Valor People Consulting Ltd

Privacy Policy

Last updated: August 2026

Introduction

Your privacy matters to us. This Privacy Policy explains, in plain terms, how Valor People Consulting Ltd (“we”, “us”, or “our”) collects, uses, shares, and protects your personal data when you visit our website at www.valor-consulting.com, get in touch with us, or engage our consultancy services.

We are committed to protecting your personal data and handling it responsibly, in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and — where it applies to our processing of personal data relating to individuals in the European Economic Area (EEA) — the EU General Data Protection Regulation (EU GDPR).

If you have any questions about this policy or how we handle your personal data, please contact us using the details below.

1. Important Information and Who We Are

Valor People Consulting Ltd is the data controller responsible for your personal data.

Registered company number: 15458647

Registered office address: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ

ICO registration number: ZB779935

Data Protection Contact: Juan Novoa — dataprotection@valor-consulting.com

Our Data Protection Contact is responsible for overseeing questions about this policy. If you have any questions or wish to exercise any of your rights, please contact them at the email address above.

This policy covers personal data relating to our website visitors, prospective clients, clients, and other business contacts. It does not cover personal data we process on behalf of our clients when delivering consultancy projects — that processing is governed by the separate agreements we put in place with each client (see Section 2).

2. The Data We Collect About You

Personal data means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).

We may collect, use, store, and transfer the following kinds of personal data about you:

Identity Data: first name, last name, title, job title, and company name.

Contact Data: business address, billing address, email address, and telephone numbers.

Financial Data: bank account details and payment information (processed through secure payment and accounting providers).

Transaction Data: details of payments to and from you, and records of the services and contracts you have entered into with us.

Technical Data: internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system, and platform used to access our website.

Usage Data: information about how you use our website and services.

Marketing and Communications Data: your preferences in receiving marketing from us and your communication preferences.

We may also collect and use Aggregated Data, such as statistical or demographic data, for business purposes. Aggregated Data may be derived from your personal data but is not treated as personal data in law, as it does not directly or indirectly identify you.

Special category data

We do not intentionally collect special category personal data (such as data revealing racial or ethnic origin, health, religious beliefs, or sexual orientation) through our website or our general business relationship with you.

Some of our consultancy work — for example equal pay audits, pay gap reporting, or job evaluation — may involve special category data relating to our clients’ employees. Where this is the case, we act as a data processor on behalf of the client, and that processing is governed by a separate written agreement with the client rather than by this policy.

If you fail to provide personal data

Where we need to collect personal data by law, or under the terms of a contract we have with you, and you do not provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you. In that case we may have to cancel a service you have with us, but we will notify you if this is so at the time.

3. How We Collect Your Personal Data

We collect personal data about you through:

Direct interactions: you provide your Identity, Contact, and Financial Data when you fill in forms on our website, request or schedule a consultation, correspond with us by email, post, or phone, or enter into a contract for our services.

Automated technologies or interactions: as you use our website, we automatically collect Technical and Usage Data about your equipment and browsing actions using cookies and similar technologies. Please see our Cookie Policy for details of the cookies we use and how you can manage them.

Third parties or publicly available sources: we may receive Identity and Contact Data from publicly available sources such as Companies House, professional networks such as LinkedIn, and business information providers.

4. How We Use Your Personal Data and Our Legal Grounds

We will only use your personal data when the law allows us to. Most commonly, we rely on the following legal bases:

Performance of a contract: where we need to perform a contract we are about to enter into or have entered into with you.

Legitimate interests: where it is necessary for our legitimate interests (or those of a third party), provided your interests and fundamental rights do not override those interests.

Legal obligation: where we need to comply with a legal or regulatory obligation.

Consent: in limited circumstances, such as certain marketing communications, where the law requires your consent. You can withdraw consent at any time.

The table below sets out the main ways we use your personal data and the legal bases we rely on. We may rely on more than one basis depending on the specific purpose.

Purpose / ActivityType of DataLegal Basis for Processing
To register you as a new client and set up our working relationshipIdentity, ContactPerformance of a contract with you
To deliver our consultancy services, manage billing, and collect paymentIdentity, Contact, Financial, TransactionPerformance of a contract with you; legitimate interests (to recover debts due to us)
To manage our ongoing relationship, including notifying you of changes to our terms or this policyIdentity, Contact, Marketing and CommunicationsPerformance of a contract with you; legal obligation; legitimate interests (to keep our records up to date)
To administer and protect our business and website, including troubleshooting, data analysis, system maintenance, and securityIdentity, Contact, Technical, UsageLegitimate interests (running our business, IT and network security); legal obligation
To send you relevant industry insights, updates, or event invitationsIdentity, Contact, Marketing and CommunicationsConsent (where required); legitimate interests (to develop and grow our business)

5. Marketing and Your Communication Preferences

We may send you industry insights, updates, or invitations to events we think may be of interest to you, where we are permitted to do so. Where the law requires it, we will only send these with your consent.

