Privacy Policy

LH Risk Strategy Advisory Ltd, trading as DueTelligence

Version 2.0 · Last updated: 29 August 2026 · Next review: 29 August 2027


1. Who we are and what this policy covers

LH Risk Strategy Advisory Ltd ("we", "us", "our") trades as DueTelligence. We provide independent
assurance, safety case and regulatory compliance services to organisations in the nuclear, defence and
high-hazard sectors, and we operate an associate network of specialist engineers who deliver work
alongside us.

This policy explains how we handle personal data when you visit our website, when you or your
organisation engage us, when you apply to join our associate network, and when we deliver services.

Company details

Legal entityLH Risk Strategy Advisory Ltd
Trading nameDueTelligence
Company registration number16510387
VAT registration numberGB 516 4979 58
Registered inEngland and Wales
Registered office71-75 Shelton Street, London, United Kingdom, WC2H 9JQ
Principal place of business71-75 Shelton Street, London, United Kingdom, WC2H 9JQ
Contact emailinfo@duetelligence.com
Websiteduetelligence.com

2. When we are a controller and when we are a processor

This distinction matters, because different obligations apply.

We are a data controller for personal data relating to our website visitors, our client contacts,
applicants to and members of our associate network, our suppliers, and our own business records. This
policy describes that processing.

We are a data processor for personal data contained in material a client provides to us, or that we
access on a client's systems, in the course of delivering services. Examples include names appearing in
safety documentation, competence records, personnel schedules or operational logs. In those cases the
client is the controller, our processing is governed by our contract with that client and by their
instructions, and their own privacy notice applies to the individuals concerned. If you believe your
personal data is held by one of our clients and processed by us on their behalf, contact that
organisation in the first instance; we will assist them in responding.


3. Personal data we collect

3.1 Website visitors

3.2 Client and prospective client contacts

3.3 Associate network applicants and members

Where you apply to join or are a member of our associate network, we process:

The source of this data is you, and where you provide them, your referees.

3.4 Procurement and bid data

Where we bid for public sector or supply chain contracts, we may include your name, role and
professional history in a bid or capability document, and provide it to the contracting authority or
prime contractor. We do this only for associates and personnel who have agreed to be named.

3.5 Supplier and adviser contacts

Names, contact details and correspondence relating to our accountants, insurers, legal advisers and
other suppliers.

3.6 Data we ask you not to send us

Please do not send us personal data about other people unless it is necessary — for example, a referee's
contact details, or personnel information required to deliver an engagement. Please do not send us
protectively marked or client-confidential material by unsecured email.


4. Security clearance and vetting information

We work in cleared environments and need to know whether an associate or applicant holds the clearance
a particular engagement requires.

What we collect: confirmation that clearance is held, the level, and the sponsoring organisation
where relevant.

What we do not collect: we do not ask for, and you should not send us, the contents of your vetting
file, financial disclosures made to a vetting authority, information about criminal convictions or
offences, health information, or any other material generated by the vetting process. If you send us
material of this kind unprompted we will delete it.

Our lawful basis for processing clearance confirmation is our legitimate interest in matching
appropriately cleared personnel to engagements and in meeting the security requirements of our clients.

Confirming your clearance status to us does not discharge any obligation you may have to declare
outside interests or secondary activity to your vetting authority or employer. That obligation remains
yours.


5. Why we process personal data, and our lawful bases

PurposeLawful basis
Responding to enquiries and providing information about our servicesLegitimate interests — responding to people who contact us; or steps at your request prior to a contract
Delivering engagements, managing client relationships and providing supportPerformance of a contract with your organisation; legitimate interests in managing the relationship
Invoicing, credit control and maintaining financial recordsLegal obligation; legitimate interests in being paid
Assessing applications to our associate network and verifying competence, insurance and clearance statusLegitimate interests in engaging suitably qualified associates; steps prior to entering a contract
Engaging associates and administering work orders and paymentsPerformance of a contract with your entity
Including named personnel in bids and capability documentsLegitimate interests in bidding for work, with your agreement to be named
Operating, securing and improving our websiteLegitimate interests in a functioning and secure website; consent for non-essential cookies
Sending occasional updates about our services to business contactsLegitimate interests in promoting our services to relevant businesses; consent where required
Obtaining insurance, legal, accounting and other professional adviceLegitimate interests in running the business properly
Establishing, exercising or defending legal claims, and responding to regulatorsLegal obligation; legitimate interests in protecting our position
Meeting security, quality and audit requirements flowed down by clients and contracting authoritiesLegal obligation; legitimate interests in meeting our contractual commitments

Where we rely on legitimate interests, we have considered whether those interests are overridden by
your rights. You can object to processing based on legitimate interests — see section 10.

