Lync HumanEdgeLync HumanEdge

Draft for legal review

This is a complete draft, not approved wording, and it must not go live until a qualified person has reviewed it. Everything describing how the website behaves has been checked against the code and is marked as checked. Everything that is a legal or commercial decision is marked as outstanding and has been left for your solicitor and for you to settle. Nothing here is legal advice.

Legal

Privacy Policy

Last updated: to be set on publication · UK GDPR, the Data Protection Act 2018 and PECR as amended by the Data (Use and Access) Act 2025

01

Who we are

Lync HumanEdge is a human performance advisory based at 7 to 9 Bridge Place, Worksop, Nottinghamshire, S80 1DT. You can reach us on 01909 484106.

For the purposes of data protection law we are the data controller for the personal data described in this policy. That means we decide what is collected and why.

Outstanding

The registered legal entity name and company number, the registered office if it differs from the trading address above, the ICO registration number, and the name or job title of the person accountable for data protection. A controller processing health data on this scale should expect to be paying a data protection fee to the ICO, and the registration number is normally published in a privacy policy.

02

What this policy covers

This policy covers the personal data we collect through this website. That is a deliberately narrow scope, and the distinction matters.

  • This website. Enquiries sent through the contact form, and the technical records created by serving you a page. That is what this policy describes.
  • Our services. When we deliver diagnostics, programmes or occupational health for a client organisation, we handle information about that organisation's employees, including health information. That processing is governed by the contract with the client organisation and by separate privacy information given to the people concerned. It is not covered here.

If you are an employee of an organisation we work with and you want to know how your health information is handled, this is not the document you need. Contact us and we will direct you to the right one.

Needs a decision, not just drafting

The separation above is the single most important structural choice on this page, and it needs to be confirmed as accurate before it is published. In particular: for the employee health data handled during service delivery, is Lync HumanEdge a controller, a joint controller with the client organisation, or a processor acting on the client's instructions? The answer changes who owes the privacy notice, who answers a subject access request, and what has to be in the client contract. It is a question for your solicitor and it should be settled before either policy is written.

03

What we collect

Through the enquiry form, we collect only what you type into it:

  • Your name, your organisation, your email address and your message. These are required.
  • Your job role, your telephone number and the size of your workforce. These are optional and the form works without them.

We ask for nothing else. There is no account to create, no newsletter checkbox and no profiling. Please do not send us health information about yourself or about a named individual through this form. It is an enquiry form and it is not the appropriate route for it.

Separately, our hosting provider creates technical records when it serves you a page. These can include your IP address, the time of the request, the page requested, and information your browser reports about itself.

Checked against the build

The field list above is exact and is enforced by the server, not merely by the page. The form posts to an endpoint on this domain rather than to any third party form service. The content of an enquiry is never written to a log, on success or on failure, which is a deliberate constraint and is covered by an automated test. At the time of writing no mailbox is connected, so the form refuses every submission with an error and says so on the page: nothing is collected or stored by it yet.

What you type is sent in the body of the request and never in the address. That distinction matters more than it sounds: a form that sends its contents in the web address puts every word of an enquiry into your browser history and into the ordinary access records of every machine the request passes through, where nobody would think to look for it and nobody would think to remove it. This form is not built that way, it does not fall back to being built that way if the page's scripts do not load, and an automated check fails the build if either of those stops being true.

Outstanding

Confirm what the hosting provider actually retains, and for how long, then state it here rather than describing it in general terms. The same applies to the mail provider once one is chosen: an enquiry becomes an email, and that email sits in a mailbox somewhere under someone's retention policy.

04

Why we collect it, and our lawful basis

We use enquiry details for one purpose: to read what you asked and to reply to it. If a conversation follows, we use your details to have that conversation.

We do not sell personal data, we do not share it for anyone else's marketing, and we do not use it to build a profile of you.

Outstanding

State the lawful basis under Article 6 and say so plainly. For an unsolicited business enquiry the usual analysis is legitimate interests, in which case the legitimate interests must be identified here and a balancing assessment kept on file. If any of it is instead consent, or steps taken at your request before entering a contract, say which and why. This should be confirmed by your solicitor rather than picked from a template.

