Privacy notice

What personal information Simple Foundry holds, where it comes from, what we do with it, and what you can do about it.

This notice covers this website and the way we run the business: enquiries, research, sales conversations, client work, speaking, and the meetings we record. Client engagements are also governed by the data protection appendices to our terms, which take precedence for information we process on a client's behalf.

We have tried to write it so that it can be read in one sitting. If anything in it is unclear, ask.

Simple Foundry Ltd. Published 6 September 2026.

Simple Foundry Ltd is the controller of the personal information described in this notice.

Company number 16441488, registered in England and Wales.

Registered office: 128 Newlaithes Road, Horsforth, Leeds, LS18 4SY.

Contact for anything in this notice: peter@simplefoundry.co.uk.

Registered with the Information Commissioner's Office, registration reference ZC051725.

We are a small consultancy. We have not appointed a data protection officer, because we are not required to and the business is run by one person, who answers every request under this notice personally.

The table gives the short version. The sections that follow give the detail for the activities that need it.

WhatWhere it comes fromWhy we hold itLawful basisHow long
Enquiries: name, work email, organisation, your messageYou, through the contact form or by emailTo reply to you and to follow the conversation you startedLegitimate interests24 months after our last contact, unless an engagement follows
Research responses: name, work email, role, organisation, your answersYou, through the surveyTo produce and publish research on EHS practiceConsentUntil 12 months after the compiled research is published
Research findings and updates by emailYou, by ticking the opt-in box on a survey or formTo send you what you asked forConsentUntil you unsubscribe, which you can do from any email
Prospective clients: name, job title, employer, work emailPublic sources: LinkedIn profiles, company websites, published reports and newsTo decide whether an organisation fits the work we do, and to make a first approachLegitimate interests24 months after our last contact, then deleted (see section 3)
Clients and their staff: contact details, roles, correspondence, meeting notesYou and your organisation, in the course of the engagementTo deliver the work you have contracted, and to keep the records the engagement requiresContract; legal obligation for financial records6 years after the engagement ends
Meeting recordings and transcriptsThe calls you join with usSo that we can concentrate on the conversation rather than on note-taking, and keep an accurate recordLegitimate interestsDeleted within 12 months of the conversation, or at the end of the engagement it relates to if later (see section 4)
Website visits: pages viewed, device and browser type, approximate location by country or regionYour browser, only if you accept analytics cookiesTo see which pages are read and where visitors arrive fromConsentGoogle Analytics event data is kept for 2 months; cookies expire after 2 years (see the cookie policy)
Server logs: IP address, request time, page requestedYour browser, automaticallyTo keep the site running and secureLegitimate interestsHeld by our hosting provider under its own retention, not accessed by us except to investigate a fault or abuse
Speaking and events: name, organisation, roleEvent organisers and youTo deliver the session you asked forLegitimate interests24 months after the event

Our only mailing list is made up of people who have ticked a box asking for our newsletter or updates by email. Nobody is added to it any other way: not from an enquiry, not from taking part in the research itself, not from a meeting.

We do not use automated decision-making or profiling that produces legal or similarly significant effects on anyone.

This section exists because you may be reading it after we contacted you and you did not give us your details.

Before approaching an organisation we research it: what it does, how its health and safety function is set up, what it has published, and who leads the relevant work. In doing so we record the names, job titles, employers and, where published, the work email addresses of the people we may want to speak to. The sources are public professional profiles (mainly LinkedIn), company websites, annual and sustainability reports, regulator publications and the trade press. We do not buy lists, use data brokers, or scrape.

We rely on legitimate interests. Our interest is in finding organisations that fit the work we do and introducing ourselves to the people responsible for it. We have weighed that against the interests of the people concerned, and limited what we hold to professional information they have already made public in a professional context. We hold nothing about anyone's private life, and we never add anyone to a marketing list or an automated sequence.

We tell you at first contact that we hold your details and point you to this notice. If we have not contacted you within one month of recording your details, we tell you separately or delete the record.

We keep these records for 24 months from our last contact if no conversation follows, then delete them. The period matches the length of a typical enterprise buying cycle for the kind of work we do, which commonly runs from 12 to 24 months between a first approach and a decision. If you tell us you do not want to hear from us, we delete your record and stop; we do not keep a suppression entry unless you ask us to.

