Legal Notices
1. Who we are
This Policy is issued on behalf of the Leonard Curtis Business Solutions Group ("the Group"). LCBSG Limited is the holding company of the Group and does not itself process personal data. The Group's operating companies, including Leonard Curtis (UK) Limited, LC Debt Solutions Limited, LC Risk Management Limited, Leonard Curtis Legal Limited, Leonard Curtis Offshore Limited, Leonard Curtis C.I. Limited, Leonard Curtis Jersey Limited, Leonard Curtis Funding Limited, Reach Commercial Finance Limited, Newsource Commercial Finance Limited, Leonard Curtis Property & Construction Advisory Limited and VirtualNonExecs Limited (together "LCBSG", "we" or "us"), are each committed to complying with all applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR) (together "Data Protection Laws").
Each operating company is a data controller in its own right in respect of the personal data it processes. Where two or more operating companies determine the purposes and means of processing together, they act as joint controllers. References to "LCBSG" in this Policy mean the operating company responsible for the relevant processing.
2. Insolvency appointments
Licensed insolvency practitioners within the Group accept formal appointments as office-holders under the Insolvency Act 1986 (for example as liquidator, administrator or trustee in bankruptcy) and as fixed charge receivers under the Law of Property Act 1925 and the provisions of the legal charge pursuant to which they have been appointed. When acting in these capacities, the appointed office-holder or receiver is a data controller in their own right in respect of personal data processed to discharge the functions of the appointment. This includes personal data relating to creditors, employees, directors and other stakeholders of the entity, individual or property over which they are appointed. Processing in this context is generally necessary for compliance with legal obligations under insolvency legislation and for the legitimate interests of conducting the appointment.
3. Data protection oversight
Data protection compliance at LCBSG is overseen jointly by the Head of Group Risk & Compliance and the Group Information Security Manager, who provide guidance and advice to the Group and its staff and monitor compliance with Data Protection Laws. They can be contacted at privacy@leonardcurtis.co.uk.
The Group has assessed the requirement for a statutory Data Protection Officer (DPO) under Article 37 UK GDPR and has determined that a statutory DPO is not currently required. This assessment is documented and reviewed annually.
In relation to Leonard Curtis Legal Limited (LC Legal), LC Legal's Compliance Officer for Legal Practice (COLP), appointed in accordance with the requirements of the Solicitors Regulation Authority (SRA), oversees LC Legal's compliance with its professional regulatory obligations, including those arising under Data Protection Laws insofar as they relate to LC Legal's regulated legal services. Where a data protection matter arises in the context of LC Legal's work that also engages SRA regulatory obligations, the COLP leads the response, coordinating with the Head of Group Risk & Compliance and the Group Information Security Manager on data protection and technical matters as required.
All staff must handle personal data in accordance with the Group's internal Data Protection Policy (DP-POL-001) and Information Security Policy (ISMS-POL-001) and must complete mandatory data protection training.
4. What is personal data?
Personal data is any information relating to an identified or identifiable natural person (a data subject). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
5. Personal data we collect
LCBSG collects the following categories of personal data (i) for marketing and business development purposes, (ii) to deliver its professional services, and (iii) in relation to formal appointments as office-holders and receivers, to discharge the functions of those appointments:
Clients and other third parties who provide personal data to LCBSG must do so in compliance with applicable Data Protection Laws.
6. How and why we use personal data
We process personal data for the following purposes and on the following lawful bases:
Wherever we rely on legitimate interests, we consider and balance any potential impact on you and your rights. We will not use personal data where our interests are overridden by the impact on you, unless we have your consent or are otherwise required or permitted to by law. You have the right to object to processing based on legitimate interests.
7. How personal data is protected
Personal data is processed both manually and electronically in accordance with the purposes above. Access is restricted to authorised LCBSG employees and third-party processors who are appropriately designated, trained and instructed. The Group maintains technical and organisational security measures under its Information Security Policy (ISMS-POL-001), which is aligned to ISO/IEC 27001.
8. How long we keep personal data
We retain personal data only for as long as necessary for the purposes for which it was collected, and in accordance with the Group's retention policy. Retention periods are determined by reference to:
When personal data is no longer required, it is securely deleted or destroyed. Further detail on retention periods for specific categories of data is available on request from privacy@leonardcurtis.co.uk.
9. Sharing personal data
We only share personal data in accordance with this Policy. We do not sell personal data. We may share personal data:
10. International transfers
Personal data is primarily stored and processed in the United Kingdom. Some of our service providers may process personal data outside the UK. Where personal data is transferred outside the UK, we ensure an adequate level of protection through one of the following safeguards:
Further information about international transfers, including copies of the relevant safeguards, is available on request from privacy@leonardcurtis.co.uk.
11. Crown Dependencies
The Group operates in the Crown Dependencies through offices and entities in Guernsey, Jersey and the Isle of Man. Where personal data is processed by or in relation to those operations, the applicable local law applies in addition to or in place of the UK GDPR:
Each of these jurisdictions benefits from UK and EU adequacy decisions, so personal data can flow between the UK and the Crown Dependencies without additional safeguards. Data subjects in these jurisdictions have equivalent rights to those set out in this Policy and may complain to their local regulator should they wish to do so.
12. Your rights
As a data subject, you have the following rights concerning personal data processed by LCBSG:
To exercise any of these rights, contact privacy@leonardcurtis.co.uk. We will respond within one calendar month of receiving your request. This can be extended by up to two further months for complex or numerous requests, in which case we ill tell you within the first month. Exercising your rights is free of charge, although a reasonable fee may apply to requests that are manifestly unfounded or excessive.
Some rights are limited in the context of insolvency appointments, where office-holders are subject to statutory duties of disclosure and record-keeping. Where an exemption applies, we will explain this in our response.
If you choose not to provide certain personal data, it may prevent us from providing some services to you or limit your ability to use some features of our websites.
13. Cookies and website use
Our websites use cookies and similar technologies. Details of the cookies we use, their purposes and how to manage them are set out in our Website Use and Cookies Policy (DP-PN-COOK-001), which should be read alongside this Policy.
14. How to complain
You have the right to complain directly to us about how we handle your personal data. You can do this using our data protection complaints form, by emailing privacy@leonardcurtis.co.uk, or by writing to the Head of Group Risk & Compliance at our correspondence address below. We will acknowledge your complaint within 30 days, keep you informed of progress, and explain the outcome in plain language.
If you are not satisfied with our response, you can complain to the Information Commissioner's Office (ico.org.uk), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, telephone 0303 123 1113. You also have the right to seek a remedy in court under Section 164A of the Data Protection Act 2018 if you believe we have infringed your data protection rights. Data subjects in the Crown Dependencies may complain to the ODPA (Guernsey), the JOIC (Jersey) or the Isle of Man Information Commissioner as applicable.
15. Contact details
Data protection queries and rights requests: privacy@leonardcurtis.co.uk
Data protection correspondence address: Leonard Curtis House, Elms Square, Bury New Road, Whitefield, Greater Manchester M45 7TA
Registered office (LCBSG Limited): Riverside House, Irwell Street, Manchester M3 5EN
16. Changes to this Policy
This Policy is reviewed at least annually and whenever there is a material change to our processing activities or to Data Protection Laws. The current version is always published on our websites.
Date of last review: 18 September 2026