Outstanding

Decide whether enquiry addresses will ever be used for marketing, such as an Insights mailing. If yes, that is a separate purpose needing its own basis and, under PECR, almost certainly consent, plus an unsubscribe route in every message. If no, say so here in one sentence, because it is a meaningful commitment and it is easy to state.

05

Health and special category data

This website does not collect health information about anybody, and it is not designed to. There is no assessment, no questionnaire and no upload on this site.

Our services are a different matter. Health assessments, mental health screening and occupational health all involve data concerning health, which is special category data under Article 9 of the UK GDPR and carries obligations well beyond those for ordinary personal data.

The line we hold in that work is that reporting to a client's board is organisational, never individual. A client sees rates, trends and costs across a workforce. A client does not see one person's results.

Needs a decision, not just drafting

This is the most consequential section on the page and it must not be written from a template. It needs, at minimum: the Article 9 condition relied on and the corresponding Schedule 1 condition in the Data Protection Act 2018; an appropriate policy document, which Schedule 1 requires for most of the conditions likely to apply here and which must be retained and made available to the ICO on request; a Data Protection Impact Assessment, which is very likely mandatory given health data processed at scale; and a written description of the technical and organisational separation between individual health records and the organisational metrics reported to a client. The commitment in the paragraph above is the right one, but as drafted it is a statement of intent. Your solicitor should turn it into a statement of what is actually enforced, and someone should confirm the enforcement exists.

06

Who we share it with

We do not sell or trade personal data. The typeface, the styles, the scripts and the images on this page are all served from this domain, so simply reading the site sends nothing to anyone else. A small number of suppliers do necessarily handle data in order for the website to work:

  • Our hosting provider serves every page and creates the technical records described above.
  • Our content management system stores the Insights articles. On an article page your browser loads images directly from that supplier, so it receives your IP address. The rest of the site does not contact it at all.
  • A mail provider will carry enquiries from the form to our mailbox once one is connected.

We may also disclose information where the law requires it, or to establish or defend a legal claim.

Separately from that, this site links out to the published research it cites, so that any figure we quote can be checked at its source. Those links open in a new tab. A link is not a request: nothing is sent to those publishers unless you choose to follow one, and if you do, that is your own visit to their site, governed by their privacy policy rather than ours. We are not told that you followed it. Because this site sends only the originating domain and not the full address when you leave it, they learn that someone arrived from us, not which page you were reading.

Checked against the build

The list of third parties your browser is asked to contact is complete and was taken from the built site rather than from memory. On the six marketing pages and these legal pages, that list is empty: every font, style, script and image comes from this domain. There is no analytics, no tag manager, no advertising pixel, no social embed and no session recording anywhere on this site. The one exception is an article page, which loads its images from the content management system's image service. An automated check fails the build if a third party is added here without this page being updated to say so.

That check draws the same distinction this section does, and it draws it in the code rather than trusting anyone to remember: a script, a stylesheet, a font or an image loaded from another domain is counted and fails the build, while a link you may choose to follow is not. The referrer behaviour described above is set by a header on every response, strict-origin-when-cross-origin, and not by anything on the page.

Outstanding

Name each supplier explicitly once they are confirmed, and put a data processing agreement in place with each. A privacy policy that says "our hosting provider" is weaker than one that names them. Two of the three are already fixed and only need naming; the mail provider does not exist yet.

07

Where it is stored, and transfers abroad

Some of the suppliers above are established outside the United Kingdom, or run infrastructure outside it. Where personal data is transferred out of the UK, the law requires an appropriate safeguard, such as adequacy regulations or the International Data Transfer Agreement.

Outstanding

This section cannot be finished until the suppliers are fixed. For each one, record the country the data is actually processed in, and the transfer mechanism relied on. Three specifics are already known to need answers: the region the site is deployed to, the region the content management system's dataset lives in, and the location of whichever mailbox receives enquiries. All three are configurable, so they are choices rather than facts, and choosing UK or EU regions where available would shorten this section considerably.

