← Back to Home

Privacy Policy

1. INTRODUCTION

1.1 Big Picture HR is a registered Data Controller with the Information Commissioner's Office (ICO).

1.2 This Privacy Notice sets out how we collect, store and use personal information in accordance with the UK General Data Protection Regulations (UK GDPR) and Data Protection Act of 2018.

1.3 It applies to all users of this website.

1.4 We reserve the right to amend this Privacy Notice at any time. It does not form part of any contract with us.

1.5 By using our website, you agree to the collection and use of information in accordance with this policy.

2. DATA CONTROLLER INFORMATION

Company: Big Picture HR

Contact Person: Victoria Norris

Address: United Kingdom

Email: hello@bigpicturehr.com

Phone: Available upon request

3. THE INFORMATION WE STORE

3.1 We collect, store and use the following categories of personal information:

4. DATA COLLECTION PROCESS

4.1 When you submit a website enquiry or sign up to our newsletter, the data that you have provided will be stored in our website database and emailed to us directly.

5. INFORMATION AUTOMATICALLY COLLECTED

5.1 When you visit our website, we may automatically collect:

5.2 Our website may contain links to other websites of interest. However, once a user has left our site we have no control over their privacy and therefore cannot be responsible for their data. Such sites are not governed by this privacy statement.

6. HOW WE USE PERSONAL INFORMATION

6.1 We only use personal information when the law allows us to. Most commonly, in the following circumstances:

6.2 We use the information we collect for the following purposes:

7. CHANGE OF PURPOSE

7.1 We only use personal information for the purposes for which we collect it, unless we reasonably consider that we need to use it for another reason and that the reason identified is compatible with the original purpose.

8. CONSENT AND WITHDRAWING CONSENT

8.1 In limited circumstances, when we will not rely on the grounds for collecting, processing and transfer set out in this Privacy Notice, we may approach individuals directly for written consent to allow us to process certain particularly sensitive data. Individuals do not have to agree to any request for consent from us.

8.2 Individuals who have provided written consent to the collection, processing and transfer of personal information for a specific purpose have the right to withdraw consent for that specific processing at any time.

9. SHARING DATA WITH THIRD PARTIES

9.1 We may share appropriate information with appointed Data Processors, such as technical or administration support engaged by the organisation, with whom we have the appropriate agreements in place.

9.2 We will share your personal information with other third parties when required by law, when it is necessary to administer our working relationship with you or when we have another legitimate interest in doing so.

9.3 We will not transfer any personal data outside of the UK in order to perform a contract or otherwise, unless:

9.4 We do not sell, trade, or rent your personal information. We may share your data with:

9.5 If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.

10. DATA STORAGE AND RETENTION

10.1 We store personal information securely and have in place the appropriate technical and organisational measures to protect and - when required - remove, both electronic and any physical records we hold.

10.2 Our appointed Data Processors and any third parties will only process your personal information on our instructions and when they have agreed to treat the information confidentially and keep it secure.

10.3 We retain information as long as the stated purposes in this Privacy Notice still apply. We use our judgement, taking a proportionate approach to balance the needs of our organisation with the impact of retention on individual privacy.

10.4 In the event that a relationship with an individual or organisation comes to an end, or the information is no longer required, we review whether we need to retain all or some personal data and delete that which it is not deemed necessary. Generally, we deem it sufficient to retain enough information to confirm that the relationship existed – such as basic contact information and details of contracts (where applicable).

10.5 In addition, we undertake an annual data audit in or around November/December each year, to thoroughly review our data retention and remove any unnecessary personal data.

10.6 We review all prospect and enquiry data annually and delete records where there has been no engagement for the specified period.

10.7 We comply with applicable legal and regulatory requirements and professional guidelines relating to the retention of information for our business – for example, income and tax audit purposes.

10.8 Upon review, we decide whether information should be erased (irretrievably deleted) or, in limited circumstances, anonymised so that it is no longer in a form which permits identification of data subjects.

10.9 The above processes mean that personal data which isn't in use or required to be retained for another stated reason, is not typically retained for longer than a maximum period of 24 months.

10.10 We will dispose of your information by irretrievably deleting it from the website database and email inboxes.

10.11 We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including:

11. DATA SECURITY

11.1 We implement appropriate technical and organisational measures to protect your personal data, including:

11.2 However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.

12. RIGHTS IN RELATION TO PERSONAL DATA

12.1 Under data protection law, individuals have rights, including:

12.2 To exercise any of these rights, please contact us using the details in the Data Controller Information section.

13. CHILDREN'S PRIVACY

13.1 Our services are not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child without parental consent, we will take steps to delete that information.

14. MARKETING COMMUNICATIONS

14.1 We may send you marketing communications if you have:

14.2 You can unsubscribe from marketing emails at any time by:

15. COOKIES

15.1 Our website uses cookies to improve your experience. For detailed information about how we use cookies, please see our Cookie Policy.

16. CHANGES TO THIS POLICY

16.1 We may update this Privacy Policy from time to time. We will notify you of any material changes by:

16.2 We encourage you to review this Privacy Policy periodically.

17. CONTACT

17.1 Our core activities do not require us to monitor or process personal data on a large scale and we are not a public authority or body, therefore we are not required to appoint a data protection officer (DPO).

17.2 Victoria Norris is responsible for data protection at the organisation. They may be contacted with any requests, queries or concerns regarding this Privacy Notice or any other data protection issue by emailing: hello@bigpicturehr.com

17.3 If you remain unhappy with how we've used your data after raising a complaint with us, you can raise your concerns with the ICO at the following address:

Information Commissioner's Office
Wycliffe House,
Water Lane,
Wilmslow,
Cheshire
SK9 5AF

The ICO Helpline number is 0303 123 1113

Website: https://www.ico.org.uk/make-a-complaint

Last updated: September 2025