Privacy Policy
Last Updated: 12th August 2026
1. Introduction
Welcome to Credwell Limited ("we," "us," "our"). As a specialist Data Protection Officer (DPO) consultancy advising UK law firms, we are strictly committed to protecting your privacy and demonstrating highest-tier compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This policy explains how we collect, process, and protect your personal data when you visit our website (https://credwell.co.uk) or engage our compliance consultancy and incident response services.
Credwell Limited is the data controller responsible for your personal data.
Company Number: 09833757
Registered Address: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
Contact Email: compliance@credwell.co.uk
2. What Data We Collect About You
We strictly adhere to the principle of data minimisation. We only collect the personal data absolutely necessary to provide our services, grouped as follows:
Identity Data: First name and last name.
Contact Data: Work email address and telephone numbers.
Professional Data: Law firm or company name, job title, SRA regulation status, and the operational compliance gaps submitted via our secure intake forms (such as our 6-Question Breach Readiness Diagnostic).
Financial Data: Billing address and payment details (processed securely by our payment gateways; we do not store full card numbers).
Technical Data: Internet protocol (IP) address, browser type, and underlying security metrics captured by our web infrastructure.
How we collect this data:
Direct interactions: You provide Identity, Contact, and Professional Data by completing secure forms on our website (powered by Fillout) or corresponding with us via Microsoft Teams and email.
Automated technologies: As you interact with our website, our security infrastructure (Cloudflare) and hosting provider collect foundational Technical Data to ensure a secure connection.
3. How We Use Your Personal Data and Our Lawful Basis Under UK data protection law, we only process your data when we have a clear, documented lawful basis:
To Respond to Your Enquiries and Diagnostics:
Lawful Basis: Legitimate Interests (assessing your regulatory risk profile to provide tailored commercial advice).
To Perform a Contract (e.g., Delivering DBIRPs and DPO services):
Lawful Basis: Performance of a Contract with you (or taking steps at your request prior to entering into a contract).
To Process Payments and Manage Invoicing:
Lawful Basis: Performance of a Contract and compliance with our Legal Obligations (tax and accounting rules).
To Administer and Protect Our Website:
Lawful Basis: Legitimate Interests (network security, fraud prevention, and traffic routing).
4. Who We Share Your Data With (Sub-Processors)
We absolutely do not sell your personal data. To deliver enterprise-grade services, we share your data with trusted third-party processors acting strictly on our instructions:
Microsoft Corporation: Provides our end-to-end encrypted email infrastructure, SharePoint environment, and Microsoft Purview for advanced eDiscovery and DSAR fulfillment.
Fillout: Powers our secure diagnostic intake forms and securely transmits your responses.
Cloudflare: Provides edge-network security, DNS routing, and DDoS protection for our web traffic.
Hostinger: Hosts our website architecture.
Xero and Stripe: Facilitate secure invoicing and payment processing.
All third parties are legally bound by strict Data Processing Agreements (DPAs) to respect the security of your personal data and treat it in accordance with the law.
5. International Data Transfers
Some of our external processors are based outside the UK. Whenever we transfer your personal data out of the UK, we ensure a similar degree of protection is afforded by implementing approved safeguards:
We rely on the UK Extension to the EU-U.S. Data Privacy Framework (DPF) for certified US-based vendors.
Where adequacy decisions are not applicable, we enforce the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, supported by Transfer Risk Assessments (TRAs) where required.
6. Data Security As a consultancy led by a qualified Data Protection Officer (CIPP/E), operational security is our core priority. We have implemented appropriate, enterprise-grade technical and organisational measures, including an encrypted Microsoft 365 architecture, strict role-based access controls, and contextual redaction workflows. These measures prevent your personal data from being accidentally lost, altered, or accessed in an unauthorised way.
7. Data Retention We retain your personal data only for as long as reasonably necessary to fulfil the purposes we collected it for.
Prospective Clients: Enquiries and diagnostic submissions that do not convert to a contract are securely purged 24 months after our last interaction.
Active Clients: Data is retained for the duration of our commercial relationship and for six years thereafter to comply with UK legal, tax, and accounting obligations.
8. Your Legal Rights Under UK data protection law, you have specific rights regarding your personal data:
Right of access: Request copies of your personal information (DSAR).
Right to rectification: Request correction of incomplete or inaccurate information.
Right to erasure: Request deletion of your personal information.
Right to restriction of processing: Request the suspension of processing of your data.
Right to object to processing: Object to processing of your personal data where we rely on a legitimate interest.
Right to data portability: Request the transfer of your data to you or a third party.
To exercise any of these rights, please contact us at: compliance@credwell.co.uk. We utilize Microsoft Purview eDiscovery tools to scope and fulfill Data Subject Access Requests (DSARs) rapidly and securely.
9. How to Complain
If you have any concerns about our use of your personal information, please raise them with us directly at compliance@credwell.co.uk.
You also have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection.
ICO Helpline: 0303 123 1113
Website: www.ico.org.uk
Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
