The TorchBrand Agency
PRIVACY POLICY
Last updated: 13 September 2026
The TorchBrand Agency ("TorchBrand", "we", "us", "our") is committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, use and look after your personal data when you visit our website, engage us as a client, apply for a role with us, or otherwise interact with us. It also explains your rights and how the law protects you.
Contact: contact@torchbrand.co.uk
1. Important information
Our website and services are directed at businesses and organisations, not children, and we do not knowingly collect data relating to children.
This Privacy Policy sits alongside our other notices, including our Terms & Conditions, and doesn't replace them.
TorchBrand is the controller responsible for your personal data.
To help you understand this policy, Schedule 1 at the end sets out a glossary of terms, the types of personal data we collect, how we use it, the lawful basis for each use, and further detail on your rights.
If you have any questions about this policy, including requests to exercise your legal rights, please contact us at contact@torchbrand.co.uk.
You have the right to complain to the Information Commissioner's Office (ICO) at any time (ico.org.uk). We'd appreciate the chance to address your concerns directly first, so please contact us before approaching the ICO if you can.
Keeping your data accurate: it's important that the data we hold about you is correct and current, so please let us know if any of your details change.
Third-party links: our website may include links to third-party websites, plug-ins or applications. Clicking these links or enabling these connections may allow third parties to collect or share data about you. We don't control these third-party sites or tools and aren't responsible for their privacy practices, so we'd encourage you to review their own privacy notices.
2. The data we collect about you
We may collect, use, store and transfer the categories of personal data set out in Part 1 of Schedule 1. We also collect and use aggregated data (such as statistics about website usage); where we combine aggregated data with your personal data in a way that could identify you, we treat the combined data as personal data.
We do not deliberately collect special category data (such as health, racial or ethnic origin, or political opinions) or information about criminal convictions, except where a client voluntarily shares such information for a specific, agreed purpose (for example, a charity client sharing beneficiary case studies for a campaign we run on their behalf).
If you don't provide data we need: where we need certain personal data to enter into or perform a contract with you and you don't provide it, we may not be able to proceed with that contract or service, and we'll let you know if this is the case.
3. How we collect your data
Direct interactions: you may give us personal data when you fill in a form on our website, request a quote or proposal, sign a contract, subscribe to updates, or otherwise correspond with us by phone, email or post.
Automated technology: as you browse or interact with our website, we automatically collect technical and usage data through cookies, server logs and similar technologies. Our separate Cookie Policy sets out more detail on this.
Publicly available sources: we may collect data from sources such as Companies House, LinkedIn, or the Electoral Register, particularly when researching a prospective client or partner organisation.
Third parties: we may receive data from analytics providers (such as Google), advertising networks (such as Meta), and suppliers who support our operations, such as hosting, CRM or payment providers.
From our clients: where a client shares contact lists, campaign data or customer information with us so we can deliver marketing services on their behalf, the client remains the controller of that data and we act as a processor, as described further in our Terms & Conditions.
4. How we use your personal data
We will only use your personal data where the law allows us to. Most commonly, we rely on the following lawful bases, set out in more detail in Part 2 of Schedule 1:
- to perform a contract we have with you;
- to comply with a legal obligation; and
- where necessary for our legitimate interests, or those of a third party, provided your own interests and rights don't override those interests.
We generally rely on your consent only when sending email marketing, and you can withdraw that consent at any time. We may rely on more than one lawful basis depending on the specific purpose.
Marketing: we may use your data to work out what services might interest you. You'll only receive marketing from us if you've requested information, purchased a service from us, or given consent, and you haven't since opted out. We'll get your clear opt-in consent before sharing your data with any third party for their own marketing purposes.
Opting out: you can unsubscribe from marketing emails using the link in any email, or by contacting us directly. Opting out of marketing won't stop us using your data for other purposes where we have a lawful basis to do so, such as delivering a service you've asked for.
Change of purpose: we'll only use your data for the purpose we collected it for, unless we reasonably need to use it for a related reason. If we need to use it for something unrelated, we'll tell you and explain the legal basis for doing so.
5. Disclosure of your personal data
We may share your personal data with the categories of third party described in Part 4 of Schedule 1, including service providers who support our operations, professional advisers, and regulators such as HMRC. We require all third parties to protect your data and use it only for the purposes we specify.
6. International transfers
Some of the tools we use, such as advertising, analytics, hosting or CRM providers, may be based outside the UK, meaning your data could be transferred internationally. Where this happens, we make sure an appropriate safeguard is in place, such as:
- transferring data only to countries recognised as providing an adequate level of protection;
- using standard contractual clauses approved for international transfers; or
- relying on a provider's own recognised data protection framework.
Contact us if you'd like more detail on the safeguards used for a specific transfer.
7. Data security
We use appropriate technical and organisational measures to prevent your data being accidentally lost, misused, accessed without authorisation, altered or disclosed. Access to your data is limited to those who have a genuine business need for it, and they are bound by confidentiality obligations. We have procedures in place to deal with any suspected data breach and will notify you and the relevant regulator where the law requires us to.
