1. Who are we?

1.1 We are The Hans de Kretser Associates Ltd (trading as HdK). 1.2 You can contact us at hello@wearehdk.com. Other contact details are available on our website.

2. What is the purpose of this policy?

2.1 This policy explains how we collect and handle your personal information. By using our services, you acknowledge the practices described in this policy.

2.2 This policy covers only information provided to us. If you provide data to third parties (such as payment providers), please review their respective privacy policies.

3. Changes to this policy

3.1 We may update this policy from time to time. The “Last Updated” date at the bottom will indicate when changes were made. Continued use of the site after changes constitutes acceptance of the new terms.

4. Data Collection

4.1 Voluntary Information: We collect information you provide directly, such as your name, contact details, gender, age group, and any photos or contributions you submit.

4.2 Automated Information: We collect data via cookies and similar technologies, including your IP address, browser type, device identifier, operating system, and “clickstream” data (the path you take through our site).

5. Legal Basis for Processing

5.1 We process your data based on:

  • Contractual Necessity: To provide the goods or services you requested.
  • Legitimate Interests: To manage and improve our service and website security.
  • Consent: For activities like email marketing or non-essential cookies.

6. Cookies & Tracking Technologies

6.1 What are cookies? Cookies are small text files placed on your device. They help the website function and provide us with analytical information.

6.2 Managing Cookies: You can manage your preferences at any time via the cookie consent banner on our website (managed by CookieYes).

6.3 Our Cookie Inventory: We use a mix of “Necessary” cookies (required for the site to work) and “Non-essential” cookies (for analytics and marketing).

7. Use of Information

7.1 We use your data to provide our services, send service messages, and—where you have opted in—send marketing communications.

7.2 We use anonymized data to track usage patterns and prevent fraud.

8. Data Retention

8.1 We generally retain personal data for up to six years following the closure of an account to handle potential disputes, or as required by law. Marketing data is kept until you unsubscribe.

9. Data Sharing

9.1 We share data with trusted service providers (e.g., web hosts, CDNs). 9.2 We may disclose data to authorities if required by law or to protect our legal rights. 9.3 In the event of a business sale or merger, data may be transferred to the new owner.

10. International Data Transfers

10.1 While we store data primarily in the UK, some third-party providers (like Google or Meta) may process data in the US.

10.2 Such transfers are protected by standard contractual clauses or the UK Extension to the EU-US Data Privacy Framework, ensuring your data receives an equivalent level of protection.

11. Your Rights

11.1 Under UK GDPR, you have the right to:

  • Access the data we hold about you.
  • Rectify inaccuracies or request deletion.
  • Object to or restrict processing.
  • Request “data portability.”

11.2 If you have concerns, please contact us at the email above. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at www.ico.org.uk.

12. Security & reCAPTCHA

12.1 Our contact forms are protected by Google reCAPTCHA. Use of this feature is subject to the Google Privacy Policy and Terms of Service.