PRIVACY POLICY

This Privacy Policy explains how Prospect 13 Limited collects, uses and protects your personal data when you interact with us.

This includes clients, suppliers, partners, website users and anyone who engages with our services.

We follow UK data protection law, including:

  • UK GDPR
  • Data Protection Act 2018
  • The Data Use and Access Act 2025 (DUAA)

DUAA builds on GDPR and introduces updates around areas like cookies, automated decision-making and how businesses demonstrate compliance.

We are committed to being clear, fair and transparent about how we use your data.

Who We Are

Prospect 13 Limited
4 Rubislaw Terrace
Aberdeen
AB10 1XE

Company Number: SC605929

We act as both a Data Controller (deciding how your data is used) and, in some cases, a Data Processor (handling data on behalf of clients).

Our Approach to Data

We follow a simple rule: if we wouldn’t feel comfortable receiving it ourselves, we don’t do it.

Your data will always be:

  • used lawfully, fairly and transparently
  • collected for clear and legitimate purposes
  • limited to what is necessary
  • kept accurate and up to date
  • stored only as long as needed
  • kept secure

What Data We Collect

We only collect data that is relevant to the services we provide.

This may include:

  • Name, email address, phone number
  • Company and job details
  • Information submitted via forms or enquiries
  • Website usage data (e.g. analytics)
  • Social media information where relevant (e.g. LinkedIn)

We collect this data when you:

  • contact us
  • fill in a form
  • use our website
  • work with us as a client or supplier

How We Use Your Data

We use your data to:

  • deliver our services
  • respond to enquiries
  • manage client relationships
  • improve our website and marketing
  • meet legal or regulatory requirements

We will never use your data for anything unexpected or unclear.

Lawful Basis for Processing

We only use your data where we have a valid reason to do so, including:

  • fulfilling a contract
  • complying with legal obligations
  • legitimate business interests (where these do not override your rights)
  • your consent (where required, e.g. marketing communications)

Marketing Communications

We will only send marketing communications where:

  • you have opted in, or
  • a relevant “soft opt-in” applies

You can unsubscribe at any time using the link in our emails or by contacting us directly.

Cookies and Tracking

Our website uses cookies to improve your experience and understand how our site is used.

Some cookies are essential. Others help with analytics or marketing.

Under DUAA, some low-impact cookies may not require consent. However, we still follow PECR rules, which means we will:

  • clearly explain what cookies are used
  • give you real choice (accept, reject or manage)
  • request consent for marketing cookies

We use a compliant cookie management platform (CMP).

For more detail, see our Cookie Policy.

Automated Decision-Making and AI

We may use tools that involve automation, such as:

  • website personalisation
  • marketing segmentation
  • analytics and performance tracking

Where we do this, we will:

  • explain it clearly
  • ensure it is fair and appropriate
  • provide a way for you to request human review

We do not make decisions that significantly affect you without appropriate safeguards.

How Long We Keep Your Data

We only keep your data for as long as necessary.

For example:

  • enquiry data is kept while relevant to your request
  • marketing data is kept until you unsubscribe
  • client data is retained in line with legal and contractual requirements

We regularly review and securely delete data when it is no longer needed.

How We Keep Your Data Secure

We take data security seriously.

We use appropriate technical and organisational measures, including:

  • secure systems and storage
  • access controls
  • password protection
  • secure file sharing

Access to your data is limited to those who need it.

Sharing Your Data

We may share your data where necessary, including:

  • with trusted service providers
  • where required by law
  • where needed to deliver our services

All third parties are required to:

  • keep your data secure
  • only use it for agreed purposes
  • follow data protection laws

We do not sell your data.

Your Rights

You have the right to:

  • access your data
  • correct inaccurate data
  • request deletion
  • restrict or object to processing
  • withdraw consent
  • request data transfer
  • challenge automated decisions

To exercise any of these rights, contact:
hello@prospect13.co.uk

We aim to respond within one month.

Data Protection Complaints

If you have concerns about how your data is used, please contact us first.

We have a process in place to:

  • review concerns
  • respond clearly and promptly
  • resolve issues where possible

If you are not satisfied, you can contact the Information Commissioner’s Office (ICO).

International Data Transfers

Your data is stored securely within the UK.

If data is transferred outside the UK, we ensure appropriate safeguards are in place.

Third Party Links

Our website may contain links to other websites.

We are not responsible for their content or privacy practices. Please review their policies separately.

Updates to This Policy

We may update this Privacy Policy from time to time.

Any changes will be posted on this page, and we encourage you to review it periodically.

Contact Us

If you have any questions about this Privacy Policy or how we handle your data, contact:

hello@prospect13.co.uk

Last updated: 16th April 2026