Valor People Consulting Ltd
Privacy Policy
Last updated: August 2026
Introduction
Your privacy matters to us. This Privacy Policy explains, in plain terms, how Valor People Consulting Ltd (“we”, “us”, or “our”) collects, uses, shares, and protects your personal data when you visit our website at www.valor-consulting.com, get in touch with us, or engage our consultancy services.
We are committed to protecting your personal data and handling it responsibly, in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and — where it applies to our processing of personal data relating to individuals in the European Economic Area (EEA) — the EU General Data Protection Regulation (EU GDPR).
If you have any questions about this policy or how we handle your personal data, please contact us using the details below.
1. Important Information and Who We Are
Valor People Consulting Ltd is the data controller responsible for your personal data.
Registered company number: 15458647
Registered office address: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
ICO registration number: ZB779935
Data Protection Contact: Juan Novoa — dataprotection@valor-consulting.com
Our Data Protection Contact is responsible for overseeing questions about this policy. If you have any questions or wish to exercise any of your rights, please contact them at the email address above.
This policy covers personal data relating to our website visitors, prospective clients, clients, and other business contacts. It does not cover personal data we process on behalf of our clients when delivering consultancy projects — that processing is governed by the separate agreements we put in place with each client (see Section 2).
2. The Data We Collect About You
Personal data means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).
We may collect, use, store, and transfer the following kinds of personal data about you:
Identity Data: first name, last name, title, job title, and company name.
Contact Data: business address, billing address, email address, and telephone numbers.
Financial Data: bank account details and payment information (processed through secure payment and accounting providers).
Transaction Data: details of payments to and from you, and records of the services and contracts you have entered into with us.
Technical Data: internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system, and platform used to access our website.
Usage Data: information about how you use our website and services.
Marketing and Communications Data: your preferences in receiving marketing from us and your communication preferences.
We may also collect and use Aggregated Data, such as statistical or demographic data, for business purposes. Aggregated Data may be derived from your personal data but is not treated as personal data in law, as it does not directly or indirectly identify you.
Special category data
We do not intentionally collect special category personal data (such as data revealing racial or ethnic origin, health, religious beliefs, or sexual orientation) through our website or our general business relationship with you.
Some of our consultancy work — for example equal pay audits, pay gap reporting, or job evaluation — may involve special category data relating to our clients’ employees. Where this is the case, we act as a data processor on behalf of the client, and that processing is governed by a separate written agreement with the client rather than by this policy.
If you fail to provide personal data
Where we need to collect personal data by law, or under the terms of a contract we have with you, and you do not provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you. In that case we may have to cancel a service you have with us, but we will notify you if this is so at the time.
3. How We Collect Your Personal Data
We collect personal data about you through:
Direct interactions: you provide your Identity, Contact, and Financial Data when you fill in forms on our website, request or schedule a consultation, correspond with us by email, post, or phone, or enter into a contract for our services.
Automated technologies or interactions: as you use our website, we automatically collect Technical and Usage Data about your equipment and browsing actions using cookies and similar technologies. Please see our Cookie Policy for details of the cookies we use and how you can manage them.
Third parties or publicly available sources: we may receive Identity and Contact Data from publicly available sources such as Companies House, professional networks such as LinkedIn, and business information providers.
4. How We Use Your Personal Data and Our Legal Grounds
We will only use your personal data when the law allows us to. Most commonly, we rely on the following legal bases:
Performance of a contract: where we need to perform a contract we are about to enter into or have entered into with you.
Legitimate interests: where it is necessary for our legitimate interests (or those of a third party), provided your interests and fundamental rights do not override those interests.
Legal obligation: where we need to comply with a legal or regulatory obligation.
Consent: in limited circumstances, such as certain marketing communications, where the law requires your consent. You can withdraw consent at any time.
The table below sets out the main ways we use your personal data and the legal bases we rely on. We may rely on more than one basis depending on the specific purpose.
| Purpose / Activity | Type of Data | Legal Basis for Processing |
|---|---|---|
| To register you as a new client and set up our working relationship | Identity, Contact | Performance of a contract with you |
| To deliver our consultancy services, manage billing, and collect payment | Identity, Contact, Financial, Transaction | Performance of a contract with you; legitimate interests (to recover debts due to us) |
| To manage our ongoing relationship, including notifying you of changes to our terms or this policy | Identity, Contact, Marketing and Communications | Performance of a contract with you; legal obligation; legitimate interests (to keep our records up to date) |
| To administer and protect our business and website, including troubleshooting, data analysis, system maintenance, and security | Identity, Contact, Technical, Usage | Legitimate interests (running our business, IT and network security); legal obligation |
| To send you relevant industry insights, updates, or event invitations | Identity, Contact, Marketing and Communications | Consent (where required); legitimate interests (to develop and grow our business) |
5. Marketing and Your Communication Preferences
We may send you industry insights, updates, or invitations to events we think may be of interest to you, where we are permitted to do so. Where the law requires it, we will only send these with your consent.
