Legal
Privacy policy
Last updated: 22 May 2026
This policy explains what personal data Northgate Compliance Ltd collects, why we collect it, and what your rights are. We've written it in plain English. If anything isn't clear, email us and we'll explain.
Who we are
Northgate Compliance Ltd is the data controller for the information described below.
- Company number: 17236577
- Registered office: Leveldale Cottage, Lathom Lane, Lathom, Ormskirk, England L40 5TT
- Email: hello@northgatecompliance.co.uk
What we collect, why, and our lawful basis
Contact and enquiries. If you email us or send a form on this website, we collect your name, email address, company name (if you give it), and whatever you write to us. We use this to reply and to follow up. Lawful basis: legitimate interests in responding to prospective clients.
Client engagements. If you engage us, we hold the information needed to deliver the work and to invoice you - typically your business contact details, billing details, and information about your IT environment relevant to the engagement. Lawful basis: contract, and legal obligation for billing and tax records.
Website analytics. We use privacy-respecting analytics to count visits and see which pages are read. It does not identify you, does not track you across other sites, and is described in the cookies section below. Lawful basis: legitimate interests in understanding how the site is used.
We do not run advertising trackers. We do not buy or sell personal data. We do not make automated decisions about you.
Cookies
This website does not set marketing or tracking cookies. Our analytics are cookie-free. If we ever introduce non-essential cookies, we'll ask for your consent first.
How long we keep your data
- Enquiries that don't become engagements: deleted within 12 months.
- Client records: kept for 6 years after the engagement ends, in line with UK tax and accounting requirements.
- Email correspondence: kept for as long as it's relevant, and reviewed periodically.
- Website analytics: aggregated and not linked to individuals.
Marketing
We don't send marketing emails to people who haven't asked for them. If we ever start a newsletter or send service updates, it'll be opt-in and you'll be able to unsubscribe at any time.
Who else processes your data
We use a small number of suppliers to run the website and the business. Each one only handles the data it needs:
- Vercel (US) - hosts the website.
- Resend (US) - delivers contact-form submissions to our inbox.
- Our email provider - stores email correspondence.
All of these process data on our written instructions.
International transfers
Some of our suppliers, including Vercel and Resend, are based in the United States. Where personal data is transferred outside the UK, we rely on the UK's adequacy decisions where available, or on the UK International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses) as the safeguard. You can ask us for a copy of these safeguards.
Your rights
Under UK GDPR you have the right to:
- ask for a copy of the personal data we hold about you,
- ask us to correct anything that's wrong,
- ask us to delete your data, where we don't need to keep it for legal reasons,
- ask us to restrict or stop a particular use,
- object to how we're using it,
- ask for your data to be sent to another provider, where this applies.
To exercise any of these rights, email hello@northgatecompliance.co.uk. We'll respond within one calendar month.
Complaints
If you're unhappy with how we've handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office:
- ico.org.uk
- 0303 123 1113
- Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Changes to this policy
If we change this policy, we'll update the date at the top. We'll keep older versions available on request.

