Privacy Notice
Last updated: 8 August 2026
1.Purpose of this notice
This Privacy Notice explains how ROSE collects, uses, stores and protects personal information when you use our Website, contact us, submit an enquiry, book a call, request a service or otherwise interact with us.
The data controller for the purposes of UK data-protection law is:
2.Personal information we may collect
Depending on how you interact with ROSE, we may collect:
- —Name
- —Job title
- —Business or organisation name
- —Work email address
- —Telephone number
- —Website address
- —Number of business entities
- —Information provided in enquiry forms, booking forms, emails or calls
- —Information about your business challenge, requirements, systems, projects or proposed engagement
- —Communication preferences
- —Technical information necessary for Website security and operation, where applicable
Please do not submit sensitive personal data, confidential third-party information, financial-account information, passwords, special-category personal data or commercially sensitive documents through the Website enquiry form unless we have specifically asked for it and agreed an appropriate secure method.
3.How we use your information
We may use personal information to:
- —Respond to enquiries and communicate with you
- —Arrange and manage Discovery calls, Consultations, Brainstorming sessions and project discussions
- —Assess whether ROSE’s services are suitable for your needs
- —Prepare proposals, scopes of work, contracts and project documentation
- —Deliver agreed services
- —Maintain business records and manage our operations
- —Protect the Website, prevent misuse and maintain security
- —Meet legal, regulatory, accounting or record-keeping obligations
- —Send marketing communications only where permitted by law and where you have consented or another lawful basis applies
4.Lawful bases for processing
We process personal information only where we have a lawful basis. Depending on the situation, this may include:
- Legitimate interests: responding to business enquiries, operating and improving our services, managing professional relationships, protecting our business and Website, and keeping appropriate records.
- Contract: taking steps at your request before entering into a contract, or performing a contract with you.
- Legal obligation: meeting legal, tax, accounting, regulatory or record-keeping requirements.
- Consent: where we ask for your clear consent, for example for optional marketing communications or non-essential cookies.
You can withdraw consent at any time by contacting privacy@rosegovernance.co.uk. Withdrawal will not affect the lawfulness of processing before consent was withdrawn.
5.Who we may share information with
We may share personal information only where necessary and appropriate with:
- —Service providers that support our business operations, such as email, cloud-storage, document-management, booking, accounting, website-hosting, CRM or communications providers
- —Professional advisers, such as accountants, insurers, legal advisers or data-protection advisers
- —Approved subcontractors or specialist consultants engaged for a client project, where this is necessary and subject to appropriate confidentiality and data-protection controls
- —Regulators, authorities or other parties where required by law or necessary to protect legal rights
We do not sell personal information.
ROSE uses Resend (resend.com) as its email service provider to deliver enquiry notifications, confirmation replies and any marketing updates you have opted into. You can withdraw marketing consent at any time using the unsubscribe link in any marketing email, or by contacting privacy@rosegovernance.co.uk.
6.AI-assisted tools
ROSE may use AI-assisted tools for research, drafting, analysis and operational support. Final governance, systems and operational decisions remain human-led.
ROSE will not intentionally enter sensitive client personal data or confidential client information into external AI tools without appropriate controls, a lawful basis and, where required, client approval.
Where AI-assisted tools are used in a client engagement, the approach to confidentiality, data handling, human review and any relevant third-party processing will be addressed in the applicable project documentation.
7.International transfers
Some service providers may process information outside the UK. Where this happens, ROSE will take appropriate steps to ensure that personal information receives an appropriate level of protection, such as using recognised transfer safeguards where required (for example, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or transfers to countries covered by UK adequacy regulations).
The specific providers and safeguards depend on the tools curated for each engagement, and the relevant arrangements are confirmed as part of the applicable client documentation.
8.How long we keep information
ROSE keeps personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, insurance, dispute-resolution and record-keeping requirements.
Indicative retention periods:
- —Enquiries that do not become clients: 12–24 months
- —Client contracts, proposals and core project records: 6 years after the engagement ends (the standard limitation period for contractual claims in England & Wales)
- —Financial and tax records: 6 years from the end of the relevant financial year, in line with HMRC requirements
- —Marketing-consent records: until consent is withdrawn or the information is no longer needed
- —Website-security records: up to 12 months
These periods may be changed where necessary for legal claims, regulatory obligations or legitimate business needs.
9.Security
ROSE uses reasonable organisational and technical measures to protect personal information from unauthorised access, loss, misuse, alteration or disclosure.
No system is completely secure. If you believe information has been sent to us in error or you have a concern about security, contact privacy@rosegovernance.co.uk promptly.
10.Your rights
Under UK data-protection law, you may have rights to:
- —Request access to your personal information
- —Request correction of inaccurate or incomplete information
- —Request deletion of information in certain circumstances
- —Object to certain processing based on legitimate interests
- —Request restriction of processing in certain circumstances
- —Request portability of certain information
- —Withdraw consent where processing is based on consent
- —Complain to the Information Commissioner’s Office
To exercise your rights, contact privacy@rosegovernance.co.uk.
You also have the right to complain to the Information Commissioner’s Office:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
Website: https://ico.org.uk/make-a-complaint
11.Changes to this notice
ROSE may update this Privacy Notice from time to time. The current version will be published on this Website with the revised “Last updated” date.
12.Contact
For privacy questions, data-rights requests or concerns about how ROSE handles personal information, contact:
