Privacy Policy
Last revised 1 July 2026
Hawthorne Ads Ltd ("Hawthorne", "we", "us", "our") is responsible for personal data belonging to visitors to this website, people who enquire about our services, our clients and suppliers, and candidates who apply to join us. This policy explains what we collect, why, how long we keep it and what rights you have.
For the purposes of the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018, Hawthorne Ads Ltd is the data controller for the processing described in this policy.
Contents
1. Who we are, and when we act as a processor
Hawthorne Ads Ltd is registered in Scotland under company number SC000000, with its registered office at 19 Charlotte Square, Edinburgh, EH2 4DF, United Kingdom.
Much of our work involves handling data belonging to our clients' customers — order records, purchase histories and advertising audiences. In all of that work we act as the client's data processor. The retailer is the controller, its own privacy notice governs the processing, and we operate under a written data processing agreement that meets Article 28 of the UK GDPR and covers confidentiality, approved sub-processors, security measures, international transfers, assistance with data subject requests, breach notification and deletion on termination.
If you shopped with a retailer and want to exercise your data rights, please contact that retailer directly — they are the controller of your data. If you contact us, we will pass your request to them promptly and confirm to you that we have done so, but we cannot act on it ourselves.
2. What we collect
Data you provide
- Enquiry data — name, company, work email, telephone number, turnover and SKU-count bands, the nature of your requirement and the content of your message.
- Client records — contact details for your team, contracts, commercial terms, correspondence and billing information.
- Supplier records — contact and payment details for freelancers, contractors and vendors.
- Recruitment data — CV, work history, task-exercise submissions, interview notes and references.
- Subscription data — name, company and email address where you subscribe to our retail trading briefing.
Data collected automatically
- Technical data — IP address, browser and device type, operating system and approximate region.
- Usage data — pages viewed, referring page, links clicked and time on page.
Beyond strictly necessary cookies, automatic collection happens only with your consent. See our Cookie Policy.
Commercially sensitive client data
In the course of our work we receive cost of goods, margin and supplier information. This is commercially sensitive rather than personal data, and we treat it under strict confidentiality: access is restricted to named individuals on the account, it is held in a segregated environment, and it is returned or destroyed on request.
3. Purposes and lawful bases
| Purpose | Data | Lawful basis |
|---|---|---|
| Replying to enquiries and preparing proposals | Enquiry data | Legitimate interests — acting on your request |
| Delivering services under contract | Client records | Performance of a contract |
| Managing suppliers and contractors | Supplier records | Performance of a contract; legal obligation |
| Invoicing, credit control and statutory accounts | Billing data | Legal obligation |
| Sending our retail trading briefing | Name, company, email | Consent, or PECR soft opt-in for existing contacts |
| Understanding how this website is used | Technical and usage data | Consent |
| Recruitment | Application data | Legitimate interests; legal obligation |
| Security, fraud prevention and enforcing our terms | Technical data, logs | Legitimate interests |
Where we rely on legitimate interests we have documented a balancing assessment and will provide a summary on request.
4. Who we share data with
We do not sell personal data. We disclose it to: processors providing our website hosting, email, CRM, data warehouse, product feed management and finance systems, each under written contract and subject to security due diligence; advertising and analytics providers where you have consented to the relevant cookies; our accountants, auditors, insurers and legal advisers; regulators, courts and law enforcement where legally required; and a successor entity in the event of a sale or reorganisation, subject to confidentiality undertakings. A current list of our sub-processors is available to clients on request.
5. International transfers
Our core systems are hosted in the United Kingdom and the European Economic Area. Where a provider processes data elsewhere — principally the United States — we rely on a UK adequacy regulation (including the UK Extension to the EU–US Data Privacy Framework), the International Data Transfer Agreement, or the UK Addendum to the European Commission's Standard Contractual Clauses, each supported by a documented transfer risk assessment. Details of the mechanism applying to a specific transfer are available on request.
6. Retention periods
| Record | Period |
|---|---|
| Enquiries that do not proceed | 24 months from last contact |
| Client contracts and account records | 7 years after the engagement ends |
| Cost of goods and margin data | Returned or destroyed within 30 days of termination |
| Accounting and tax records | 7 years (HMRC requirement) |
| Trading briefing subscribers | Until you unsubscribe, plus 12 months suppression |
| Unsuccessful applications | 12 months |
| Website analytics | 14 months |
| Access and security logs | 13 months |
Client customer data we process as processor is deleted or returned per the relevant data processing agreement, normally within 30 days of termination.
7. Security
Our measures include TLS encryption in transit and encryption at rest, single sign-on with enforced multi-factor authentication, role-based least-privilege access reviewed quarterly, segregated per-client environments for commercially sensitive data, centrally managed encrypted devices, secrets management, peer review of changes to client systems, annual penetration testing of internet-facing systems, documented supplier assessment and annual security training. We maintain a written incident response plan and will notify the Information Commissioner's Office of a notifiable personal data breach within 72 hours of becoming aware of it, informing affected individuals directly where the risk to them is high.
8. Your rights
You have the rights to be informed, of access, to rectification, to erasure, to restriction of processing, to data portability, to object to processing based on legitimate interests, to object to direct marketing at any time, and to withdraw consent where consent is our lawful basis. We do not carry out solely automated decision-making that produces legal or similarly significant effects on individuals.
Email [email protected] with "Data rights request" in the subject line, or write to us at the address in section 12. We respond within one calendar month and will tell you if a complex request requires up to two further months. There is no charge unless a request is manifestly unfounded or excessive.
Please raise any concern with us first so we can put it right. You also have the right to complain to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF — 0303 123 1113, ico.org.uk.
9. Cookies
Non-essential cookies are set only with your consent. Full detail, including provider and duration for each cookie, is in our Cookie Policy.
10. Marketing
Our monthly retail trading briefing is sent only to people who asked for it, and to existing business contacts in reliance on the soft opt-in permitted by the Privacy and Electronic Communications Regulations 2003 for closely related services. Every message contains a working one-click unsubscribe link, honoured immediately. We never share or sell our subscriber list.
11. Children
This is a business-to-business website and is not directed at children. We do not knowingly collect personal data about anyone under 18 through it. Where a client's products or campaigns are directed at children or young people, we apply the CAP Code restrictions and the ICO's Age Appropriate Design Code in our planning and audience work.
12. Changes and contact
We review this policy annually and whenever our processing changes materially. The date at the head of the page identifies the current version.
Hawthorne Ads Ltd
Data Protection
19 Charlotte Square
Edinburgh, EH2 4DF, United Kingdom
Email [email protected]