Skip to content
Thurloe Bancroft
  • What We Do
  • The Thurloe Index
  • Openings Report
  • Coverage
  • Enquiries
  1. Home
  2. Privacy Policy

Legal

Privacy Policy

Last updated: 21 August 2026 · Version 1.0

This notice explains what personal data Thurloe Bancroft holds, where it comes from, why we hold it, and what you can do about it. It covers both people who deal with us directly and people whose details appear in the public registers we compile.

Contents

  1. 1Who we are
  2. 2Scope of this notice
  3. 3Data about customers and enquirers
  4. 4Personal data in public records
  5. 5Where public record data comes from
  6. 6Our lawful bases
  7. 7If we did not obtain your data from you
  8. 8Who we share data with
  9. 9International transfers
  10. 10How long we keep data
  11. 11Your rights
  12. 12Complaints
  13. 13Security
  14. 14Cookies
  15. 15Changes to this notice

1Who we are

Thurloe Bancroft is the trading name of [FULL NAME TO BE INSERTED], who operates the business as a sole trader in the United Kingdom. Thurloe Bancroft is not a limited company. The business is run by an individual, and that individual is personally responsible for the personal data described in this notice.

We are the controller of that data for the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Controller means the person who decides why and how personal data is processed.

Controller
[FULL NAME TO BE INSERTED], trading as Thurloe Bancroft
Email
privacy@thurloebancroft.co.uk
Postal address
[ADDRESS TO BE INSERTED]
ICO registration
[ICO REGISTRATION NUMBER TO BE INSERTED]

We have not appointed a data protection officer. We are not required to appoint one, and enquiries should be sent to the email address above.

Back to top

2Scope of this notice

This notice covers two groups of people. They are treated differently, because their relationship with us is different.

Group A — people who deal with us directly

Enquirers, subscribers, and visitors to this website. If you have contacted us, taken a subscription, or simply loaded this page, you are in this group. You, or your browser, provided the information we hold. Section 3 sets out what that information is.

Group B — people named in the public records we compile

Individuals whose details appear in a statutory register that a public authority is required by law to publish, and which we compile and supply to business subscribers. If you are in this group, you gave us nothing and you have probably never heard of us. section 4, section 5 and section 7 are the ones that concern you.

If you are in Group B and want your details removed from our data, go straight to section 7. We act on those requests without asking for a reason.

Back to top

3Personal data we collect about customers and enquirers

This section applies to Group A. We collect only what we need to answer an enquiry, provide a subscription, and keep proper business records.

Data we hold about customers and enquirers
Category What it includes
Identity and contact details Name, business name, job title, business email address, business telephone number, and business postal address.
Correspondence Emails you send us, our replies, and notes of telephone calls, including the substance of an enquiry.
Subscription records The regions and services subscribed to, start and renewal dates, delivery preferences, and the record of data supplied.
Billing records Invoices, payment references, and the record of payments received. Card details are handled by our payment processor and are never held by us.
Technical information Information generated when a browser requests a page, such as an IP address, the time of the request, and the browser and device type. This is processed by our hosting and network providers to deliver the site and to protect it from attack.

What we do not collect

  • No special category data — nothing about health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetics, biometrics, sex life or sexual orientation.
  • No data relating to children. Our services are sold to businesses and this website is not directed at children.
  • No payment card numbers. Card details are entered with our payment processor and are not passed to us.

Measurement of website use

We may collect aggregated technical and usage information about visits to this website — for example how many times a page is requested — in order to understand how the site is used and to keep it available and secure. Where such information is collected in a way capable of identifying an individual, it is processed on the basis of consent or legitimate interests, as appropriate to the method used. Any tool in use for this purpose is identified in our Cookie Policy. At the date of this notice, no analytics, heatmap or session-recording tool is in use on this website.

Back to top

4Personal data contained in public records

This section applies to Group B, and it is the part of our processing that matters most.

