Important
The Raeburn Group is a group of separate legal entities. The company that determines why and how your personal data is used is normally the company you deal with. In some circumstances, more than one group company may act as an independent or joint controller. We explain the relevant arrangement below and in service-specific notices where required.
Scope and who is responsible for your data
This policy applies to personal data processed through theraeburngroup.com, enquiries routed through the Group, and central group functions operated by The Raeburn Holding Group Limited. It also provides a group-level privacy framework for subsidiaries and trading businesses where they link to or adopt this policy.
The Raeburn Holding Group Limited, registered in England and Wales under company number 17361231, is the controller for personal data collected for its own corporate, website, group-governance and central administration purposes. A subsidiary is the controller for personal data it collects and determines the purposes of in connection with its own services, clients, candidates, users, suppliers or operations.
Where an enquiry is intended for a particular group company, we may pass the enquiry and relevant personal data to that company so it can respond. The receiving company then processes that information under its own responsibilities as a controller.
Personal data we may collect
Depending on how you interact with us, we may collect:
- identity and contact data, including name, role, organisation, postal address, email address and telephone number;
- business and professional data, including employer, job title, work history, skills, CV information and professional profiles;
- communications, enquiry content, meeting notes, correspondence, customer-support records and preferences;
- contract, transaction, billing, payment and account-administration information;
- authorised bank-connection data described in section 3 where a relevant service uses financial-account connectivity;
- technical and usage data, such as IP address, browser/device information, security logs, page interactions and cookie or similar technology data;
- supplier, partner, investor, adviser and other business-contact information;
- recruitment and candidate information where you apply for a role, register as a candidate or interact with a recruitment business in the Group; and
- other information you choose to provide to us.
We do not seek special-category or criminal-offence data unless it is necessary for a specific lawful purpose. If it is required, we will apply the additional UK GDPR and Data Protection Act 2018 conditions that are relevant to that processing.
Payments, Financial Connections and bank-account data
Some Group products or services may use Stripe or another regulated/payment technology provider to process payments or allow an authorised user to connect a financial account. Where Stripe Financial Connections is used, the connection is initiated by you and data made available will depend on the permissions and account information presented during that connection flow.
Subject to the particular service and your authorisation, this can include financial-institution and account identifiers, account-holder or ownership information, balances and transaction information. We may use this information for payment or payout operations, account ownership verification, reconciliation, cash-flow or financial-management functionality, fraud and security controls, and related service administration.
We do not use Financial Connections data for lending, credit scoring or underwriting unless a separate service expressly tells you otherwise and provides any additional notices and permissions required by law. We do not sell Financial Connections data.
Stripe and other payment providers process some information under their own legal responsibilities and privacy terms. We do not normally receive full payment-card credentials when they are entered directly into a payment provider's hosted or tokenised payment interface.
How we use personal data
We may use personal data to:
- respond to enquiries and identify the appropriate Group company or service;
- provide, administer, support, secure and improve services and digital products;
- enter into and perform contracts, process payments and maintain business records;
- verify account ownership, reconcile transactions and operate authorised financial-management functionality where applicable;
- manage clients, candidates, suppliers, partners and other business relationships;
- carry out recruitment and talent activities;
- protect our systems, users, businesses and rights, including fraud prevention, audit and information security;
- meet legal, tax, accounting, regulatory and corporate-governance obligations;
- establish, exercise or defend legal claims;
- measure website/service performance and improve user experience; and
- send permitted business or marketing communications, subject to your rights and applicable electronic-marketing rules.
Our lawful bases under UK data protection law
We rely on one or more lawful bases depending on the activity:
- Contract: where processing is necessary to take requested pre-contract steps or perform a contract with you.
- Legitimate interests: for proportionate business administration, service improvement, relationship management, security, fraud prevention, business-to-business development and Group operations, where those interests are not overridden by your rights.
- Legal obligation: where processing is necessary to comply with applicable law.
- Consent: where consent is legally required or is otherwise the appropriate basis, including certain marketing, cookie or optional data uses. You may withdraw consent at any time without affecting earlier lawful processing.
Connecting a bank account or selecting permissions in a third-party connection flow authorises the technical access described in that flow; the UK GDPR lawful basis for our subsequent processing will depend on the relevant service and purpose and may be contract, legitimate interests, legal obligation or consent as appropriate.
