Legal
Privacy Policy
Last updated: 17 September 2026
Pharos IX Limited (Pharos IX, we, us or our) helps businesses improve how they operate, scale and perform. This notice explains how we collect and use personal information through pharosix.co.uk, enquiries, marketing and our PIQ assessment, blueprint, delivery and strategic partnership services. It also explains your choices and rights.
1Who we are and how to contact us
Pharos IX Limited (Pharos IX, we, us or our) helps businesses improve how they operate, scale and perform. This notice explains how we collect and use personal information through pharosix.co.uk, enquiries, marketing and our PIQ assessment, blueprint, delivery and strategic partnership services. It also explains your choices and rights.
Our registered address is Level One, Basecamp Liverpool 49, Jamaica Street, Liverpool, Merseyside, England, L1 0AH. For privacy questions, rights requests or complaints, email [email protected] or write to us at this address.
We are the controller where we decide why and how your personal information is used, including managing enquiries and business relationships. Where we process information solely on a client's instructions, that client is the controller and their privacy notice applies to that processing. We assist them with privacy requests. Our agreement must identify these responsibilities; receiving a client document does not automatically make us its controller.
2Information we collect
We collect names, job roles, business contact details, company information, enquiry answers, correspondence and commercial records needed for the relationship. Information about a company, such as aggregate employee numbers, is personal information only where it relates to an identifiable person.
During engagements, we may receive interview and meeting notes, transcripts, relevant personal information in client documents, and assessment evidence or reports. These may contain the views or actions of identifiable employees and other business contacts. We do not routinely request personnel files or sensitive personal information.
Please remove unnecessary personal details from documents before sharing them. Do not send health information, other special category information or criminal offence information unless we have expressly agreed a necessary and lawful arrangement. If unnecessary sensitive information reaches us, we restrict access and arrange its deletion or redaction as appropriate.
3Where information comes from
We receive information directly from you through our website, email, calls, meetings, networking and social media. We may also obtain relevant business contact information from your organisation, referrals, company websites, Companies House and publicly available professional profiles. Public availability does not remove your privacy rights.
When we collect information indirectly, we tell you about our use and its source within the applicable legal timescale, normally no later than one month and sooner at our first communication or disclosure, unless a lawful exception applies. You can ask us which source we used.
4Why we use information and our lawful bases
Enquiries and business relationships: we use contact details, enquiry answers and correspondence to assess service fit, respond, prepare proposals and administer engagements. Our legitimate interests are communicating with business contacts and providing relevant services. Where you personally enter a contract with us, we use the contract basis for necessary contractual or requested pre-contractual steps; a contract with your employer alone is not that basis for your information.
Client services and quality assurance: where acting as controller, we use relevant interview material, documents and evidence for our legitimate interests in delivering accurate assessments, recommendations and services, checking quality and substantiating our work. We consider the effect on the people concerned and limit information to what is necessary. Where acting as processor, we follow the client's lawful documented instructions instead.
Marketing: our legitimate interests support proportionate business development where legally permitted. We obtain consent where the rules require it. Section 5 explains your choices.
Business administration and protection: we use necessary financial and contractual records to meet accounting and tax obligations, and relevant records for our legitimate interests in security, preventing misuse, resolving disputes and establishing or defending legal claims. We use information to comply with legal duties relating to privacy requests and complaints.
Where we rely on legitimate interests, we assess necessity and balance our interests against your rights. You may object. Where we rely on consent, you may withdraw it at any time without affecting earlier lawful processing. We do not treat submitting an enquiry as consent to unrelated marketing.
5Marketing and your choices
We develop business through outbound and inbound enquiries, social media, networking and advertisements. We use relevant business contact information for direct marketing only where permitted, including any consent required for the channel and recipient. Public contact details are not automatically permission to market to you.
You can object to direct marketing at any time, including related profiling, by emailing [email protected] or using an unsubscribe option in the message. We stop that use and keep only the suppression details needed to respect your choice. Necessary service communications may continue. Social media platforms also process information under their own privacy notices.
6Who receives information
Access is limited to people who need information for the relevant purpose. This may include our authorised personnel and delivery or quality assurance support, subject to appropriate confidentiality and data protection arrangements. Relevant engagement findings are shared with authorised client recipients; interview information is not automatically anonymous, so we explain any agreed confidentiality arrangements before participation.
We use GoDaddy for email and GoDaddy Airo for our website. Providers operating these services may process the information transmitted or stored through them. We may also disclose necessary information to IT support, professional advisers, accountants, insurers, and authorities or courts where required or justified. A website designer's access must be limited to what is necessary for the agreed work.
