Heyworth & Co Group← Home

Heyworth & Co Group Ltd

Privacy Notice

How Heyworth & Co Group Ltd collects, uses, stores and shares personal information in connection with heyworth.io and related business communications.

Version: 1.0
Effective from: 4 August 2026
Last updated: 4 August 2026

Key points

Heyworth & Co Group Ltd is the controller responsible for the personal information covered by this Privacy Notice.

We mainly process personal information when someone:

  • visits heyworth.io;
  • contacts us about the group, a Group Company or a Portfolio Business;
  • discusses a business, strategic, investment, acquisition, funding, supplier or professional opportunity;
  • communicates with us as a business contact, adviser, supplier or representative;
  • reports a security concern;
  • makes a complaint; or
  • exercises a data-protection right.

We do not sell personal information.

For privacy requests or data-protection complaints, email using the subject line Data Protection.

1. About this Privacy Notice

1.1 Scope

This Privacy Notice explains how Heyworth & Co Group Ltd may collect, use, store, disclose and otherwise process personal information when you:

a. visit our Website;

b. contact us about the group, a company, venture, brand or business identified on the Website;

c. communicate with us by email, telephone, video call, post or another method;

d. discuss a prospective commercial, strategic, supplier, investment, acquisition, disposal, financing or professional relationship;

e. attend a meeting or event involving Heyworth & Co;

f. report a security concern;

g. make a complaint or exercise a data-protection right; or

h. otherwise interact with us in connection with the Website or our corporate activities.

1.2 Website covered

The Website covered by this Privacy Notice includes:

a. heyworth.io;

b. www.heyworth.io;

c. any subdomain of heyworth.io on which this Notice is published or linked; and

d. any replacement domain on which this Notice is published.

1.3 Other organisations

A Group Company, Portfolio Business or linked third party may be a separate controller responsible for its own processing.

Its privacy notice applies where it independently decides why and how personal information is used.

1.4 Other processing

Separate privacy information may apply to:

a. employees, workers and applicants;

b. shareholders or investors;

c. directors and officers;

d. customers or users of a Group Company or Portfolio Business;

e. a formal corporate transaction;

f. a service governed by a separate agreement; or

g. another product, platform, website or business.

1.5 Legal effect

This Privacy Notice provides information about our processing of personal information. It does not create contractual rights beyond those provided by applicable law.

Nothing in this Notice limits a right or protection that cannot lawfully be limited.

2. Who we are

2.1 Controller

The controller responsible for the personal information described in this Privacy Notice is:

Heyworth & Co Group Ltd
Company number: 14622566
Registered in: England and Wales

Registered office:

5 Ribblesdale Place
Preston
Lancashire
England
PR1 8BZ

Email:

2.2 Definitions

In this Privacy Notice:

a. Heyworth & Co, we, us and our mean Heyworth & Co Group Ltd;

b. personal information and personal data mean information relating to an identified or identifiable individual;

c. Group Company means a company that is a parent undertaking or subsidiary undertaking of Heyworth & Co within the meaning of applicable company law;

d. Portfolio Business means a company, venture, brand or activity identified on the Website as forming part of, being supported by, or otherwise being associated with Heyworth & Co; and

e. Website means the website described in section 1.2.

3. Personal information we may collect

3.1 Information you provide

When you contact or communicate with us, we may collect:

a. your name;

b. your business or personal email address;

c. your telephone number;

d. your job title, occupation or role;

e. the organisation you represent;

f. your organisation's website or business address;

g. the subject and content of your enquiry;

h. information about a proposed commercial, strategic, supplier, investment, acquisition, disposal, financing or professional opportunity;

i. documents, presentations, proposals or attachments you provide;

j. correspondence and written notes relating to calls or meetings;

k. your communication preferences; and

l. other information you choose to provide.

3.2 Corporate and transaction information

Where discussions progress, we may collect or create limited personal information concerning:

a. directors, officers, shareholders, beneficial owners, advisers and representatives;

b. professional experience and authority;

c. ownership and management structures;

d. conflicts of interest;

e. financial-crime, fraud, sanctions or reputational checks;

f. negotiation and decision records;

g. due-diligence material;

h. draft transaction documents; and

i. information reasonably required to assess, structure, approve, administer or protect a proposed relationship or transaction.

3.3 Technical Website information

When you access the Website, we and our hosting, networking, security or technical providers may process limited technical information, including:

a. your IP address;

b. the date and time of a request;

c. the page, resource or file requested;

d. the referring page or website;

e. browser type and version;

f. device type;

g. operating system;

h. approximate geographic information derived from an IP address;

i. HTTP request and response information;

j. diagnostic and error information;

k. security information; and

l. information used to detect unusual, malicious or automated traffic.

