Privacy Policy

Last updated: 20 October 2025. This notice explains how we handle personal data for leancrest.com and when you interact with us. We comply with the UK GDPR and the Data Protection Act 2018.

Controller: Leancrest Limited (Company No. 16775287)

Registered office: Newtown House, 38 Newtown Road, Liphook, United Kingdom, GU30 7DX

Contact: privacy@leancrest.com

What data we collect

Purposes and lawful bases

Sharing and processors

We use reputable service providers (acting as processors) to host, store and secure our systems, under written terms that meet UK GDPR Article 28. We do not sell personal data. Where we appoint sub‑processors for client work, these are disclosed and governed within the relevant DPA or contract schedule.

International transfers

If data is transferred outside the UK/EEA, we use appropriate safeguards (e.g., UK International Data Transfer Agreement or Addendum, EU Standard Contractual Clauses, adequacy regulations) and apply supplementary measures where appropriate.

Retention

Your rights

You have rights to access, rectification, erasure, restriction, objection, and data portability, plus the right to complain to the UK Information Commissioner’s Office (ICO). To exercise your rights, contact privacy@leancrest.com. You can contact the ICO at ico.org.uk/make-a-complaint/.

Security

Public‑sector & regulated engagements

Where an engagement imposes additional requirements (e.g., specific breach notification timelines, data location restrictions, DPIAs, audits), we comply as set out in the contract and DPA. We maintain records of processing and support reasonable assurance requests.

Changes

We may update this notice to reflect changes in law or practice. The “Last updated” date will change and the new version will apply from publication.


This website notice does not replace or limit any client DPA or contract, which prevails for commissioned work.