Effective Date: 17th April 2025
Last Updated: 17th April 2025
Purpose: This Privacy Policy outlines how HOF Consulting ("we", "us", "our") collects, uses, discloses, protects, and otherwise processes the personal data of individuals ("you", "your") who visit or interact with our website located at https://hofconsulting.co.uk/ (the "Website").
Data Controller: For the purposes of applicable data protection legislation, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, the data controller responsible for the personal data collected through this Website is HOF Consulting. Our contact details can be found in Section 12 of this policy.
Commitment to Privacy: HOF Consulting is committed to protecting your privacy and handling your personal data in a transparent and secure manner. We process personal data in accordance with the UK GDPR and the Data Protection Act 2018. This policy serves to inform you about our data practices and your rights concerning your personal data. Establishing clarity regarding the entity responsible for data processing is a fundamental requirement for transparency under data protection law.
Scope: This policy applies solely to personal data collected through your use of the Website. It does not extend to data collected offline or through other means, unless explicitly stated otherwise.
We collect personal data to provide and improve our services, respond effectively to your inquiries, and ensure the secure and efficient operation of our Website. The types of personal data we collect fall into two main categories:
Information You Provide Directly:
We collect personal data that you voluntarily submit to us through the Website. This includes:
Information Collected Automatically:
When you navigate and interact with our Website, we automatically collect certain information about your device and browsing actions. This includes:
We use the personal data we collect for specific, explicit, and legitimate purposes, directly related to our business operations as strategic and technical consultants for the medical device industry. Your data is used in the following ways:
We process data only for the purposes for which it was collected, adhering to the purpose limitation principle under UK GDPR.
We only process your personal data when we have a valid legal basis to do so under the UK GDPR. The lawful bases we rely upon depend on the specific purpose of the processing activity:
Clearly identifying the lawful basis for each distinct processing activity is a core requirement of transparency under data protection law.
HOF Consulting respects the confidentiality of your personal data. We do not sell your personal data to third parties. We only share your personal data with third parties in specific circumstances and where legally permitted, primarily to facilitate the operation of our Website and business activities. The categories of recipients with whom we may share your data include :
We ensure that any third party with whom we share personal data provides adequate protection for that data and complies with applicable data protection laws. The following provides a structured overview of our data sharing practices:
IT Hosting Provider
Website content, potentially usage logs, contact form data - Website operation, maintenance, data storage
Analytics Provider(s)
Aggregated/anonymised usage data, IP address (potentially) - Website traffic analysis & performance improvement
Security Provider (Google reCAPTCHA)
Device and application data, interaction data - Spam prevention, website security
Professional Advisors
Contact details, inquiry details (as relevant) Obtaining legal, financial, or consulting advice
Legal/Regulatory Authorities
Relevant data as legally required - Compliance with legal obligations, legal proceedings
HOF Consulting takes the security of your personal data seriously. We implement and maintain appropriate technical and organisational measures designed to protect the personal data we process against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures are proportionate to the risks involved in the processing activities, considering the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing.
Our security measures include, but are not limited to:
While we strive to use commercially acceptable means to protect your personal data, it is important to note that no method of transmission over the Internet or method of electronic storage is 100% secure. Therefore, we cannot guarantee its absolute security. Given the nature of our business within the medical device sector, we recognise the importance of robust data protection practices, even for the business contact information processed via this Website.
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, as outlined in this Privacy Policy, and to comply with our legal, accounting, or reporting obligations. The criteria used to determine our retention periods include the nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process the data, and applicable legal requirements.
Specific retention periods or criteria include:
Vague statements about retention are insufficient; providing clear periods or criteria is essential for transparency. We periodically review our data retention practices to ensure data is not held longer than necessary.
Under the UK GDPR, you have several rights concerning your personal data. HOF Consulting is committed to upholding these rights. Subject to certain exemptions and limitations provided by law, your rights include:
How to Exercise Your Rights: To exercise any of these rights, please contact us using the details provided in Section 12. We may need to request specific information from you to help us confirm your identity before processing your request. We aim to respond to all legitimate requests within one month. Providing clear pathways for users to exercise their rights is a key aspect of compliance.
Right to Complain: You have the right to lodge a complaint at any time with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection issues, if you are unsatisfied with our response or believe we are not processing your personal data in accordance with the law. Contact details for the ICO can be found on their website: www.ico.org.uk.
What are Cookies? Cookies are small text files placed on your device (computer, smartphone, etc.) when you visit websites. They are widely used to make websites work, or work more efficiently, as well as to provide information to the site owners.
How We Use Cookies: Our Website uses cookies for several purposes:
Your Consent: When you first visit our Website, a banner appears informing you about our use of cookies and requesting your consent for non-essential cookies (Analytical/Performance and Functional, if used). By clicking "Accept", you consent to our use of these cookies. If you click "Decline", only strictly necessary cookies will be used. The alignment between this policy (providing information) and the banner (obtaining consent) is crucial for compliance with cookie regulations.
Managing Cookies: Most web browsers allow some control of most cookies through the browser settings. You can usually block cookies by activating the setting on your browser that allows you to refuse the setting of all or some cookies. However, if you use your browser settings to block all cookies (including essential cookies), you may not be able to access all or parts of our Website. You can typically find information on how to manage cookies in the 'Help' section of your browser or by visiting www.aboutcookies.org or www.allaboutcookies.org.
Personal data collected through the Website may be processed in, and transferred to, countries outside the United Kingdom (UK). This occurs primarily through our use of third-party service providers, such as Google for reCAPTCHA and potentially website hosting or analytics providers, whose servers may be located globally, including in the United States. The use of such global services makes international data transfers highly probable.
When we transfer your personal data outside the UK to countries that have not been deemed by the UK government to provide an adequate level of data protection, we ensure that appropriate safeguards are in place to protect your personal data. These safeguards may include:
We take steps to ensure that any data transferred internationally is treated securely and in accordance with this Privacy Policy and applicable data protection laws. You can request further information about the specific safeguards used for international transfers by contacting us using the details in Section 12. Transparency regarding such transfers and the protections applied is a key requirement.
We may update this Privacy Policy from time to time to reflect changes in our data processing activities, legal requirements, or best practices. Any changes will be effective immediately upon posting the revised policy on this Website.
We will indicate the date the policy was last updated at the top of this page. We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. For significant changes, we may provide a more prominent notice on the Website. Regular review, at least annually or upon significant changes in processing, is considered best practice.
If you have any questions about this Privacy Policy, our data protection practices, or if you wish to exercise any of your data protection rights, please contact us at:
HOF Consulting
Email: info@hofconsulting.co.uk
Phone: +44 (0)7748 322256
(Further contact details, such as a registered address, are available upon request).
Data Protection Officer (DPO): HOF Consulting has assessed its processing activities and currently is not required to appoint a formal Data Protection Officer under the UK GDPR. However, we take data protection seriously, and inquiries can be directed to the contact details above.
This Privacy Policy is provided for informational purposes only and does not constitute legal advice. The information contained herein is intended to be accurate and up-to-date, but HOF Consulting makes no warranty or representation regarding its completeness or accuracy. You should consult with a qualified legal professional for advice tailored to your specific circumstances regarding data protection compliance.
This Privacy Policy is effective as of 17th April 2025
This Privacy Policy was last updated on 17th April 2025