Some technical information may be processed through hosting, network, security and diagnostic logs even where the Website does not place cookies on your device.

3.4 Analytics information

Where Website analytics are enabled, we may collect or receive information such as:

a. page views and approximate visitor numbers;

b. pages visited;

c. referring websites or campaigns;

d. general geographic region;

e. browser, operating-system, device and screen information;

f. outbound-link activity;

g. interactions with selected Website elements; and

h. technical performance information.

We do not intend to configure Website analytics to receive enquiry contents, form-field contents, correspondence, credentials, confidential documents or special-category information.

3.5 Calls, meetings and transcription

We may process meeting invitations, attendance information, notes, follow-up actions and correspondence.

Where a call or meeting is recorded or transcribed, additional notice will be provided at or before recording where required.

3.6 Rights, complaints and security information

Where you exercise a legal right, make a complaint or report a security concern, we may collect:

a. your identity and contact details;

b. evidence of identity or authority;

c. details of your request, complaint or report;

d. correspondence and supporting documents;

e. technical information or evidence;

f. investigation notes and decisions;

g. professional advice;

h. actions considered or taken; and

i. the outcome and follow-up record.

3.7 Information you should not send without prior agreement

Unless we have specifically requested it and appropriate arrangements are in place, please do not send:

a. passwords or authentication credentials;

b. private encryption keys;

c. payment-card information;

d. confidential source code or production-system access information;

e. special-category personal information;

f. criminal-offence information;

g. legally privileged material;

h. material non-public or price-sensitive information;

i. information subject to another person's confidentiality rights; or

j. information you are not authorised to disclose.

If this type of information is sent without being requested, we may restrict access to it, return it, securely delete it, move it to an appropriate controlled process, or retain only what is reasonably necessary to deal with the communication, protect legal rights or comply with law.

4. Information received from other sources

We may receive limited personal information from:

a. a colleague or representative of your organisation;

b. a Group Company or Portfolio Business;

c. a client, supplier, lender, investor, funder or commercial counterparty;

d. a solicitor, accountant, tax adviser, auditor, insurer, broker or other professional adviser;

e. a referral source or business contact;

f. a publicly available company or professional source;

g. a professional-networking service;

h. a regulator, authority or screening provider; or

i. a person authorised to act on your behalf.

Where required by law, we will provide appropriate privacy information concerning personal information obtained from another source.

5. How we use personal information

We may use personal information to:

a. operate, maintain, secure and deliver the Website;

b. provide requested Website content and functionality;

c. understand, assess and respond to enquiries;

d. identify the person and organisation contacting us;

e. route an enquiry to a relevant Group Company or Portfolio Business;

f. arrange and administer calls, meetings and discussions;

g. assess a prospective business, strategic, supplier, professional, investment, acquisition, disposal, financing or other opportunity;

h. prepare, negotiate and administer proposals, heads of terms, contracts and transaction documents;

i. carry out proportionate corporate, conflict, fraud, sanctions, financial-crime, legal, regulatory, commercial and reputational checks;

j. manage relationships with Group Companies, Portfolio Businesses, advisers, suppliers and other business contacts;

k. administer group governance, ownership, intellectual property, finance and corporate affairs;

l. keep an appropriate history of communications, decisions and dealings;

m. understand Website use and performance;

n. improve Website content and user experience;

o. detect errors, misuse, fraud and security threats;

p. investigate vulnerability or security reports;

q. prevent duplicate, abusive, deceptive or unwanted communications;

r. maintain suppression or do-not-contact records;

s. respond to data-protection requests and complaints;

t. establish, exercise or defend legal rights;

u. comply with legal, regulatory, accounting, tax, insurance and corporate requirements;

v. manage an investment, sale, acquisition, financing, restructuring, insolvency or transfer;

w. protect Heyworth & Co, Group Companies, Portfolio Businesses, business contacts and Website visitors;

x. send relevant business communications where permitted by law; and

y. carry out another purpose that is reasonably compatible with the purposes described above.

We do not sell personal information or trade it as a commodity.

6. Our lawful bases

6.1 General

We must have a lawful basis for processing personal information. The basis used depends on the information, purpose and circumstances.

