Last Updated: Version 2.0: June 2026
TSOS Group Limited referred to herein as (“the Company”, “We”, “Us” or “Our”) is committed to protecting your privacy. This notice explains what Personal Data we collect when you visit our website tsosgroup.com, how we use it, the legal basis for doing so, how long we keep it and what your rights are.
We are the data controller for the personal data collected through this website. Our registered details are:
Organisation Name: TSOS Group Limited
Registered Address: 20 - 22 Wenlock Road, London, N1 7GU
Trading Address: TSOS Unity Hub, Town Hall Evreux Way, Rugby, CV21 2RR
Company Registration Number: 10930782
ICO Registration Number: ZA726097
Email: privacy@tsosgroup.com
This Privacy Notice applies to Personal Data that is collected via this Website and the forms available on it. Please read it carefully and ensure that you understand it. If you do not agree with and accept this Privacy Notice, do not access or use the Website or any other aspect of Our business.
Our website is not intended for children, and we do not knowingly collect any data relating to minors.
In this Privacy Notice the following terms shall have the following meanings:
| Term | Definition |
| Account | A registered profile or account created by a User to access restricted areas, services, bookings, purchases or resources on the Website. |
| Aggregated Data | Statistical or demographic data that does not directly or indirectly identify an individual. |
| Automated Decision Making (ADM) | A decision made solely by automated means, without any meaningful human involvement, that produces a legal or similarly significant effect on an individual. Subject to specific restrictions and transparency duties under UK GDPR Article 22. |
| Company / We / Us / Our | The organisation operating the Website and providing the Services, acting as the Data Controller unless otherwise stated. |
| Consent | A lawful basis for processing personal data under UK GDPR and EU GDPR. Must be freely given, specific, informed and unambiguous. Requires a clear affirmative action. Pre-ticked boxes or silence do not constitute valid consent. |
| Content | Any text, graphics, images, photographs, audio, video, software, code, databases, documents, data compilations, downloadable materials, or other information capable of being stored electronically that appears on, forms part of, or is made available through a website, platform, application or service. |
| Controller (Data Controller) | The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing personal data. Where an organisation collects and uses personal data for its own purposes, it will generally act as the Controller unless otherwise stated. |
| Cookies | A small file placed on a user's device when they visit a website. Under PECR, cookies (and similar technologies) that are not strictly necessary require the user's prior informed consent before being set. |
| Cookie Policy | The separate policy explaining what cookies and similar technologies are used on the Website, why they are used, and how Users can manage preferences. |
| CRM System | A Customer Relationship Management system used to manage enquiries, customer records, bookings, communications and related business interactions. |
| Data Protection Law | All applicable laws and regulations governing privacy, electronic communications and Personal Data, including the UK GDPR, DPA 2018, DUAA 2025, PECR, EU GDPR where applicable, and related guidance. |
| Data Protection Officer / DPO | A designated individual responsible for overseeing data protection compliance within an organisation. Mandatory under UK GDPR Article 37 for public authorities, organisations with large-scale systematic monitoring, or large-scale special category processing. |
| Data Subject | A living identified or identifiable individual about whom we hold Personal Data. Data Subjects may be nationals or residents of any country and have legal rights regarding their Personal Data. |
| EEA | The European Economic Area. |
| ICO | The UK's independent data protection and freedom of information regulator. Responsible for enforcing UK GDPR, DPA 2018, PECR and FOIA. |
| Information Systems | The collective term for all devices, hardware, software, networks, infrastructure, applications and communications technologies used to access, process, store, transmit or manage the organisation's information, IT resources and communication systems. This may include, but is not limited to, desktop computers, servers, smartphones, mobile or cellular phones, tablets, laptop or notebook computers, removable media, cloud services, email platforms, messaging systems, telecommunications equipment, and network-connected devices. |
| International Data Transfer | The transfer of Personal Data to a country or organisation outside the UK (for UK GDPR) or outside the EEA (for EU GDPR). Requires an appropriate transfer mechanism such as an adequacy decision, standard contractual clauses or binding corporate rules. |
