Privacy policy
Your privacy matters, and this policy is written to be read, not buried. It explains, in plain terms, what personal data we collect, why, how we look after it and the control you have over it.
Who we are and what this covers
In this policy, “PDQ”, “we”, “us” and “our” mean PDQ Works Ltd, a company registered in England and Wales (company number 17002817), with its registered office at 7 Yorke Gate, Watford, England, WD17 4NQ. We’re the controller for the personal data described here, and we’re responsible for this website (pdq.works) and this policy.
“Personal data” means information that identifies you, directly or indirectly. It doesn’t include anonymous data. This policy covers what we collect, how we collect it, how and why we use it, who we share it with, how long we keep it and the rights you hold.
The personal data we collect
We collect a few different types of personal data, depending on how you interact with us:
- Identity data: your name, title and job role.
- Contact data: your email address, phone number and postal address.
- Technical data: your IP address, browser type and version, device, time zone and how you move around our website.
- Profile data: your interests, preferences and any feedback or survey responses you share with us.
- Marketing data: your preferences for receiving marketing from us and how you like to hear from us.
How we collect it
We collect your data three ways:
- When you interact with us: you give us data directly when you fill in our contact form, sign up to our newsletter, correspond with us or apply for a job.
- When you visit our website: we collect some technical data automatically through cookies and similar tools. Section 5 explains this in full.
- From third parties or public sources: a client may pass us a colleague’s contact details, or we may collect business contact data from sources such as LinkedIn and marketing databases.
The legal bases for using your data
The law lets us use your data only where we have a valid reason: a “lawful basis”. We rely on four:
- Legitimate interests: where using your data is reasonable, expected and doesn’t override your rights. This covers most of what we do: keeping the site secure, delivering our work, improving the website, business development and recruitment.
- Consent: where you’ve actively opted in, such as non-essential cookies or our newsletter. You can withdraw consent at any time.
- Legal obligation: where the law requires it, such as right-to-work checks or keeping tax and accounting records.
- Contract: where we need your data to agree or deliver an engagement.
Here’s how that maps to what we actually do:
| What we use it for | Data used | Lawful basis |
|---|---|---|
| Keeping the site and our people secure | Identity, Contact, Profile | Legitimate interests |
| Providing our services to you or your organisation | Identity, Contact | Contract / legitimate interests |
| Sending you service updates and marketing on topics relevant to you | Identity, Contact, Profile, Marketing | Legitimate interests / consent |
| Running and improving the website | Identity, Technical, Profile, Marketing | Legitimate interests |
| Developing our own work using insights and feedback you share | Identity, Contact, Profile | Legitimate interests / consent |
| Handling job applications | Identity, Contact, Profile | Legitimate interests |
We won’t rely on legitimate interests where we think you’d find it intrusive or unwarranted, and we always aim to use the least data needed.
Cookies
A cookie is a small text file a website stores on your device. Cookies help a site remember you, work properly and understand how it’s being used.
Cookies fall into two groups:
- Necessary cookies keep the website working; you can’t switch these off.
- Non-essential cookies do everything else, and we only set them with your consent.
We use three kinds:
- Necessary: including the cookie that remembers your cookie choices.
- Statistics: Google Analytics (GA4), which tells us how visitors find and use the site so we can improve it.
- Marketing: a LinkedIn tag, which helps us understand and reach a relevant professional audience.
Statistics and marketing cookies are set by Google and LinkedIn rather than by us, so they are “third-party” cookies. Analytics cookies typically last up to two years; the marketing cookies last anywhere from a day to around a year, depending on the cookie.
You can see the full, current list of cookies and accept or reject the non-essential ones through our cookie banner and the “” settings on the site, and you can change your choice at any time. Most browsers also let you block or delete cookies, though if you block everything, parts of the site may not work properly.
Marketing
When you opt in, we’ll send you occasional updates, insights and news. Two ways to stop, whenever you like:
- click unsubscribe in any marketing email, or
- email us at admin [at] pdq.works.
We treat your marketing preferences as instructions and act on them promptly.
Sharing your data
We don’t sell your data. We share it only where there’s a clear reason, and only with:
- Service providers who help us run the business: website hosting, our newsletter platform, analytics and cloud storage. They act on our instructions and can’t use your data for anything else.
