PRIVACY POLICY
Last updated: 1 September 2026
1. WHO WE ARE
GRS Consultancy Ltd ("GRS", "we", "us" or "our") is a private limited company registered in England and Wales.
Company number: 16599665
Registered office: 252–260 Quayside Tower, Broad Street, Birmingham, B1 2HF
Website: www.grsconsultancy.com
Email: info@grsconsultancy.com
GRS Consultancy Ltd is the data controller responsible for personal data processed through this website and in connection with our services.
We are committed to protecting personal information and handling it in accordance with applicable UK data protection law, including the UK GDPR and Data Protection Act 2018, as amended from time to time.
2. INFORMATION WE COLLECT
Depending on how you interact with GRS, we may collect:
• Name
• Business name
• Job title or position
• Telephone number
• Email address
• Business address
• Information about your business
• Information about the products or services you are interested in
• Information provided when requesting a quotation or consultation
• Correspondence and communications with us
• Information submitted through our website forms
• Technical information such as IP address, browser type and device information
• Information relating to marketing preferences
We only collect information that is reasonably necessary for the purposes explained in this Privacy Policy.
3. HOW WE USE YOUR INFORMATION
We may use personal information to:
• Respond to enquiries and quotation requests
• Contact you regarding services you have requested
• Provide and manage our services
• Understand your business requirements
• Compare or identify suitable commercial solutions
• Communicate with you about your enquiry
• Manage our business relationship with you
• Process contracts and payments
• Maintain business and accounting records
• Meet legal and regulatory obligations
• Improve our website, services and customer experience
• Prevent fraud, misuse or security incidents
• Send marketing communications where we are legally permitted to do so
We will not use your personal information for purposes that are incompatible with the purpose for which it was collected without providing appropriate information or obtaining consent where required.
4. OUR LAWFUL BASES
We process personal information using one or more of the lawful bases available under UK data protection law.
Contract / pre-contractual steps
Where processing is necessary to provide a quotation, respond to an enquiry or take steps at your request before entering into a contract.
Legitimate interests
Where processing is necessary for our legitimate business interests, provided those interests do not override your rights and freedoms.
Legal obligation
Where we are required to process information to comply with a legal or regulatory obligation.
Consent
Where we ask for your consent, you can withdraw that consent at any time.
The lawful basis used will depend on the particular processing activity.
5. MARKETING
We may contact businesses and business contacts about GRS services where permitted by applicable marketing and data protection laws.
Where consent is required, we will obtain it before sending marketing communications.
You can opt out of marketing communications at any time by contacting us or using an unsubscribe option provided in the communication.
You have the right to object to direct marketing at any time.
6. WHERE WE OBTAIN INFORMATION
We normally collect information directly from you when you:
• Complete a form on our website
• Request a quotation
• Contact us
• Request a callback
• Communicate with us
• Enter into a business relationship with us
We may also obtain business contact information from publicly available sources or third-party sources where permitted by law.
Where we obtain personal information from another source, we will provide the required privacy information in accordance with applicable data protection law.
7. WHO WE MAY SHARE INFORMATION WITH
We may share information where reasonably necessary with:
• Service providers supporting our website and business operations
• CRM and customer management systems
• Website and form providers
• IT and cloud service providers
• Professional advisers such as accountants, insurers or legal advisers
• Payment providers where applicable
• Suppliers or commercial partners where necessary to provide a requested service
• Government, regulatory or law-enforcement authorities where legally required
We only share information where there is a lawful reason to do so.
We do not sell personal information to third parties.
8. KEEPING YOUR INFORMATION SECURE
We take reasonable technical and organisational measures to protect personal information against:
• Unauthorised access
• Accidental loss
• Destruction
• Misuse
• Unauthorised disclosure
• Alteration
However, no internet transmission or electronic storage system can be guaranteed to be completely secure.
9. HOW LONG WE KEEP INFORMATION
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected.
The retention period depends on the type of information and why we hold it.
We may retain information for longer where necessary to:
• Comply with legal or accounting requirements
• Resolve disputes
• Establish or defend legal claims
• Maintain appropriate business records
When information is no longer required, we will securely delete or anonymise it where appropriate.
10. YOUR DATA PROTECTION RIGHTS
Depending on the circumstances, you may have the right to:
• Request access to your personal information
• Request correction of inaccurate information
• Request deletion of your information
• Request restriction of processing
• Object to certain processing
• Request transfer of certain information to another organisation
• Withdraw consent where processing is based on consent
Some rights are subject to legal conditions and exemptions.
To exercise your rights, contact us using the details below.
Email: info@grsconsultancy.com
11. COMPLAINTS
If you have concerns about how GRS handles your personal information, please contact us first so that we can investigate the issue.
You also have the right to complain to the Information Commissioner's Office (ICO), the UK's independent data protection regulator.
You can find information about making a complaint through the ICO's website.
12. COOKIES
Our website may use cookies and similar technologies to operate the website, understand website usage and improve your experience.
Some cookies are necessary for the website to operate.
Where consent is required for non-essential cookies, we will request your consent before using them.
You can manage your cookie preferences through the cookie controls provided on our website.
13. INTERNATIONAL DATA TRANSFERS
Some of our service providers may process personal information outside the UK.
Where personal information is transferred internationally, we will take appropriate steps to ensure that the transfer is carried out in accordance with applicable UK data protection requirements.
14. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect changes to our business, services, technology or legal requirements.
The latest version will always be published on this website.
Last updated: 1 September 2026