| Lawful Basis | The legal ground that justifies processing Personal Data under UK GDPR Article 6. There are six lawful bases: consent, contract, legal obligation, vital interests, public task and legitimate interests. Controllers must identify and document a lawful basis before processing begins. |
| Legitimate Interests | A lawful basis for processing personal data under UK GDPR Article 6(1)(f). The controller's (or a third party's) legitimate interests must be balanced against the individual's interests, rights and freedoms. Requires a Legitimate Interests Assessment (LIA). |
| Marketing Communications | Emails, newsletters, service updates, offers or other promotional communications sent to Users. |
| Personal Data | Any information relating to an identified or identifiable living individual. Includes names, email addresses, IP addresses, location data, cookies, and any other data that can directly or indirectly identify a person. |
| Processing | Any operation performed on Personal Data, including collection, recording, storage, use, disclosure, transfer, deletion or destruction. |
| Processor / Data Processor | An organisation or individual that processes personal data on behalf of and under the instructions of a controller. Processors have direct obligations under UK GDPR including security, sub-processor controls and breach notification to the controller. |
| Recipient | A person, organisation or authority to whom Personal Data is disclosed. |
| Retention Period | The defined period for which personal data is kept before being securely deleted or anonymised. Must be no longer than necessary for the original purpose. Controllers must document retention periods and implement automatic deletion or review processes. |
| Services | Any products, services, training, consultancy, software, digital platforms, memberships, subscriptions, support, resources or other offerings provided by the organisation to customers, members, users or other stakeholders, whether delivered online, remotely or in person. |
| Soft Opt-In | The limited PECR rule that may allow marketing to existing customers about similar goods or services where they were given a clear chance to opt out. |
| Special Category Data | A defined set of particularly sensitive personal data categories requiring additional protection under UK GDPR Article 9. Includes data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for identification, health data, sex life or sexual orientation. |
| Technical and Usage Data | Information about how a User accesses and uses the Website, such as IP address, browser type, pages visited, referral source, device type and operating system. |
| Third Party Provider | The UK addendum to the EU Standard Contractual Clauses used for certain international transfers of Personal Data. |
| UK Addendum | The UK addendum to the EU Standard Contractual Clauses used for certain international transfers of Personal Data. |
| Website | The website operated by the Company, including associated webpages, online forms, booking pages, portals, applications and digital resources. |
3.1 We may, from time to time, modify this Privacy Notice. Please check this Website periodically for updates. We will comply with applicable legal obligations to provide you with relevant notice of changes to this Privacy Notice. Your continued use of our Website after any such update constitutes your acceptance of such changes.
4.1 Personal data provided by Users will, where it is relevant to any division, be transferred along with that division. The new owner or newly controlling party will, under the terms of this Privacy Notice, be permitted to use the Personal Data for the purposes for which it was supplied to Us.
4.2 In the event of 4.1 (above), written notice will be delivered to the email address associated with the Users account. Following this, you may opt for your Personal Data to be transferred to the new owner or withheld.
5.1 You may access certain areas of this website without providing any Personal Data at all. Our website uses cookies. Some are strictly necessary for the site to function. Others, including analytics and marketing cookies, require your consent before they are placed on your device. You can manage your cookie preferences at any time using the cookie banner or preference centre on our website. For more information, please visit our Cookie Policy.
5.2 We may collect, use, store and transfer different kinds of personal and non-personal data about you which We have grouped together as follows:
5.2.1 Aggregated Data
Statistical or demographic data for any purpose. Aggregated data could be derived from Personal Data but is not considered Personal Data in law as this data will not directly or indirectly reveal the identity of a Data Subject. For example, We may aggregate usage data to calculate the percentage of Users accessing a specific Website feature. However, if We combine or connect aggregated data with Personal Data so that it can directly or indirectly identify an individual, We treat the combined data as Personal Data which will be used in accordance with our Privacy Notice.
