Skip to searchSkip to main content
  • Privacy Notice

Last Updated: Version 2.0: June 2026

Our Privacy Notice explains how TSOS Group collects, uses, stores and protects personal information. It sets out what data we may process, why we use it, who it may be shared with, how long we keep it and the rights individuals have under data protection law.

TSOS Group Limited referred to herein as (“the Company”, “We”, “Us” or “Our”) is committed to protecting your privacy. This notice explains what Personal Data we collect when you visit our website tsosgroup.com, how we use it, the legal basis for doing so, how long we keep it and what your rights are.


We are the data controller for the personal data collected through this website. Our registered details are: 

Organisation Name: TSOS Group Limited

Registered Address: 20 - 22 Wenlock Road, London, N1 7GU

Trading Address: TSOS Unity Hub, Town Hall Evreux Way, Rugby, CV21 2RR

Company Registration Number: 10930782

ICO Registration Number: ZA726097

Email: privacy@tsosgroup.com


This Privacy Notice applies to Personal Data that is collected via this Website and the forms available on it. Please read it carefully and ensure that you understand it. If you do not agree with and accept this Privacy Notice, do not access or use the Website or any other aspect of Our business.

Our website is not intended for children, and we do not knowingly collect any data relating to minors.

In this Privacy Notice the following terms shall have the following meanings:

 Term Definition
 AccountA registered profile or account created by a User to access restricted areas, services, bookings, purchases or resources on the Website. 
 Aggregated DataStatistical or demographic data that does not directly or indirectly identify an individual. 
 Automated Decision Making (ADM)A decision made solely by automated means, without any meaningful human involvement, that produces a legal or similarly significant effect on an individual. Subject to specific restrictions and transparency duties under UK GDPR Article 22. 
Company / We / Us / Our The organisation operating the Website and providing the Services, acting as the Data Controller unless otherwise stated. 
 ConsentA lawful basis for processing personal data under UK GDPR and EU GDPR. Must be freely given, specific, informed and unambiguous. Requires a clear affirmative action. Pre-ticked boxes or silence do not constitute valid consent.
 ContentAny text, graphics, images, photographs, audio, video, software, code, databases, documents, data compilations, downloadable materials, or other information capable of being stored electronically that appears on, forms part of, or is made available through a website, platform, application or service.
Controller (Data Controller)The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing personal data. Where an organisation collects and uses personal data for its own purposes, it will generally act as the Controller unless otherwise stated.
 CookiesA small file placed on a user's device when they visit a website. Under PECR, cookies (and similar technologies) that are not strictly necessary require the user's prior informed consent before being set.
 Cookie PolicyThe separate policy explaining what cookies and similar technologies are used on the Website, why they are used, and how Users can manage preferences.
 CRM SystemA Customer Relationship Management system used to manage enquiries, customer records, bookings, communications and related business interactions. 
 Data Protection LawAll applicable laws and regulations governing privacy, electronic communications and Personal Data, including the UK GDPR, DPA 2018, DUAA 2025, PECR, EU GDPR where applicable, and related guidance. 
 Data Protection Officer / DPOA designated individual responsible for overseeing data protection compliance within an organisation. Mandatory under UK GDPR Article 37 for public authorities, organisations with large-scale systematic monitoring, or large-scale special category processing. 
 Data SubjectA living identified or identifiable individual about whom we hold Personal Data. Data Subjects may be nationals or residents of any country and have legal rights regarding their Personal Data. 
 EEAThe European Economic Area. 
 ICOThe UK's independent data protection and freedom of information regulator. Responsible for enforcing UK GDPR, DPA 2018, PECR and FOIA. 
 Information SystemsThe collective term for all devices, hardware, software, networks, infrastructure, applications and communications technologies used to access, process, store, transmit or manage the organisation's information, IT resources and communication systems. This may include, but is not limited to, desktop computers, servers, smartphones, mobile or cellular phones, tablets, laptop or notebook computers, removable media, cloud services, email platforms, messaging systems, telecommunications equipment, and network-connected devices. 
 International Data Transfer The transfer of Personal Data to a country or organisation outside the UK (for UK GDPR) or outside the EEA (for EU GDPR). Requires an appropriate transfer mechanism such as an adequacy decision, standard contractual clauses or binding corporate rules. 
 Lawful BasisThe legal ground that justifies processing Personal Data under UK GDPR Article 6. There are six lawful bases: consent, contract, legal obligation, vital interests, public task and legitimate interests. Controllers must identify and document a lawful basis before processing begins. 
 Legitimate InterestsA lawful basis for processing personal data under UK GDPR Article 6(1)(f). The controller's (or a third party's) legitimate interests must be balanced against the individual's interests, rights and freedoms. Requires a Legitimate Interests Assessment (LIA). 
 Marketing CommunicationsEmails, newsletters, service updates, offers or other promotional communications sent to Users. 
 Personal DataAny information relating to an identified or identifiable living individual. Includes names, email addresses, IP addresses, location data, cookies, and any other data that can directly or indirectly identify a person. 
 ProcessingAny operation performed on Personal Data, including collection, recording, storage, use, disclosure, transfer, deletion or destruction. 
Processor / Data Processor An organisation or individual that processes personal data on behalf of and under the instructions of a controller. Processors have direct obligations under UK GDPR including security, sub-processor controls and breach notification to the controller. 
RecipientA person, organisation or authority to whom Personal Data is disclosed. 
 Retention PeriodThe defined period for which personal data is kept before being securely deleted or anonymised. Must be no longer than necessary for the original purpose. Controllers must document retention periods and implement automatic deletion or review processes. 
 ServicesAny products, services, training, consultancy, software, digital platforms, memberships, subscriptions, support, resources or other offerings provided by the organisation to customers, members, users or other stakeholders, whether delivered online, remotely or in person. 
Soft Opt-InThe limited PECR rule that may allow marketing to existing customers about similar goods or services where they were given a clear chance to opt out. 
 Special Category DataA defined set of particularly sensitive personal data categories requiring additional protection under UK GDPR Article 9. Includes data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for identification, health data, sex life or sexual orientation. 
 Technical and Usage DataInformation about how a User accesses and uses the Website, such as IP address, browser type, pages visited, referral source, device type and operating system. 
 Third Party ProviderThe UK addendum to the EU Standard Contractual Clauses used for certain international transfers of Personal Data. 
 UK AddendumThe UK addendum to the EU Standard Contractual Clauses used for certain international transfers of Personal Data. 
 WebsiteThe website operated by the Company, including associated webpages, online forms, booking pages, portals, applications and digital resources. 

