How we collect, use and safeguard personal data — written plainly, for the professionals and organisations we work with. We hold data as a foundation to be protected, not a resource to be exploited.
Sylfaen Advisory Limited is a construction assurance consultancy registered in Wales, providing specialist information management, CDE engineering and ISO 19650 compliance services to the UK construction sector.
We are the data controller for the personal data described in this policy. The individual responsible for data protection is Mark Biscoe, Principal, who can be reached at mark@sylfaenadvisory.co.uk. Our company number is 17275026, and our ICO registration number is C1967400.
We are a business-to-business consultancy. The personal data we process relates to professional contacts at the organisations we work with or are in conversation with. Specifically:
We do not collect special category (sensitive) data, and we do not process consumer or individual-customer data. We only ask for what an engagement genuinely requires.
We rely on legitimate interests under Article 6(1)(f) of the UK GDPR as our lawful basis for processing personal data in a professional, business-to-business context.
We process your data to respond to business enquiries, to deliver consultancy services, to maintain professional relationship records, and to share occasional practice updates relevant to your work. We have assessed that this processing is necessary, limited, and within the reasonable expectations of professional contacts.
You have the right to object to processing carried out on the basis of legitimate interests at any time — see Section 07.
We do not carry out automated decision-making or profiling, and we do not send unsolicited marketing. Any non-essential communication is relevant to your professional role and easy to decline.
We retain personal data for three years from our last meaningful contact with you. After that, it is deleted in the ordinary course of our records housekeeping.
We keep data for longer only where a professional indemnity obligation requires it, and in that case we retain the minimum data necessary for that purpose alone. Where you ask us to erase your data, we action the request within 30 days.
We do not sell your data, and we never share it for marketing purposes. We use a small number of trusted processors purely to operate the practice:
We will disclose data to law enforcement or regulatory bodies only where we are legally required to do so.
Under UK GDPR you have the right to:
To exercise any of these, email mark@sylfaenadvisory.co.uk. We respond within 30 days and make no charge for reasonable requests.
We would always prefer to resolve any concern with you directly — so please contact us first, and we will do our best to put it right.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK’s data protection regulator:
We may update this policy from time to time. The “last updated” date in the sidebar always reflects the latest revision.
The current version is always available at sylfaenadvisory.co.uk/privacy.html.