You have the right to ask us to stop sending you marketing communications at any time — either by using the “unsubscribe” link in any marketing email, or by contacting us at dataprotection@valor-consulting.com. You also have an absolute right to object to your personal data being used for direct marketing.
Opting out of marketing will not affect any processing we carry out to provide our services to you under a contract.
6. Disclosures of Your Personal Data
We may share your personal data with the following categories of third parties for the purposes set out above:
- Service providers acting as processors, including IT support, cloud storage and hosting providers (for example Microsoft 365 or Google Workspace), CRM platforms, email providers, and cloud accounting software providers.
- Professional advisers, including lawyers, accountants, auditors, bankers, and insurers.
- Regulators and authorities, including HM Revenue & Customs, the Information Commissioner’s Office, and other regulatory or law enforcement bodies where we are legally required to disclose your data.
- Third parties in connection with a business sale or restructuring, where we sell, transfer, or merge parts of our business. If this happens, the new owners may use your personal data in the same way as set out in this policy.
We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes, and we only permit them to process it for specified purposes and in accordance with our instructions.
7. International Data Transfers
Some of our service providers can be based outside the UK and the EEA, which means the processing of your personal data may involve a transfer of data outside these areas. Whenever we transfer your personal data out of the UK or EEA, we ensure a similar degree of protection by making sure at least one of the following safeguards is in place:
- We transfer your personal data to countries that have been deemed to provide an adequate level of protection under UK or EU adequacy regulations; or
- We use specific contracts approved for use in the UK and/or EEA (such as the UK International Data Transfer Agreement or Addendum, or the EU Standard Contractual Clauses) that give personal data the same protection it has in the UK and EEA.
Please contact us if you would like more information about the specific mechanism we use when transferring your personal data internationally.
8. Data Security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorised way, altered, or disclosed. We limit access to your personal data to those employees, contractors, and other third parties who have a genuine business need to know, and they are subject to a duty of confidentiality.
We have procedures in place to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
9. Data Retention
We will only keep your personal data for as long as necessary to fulfil the purposes we collected it for, including to satisfy any legal, accounting, or reporting requirements.
To decide the appropriate retention period, we consider the amount, nature, and sensitivity of the data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it, and whether we can achieve those purposes by other means.
Where we must keep basic information about our clients for legal or tax purposes, we will normally retain it for six years after the end of our relationship with you. In some circumstances we may keep certain records for longer where the law requires, or anonymise your data so it can no longer be associated with you, in which case we may use it indefinitely without further notice.
10. Your Legal Rights
Under the UK GDPR and EU GDPR, you have the following rights in relation to your personal data:
- The right to be informed about how we use your personal data.
- The right of access to your personal data (commonly known as a data subject access request).
- The right to rectification of inaccurate or incomplete data.
- The right to erasure of your personal data (the “right to be forgotten”) where there is no good reason for us to continue processing it.
- The right to restrict processing of your personal data in certain circumstances.
- The right to object to processing where we rely on legitimate interests, and an absolute right to object to direct marketing.
- The right to data portability, allowing you to obtain and reuse your data for your own purposes.
- The right to withdraw consent at any time where we rely on consent to process your data. This will not affect the lawfulness of any processing carried out before you withdraw.
To exercise any of these rights, please contact our Data Protection Contact at dataprotection@valor-consulting.com. You will not usually have to pay a fee. We aim to respond to all legitimate requests within one calendar month; occasionally it may take us longer if your request is particularly complex or you have made several requests, in which case we will notify you and keep you updated.
11. Automated Decision-Making
We do not make decisions based solely on automated processing (including profiling) that produce legal effects concerning you or similarly significantly affect you.
12. Children’s Data
Our website and services are directed at businesses and professionals, and are not intended for children. We do not knowingly collect personal data relating to children. If you believe we have inadvertently collected such data, please contact us and we will delete it.
13. Third-Party Links
Our website may include links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy practices. When you leave our website, we encourage you to read the privacy policy of every website you visit.
14. Changes to This Privacy Policy
We may update this policy from time to time to reflect changes in our practices or for legal, regulatory, or operational reasons. When we do, we will revise the “Last updated” date at the top of this policy. Where changes are significant, we will take reasonable steps to notify you. We encourage you to review this policy periodically.
15. How to Contact Us and Complaints
If you have any questions about this policy, or wish to exercise any of your rights, please contact:
Data Protection Contact: Juan Novoa
Email: dataprotection@valor-consulting.com
Valor People Consulting Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
You also have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues, at https://www.ico.org.uk. If you are based in the EEA, you may also lodge a complaint with your local supervisory authority. We would, however, appreciate the chance to address your concerns before you approach the regulator, so please contact us in the first instance.
