KRATOSYN LIMITED

Legal

Privacy Policy & Cookie Notice

Kratosyn Limited is committed to protecting your personal data and being transparent about how we use it. This policy explains your rights and our responsibilities under the UK GDPR and the Data Protection Act 2018.

Company

Kratosyn Limited

last updated

July 2026

Contact

info@kratosyn.co.uk

registered in

England & Wales

Table of Contents

01

Who we are

Kratosyn Limited is committed to protecting your personal data and being transparent about how we use it. This policy explains your rights and our responsibilities under the UK GDPR, the Data Protection Act 2018, and the Data (Use and Access) Act 2025.

Kratosyn Limited is the data controller responsible for your personal data. We are a specialist HR consultancy providing services to businesses and professionals across the UK, India and APAC.

Contact: info@kratosyn.co.uk  |  Website: kratosyn.co.uk

We are registered with the Information Commissioner’s Office (ICO) as a data controller. Our ICO registration number is ZC125255

Company No. 17157687 

Company Address : 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ

02

What data we collect

When you contact us through our website, enquiry form, or directly by email or phone, we may collect:

Full Name

Email address

Phone number

Company name

Job title

Number of employees

Your enquiry details

IP address (via website)

We only collect data necessary for the purpose for which it is provided. We do not collect special category (sensitive) personal data unless you voluntarily share it as part of a coaching or HR engagement.

03

Why we collect it & our legal basis

We process your personal data for the following reasons:

To respond to enquiries — Legal basis: Legitimate interests. When you contact us, we have a legitimate interest in responding to you.

To deliver our services — Legal basis: Performance of a contract. When you engage Kratosyn, we process your data to fulfil our contractual obligations.

To comply with legal obligations — Legal basis: Legal obligation. We may need to retain certain records to comply with employment law, tax law, or other applicable regulations.

To improve our website — Legal basis: Legitimate interests. We may use anonymised analytics data to understand how our website is used.

04

How long we keep your data

Enquiries that do not lead to an engagement: We retain contact details for up to 2 years, after which they are securely deleted.

Active and past clients: We retain records for 6 years from the end of the engagement, in line with standard UK business record-keeping requirements.

Financial and contractual records: Retained for 7 years as required by HMRC guidelines.

05

Who we share your data with

We do not sell, rent, or trade your personal data. We only share your data in the following limited circumstances:

Service providers: We may share data with trusted tools we use to operate our business (such as email platforms or scheduling software). These providers act as data processors and are bound by data processing agreements.

Legal requirement: We may disclose your data where required by law, court order, or regulatory authority.

We do not transfer your personal data outside of the UK without ensuring appropriate safeguards are in place.

06

Your rights

Under UK GDPR, you have the following rights:

  • Right of access — request a copy of the personal data we hold about you
  • Right to rectification — ask us to correct inaccurate or incomplete data
  • Right to erasure — ask us to delete your data in certain circumstances
  • Right to restriction — ask us to limit how we use your data
  • Right to data portability — receive your data in a structured, machine-readable format
  • Right to object — object to processing based on legitimate interests

To exercise any of these rights, email info@kratosyn.co.uk. We will respond within 30 days.

07

Cookie notice

Our website uses cookies — small text files stored on your device. Here is what we use and why:

Cookie Type Purpose Can You Opt Out
Essential
Required for the website to function (e.g. form submissions, security). Cannot be disabled.
No. It’s Necessary
Analytical
We may use Google Analytics to understand how visitors use our site. All data is anonymised.
Yes. via cookie banner
Preference
Remembers your cookie choices on return visits.
Yes. via cookie banner

You can manage or withdraw your cookie consent at any time by clicking “Cookie settings” in the footer of our website, or by adjusting your browser settings.

08

Data Protection Complaints

Under the Data (Use and Access) Act 2025, you have a statutory right to raise data protection concerns directly with us. We are required to operate a formal complaints process
 

If you are unhappy with how we have handled your personal data, please follow the process below:

Step 1 — Contact us directly: Email your complaint to info@kratosyn.co.uk with the subject line “Data Protection Complaint”. Please describe your concern clearly, including any relevant dates or reference numbers.

Step 2 — Acknowledgement: We will acknowledge receipt of your complaint within 30 days of receiving it. We will confirm who is handling your complaint and the next steps.

Step 3 — Investigation: Our designated Data Privacy contact will investigate your complaint promptly and keep you informed throughout the process.

Step 4 — Outcome: We will notify you of the outcome of our investigation without undue delay, along with any remedial action taken.

Step 5 — Escalation: If you are not satisfied with our response, or if we have not responded within a reasonable timeframe, you may escalate your complaint to the Information Commissioner’s Office (ICO):

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) the UK’s data protection regulator.

Website: ico.org.uk  |  Helpline: 0303 123 1113

We maintain a confidential record of all data protection complaints received, including dates, the nature of each complaint, our investigation steps, and the outcome. This log is retained for internal governance and audit purposes.

09

security

We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure, including secure email, access controls, and regular review of our data practices.

10

AI & Automated Processing

Where we use artificial intelligence tools to assist with the processing of personal data (for example, in HR analytics, candidate screening, or service delivery), we will ensure this is disclosed in our communications with you. We will explain what data is used, the purpose of the AI processing, and any significant decisions that may affect you.

We do not make solely automated decisions that produce legal or similarly significant effects without human oversight.

11

Changes to this policy

We may update this policy from time to time. The date at the top of this page will always reflect the most recent version. We encourage you to review it periodically.