6.2 Lawful-basis summary

Processing purposeLawful basis normally relied on
Operating, securing and maintaining the WebsiteLegitimate interests
Responding to enquiries and arranging discussionsLegitimate interests and, where applicable, steps requested before entering a contract
Assessing a business, strategic, supplier, professional or transaction opportunityLegitimate interests and, where applicable, steps before entering a contract
Routing an enquiry to a relevant Group Company or Portfolio BusinessLegitimate interests
Conducting proportionate due diligence, conflict, fraud, sanctions or reputational checksLegitimate interests and legal obligation where applicable
Administering a contract with an individualContract
Managing business contacts where a contract is with an organisationLegitimate interests
Website measurement and improvementLegitimate interests, unless consent or another basis is required
Accounting, tax, corporate, regulatory and legal complianceLegal obligation and legitimate interests
Establishing, exercising or defending legal claimsLegitimate interests and, where applicable, legal obligation
Direct marketing and business-development communicationsLegitimate interests or consent, together with compliance with electronic-marketing rules
Processing based on a specific permission you give usConsent

6.3 Legitimate interests

Relevant legitimate interests may include:

a. operating and protecting the Website;

b. responding to enquiries;

c. developing and managing business relationships;

d. administering the group and its corporate affairs;

e. assessing opportunities and transactions;

f. keeping appropriate evidential and relationship records;

g. preventing fraud, misuse and security incidents;

h. protecting confidential information, systems, reputation and legal rights;

i. resolving complaints and disputes; and

j. sending relevant business-to-business communications where permitted.

Where appropriate, we consider the purpose and necessity of the processing, the nature of the information, what an individual may reasonably expect, possible effects on the individual and available safeguards.

6.4 Steps before a contract and contract

We may process information where necessary to take steps at your request before entering a contract, or to perform a contract with you as an individual.

Where a contract is with your employer, company, fund or another organisation, we will normally rely on legitimate interests or another appropriate basis when processing your business contact information.

6.5 Legal obligations

We may process personal information where necessary to comply with legal obligations concerning matters such as:

a. tax, accounting and corporate administration;

b. data protection;

c. sanctions, fraud and financial crime;

d. court or tribunal proceedings;

e. regulatory, law-enforcement or public-authority requests; and

f. legally required records.

6.6 Consent

We may rely on consent where it is appropriate or legally required.

Where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect processing carried out before consent was withdrawn and does not prevent processing under another lawful basis where one applies.

7. Cookies, analytics and similar technologies

7.1 Technical operation

The Website and its providers may use cookies, browser storage, scripts, tags or similar technologies where necessary or appropriate to:

a. deliver pages and requested functionality;

b. maintain security;

c. manage traffic;

d. prevent misuse;

e. remember a visitor choice; or

f. measure Website use and performance.

7.2 Consent and controls

Where consent or another user control is required by law, the relevant technology will be handled through an appropriate consent or preference mechanism.

7.3 Changes in technology

The providers and technologies used may change as the Website develops.

We will update this Notice or publish additional cookie and analytics information where required before introducing materially different tracking or advertising technologies.

8. Business communications and direct marketing

8.1 Enquiry-related communications

We may contact you about:

a. an enquiry you made;

b. a meeting or discussion you requested;

c. a current, prospective or previous business relationship;

d. a matter reasonably connected with your organisation; or

e. another matter where contact is permitted by law.

8.2 Direct marketing

Where a communication constitutes direct marketing, we handle it in accordance with data-protection and electronic-marketing law.

The rules may differ depending on whether the recipient is a corporate subscriber or an individual subscriber, such as a sole trader or certain partnerships.

Where consent or another specific condition is required, we will rely on it only where the relevant requirements are met.

8.3 Objections

You may object to direct marketing at any time.

Where a valid objection is received, we may retain limited information on a suppression list so that the objection continues to be respected.

9. Who we may share information with

9.1 General

We may share personal information only where reasonably necessary and where an appropriate lawful basis applies.

9.2 Group Companies and Portfolio Businesses

We may share information with a Group Company or Portfolio Business where reasonably necessary to:

a. route or respond to an enquiry relating to it;

b. assess or manage a shared business opportunity;

c. provide corporate, administrative, financial, technical or legal support;

d. manage group governance or intellectual property;

e. protect legal rights;

f. complete a restructuring or transaction; or

g. carry out another purpose explained at the time.

A Group Company or Portfolio Business may act as a separate controller where it determines its own purposes and methods of processing.

We will not ordinarily forward the full contents of an unsolicited first-contact enquiry to an unrelated commercial business merely because it may be interested.

9.3 Website, communication and operational providers

We may use providers of:

a. Website hosting, content delivery, networking and security;

b. business email;

c. calendars, video meetings and transcription;

d. cloud storage and document management;

e. project, task and relationship management;

f. backups, monitoring and diagnostics;

g. electronic signatures and transaction administration; and

h. general business administration.

