Legal
Privacy Policy
Last updated: 21 August 2026 · Version 1.0
This notice explains what personal data Thurloe Bancroft holds, where it comes from, why we hold it, and what you can do about it. It covers both people who deal with us directly and people whose details appear in the public registers we compile.
Who we are
Thurloe Bancroft is the trading name of [FULL NAME TO BE INSERTED], who operates the business as a sole trader in the United Kingdom. Thurloe Bancroft is not a limited company. The business is run by an individual, and that individual is personally responsible for the personal data described in this notice.
We are the controller of that data for the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Controller means the person who decides why and how personal data is processed.
- Controller
- [FULL NAME TO BE INSERTED], trading as Thurloe Bancroft
- Postal address
- [ADDRESS TO BE INSERTED]
- ICO registration
- [ICO REGISTRATION NUMBER TO BE INSERTED]
We have not appointed a data protection officer. We are not required to appoint one, and enquiries should be sent to the email address above.
Scope of this notice
This notice covers two groups of people. They are treated differently, because their relationship with us is different.
Group A — people who deal with us directly
Enquirers, subscribers, and visitors to this website. If you have contacted us, taken a subscription, or simply loaded this page, you are in this group. You, or your browser, provided the information we hold. Section 3 sets out what that information is.
Group B — people named in the public records we compile
Individuals whose details appear in a statutory register that a public authority is required by law to publish, and which we compile and supply to business subscribers. If you are in this group, you gave us nothing and you have probably never heard of us. section 4, section 5 and section 7 are the ones that concern you.
If you are in Group B and want your details removed from our data, go straight to section 7. We act on those requests without asking for a reason.
Personal data we collect about customers and enquirers
This section applies to Group A. We collect only what we need to answer an enquiry, provide a subscription, and keep proper business records.
| Category | What it includes |
|---|---|
| Identity and contact details | Name, business name, job title, business email address, business telephone number, and business postal address. |
| Correspondence | Emails you send us, our replies, and notes of telephone calls, including the substance of an enquiry. |
| Subscription records | The regions and services subscribed to, start and renewal dates, delivery preferences, and the record of data supplied. |
| Billing records | Invoices, payment references, and the record of payments received. Card details are handled by our payment processor and are never held by us. |
| Technical information | Information generated when a browser requests a page, such as an IP address, the time of the request, and the browser and device type. This is processed by our hosting and network providers to deliver the site and to protect it from attack. |
What we do not collect
- No special category data — nothing about health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetics, biometrics, sex life or sexual orientation.
- No data relating to children. Our services are sold to businesses and this website is not directed at children.
- No payment card numbers. Card details are entered with our payment processor and are not passed to us.
Measurement of website use
We may collect aggregated technical and usage information about visits to this website — for example how many times a page is requested — in order to understand how the site is used and to keep it available and secure. Where such information is collected in a way capable of identifying an individual, it is processed on the basis of consent or legitimate interests, as appropriate to the method used. Any tool in use for this purpose is identified in our Cookie Policy. At the date of this notice, no analytics, heatmap or session-recording tool is in use on this website.
Personal data contained in public records
This section applies to Group B, and it is the part of our processing that matters most.
Our services are compiled from information published by local authorities in statutory public registers. In relation to premises licensing, the particulars we compile may include:
- the name of the applicant
- the name and address of the premises to which the application relates
- the application reference number allocated by the authority
- the type of application, and the activities applied for
- relevant dates, such as the date the application was made or advertised
- the licensing authority holding the register
In most cases the applicant is a company, and information about a company is not personal data. In some cases the applicant is a named individual — a sole trader, or a member of a partnership. Where an individual is named, that information is personal data, and this notice applies to it. The address recorded is the address of the premises, which for some businesses is also a home address.
We do not collect or retain documents submitted in support of an application, operating schedules, plans, drawings, photographs, correspondence between an applicant and an authority, or any special category data that may incidentally appear in a register. Where such material appears, we do not copy it.
Where we obtain public record data
The data comes from public registers maintained by local licensing authorities. Those authorities are required by statute to keep such registers and to make them available for public inspection, so that the public may be informed of applications affecting them.
We consult those registers in the same way as any other member of the public. We do not obtain information by private, covert or unauthorised means, we do not use information given to us in confidence, and we do not buy personal data from data brokers.
The authorities currently within our coverage are listed on our Data Protection and Data Sources page, which also explains our method in more detail.
Our lawful bases
We must have a lawful basis for each purpose for which we process personal data. Ours are set out below.
| Purpose | Lawful basis |
|---|---|
| Compiling public record information and supplying it to business subscribers | Legitimate interests |
| Providing our services to subscribers and administering their account | Performance of a contract |
| Direct marketing to business contacts | Legitimate interests, subject to the Privacy and Electronic Communications Regulations (PECR) |
| Meeting our legal, tax and regulatory obligations | Legal obligation |
| Responding to enquiries | Legitimate interests |
What our legitimate interests are
- Compiling and supplying public record information. Our interest, and our subscribers' interest, in making practical use of information that Parliament has required to be published. The information is already public, is limited to the factual particulars of an application, and is supplied only to business subscribers for business purposes. Against that we weigh the interests of any individual named, which is why removal is available on request, without conditions.
