Heyworth & Co Group Ltd
Privacy Notice
How Heyworth & Co Group Ltd collects, uses, stores and shares personal information in connection with heyworth.io and related business communications.
Version: 1.0
Effective from: 4 August 2026
Last updated: 4 August 2026
Key points
Heyworth & Co Group Ltd is the controller responsible for the personal information covered by this Privacy Notice.
We mainly process personal information when someone:
- visits heyworth.io;
- contacts us about the group, a Group Company or a Portfolio Business;
- discusses a business, strategic, investment, acquisition, funding, supplier or professional opportunity;
- communicates with us as a business contact, adviser, supplier or representative;
- reports a security concern;
- makes a complaint; or
- exercises a data-protection right.
We do not sell personal information.
For privacy requests or data-protection complaints, email using the subject line Data Protection.
1. About this Privacy Notice
1.1 Scope
This Privacy Notice explains how Heyworth & Co Group Ltd may collect, use, store, disclose and otherwise process personal information when you:
a. visit our Website;
b. contact us about the group, a company, venture, brand or business identified on the Website;
c. communicate with us by email, telephone, video call, post or another method;
d. discuss a prospective commercial, strategic, supplier, investment, acquisition, disposal, financing or professional relationship;
e. attend a meeting or event involving Heyworth & Co;
f. report a security concern;
g. make a complaint or exercise a data-protection right; or
h. otherwise interact with us in connection with the Website or our corporate activities.
1.2 Website covered
The Website covered by this Privacy Notice includes:
a. heyworth.io;
b. www.heyworth.io;
c. any subdomain of heyworth.io on which this Notice is published or linked; and
d. any replacement domain on which this Notice is published.
1.3 Other organisations
A Group Company, Portfolio Business or linked third party may be a separate controller responsible for its own processing.
Its privacy notice applies where it independently decides why and how personal information is used.
1.4 Other processing
Separate privacy information may apply to:
a. employees, workers and applicants;
b. shareholders or investors;
c. directors and officers;
d. customers or users of a Group Company or Portfolio Business;
e. a formal corporate transaction;
f. a service governed by a separate agreement; or
g. another product, platform, website or business.
1.5 Legal effect
This Privacy Notice provides information about our processing of personal information. It does not create contractual rights beyond those provided by applicable law.
Nothing in this Notice limits a right or protection that cannot lawfully be limited.
2. Who we are
2.1 Controller
The controller responsible for the personal information described in this Privacy Notice is:
Heyworth & Co Group Ltd
Company number: 14622566
Registered in: England and Wales
Registered office:
5 Ribblesdale Place
Preston
Lancashire
England
PR1 8BZ
Email:
2.2 Definitions
In this Privacy Notice:
a. Heyworth & Co, we, us and our mean Heyworth & Co Group Ltd;
b. personal information and personal data mean information relating to an identified or identifiable individual;
c. Group Company means a company that is a parent undertaking or subsidiary undertaking of Heyworth & Co within the meaning of applicable company law;
d. Portfolio Business means a company, venture, brand or activity identified on the Website as forming part of, being supported by, or otherwise being associated with Heyworth & Co; and
e. Website means the website described in section 1.2.
3. Personal information we may collect
3.1 Information you provide
When you contact or communicate with us, we may collect:
a. your name;
b. your business or personal email address;
c. your telephone number;
d. your job title, occupation or role;
e. the organisation you represent;
f. your organisation's website or business address;
g. the subject and content of your enquiry;
h. information about a proposed commercial, strategic, supplier, investment, acquisition, disposal, financing or professional opportunity;
i. documents, presentations, proposals or attachments you provide;
j. correspondence and written notes relating to calls or meetings;
k. your communication preferences; and
l. other information you choose to provide.
3.2 Corporate and transaction information
Where discussions progress, we may collect or create limited personal information concerning:
a. directors, officers, shareholders, beneficial owners, advisers and representatives;
b. professional experience and authority;
c. ownership and management structures;
d. conflicts of interest;
e. financial-crime, fraud, sanctions or reputational checks;
f. negotiation and decision records;
g. due-diligence material;
h. draft transaction documents; and
i. information reasonably required to assess, structure, approve, administer or protect a proposed relationship or transaction.
3.3 Technical Website information
When you access the Website, we and our hosting, networking, security or technical providers may process limited technical information, including:
a. your IP address;
b. the date and time of a request;
c. the page, resource or file requested;
d. the referring page or website;
e. browser type and version;
f. device type;
g. operating system;
h. approximate geographic information derived from an IP address;
i. HTTP request and response information;
j. diagnostic and error information;
k. security information; and
l. information used to detect unusual, malicious or automated traffic.
