Privacy Policy for Northstar Brand Strategy Ltd
Effective date: 8 July 2026
1. Introduction and company information
This Privacy Policy explains how Northstar Brand Strategy Ltd collects, uses, stores, shares, and protects personal data when you visit our website, contact us, use our services, or otherwise interact with us. We are committed to handling personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR), and other applicable UK data protection laws.
Data controller: Northstar Brand Strategy Ltd
Registered / business address: Northstar Brand Strategy Ltd, 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, UK
Email: [email protected]
Phone: +44 20 7946 3821
As a brand-strategy business, we may process personal data relating to clients, prospective clients, suppliers, website users, and other individuals who communicate with us or receive our services.
2. Data collection and processing
We may collect and process the following categories of personal data:
- Identity data: name, job title, company name, and professional role.
- Contact data: email address, telephone number, postal address, and other contact details.
- Business and project data: information you provide about your business, brand, objectives, preferences, market position, competitors, and project requirements.
- Communication data: correspondence with us by email, phone, contact forms, meetings, and other channels.
- Technical data: IP address, browser type, device identifiers, operating system, pages visited, referral source, and website usage data.
- Marketing data: your preferences in receiving marketing from us and your communication preferences.
- Financial and transaction data: billing details, payment records, and invoice information where relevant.
- Special category data: we do not generally seek to collect special category data. If such data is provided to us, we will only process it where permitted by law and where necessary for a lawful purpose.
We collect personal data directly from you, from your organisation, from publicly available sources, from our website and analytics tools, and from third-party service providers where appropriate and lawful.
3. Purpose of data processing
We process personal data for the following purposes:
- to respond to enquiries and communicate with you;
- to provide brand-strategy services, including discovery, research, workshops, strategy development, and delivery of project outputs;
- to manage client relationships, contracts, invoicing, and payments;
- to administer and improve our website, systems, and internal operations;
- to analyse website performance and user engagement;
- to send service-related updates and, where permitted, marketing communications;
- to maintain records and comply with legal, tax, accounting, and regulatory obligations;
- to establish, exercise, or defend legal claims;
- to protect our business, staff, clients, and users from fraud, misuse, or security threats.
4. Legal basis for processing
We will only process personal data where we have a lawful basis under UK data protection law. Depending on the context, our legal bases may include:
- Consent: where you have given clear consent, for example for certain marketing communications or optional cookies.
- Contract: where processing is necessary to enter into or perform a contract with you.
- Legal obligation: where processing is required to comply with applicable law, including tax and accounting obligations.
- Legitimate interests: where processing is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. This may include business development, service improvement, fraud prevention, and website administration.
- Vital interests: in rare cases where processing is necessary to protect someone’s life.
- Public task: where applicable, although this is unlikely to be relevant to our business.
Where we rely on legitimate interests, we will consider and balance any potential impact on you and your rights before processing your personal data.
5. Data sharing and third parties
We may share personal data with trusted third parties where necessary for the purposes described in this Privacy Policy. These may include:
- IT, hosting, cloud storage, and software providers;
- email and communication service providers;
- analytics and website performance providers;
- payment processors and invoicing platforms;
- professional advisers such as accountants, lawyers, insurers, and auditors;
- subcontractors, consultants, and freelancers assisting with project delivery;
- regulatory bodies, law enforcement, courts, or other authorities where required by law.
We require third parties to process personal data only in accordance with our instructions, applicable law, and appropriate confidentiality and security obligations.
6. Data transfer to third countries
Some of our service providers may process personal data outside the United Kingdom. Where this occurs, we will ensure that appropriate safeguards are in place to protect your data, such as:
- an adequacy regulation or adequacy decision recognised under UK law;
- the UK International Data Transfer Agreement (IDTA);
- the UK Addendum to the EU Standard Contractual Clauses;
- other lawful transfer mechanisms permitted under UK data protection law.
Where required, we will also carry out transfer risk assessments and implement supplementary measures to protect personal data.
7. Storage duration
We retain personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting, reporting, or contractual requirements.
- Client and project records: retained for the duration of the relationship and for a reasonable period afterwards.
- Financial and tax records: retained for the period required by applicable UK law.
- Enquiry and correspondence data: retained for as long as needed to manage the enquiry and any follow-up.
- Marketing data: retained until you opt out or withdraw consent, or we determine it is no longer needed.
- Website analytics data: retained in line with our analytics settings and provider retention periods.
When personal data is no longer required, we will securely delete, anonymise, or archive it in accordance with our retention practices.
8. User rights
Under UK data protection law, you may have the following rights in relation to your personal data:
- Right of access: to request a copy of the personal data we hold about you.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of your personal data in certain circumstances.
- Right to restriction: to request that we limit how we use your personal data in certain circumstances.
- Right to data portability: to receive certain data in a structured, commonly used, machine-readable format and to request transfer to another controller where applicable.
- Right to object: to object to processing based on legitimate interests or to direct marketing at any time.
These rights are subject to legal limitations and exemptions. If you wish to exercise any of these rights, please contact us using the details below.
9. Withdrawal of consent
Where we rely on your consent to process personal data, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of processing carried out before the withdrawal.
You can withdraw consent by contacting us at [email protected] or by using any unsubscribe or preference-management options we provide in our communications.
10. Right to complain
If you have concerns about how we handle your personal data, we encourage you to contact us first so we can try to resolve the issue.
You also have the right to lodge a complaint with the UK supervisory authority, the Information Commissioner’s Office (ICO):
Information Commissioner’s Office (ICO)
Website: https://www.ico.org.uk
We would appreciate the opportunity to address your concerns before you contact the ICO.
11. Data security
We take appropriate technical and organisational measures to protect personal data against accidental loss, unauthorised access, alteration, disclosure, or destruction. These measures may include:
- access controls and role-based permissions;
- password protection and multi-factor authentication where available;
- encryption and secure transmission methods where appropriate;
- regular software updates and security monitoring;
- staff confidentiality obligations and data protection training;
- backup and recovery procedures;
- supplier due diligence and contractual safeguards.
While we take reasonable steps to protect your data, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security.
12. Contact information
If you have any questions about this Privacy Policy or how we process personal data, or if you wish to exercise your rights, please contact:
Northstar Brand Strategy Ltd
71-75 Shelton Street, Covent Garden, London WC2H 9JQ, UK
Email: [email protected]
Phone: +44 20 7946 3821
13. Changes to privacy policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. Any updated version will be posted on our website with a revised effective date.
We encourage you to review this Privacy Policy periodically to stay informed about how Northstar Brand Strategy Ltd protects your personal data.