+44 75 999 88 090 nb@business-mantra.co.uk

Privacy Policy

Last updated: 29 January 2026

Business Mantra Limited (“we”, “us”, “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect personal data when you interact with our website, communicate with us, or engage with us as a client, supplier, or enterprise customer.

We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other applicable data protection laws.


1. Your privacy matters

Your privacy is important to us. This policy explains what personal data we collect, why we collect it, how it is used, how it is protected, and the rights you have in relation to your personal data.


2. What personal data do we collect?

We may collect and process the following types of personal data:

  • Name, email address, telephone number, job title, and organisation details

  • Contact details provided via enquiry forms, email, or direct communication

  • Website usage data (such as IP address, browser type, pages visited)

  • Any personal data you voluntarily provide when engaging with our services

We only collect personal data that is necessary for legitimate business purposes.


3. How we use your personal data

We use personal data for the following purposes:

  • To respond to enquiries and provide requested information

  • To deliver services and manage client relationships

  • To administer contracts, invoicing, and payments

  • To improve our website and services

  • To comply with legal and regulatory obligations


4. Lawful basis for processing

We process personal data under one or more of the following lawful bases:

  • Contractual necessity – where processing is required to deliver services

  • Legitimate interests – to operate and improve our business, provided these interests are not overridden by your rights

  • Legal obligation – where required to comply with applicable laws

  • Consent – where you have explicitly provided consent (for example, marketing communications)


5. Client and Enterprise Data (B2B / Contractor Engagements)

Where Business Mantra Limited provides services as a contractor, consultant, or supplier to enterprise clients, we process personal data solely on the documented instructions of the client and in accordance with applicable contractual obligations and data protection laws.

In these circumstances:

  • We act as a Data Processor, and the client acts as the Data Controller

  • Personal data is accessed only within client-approved systems and environments

  • Where clients provide managed devices, accounts, virtual desktops, or secure environments, all work is performed exclusively on those client-supplied or client-approved systems

  • No client personal data is stored on local devices, personal equipment, or unmanaged systems

  • Client data is not reused, sold, or processed for our own independent purposes

  • Client data is not shared with third parties unless explicitly authorised by the client or required by law

For enterprise engagements, data protection obligations are governed by the applicable contract and any associated Data Processing Addendum (DPA).


6. Who we share personal data with

We may share personal data only where necessary and appropriate, including with:

  • Professional advisers (such as accountants or legal advisers)

  • IT, hosting, and infrastructure service providers

  • Payment and invoicing service providers

  • Regulatory authorities where legally required

We do not sell personal data to third parties.


7. International data transfers

Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place, such as adequacy decisions or approved contractual protections.


8. Data retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, or reporting requirements. When data is no longer required, it is securely deleted or anonymised.


9. How we keep your information safe

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, or disclosure. These measures include access controls, least-privilege principles, secure authentication, and regular review of data handling practices.

For enterprise client engagements, access controls, authentication, device security, monitoring, and logging are governed by client-managed systems and security policies. Where clients provide managed devices or secure environments, all work is performed exclusively within those environments, and no client data is downloaded, copied, or retained locally.


10. Cookies and website analytics

Our website uses cookies to improve functionality and user experience.

Cookies may be used to:

  • Enable core website functionality

  • Understand how visitors use our website (for example, analytics)

You can control or disable cookies through your browser settings.


11. Marketing communications

We may contact you with information about our services where permitted by law. You can opt out of marketing communications at any time by contacting us or using the unsubscribe option provided.


12. Your data protection rights

You have the right to:

  • Access your personal data

  • Request correction of inaccurate data

  • Request erasure of your data

  • Object to or restrict processing

  • Request data portability

  • Withdraw consent where applicable

To exercise your rights, please contact us using the details below.


13. Your right to lodge a complaint with the Information Commissioner’s Office (ICO)

If you have concerns about how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection matters.

Information Commissioner’s Office
Wycliffe House, Water Lane
Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
Website: https://www.ico.org.uk


14. Contact us

If you have any questions about this Privacy Policy or how we handle your personal data, please contact:

Business Mantra Limited
Email: nb @ business – mantra . co . uk


15. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page and, where appropriate, notified to you directly.


16. Information Security Statement

Business Mantra Limited follows security-by-design principles appropriate to the size and nature of the organisation. In particular:

  • Client and enterprise data is accessed only where required to deliver contracted services

  • No client personal data is stored on personal devices, removable media, or unmanaged systems

  • Work for enterprise clients is performed on client-supplied or client-approved systems only, where provided

  • Credentials and access are protected using client-mandated authentication and security controls

  • Access to client systems and data is removed promptly at the end of an engagement

This statement is provided for transparency and to support client supplier assurance and risk assessments.