Privacy Policy
CM Beyer Limited — Company No. 17009212
Contents
Who We Are
CM Beyer Limited (“we”, “us”, “our”) is a marketing, advertising, and business management consultancy providing direct-to-client marketing and sales services. For the personal data described in this policy, we are the data controllerThe organisation that decides the purposes and means of processing personal data. As data controller, CM Beyer must follow data protection law..
What Data We Collect
The personal data we hold depends on how you interact with us:
Why We Collect It
We use your personal data for the following purposes:
- Responding to enquiries and providing our services
- Managing client and supplier relationships
- Fulfilling contractual and billing obligations
- Carrying out marketing and sales activity, including B2B outreach
- Conducting business development and market research
- Operating and improving our website
- Processing job applications
- Complying with legal and regulatory obligations (tax, accounting, Companies Act)
- Protecting our legitimate business interests and preventing fraud
Our Legal Basis
We must have a lawful basis for processing your personal data under the UK GDPRThe UK General Data Protection Regulation — the UK's version of the EU GDPR, retained in UK law after Brexit. It sets out rules for how organisations collect, store and use personal data.. We rely on the following:
Business-to-Business Marketing
Outreach to business contacts is central to what we do. Where we market to corporate contacts at their business email addresses, we rely on legitimate interests under UK GDPR and the business-to-business provisions of PECRThe Privacy and Electronic Communications Regulations 2003 — UK law that sits alongside GDPR and governs electronic marketing, cookies, and telecommunications privacy. PECR allows unsolicited B2B marketing emails to corporate email addresses without prior consent..
PECR Regulation 22(3) permits unsolicited marketing to corporate subscribers (business email addresses) without prior consent, provided the sender is identifiable, and the message includes a valid opt-out mechanism.
You may opt out of B2B marketing at any time by contacting privacy@cmbeyer.co.uk or using the unsubscribe mechanism in any marketing communication.
Cookies
Our website uses cookies — small text files stored on your device — for the following purposes:
You can manage your cookie preferences through the cookie banner displayed on your first visit, or by adjusting your browser settings. Disabling essential cookies may affect website functionality.
How Long We Keep It
We keep personal data only as long as the purpose we collected it for requires:
Your Rights
Under UK GDPR you have the following rights in relation to your personal data:
To exercise any of these rights, contact privacy@cmbeyer.co.uk. We will respond within one calendar month. Most requests cost nothing, but we may charge a reasonable fee for manifestly unfounded or excessive ones.
Data Security
We maintain appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, or alteration. These include:
- Encryption in transit (TLS/SSL) for all web traffic and email
- Access controls limiting data access to authorised personnel
- Regular security reviews of systems and processes
- Secure hosting with EU-based data centres
- Staff awareness of data protection obligations
We assess the risk of every personal data breachA breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. If a breach is likely to result in a risk to individuals, the organisation must notify the ICO within 72 hours.. Where a breach is likely to put individuals' rights and freedoms at risk, we will notify the ICO within 72 hours and affected individuals without undue delay.
International Transfers
We primarily process personal data within the UK and the European Economic Area. Some of our providers (for example, cloud services) process personal data outside the UK. When that happens, we rely on a UK adequacy determination for the receiving country or on UK Government-approved Standard Contractual ClausesPre-approved contractual terms issued by the European Commission (and adopted by the UK) that provide safeguards for personal data transferred internationally. They impose data protection obligations on the data recipient..
CM Beyer Australia Pty Ltd (ACN 694 721 992), our Australian subsidiary, may process limited personal data in connection with Australian operations. The UK Government has recognised Australia as providing an adequate level of data protection.
Children's Data
Our services are for businesses and business professionals. We do not knowingly collect personal data from children under 13. If we become aware that we have collected data from a child, we will delete it without delay. If you believe we hold data relating to a child, please contact privacy@cmbeyer.co.uk.
Changes to This Policy
We may update this policy as our business or the law changes. The effective date above reflects the current version. Where changes are significant, we will take reasonable steps to notify you — for example, by posting a notice on our website.
Complaints
If you have a concern about how we handle your personal data, please contact privacy@cmbeyer.co.uk first. We will do our best to resolve your concern.
You also have the right to complain to the Information Commissioner's OfficeThe UK's independent body set up to uphold information rights. The ICO can investigate complaints about organisations' data protection practices and has the power to issue fines and enforcement notices. (ICO):