3.1 We may, from time to time, modify this Privacy Notice. Please check this Website periodically for updates. We will comply with applicable legal obligations to provide you with relevant notice of changes to this Privacy Notice. Your continued use of our Website after any such update constitutes your acceptance of such changes.

4.1 Personal data provided by Users will, where it is relevant to any division, be transferred along with that division. The new owner or newly controlling party will, under the terms of this Privacy Notice, be permitted to use the Personal Data for the purposes for which it was supplied to Us.


4.2 In the event of 4.1 (above), written notice will be delivered to the email address associated with the Users account. Following this, you may opt for your Personal Data to be transferred to the new owner or withheld.

5.1 You may access certain areas of this website without providing any Personal Data at all. Our website uses cookies. Some are strictly necessary for the site to function. Others, including analytics and marketing cookies, require your consent before they are placed on your device. You can manage your cookie preferences at any time using the cookie banner or preference centre on our website. For more information, please visit our Cookie Policy


5.2 We may collect, use, store and transfer different kinds of personal and non-personal data about you which We have grouped together as follows: 


5.2.1 Aggregated Data 

  • Statistical or demographic data for any purpose. Aggregated data could be derived from Personal Data but is not considered Personal Data in law as this data will not directly or indirectly reveal the identity of a Data Subject. For example, We may aggregate usage data to calculate the percentage of Users accessing a specific Website feature. However, if We combine or connect aggregated data with Personal Data so that it can directly or indirectly identify an individual, We treat the combined data as Personal Data which will be used in accordance with our Privacy Notice. 

