Privacy Policy
LH Risk Strategy Advisory Ltd, trading as DueTelligence
Version 2.0 · Last updated: 29 August 2026 · Next review: 29 August 2027
1. Who we are and what this policy covers
LH Risk Strategy Advisory Ltd ("we", "us", "our") trades as DueTelligence. We provide independent
assurance, safety case and regulatory compliance services to organisations in the nuclear, defence and
high-hazard sectors, and we operate an associate network of specialist engineers who deliver work
alongside us.
This policy explains how we handle personal data when you visit our website, when you or your
organisation engage us, when you apply to join our associate network, and when we deliver services.
Company details
| Legal entity | LH Risk Strategy Advisory Ltd |
| Trading name | DueTelligence |
| Company registration number | 16510387 |
| VAT registration number | GB 516 4979 58 |
| Registered in | England and Wales |
| Registered office | 71-75 Shelton Street, London, United Kingdom, WC2H 9JQ |
| Principal place of business | 71-75 Shelton Street, London, United Kingdom, WC2H 9JQ |
| Contact email | info@duetelligence.com |
| Website | duetelligence.com |
2. When we are a controller and when we are a processor
This distinction matters, because different obligations apply.
We are a data controller for personal data relating to our website visitors, our client contacts,
applicants to and members of our associate network, our suppliers, and our own business records. This
policy describes that processing.
We are a data processor for personal data contained in material a client provides to us, or that we
access on a client's systems, in the course of delivering services. Examples include names appearing in
safety documentation, competence records, personnel schedules or operational logs. In those cases the
client is the controller, our processing is governed by our contract with that client and by their
instructions, and their own privacy notice applies to the individuals concerned. If you believe your
personal data is held by one of our clients and processed by us on their behalf, contact that
organisation in the first instance; we will assist them in responding.
3. Personal data we collect
3.1 Website visitors
- Technical and usage data: IP address, approximate location at country or city level, browser and device type, operating system, referring page, pages viewed, and time and duration of visit.
- Any information you choose to submit through an enquiry form or by emailing us.
3.2 Client and prospective client contacts
- Name, job title, employer, work email address, telephone number and postal address.
- Records of our correspondence and meetings with you.
- Information about the engagement, enquiry or tender to which you relate.
- Billing and invoicing details, purchase order references, and payment history. We invoice directly and do not collect or store payment card details.
3.3 Associate network applicants and members
Where you apply to join or are a member of our associate network, we process:
- Name, contact details and the name and registration details of your company or sole trader entity.
- Your curriculum vitae, qualifications, professional memberships, training records and technical experience.
- Areas of specialism, sector experience and availability.
- Confirmation of the security clearance you hold and its level — see section 4.
- Confirmation that you hold the insurance required by our associate agreement, and the insurer and limits.
- References and the outcome of any competence verification we carry out.
- Records of work you have delivered for us, engagement history and payment records.
- Any declarations you make to us about conflicts of interest or permissions required from an employer.
The source of this data is you, and where you provide them, your referees.
3.4 Procurement and bid data
Where we bid for public sector or supply chain contracts, we may include your name, role and
professional history in a bid or capability document, and provide it to the contracting authority or
prime contractor. We do this only for associates and personnel who have agreed to be named.
3.5 Supplier and adviser contacts
Names, contact details and correspondence relating to our accountants, insurers, legal advisers and
other suppliers.
3.6 Data we ask you not to send us
Please do not send us personal data about other people unless it is necessary — for example, a referee's
contact details, or personnel information required to deliver an engagement. Please do not send us
protectively marked or client-confidential material by unsecured email.
4. Security clearance and vetting information
We work in cleared environments and need to know whether an associate or applicant holds the clearance
a particular engagement requires.
What we collect: confirmation that clearance is held, the level, and the sponsoring organisation
where relevant.
What we do not collect: we do not ask for, and you should not send us, the contents of your vetting
file, financial disclosures made to a vetting authority, information about criminal convictions or
offences, health information, or any other material generated by the vetting process. If you send us
material of this kind unprompted we will delete it.