- Direct marketing to business contacts. Our interest in offering a business service to organisations likely to have a use for it, using business contact details. This is always subject to PECR, and to the absolute right to object described in section 11.
- Responding to enquiries. Our interest, and yours, in being able to answer a question you have asked.
We have carried out a Legitimate Interests Assessment for each of these purposes, weighing our interest against the interests, rights and freedoms of the individuals concerned. A copy is available on request, and to any regulator without request.
If we did not obtain your data from you
This section is provided under Article 14 of the UK GDPR, which requires that people are told when their personal data has been obtained from a source other than themselves. It applies to individuals named in the public registers we compile.
Why you are reading this rather than hearing from us directly
We obtain the data from publicly accessible statutory registers, in volume, as those registers are published. Writing to each individual named would involve disproportionate effort within the meaning of Article 14(5)(b): it would require us to obtain contact details that the registers do not give us and that we would not otherwise seek, and to send unsolicited messages to people who have not asked to hear from us. Article 14 permits us instead to make this information publicly available. That is what this page is. It is published permanently, without restriction, and without any requirement to register or ask.
The information Article 14 requires us to give you
- Who holds the data. [FULL NAME TO BE INSERTED], trading as Thurloe Bancroft. Contact details are in section 1.
- The categories of personal data concerned. The name of an applicant, the name and address of the premises applied for, the application reference, the type of application and activities applied for, and the relevant dates. These are set out in full in section 4.
- The source of the data. Public registers maintained by local licensing authorities and published by those authorities for public inspection under statutory duty. The data is not obtained from you, from any private source, or from a data broker.
- The purpose of the processing. To compile a structured, verified record of new licence applications by region, and to supply it to business subscribers who serve those premises.
- The lawful basis. Legitimate interests, as explained in section 6.
- Who receives the data. Our business subscribers, and the service providers listed in section 8 who host and store it on our behalf.
- How long we keep it. As set out in section 10.
- Your rights. Access, rectification, erasure, restriction, portability, and objection — including an absolute right to object to direct marketing. These are set out in section 11.
- Your right to complain. You may complain to the Information Commissioner's Office at any time. See section 12.
How to have your data removed
Email privacy@thurloebancroft.co.uk with the name and premises address as they appear, and ask us to remove them.
You do not need to give a reason, and we will not ask for one. We act on removal requests promptly, and in any event within one month, which is the period allowed by law. There is no charge.
Once removed, the entry is added to a suppression list — a permanent record of the objection, held so that the same details are not collected again in a future cycle. The suppression list holds the minimum necessary to recognise the record, is never supplied to subscribers, and is used for no other purpose. This is explained further in section 10.
Who we share data with
Compiled register data is supplied to our business subscribers, on terms that require them to comply with data protection and electronic marketing law in their own use of it. Beyond that, personal data is shared only with the service providers we use to run the business, and with professional advisers or public authorities where the law requires it.
We name our providers rather than describing them in categories, because you are entitled to know who holds your data.
| Provider | Role | Corporate establishment |
|---|---|---|
| Hostinger | Website hosting | Lithuania (European Economic Area) |
| Cloudflare | DNS, content delivery, network security and bot management | United States, with United Kingdom and European Economic Area infrastructure |
| Supabase | Database and application data storage | United States, with United Kingdom and European Economic Area hosting regions |
| [PAYMENT PROCESSOR TO BE INSERTED] | Payment processing and handling of card details | [TO BE INSERTED] |
| Professional advisers | Accountancy and, where required, legal advice | United Kingdom |
Each provider acts as a processor on our instructions under a written data processing agreement, except where a provider is a controller in its own right for its own limited purposes, such as a payment processor meeting its own regulatory obligations.
We do not sell personal data to advertisers. We do not supply data for consumer marketing purposes. We do not enrich our records with data obtained from third-party data brokers.
International transfers
Where data is stored
All personal data we hold is stored and processed within the United Kingdom and the European Economic Area. The specific hosting region within that footprint may change from time to time for performance and resilience reasons.
Adequacy
Transfers of personal data from the United Kingdom to countries in the European Economic Area are permitted under UK adequacy regulations. No additional transfer safeguard is required for them. This is why the arrangement is straightforward: the data stays inside a footprint the United Kingdom has already recognised as providing an adequate level of protection.
Providers established outside the United Kingdom and the EEA
Some of our providers are corporately established in the United States even though the infrastructure serving Thurloe Bancroft is located in the United Kingdom or the European Economic Area. Limited access from outside the UK and the EEA may occur for support, security and maintenance purposes. Where such access amounts to a restricted transfer, it is governed by the UK International Data Transfer Addendum to the European Commission's standard contractual clauses, or by applicable adequacy regulations, as incorporated in each provider's data processing agreement.
