Back to the site

Privacy Notice

PN-001 v1.2 · Last updated 23 September 2026

1. Who we are

Wright Frameworks Ltd ("we", "us", "our") is the data controller for the personal data described in this notice.

Registered nameWright Frameworks Ltd
Company number17412236
Place of registrationEngland and Wales
Registered office71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Privacy contactprivacy@wrightframeworks.co.uk
ICO registrationZC228428

We are not required to appoint a Data Protection Officer under Article 37 of the UK GDPR, because we are not a public authority, we do not carry out large-scale systematic monitoring, and we do not process special category data on a large scale. Data protection matters are handled by the owner at the privacy contact address above.

2. What this notice covers

This notice explains how we handle personal data submitted through the client enquiry form on our website. It covers the information you give us when you ask us about our services.

3. What personal data we collect

When you submit the enquiry form we collect:

DataSourceWhy we need it
Full nameYouTo address you correctly and identify your enquiry
OrganisationYouTo know which organisation you are enquiring for, and to prepare a relevant response
Business email addressYouTo reply to your enquiry
Telephone numberYou, if you choose to give itTo call you, if you have asked us to. It is optional unless you choose telephone as your preferred contact method
Preferred contact methodYouTo contact you in the way you have asked
Service of interestYouTo route your enquiry and prepare a relevant response
Your enquiry messageYouTo understand and answer what you have asked
Privacy notice versionAutomatically addedTo record which version of this notice applied at the time
Source pageAutomatically addedTo record which page the enquiry came from
Date receivedAutomatically addedRecord-keeping and response tracking
Correlation IDAutomatically generatedA random reference used to trace a single submission in our logs

We also generate technical service logs when you use the site. These are created by Microsoft Azure as part of hosting and may include browser user-agent, request time, error details and an approximate location (town or city level) derived from your IP address at the time of the request. The IP address itself is not retained. They are used for security, fault diagnosis and service availability only.

Please do not include sensitive information in your message. The enquiry form is for initial business contact. Do not send health information, information about criminal offences, or other special category data through it.

4. Why we process it, and our legal basis

PurposeLegal basis (UK GDPR Article 6)
Responding to your enquiry and discussing whether we can helpArticle 6(1)(b) — taking steps at your request before entering into a contract
Keeping a record of enquiries received and how they were handledArticle 6(1)(f) — legitimate interests
Securing our systems, diagnosing faults and preventing misuseArticle 6(1)(f) — legitimate interests
Meeting our legal, accounting and regulatory obligationsArticle 6(1)(c) — legal obligation

Where we rely on legitimate interests, those interests are running and administering our consultancy business, maintaining an accurate record of client and prospective client contact, and keeping our systems secure. We have considered your interests and rights and consider this processing to be within your reasonable expectations, because you contacted us. You can object to this processing — see section 8.

5. Marketing

We will not add you to a marketing list, send you marketing emails or make marketing calls to you on the basis of an enquiry alone. If you give us a telephone number, we will use it only to respond to your enquiry. If we ever wish to send you marketing, we will ask for your consent separately, and every marketing message will contain a one-click unsubscribe. This reflects our obligations under the Privacy and Electronic Communications Regulations 2003 (PECR).

6. Who your data is shared with

We do not sell your personal data and we do not share it for anyone else's marketing.

Your enquiry is processed using Microsoft services, which act as our processor under a written data processing agreement (the Microsoft Products and Services Data Protection Addendum):

We may also disclose personal data to our professional advisers, or where we are required to do so by law or by a regulator.

7. International transfers

Your enquiry data is stored in the United Kingdom.

Microsoft may access data from outside the UK for limited support, engineering and security purposes. Where that happens, the transfer is covered by the safeguards in Microsoft's data protection addendum, which incorporates the UK International Data Transfer Addendum to the EU Standard Contractual Clauses under Article 46 of the UK GDPR. You can ask us for more information about these safeguards using the contact details in section 1.

8. How long we keep it

RecordRetention
Enquiry that does not lead to an engagement24 months from the date of last contact, then deleted
Enquiry that leads to an engagementRetained as part of the client record for 6 years after the engagement ends, reflecting the limitation period under the Limitation Act 1980 and HMRC record-keeping requirements
Technical service logs90 days

9. Your rights

Under the UK GDPR you have the right to:

To exercise any of these rights, contact us using the details in section 1. We will respond within one month. We may need to ask you for information to confirm your identity before we act on a request; if we do, the response period begins when we receive that information. There is normally no charge.

Automated decision-making. We do not carry out automated decision-making that produces legal or similarly significant effects, and we do not carry out profiling.

10. Complaints

If you are unhappy with how we have handled your personal data, please tell us first using the contact details in section 1. Under the Data (Use and Access) Act 2025 you have a statutory right to complain to us directly. We will acknowledge your complaint within 30 days and keep you informed of the outcome. Our procedure is set out in DPC-001 Data Protection Complaints Procedure.

You also have the right to complain to the Information Commissioner's Office at any time:

Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF Helpline: 0303 123 1113 — https://ico.org.uk/make-a-complaint/

Complaining to us first does not affect your right to go to the ICO.

11. Is providing your data required?

Providing your name, organisation, email address, preferred contact method, service of interest and message is not a statutory or contractual requirement, but the form cannot be submitted without them, because we cannot respond to an enquiry without them. Your telephone number is optional, unless you ask us to contact you by telephone. You can contact us by other means instead.

12. Changes to this notice

We keep this notice under review. Each version has an identifier (this is PN-001 v1.2) and the version applying at the time of your submission is recorded with your enquiry. Material changes will be published on this page before they take effect.