Last updated 29 July 2026
This site collects nothing about you. No cookies, no analytics, no tracking, no
mailing list. If you get in touch, I keep what you send me so I can reply and, where it goes further,
do the work — and nothing beyond that.
Who is responsible. Integrity Partners Limited is the data controller for the
personal data described here. Registered in England and Wales, company number 9230028. Registered
office: The White House, 73 Havers Lane, Bishop's Stortford, Hertfordshire, CM23 3PA.
Any question about this note, or about data I hold, comes to me directly:
matthew.batchelor@integritypartners.co.uk
or +44 20 7952 6610.
This website
The site is a single static page. It sets no cookies, runs no analytics, and has no forms, logins or
database — there is nothing to submit and nothing stored here about you. Two things still involve third
parties, and you should know about both:
- Server logs. The web server records each request — IP address, time, the page
requested, the response code, your browser's user-agent string and the referring page. That is
standard for any web server. It is used to keep the site up and secure, never to build a profile, and
it is not exported or analysed anywhere else. The site is hosted on
Railway, and logs
expire on their rolling retention.
- Fonts. The typefaces are loaded from Google Fonts, so your browser fetches them
from Google's servers and Google receives your IP address and user-agent as part of that request. No
cookie is set by it. Google's
privacy policy
applies to what they do with it.
Links out to LinkedIn are ordinary links. Once you follow one you are on LinkedIn's site under
LinkedIn's policy, not mine.
If you get in touch
Email, telephone and LinkedIn are the ways to reach me. Whichever you use, I end up holding your name
and contact details, usually your employer and role, and whatever you have chosen to tell me about what
you need. I use it to reply, to work out whether I can help, and to scope and quote for the work.
You are not added to a mailing list. I do not send marketing emails, and I never sell, rent or share
contact details for anyone else's marketing.
If we work together
An engagement generates the ordinary record of one: a contract, correspondence, notes, timesheets and
invoices. That will usually include names, roles and contact details of colleagues at your organisation.
Due diligence work is the case that deserves a specific mention. Material shared with me by a client or
a target company can contain personal data — team lists, contracts, salary bands, CVs. I handle it only
for that engagement, under the confidentiality terms of the engagement letter or NDA, and I return or
delete it at the end of the engagement or when you ask.
Why I am allowed to hold it
- Legitimate interests — replying to an enquiry, keeping a record of who I have
spoken to and about what, and running and securing the site. I have weighed this against your
interests; the processing is limited, expected in a business context and easy to object to.
- Performance of a contract — delivering an engagement, and the steps taken before
one to agree it.
- Legal obligation — invoices and accounting records, which company law and HMRC
require me to keep.
I do not rely on consent for anything described here, and there is no automated decision-making or
profiling of any kind.
Who else sees it
As few people as the work allows. In practice that means the suppliers who make the business run: the
hosting provider for this site, my email and office software provider, my accountant and the accounting
software used for invoicing and tax. Each acts on my instructions under a contract. Beyond that, I would
disclose data only where the law requires it, or to professional advisers where I genuinely need their
advice. Never to advertisers, data brokers or marketing lists.
Some of those suppliers are based outside the UK or process data outside it. Where that happens, the
transfer relies on the UK's adequacy regulations for the country concerned or on the International Data
Transfer Addendum to the standard contractual clauses.
How long I keep it
- Enquiries that do not lead to work — up to 12 months, then deleted.
- Client records and correspondence — for the engagement and six years after it ends, matching the
limitation period for contract claims.
- Invoices and accounting records — six years from the end of the accounting period they fall in, as
HMRC requires.
- Due diligence material — returned or deleted at the end of the engagement, or on the timescale the
engagement letter or NDA sets.
- Server logs — the hosting platform's rolling retention only.
Keeping it safe
The site is served over HTTPS with HSTS, and being static it holds no personal data at all. Everything
else lives in a deliberately small number of reputable, well-secured services, with access protected by
multi-factor authentication and held to what the work needs. No system is perfectly secure and I will
not claim otherwise, but the surface here is small by design.
Your rights
Under UK data protection law you can ask me for a copy of the personal data I hold about you, to
correct it if it is wrong, to delete it, to restrict or object to what I am doing with it — including
objecting to the legitimate interests above — and to receive it in a portable form.
Email me and I will deal with it. There is no charge, and I will respond within one month. If you are
not satisfied with how I have handled it, please tell me first so I have the chance to put it right, but
you always have the right to complain to the Information Commissioner's Office at
ico.org.uk/make-a-complaint
or on 0303 123 1113.
Children
This is a business-to-business service. It is not directed at children and I do not knowingly collect
data about them.
Changes
If this note changes, the date at the top changes with it. There is no archive of previous versions —
the current one is what applies.