You can object at any time by emailing peter@simplefoundry.co.uk. Section 8 explains your other rights.

We use an AI note-taking service, Fireflies, on most of our video calls. It joins the meeting as a visible participant, records the call, and produces a transcript and summary. We say so at the start of a call, and if anyone on the call would rather it did not record we remove it before continuing.

Recordings and transcripts are used to keep an accurate record of what was discussed and agreed. They are not shared beyond the people who were on the call and anyone they ask us to share them with. They are deleted within 12 months of the conversation, or at the end of the engagement they relate to if that is later.

Participation in our research is voluntary and by invitation. Responses are collected through a HubSpot form and held in our customer relationship system alongside your name, work email, role and organisation. Findings are analysed in aggregate and published only in a form that does not identify any person or organisation.

Every respondent is sent the findings by email when they are published; that is part of taking part, and the survey says so. Beyond that, the only reason we would email you is about the research itself, for example to ask before quoting you. Taking part does not put you on a mailing list and never puts you into a sales sequence. If you would like our newsletter, future waves of the research or other updates by email, the survey has separate boxes you can tick; none is ticked for you and none is a condition of taking part.

The research base starts with the September 2026 survey. We hold no responses from earlier research.

You can withdraw from the research at any time by emailing us; if you do, we delete your individual responses, though we cannot recall findings already published in aggregate.

We use AI tools in the course of our work, in research, analysis, drafting and document production, and we say so in our terms. Every output is reviewed by a competent person before it forms part of any advice or deliverable.

We do not enter special category information (health information, for example), or information a client has marked as restricted, into any AI tool without prior written agreement. Where personal information is processed through these tools in the course of our work, the provider is listed in section 7 and does not use the information to train its models.

We do not sell personal information and we do not share it with anyone for their own marketing.

We use the following providers to run the business. Each processes personal information only on our instructions and under a written contract.

ProviderWhat forWhere it is based
WebflowHosting this website and receiving contact form submissionsUnited States
HubSpotCustomer relationship records: enquiries, prospects, clients, research responses and the opt-in mailing list; and the research form itself, which is delivered through HubSpot's content networkUnited States
FirefliesMeeting recording and transcriptionUnited States
GoogleWebsite analytics, only if you accept analytics cookies; and reCAPTCHA spam protection on the research form, which runs whenever that form loads and sends Google the signals it uses to tell people from botsUnited States
AnthropicAI tools used in research, analysis and draftingUnited States
Microsoft 365Email, calendar, documents and file storageData stored in Microsoft's UK and EU data centres; Microsoft is a US company and some support processing may take place there

We may also disclose personal information where the law requires it, to our professional advisers where necessary to protect our legal position, and to a buyer or successor if the business changes hands, in which case this notice would continue to apply.

Most of the providers above are in the United States, so personal information leaves the United Kingdom. Where a provider is certified under the UK Extension to the EU-US Data Privacy Framework, we rely on that certification. Otherwise we rely on the provider's standard contractual clauses with the UK International Data Transfer Addendum. Either route gives the information legal protection equivalent to UK law. You can ask us for details of the safeguard that applies to any provider.

You have the right to:

ask for a copy of the personal information we hold about you;

have inaccurate information corrected;

have information deleted, where we no longer have a reason to keep it;

object to processing based on legitimate interests, including everything in section 3;

restrict processing while a dispute about it is resolved;

receive information you gave us in a portable format;

withdraw consent at any time where consent is the basis, which covers research participation, the mailing list and analytics cookies.

Email peter@simplefoundry.co.uk. We respond within one month. We may ask you to confirm your identity first, and we will say why if we cannot do what you ask.

Everything we hold sits with the providers in section 7, each of which encrypts data in transit and at rest and is independently certified for information security. Access to every system is protected by strong, unique passwords and multi-factor authentication. We keep only what the table in section 2 says we keep. No system is perfectly secure, and if a breach were ever to affect you we would tell you without undue delay.

If you are unhappy with how we have handled your information, tell us first and we will try to put it right. You also have the right to complain to the Information Commissioner's Office, the UK's data protection regulator, at ico.org.uk/make-a-complaint or on 0303 123 1113.

We will update this notice when our practices change and show the date of the current version at the top. Changes that materially affect you will be flagged on this page for a reasonable period after they take effect.