Some technical information may be processed through hosting, network, security and diagnostic logs even where the Website does not place cookies on your device.
3.4 Analytics information
Where Website analytics are enabled, we may collect or receive information such as:
a. page views and approximate visitor numbers;
b. pages visited;
c. referring websites or campaigns;
d. general geographic region;
e. browser, operating-system, device and screen information;
f. outbound-link activity;
g. interactions with selected Website elements; and
h. technical performance information.
We do not intend to configure Website analytics to receive enquiry contents, form-field contents, correspondence, credentials, confidential documents or special-category information.
3.5 Calls, meetings and transcription
We may process meeting invitations, attendance information, notes, follow-up actions and correspondence.
Where a call or meeting is recorded or transcribed, additional notice will be provided at or before recording where required.
3.6 Rights, complaints and security information
Where you exercise a legal right, make a complaint or report a security concern, we may collect:
a. your identity and contact details;
b. evidence of identity or authority;
c. details of your request, complaint or report;
d. correspondence and supporting documents;
e. technical information or evidence;
f. investigation notes and decisions;
g. professional advice;
h. actions considered or taken; and
i. the outcome and follow-up record.
3.7 Information you should not send without prior agreement
Unless we have specifically requested it and appropriate arrangements are in place, please do not send:
a. passwords or authentication credentials;
b. private encryption keys;
c. payment-card information;
d. confidential source code or production-system access information;
e. special-category personal information;
f. criminal-offence information;
g. legally privileged material;
h. material non-public or price-sensitive information;
i. information subject to another person's confidentiality rights; or
j. information you are not authorised to disclose.
If this type of information is sent without being requested, we may restrict access to it, return it, securely delete it, move it to an appropriate controlled process, or retain only what is reasonably necessary to deal with the communication, protect legal rights or comply with law.
4. Information received from other sources
We may receive limited personal information from:
a. a colleague or representative of your organisation;
b. a Group Company or Portfolio Business;
c. a client, supplier, lender, investor, funder or commercial counterparty;
d. a solicitor, accountant, tax adviser, auditor, insurer, broker or other professional adviser;
e. a referral source or business contact;
f. a publicly available company or professional source;
g. a professional-networking service;
h. a regulator, authority or screening provider; or
i. a person authorised to act on your behalf.
Where required by law, we will provide appropriate privacy information concerning personal information obtained from another source.
5. How we use personal information
We may use personal information to:
a. operate, maintain, secure and deliver the Website;
b. provide requested Website content and functionality;
c. understand, assess and respond to enquiries;
d. identify the person and organisation contacting us;
e. route an enquiry to a relevant Group Company or Portfolio Business;
f. arrange and administer calls, meetings and discussions;
g. assess a prospective business, strategic, supplier, professional, investment, acquisition, disposal, financing or other opportunity;
h. prepare, negotiate and administer proposals, heads of terms, contracts and transaction documents;
i. carry out proportionate corporate, conflict, fraud, sanctions, financial-crime, legal, regulatory, commercial and reputational checks;
j. manage relationships with Group Companies, Portfolio Businesses, advisers, suppliers and other business contacts;
k. administer group governance, ownership, intellectual property, finance and corporate affairs;
l. keep an appropriate history of communications, decisions and dealings;
m. understand Website use and performance;
n. improve Website content and user experience;
o. detect errors, misuse, fraud and security threats;
p. investigate vulnerability or security reports;
q. prevent duplicate, abusive, deceptive or unwanted communications;
r. maintain suppression or do-not-contact records;
s. respond to data-protection requests and complaints;
t. establish, exercise or defend legal rights;
u. comply with legal, regulatory, accounting, tax, insurance and corporate requirements;
v. manage an investment, sale, acquisition, financing, restructuring, insolvency or transfer;
w. protect Heyworth & Co, Group Companies, Portfolio Businesses, business contacts and Website visitors;
x. send relevant business communications where permitted by law; and
y. carry out another purpose that is reasonably compatible with the purposes described above.
We do not sell personal information or trade it as a commodity.
6. Our lawful bases
6.1 General
We must have a lawful basis for processing personal information. The basis used depends on the information, purpose and circumstances.