9.4 Professional advisers and insurers

We may share information with solicitors, barristers, accountants, auditors, tax advisers, insurers, brokers, consultants, due-diligence providers and other professional advisers.

9.5 Prospective and actual transaction parties

Where appropriate, we may share limited information with prospective or actual:

a. purchasers or sellers;

b. investors or funders;

c. lenders;

d. transaction advisers;

e. counterparties;

f. insolvency practitioners; or

g. successors,

in connection with an investment, sale, acquisition, disposal, merger, financing, restructuring, insolvency process or transfer of assets or business operations.

We will seek to limit disclosure to what is reasonably necessary and use confidentiality or other safeguards where appropriate.

9.6 Authorities and legal recipients

We may disclose information to courts, tribunals, regulators, law-enforcement bodies, tax authorities, public authorities and other persons where disclosure is required or permitted by law.

10. International transfers

10.1 General

Some service providers, professional advisers, Group Companies, Portfolio Businesses or transaction counterparties may process personal information outside the United Kingdom.

10.2 Safeguards

Where rules concerning restricted international transfers apply, we will use or rely on an appropriate legal mechanism.

Depending on the recipient and circumstances, this may include:

a. UK adequacy regulations;

b. the UK Extension to the EU-US Data Privacy Framework where the recipient participates;

c. the UK International Data Transfer Agreement;

d. the UK Addendum to approved standard contractual clauses;

e. approved standard contractual clauses; or

f. another mechanism permitted by law.

We may review provider terms, carry out required assessments and implement additional contractual, technical or organisational safeguards.

You may contact us for further information about safeguards applying to a particular category of transfer.

11. How long we retain personal information

11.1 General approach

We keep personal information only for as long as reasonably required for the relevant purpose, subject to legal, accounting, security, transaction and claims-related requirements.

11.2 Normal retention periods

Information categoryNormal retention approach
Unsuccessful or inactive initial enquiriesNormally up to 3 years after the last meaningful contact
Developed commercial, strategic, investment, acquisition, financing or supplier discussionsNormally up to 6 years after the discussion or proposed relationship ends
Contracts, corporate, transaction, invoice, payment, tax and accounting recordsNormally 6 years after the relevant financial year, transaction or relationship, subject to applicable requirements
Business contact and relationship recordsWhile the relationship remains active and normally up to 3 years afterwards, unless a longer period is justified
Direct-marketing recordsWhile marketing remains relevant and lawful; minimal suppression information may be retained for as long as needed to respect an objection
Technical, hosting, diagnostic and security logsNormally up to 12 months, unless needed for an incident, investigation, dispute or legal claim
Data-protection rights and complaint recordsNormally 6 years after the matter closes
Security and vulnerability reportsNormally up to 6 years after closure where needed for accountability or legal rights
Anonymised or aggregated informationMay be retained for longer where it no longer identifies an individual

11.3 Longer retention

We may retain information for longer where reasonably necessary because:

a. a complaint, dispute, investigation or legal claim exists or is reasonably anticipated;

b. a legal or regulatory hold applies;

c. law, insurance or a binding contractual obligation requires it;

d. the information is relevant to fraud, sanctions, misuse, security or legal rights; or

e. deletion is temporarily impracticable because information is held in a secure backup or archive.

11.4 Deletion and backups

When identifiable information is no longer reasonably required, it may be deleted, anonymised, aggregated, securely archived with restricted access or allowed to expire through ordinary backup and archive cycles.

Backup information is not ordinarily restored except for continuity, recovery, security or technical necessity. Where restored, applicable deletion and restriction decisions will be reapplied where reasonably practicable.

12. Security

We use organisational and technical measures intended to protect personal information against unauthorised access, accidental loss, misuse, alteration, inappropriate disclosure and destruction.

Measures may include:

a. access restrictions;

b. authentication;

c. encryption in transit;

d. supplier controls;

e. software updates;

f. security logging;

g. backups;

h. confidentiality obligations;

i. vulnerability management; and

j. incident-response arrangements.

The measures used depend on the nature of the information, systems involved, likelihood and severity of the risk, available technology and proportionality.

No internet service, system or electronic communication can be guaranteed to be completely secure.

You are responsible for choosing an appropriate method when sending confidential or sensitive information to us.

13. Artificial intelligence, recording and transcription

We do not intentionally use personal information submitted through the Website to train general-purpose artificial-intelligence models.

