Last updated: 15 May 2026
Privacy
Who we are
Biggin Insights Limited is a UK company registered in England and Wales (Company no. 15954534). For the purposes of UK GDPR, we are the data controller for personal information handled through this site and our consulting work.
What we collect, and why
When you book a call through our Cal.com link, you provide your name, email address, and any context you choose to share about the meeting. We use this to confirm and run the call.
When you email us at keith@biggin-insights.com, you provide your name, email address, and whatever you choose to write. We use this to reply.
When you visit the site, we collect basic anonymised analytics: pages viewed, country, device type, referring source. We do not use cross-site tracking cookies and we do not run behavioural advertising.
When you become a client, we hold the contact, billing and engagement information needed to deliver the work and meet our legal obligations as a UK-registered company.
When you subscribe to the email list, we store your email address, subscription status (pending, confirmed, unsubscribed, bounced or complained), the timestamps of those state changes, and which page you subscribed from. We use this only to send confirmation, occasional new-post notifications, and to respect unsubscribe requests.
Newsletter
The email list runs on a double opt-in model: when you submit your address, we send a confirmation link, and only confirmed addresses ever receive a post notification. Every notification email has a one-click unsubscribe link in the footer. Unsubscribed addresses are retained as a suppression entry to prevent re-sending. They are not otherwise used.
The list itself lives in Cloudflare D1 (UK / global edge network); sending is handled by Resend (Delaware, US; DPA at resend.com/dpa).
Lawful basis
We rely on four lawful bases under UK GDPR:
- Legitimate interests: for handling enquiries, running discovery calls, and operating the website
- Consent: for the email subscription list; you can withdraw consent at any time via the one-click unsubscribe link in every email
- Contract: for delivering services to clients
- Legal obligation: for invoicing, accounting, and meeting tax and regulatory requirements
Who we share data with
We use a small number of third-party services to run the practice:
- Cal.com for booking
- Microsoft 365 for email and document storage
- Cloudflare Web Analytics for anonymised site analytics
- Cloudflare D1 for storing the email subscription list
- Resend for sending confirmation and post-notification emails
- Xero for invoicing and bookkeeping
- Compliance platforms such as Drata where engaged for client work
We do not sell personal data, and we do not share it with third parties for marketing purposes.
How long we keep it
Enquiry data is held for up to two years from last contact unless an engagement is established. Client records are kept for the duration of the engagement and for seven years afterwards to meet UK accounting and tax requirements. Site analytics are aggregated and not retained at the individual visit level.
Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion, subject to legal retention requirements
- Object to processing or request restriction
- Data portability where applicable
To exercise any of these rights, email keith@biggin-insights.com.
If you believe we have not handled your data appropriately, you have the right to complain to the Information Commissioner's Office at ico.org.uk.
International transfers
Some of our service providers may process data outside the UK. Where that happens, transfers are made under appropriate safeguards, including UK-approved Standard Contractual Clauses and equivalent mechanisms.
Changes
We update this policy occasionally to reflect how we operate. The "Last updated" date at the top tells you when it was last revised.
Contact
For any questions about this policy or how we handle your data:
keith@biggin-insights.com
Biggin Insights Limited