Our lawful basis for processing clearance confirmation is our legitimate interest in matching
appropriately cleared personnel to engagements and in meeting the security requirements of our clients.
Confirming your clearance status to us does not discharge any obligation you may have to declare
outside interests or secondary activity to your vetting authority or employer. That obligation remains
yours.
5. Why we process personal data, and our lawful bases
| Purpose | Lawful basis |
|---|---|
| Responding to enquiries and providing information about our services | Legitimate interests — responding to people who contact us; or steps at your request prior to a contract |
| Delivering engagements, managing client relationships and providing support | Performance of a contract with your organisation; legitimate interests in managing the relationship |
| Invoicing, credit control and maintaining financial records | Legal obligation; legitimate interests in being paid |
| Assessing applications to our associate network and verifying competence, insurance and clearance status | Legitimate interests in engaging suitably qualified associates; steps prior to entering a contract |
| Engaging associates and administering work orders and payments | Performance of a contract with your entity |
| Including named personnel in bids and capability documents | Legitimate interests in bidding for work, with your agreement to be named |
| Operating, securing and improving our website | Legitimate interests in a functioning and secure website; consent for non-essential cookies |
| Sending occasional updates about our services to business contacts | Legitimate interests in promoting our services to relevant businesses; consent where required |
| Obtaining insurance, legal, accounting and other professional advice | Legitimate interests in running the business properly |
| Establishing, exercising or defending legal claims, and responding to regulators | Legal obligation; legitimate interests in protecting our position |
| Meeting security, quality and audit requirements flowed down by clients and contracting authorities | Legal obligation; legitimate interests in meeting our contractual commitments |
Where we rely on legitimate interests, we have considered whether those interests are overridden by
your rights. You can object to processing based on legitimate interests — see section 10.
We do not carry out automated decision-making that produces legal or similarly significant effects.
Decisions about whether to engage an associate, or to accept an engagement, are made by a person.
6. Who we share personal data with
- Professional advisers — our accountant, solicitors and insurance brokers, where necessary.
- Clients and prospective clients — where you are a named associate on an engagement or a bid, and have agreed to be named.
- Contracting authorities and prime contractors — where required as part of a tender, framework application or supply chain assurance process.
- Service providers — our hosting, email, accounting and document storage providers, acting on our instructions under written terms. A current list is available on request.
- Where required by law — including to regulators, HMRC, or in connection with legal proceedings.
We do not sell personal data, and we do not share it for third-party advertising.
7. International transfers
Our website hosting and our primary business systems are located in the United Kingdom or the European
Economic Area.
Where a service provider processes personal data outside the UK, we rely on UK adequacy regulations
where they apply, or on the International Data Transfer Agreement or the UK Addendum to the EU Standard
Contractual Clauses, together with any additional measures needed.
Client material handled in the course of an engagement is subject to the client's own requirements. Where
a client requires material to remain within a specified jurisdiction or on their own systems, we work to
that requirement and it takes precedence over our default arrangements.
8. How long we keep personal data
| Category | Retention |
|---|---|
| Website enquiry correspondence where no engagement follows | 24 months |
| Client contact and relationship records | 6 years from the end of the relationship |
| Engagement records and deliverables | 7 years from completion, or longer where a client contract or regulatory requirement specifies |
| Financial and transaction records | 6 years from the end of the accounting period, as required by tax law |
| Associate applications where no engagement follows | 12 months, then deleted unless you ask us to retain your details |
| Associate records where engagements have taken place | 7 years from the last engagement |
| Clearance status confirmations | Deleted or updated when the clearance lapses or the associate relationship ends |
| Bid and tender records | 7 years from submission, reflecting public procurement audit periods |
| Website analytics data | 26 months |
Client material processed on a client's behalf is retained, returned or destroyed in accordance with our
contract with that client and their instructions.
9. How we protect personal data
We are a small specialist firm and we describe our measures honestly rather than by reference to
capabilities we do not have.
- Access to client and associate information is limited to personnel working on the relevant engagement.
- Devices are encrypted and protected by strong authentication.
- Multi-factor authentication is enabled on business systems that support it.
- Data in transit is protected using current transport layer encryption.