We do not carry out automated decision-making that produces legal or similarly significant effects.

Decisions about whether to engage an associate, or to accept an engagement, are made by a person.


6. Who we share personal data with

We do not sell personal data, and we do not share it for third-party advertising.


7. International transfers

Our website hosting and our primary business systems are located in the United Kingdom or the European
Economic Area.

Where a service provider processes personal data outside the UK, we rely on UK adequacy regulations
where they apply, or on the International Data Transfer Agreement or the UK Addendum to the EU Standard
Contractual Clauses, together with any additional measures needed.

Client material handled in the course of an engagement is subject to the client's own requirements. Where
a client requires material to remain within a specified jurisdiction or on their own systems, we work to
that requirement and it takes precedence over our default arrangements.


8. How long we keep personal data

CategoryRetention
Website enquiry correspondence where no engagement follows24 months
Client contact and relationship records6 years from the end of the relationship
Engagement records and deliverables7 years from completion, or longer where a client contract or regulatory requirement specifies
Financial and transaction records6 years from the end of the accounting period, as required by tax law
Associate applications where no engagement follows12 months, then deleted unless you ask us to retain your details
Associate records where engagements have taken place7 years from the last engagement
Clearance status confirmationsDeleted or updated when the clearance lapses or the associate relationship ends
Bid and tender records7 years from submission, reflecting public procurement audit periods
Website analytics data26 months

Client material processed on a client's behalf is retained, returned or destroyed in accordance with our
contract with that client and their instructions.


9. How we protect personal data

We are a small specialist firm and we describe our measures honestly rather than by reference to
capabilities we do not have.

Certification status: we do not currently hold Cyber Essentials, Cyber Essentials Plus, ISO 27001 or
ISO 9001 certification. We operate in accordance with the principles of ISO 27001 for information
security and ISO 9001 for quality management, and our Quality, Security and Technical Review Plan
(LHRSA-QP-01) sets out those arrangements. It is available on request. We will update this section if
our certification position changes.

Insurance: we maintain professional indemnity, public liability, products liability and employers'
liability insurance. Limits and evidence of cover are set out in our Terms and Conditions and are
available on request.

No system is completely secure, and transmission of information over the internet carries inherent risk.
If you need to send us sensitive material, contact us first and we will agree a secure method.


10. Your rights

Under UK data protection law you have the right to:

To exercise any of these rights, email us at info@duetelligence.com. We will respond within one month. In complex
cases we may extend this by up to two further months and will tell you if we do.

There is no fee, unless a request is manifestly unfounded or excessive.

Some rights are qualified. We may need to retain information to comply with a legal obligation, to meet
a client's contractual or regulatory requirement, or to establish or defend a legal claim.


11. Cookies

We use a small number of cookies.

Strictly necessary cookies keep the site working and secure — session management and protection
against cross-site request forgery. These do not require consent.

Analytics cookies help us understand how the site is used, so we can improve it. These are only set
if you consent.

You can accept or reject non-essential cookies through the banner shown on your first visit, and change
your choice at any time through the cookie settings link in our footer. You can also block or delete
cookies through your browser settings, though blocking strictly necessary cookies will affect how the
site works.


12. Working in regulated sectors

We work with organisations subject to nuclear, defence and other regulatory regimes. In that context:


13. Other websites

Our website may link to other websites. We are not responsible for their privacy practices, and we
encourage you to read their policies.


14. Children

Our website and services are directed at businesses and are not intended for anyone under 18. We do not
knowingly collect personal data from children. If you believe we hold data about a child, contact us and
we will delete it.


15. Changes to this policy

We may update this policy. The version number and date at the top show when it last changed. Where
changes are significant we will bring them to the attention of clients and associates directly. We review
this policy at least annually.


16. Contact and complaints

For any question about this policy or about how we handle personal data:

Email: info@duetelligence.com

Post: LH Risk Strategy Advisory Ltd, 71-75 Shelton Street, London, WC2H 9JQ, United Kingdom

We have not appointed a Data Protection Officer. Data protection enquiries are handled by the Managing
Director at the address above.

If you are not satisfied with our response, you can complain to the Information Commissioner's Office:

Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Telephone 0303 123 1113 · ico.org.uk

We would appreciate the chance to resolve your concern before you approach the ICO.

Ready to Get Started?

See how DueTelligence can support your safety-critical engineering programmes.

Talk to an Assurance Specialist