GDPR Policy

GDPR & Data Protection Policy

Beetlestone HR Consultancy

Beetlestone HR – GDPR & Data Protection Policy
Effective Date: 01/01/2026

Last Reviewed: 13/01/2026

1. Policy Statement

Beetlestone HR is committed to protecting the privacy and security of personal data.

We recognise the importance of handling personal information responsibly and in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

This policy sets out how we collect, store, use and protect personal data in the course of providing HR consultancy services.

2. Scope

This policy applies to:

  • All personal data processed by Beetlestone HR
  • Data relating to clients, employees, contractors, job applicants, and other third parties
  • All systems, devices and records used for business purposes

3. Data Protection Principles

Beetlestone HR processes personal data in line with the following principles:

  • Lawfully, fairly and transparently
  • For specified, explicit and legitimate purposes
  • Adequate, relevant and limited to what is necessary
  • Accurate and kept up to date
  • Stored only as long as required
  • Processed securely to prevent unauthorised access or loss

4. Types of Data We May Process

We may process the following categories of personal data:

  • Contact details (name, email, phone number, business address)
  • Employment information (job role, contract details, HR records)
  • Special category data where necessary (e.g. health or diversity data)
  • Business communications and consultancy documentation

5. Lawful Bases for Processing

We process personal data under one or more lawful bases, including:

  • Performance of a contract
  • Compliance with legal obligations
  • Legitimate business interests
  • Consent (where required)
  • Establishment, exercise or defence of legal claims

6. Data Security

Beetlestone HR takes appropriate technical and organisational measures to protect data, including:

  • Secure password-protected devices
  • Encrypted storage and secure cloud systems
  • Restricted access to confidential information
  • Regular review of data handling practices

7. Data Sharing

We may share data only where necessary with:

  • Professional advisers (e.g. solicitors, accountants)
  • Trusted service providers supporting delivery of services
  • Regulatory bodies where legally required

All third parties are required to comply with GDPR standards.

8. Data Retention

Personal data will be retained only for as long as necessary for business, legal or contractual purposes. Records will be securely deleted or destroyed when no longer required.

9. Individual Rights

Individuals have the right to:

  • Access their personal data
  • Request correction or deletion
  • Restrict or object to processing
  • Data portability (where applicable)
  • Lodge a complaint with the ICO

10. Contact Details

For any data protection queries, please contact:

Rachel Yates
Beetlestone HR
Email: Beetlestone-enquiries@outlook.com
ICO Registration Number: ZC094449