International data transfers
Some suppliers or systems may process personal data outside the United Kingdom. Where UK data protection law restricts a transfer, we use an available lawful transfer mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved EU Standard Contractual Clauses, or another legally recognised safeguard, together with supplementary measures where appropriate.
Where a particular product commits to a defined data-hosting region, such as the United Kingdom or United States, that product's technical configuration and service terms will govern the relevant hosting commitment. A hosting location does not necessarily prevent limited authorised support, security or subprocessors from operating in other jurisdictions where lawful safeguards are in place.
How long we keep personal data
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including contractual, operational, security, tax, accounting, regulatory and legal-claims requirements. Retention periods differ by data type and business activity.
When deciding how long to retain information, we consider the amount, nature and sensitivity of the data, the risk of harm, why we need it, whether the purpose can be achieved another way, contractual requirements and applicable limitation or statutory periods. Data may be securely deleted, anonymised or retained in restricted archives when its active use ends.
Security and confidentiality
We use technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures are selected according to risk and may include access controls, least-privilege permissions, encryption or secure transport, authentication controls, logging, supplier due diligence, backup, vulnerability management and incident-response procedures.
No internet transmission or storage system can be guaranteed to be completely secure. Where the law requires it, we will assess and report qualifying personal-data breaches to the UK Information Commissioner's Office and notify affected individuals when the relevant legal threshold is met.
Your data-protection rights
Subject to the conditions and exemptions in applicable law, you may have rights to request access to your personal data; correction of inaccurate or incomplete data; erasure; restriction of processing; data portability; and objection to processing based on legitimate interests or to direct marketing. You may also withdraw consent where processing relies on consent.
We may need to verify your identity before acting on a request. There is normally no fee, although the law permits a reasonable fee or refusal in limited circumstances for manifestly unfounded or excessive requests. We aim to respond within the statutory period and will tell you if a lawful extension is required.
Marketing, analytics and cookies
We apply the Privacy and Electronic Communications Regulations (PECR) and UK GDPR to electronic marketing and cookie technologies where they apply. You can opt out of direct marketing at any time using the unsubscribe method in the communication or by contacting us. An opt-out does not prevent service, transactional, security or legally required messages.
Our use of cookies and similar technologies, including the distinction between strictly necessary and optional technologies, is explained in our Cookie Policy.
Recruitment and candidate data
If you apply for employment, register as a candidate or engage with a Group recruitment business, additional information may be processed to assess suitability, communicate about roles, verify information, conduct lawful checks, introduce candidates where authorised, maintain recruitment records and meet legal obligations. A recruitment business may provide a more specific candidate privacy notice where its processing requires additional detail.
Automated processing and AI-assisted tools
We may use automation or AI-assisted tools to support analysis, classification, drafting, workflow routing, fraud/security controls or operational decision support. Unless a specific service tells you otherwise, we do not intend to make a decision producing legal or similarly significant effects about an individual solely by automated means without the safeguards required by law.
Where a service uses automated decision-making within Article 22 UK GDPR or equivalent applicable rules, we will provide any additional information and rights required for that processing.
Children's data
The Group's corporate website and general business services are not directed at children. A product or service specifically designed for children or families will use an appropriate service-specific privacy notice and age-appropriate safeguards where required. If we become aware that children's data has been collected in circumstances where it should not have been, we will take appropriate steps to address it.
Changes to this policy
We may update this policy to reflect changes in law, regulation, technology, Group structure, suppliers or processing activities. The effective date at the top of this page will be updated when material changes are published. Where required by law, we will provide additional notice or seek fresh consent before materially changing a consent-based use of personal data.
Contact, requests and complaints
For privacy questions or to exercise a data-protection right, contact contact@theraeburngroup.com. Please identify the Group company or service you dealt with where possible so the request can be routed to the correct controller.
The Raeburn Holding Group Limited's registered office is 82a James Carter Road, Bury St. Edmunds, England, IP28 7DE.
You also have the right to complain to the UK Information Commissioner's Office (ICO). We would welcome the opportunity to address your concern first, but you are not required to contact us before approaching the ICO.
For information on our broader security and governance posture, visit Trust & Security.