Privacy Policy

1. Introduction

Origin8tive Ltd ("Origin8tive", "we", "us", "our") is committed to protecting the privacy of the people who use our website, engage our services, and interact with us professionally.

This policy explains what personal data we collect, why we collect it, how we use it, who we share it with, how long we keep it, and the rights you have in relation to your data. It covers our website at origin8tive.com and any subdomains we operate.

If you have questions about this policy or about how we handle your personal data, you can contact us using the details in Section 12.

2. Who are we

Origin8tive Ltd is a UK company registered in England and Wales.

Company number: 05215512
Registered office: Baileybrook Cottage, Hope Mansell, Ross-On-Wye, England, HR9 5TT

We are the data controller for the personal data described in this policy, which means we are responsible for deciding how it is collected and used.

3. Data protection contact

We have not appointed a statutory Data Protection Officer (DPO), as one is not legally required for our processing activities. Our nominated data protection contact is:

Name: Morgan Brudenell
Role: Human Resources Manager
Email: morgan.brudenell@origin8tive.com

Please direct any privacy-related enquiries, subject access requests, or complaints to this contact in the first instance.

4. What personal data we collect

We collect personal data in the following situations:

When you visit our website

Even if you do not fill in a form or contact us, we may automatically collect limited technical data such as your IP address, browser type and version, device type, operating system, referring URL, pages visited, and time spent on each page. This data helps us understand how our site is used and to keep it secure. Where this data is collected via cookies, see our Cookie Policy for detail.

When you contact us or complete a form

We collect the information you provide, which typically includes your name, job title, organisation, email address, phone number (if you choose to share it), and any details you include in your enquiry.

When you subscribe to our newsletter

If you sign up to receive the Origin8tive Cyber Assurance Briefing or any other communication, we collect your name, organisation, and email address.

When you apply for a role

If you apply for a job or send a speculative application, we collect the information contained in your CV, covering letter, and any application form fields. This may include contact details, employment history, qualifications, security clearance status (where relevant), and any other information you choose to include. Recruitment data is handled in line with our internal recruitment privacy notice, available on request.

When you engage us as a client or supplier

We collect the contact details of your representatives, records of our communications, and any commercial or contractual information needed to deliver the engagement.

Special category data

We do not routinely collect special category data (such as health, race, religion, or political opinions) through the website. Where such data is necessary in a recruitment or contractual context (for example, disability-related adjustments), it is handled with additional safeguards and only where lawful.

5. How we use your personal data

We use personal data for the following purposes, each of which is grounded in a lawful basis under UK GDPR:

To respond to enquiries and deliver services

Where you contact us with a question, request for information, or service enquiry, we use your data to respond and, where relevant, to progress the conversation into a commercial engagement. Lawful basis: legitimate interests (responding to your request) and, where a contract is agreed, contractual necessity.

To send you communications you have requested

If you subscribe to our Cyber Assurance Briefing or any other newsletter, we use your details to deliver those communications and to allow you to manage your subscription. Lawful basis: consent. You can withdraw consent at any time using the unsubscribe link in any communication or by contacting us directly.

To assess job applications

We use recruitment data to evaluate applications, contact candidates, arrange interviews, conduct pre-employment checks (with your consent), and manage the recruitment process. Lawful basis: taking steps at your request prior to entering a contract, and legitimate interests in identifying and hiring suitable candidates.

To improve our website and services

We use aggregated, non-identifiable usage data to understand how our site is used and to improve it. Lawful basis: legitimate interests in operating and improving our website.

To meet legal and regulatory obligations

We use and retain personal data where required by law, for example to comply with financial record-keeping, HMRC obligations, or lawful requests from public authorities. Lawful basis: legal obligation.

To protect the security of our systems

We may use technical data (including IP addresses and log data) to detect, investigate, and prevent malicious activity against our website and infrastructure. Lawful basis: legitimate interests in maintaining the security and integrity of our systems.

