Privacy and cookie policy
Last updated: 3 October 2026
About this policy
This policy explains how Taylor Baines Ltd collects, uses, shares, and protects personal data when you visit this website, contact us, or work with us as a client, partner, or supplier. It also explains your rights and how to exercise them, and the cookies and similar technologies this website uses.
We are the controller of the personal data described in this policy. We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR), as amended by the Data (Use and Access) Act 2025. Where the EU GDPR applies to our work for clients in the European Union, we comply with that too.
We may update this policy from time to time. The date at the top shows when it was last changed, and we will tell you directly about any significant change that affects you.
Who we are and how to contact us
Taylor Baines Ltd is an independent consultancy providing consulting and auditing in information & cyber security, privacy, and AI governance. We are registered in England & Wales with company number 07272922.
| Head office and postal address | Registered office |
|---|---|
| 22 Magenta Close Billericay Essex CM12 0LF United Kingdom | 203 London Road Hadleigh Benfleet Essex SS7 2RD United Kingdom |
For any question about this policy or your personal data, email info@taylorbaines.co.uk, use our contact page, or contact our Data Protection Officer at dpo@taylorbaines.co.uk.
The personal data we collect
- When you contact us: through the forms on this website (name, email address, phone number, organisation, job title, website, and your message), or by email or phone.
- When you book a consultation online: your name, email address, the answers you give to the booking questions, and the date and time you choose.
- When we work together: business contact details and correspondence for client, partner, and supplier contacts, and any personal data we need to see while delivering consulting or audit work for a client, which we handle under our contract with that client.
- When you use this website: technical information such as your IP address, browser and device type, the pages you visit, the site that referred you, and the date and time of your visit.
- When you subscribe to our weekly insights email: your email address, your first name if you give it, the topics and regions you choose, whether you have asked for urgent alerts, and a record of your consent (the date and time, and the IP address you signed up from). We also record whether our emails are delivered and opened, and which links are clicked.
- Billing: the names and business contact details needed to invoice and receive payment.
We do not intentionally collect special category data (such as health, ethnicity, or religious beliefs) or information about criminal convictions, and our website and services are not aimed at children.
How we use your personal data and our lawful bases
| Purpose | Lawful basis |
|---|---|
| Responding to your enquiry, request for a consultation, or consultation booking | Legitimate interests (responding to people who contact us), or steps taken at your request before entering into a contract |
| Delivering our consulting and auditing services, and managing our relationship with clients, partners, and suppliers | Performance of a contract, and legitimate interests where our contract is with your organisation rather than with you |
| Invoicing, accounting, and keeping business records | Performance of a contract and compliance with legal obligations (for example tax law) |
| Keeping business contacts informed about our services and relevant developments | Legitimate interests, and consent where the law requires it. You can opt out at any time. |
| Sending our weekly insights email (and urgent alerts, if requested) to people who have subscribed, tailored to the topics and regions they chose, and measuring how our emails are opened and used | Consent. You can withdraw it at any time using the unsubscribe link in every email, or by contacting us. |
| Running, securing, and improving this website, including preventing spam and abuse and producing visitor statistics | Legitimate interests (a secure, working website and understanding how it is used) |
| Dealing with legal claims, and requests from courts, regulators, or law enforcement | Compliance with legal obligations and legitimate interests |
Where we rely on legitimate interests, we have balanced our interests against your rights and freedoms. You can ask us for more information about this assessment. We do not make decisions about you based solely on automated processing.
Who we share your personal data with
We do not sell your personal data or share it with other organisations for their own marketing. We share it only with service providers who process it on our behalf and under contract, and only where necessary:
- IONOS: website hosting.
- Automattic (Jetpack and Akismet): website statistics, security, performance, and spam protection.
- Optimole: optimising and delivering the images on this website through its content delivery network, which receives your IP address so that it can send images to your browser.
- Providers of our business systems: such as email, file storage, and accounting software.
- Professional advisers: such as our accountants, insurers, and lawyers, where needed.
- Brevo (Sendinblue SAS): managing our subscriber list and sending our weekly insights email and urgent alerts.
- SavvyCal: our online booking calendar. If you book a consultation, SavvyCal receives the details you enter and the time you choose, and adds the meeting to our calendar. The calendar on our consultation page is loaded from SavvyCal, which receives your IP address and device information when it loads.
- Google (reCAPTCHA): protecting our subscription, contact, and consultation request forms from spam and automated abuse. reCAPTCHA collects information about your device and how you use the page, and Google processes it under its own privacy policy.
