Privacy & Cookie Policy
How we collect, use and protect personal data — and the choices you have.
Last updated 27 July 2026
1. Who we are
Talent Ascent Ltd (“Talent Ascent”, “we”, “us”) is the data controller responsible for your personal data. We are a company registered in England and Wales (company no. 16736436), registered office 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, and registered with the UK Information Commissioner’s Office under reference ZC042741. Contact: contact@talentascent.io.
2. Who this policy covers
This policy covers: website visitors; people who contact us or whom we contact about our services (prospects and business contacts); client personnel we work with during engagements; and buyers paying for services. If your information may be included in talent research we conduct for clients (for example market maps or succession research), our separate Privacy Notice for Talent Research applies to that processing.
We work business-to-business. We do not knowingly collect data about children, and we do not sell personal data.
3. What we collect
Information you give us — contact-form submissions (name, work email, company, company stage, message); correspondence by email or messaging; information shared during engagements (names, roles and business contact details of client personnel; materials your company provides). Information we collect about business contacts — professional details from public and professional sources (such as LinkedIn profiles, company websites and business directories) used to identify and contact companies that may benefit from our services: name, role, employer, business contact details. Order and billing information — company details, billing contact, order details and payment status (see Section 6 for what we never receive). Technical data — our hosting provider automatically logs limited technical information (IP address, browser type, pages requested) to deliver and secure the site. Consent preferences — your cookie/privacy choice, stored in your browser’s local storage.
4. Why we use it, and our legal bases
| Purpose | Legal basis (UK GDPR Art 6) |
|---|---|
| Responding to enquiries and providing information you request | Legitimate interests; steps to enter a contract at your request |
| Delivering engagements, managing client relationships, invoicing and accounts | Contract performance; legal obligation (tax and accounting records) |
| Business-to-business outreach about our services to relevant professional contacts | Legitimate interests in marketing relevant services to businesses — you can object at any time (Section 11) and we will stop |
| Operating, securing and improving the website | Legitimate interests in running a safe, functioning site |
| Processing payments and preventing fraud | Contract performance; legal obligation |
| Establishing, exercising or defending legal claims | Legitimate interests |
| Analytics (if enabled) | Consent only — off by default, withdrawable at any time |
We do not carry out automated decision-making that produces legal or similarly significant effects about you.
5. Business outreach
Where we contact people at companies we believe may benefit from our services, we use professional contact details relevant to their role, gathered from professional and public sources. We contact business capacities only, we identify ourselves clearly, and every message offers a straightforward way to opt out. If you ask us to stop, we suppress your details rather than merely deleting them, so you are not contacted again.
6. Payments
Card and bank payments are handled by our payment providers on their secure, hosted payment pages. Card details are entered directly with the provider and never reach our systems. Our providers act as independent controllers of payment data for purposes such as fraud prevention, security and financial compliance, under their own privacy notices. We receive confirmation of payment, the payment method type, and the billing details needed for our records — not card numbers.
7. Who we share data with
We use carefully selected service providers who process data on our behalf under contract: Cloudflare (website hosting and content delivery), Resend (contact-form email delivery), Google Workspace (email and document storage), Notion (client and prospect relationship records), Clinked (our client portal — secure exchange and storage of engagement materials, including any documents and data you submit for a report, audit or design engagement), FreeAgent (invoicing and accounting), and our payment providers (payment processing — see Section 6). We may also share data with professional advisers (accountants, lawyers, insurers) under confidentiality, and with authorities where the law requires. We do not sell personal data and we do not use advertising trackers.
8. International transfers
Some providers are based outside the UK/EEA (for example, in the United States). Where personal data is transferred internationally, we rely on UK adequacy regulations or appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
9. How long we keep it
We keep personal data only as long as needed for the purposes described, then delete or anonymise it: contracts, invoices, tax and accounting records — 6 years from the end of the relevant financial year (legal requirement); engagement deliverables and correspondence — 6 years from the end of the engagement (aligned to the legal limitation period); personal data gathered in talent research — no longer than 12 months after delivery of the engagement (see the Privacy Notice for Talent Research); prospect and business-contact data — 24 months from our last meaningful contact, or immediately suppressed on objection; contact-form enquiries that do not become engagements — 24 months; technical logs — a short period for security and diagnostics; analytics data — as set out in Section 12.
10. Security
We protect personal data with appropriate technical and organisational measures, including encryption in transit, access controls on a least-privilege basis, reputable providers with strong security practices, and retention limits enforced by scheduled deletion.
11. Your rights
Under UK GDPR you have the right to access, rectify, erase, restrict or object to our processing of your personal data, the right to data portability, and the right to withdraw consent at any time where processing is based on consent. Objections to business outreach are always honoured. To exercise any right, email contact@talentascent.io; we respond within one month and may need to verify your identity.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority — although we would welcome the chance to resolve your concerns first.
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113 · ico.org.uk
12. Cookies and local storage
We keep this minimal. Everything we store in your browser is first-party, is set only when you take an action that asks us to remember something, and identifies nothing about you beyond the preference itself:
None of these require consent under PECR: each is essential to providing a service you explicitly requested — remembering a choice you made. Analytics / Marketing — not currently active. If we add them in future, they will load only after you opt in, and you can change your mind at any time via Manage cookie settings in the site footer.
13. Changes to this policy
We may update this policy from time to time. Material changes will be reflected here with a revised “last updated” date, and where required we will ask for your consent again.
14. Contact
Questions about this policy or your data? Email contact@talentascent.io.