6. Who we share your personal data with

We do not sell your personal data. We share it only in the following limited situations:

  • Service providers we rely on to operate our business (for example, our website hosting, email delivery, CRM, HR, recruitment and applicant tracking systems, payroll and employee administration platforms and cloud infrastructure providers). All are contractually bound to protect your data and process it only on our instructions.
  • Professional advisers (accountants, lawyers, auditors) where relevant and only to the extent needed.
  • Clients or partners, where you have made an enquiry that needs to be routed through a specific engagement or partnership. In these cases we will only share data with your knowledge.

Some of our service providers may process personal data outside the UK, including in the European Economic Area (EEA) or the United States. Where personal data is transferred outside the UK, we ensure that appropriate safeguards are in place in accordance with applicable data protection law. These may include UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or another lawful transfer mechanism.

A full list of our current data processors can be provided on request.

7. How long we keep your personal data

We keep personal data only for as long as is necessary for the purpose for which it was collected, and to meet any legal, accounting, or reporting requirements. Typical retention periods:

  • Enquiry and general correspondence data: [insert retention period, e.g. 3 years after last contact]
  • Client contract and commercial records: for the duration of the engagement and [insert period, e.g. 7 years] afterwards, to meet HMRC and audit obligations
  • Newsletter subscriber data: for as long as you remain subscribed, and deleted within [insert period, e.g. 90 days] of unsubscribing
  • Unsuccessful job applicant data: [insert period, e.g. 12 months] unless you consent to us retaining your details for future opportunities
  • Website server logs and technical data: [insert retention period, typically 30 to 90 days]

At the end of the retention period, data is either deleted or fully anonymised so it can no longer be linked to you.

8. How we protect your personal data

As a cyber and software assurance specialist, we take data protection seriously. We apply appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These include:

  • Encryption in transit and, where appropriate, at rest
  • Access controls and role-based permissions across our systems
  • Regular review of our supplier and processor arrangements
  • Staff training on data protection and information security
  • Documented incident response procedures in the event of a suspected data breach

9. Your rights

Under UK GDPR, you have the following rights in relation to your personal data:

  • The right to be informed about how your data is used (this policy fulfils that right)
  • The right of access to a copy of your personal data (a "subject access request")
  • The right to rectification of inaccurate or incomplete data
  • The right to erasure of your data in certain circumstances
  • The right to restrict processing of your data in certain circumstances
  • The right to data portability, where processing is based on consent or contract
  • The right to object to processing based on legitimate interests
  • The right to withdraw consent at any time, where consent is the basis for processing
  • The right not to be subject to automated decision-making with significant effects (we do not use automated decision-making of this kind)

To exercise any of these rights, contact us using the details in Section 12.  We will respond to your request without undue delay and normally within one month. Where permitted by law, this period may be extended if your request is particularly complex or you have made multiple requests. We will let you know if an extension applies. We may need to verify your identity before responding.

10. Complaints

If you have a concern about how we handle your personal data, please contact us using the details in Section 12. We will acknowledge your complaint within 30 days, investigate it without undue delay, keep you informed of progress where appropriate, and let you know the outcome.

If you are not satisfied with our response, or you believe we are not handling your personal data in accordance with data protection law, you have the right to complain to the UK Information Commissioner's Office (ICO):

Website: ico.org.uk
Helpline: 0303 123 1113
Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

11. Changes to this policy

We may update this policy from time to time to reflect changes in our practices, technology, legal requirements, or other operational factors. The "Last updated" date at the top of this policy indicates when it was last revised. We encourage you to review it periodically. Where changes are material, we will bring them to your attention directly.

12. Contact us

For any question about this policy or about how we handle your personal data:

Email: morgan.brudenell@origin8tive.com
Post: Origin8tive Ltd, Baileybrook Cottage, Hope Mansell, Ross-On-Wye, England, HR9 5TT  

We aim to respond to all privacy enquiries within five working days.