CM Beyer Limited · Company No. 17009212 sales@cmbeyer.co.uk
Home › Privacy Policy

Privacy Policy

CM Beyer Limited — Company No. 17009212

Effective: 3 February 2026
In plain language: We collect the minimum data needed to provide our services, we don't sell your data, and you can ask us to delete it at any time by emailing privacy@cmbeyer.co.uk.
1

Who We Are

CM Beyer Limited (“we”, “us”, “our”) is a marketing, advertising, and business management consultancy providing direct-to-client marketing and sales services. For the personal data described in this policy, we are the data controllerThe organisation that decides the purposes and means of processing personal data. As data controller, CM Beyer must follow data protection law..

Data Controller Details
CompanyCM Beyer Limited
Company No.17009212
AddressSuite 53C Unimix House, Abbey Road, London NW10 7TR
Phone+44 7946 812112
ICO RegistrationPending
ICO registration. We are completing our registration with the Information Commissioner's Office (ICO). The Data Protection (Charges and Information) Regulations 2018 require every UK organisation that processes personal data to register. The annual fee for small organisations is £40. We will publish our registration number here once confirmed.
2

What Data We Collect

The personal data we hold depends on how you interact with us:

Data Categories
Business contacts & clientsName, job title, company, email, phone, relationship records
Prospective clientsContact details from networking, referrals, enquiries, prospecting
Website visitorsIP address, browser type, pages visited, time on site, cookies
Suppliers & partnersContact details, contractual information
Job applicantsCV, cover letter, contact details, qualifications
We do not routinely collect special category dataSensitive personal data including racial origin, political opinions, religious beliefs, trade union membership, genetic/biometric data, health data, sex life, or sexual orientation. This data has extra legal protections under UK GDPR Article 9. (such as health information, racial or ethnic origin, or political opinions). If we ever need to, we will ask for your explicit consent first.
3

Why We Collect It

We use your personal data for the following purposes:

  • Responding to enquiries and providing our services
  • Managing client and supplier relationships
  • Fulfilling contractual and billing obligations
  • Carrying out marketing and sales activity, including B2B outreach
  • Conducting business development and market research
  • Operating and improving our website
  • Processing job applications
  • Complying with legal and regulatory obligations (tax, accounting, Companies Act)
  • Protecting our legitimate business interests and preventing fraud
5

Business-to-Business Marketing

Outreach to business contacts is central to what we do. Where we market to corporate contacts at their business email addresses, we rely on legitimate interests under UK GDPR and the business-to-business provisions of PECRThe Privacy and Electronic Communications Regulations 2003 — UK law that sits alongside GDPR and governs electronic marketing, cookies, and telecommunications privacy. PECR allows unsolicited B2B marketing emails to corporate email addresses without prior consent..

PECR Regulation 22(3) permits unsolicited marketing to corporate subscribers (business email addresses) without prior consent, provided the sender is identifiable, and the message includes a valid opt-out mechanism.

You may opt out of B2B marketing at any time by contacting privacy@cmbeyer.co.uk or using the unsubscribe mechanism in any marketing communication.

6

Cookies

Our website uses cookies — small text files stored on your device — for the following purposes:

Cookie Types
Essential cookiesRequired for the website to function. You cannot turn them off.
Analytics cookiesHelp us understand how visitors use the site. Set only with consent.
Preference cookiesRemember your settings (e.g. cookie consent choice).

You can manage your cookie preferences through the cookie banner displayed on your first visit, or by adjusting your browser settings. Disabling essential cookies may affect website functionality.

