Legal Notices

Privacy policy

1. Who we are

This Policy is issued on behalf of the Leonard Curtis Business Solutions Group ("the Group"). LCBSG Limited is the holding company of the Group and does not itself process personal data. The Group's operating companies, including Leonard Curtis (UK) Limited, LC Debt Solutions Limited, LC Risk Management Limited, Leonard Curtis Legal Limited, Leonard Curtis Offshore Limited, Leonard Curtis C.I. Limited, Leonard Curtis Jersey Limited, Leonard Curtis Funding Limited, Reach Commercial Finance Limited, Newsource Commercial Finance Limited, Leonard Curtis Property & Construction Advisory Limited and VirtualNonExecs Limited (together "LCBSG", "we" or "us"), are each committed to complying with all applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR) (together "Data Protection Laws").

Each operating company is a data controller in its own right in respect of the personal data it processes. Where two or more operating companies determine the purposes and means of processing together, they act as joint controllers. References to "LCBSG" in this Policy mean the operating company responsible for the relevant processing.

2. Insolvency appointments

Licensed insolvency practitioners within the Group accept formal appointments as office-holders under the Insolvency Act 1986 (for example as liquidator, administrator or trustee in bankruptcy) and as fixed charge receivers under the Law of Property Act 1925 and the provisions of the legal charge pursuant to which they have been appointed. When acting in these capacities, the appointed office-holder or receiver is a data controller in their own right in respect of personal data processed to discharge the functions of the appointment. This includes personal data relating to creditors, employees, directors and other stakeholders of the entity, individual or property over which they are appointed. Processing in this context is generally necessary for compliance with legal obligations under insolvency legislation and for the legitimate interests of conducting the appointment.

3. Data protection oversight

Data protection compliance at LCBSG is overseen jointly by the Head of Group Risk & Compliance and the Group Information Security Manager, who provide guidance and advice to the Group and its staff and monitor compliance with Data Protection Laws. They can be contacted at privacy@leonardcurtis.co.uk.

The Group has assessed the requirement for a statutory Data Protection Officer (DPO) under Article 37 UK GDPR and has determined that a statutory DPO is not currently required. This assessment is documented and reviewed annually.

In relation to Leonard Curtis Legal Limited (LC Legal), LC Legal's Compliance Officer for Legal Practice (COLP), appointed in accordance with the requirements of the Solicitors Regulation Authority (SRA), oversees LC Legal's compliance with its professional regulatory obligations, including those arising under Data Protection Laws insofar as they relate to LC Legal's regulated legal services. Where a data protection matter arises in the context of LC Legal's work that also engages SRA regulatory obligations, the COLP leads the response, coordinating with the Head of Group Risk & Compliance and the Group Information Security Manager on data protection and technical matters as required.

All staff must handle personal data in accordance with the Group's internal Data Protection Policy (DP-POL-001) and Information Security Policy (ISMS-POL-001) and must complete mandatory data protection training.

4. What is personal data?

Personal data is any information relating to an identified or identifiable natural person (a data subject). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

5. Personal data we collect

LCBSG collects the following categories of personal data (i) for marketing and business development purposes, (ii) to deliver its professional services, and (iii) in relation to formal appointments as office-holders and receivers, to discharge the functions of those appointments:

  • Contact details, such as name, email address, phone number and postal address, of clients, potential clients, and individuals who work for or on behalf of them, and, in relation to appointments as office-holders and receivers, such external contact information of the stakeholders of the entity, individual or property concerned.
  • Service delivery information, being personal data provided to us by clients and stakeholders, or acquired from third parties at the direction of our client, to the extent required to perform our services or discharge an appointment as office-holder and/or receiver.
  • Marketing information, collected to respond to enquiries about our products and services or to provide information, reports or updates.
  • Website visitor information, such as IP address and pages visited. Please see our Website Use and Cookies Policy for more detail.

Clients and other third parties who provide personal data to LCBSG must do so in compliance with applicable Data Protection Laws.