08

How long we keep it

We keep enquiries for as long as we need them for the purpose described in section 04, and then we delete them.

Outstanding

Replace the sentence above with real periods before publication. As written it says almost nothing, and the UK GDPR requires retention periods, or at least the criteria used to set them, to be stated. Decide separately for: an enquiry that leads nowhere, an enquiry that becomes a client, and the technical records held by the hosting provider. Then make sure the stated periods are the ones actually applied, including inside the mailbox, which is where enquiries will really accumulate.

09

What this site stores on your device

This website sets no cookies at all.

One item is stored on your device. If you use the light and dark toggle, we save your choice in your browser's local storage under the name theme, with a value of either light or dark. That is the whole of it. It is written only when you press the toggle, it never leaves your device, it identifies nothing about you, and it is not read by anybody but this site.

We rely on the appearance exception in PECR for this, which covers storage whose only purpose is to adapt how a service appears in line with your preference. If you would rather we did not keep it, you can clear site data for this domain in your browser settings at any time, and the site will simply follow your system's light or dark setting instead. Nothing else on the site changes.

There is no analytics on this website, so nothing measures or reports how you use it.

Checked against the build

Verified in the code: no cookie is set anywhere on this site, and the single local storage entry is the theme preference described above. If analytics is ever added, this section stops being accurate and a consent banner becomes a live question rather than a theoretical one.

Needs a decision, not just drafting

The appearance exception is one of the five PECR exceptions and was put on its current footing by the Data (Use and Access) Act 2025, with the ICO's finalised guidance published in April 2026. Relying on it is permitted without consent, but only if two conditions are met: clear and comprehensive information about the purpose, which the paragraphs above are intended to be, and a simple, free means of objecting. Ask your solicitor whether pointing people at their browser settings is a sufficient means of objecting, or whether the toggle itself should offer a way to use the site without the preference being remembered. That is a small build change if the answer is the latter.

10

Your rights

Under UK data protection law you have the right to ask us for a copy of the personal data we hold about you, to have it corrected if it is wrong, to have it deleted, to restrict or object to how we use it, and to receive it in a portable form. Where we rely on consent, you can withdraw it at any time, and that does not affect anything done before you withdrew it.

You will not be charged for making a request. We will respond within one month, and we will tell you if we need longer because the request is complex.

To make a request, contact us using the details in section 13.

Outstanding

Confirm the internal process behind this promise before publishing it. A response within one month is a legal deadline, not a courtesy, and stating it commits you to being able to find and produce the data. That includes finding it in the mailbox. Also confirm what identification will be asked for, and record it here if anything is.

11

How to complain

If you are unhappy with how we have handled your personal data, please tell us first so we can try to put it right.

You also have the right to complain to the Information Commissioner's Office, which is the UK's supervisory authority for data protection. You can reach the ICO at ico.org.uk, or on 0303 123 1113, or by writing to Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.

Outstanding

Confirm the ICO's published contact details on the day this page is finalised, and check them again whenever the page is next reviewed. They are stated here because a privacy policy must tell people about their right to complain, but details should be verified rather than inherited from a draft.

12

Changes to this policy

If we change how we handle personal data, we will update this page and change the date at the top. Where a change is significant, we will do more than quietly amend the page.

Outstanding

Decide what "more than quietly amend the page" means in practice and say it precisely, or remove the sentence. Decide too how often this page is reviewed even when nothing changes, and put the review in someone's calendar. A policy that is never revisited stops being accurate without anyone noticing.

13

Contact

For anything in this policy, including a request about your own data, write to us at 7 to 9 Bridge Place, Worksop, Nottinghamshire, S80 1DT, or call 01909 484106.

Email to be confirmed on the new domain.

Outstanding

A privacy policy needs a working contact route, and a postal address alone is a poor one for a data subject request. The email address on the new domain should be in place before this page is published, and it should be a monitored mailbox rather than a personal one.