Our services are compiled from information published by local authorities in statutory public registers. In relation to premises licensing, the particulars we compile may include:

  • the name of the applicant
  • the name and address of the premises to which the application relates
  • the application reference number allocated by the authority
  • the type of application, and the activities applied for
  • relevant dates, such as the date the application was made or advertised
  • the licensing authority holding the register

In most cases the applicant is a company, and information about a company is not personal data. In some cases the applicant is a named individual — a sole trader, or a member of a partnership. Where an individual is named, that information is personal data, and this notice applies to it. The address recorded is the address of the premises, which for some businesses is also a home address.

We do not collect or retain documents submitted in support of an application, operating schedules, plans, drawings, photographs, correspondence between an applicant and an authority, or any special category data that may incidentally appear in a register. Where such material appears, we do not copy it.

Back to top

5Where we obtain public record data

The data comes from public registers maintained by local licensing authorities. Those authorities are required by statute to keep such registers and to make them available for public inspection, so that the public may be informed of applications affecting them.

We consult those registers in the same way as any other member of the public. We do not obtain information by private, covert or unauthorised means, we do not use information given to us in confidence, and we do not buy personal data from data brokers.

The authorities currently within our coverage are listed on our Data Protection and Data Sources page, which also explains our method in more detail.

Back to top

6Our lawful bases

We must have a lawful basis for each purpose for which we process personal data. Ours are set out below.

Purpose and lawful basis
Purpose Lawful basis
Compiling public record information and supplying it to business subscribers Legitimate interests
Providing our services to subscribers and administering their account Performance of a contract
Direct marketing to business contacts Legitimate interests, subject to the Privacy and Electronic Communications Regulations (PECR)
Meeting our legal, tax and regulatory obligations Legal obligation
Responding to enquiries Legitimate interests

What our legitimate interests are

  • Compiling and supplying public record information. Our interest, and our subscribers' interest, in making practical use of information that Parliament has required to be published. The information is already public, is limited to the factual particulars of an application, and is supplied only to business subscribers for business purposes. Against that we weigh the interests of any individual named, which is why removal is available on request, without conditions.
  • Direct marketing to business contacts. Our interest in offering a business service to organisations likely to have a use for it, using business contact details. This is always subject to PECR, and to the absolute right to object described in section 11.
  • Responding to enquiries. Our interest, and yours, in being able to answer a question you have asked.

We have carried out a Legitimate Interests Assessment for each of these purposes, weighing our interest against the interests, rights and freedoms of the individuals concerned. A copy is available on request, and to any regulator without request.

Back to top

7If we did not obtain your data from you

This section is provided under Article 14 of the UK GDPR, which requires that people are told when their personal data has been obtained from a source other than themselves. It applies to individuals named in the public registers we compile.

Why you are reading this rather than hearing from us directly

We obtain the data from publicly accessible statutory registers, in volume, as those registers are published. Writing to each individual named would involve disproportionate effort within the meaning of Article 14(5)(b): it would require us to obtain contact details that the registers do not give us and that we would not otherwise seek, and to send unsolicited messages to people who have not asked to hear from us. Article 14 permits us instead to make this information publicly available. That is what this page is. It is published permanently, without restriction, and without any requirement to register or ask.

The information Article 14 requires us to give you

  • Who holds the data. [FULL NAME TO BE INSERTED], trading as Thurloe Bancroft. Contact details are in section 1.
  • The categories of personal data concerned. The name of an applicant, the name and address of the premises applied for, the application reference, the type of application and activities applied for, and the relevant dates. These are set out in full in section 4.
  • The source of the data. Public registers maintained by local licensing authorities and published by those authorities for public inspection under statutory duty. The data is not obtained from you, from any private source, or from a data broker.
  • The purpose of the processing. To compile a structured, verified record of new licence applications by region, and to supply it to business subscribers who serve those premises.
  • The lawful basis. Legitimate interests, as explained in section 6.
  • Who receives the data. Our business subscribers, and the service providers listed in section 8 who host and store it on our behalf.
  • How long we keep it. As set out in section 10.
  • Your rights. Access, rectification, erasure, restriction, portability, and objection — including an absolute right to object to direct marketing. These are set out in section 11.
  • Your right to complain. You may complain to the Information Commissioner's Office at any time. See section 12.