- Client material is segregated by client. Material from different clients is not commingled.
- Protectively marked and client-confidential material is handled only in accordance with the client's own arrangements, and where required only on client-issued equipment or client premises.
- Third-party services are not used to process client material without the client's prior written agreement. This includes cloud and artificial intelligence services.
- Backups are taken and retention is controlled.
- Associates are bound by written confidentiality and security obligations before receiving any material.
Certification status: we do not currently hold Cyber Essentials, Cyber Essentials Plus, ISO 27001 or
ISO 9001 certification. We operate in accordance with the principles of ISO 27001 for information
security and ISO 9001 for quality management, and our Quality, Security and Technical Review Plan
(LHRSA-QP-01) sets out those arrangements. It is available on request. We will update this section if
our certification position changes.
Insurance: we maintain professional indemnity, public liability, products liability and employers'
liability insurance. Limits and evidence of cover are set out in our Terms and Conditions and are
available on request.
No system is completely secure, and transmission of information over the internet carries inherent risk.
If you need to send us sensitive material, contact us first and we will agree a secure method.
10. Your rights
Under UK data protection law you have the right to:
- Access the personal data we hold about you and receive a copy.
- Rectification of inaccurate data and completion of incomplete data.
- Erasure of your data in certain circumstances.
- Restriction of processing in certain circumstances.
- Object to processing based on legitimate interests, on grounds relating to your situation, and to object at any time to direct marketing.
- Portability — to receive data you provided to us, in a machine-readable format, where processing is based on consent or contract and carried out by automated means.
- Withdraw consent at any time where we rely on consent. This does not affect processing carried out before withdrawal.
- Complain to the Information Commissioner's Office.
To exercise any of these rights, email us at info@duetelligence.com. We will respond within one month. In complex
cases we may extend this by up to two further months and will tell you if we do.
There is no fee, unless a request is manifestly unfounded or excessive.
Some rights are qualified. We may need to retain information to comply with a legal obligation, to meet
a client's contractual or regulatory requirement, or to establish or defend a legal claim.
11. Cookies
We use a small number of cookies.
Strictly necessary cookies keep the site working and secure — session management and protection
against cross-site request forgery. These do not require consent.
Analytics cookies help us understand how the site is used, so we can improve it. These are only set
if you consent.
You can accept or reject non-essential cookies through the banner shown on your first visit, and change
your choice at any time through the cookie settings link in our footer. You can also block or delete
cookies through your browser settings, though blocking strictly necessary cookies will affect how the
site works.
12. Working in regulated sectors
We work with organisations subject to nuclear, defence and other regulatory regimes. In that context:
- Client material is handled under the client's own security classification and information handling arrangements, which take precedence over our general practice.
- We accept flow-down security, audit and compliance requirements from clients and contracting authorities.
- Clients remain responsible for classifying material correctly before providing it to us, for determining who may access it, and for complying with export control and other sector obligations.
- Security documentation, our Quality, Security and Technical Review Plan, and a data processing agreement are available to clients on request.
13. Other websites
Our website may link to other websites. We are not responsible for their privacy practices, and we
encourage you to read their policies.
14. Children
Our website and services are directed at businesses and are not intended for anyone under 18. We do not
knowingly collect personal data from children. If you believe we hold data about a child, contact us and
we will delete it.
15. Changes to this policy
We may update this policy. The version number and date at the top show when it last changed. Where
changes are significant we will bring them to the attention of clients and associates directly. We review
this policy at least annually.
16. Contact and complaints
For any question about this policy or about how we handle personal data:
Email: info@duetelligence.com
Post: LH Risk Strategy Advisory Ltd, 71-75 Shelton Street, London, WC2H 9JQ, United Kingdom
We have not appointed a Data Protection Officer. Data protection enquiries are handled by the Managing
Director at the address above.
If you are not satisfied with our response, you can complain to the Information Commissioner's Office:
Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Telephone 0303 123 1113 · ico.org.uk
We would appreciate the chance to resolve your concern before you approach the ICO.
Ready to Get Started?
See how DueTelligence can support your safety-critical engineering programmes.
Talk to an Assurance Specialist