6. How and why we use personal data

We process personal data for the following purposes and on the following lawful bases:

  • To provide products or perform services requested by clients under a letter of engagement, statement of work or similar, where processing is necessary for the performance of a contract or for our legitimate interests in conducting and managing our business.
  • To discharge the functions of an appointment as office-holder or receiver, where processing is necessary for compliance with legal obligations under insolvency legislation and for the legitimate interests of conducting the appointment.
  • To comply with legal and regulatory obligations, including anti-money laundering, sanctions and professional regulatory requirements, where processing is based on a legal obligation.
  • To send marketing communications, including updates, newsletters and event invitations. Where you have actively opted in, we rely on your consent. Where you are an existing client whose details we collected in the course of providing or discussing our services, we rely on our legitimate interests to send marketing information about similar services, in line with the soft opt-in rules under PECR. Every communication includes an unsubscribe link, and you can opt out at any time, including via our preference centre or by emailing privacy@leonardcurtis.co.uk.
  • To measure engagement with our communications. Our email technology records who opens particular articles or emails. We rely on our legitimate interests to understand which content is useful and to keep our records accurate. You can object to this at any time.
  • To operate and improve our websites and your customer experience, where processing is necessary for our legitimate interests. Please see our Website Use and Cookies Policy.
  • For security purposes, including protecting LCBSG and third parties against security incidents and preventing fraud, where processing is necessary for our legitimate interests.

Wherever we rely on legitimate interests, we consider and balance any potential impact on you and your rights. We will not use personal data where our interests are overridden by the impact on you, unless we have your consent or are otherwise required or permitted to by law. You have the right to object to processing based on legitimate interests.

7. How personal data is protected

Personal data is processed both manually and electronically in accordance with the purposes above. Access is restricted to authorised LCBSG employees and third-party processors who are appropriately designated, trained and instructed. The Group maintains technical and organisational security measures under its Information Security Policy (ISMS-POL-001), which is aligned to ISO/IEC 27001.

8. How long we keep personal data

We retain personal data only for as long as necessary for the purposes for which it was collected, and in accordance with the Group's retention policy. Retention periods are determined by reference to:

  • Statutory and regulatory requirements, including insolvency legislation, tax, anti-money laundering and professional regulatory record-keeping obligations.
  • Legitimate business needs, including dealing with queries after an engagement or appointment has concluded.

When personal data is no longer required, it is securely deleted or destroyed. Further detail on retention periods for specific categories of data is available on request from privacy@leonardcurtis.co.uk.

9. Sharing personal data

We only share personal data in accordance with this Policy. We do not sell personal data. We may share personal data:

  • Among LCBSG controlled affiliates and subsidiaries for the purposes set out in this Policy, subject to the following restriction. Personal data obtained by Leonard Curtis (UK) Limited or LC Debt Solutions Limited in the course of an insolvency or receivership appointment or obtained by Leonard Curtis Legal Limited in the course of an instruction by a client, will not be shared with any other Group entity. The only exception is where an insolvency practitioner within Leonard Curtis (UK) Limited or LC Debt Solutions Limited instructs Leonard Curtis Legal Limited to provide legal advice in the course of an insolvency or receivership appointment, and the provision of personal data is required to fulfil those instructions.
  • With external third parties such as vendors, consultants and service providers performing services on our behalf. These processors may access personal data solely to perform the services specified in their contract, under written agreements meeting the requirements of Article 28 UK GDPR, and must maintain security measures consistent with this Policy.
  • In response to lawful requests by public authorities, courts and regulators, including to meet national security or law enforcement requirements.
  • With prospective or actual acquirers or partners if LCBSG enters into a joint venture, merger, acquisition or business transfer, subject to appropriate safeguards.

10. International transfers

Personal data is primarily stored and processed in the United Kingdom. Some of our service providers may process personal data outside the UK. Where personal data is transferred outside the UK, we ensure an adequate level of protection through one of the following safeguards:

  • A UK adequacy decision covering the destination country or territory.
  • The UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, together with any additional measures identified by a transfer risk assessment.
  • Another safeguard or derogation permitted by UK GDPR in the specific circumstances.