We ask for your consent before setting non-essential cookies, as PECR requires. Our cookie banner provides clear options to accept or reject them.
7

Who We Share Data With

We do not sell personal data. We may share personal data with the following categories of recipient:

  • Service providers (processors) — including our hosting provider (Hostinger), our email provider, Google (website analytics, where you consent), Stripe (payment processing), and Anthropic (which powers our on-site AI assistant, “Bea”) — all under appropriate data processing agreements. Some of these providers (notably Anthropic, Google, and Stripe) process data in the United States. The UK International Data Transfer Agreement / Addendum or equivalent safeguards protect those transfers. Please do not enter sensitive personal data into the AI assistant.
  • Clients — where sharing is necessary to deliver the services they have engaged us to provide
  • Professional advisers — accountants, lawyers, and auditors acting under professional obligations of confidentiality
  • Regulatory authorities — HMRC, the ICO, Companies House, and any other body where the law requires disclosure
  • Business acquirers — in the event of a sale, merger, or restructuring of the Company, subject to appropriate confidentiality protections
8

How Long We Keep It

We keep personal data only as long as the purpose we collected it for requires:

Retention Periods
Client records7 years from end of engagement
Prospective client dataReviewed annually; deleted if no longer relevant
Website analytics26 months
Financial & tax records6 years (Limitation Act 1980) / 7 years (HMRC)
Job applications6 months from decision, unless you consent to a longer period
Director's Resolutions10 years (per Articles of Association, Art. 6.5)
9

Your Rights

Under UK GDPR you have the following rights in relation to your personal data:

Data Subject Rights under UK GDPR
Right of accessGet a copy of the data we hold about you
Right to rectificationCorrect inaccurate or incomplete data
Right to erasureRequest deletion (the “right to be forgotten”)
Right to restrictionLimit how we process your data
Right to objectChallenge processing based on legitimate interests
Right to portabilityReceive your data in a structured, machine-readable format
Right to withdraw consentWhere consent is the lawful basis

To exercise any of these rights, contact privacy@cmbeyer.co.uk. We will respond within one calendar month. Most requests cost nothing, but we may charge a reasonable fee for manifestly unfounded or excessive ones.

10

Data Security

We maintain appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, or alteration. These include:

  • Encryption in transit (TLS/SSL) for all web traffic and email
  • Access controls limiting data access to authorised personnel
  • Regular security reviews of systems and processes
  • Secure hosting with EU-based data centres
  • Staff awareness of data protection obligations

We assess the risk of every personal data breachA breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. If a breach is likely to result in a risk to individuals, the organisation must notify the ICO within 72 hours.. Where a breach is likely to put individuals' rights and freedoms at risk, we will notify the ICO within 72 hours and affected individuals without undue delay.

11

International Transfers

We primarily process personal data within the UK and the European Economic Area. Some of our providers (for example, cloud services) process personal data outside the UK. When that happens, we rely on a UK adequacy determination for the receiving country or on UK Government-approved Standard Contractual ClausesPre-approved contractual terms issued by the European Commission (and adopted by the UK) that provide safeguards for personal data transferred internationally. They impose data protection obligations on the data recipient..

CM Beyer Australia Pty Ltd (ACN 694 721 992), our Australian subsidiary, may process limited personal data in connection with Australian operations. The UK Government has recognised Australia as providing an adequate level of data protection.

12

Children's Data

Our services are for businesses and business professionals. We do not knowingly collect personal data from children under 13. If we become aware that we have collected data from a child, we will delete it without delay. If you believe we hold data relating to a child, please contact privacy@cmbeyer.co.uk.

13

Changes to This Policy

We may update this policy as our business or the law changes. The effective date above reflects the current version. Where changes are significant, we will take reasonable steps to notify you — for example, by posting a notice on our website.

14

Complaints

If you have a concern about how we handle your personal data, please contact privacy@cmbeyer.co.uk first. We will do our best to resolve your concern.

You also have the right to complain to the Information Commissioner's OfficeThe UK's independent body set up to uphold information rights. The ICO can investigate complaints about organisations' data protection practices and has the power to issue fines and enforcement notices. (ICO):

ICO Contact Details
Websiteico.org.uk
Helpline0303 123 1113
AddressWycliffe House, Water Lane, Wilmslow, SK9 5AF
CM Beyer Limited · Company No. 17009212 · Trade Mark UK00004349102
VAT 515289678 · Suite 53C Unimix House, Abbey Road, London NW10 7TR