We may also disclose personal data where the law requires it, to protect our legal rights, or to a buyer or investor if our business, or part of it, is sold or restructured.
International transfers
Some of our service providers, including Automattic and SavvyCal, are based in or process data in the United States or other countries outside the UK. Where personal data is transferred outside the UK, we make sure it is protected by UK adequacy regulations (including the UK Extension to the EU–US Data Privacy Framework, where the recipient is certified), or by the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. Brevo is based in France and stores our subscriber data in the European Union, which the UK recognises as providing adequate protection. Google may process reCAPTCHA data in the United States, under the UK Extension to the EU–US Data Privacy Framework.
How long we keep your personal data
We keep personal data only for as long as we need it for the purposes above, including meeting legal, accounting, and reporting requirements. For example, we keep basic client records and accounting information for six years after the end of the relevant financial year, as required for tax purposes. Visitor statistics logs held by Jetpack are kept for 28 days. When personal data is no longer needed, we delete or anonymise it.
If you subscribe to our weekly insights email or urgent alerts, we keep your details until you unsubscribe. After that we keep only your email address on a suppression list, so that we do not email you again, and a record of your consent and when you withdrew it for two years, in case we need to show that we had your consent.
How we protect your personal data
As information security professionals, we apply the same standards to our own business that we recommend to our clients. We use appropriate technical and organisational measures to protect personal data against loss and unauthorised access, use, alteration, or disclosure, and we limit access to people with a business need to know who are bound by confidentiality. We have procedures for dealing with any suspected personal data breach, and we will notify you and the regulator where the law requires us to.
Your rights
You have the right to:
- access the personal data we hold about you (a subject access request);
- ask us to correct inaccurate or incomplete data;
- ask us to erase your data, where there is no good reason for us to keep it;
- object to processing based on legitimate interests, and to direct marketing at any time;
- ask us to restrict how we use your data in certain circumstances;
- ask us to transfer data you gave us to you or another organisation (data portability); and
- withdraw consent at any time, where we rely on consent.
To exercise any of these rights, contact us using the details above. We may need to confirm your identity first. We will respond within one month, or tell you if we need longer because a request is complex. There is normally no fee.
Complaints
If you are unhappy with how we have handled your personal data, please tell us first so that we can put things right. We will acknowledge your complaint within 30 days, look into it without undue delay, and tell you the outcome.
You also have the right to complain to the UK regulator for data protection, the Information Commission (known as the ICO), which replaced the Information Commissioner’s Office on 30 September 2026: ico.org.uk.
Cookies and similar technologies
Cookies are small text files placed on your device by a website. Similar technologies, such as your browser’s local and session storage, work in a comparable way.
This website does not use advertising or marketing cookies, and we do not use Google Analytics. We use only the following:
| Name or type | Purpose | How long |
|---|---|---|
| Browser session storage (set by this website) | Remembers your place in the News & insights list, so that the “Back to where you were” button can return you to it after you read a post | Until you close the browser tab |
| Browser local storage (set by this website) | Remembers the vendors, sectors, regions, and threat types you choose under “My profile” on our threat intelligence pages, and whether you have turned on “My profile only”, so that the threat log, threat statistics, and threat report can show what is most relevant to you. This is stored in your own browser only and is never sent to us. Use “Clear my profile” to remove it. | Until you use “Clear my profile” or clear your browser’s stored data |
| WordPress cookies (wordpress_*, wp-settings-*) | Strictly necessary for signing in to the website’s administration area. They are only set for our own staff who sign in. | Session, or up to one year |
| jpp_math_pass (Jetpack) | Security check on the administration sign-in page | 1 day |
| _GRECAPTCHA (Google reCAPTCHA) | Spam and abuse protection on our subscription, contact, and consultation request forms. On the subscription form, reCAPTCHA loads, and this cookie is set, only when you start filling in the form. On the contact and consultation request pages, it loads when the page opens. | 6 months |
| SavvyCal booking calendar | Runs the booking calendar on our consultation page. The calendar loads from SavvyCal, and SavvyCal may set its own cookies, only when you choose “Show available times”. | Set by SavvyCal; see its privacy policy |
We measure visits using Jetpack Stats, which records information such as your IP address, browser, the page visited, and the referring page, so that we can see how the website is used. It is run by Automattic, and the logs are kept for 28 days.
Our weekly insights and urgent alert emails contain a small tracking image and tracked links, which show us whether an email was opened and which links were clicked. We use this only to understand which content is useful. You can stop it by turning off images in your email program. We ask for your consent to this when you subscribe.
You can set your browser to block or delete cookies and stored data. This will not stop you using the public pages of this website.