- Delivery and project partners: where we work alongside a collaborator on a client engagement, we may share the contact details needed to do that.
- Professional advisers: such as our accountant, lawyer or insurer.
- A buyer or successor: if we ever sell or merge the business, your data may transfer with it.
Anyone we share data with is required to protect it and use it lawfully.
International transfers
Some of the providers we rely on are based outside the UK. Our analytics and LinkedIn tools send data to the United States, for example. Where data leaves the UK, we make sure it’s protected: either the destination country is covered by UK “adequacy” rules, or we put approved safeguards in place, such as the UK’s International Data Transfer Agreement.
How we protect and keep your data
Keeping it safe
We use appropriate technical and organisational measures to protect your data from loss, misuse, unauthorised access and disclosure. If something does go wrong, we have procedures to deal with a suspected breach, and we’ll notify you and the regulator where the law requires it.
Keeping it only as long as needed
We hold your data only as long as we need it for the purposes set out here, including any legal, accounting or reporting duties. To decide how long that is, we weigh the amount, nature and sensitivity of the data, the risk of harm, the purpose, whether we can achieve it another way and what the law requires. You can ask us to delete your data in some circumstances; see Section 11.
If you apply for a job with us
If you apply for a role at PDQ, here’s how we handle your data.
The careers form
Our website has a short careers form: your name, a link to your CV or professional profile and when you’re available from. Submissions are stored on our own UK-hosted server, where our recruitment lead reviews them. If you give us a link, we’ll view what it points to — your profile or CV — to assess your application.
What we collect, and why
| Data | Where it comes from | Why we use it |
|---|---|---|
| Your name and contact details | You, or a recruitment agent | To talk to you about your application |
| Your CV and covering letter | You, or a recruitment agent | To assess your suitability for the role |
| When you’re available from | You | To plan when you could join us |
| What you tell us at interview | You | To assess your suitability for the role |
| Your application form | You | To assess your suitability for the role |
| Confirmation of your qualifications | You, or the awarding body | To assess your suitability for the role |
| Confirmation of your employment history | Your referees | To verify your history |
| Information about your health | You | Only to make any reasonable adjustments you need |
| ID and right-to-work check | You, or a screening provider | To confirm your identity and your right to work in the UK |
We rely on our legitimate interests in finding the right person for the role, except for right-to-work and ID checks, which we carry out to meet our legal obligations as an employer. Health information is used solely to support you, never to make a hiring decision.
Sharing
We may share your data with, or ask you to share it directly with, recruitment agents working for us or a provider of screening services.
How long we keep it
If your application isn’t successful, we keep your data for six months after the role is filled, in case a question comes up. Careers-form submissions we don’t take forward are kept for six months from the date you send them. We may keep it longer to tell you about future opportunities, but only if you’re happy for us to. If you join us, we’ll keep your data as an employee, and we’ll explain that separately.
Your rights
The law gives you a set of rights over your data. You can ask us to:
- Access it: get a copy of the data we hold about you (a “subject access request”).
- Correct it: fix anything inaccurate or incomplete.
- Erase it: delete it, where there’s no good reason for us to keep it.
- Restrict it: pause our use of it while something’s being sorted out.
- Object: to us using your data on the basis of legitimate interests.
- Port it: receive certain data in a reusable format, or have it sent to another provider.
- Withdraw consent: where we’re relying on it, at any time.
Cost and timing
Exercising these rights is usually free, and we’ll respond within one month. If we need to confirm your identity first, the clock pauses until you’ve given us what we need.
To exercise any of these, email us at admin [at] pdq.works.
Complaints
If you’re unhappy with how we’ve handled your data, tell us first: email admin [at] pdq.works and we’ll put it right wherever we can. When you raise a concern, we’ll acknowledge it within 30 days, look into it without undue delay, keep you posted and let you know the outcome.
You can also complain to the Information Commissioner’s Office (ICO), the UK’s data protection regulator, at ico.org.uk. We’d appreciate the chance to sort things out first, but it’s your right to go straight to them.
Changes and contact
We may update this policy from time to time. Any changes take effect as soon as they’re posted here, so it’s worth checking back now and then.
Questions about this policy, or about your data? Email us at admin [at] pdq.works.