This policy explains how Rothian Ltd ("Rothian", "we", "us") collects and uses personal data when you visit www.rothian.com, contact us, work with us as a client, supplier or associate, or read our content. We have written it to be read, not just to be compliant. If anything is unclear, ask us.
Who we are
Rothian Ltd is the data controller for the personal data described in this policy. We are a company registered in England and Wales, company number 11570066, with our registered office at The Spinney, Highfield, Banstead, England, SM7 3LJ.
For anything to do with your personal data, email info@rothian.com with "Privacy" in the subject line. We do not have a statutory obligation to appoint a data protection officer; a named director is accountable for data protection.
The law we follow
We process personal data in line with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (PECR) as amended by the Data (Use and Access) Act 2025, and, where they apply to our work with clients in those jurisdictions, the EU GDPR and the UAE Personal Data Protection Law.
What we collect and why
| When | What we collect | Why | Lawful basis |
|---|---|---|---|
| You use the contact form | Name, work email, organisation, the topic and solution you select, and anything you write | To reply to your enquiry and arrange a working session | Legitimate interests: responding to people who contact us |
| You email or call us | Your contact details and the content of the conversation | To respond and keep a record of what was agreed | Legitimate interests |
| You browse the site | IP address, browser and device details, pages requested, in our hosting provider’s server logs | To deliver the site, keep it secure and diagnose faults | Legitimate interests: operating a secure website |
| You accept analytics cookies | Pseudonymous usage data: pages viewed, approximate location, device type, referrer | To understand which content is useful and improve the site | Consent |
| You accept marketing cookies | Identifiers set by LinkedIn and conversion events | To measure our LinkedIn advertising | Consent |
| You become a client | Business contact details of your staff, and any personal data contained in the work | To deliver and invoice the engagement | Contract; legitimate interests; legal obligation |
| You join our associate network or apply to work with us | CV, skills, rates, availability, right-to-work evidence, references | To match you with engagements and meet our legal duties | Steps before a contract; contract; legal obligation |
| You supply goods or services to us | Business contact and payment details | To manage the relationship and pay you | Contract; legal obligation |
| We contact business prospects | Business contact details from public sources such as company websites or LinkedIn | To introduce services relevant to your role | Legitimate interests: business-to-business marketing |
We do not knowingly collect special category data through this website, and we ask you not to include it in enquiries. We do not sell personal data, and we do not use it for automated decision-making that has legal or similarly significant effects on you.
Marketing
We send marketing emails only to business contacts where the law allows it, and every message includes a simple way to opt out. If you opt out we keep a minimal record so we do not contact you again. The contact form does not add you to a mailing list: we reply from a named person, and that is all.
Who we share it with
We share personal data only where needed, and with organisations that are bound to protect it:
- Hosting. Vercel Inc. hosts this website and processes server logs.
- Email delivery. Enquiries sent through the contact form are delivered by our email provider (Resend or Microsoft 365).
- Business systems. Microsoft 365 for email, documents and collaboration, and our CRM and accounting providers.
- Analytics and advertising. Google (Google Analytics) and LinkedIn, only if you have given consent for the relevant cookies.
- Associates and partners. Where an engagement needs a specialist from our associate network or a technology partner, we share the minimum needed to deliver it, under a contract that requires confidentiality and data protection.
- Professional advisers and authorities. Accountants, lawyers, insurers, HMRC, regulators, courts or the police where we are legally required or entitled to.
- A buyer or investor. If Rothian, or part of it, is sold or restructured.
International transfers
Some of our providers process data outside the UK, including in the United States, and we work with clients and associates in the European Union, the United Arab Emirates, India and Australia. Where personal data leaves the UK, we rely on UK adequacy regulations where they exist (for example for the European Economic Area, or for US organisations certified to the UK Extension to the EU–US Data Privacy Framework), or on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with any additional safeguards the transfer needs.
How long we keep it
| Data | How long |
|---|---|
| Enquiries that do not lead to work | 24 months after our last contact with you |
| Client engagement records and invoices | 6 years after the end of the engagement, for tax and legal claims |
| Associate network profiles | Until you ask us to remove you, reviewed at least every 2 years |
| Unsuccessful applications | 12 months |
| Server logs | As set by our hosting provider, typically no more than 30 days |
| Analytics data | 14 months |
| Your cookie choice | 6 months, then we ask again |
| Marketing opt-outs | Indefinitely, so we can honour them |
Keeping it secure
We protect personal data with controls proportionate to the risk, including encryption in transit and at rest, multi-factor authentication, least-privilege access, device management, and supplier due diligence. Our information security policy describes our approach. If a breach is likely to put your rights at risk, we will tell you and the Information Commissioner’s Office as the law requires.
Your rights
You have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased, in some circumstances;
- restrict or object to how we use it, including an absolute right to object to direct marketing;
- data portability, where processing is based on consent or contract and carried out by automated means; and
- withdraw consent at any time, where we rely on it. For cookies, use Cookie settings in the footer of any page.
To use any of these rights, email info@rothian.com. We will confirm who you are if we need to, and respond within one month, or tell you within that month if we need longer because the request is complex. There is normally no charge.
Complaints
If you are unhappy with how we have handled your personal data, please tell us first at info@rothian.com so we can put it right. We will acknowledge your complaint within 30 days and investigate without undue delay, as the Data (Use and Access) Act 2025 requires. Our complaints procedure explains the steps.
You also have the right to complain to the Information Commissioner’s Office: ico.org.uk/make-a-complaint, or 0303 123 1113.
Children
Our website and services are for businesses and professionals. They are not directed at children, and we do not knowingly collect children’s data.
Changes to this policy
We review this policy at least once a year and whenever our processing changes. The date at the top shows when it was last updated. If we make a significant change that affects you, we will tell you directly where we can.