signrighthr.co.uk Privacy Policy

Type of website: Hr consultant Effective date: 17th day of December, 2025

signrighthr.co.uk (the “Site”) is owned and operated by Sign Right HR. Sign Right HR is the data controller and can be contacted at:

info@signrighthr.co.uk 07598 720411 Hops & Barley Community Stadium, Grange Rd, Rhyl, Wales, LL18 4BY

Purpose The purpose of this privacy policy (this “Privacy Policy”) is to inform users of our Site of the following:

  1. The personal data we will collect;
  • Use of collected data;
  • Who has access to the data collected;
  • The rights of Site users; and
  • The Site’s cookie policy.

This Privacy Policy applies in addition to the terms and conditions of our Site.

GDPR For users in the European Union, we adhere to the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, known as the General Data Protection Regulation (the “GDPR”). For users in the United Kingdom, we adhere to the GDPR as enshrined in the Data Protection Act 2018.

Consent By using our Site users agree that they consent to:

  1. The conditions set out in this Privacy Policy.

When the legal basis for us processing your personal data is that you have provided your consent to that processing, you may withdraw your consent at any time. If you withdraw your consent, it will not make processing which we completed before you withdrew your consent unlawful.

You can withdraw your consent by: Contacting the Data Protection Officer.

Legal Basis for Processing We collect and process personal data about users in the EU only when we have a legal basis for doing so under Article 6 of the GDPR.

We rely on the following legal bases to collect and process the personal data of users in the EU:

  1. Users have provided their consent to the processing of their data for one or more specific purposes;
  • Processing of user personal data is necessary for us or a third party to pursue a legitimate interest. Our legitimate interest is not overridden by the interests or fundamental rights and freedoms of users. Our legitimate interest(s) are: Our legitimate interests include the delivery of HR consultancy services, business administration, service improvement through website analytics, and the marketing of our professional services to other businesses;
  • Processing of user personal data is necessary for us to take, at the request of a user, steps before entering a contract or for the performance of a contract to which a user is a party. If a user does not provide the the personal data necessary to perform a contract the consequences are as follows: If you do not provide the personal data we request, we may not be able to perform the contract we have entered into or are trying to enter into with you (for example, to provide you with HR consultancy or process your payment). In this case, we may have to cancel a service you have with us, but we will notify you if this is the case at the time; and
  • Processing of user personal data is necessary for us to comply with a legal obligation. If a user does not provide the the personal data necessary for us to perform a legal obligation the consequences are as follows: We process personal data to comply with legal and regulatory requirements, such as reporting to HMRC for payroll services or responding to valid court orders..

Personal Data We Collect We only collect data that helps us achieve the purpose set out in this Privacy Policy. We will not collect any additional data beyond the data listed below without notifying you first.

Data Collected Automatically When you visit and use our Site, we may automatically collect and store the following information:

  1. IP address;
  • Location; and
  • Hardware and software details.

Data Collected in a Non-Automatic Way We may also collect the following data when you perform certain functions on our Site:

  1. First and last name;
  2. Email address;
  3. Phone number;
  4. Address;
  5. Payment information;
  6. Business Name; and
  7. Employment Details.

This data may be collected using the following methods:

  1. We collect personal data directly from you when you complete forms on our website, correspond with us by email or telephone, or enter into a contract for HR services..

How We Use Personal Data DataF collected on our Site will only be used for the purposes specified in this Privacy Policy or indicated on the relevant pages of our Site. We will not use your data beyond what we disclose in this Privacy Policy.

The data we collect automatically is used for the following purposes:

  1. When you visit our website, we automatically collect certain technical information, such as your IP address and browser type. We use this data for security purposes and to ensure our website functions.

The data we collect when the user performs certain functions may be used for the following purposes:

  1. We use your data to deliver our HR consultancy services, including drafting contracts and providing advisory support. We also use it for administrative purposes such as billing and meeting our legal t.

Who We Share Personal Data With Employees We may disclose user data to any member of our organisation who reasonably needs access to user data to achieve the purposes set out in this Privacy Policy.

Third Parties We may share user data with the following third parties:

  1. BreatheHR;
  2. Hostinger;
  3. Payment Provider; and
  4. Email Provider.

We may share the following user data with third parties:

  1. Identity, Contact, and Employment Data;
  2. Technical Data (IP addresses) and Contact Data;
  3. Financial and Transaction Data; and
  4. Contact and Communication Data.

We may share user data with third parties for the following purposes:

  1. To securely store and manage client employee records, leave, and performance.;
  2. To provide website hosting services and store inquiry form submissions.;
  3. To process service payments and manage invoicing.; and
  4. To facilitate professional communication and provide HR advice..

Third parties will not be able to access user data beyond what is reasonably necessary to achieve the given purpose.

Other Disclosures We will not sell or share your data with other third parties, except in the following cases:

  1. If the law requires it;
  2. If it is required for any legal proceeding;
  3. To prove or protect our legal rights; and
  4. To buyers or potential buyers of this company in the event that we seek to sell the company.