6.2 Lawful-basis summary
| Processing purpose | Lawful basis normally relied on |
|---|---|
| Operating, securing and maintaining the Website | Legitimate interests |
| Responding to enquiries and arranging discussions | Legitimate interests and, where applicable, steps requested before entering a contract |
| Assessing a business, strategic, supplier, professional or transaction opportunity | Legitimate interests and, where applicable, steps before entering a contract |
| Routing an enquiry to a relevant Group Company or Portfolio Business | Legitimate interests |
| Conducting proportionate due diligence, conflict, fraud, sanctions or reputational checks | Legitimate interests and legal obligation where applicable |
| Administering a contract with an individual | Contract |
| Managing business contacts where a contract is with an organisation | Legitimate interests |
| Website measurement and improvement | Legitimate interests, unless consent or another basis is required |
| Accounting, tax, corporate, regulatory and legal compliance | Legal obligation and legitimate interests |
| Establishing, exercising or defending legal claims | Legitimate interests and, where applicable, legal obligation |
| Direct marketing and business-development communications | Legitimate interests or consent, together with compliance with electronic-marketing rules |
| Processing based on a specific permission you give us | Consent |
6.3 Legitimate interests
Relevant legitimate interests may include:
a. operating and protecting the Website;
b. responding to enquiries;
c. developing and managing business relationships;
d. administering the group and its corporate affairs;
e. assessing opportunities and transactions;
f. keeping appropriate evidential and relationship records;
g. preventing fraud, misuse and security incidents;
h. protecting confidential information, systems, reputation and legal rights;
i. resolving complaints and disputes; and
j. sending relevant business-to-business communications where permitted.
Where appropriate, we consider the purpose and necessity of the processing, the nature of the information, what an individual may reasonably expect, possible effects on the individual and available safeguards.
6.4 Steps before a contract and contract
We may process information where necessary to take steps at your request before entering a contract, or to perform a contract with you as an individual.
Where a contract is with your employer, company, fund or another organisation, we will normally rely on legitimate interests or another appropriate basis when processing your business contact information.
6.5 Legal obligations
We may process personal information where necessary to comply with legal obligations concerning matters such as:
a. tax, accounting and corporate administration;
b. data protection;
c. sanctions, fraud and financial crime;
d. court or tribunal proceedings;
e. regulatory, law-enforcement or public-authority requests; and
f. legally required records.
6.6 Consent
We may rely on consent where it is appropriate or legally required.
Where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect processing carried out before consent was withdrawn and does not prevent processing under another lawful basis where one applies.
7. Cookies, analytics and similar technologies
7.1 Technical operation
The Website and its providers may use cookies, browser storage, scripts, tags or similar technologies where necessary or appropriate to:
a. deliver pages and requested functionality;
b. maintain security;
c. manage traffic;
d. prevent misuse;
e. remember a visitor choice; or
f. measure Website use and performance.
7.2 Consent and controls
Where consent or another user control is required by law, the relevant technology will be handled through an appropriate consent or preference mechanism.
7.3 Changes in technology
The providers and technologies used may change as the Website develops.
We will update this Notice or publish additional cookie and analytics information where required before introducing materially different tracking or advertising technologies.
8. Business communications and direct marketing
8.1 Enquiry-related communications
We may contact you about:
a. an enquiry you made;
b. a meeting or discussion you requested;
c. a current, prospective or previous business relationship;
d. a matter reasonably connected with your organisation; or
e. another matter where contact is permitted by law.
8.2 Direct marketing
Where a communication constitutes direct marketing, we handle it in accordance with data-protection and electronic-marketing law.
The rules may differ depending on whether the recipient is a corporate subscriber or an individual subscriber, such as a sole trader or certain partnerships.
Where consent or another specific condition is required, we will rely on it only where the relevant requirements are met.
8.3 Objections
You may object to direct marketing at any time.
Where a valid objection is received, we may retain limited information on a suppression list so that the objection continues to be respected.
9. Who we may share information with
9.1 General
We may share personal information only where reasonably necessary and where an appropriate lawful basis applies.
9.2 Group Companies and Portfolio Businesses
We may share information with a Group Company or Portfolio Business where reasonably necessary to:
a. route or respond to an enquiry relating to it;
b. assess or manage a shared business opportunity;
c. provide corporate, administrative, financial, technical or legal support;
d. manage group governance or intellectual property;
e. protect legal rights;
f. complete a restructuring or transaction; or
g. carry out another purpose explained at the time.
A Group Company or Portfolio Business may act as a separate controller where it determines its own purposes and methods of processing.
We will not ordinarily forward the full contents of an unsolicited first-contact enquiry to an unrelated commercial business merely because it may be interested.
9.3 Website, communication and operational providers
We may use providers of:
a. Website hosting, content delivery, networking and security;
b. business email;
c. calendars, video meetings and transcription;
d. cloud storage and document management;
e. project, task and relationship management;
f. backups, monitoring and diagnostics;
g. electronic signatures and transaction administration; and
h. general business administration.