5.2.2 Enquiry and Contact Forms 

  • Name 

  • Email address 

  • Job title (if provided) 

  • Telephone number (if provided) 

  • Organisation name (if provided) 

  • The content of your message or enquiry 

5.2.2 Account Registration (if applicable) 

  • Name and email address 

  • Username and password (stored in encrypted form) 

  • Organisation and role (if requested) 

5.2.3 Booking and Purchasing 

  • Name, email and contact details 

  • Billing address and payment information (processed by a third-party payment provider.  

  • Where applicable, data Including card or bank information for transfers and direct debits are collected by Our payment providers Stripe (Privacy Policy) and GoCardless (Privacy Centre - Payers | GoCardless). You can access their Privacy Policy by clicking the link next to the payment provider's name. We do not process or store card or bank details. 

  • Details of the service or product purchased 

5.2.4 Technical and Usage Data 

  • IP address 

  • Browser type and version 

  • Pages visited and time spent on pages 

  • Referral source (how you found our website) 

  • Device type and operating system 

Technical data may be collected through cookies and similar technologies. Please see our Cookie Policy for further information. 


We do not collect any Special Categories of Personal Data about you on this Website (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data). Nor do We collect any information about criminal convictions and offences.

6.1 We use the personal data we collect for the following purposes:

 Purpose Lawful Basis
Responding to your enquiries and providing the information or service you requested Contract (Article 6(1)(b)) or Legitimate Interests (Article 6(1)(f)) 
Processing bookings, orders and payments Contract (Article 6(1)(b)) 
Sending you information about our services where you have requested this or where the soft opt-in applies Consent (Article 6(1)(a)) or Legitimate Interests (Article 6(1)(f)) 
Improving our website and understanding how visitors use it Legitimate Interests (Article 6(1)(f)) 
Complying with legal obligations such as financial record-keeping Legal Obligation (Article 6(1)(c)) 
Preventing fraud and ensuring the security of our website Legitimate Interests (Article 6(1)(f)) 
Providing  you with information via emails and newsletters that you have opted into. You can withdraw your consent at any time. You can do this by clicking unsubscribe at the footer of the email. Consent (Article 6(1)(a))

7.1 Where required we may share this information as follows with:


Email and CRM platform providers: used to manage communications. 


Professional Advisers: Accountants, consultants, auditors, lawyers and other outside professional advisors to us, subject to binding professional and/or contractual obligations of confidentiality. Third Party Service Providers: With third party service providers who support Our business, who will process it on behalf of us for the purposes identified above. Such third parties may include providers of hosting services.


Regulatory authorities or law enforcement:where we are legally required to disclose information. 


Business or Share Sales: With any relevant third-party acquirer(s), in the event that We sell or transfer all or any relevant portion of our shares, business or assets (including in the event of a re organisation, dissolution or liquidation).


Third Party Providers of Advertising, Plugins and Content: The Website may use third party advertising, plugins or content. If you choose to interact with any such advertising, plugins or content, your Personal Data may be shared with the relevant third-party provider. We recommend that you review that third-party’s Privacy Notice before interacting with such content.


7.2 If any of your Personal Data is required by a third party, as described above, We will take steps to ensure that your Personal Data is handled safely, securely, and in accordance with your rights, Our obligations, and the third party’s obligations under Data Protection Legislation.


7.3 If any Personal Data is transferred outside of the EEA or UK, We will take suitable steps in order to ensure that your Personal Data is treated just as safely and securely as it would be within the EU/UK and under the GDPR, as explained above.


7.4 You can request details of the safeguards we rely on by contacting us using the details in Section 9.4.  

8.1 We will not keep your Personal Data for any longer than is necessary for the reason(s) for which it was first collected. Your Personal Data will therefore be kept for the following periods (or, where there is no fixed period, the following factors will be used to determine how long it is kept):

 

Personal Data you provide on this Website or any forms contained within it, is securely stored in Our Customer Relationship Management (CRM) system.