The providers we use
- Hostinger — website hosting. Established in Lithuania, within the European Economic Area.
- Cloudflare — DNS, content delivery, network security and bot management. Established in the United States, with United Kingdom and European Economic Area infrastructure.
- Supabase — database and application data storage. Established in the United States, with United Kingdom and European Economic Area hosting regions.
Access while travelling
The operator of Thurloe Bancroft may access our systems from outside the United Kingdom while travelling. Because Thurloe Bancroft is a sole trader, such access is by the same legal person who is the controller, rather than a transfer to a separate organisation, and it therefore does not constitute a restricted transfer. Technical controls are maintained regardless: encrypted connections, device security, and access controls on the systems concerned.
Change of provider or region
Providers and hosting regions may change. Any replacement will be selected on the basis that personal data remains within the United Kingdom or the European Economic Area, or is otherwise covered by an appropriate safeguard permitted by UK data protection law. This page will be updated to reflect any material change, and the last updated date at the top will change with it.
How long we keep data
| Record | Retention period | Reason |
|---|---|---|
| Enquiry correspondence | 24 months from the last contact | So that we can pick up a conversation where it left off, and evidence what was said. |
| Subscriber and billing records | Six years after the end of the tax year to which they relate | HMRC requires business records to be kept for at least five years after the 31 January submission deadline for the relevant tax year. |
| Public record data | For as long as we publish the region concerned; superseded versions are kept for up to 24 months | To supply the current dataset, to correct errors, and to show what was supplied and when. |
| Suppression list entries | Indefinitely | A record of an objection is the only reliable way to guarantee that the same details are never reintroduced in a later collection cycle. Deleting it would defeat the objection. |
| Website and security logs | Short periods set by our hosting and network providers | To deliver the site and to detect and prevent attacks against it. |
Keeping a suppression list indefinitely is deliberate and is permitted. It holds the minimum necessary to recognise a record we must not collect again — nothing more — and it is never supplied to subscribers or used for any other purpose.
Your rights
Under the UK GDPR you have the following rights. They apply whether you dealt with us directly or your details reached us through a public register.
- Access. To be told whether we hold personal data about you and to receive a copy of it.
- Rectification. To have inaccurate data corrected and incomplete data completed.
- Erasure. To have your data deleted, in the circumstances the law provides.
- Restriction. To have our use of your data paused while an issue is resolved.
- Portability. To receive data you gave us in a commonly used electronic format, where the processing is based on consent or contract.
- Objection. To object to processing based on legitimate interests, including our compilation of public record data.
- Automated decision-making. Not to be subject to a decision based solely on automated processing that produces a legal or similarly significant effect. We do not carry out automated decision-making of that kind, and we do not profile individuals.
Objecting to direct marketing
In the context of direct marketing, the right to object is absolute. There is no balancing exercise and no exception. Tell us to stop and we stop immediately, and we record the fact so that it does not happen again.
How to exercise a right
Email privacy@thurloebancroft.co.uk. Tell us what you want us to do, and give us enough detail to find the record — for a public register entry, the name and premises address as they appear. We may ask for confirmation of identity where a request concerns data we would not otherwise be able to match to you.
We respond within one month. If a request is unusually complex we may extend that period by up to two further months, and we will tell you if that happens. No fee applies.
Complaints
If you are unhappy with how we have handled your personal data, please tell us first at privacy@thurloebancroft.co.uk. Most problems can be settled quickly, and we would rather hear about it directly.
You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority for data protection. Complaining to us first is not a precondition.
- Helpline
- 0303 123 1113
- Post
- Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Security
This website is served over an encrypted connection, and data held in our systems is transmitted over encrypted connections. Access is limited to the operator of the business and is protected by access controls and, where the provider supports it, multi-factor authentication. Devices used to access the systems are kept up to date and secured.
We hold no payment card details. We keep no personal data for longer than the periods in section 10, because data not held cannot be lost.
We make no claim to hold any security certification, and we do not describe our arrangements as more than they are. No system is entirely secure; if a breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner's Office and, where the law requires, tell you.
Cookies
This website sets only strictly necessary cookies, which is why you have not been shown a consent banner. Our Cookie Policy lists each cookie, says who sets it and why, and explains what would change if we ever introduced measurement tools.
Changes to this notice
This is version 1.0 of this notice. We will update it when our processing changes — for example if we add a data source, a sector, a service provider, or a measurement tool. Material changes are reflected in the last updated date at the top of this page.
Because this page carries the information required by Article 14, it is maintained permanently and publicly, and it will remain available at this address.
This notice describes our own practice. It is not legal advice, and it should not be relied on as a template by anyone else. We recommend that any organisation handling personal data obtains its own independent advice.