Privacy Notice
Last updated: 31 May 2026
1. Introduction
Summit Performance Consulting Ltd ("we", "us", "our") is committed to protecting and respecting your privacy. This Privacy Notice explains how we collect, use, store, and protect your personal data when you visit our website at https://summitperformanceconsulting.co.uk, use our contact forms, subscribe to our newsletter, or engage our consulting services.
We are the data controller for personal data processed through this website. We are registered in England and Wales (Company Number: 16167994) with our registered office at 301 Tea Factory, St Peters Square, Fleet Street, Liverpool, Merseyside, United Kingdom, L1 4DQ. Our ICO registration reference is ZC108286.
2. Legal Basis for Processing
Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we process personal data on the following legal bases:
- Consent — for newsletter subscriptions, cookie analytics, and marketing communications where applicable.
- Legitimate Interests — for responding to enquiries, improving our website, and business development, balanced against your rights.
- Contractual Necessity — where processing is necessary to perform a contract or take steps at your request before entering a contract.
- Legal Obligation — where we are required to process data to comply with applicable law.
3. Personal Data We Collect
We may collect and process the following categories of personal data:
- Identity Data: name, job title, organisation name.
- Contact Data: email address, telephone number, postal address.
- Technical Data: IP address, browser type, device information, pages visited, time spent on pages, referral source.
- Communication Data: messages submitted via contact forms, consultation requests, and email correspondence.
- Marketing Data: newsletter subscription preferences.
4. How We Use Your Data
We use your personal data to:
- Respond to enquiries and contact form submissions.
- Schedule and manage consultation appointments.
- Send confirmation emails and meeting invitations via Microsoft Outlook.
- Deliver consulting services you have engaged us for.
- Send newsletters and insights (where you have opted in).
- Analyse website usage to improve our services (with cookie consent).
- Comply with legal and regulatory obligations.
5. Data Sharing and Processors
We may share personal data with trusted third-party processors who assist us in operating our website and business, including:
- Supabase — database hosting for form submissions, analytics, and user accounts.
- Vercel — website hosting and content delivery.
- Microsoft (Outlook/Graph API) — email delivery and calendar scheduling.
- Calendly — appointment scheduling (where used).
All processors are bound by data processing agreements and process data only on our instructions. We do not sell your personal data to third parties.
6. International Transfers
Some of our service providers may process data outside the UK. Where this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the UK Information Commissioner's Office (ICO), or transfers to countries with an adequacy decision.
7. Data Retention
We retain personal data only for as long as necessary:
- Contact form enquiries: 3 years from last contact.
- Newsletter subscriptions: until you unsubscribe.
- Website analytics: 26 months.
- Client engagement records: 7 years (for legal and accounting purposes).
8. Your Rights
Under UK GDPR, you have the following rights:
- Right of Access — request a copy of your personal data.
- Right to Rectification — request correction of inaccurate data.
- Right to Erasure — request deletion of your data ("right to be forgotten").
- Right to Restrict Processing — request limitation of processing.
- Right to Data Portability — receive your data in a structured format.
- Right to Object — object to processing based on legitimate interests.
- Right to Withdraw Consent — withdraw consent at any time where processing is consent-based.
To exercise any of these rights, contact us at FaaizKhan@summitperformanceconsulting.co.uk.
9. Cookies
We use essential cookies for website functionality and, with your consent, analytics cookies to understand how visitors use our site. You can manage cookie preferences via the cookie consent banner. For more information, see our cookie settings or contact us.
10. Security
We implement appropriate technical and organisational measures to protect your personal data, including encryption in transit (HTTPS/TLS), access controls, and secure hosting infrastructure.
11. Complaints
If you are unhappy with how we handle your personal data, please contact us first at FaaizKhan@summitperformanceconsulting.co.uk. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
12. Changes to This Notice
We may update this Privacy Notice from time to time. The latest version will always be published on this page with the date of last update.
13. Contact Us
Summit Performance Consulting Ltd
301 Tea Factory, St Peters Square, Fleet Street, Liverpool, Merseyside, United Kingdom, L1 4DQ
Email: FaaizKhan@summitperformanceconsulting.co.uk
ICO Registration: ZC108286