 Type of Data Retention Period
Enquiry and contact form submissions2 years from the date of last contact, unless a contract follows
Customer and transaction records7 years from the end of the financial year in which the transaction occurred (HMRC requirement)
Account informationFor the duration of your account plus 2 years after closure
Website analytics and usage data13 months (in line with ICO guidance on analytics cookies)
Email marketing preferencesFor as long as you remain subscribed (have positively opted-in) to Our emailing list and wish to receive news and offers from Us

If none of the above applies, then we will keep your data for a maximum period of five years following your initial communication or signup/Personal Data submission.

8.2 We take every reasonable step to ensure that your personal data are only processed for the minimum period necessary for the purposes set out in this Privacy Notice.


8.3 We will retain Personal Data in a form that permits identification only for as long as:


(a) we maintain an ongoing relationship with you (for example, for as long as you are using Our products and/or services); or

(b) retention of your Personal Data is necessary in connection with the lawful purposes set out in this Privacy Notice, for which we have a valid legal basis.


8.4 We will retain the Personal Data for the duration of:


(a) any applicable limitation period under law (i.e., any period during which a person could bring a legal claim against us in connection with your Personal Data or to which your Personal Data is relevant), plus an additional two-month period following the end of such limitation period; and

(b) if any relevant legal claims are brought, We will continue to process Personal Data for such an additional period as is necessary in connection with that claim.


8.5 Once the periods at 8.4 and 8.5 above have passed, We will either permanently delete or destroy the relevant Personal Data; or anonymise the relevant Personal Data.


8.6 We do Our best to keep your data secure and have put in place appropriate security measures to prevent your Personal Data from being accidentally lost, used, or accessed in an unauthorised way, altered, or disclosed. In addition, We limit access to your Personal Data to those employees, contractors and other third parties who have a business need to know. Any such process will be subject to a duty of confidentiality.


8.7 As no security measures are guaranteed We have put in place procedures to deal with any suspected Personal Data breach and will notify you and any applicable regulator of a breach where We are legally required to do so.

9.1 Under UK GDPR, you have the following rights in relation to your personal data:

Right What it means
Informed You have the right to be informed about our collection and use of your Personal Data. This Privacy Notice should tell you everything you need to know, but if you have any questions or concerns about this Privacy Notice, please contact us via the contact details below (9.4). 
Access 
You can request a copy of the personal Data we hold about you (Subject Access Request). 
Rectification 
You have the right to ask Us to rectify Personal Data you think is inaccurate. You also have the right to ask Us to complete information you think is incomplete. 
Erasure You have the right to ask Us to erase your Personal Data in certain circumstances. 
Restriction You have the right to ask Us to restrict the processing of your Personal Data in certain circumstances. 
Portability You have the right to ask that We transfer the Personal Data you gave Us to another organisation, or to you, in certain circumstances. 
Objection You have the right to object to the processing of your Personal Data in certain circumstances. 
Withdraw Consent Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal. 
Automated Decisions You have the right not to be subject to solely automated decisions that have a significant effect on you. 

9.2 You are permitted to make a data protection request also known as a subject access request (SAR) for personal information held, in accordance with the Data Protection Act 2018. You are not required to pay any charge for exercising your rights.


9.3 However, if your request is ‘manifestly unfounded or excessive’ (for example, if you make repetitive requests) a fee may be charged to cover our administrative costs in responding.


9.4 To make a data protection request please ensure the request is made in writing, specifying the information sought, whether you would like the information in electronic or hard copy, and providing proof of identity, to Our Data Protection Officer who can be contacted via email: privacy@tsosgroup.com.

If you are not satisfied with how we handle your data, you have the right to complain to the Information Commissioner's Office (ICO)


The ICO’s Address: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF


The ICO’s Helpline number:0303 123 1113


The ICO’s Website: www.ico.org.uk