Where an approved AI-assisted, meeting-recording or transcription tool is used for business administration, analysis, drafting or summarisation, we will:

a. use it only where a lawful basis applies;

b. minimise the personal and confidential information provided;

c. apply proportionate supplier, access and retention controls; and

d. provide additional notice where required.

Do not send credentials, privileged material, price-sensitive information or confidential transaction information for use with such a tool unless an approved arrangement is in place.

14. Automated decision-making

We do not currently use personal information collected through the Website to make decisions producing legal or similarly significant effects through solely automated processing.

If this materially changes, appropriate privacy information and safeguards will be provided where required.

15. Your data-protection rights

15.1 Rights

Depending on the circumstances, processing and lawful basis used, you may have the right to:

a. ask whether we process your personal information;

b. obtain a copy of personal information we hold about you;

c. correct inaccurate or incomplete information;

d. ask us to erase personal information;

e. ask us to restrict processing;

f. object to processing;

g. receive certain information in a portable format;

h. withdraw consent where processing is based on consent; and

i. complain about how personal information has been handled.

These rights are subject to legal conditions, limitations and exemptions.

15.2 Identity and scope

We may request information reasonably required to:

a. verify your identity;

b. confirm your authority to act for another person;

c. identify the information concerned; or

d. clarify the scope of a request.

We will not request more information than is reasonably necessary.

15.3 Fees

We do not ordinarily charge a fee.

A reasonable fee may be charged, or a request may be refused, where permitted by law, including where a request is manifestly unfounded or excessive.

15.4 Response times

We respond to rights requests within the periods required by applicable data-protection law.

The usual period is one month after receiving the request and any information reasonably required to confirm identity or authority.

Where permitted by law, the period may be extended by up to two further months where a request is complex or a person has made a number of requests. Where an extension applies, we will provide information about it within the initial statutory period.

15.5 Right to object

You have the right to object where we process personal information on the basis of legitimate interests.

This right is subject to the applicable legal test. Processing may continue where there are compelling legitimate grounds that override your interests, rights and freedoms, or where processing is required to establish, exercise or defend legal claims.

You may object to direct marketing at any time.

15.6 How to exercise a right

Email using the subject line Data Protection Request.

You may also write to the address in section 19.

16. Data-protection complaints

16.1 How to complain

You may make a data-protection complaint by:

a. emailing using the subject line Data Protection Complaint; or

b. writing to the address in section 19.

A complaint may be made through another channel. We will not refuse to consider a complaint solely because it was not submitted using the suggested route.

16.2 Helpful information

It is helpful, but not mandatory, to provide:

a. your name and contact details;

b. a description of the concern;

c. relevant dates or communications;

d. the outcome you are seeking; and

e. supporting information.

16.3 Our process

We will:

a. acknowledge receipt within 30 days;

b. take appropriate steps to investigate without undue delay;

c. keep you appropriately informed where required; and

d. communicate the outcome without undue delay.

We may request further information or evidence of identity or authority where reasonably necessary.

16.4 Information Commissioner's Office

You also have the right to complain to the Information Commissioner's Office, the UK regulator for data protection and information rights.

Information about making a complaint is available through the ICO's website.

You are not required to complete our complaints process before contacting the ICO, although raising the matter with us first may allow it to be resolved more quickly.

17. Children

The Website is intended for general corporate and business information and is not directed at children.

We do not intentionally seek to collect personal information from children through the Website.

If we become aware that information concerning a child has been provided in circumstances where it should not have been, we may investigate and take appropriate action.

18. Third-party websites

The Website may contain links to Group Companies, Portfolio Businesses and other organisations.

Those organisations are responsible for their own privacy practices where they independently determine how and why personal information is processed.

This Privacy Notice does not govern personal information collected independently by another organisation. You should review the relevant privacy information where appropriate.

19. Changes and contact details

19.1 Changes to this Notice

We may update this Privacy Notice where:

a. the Website changes;

b. a service or technology is introduced or removed;

c. a supplier changes;

d. our processing activities change;

e. the law or regulatory guidance changes;

f. our business, group or portfolio structure changes; or

g. clarification is appropriate.

The current version will be identified by its version number, effective date and last-updated date.

Changes apply from the effective date stated in the updated Notice.

Where required by law, additional information will be provided before personal information is used for a materially different purpose.

19.2 Contact us

Questions, requests and complaints concerning this Privacy Notice or our use of personal information may be sent to:

Email:

Suggested subject lines:

  • Data Protection
  • Data Protection Request
  • Data Protection Complaint

Post:

Heyworth & Co Group Ltd
5 Ribblesdale Place
Preston
Lancashire
England
PR1 8BZ

Postal correspondence may be marked for the attention of the directors.