How to have your data removed

Email privacy@thurloebancroft.co.uk with the name and premises address as they appear, and ask us to remove them.

You do not need to give a reason, and we will not ask for one. We act on removal requests promptly, and in any event within one month, which is the period allowed by law. There is no charge.

Once removed, the entry is added to a suppression list — a permanent record of the objection, held so that the same details are not collected again in a future cycle. The suppression list holds the minimum necessary to recognise the record, is never supplied to subscribers, and is used for no other purpose. This is explained further in section 10.

Back to top

8Who we share data with

Compiled register data is supplied to our business subscribers, on terms that require them to comply with data protection and electronic marketing law in their own use of it. Beyond that, personal data is shared only with the service providers we use to run the business, and with professional advisers or public authorities where the law requires it.

We name our providers rather than describing them in categories, because you are entitled to know who holds your data.

Service providers
Provider Role Corporate establishment
Hostinger Website hosting Lithuania (European Economic Area)
Cloudflare DNS, content delivery, network security and bot management United States, with United Kingdom and European Economic Area infrastructure
Supabase Database and application data storage United States, with United Kingdom and European Economic Area hosting regions
[PAYMENT PROCESSOR TO BE INSERTED] Payment processing and handling of card details [TO BE INSERTED]
Professional advisers Accountancy and, where required, legal advice United Kingdom

Each provider acts as a processor on our instructions under a written data processing agreement, except where a provider is a controller in its own right for its own limited purposes, such as a payment processor meeting its own regulatory obligations.

We do not sell personal data to advertisers. We do not supply data for consumer marketing purposes. We do not enrich our records with data obtained from third-party data brokers.

Back to top

9International transfers

Where data is stored

All personal data we hold is stored and processed within the United Kingdom and the European Economic Area. The specific hosting region within that footprint may change from time to time for performance and resilience reasons.

Adequacy

Transfers of personal data from the United Kingdom to countries in the European Economic Area are permitted under UK adequacy regulations. No additional transfer safeguard is required for them. This is why the arrangement is straightforward: the data stays inside a footprint the United Kingdom has already recognised as providing an adequate level of protection.

Providers established outside the United Kingdom and the EEA

Some of our providers are corporately established in the United States even though the infrastructure serving Thurloe Bancroft is located in the United Kingdom or the European Economic Area. Limited access from outside the UK and the EEA may occur for support, security and maintenance purposes. Where such access amounts to a restricted transfer, it is governed by the UK International Data Transfer Addendum to the European Commission's standard contractual clauses, or by applicable adequacy regulations, as incorporated in each provider's data processing agreement.

The providers we use

  • Hostinger — website hosting. Established in Lithuania, within the European Economic Area.
  • Cloudflare — DNS, content delivery, network security and bot management. Established in the United States, with United Kingdom and European Economic Area infrastructure.
  • Supabase — database and application data storage. Established in the United States, with United Kingdom and European Economic Area hosting regions.

Access while travelling

The operator of Thurloe Bancroft may access our systems from outside the United Kingdom while travelling. Because Thurloe Bancroft is a sole trader, such access is by the same legal person who is the controller, rather than a transfer to a separate organisation, and it therefore does not constitute a restricted transfer. Technical controls are maintained regardless: encrypted connections, device security, and access controls on the systems concerned.

Change of provider or region

Providers and hosting regions may change. Any replacement will be selected on the basis that personal data remains within the United Kingdom or the European Economic Area, or is otherwise covered by an appropriate safeguard permitted by UK data protection law. This page will be updated to reflect any material change, and the last updated date at the top will change with it.

