Privacy Notice
Last Updated: 24/11/25
This Privacy Notice explains how Principle Defence (“we”, “us”, “our”) collects, uses, stores, and shares personal data in accordance with the UK GDPR, EU GDPR, the Privacy and Electronic Communications Regulations (PECR), and the e-Privacy Directive.
1. Who we are
Company Name: Principle Defence Ltd
Registered Address: 65 Knowl Piece, Wilbury Way, Hitchin, SG4 0TY
Phone: 01707 330986
Email: hello@principledefence.com
Web: https://principledefence.com
2. What personal data we collect
We may collect and process the following categories of personal data, depending on how you interact with us.
When you contact us: full name, email address, phone number or other contact details, IP address, the content of your communication.
When we provide services (consulting or training): full name, contact details, email address, role and organisation, financial and billing information, any additional personal or technical information you choose to provide.
Training courses: full name, contact details and email address, organisation and role, financial information, certification or membership details (where applicable).
Use of our website — Comments: data shown in the comments form, IP address, browser user agent string (for spam prevention).
Employment and recruitment: full name, email address and phone number, employment history and CV, references and referee contact details. If successful: next of kin details, date of birth, identity documentation, background check information (where legally required), financial details (e.g. payroll).
3. How we collect your personal data
Social media: when you follow, like, comment on, or interact with our social media content.
Direct interactions: when you email us, complete forms, or provide information directly.
Contracts: when entering into or performing a contract for services or training.
Events and networking: when you engage with us at events, exhibitions, or training sessions.
Public sources: where information is lawfully made public (e.g. professional profiles).
Website interactions: including comments, forms, and technical usage data.
4. Why we collect your personal data
We process personal data for the following purposes: to respond to enquiries and communicate with you; to provide consulting services and training courses; to manage contracts, payments, certifications, and memberships; to administer recruitment and employment processes; to operate, maintain, and improve our website and services; to meet legal and regulatory obligations; to send service-related communications; to send marketing communications in compliance with GDPR and PECR.
Marketing communications are sent only where you have provided consent, or where permitted under PECR (e.g. the “soft opt-in”), with a clear and easy opt-out in every message.
5. Who we share your personal data with
Government bodies and regulators: where required by law (e.g. tax, employment, regulatory reporting).
Service providers and processors: including website and hosting providers (e.g. WordPress), training, certification, and examination bodies, IT, communications, finance, and professional service providers. All processors act under written agreements requiring appropriate security, confidentiality, and GDPR compliance.
Corporate transactions: if we merge, sell, or restructure the business, personal data may be transferred as part of that transaction. Where required, we will notify you.
We do not sell personal data for commercial gain.
6. Lawful bases for processing
We rely on one or more of the following lawful bases: Legitimate interests — where processing is necessary for our legitimate business interests and your rights and freedoms are not overridden; Consent — where you have given clear and informed consent; Contract — where processing is necessary to enter into or perform a contract; Legal obligation — where required by law.
7. Legitimate Interest Assessment (LIA) — Summary
Where we rely on legitimate interests as our lawful basis, we have carried out a Legitimate Interests Assessment (LIA) to ensure compliance with GDPR. Our legitimate interests include: operating and managing our business effectively; delivering and improving our services and training courses; communicating with existing clients and professional contacts; marketing our services to business contacts in a proportionate manner; ensuring network, information, and website security; preventing fraud and misuse of our services.
The processing is necessary to achieve these purposes and cannot reasonably be achieved by less intrusive means. We have considered the impact on individuals and concluded that the processing is expected and proportionate; it does not involve sensitive personal data unless strictly necessary; individuals’ rights and freedoms are not overridden; appropriate safeguards are in place, including opt-out rights and data minimisation. You have the right to object to processing based on legitimate interests at any time.
8. International transfers of personal data
Personal data is primarily processed and stored within the UK and the European Economic Area (EEA). However, in some circumstances, your personal data may be transferred to, or accessed from, countries outside the UK or EEA (for example where we use international service providers or cloud-based systems). Where international transfers occur, we ensure appropriate safeguards are in place, including transfers to countries recognised by the UK or EU as providing an adequate level of protection; use of Standard Contractual Clauses (SCCs) approved by the UK Government or European Commission; and/or additional technical and organisational measures to protect personal data. We ensure that any international transfers comply with Articles 44–49 of the UK GDPR and EU GDPR.
9. How we store and protect your personal data
Personal data is stored electronically on secure systems. Data is encrypted in transit and, where appropriate, at rest. Access is restricted to authorised personnel only.
10. How long we retain your personal data
We retain personal data in line with our Data Retention Schedule, taking into account: legal and regulatory requirements; contractual obligations; business and operational needs. In general: financial and contractual data is retained as required by law; recruitment data is retained only for a limited period; marketing data is retained until consent is withdrawn or you opt out; website data is retained for operational and security purposes.
11. How we destroy personal data
All personal data is held electronically. When no longer required: data is destroyed beyond recovery; data is securely deleted from systems and backups; devices are securely wiped before disposal.
12. Your data protection rights
You have the right to: be informed; access your personal data; rectify inaccurate or incomplete data; request erasure; restrict processing; object to processing (including marketing and legitimate interests); data portability. You will not be subject to automated decision-making, except where legally permitted.
13. How to exercise your rights
You can exercise your rights by contacting us using the details at the top of this notice. Requests may be made via email, phone, or other reasonable means.
14. How we handle rights requests
Response time: within one month (extendable by up to two months for complex requests). Identity verification: may be required. Fees: generally free; a reasonable fee may apply for excessive or unfounded requests.
15. Complaints
If you are unhappy with how we handle your personal data, please contact us first. You also have the right to complain to the Information Commissioner’s Office (ICO): Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Tel: 0303 123 1113. Website: https://www.ico.org.uk
16. Changes to this notice
We may update this Privacy Notice from time to time. The latest version will always be available on our website.