8. Data retention
We only keep your personal data for as long as necessary to fulfil the purpose we collected it for, including to satisfy legal, accounting or reporting requirements. As a general guide:
- client and contract records are kept for the duration of the engagement plus 6 years, to meet UK tax and contractual requirements;
- enquiry and prospect data is kept for up to 24 months from your last contact with us, unless you ask us to delete it sooner;
- job application data is kept for up to 12 months, unless you consent to us keeping it for future opportunities.
We may anonymise your data so it can no longer be linked to you, and use that anonymised data indefinitely for research or reporting purposes.
9. Your legal rights
Under UK data protection law, you have the rights set out in full in Part 3 of Schedule 1, including the right to access, correct, erase or restrict use of your data, to object to certain processing, to request a transfer of your data, and to withdraw consent at any time.
You won't usually have to pay a fee to exercise these rights, though we may charge a reasonable fee, or decline to act, if a request is clearly unfounded, repetitive or excessive. We may ask you to confirm your identity before acting on a request, as a security measure.
We aim to respond to legitimate requests within one month. If a request is particularly complex, or you've made several requests, it may take us longer, and we'll keep you updated if so.
Schedule 1
Part 1: Types of personal data
| Category | Examples |
|---|---|
| Contact data | Billing address, delivery address, email address, telephone number |
| Financial data | Bank account and payment details |
| Identity data | Name, username, job title, date of birth (where relevant) |
| Marketing and communications data | Your marketing preferences |
| Profile data | Account details, orders or services purchased, feedback and survey responses |
| Technical data | IP address, login data, browser type and version, time zone, device and platform information |
| Transaction data | Details of payments to and from you and services purchased |
Part 2: Lawful basis for processing
| Lawful basis | What it means |
|---|---|
| Consent | You've given clear consent for a specific purpose |
| Contract | Processing is needed to perform our contract with you, or to take steps at your request before entering one |
| Legal obligation | Processing is needed to comply with a legal or regulatory requirement |
| Legitimate interests | Processing is needed for our or a third party's legitimate interest, balanced against your rights and interests |
| Purpose | Type of data | Lawful basis |
|---|---|---|
| Registering you as a client or contact | Identity, contact | Contract |
| Delivering services, managing payments and fees | Identity, contact, financial, transaction, marketing | Contract; legitimate interests in recovering amounts owed |
| Managing our relationship, including updates to our Terms or this Policy | Identity, contact, profile, marketing | Contract; legal obligation; legitimate interests in keeping records accurate |
| Administering and protecting our business and website | Identity, contact, technical | Legitimate interests in running our business securely; legal obligation |
| Delivering relevant content or advertising and measuring its effectiveness | Identity, contact, profile, usage, marketing, technical | Legitimate interests in understanding and improving our marketing |
| Using analytics to improve our website and services | Technical, usage | Legitimate interests in developing our services and business |
Part 3: Your legal rights
| Right | What it means |
|---|---|
| Access | You can ask for a copy of your personal data and confirmation of how we're using it |
| Correction | You can ask us to correct inaccurate or incomplete data |
| Erasure | You can ask us to delete data where there's no good reason for us to keep it, you've objected to processing, we've processed it unlawfully, or the law requires erasure |
| Object | You can object to processing based on legitimate interests, or to direct marketing at any time |
| Restrict processing | You can ask us to pause processing while we resolve an accuracy or lawfulness concern, or where you need us to retain data for a legal claim |
| Data portability | You can ask for a copy of data you provided under consent or contract, in a structured, machine-readable format |
| Withdraw consent | You can withdraw consent at any time, without affecting processing carried out before withdrawal |
Part 4: Categories of third party we may share data with
| Category | Description |
|---|---|
| Service providers | IT, hosting, CRM and system administration providers who process data on our behalf |
| Professional advisers | Lawyers, accountants, auditors and insurers who provide us with professional advice |
| HMRC, regulators and authorities | Where reporting or disclosure is required by law |
| Advertising and analytics platforms | Such as Meta and Google, where we run or measure campaigns on your behalf |
| A buyer or successor business | If we sell, transfer or merge parts of our business, the new owner may use data as set out in this policy |
Part 5: Glossary
| Term | Meaning |
|---|---|
| Aggregated data | Statistical or demographic data that, by itself, doesn't identify anyone |
| Controller | The organisation that decides why and how personal data is processed |
| Data subject | The individual the personal data is about |
| Personal data | Information that identifies a data subject, alone or combined with other data we hold |
| Processor | An organisation that processes personal data on behalf of a controller |
| Special category data | Data about race, ethnicity, political opinions, religion, trade union membership, health, genetics, biometrics, sex life or sexual orientation |
| ICO | The Information Commissioner's Office, the UK's data protection regulator |
Contact us
The TorchBrand Agency
contact@torchbrand.co.uk