Privacy notice

How we collect, use and protect your information.

Issued by All Things Risk Ltd. Plain English, as you would expect.

Last reviewed: August 2026. The up-to-date version of this notice will always be available on this page.

This privacy notice is issued by All Things Risk Ltd ("we", "us" and "our"). We provide risk and compliance consultancy to law firms and other regulated businesses. We operate in the United Kingdom.

This Privacy Notice outlines how we collect, use, and protect your personal information when you visit our website www.itsallthingsrisk.com and/or engage our consulting services. This policy applies to individuals and businesses based in England and Wales.

Contact details

Company details: All Things Risk Ltd (Company Number 17373808).
Email: eloise@itsallthingsrisk.com

This Privacy Notice will be subject to regular review to ensure it remains accurate and compliant in terms of how we use your personal data.

Data controller

All Things Risk Ltd is the data controller. Our processing of your personal information is governed by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Data collected

The data we collect about you will depend on the nature of your interaction with us. It will be limited to what we need. It may include:

In addition, we may collect information about others such as your clients. If you give us this information (which may be required in order for us to comply with our contractual obligations) it is your responsibility to ensure:

Virtual meetings, events and training

We may from time to time host online events using platforms such as MS Teams, Zoom or equivalent providers. Registration details, attendance data and any interactions during the session may be recorded.

An event or meeting may also be recorded, although this will always be made clear to attendees at the outset.

Training sessions may be recorded and provided to attendees or other interested parties. This will only be done where appropriate, taking into account our data protection and client confidentiality obligations. Training prepared and delivered bespoke for a firm will not be provided to anyone outside of that organisation without their express written consent.

Meetings may be recorded for the purpose of capturing an accurate record of the discussions to enable prompt and efficient progression of the matter. Artificial intelligence (AI) may be utilised for the purpose of creating a transcription of a recorded meeting. We will usually delete the recording once a transcript has been created although may occasionally retain the recording for longer if we deem it necessary to fulfil our obligations.

Sensitive data

Sensitive data includes, but is not limited to, details about race/ethnicity, religious belief, sex life, sexual orientation, political opinions, information about your health or biometric data. We do not collect any sensitive data about you.

What we use your data for

The personal data we collect from you is used to respond to enquiries, provide and administer our services, manage client relationships and meet our own legal and regulatory obligations. This may include third party suppliers we use to conduct our business. Where you have consented to marketing activities, we may share your information with third parties who help run any marketing campaigns.

Where such data is shared with third parties, we will wherever possible require them to maintain appropriate security to protect your information from unauthorised access or processing.

Lawful basis and your legal rights

Under UK data protection law, we must have a "lawful basis" for collecting and using your personal information. The lawful basis we rely on may affect your data protection rights, which are set out in brief below.

We shall respond to any request you make without undue delay and in any event within one calendar month of the original request unless it is unusually complex, in which circumstances it may take longer. We may need to take steps to confirm your identity, or clarify your request, to ensure that personal data is not disclosed to any person who has no right to receive it. Your response times to such requests may impact how long it takes us to respond to your original request.

Our lawful bases for collecting or using personal information are:

Further information about the possible lawful bases available under the UK GDPR can be found on the ICO website along with further information relating to your data protection rights and exemptions: ico.org.uk individual rights guidance.

Sharing your information

We will not sell your personal data. We may share it with:

Where third parties process data on our behalf, where possible, they do so under written agreements that protect your information.

Transferring your data outside the European Economic Area (EEA)

Generally, we do not transfer your data outside of the EEA. That said, third party service providers may be based outside the EEA. In such circumstances, we will endeavour to ensure there is a contract in place to require the recipient to protect the data to the same standard as the UK.

Where data is transferred outside of the UK, we will:

How long we keep your data

Data is only retained for as long as necessary to fulfil the purpose we collected it for. We have legal requirements to keep certain information about our clients for six years after they cease being clients for tax purposes. When data is no longer needed, we securely destroy it or anonymise it.

Keeping your information safe

We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss or misuse, and we keep those measures under review. We will notify you and any applicable regulator of any suspected personal data breach where we are legally required to do so.

Marketing

If you have requested information from us, engaged with our services or signed up to receive updates we may provide you with direct marketing (either by telephone, email or text message). The information we hold about you may be used to help identify products and services that may be of interest to you.

Where you have opted-out, you will not receive such marketing communications. You are free to opt-out at any time but please note this will apply only to marketing communications and not any other personal data provided to us for other purposes.

Cookies

Our website does not currently set any cookies, and we do not currently run analytics on it. If that changes, this notice will be updated before any cookies are used, and you can control or delete cookies at any time via your browser settings. Pages on this site load the Hanken Grotesk typeface from Google Fonts, which involves your browser requesting font files from Google; see Google's privacy policy for how it handles those requests.

Third party links

Our website contains links to third-party websites and services, such as LinkedIn and the Information Commissioner's Office. Clicking those links may allow third parties to collect or share data about you. We do not control these websites and are not responsible for their privacy practices, and we encourage you to read the privacy notice of every site you visit.

How to complain

If you have any concerns about our use of your personal information, you can make a data protection complaint to us by email: eloise@itsallthingsrisk.com.

If you remain unhappy with how we've used your data after raising a complaint with us, you can also complain to the ICO. The ICO's address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Helpline number: 0303 123 1113. Website: ico.org.uk/make-a-complaint.

Eloise Butterworth
Get in touch

Let's talk about where you're trying to get to.

No pitch, no jargon, nothing open-ended. Email eloise@itsallthingsrisk.com, find All Things Risk on LinkedIn, or start with a fifteen-minute call.

Let's talk