If you follow hyperlinks from our Site to another Site, please note that we are not responsible for and have no control over their privacy policies and practices.

How Long We Store Personal Data User data will be stored for Client files and contracts are kept for 6 years post-service to meet legal claim limits. Tax/payroll records are held for 6 years plus the current year for HMRC. Web inquiries are kept for 2 years.

You will be notified if your data is kept for longer than this period.

How We Protect Your Personal Data We protect your data using a multi-layered security approach. All information sent via our website is fully encrypted using SSL (HTTPS). Client and employee records are stored in BreatheHR, an ISO 27001 certified platform that uses industry-leading encryption and secure UK data centres. Within our business, we enforce strict access controls, including Two-Factor Authentication (2FA) and complex password policies, ensuring only authorized personnel can access sensitive files. We also maintain daily backups and utilize Hostinger’s Web Application Firewalls to defend against unauthorized access and cyber threats.

While we take all reasonable precautions to ensure that user data is secure and that users are protected, there always remains the risk of harm. The Internet as a whole can be insecure at times and therefore we are unable to guarantee the security of user data beyond what is reasonably practical.

Your Rights as a User Under the GDPR, you have the following rights:

  1. Right to be informed;
  2. Right of access;
  3. Right to rectification;
  4. Right to erasure;
  5. Right to restrict processing;
  6. Right to data portability; and
  7. Right to object.

Children We do not knowingly collect or use personal data from children under 16 years of age. If we learn that we have collected personal data from a child under 16 years of age, the personal data will be deleted as soon as possible. If a child under 16 years of age has provided us with personal data their parent or guardian may contact our data protection officer.

How to Access, Modify, Delete, or Challenge the Data Collected If you would like to know if we have collected your personal data, how we have used your personal data, if we have disclosed your personal data and to who we disclosed your personal data, if you would like your data to be deleted or modified in any way, or if you would like to exercise any of your other rights under the GDPR, please contact our data protection officer here:

Alison Dean info@signrighthr.co.uk 07598 720411 Hops & Barley Community Stadium, Grange Rd, Rhyl, Wales, LL18 4BY

How to Opt-Out of Data Collection, Use or Disclosure In addition to the method(s) described in the How to Access, Modify, Delete, or Challenge the Data Collected section, we provide the following specific opt-out methods for the forms of collection, use, or disclosure of your personal data specified below:

  1. Receiving direct marketing communications, newsletters, and HR legislative updates via email. You can opt-out by click the ‘unsubscribe’ link at the bottom of any marketing email, or email us at info@signrighthr.co.uk with the subject line ‘OPT OUT’.
  2. The collection of technical and website usage data via non-essential cookies for analytics and performance tracking. You can opt-out by select the ‘Reject’ or ‘Manage Settings’ option on our website’s cookie consent banner. You can also adjust your web browser settings to block all cookies.
  • The processing of personal data for direct marketing purposes based on legitimate interests. You can opt-out by submit a written request to our data protection officer at Hops & Barley Community Stadium, Grange Rd, Rhyl, Wales, LL18 4BY or email info@signrighthr.co.uk stating your objection to further processing.

Cookie Policy A cookie is a small file, stored on a user’s hard drive by a website. Its purpose is to collect data relating to the user’s browsing habits. You can choose to be notified each time a cookie is transmitted. You can also choose to disable cookies entirely in your internet browser, but this may decrease the quality of your user experience.

We use the following types of cookies on our Site:

  1. Functional cookies Functional cookies are used to remember the selections you make on our Site so that your selections are saved for your next visits;
  2. Analytical cookies Analytical cookies allow us to improve the design and functionality of our Site by collecting data on how you access our Site, for example data on the content you access, how long you stay on our Site, etc; and
  3. Third-Party Cookies Third-party cookies are created by a website other than ours. We may use third-party cookies to achieve the following purposes: a. To analyse website traffic and enable social media features like LinkedIn sharing..

Modifications This Privacy Policy may be amended from time to time in order to maintain compliance with the law and to reflect any changes to our data collection process. When we amend this Privacy Policy we will update the “Effective Date” at the top of this Privacy Policy. We recommend that our users periodically review our Privacy Policy to ensure that they are notified of any updates. If necessary, we may notify users by email of changes to this Privacy Policy.

Complaints If you have any complaints about how we process your personal data, please contact us through the contact methods listed in the Contact Information section so that we can, where possible, resolve the issue. If you feel we have not addressed your concern in a satisfactory manner you may contact a supervisory authority. You also have the right to directly make a complaint to a supervisory authority. You can lodge a complaint with a supervisory authority by contacting the Information Commissioner’s Office (ICO).

Contact Information If you have any questions, concerns or complaints, you can contact our Data Protection Officer, Alison Dean, at:

info@signrighthr.co.uk 07598 720411 Hops & Barley Community Stadium, Grange Rd, Rhyl, Wales, LL18 4BY

Definitions:What we mean by marketing: We use your contact details solely to keep you informed about our own HR services, legislation updates, and helpful business resources. We will never sell your data to other companies. If we ever wish to mention your business in a case study or testimonial, we will always ask for your explicit permission first.