Back to top

10How long we keep data

Retention periods
Record Retention period Reason
Enquiry correspondence 24 months from the last contact So that we can pick up a conversation where it left off, and evidence what was said.
Subscriber and billing records Six years after the end of the tax year to which they relate HMRC requires business records to be kept for at least five years after the 31 January submission deadline for the relevant tax year.
Public record data For as long as we publish the region concerned; superseded versions are kept for up to 24 months To supply the current dataset, to correct errors, and to show what was supplied and when.
Suppression list entries Indefinitely A record of an objection is the only reliable way to guarantee that the same details are never reintroduced in a later collection cycle. Deleting it would defeat the objection.
Website and security logs Short periods set by our hosting and network providers To deliver the site and to detect and prevent attacks against it.

Keeping a suppression list indefinitely is deliberate and is permitted. It holds the minimum necessary to recognise a record we must not collect again — nothing more — and it is never supplied to subscribers or used for any other purpose.

Back to top

11Your rights

Under the UK GDPR you have the following rights. They apply whether you dealt with us directly or your details reached us through a public register.

  • Access. To be told whether we hold personal data about you and to receive a copy of it.
  • Rectification. To have inaccurate data corrected and incomplete data completed.
  • Erasure. To have your data deleted, in the circumstances the law provides.
  • Restriction. To have our use of your data paused while an issue is resolved.
  • Portability. To receive data you gave us in a commonly used electronic format, where the processing is based on consent or contract.
  • Objection. To object to processing based on legitimate interests, including our compilation of public record data.
  • Automated decision-making. Not to be subject to a decision based solely on automated processing that produces a legal or similarly significant effect. We do not carry out automated decision-making of that kind, and we do not profile individuals.

Objecting to direct marketing

In the context of direct marketing, the right to object is absolute. There is no balancing exercise and no exception. Tell us to stop and we stop immediately, and we record the fact so that it does not happen again.

How to exercise a right

Email privacy@thurloebancroft.co.uk. Tell us what you want us to do, and give us enough detail to find the record — for a public register entry, the name and premises address as they appear. We may ask for confirmation of identity where a request concerns data we would not otherwise be able to match to you.

We respond within one month. If a request is unusually complex we may extend that period by up to two further months, and we will tell you if that happens. No fee applies.

Back to top

12Complaints

If you are unhappy with how we have handled your personal data, please tell us first at privacy@thurloebancroft.co.uk. Most problems can be settled quickly, and we would rather hear about it directly.

You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority for data protection. Complaining to us first is not a precondition.

Website
ico.org.uk/make-a-complaint (opens in a new tab)
Helpline
0303 123 1113
Post
Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

Back to top

13Security

This website is served over an encrypted connection, and data held in our systems is transmitted over encrypted connections. Access is limited to the operator of the business and is protected by access controls and, where the provider supports it, multi-factor authentication. Devices used to access the systems are kept up to date and secured.

We hold no payment card details. We keep no personal data for longer than the periods in section 10, because data not held cannot be lost.

We make no claim to hold any security certification, and we do not describe our arrangements as more than they are. No system is entirely secure; if a breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner's Office and, where the law requires, tell you.

Back to top

14Cookies

This website sets only strictly necessary cookies, which is why you have not been shown a consent banner. Our Cookie Policy lists each cookie, says who sets it and why, and explains what would change if we ever introduced measurement tools.

Back to top

15Changes to this notice

This is version 1.0 of this notice. We will update it when our processing changes — for example if we add a data source, a sector, a service provider, or a measurement tool. Material changes are reflected in the last updated date at the top of this page.

Because this page carries the information required by Article 14, it is maintained permanently and publicly, and it will remain available at this address.

Back to top

This notice describes our own practice. It is not legal advice, and it should not be relied on as a template by anyone else. We recommend that any organisation handling personal data obtains its own independent advice.

Data Protection Cookie Policy Terms of Use Back to top
Thurloe Bancroft
  • The Thurloe Index
  • Openings Report
  • Privacy Policy
  • Data Protection
  • Cookies
  • Terms of Use
  • Enquiries

© 2026 Thurloe Bancroft. All rights reserved.

ICO registration number: [TO BE INSERTED]