9.4 Professional advisers and insurers
We may share information with solicitors, barristers, accountants, auditors, tax advisers, insurers, brokers, consultants, due-diligence providers and other professional advisers.
9.5 Prospective and actual transaction parties
Where appropriate, we may share limited information with prospective or actual:
a. purchasers or sellers;
b. investors or funders;
c. lenders;
d. transaction advisers;
e. counterparties;
f. insolvency practitioners; or
g. successors,
in connection with an investment, sale, acquisition, disposal, merger, financing, restructuring, insolvency process or transfer of assets or business operations.
We will seek to limit disclosure to what is reasonably necessary and use confidentiality or other safeguards where appropriate.
9.6 Authorities and legal recipients
We may disclose information to courts, tribunals, regulators, law-enforcement bodies, tax authorities, public authorities and other persons where disclosure is required or permitted by law.
10. International transfers
10.1 General
Some service providers, professional advisers, Group Companies, Portfolio Businesses or transaction counterparties may process personal information outside the United Kingdom.
10.2 Safeguards
Where rules concerning restricted international transfers apply, we will use or rely on an appropriate legal mechanism.
Depending on the recipient and circumstances, this may include:
a. UK adequacy regulations;
b. the UK Extension to the EU-US Data Privacy Framework where the recipient participates;
c. the UK International Data Transfer Agreement;
d. the UK Addendum to approved standard contractual clauses;
e. approved standard contractual clauses; or
f. another mechanism permitted by law.
We may review provider terms, carry out required assessments and implement additional contractual, technical or organisational safeguards.
You may contact us for further information about safeguards applying to a particular category of transfer.
11. How long we retain personal information
11.1 General approach
We keep personal information only for as long as reasonably required for the relevant purpose, subject to legal, accounting, security, transaction and claims-related requirements.
11.2 Normal retention periods
| Information category | Normal retention approach |
|---|---|
| Unsuccessful or inactive initial enquiries | Normally up to 3 years after the last meaningful contact |
| Developed commercial, strategic, investment, acquisition, financing or supplier discussions | Normally up to 6 years after the discussion or proposed relationship ends |
| Contracts, corporate, transaction, invoice, payment, tax and accounting records | Normally 6 years after the relevant financial year, transaction or relationship, subject to applicable requirements |
| Business contact and relationship records | While the relationship remains active and normally up to 3 years afterwards, unless a longer period is justified |
| Direct-marketing records | While marketing remains relevant and lawful; minimal suppression information may be retained for as long as needed to respect an objection |
| Technical, hosting, diagnostic and security logs | Normally up to 12 months, unless needed for an incident, investigation, dispute or legal claim |
| Data-protection rights and complaint records | Normally 6 years after the matter closes |
| Security and vulnerability reports | Normally up to 6 years after closure where needed for accountability or legal rights |
| Anonymised or aggregated information | May be retained for longer where it no longer identifies an individual |
11.3 Longer retention
We may retain information for longer where reasonably necessary because:
a. a complaint, dispute, investigation or legal claim exists or is reasonably anticipated;
b. a legal or regulatory hold applies;
c. law, insurance or a binding contractual obligation requires it;
d. the information is relevant to fraud, sanctions, misuse, security or legal rights; or
e. deletion is temporarily impracticable because information is held in a secure backup or archive.
11.4 Deletion and backups
When identifiable information is no longer reasonably required, it may be deleted, anonymised, aggregated, securely archived with restricted access or allowed to expire through ordinary backup and archive cycles.
Backup information is not ordinarily restored except for continuity, recovery, security or technical necessity. Where restored, applicable deletion and restriction decisions will be reapplied where reasonably practicable.
12. Security
We use organisational and technical measures intended to protect personal information against unauthorised access, accidental loss, misuse, alteration, inappropriate disclosure and destruction.
Measures may include:
a. access restrictions;
b. authentication;
c. encryption in transit;
d. supplier controls;
e. software updates;
f. security logging;
g. backups;
h. confidentiality obligations;
i. vulnerability management; and
j. incident-response arrangements.
The measures used depend on the nature of the information, systems involved, likelihood and severity of the risk, available technology and proportionality.
No internet service, system or electronic communication can be guaranteed to be completely secure.
You are responsible for choosing an appropriate method when sending confidential or sensitive information to us.
13. Artificial intelligence, recording and transcription
We do not intentionally use personal information submitted through the Website to train general-purpose artificial-intelligence models.