We do not sell personal information. We do not publish identifiable client material as a case study or testimonial without the necessary permission and lawful basis.
7Storage, security and international processing
Our bespoke CRM is offline and our company file system is on the local network at our offices. Email and website information also passes through external services, so not all processing is confined to our offices or necessarily to the UK.
Where a provider processes information outside the UK, an applicable UK adequacy arrangement or appropriate safeguards, such as approved transfer terms and any necessary additional measures, must protect the transfer. Contact us for details of relevant processing locations and safeguards or a copy of the safeguards, subject to necessary redactions.
We use proportionate organisational and technical measures to protect information and restrict access. No storage or transmission method can be guaranteed completely secure. Please contact us if you suspect that information shared with us has been compromised.
8How long we retain information
Our default retention period is six years. For client records, this runs from completion or termination of the relevant engagement. For enquiries and leads that do not become clients, it runs from the last meaningful interaction; if there has been no interaction, it runs from collection. Sending repeated unanswered marketing messages does not restart that period. For other business records, it runs from completion of the relevant transaction or closure of the matter.
This default supports continuity of service, accountability and the handling of potential claims. It is not a requirement to keep everything for six years. We review necessity and delete or anonymise irrelevant, excessive or no-longer-needed information sooner, including unnecessary copies, raw material and technical records. We also consider valid deletion requests during this period.
We may retain relevant information for longer where a specific legal obligation requires it or an active dispute or legal claim makes it necessary. We restrict its use and review that need. Minimal marketing suppression records may be retained for as long as needed to prevent unwanted contact.
Information processed solely on a client's behalf follows the agreed return or deletion instructions, subject to applicable law, rather than automatically following our six-year default. Information removed from active systems may remain temporarily in protected backups until normal overwrite or deletion; it is not reused for ordinary purposes, and deletion must be reapplied if a backup is restored.
9Website forms, cookies and new tools
Our guided enquiry form collects the answers and contact information you submit to help us respond and recommend next steps. Required fields will be identified. You can choose not to provide information, but missing contact details or relevant business information may prevent us from answering or assessing an enquiry. Please do not include sensitive information about yourself or anyone else.
Website providers may process technical information, such as an IP address and browser or device details, to deliver and protect the site. Any use of cookies, analytics or advertising technologies must be explained in the website's cookie information, including their purpose, duration and available choices. Where consent is required, those technologies must not operate before you choose to allow them.
We will update the relevant privacy information before introducing new AI or other tools that change how personal information is processed, and assess the necessary safeguards before use. This notice does not authorise undisclosed recording or transcription. Before recording or transcribing a meeting, we explain the purpose, method, access and applicable lawful basis, and obtain permission where required.
10Your data protection rights
Depending on the circumstances, you can ask to access your personal information, correct inaccuracies, erase information, restrict its use or receive and transfer information under the right to data portability. These rights have conditions and lawful exceptions; we will explain any restriction we apply.
You can object to processing based on legitimate interests. Your right to object to direct marketing is absolute. You can also withdraw consent where that is our basis. Withdrawal does not affect processing that was lawful before withdrawal.
We do not use solely automated decisions that produce legal or similarly significant effects about you under the processing described in this notice. Service recommendations and assessment judgements involve human consideration.
Contact [email protected] to exercise your rights. There is normally no fee. We may ask for proportionate information to verify identity or clarify a request. We respond without undue delay and normally within one month, subject to permitted timing rules. If a lawful extension or exception applies, we explain it. Where we hold information solely for a client, we help route your request to the responsible controller.
11How to complain
Please send a data protection complaint to [email protected], or write to our registered address, explaining your concern and how we can contact you. We acknowledge complaints within 30 days, investigate without undue delay and inform you of progress and the outcome. This acknowledgement period does not replace the separate deadline for a rights request.
You also have the right to complain to the Information Commissioner's Office, the UK data protection regulator. Visit ico.org.uk/make-a-complaint for current routes and guidance. Contacting us first can help resolve the issue, but this does not remove your right to approach the ICO.
12Changes to this notice
We review this notice when our processing changes and periodically to keep it accurate. The published notice shows its latest update date. Where a change affects how we use your information, we provide appropriate information before the new processing starts and obtain consent where required.
For privacy questions or rights requests, email [email protected] or write to Pharos IX Limited, Level One, Basecamp Liverpool 49, Jamaica Street, Liverpool, Merseyside, England, L1 0AH.
Effective date: 17 September 2026. Next review: 17 September 2027.