5.2.2 Enquiry and Contact Forms
Name
Email address
Job title (if provided)
Telephone number (if provided)
Organisation name (if provided)
The content of your message or enquiry
5.2.2 Account Registration (if applicable)
Name and email address
Username and password (stored in encrypted form)
Organisation and role (if requested)
5.2.3 Booking and Purchasing
Name, email and contact details
Billing address and payment information (processed by a third-party payment provider.
Where applicable, data Including card or bank information for transfers and direct debits are collected by Our payment providers Stripe (Privacy Policy) and GoCardless (Privacy Centre - Payers | GoCardless). You can access their Privacy Policy by clicking the link next to the payment provider's name. We do not process or store card or bank details.
Details of the service or product purchased
5.2.4 Technical and Usage Data
IP address
Browser type and version
Pages visited and time spent on pages
Referral source (how you found our website)
Device type and operating system
Technical data may be collected through cookies and similar technologies. Please see our Cookie Policy for further information.
We do not collect any Special Categories of Personal Data about you on this Website (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data). Nor do We collect any information about criminal convictions and offences.
6.1 We use the personal data we collect for the following purposes:
| Purpose | Lawful Basis |
| Responding to your enquiries and providing the information or service you requested | Contract (Article 6(1)(b)) or Legitimate Interests (Article 6(1)(f)) |
| Processing bookings, orders and payments | Contract (Article 6(1)(b)) |
| Sending you information about our services where you have requested this or where the soft opt-in applies | Consent (Article 6(1)(a)) or Legitimate Interests (Article 6(1)(f)) |
| Improving our website and understanding how visitors use it | Legitimate Interests (Article 6(1)(f)) |
| Complying with legal obligations such as financial record-keeping | Legal Obligation (Article 6(1)(c)) |
| Preventing fraud and ensuring the security of our website | Legitimate Interests (Article 6(1)(f)) |
| Providing you with information via emails and newsletters that you have opted into. You can withdraw your consent at any time. You can do this by clicking unsubscribe at the footer of the email. | Consent (Article 6(1)(a)) |
7.1 Where required we may share this information as follows with:
Email and CRM platform providers: used to manage communications.
Professional Advisers: Accountants, consultants, auditors, lawyers and other outside professional advisors to us, subject to binding professional and/or contractual obligations of confidentiality. Third Party Service Providers: With third party service providers who support Our business, who will process it on behalf of us for the purposes identified above. Such third parties may include providers of hosting services.
Regulatory authorities or law enforcement:where we are legally required to disclose information.
Business or Share Sales: With any relevant third-party acquirer(s), in the event that We sell or transfer all or any relevant portion of our shares, business or assets (including in the event of a re organisation, dissolution or liquidation).
Third Party Providers of Advertising, Plugins and Content: The Website may use third party advertising, plugins or content. If you choose to interact with any such advertising, plugins or content, your Personal Data may be shared with the relevant third-party provider. We recommend that you review that third-party’s Privacy Notice before interacting with such content.
7.2 If any of your Personal Data is required by a third party, as described above, We will take steps to ensure that your Personal Data is handled safely, securely, and in accordance with your rights, Our obligations, and the third party’s obligations under Data Protection Legislation.
7.3 If any Personal Data is transferred outside of the EEA or UK, We will take suitable steps in order to ensure that your Personal Data is treated just as safely and securely as it would be within the EU/UK and under the GDPR, as explained above.