You have the right to ask us to stop sending you marketing communications at any time — either by using the “unsubscribe” link in any marketing email, or by contacting us at dataprotection@valor-consulting.com. You also have an absolute right to object to your personal data being used for direct marketing.

Opting out of marketing will not affect any processing we carry out to provide our services to you under a contract.

6. Disclosures of Your Personal Data

We may share your personal data with the following categories of third parties for the purposes set out above:

  • Service providers acting as processors, including IT support, cloud storage and hosting providers (for example Microsoft 365 or Google Workspace), CRM platforms, email providers, and cloud accounting software providers.
  • Professional advisers, including lawyers, accountants, auditors, bankers, and insurers.
  • Regulators and authorities, including HM Revenue & Customs, the Information Commissioner’s Office, and other regulatory or law enforcement bodies where we are legally required to disclose your data.
  • Third parties in connection with a business sale or restructuring, where we sell, transfer, or merge parts of our business. If this happens, the new owners may use your personal data in the same way as set out in this policy.

We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes, and we only permit them to process it for specified purposes and in accordance with our instructions.

7. International Data Transfers

Some of our service providers can be based outside the UK and the EEA, which means the processing of your personal data may involve a transfer of data outside these areas. Whenever we transfer your personal data out of the UK or EEA, we ensure a similar degree of protection by making sure at least one of the following safeguards is in place:

  • We transfer your personal data to countries that have been deemed to provide an adequate level of protection under UK or EU adequacy regulations; or
  • We use specific contracts approved for use in the UK and/or EEA (such as the UK International Data Transfer Agreement or Addendum, or the EU Standard Contractual Clauses) that give personal data the same protection it has in the UK and EEA.

Please contact us if you would like more information about the specific mechanism we use when transferring your personal data internationally.

8. Data Security

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorised way, altered, or disclosed. We limit access to your personal data to those employees, contractors, and other third parties who have a genuine business need to know, and they are subject to a duty of confidentiality.

We have procedures in place to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

9. Data Retention

We will only keep your personal data for as long as necessary to fulfil the purposes we collected it for, including to satisfy any legal, accounting, or reporting requirements.

To decide the appropriate retention period, we consider the amount, nature, and sensitivity of the data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it, and whether we can achieve those purposes by other means.

Where we must keep basic information about our clients for legal or tax purposes, we will normally retain it for six years after the end of our relationship with you. In some circumstances we may keep certain records for longer where the law requires, or anonymise your data so it can no longer be associated with you, in which case we may use it indefinitely without further notice.

10. Your Legal Rights

Under the UK GDPR and EU GDPR, you have the following rights in relation to your personal data:

  • The right to be informed about how we use your personal data.
  • The right of access to your personal data (commonly known as a data subject access request).
  • The right to rectification of inaccurate or incomplete data.
  • The right to erasure of your personal data (the “right to be forgotten”) where there is no good reason for us to continue processing it.
  • The right to restrict processing of your personal data in certain circumstances.
  • The right to object to processing where we rely on legitimate interests, and an absolute right to object to direct marketing.
  • The right to data portability, allowing you to obtain and reuse your data for your own purposes.
  • The right to withdraw consent at any time where we rely on consent to process your data. This will not affect the lawfulness of any processing carried out before you withdraw.

To exercise any of these rights, please contact our Data Protection Contact at dataprotection@valor-consulting.com. You will not usually have to pay a fee. We aim to respond to all legitimate requests within one calendar month; occasionally it may take us longer if your request is particularly complex or you have made several requests, in which case we will notify you and keep you updated.

11. Automated Decision-Making

We do not make decisions based solely on automated processing (including profiling) that produce legal effects concerning you or similarly significantly affect you.

12. Children’s Data

Our website and services are directed at businesses and professionals, and are not intended for children. We do not knowingly collect personal data relating to children. If you believe we have inadvertently collected such data, please contact us and we will delete it.

13. Third-Party Links

Our website may include links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy practices. When you leave our website, we encourage you to read the privacy policy of every website you visit.

14. Changes to This Privacy Policy

We may update this policy from time to time to reflect changes in our practices or for legal, regulatory, or operational reasons. When we do, we will revise the “Last updated” date at the top of this policy. Where changes are significant, we will take reasonable steps to notify you. We encourage you to review this policy periodically.

15. How to Contact Us and Complaints

If you have any questions about this policy, or wish to exercise any of your rights, please contact:

Data Protection Contact: Juan Novoa

Email: dataprotection@valor-consulting.com

Valor People Consulting Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ

You also have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues, at https://www.ico.org.uk. If you are based in the EEA, you may also lodge a complaint with your local supervisory authority. We would, however, appreciate the chance to address your concerns before you approach the regulator, so please contact us in the first instance.