Privacy notice
Last updated 9 October 2026 · Version 1.0
This notice explains how Compliance & Data Guard Services handles personal data. It is written to be read, not to be tolerated. If anything in it is unclear, ask and I will explain it.
1. Who I am
Compliance & Data Guard Services is the practice of Ransford Stanley, London, United Kingdom. I am the data controller for the personal data described in this notice.
| Contact | rstanley@compliancedataguardservices.com |
|---|---|
| Telephone | 07586 553272 |
| ICO registration | ZC256438 — verify on the ICO register |
2. This website
This website sets no cookies, uses no analytics, embeds no third-party fonts, scripts, videos or trackers, and asks you to fill in no forms. Nothing you do here is tracked and no profile of you is built.
The site is hosted by Cloudflare, Inc., which processes the IP address of anyone requesting a page in order to deliver it, to protect the site from attack and to keep short-lived security logs. That processing is necessary to run a website at all, and I rely on my legitimate interest in providing a secure and available site. Cloudflare acts as my processor under a data processing agreement, and personal data may be processed outside the UK under the safeguards set out in that agreement.
3. If you contact me
If you email, call or connect with me, I hold your name, contact details, the organisation you represent and what you wrote or said. I use this to reply to you, to discuss a possible instruction, and to keep a record of what was agreed.
My lawful basis is my legitimate interest in responding to enquiries and running my practice, or, where we go on to work together, the performance of our contract.
My email is provided by Google Workspace, which acts as my processor.
4. If you instruct me
Where a client organisation instructs me to carry out an investigation, a review or complaints work, I will handle personal data about people involved in that matter, including parties, witnesses and staff. That data often includes sensitive information, and in investigations it frequently includes special category data such as health information, and data relating to alleged criminal conduct.
Who controls that data
The commissioning organisation decides that an investigation will take place, what is investigated and what happens to the report. For most instructions I therefore act as that organisation's processor, and the organisation's own privacy notice governs the matter. Where an instruction requires me to determine any purpose or means of my own, I will say so in writing at the outset and will act as a joint or independent controller for that element.
How I protect it
- Case material is held in an access-controlled environment with multi-factor authentication and full-disk encryption.
- Material is shared only through channels agreed in writing with the client, never by unencrypted attachment to a general email address.
- Only the data needed for the instruction is collected, and only for as long as the instruction and the agreed retention period require.
- I carry professional indemnity insurance and operate under a written data processing agreement with every client.
5. If you are a party to an investigation
If you have been told that I am investigating a matter involving you, the organisation that commissioned me is responsible for the lawfulness of that investigation and for telling you how your data is used. It should have given you its own privacy information. If it has not, ask it, and tell me — I will raise it.
You are entitled to know what is alleged, to respond to it, and to ask what will happen to your information. Requests to access your data in the investigation should normally go to the commissioning organisation, because it holds the record. If you send such a request to me, I will pass it on promptly and tell you that I have done so.
6. Who else sees your data
| Recipient | Why |
|---|---|
| The commissioning organisation | Delivery of the report or advice it instructed |
| Google (Workspace) | Email and document storage, as my processor |
| Cloudflare | Website hosting and security, as my processor |
| My accountant, insurer and professional advisers | Running the practice and handling any claim |
| Regulators, courts or the police | Only where required by law, or where there is a risk to someone's safety |
I do not sell personal data, share it for marketing, or use it to train any automated or machine learning system.
7. How long I keep it
| Record | Retention |
|---|---|
| Enquiries that do not become instructions | 12 months from last contact |
| Case files and working papers | As agreed with the client in the engagement, normally 6 years from closure, then securely destroyed |
| Contracts and financial records | 6 years, for tax and limitation purposes |
8. Your rights
You have the right to be told how your data is used, to ask for a copy of it, to have it corrected if it is wrong, to ask for it to be deleted, to ask that its use be restricted, to object to its use, and to have it transferred where that applies. Exercising a right is free and I will not treat you any differently for doing so.
Some rights work differently where I act as a processor, or where data forms part of a live investigation. If a right is limited in your case I will tell you which one, why, and who you should approach instead.
To exercise a right, email rstanley@compliancedataguardservices.com. I will respond within one month.
9. Complaints
If you are unhappy with how I have handled your personal data, please tell me. My data protection complaints procedure sets out how I will deal with it and by when.
You can also complain to the Information Commissioner's Office at any time, whether or not you complain to me first. Visit ico.org.uk or call 0303 123 1113. Your right to do so is not affected by anything in this notice.
10. Changes
If I change this notice materially I will update the version and date above, and will tell current clients directly.