Where an approved AI-assisted, meeting-recording or transcription tool is used for business administration, analysis, drafting or summarisation, we will:
a. use it only where a lawful basis applies;
b. minimise the personal and confidential information provided;
c. apply proportionate supplier, access and retention controls; and
d. provide additional notice where required.
Do not send credentials, privileged material, price-sensitive information or confidential transaction information for use with such a tool unless an approved arrangement is in place.
14. Automated decision-making
We do not currently use personal information collected through the Website to make decisions producing legal or similarly significant effects through solely automated processing.
If this materially changes, appropriate privacy information and safeguards will be provided where required.
15. Your data-protection rights
15.1 Rights
Depending on the circumstances, processing and lawful basis used, you may have the right to:
a. ask whether we process your personal information;
b. obtain a copy of personal information we hold about you;
c. correct inaccurate or incomplete information;
d. ask us to erase personal information;
e. ask us to restrict processing;
f. object to processing;
g. receive certain information in a portable format;
h. withdraw consent where processing is based on consent; and
i. complain about how personal information has been handled.
These rights are subject to legal conditions, limitations and exemptions.
15.2 Identity and scope
We may request information reasonably required to:
a. verify your identity;
b. confirm your authority to act for another person;
c. identify the information concerned; or
d. clarify the scope of a request.
We will not request more information than is reasonably necessary.
15.3 Fees
We do not ordinarily charge a fee.
A reasonable fee may be charged, or a request may be refused, where permitted by law, including where a request is manifestly unfounded or excessive.
15.4 Response times
We respond to rights requests within the periods required by applicable data-protection law.
The usual period is one month after receiving the request and any information reasonably required to confirm identity or authority.
Where permitted by law, the period may be extended by up to two further months where a request is complex or a person has made a number of requests. Where an extension applies, we will provide information about it within the initial statutory period.
15.5 Right to object
You have the right to object where we process personal information on the basis of legitimate interests.
This right is subject to the applicable legal test. Processing may continue where there are compelling legitimate grounds that override your interests, rights and freedoms, or where processing is required to establish, exercise or defend legal claims.
You may object to direct marketing at any time.
15.6 How to exercise a right
Email using the subject line Data Protection Request.
You may also write to the address in section 19.
16. Data-protection complaints
16.1 How to complain
You may make a data-protection complaint by:
a. emailing using the subject line Data Protection Complaint; or
b. writing to the address in section 19.
A complaint may be made through another channel. We will not refuse to consider a complaint solely because it was not submitted using the suggested route.
16.2 Helpful information
It is helpful, but not mandatory, to provide:
a. your name and contact details;
b. a description of the concern;
c. relevant dates or communications;
d. the outcome you are seeking; and
e. supporting information.
16.3 Our process
We will:
a. acknowledge receipt within 30 days;
b. take appropriate steps to investigate without undue delay;
c. keep you appropriately informed where required; and
d. communicate the outcome without undue delay.
We may request further information or evidence of identity or authority where reasonably necessary.
16.4 Information Commissioner's Office
You also have the right to complain to the Information Commissioner's Office, the UK regulator for data protection and information rights.
Information about making a complaint is available through the ICO's website.
You are not required to complete our complaints process before contacting the ICO, although raising the matter with us first may allow it to be resolved more quickly.
17. Children
The Website is intended for general corporate and business information and is not directed at children.
We do not intentionally seek to collect personal information from children through the Website.
If we become aware that information concerning a child has been provided in circumstances where it should not have been, we may investigate and take appropriate action.
18. Third-party websites
The Website may contain links to Group Companies, Portfolio Businesses and other organisations.
Those organisations are responsible for their own privacy practices where they independently determine how and why personal information is processed.
This Privacy Notice does not govern personal information collected independently by another organisation. You should review the relevant privacy information where appropriate.
19. Changes and contact details
19.1 Changes to this Notice
We may update this Privacy Notice where:
a. the Website changes;
b. a service or technology is introduced or removed;
c. a supplier changes;
d. our processing activities change;
e. the law or regulatory guidance changes;
f. our business, group or portfolio structure changes; or
g. clarification is appropriate.
The current version will be identified by its version number, effective date and last-updated date.
Changes apply from the effective date stated in the updated Notice.
Where required by law, additional information will be provided before personal information is used for a materially different purpose.
19.2 Contact us
Questions, requests and complaints concerning this Privacy Notice or our use of personal information may be sent to:
Email:
Suggested subject lines:
- Data Protection
- Data Protection Request
- Data Protection Complaint
Post:
Heyworth & Co Group Ltd
5 Ribblesdale Place
Preston
Lancashire
England
PR1 8BZ
Postal correspondence may be marked for the attention of the directors.