

Marketing records: until you opt out, the information becomes inaccurate or the purpose no longer applies;

Recruitment information for unsuccessful applicants: normally six months after the recruitment process, unless a longer period has been agreed;

Complaint, dispute or legal-claim records: for as long as necessary to manage the matter and any applicable limitation period;

Cookie and analytics information: according to the retention period stated within the website’s cookie settings or the relevant analytics provider.

We may retain information for longer where:

there is an ongoing complaint, investigation or legal claim;

a regulator, court or public authority requires it;

safeguarding or public-protection considerations apply;

there is another lawful and documented reason.

Information that is no longer required will be securely deleted, destroyed or anonymised.

12. How we protect personal information

We take reasonable technical and organisational measures to protect personal information against:

unauthorised access;

accidental loss;

alteration;

disclosure;

misuse;

destruction.

Measures may include:

access controls;

password protection;

multi-factor authentication where available;

device and system security;

secure cloud storage;

staff confidentiality requirements;

data-protection procedures;

secure disposal arrangements;

limiting access to people who need the information for their role;

reviewing suspected data breaches.

No website, email service or internet transmission can be guaranteed to be completely secure. You should avoid sending highly sensitive or confidential information through an ordinary website form or unencrypted email.

13. Your data-protection rights

Depending on the circumstances, you may have the right to:

Be informed

You have the right to understand how and why we use your personal information.

Access your information

You may request a copy of the personal information we hold about you.

Correct inaccurate information

You may ask us to correct incomplete or inaccurate information.

Request deletion

You may ask us to delete personal information in certain circumstances. This right is not absolute and may not apply where information must be retained for legal, contractual or legitimate reasons.

Restrict processing

You may ask us to limit how we use your information in certain circumstances.

Object to processing

You may object where processing is based on legitimate interests or is being used for direct marketing.

Data portability

Where processing is based on consent or contract and carried out electronically, you may have the right to receive certain information in a structured, commonly used and machine-readable form.

Withdraw consent

Where we rely on consent, you may withdraw it at any time.

Rights concerning automated decisions

You may have rights where a decision with legal or similarly significant effects is made solely through automated processing.

Pheon Agency Ltd does not normally make such decisions through its website.

14. Making a rights request

To exercise a data-protection right, please contact us using the privacy contact details in this notice.

We may need to request information to confirm your identity and ensure that personal information is not disclosed to the wrong person.

We will normally respond within one month. The response period may be extended where a request is complex or where several requests have been made, but we will explain this where applicable.

There is usually no charge for exercising your rights. A reasonable fee may be charged, or a request refused, where it is manifestly unfounded or excessive.

15. Complaints

Please contact Pheon Agency Ltd in the first instance if you have concerns about how your personal information has been handled. We will investigate the matter and try to resolve it.

You also have the right to complain to the UK supervisory authority:

Information Commissioner’s Office

Telephone: 0303 123 1113
Website: www.ico.org.uk
Postal address:

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

You may raise a complaint with the ICO at any time, although it will generally expect you to have raised the issue with us first.

16. Third-party websites

Our website may contain links to websites operated by other organisations.

Pheon Agency Ltd is not responsible for the privacy practices, security or content of third-party websites. You should read the privacy notice of any external website you visit.

17. Children’s information

Our website and consultancy services are primarily directed at businesses and adult professionals. We do not knowingly collect personal information directly from children through the website.

Where information about a child is processed as part of a legitimate professional service, it will be handled according to applicable data-protection, safeguarding and confidentiality requirements.

18. Changes to this privacy notice

We may update this privacy notice to reflect:

changes in our services;

changes in technology or website functions;

changes in the organisations that process information on our behalf;

changes in data-protection law or regulatory guidance.

The latest version will be published on our website with its updated date.

19. Contact us

Questions, concerns and requests concerning personal information should be sent to:

Pheon Agency Ltd
71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
Email: help@pheonagency.co.uk
Website: www.pheonagency.co.uk

Information icon

We need your consent to load the translations

We use a third-party service to translate the website content that may collect data about your activity. Please review the details in the privacy policy and accept the service to view the translations.