7.4 You can request details of the safeguards we rely on by contacting us using the details in Section 9.4.
8.1 We will not keep your Personal Data for any longer than is necessary for the reason(s) for which it was first collected. Your Personal Data will therefore be kept for the following periods (or, where there is no fixed period, the following factors will be used to determine how long it is kept):
Personal Data you provide on this Website or any forms contained within it, is securely stored in Our Customer Relationship Management (CRM) system.
| Type of Data | Retention Period |
| Enquiry and contact form submissions | 2 years from the date of last contact, unless a contract follows |
| Customer and transaction records | 7 years from the end of the financial year in which the transaction occurred (HMRC requirement) |
| Account information | For the duration of your account plus 2 years after closure |
| Website analytics and usage data | 13 months (in line with ICO guidance on analytics cookies) |
| Email marketing preferences | For as long as you remain subscribed (have positively opted-in) to Our emailing list and wish to receive news and offers from Us |
If none of the above applies, then we will keep your data for a maximum period of five years following your initial communication or signup/Personal Data submission.
8.2 We take every reasonable step to ensure that your personal data are only processed for the minimum period necessary for the purposes set out in this Privacy Notice.
8.3 We will retain Personal Data in a form that permits identification only for as long as:
(a) we maintain an ongoing relationship with you (for example, for as long as you are using Our products and/or services); or
(b) retention of your Personal Data is necessary in connection with the lawful purposes set out in this Privacy Notice, for which we have a valid legal basis.
8.4 We will retain the Personal Data for the duration of:
(a) any applicable limitation period under law (i.e., any period during which a person could bring a legal claim against us in connection with your Personal Data or to which your Personal Data is relevant), plus an additional two-month period following the end of such limitation period; and
(b) if any relevant legal claims are brought, We will continue to process Personal Data for such an additional period as is necessary in connection with that claim.
8.5 Once the periods at 8.4 and 8.5 above have passed, We will either permanently delete or destroy the relevant Personal Data; or anonymise the relevant Personal Data.
8.6 We do Our best to keep your data secure and have put in place appropriate security measures to prevent your Personal Data from being accidentally lost, used, or accessed in an unauthorised way, altered, or disclosed. In addition, We limit access to your Personal Data to those employees, contractors and other third parties who have a business need to know. Any such process will be subject to a duty of confidentiality.
8.7 As no security measures are guaranteed We have put in place procedures to deal with any suspected Personal Data breach and will notify you and any applicable regulator of a breach where We are legally required to do so.
9.1 Under UK GDPR, you have the following rights in relation to your personal data:
| Right | What it means |
| Informed | You have the right to be informed about our collection and use of your Personal Data. This Privacy Notice should tell you everything you need to know, but if you have any questions or concerns about this Privacy Notice, please contact us via the contact details below (9.4). |
| Access | You can request a copy of the personal Data we hold about you (Subject Access Request). |
| Rectification | You have the right to ask Us to rectify Personal Data you think is inaccurate. You also have the right to ask Us to complete information you think is incomplete. |
| Erasure | You have the right to ask Us to erase your Personal Data in certain circumstances. |
| Restriction | You have the right to ask Us to restrict the processing of your Personal Data in certain circumstances. |
| Portability | You have the right to ask that We transfer the Personal Data you gave Us to another organisation, or to you, in certain circumstances. |
| Objection | You have the right to object to the processing of your Personal Data in certain circumstances. |
| Withdraw Consent | Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal. |
| Automated Decisions | You have the right not to be subject to solely automated decisions that have a significant effect on you. |
9.2 You are permitted to make a data protection request also known as a subject access request (SAR) for personal information held, in accordance with the Data Protection Act 2018. You are not required to pay any charge for exercising your rights.
9.3 However, if your request is ‘manifestly unfounded or excessive’ (for example, if you make repetitive requests) a fee may be charged to cover our administrative costs in responding.
9.4 To make a data protection request please ensure the request is made in writing, specifying the information sought, whether you would like the information in electronic or hard copy, and providing proof of identity, to Our Data Protection Officer who can be contacted via email: privacy@tsosgroup.com.
If you are not satisfied with how we handle your data, you have the right to complain to the Information Commissioner's Office (ICO)
The ICO’s Address: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
The ICO’s Helpline number:0303 123 1113
The ICO’s Website: www.ico.org.uk