Effective date: 31 August 2026
1. Introduction and company information
This Privacy Policy explains how Northbridge Retail Marketing Ltd (“we”, “us”, “our”) collects, uses, stores, shares, and protects personal data in connection with our retail-marketing services and related business activities.
Northbridge Retail Marketing Ltd is the data controller for the personal data described in this policy.
Contact details:
- Company name: Northbridge Retail Marketing Ltd
- Address: Northbridge Retail Marketing, 3 Broad Quay, Bristol BS1 4DA, United Kingdom
- Email: [email protected]
- Phone: +44 117 923 7468
This policy applies to personal data collected from clients, prospective clients, business contacts, website visitors, suppliers, candidates, and other individuals with whom we interact in the ordinary course of business.
2. Data collection and processing
We may collect and process the following categories of personal data, depending on your relationship with us:
- Identity data: name, title, job title, company name, and related identifiers.
- Contact data: email address, telephone number, postal address, and preferred communication details.
- Business and account data: correspondence, service requirements, meeting notes, project details, invoicing information, and contractual records.
- Marketing and communications data: preferences, subscription choices, responses to campaigns, and engagement with our communications.
- Technical data: IP address, browser type, device information, log data, and website usage data.
- Transactional data: payment-related records, billing details, and service history, where applicable.
- Recruitment data: CVs, application information, interview notes, references, and eligibility information, where you apply for a role.
We may collect personal data directly from you, from your organisation, through our website, from publicly available sources, and from third parties such as service providers, business partners, and professional platforms.
We process personal data using both automated and manual methods where appropriate and necessary for our business operations.
3. Purpose of data processing
We process personal data for the following purposes:
- to provide and manage our retail-marketing services;
- to communicate with clients, suppliers, and other business contacts;
- to prepare and perform contracts;
- to manage billing, invoicing, accounting, and payment administration;
- to deliver marketing communications, where permitted by law;
- to analyse website performance, service use, and campaign effectiveness;
- to maintain internal records and business administration;
- to comply with legal and regulatory obligations;
- to detect, prevent, and investigate fraud, misuse, security incidents, or other unlawful activity;
- to recruit and assess candidates for employment or engagement;
- to defend, establish, or exercise legal claims.
We only process personal data where the processing is relevant and limited to the stated purpose.
4. Legal basis for processing
We process personal data on one or more of the following legal bases, as applicable under relevant privacy laws:
- Consent: where you have given clear permission for specific processing activities, such as certain marketing communications or optional cookies.
- Contract: where processing is necessary to enter into or perform a contract with you or your organisation.
- Legal obligation: where we must process data to comply with applicable law, regulation, court order, or lawful request from a public authority.
- Legitimate interests: where processing is necessary for our legitimate business interests and those interests are not overridden by your rights and freedoms, including operating and improving our services, managing client relationships, ensuring network and information security, and conducting business development.
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
5. Data sharing and third parties
We may share personal data with third parties where necessary and appropriate for the purposes described in this policy, including:
- Service providers: IT hosting, cloud infrastructure, email delivery, customer relationship management, analytics, document storage, and administrative support providers;
- Professional advisers: lawyers, accountants, auditors, insurers, and other consultants;
- Payment and finance providers: banks, payment processors, and invoicing platforms;
- Business partners and clients: where required to deliver services or fulfil contractual obligations;
- Regulators, authorities, and law enforcement: where required by law or to protect our legal rights;
- Recruitment-related third parties: reference providers, background screening providers, and recruitment platforms, where applicable.
We require third parties to handle personal data in accordance with contractual obligations and applicable law, including appropriate confidentiality and security measures.
6. Data transfer to third countries
Where personal data is transferred outside the United Kingdom and/or other jurisdictions with comparable data protection rules, we take steps to ensure that the data remains protected by appropriate safeguards.
Such safeguards may include:
- transfer to countries recognised as providing an adequate level of protection;
- standard contractual clauses or equivalent approved transfer mechanisms;
- additional technical and organisational measures where required.
If you would like further information about international transfers and the safeguards we use, please contact us using the details below.
7. Storage duration
We retain personal data only for as long as necessary for the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, reporting, or contractual requirements.
Retention periods vary depending on the type of data and the purpose of processing. In general:
- client and business records are retained for the duration of the relationship and for a reasonable period afterwards;
- financial and tax records are retained for the period required by applicable law;
- marketing data is retained until you opt out, object, or the data is no longer needed;
- recruitment data is retained for the duration of the recruitment process and for a limited period afterwards, unless a longer retention period is required or permitted by law;
- technical logs are retained for limited periods for security, operational, and diagnostic purposes.
When personal data is no longer required, we will delete, anonymise, or securely archive it in accordance with our retention practices.
8. User rights
Subject to applicable law, you may have the following rights in relation to your personal data:
- Access: to request confirmation of whether we process your personal data and to obtain a copy of that data;
- Rectification: to request correction of inaccurate or incomplete personal data;
- Erasure: to request deletion of your personal data in certain circumstances;
- Restriction: to request restriction of processing in certain circumstances;
- Data portability: to request receipt of certain personal data in a structured, commonly used, machine-readable format and, where feasible, transfer to another controller;
- Objection: to object to processing based on legitimate interests and to object at any time to direct marketing.
We may need to verify your identity before responding to your request. We will respond within the timeframe required by applicable law. In some cases, we may lawfully refuse a request or limit our response where exceptions apply.
9. Withdrawal of consent
Where we rely on your consent to process personal data, you may withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing carried out before consent was withdrawn.
If you wish to withdraw consent, please contact us using the contact details provided in this policy or use any available unsubscribe or preference-management option in our communications.
10. Right to complain
If you have concerns about our handling of your personal data, we encourage you to contact us first so that we can try to resolve the matter.
You also have the right to lodge a complaint with a relevant supervisory authority or data protection regulator in your country of residence, place of work, or place of the alleged infringement, where applicable.
For individuals in the United Kingdom, this may include the Information Commissioner’s Office (ICO).
11. Data security
We use appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
These measures may include:
- access controls and role-based permissions;
- encryption and secure transmission methods where appropriate;
- regular backups and system monitoring;
- staff confidentiality obligations and security awareness;
- vendor due diligence and contractual security requirements;
- procedures for handling suspected personal data breaches.
No method of transmission or storage is completely secure. While we take reasonable steps to protect personal data, we cannot guarantee absolute security.
12. Contact information
If you have any questions about this Privacy Policy or our processing of personal data, please contact:
- Northbridge Retail Marketing Ltd
- Northbridge Retail Marketing, 3 Broad Quay, Bristol BS1 4DA, United Kingdom
- Email: [email protected]
- Phone: +44 117 923 7468
13. Changes to privacy policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, legal requirements, or other operational reasons.
Any updated version will be posted on our website or otherwise made available to you where appropriate. The “Effective date” above indicates when this policy was last updated.
We encourage you to review this Privacy Policy periodically to stay informed about how Northbridge Retail Marketing Ltd protects your personal data.