Further information about international transfers, including copies of the relevant safeguards, is available on request from privacy@leonardcurtis.co.uk.

11. Crown Dependencies

The Group operates in the Crown Dependencies through offices and entities in Guernsey, Jersey and the Isle of Man. Where personal data is processed by or in relation to those operations, the applicable local law applies in addition to or in place of the UK GDPR:

  • Guernsey: the Data Protection (Bailiwick of Guernsey) Law 2017, regulated by the Office of the Data Protection Authority (ODPA).
  • Jersey: the Data Protection (Jersey) Law 2018, regulated by the Jersey Office of the Information Commissioner (JOIC).
  • Isle of Man: the Data Protection Act 2018 (an Act of Tynwald) and the GDPR and LED Implementing Regulations 2018, regulated by the Isle of Man Information Commissioner.

Each of these jurisdictions benefits from UK and EU adequacy decisions, so personal data can flow between the UK and the Crown Dependencies without additional safeguards. Data subjects in these jurisdictions have equivalent rights to those set out in this Policy and may complain to their local regulator should they wish to do so.

12. Your rights

As a data subject, you have the following rights concerning personal data processed by LCBSG:

  • Access: you have the right to obtain details of the personal data we hold about you.
  • Rectification: you have the right to ask us to correct personal data that is inaccurate or incomplete.
  • Erasure: you can request that we erase your personal data. Where we agree, we will keep basic data to identify you solely to prevent further unwanted processing.
  • Restriction: you have the right to ask us to restrict how we process your data, so that we store it but do not further process it.
  • Objection: where processing is based on legitimate interests, you have the right to object. We will stop processing unless we can demonstrate compelling legitimate grounds.
  • Portability: you have the right to request that we transfer data you provided to us to another organisation, or directly to you, in certain circumstances.
  • Withdraw consent: where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

To exercise any of these rights, contact privacy@leonardcurtis.co.uk. We will respond within one calendar month of receiving your request. This can be extended by up to two further months for complex or numerous requests, in which case we ill tell you within the first month. Exercising your rights is free of charge, although a reasonable fee may apply to requests that are manifestly unfounded or excessive.

Some rights are limited in the context of insolvency appointments, where office-holders are subject to statutory duties of disclosure and record-keeping. Where an exemption applies, we will explain this in our response.

If you choose not to provide certain personal data, it may prevent us from providing some services to you or limit your ability to use some features of our websites.

13. Cookies and website use

Our websites use cookies and similar technologies. Details of the cookies we use, their purposes and how to manage them are set out in our Website Use and Cookies Policy (DP-PN-COOK-001), which should be read alongside this Policy.

14. How to complain

You have the right to complain directly to us about how we handle your personal data. You can do this using our data protection complaints form, by emailing privacy@leonardcurtis.co.uk, or by writing to the Head of Group Risk & Compliance at our correspondence address below. We will acknowledge your complaint within 30 days, keep you informed of progress, and explain the outcome in plain language.

If you are not satisfied with our response, you can complain to the Information Commissioner's Office (ico.org.uk), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, telephone 0303 123 1113. You also have the right to seek a remedy in court under Section 164A of the Data Protection Act 2018 if you believe we have infringed your data protection rights. Data subjects in the Crown Dependencies may complain to the ODPA (Guernsey), the JOIC (Jersey) or the Isle of Man Information Commissioner as applicable.

15. Contact details

Data protection queries and rights requests: privacy@leonardcurtis.co.uk

Data protection correspondence address: Leonard Curtis House, Elms Square, Bury New Road, Whitefield, Greater Manchester M45 7TA

Registered office (LCBSG Limited): Riverside House, Irwell Street, Manchester M3 5EN

16. Changes to this Policy

This Policy is reviewed at least annually and whenever there is a material change to our processing activities or to Data Protection Laws. The current version is always published on our websites.

Date of last review: 18 September 2026

Get in touch
with Leonard Curtis

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.