Privacy Policy
This policy explains how PNM CONSULTANTS LIMITED handles personal data when you enquire about our services, when we act for you under contract, and when we process personal data held inside your own systems on your behalf.
Last updated: 14 September 2026
1. Who we are
PNM CONSULTANTS LIMITED ("PNM Consultants", "we", "us") is a company registered in England and Wales under company number 17207074. Our registered office is 17 Wiley House Mill Road, Gillingham, Kent, United Kingdom, ME7 1HZ.
We provide combined office administrative service activities (SIC 82110) to businesses in the United Kingdom, delivered remotely under contract.
You can reach us by email at [email protected], by telephone on +44 7481 226905, or by post at the registered office above.
This policy is governed by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Controller and processor roles
We act in two distinct roles, and it matters which one applies:
- Controller. For data about our own enquirers, clients and their staff contacts — the information we need to quote, contract, invoice and correspond — we decide the purposes and means of processing, so we are the controller.
- Processor. When we work inside a client's mailboxes, systems and documents, we process personal data belonging to that client's employees, suppliers, contractors and customers. In that work the client is the controller and we are the processor, acting only on the client's documented instructions.
Our processing on a client's behalf is governed by a written agreement meeting the requirements of Article 28 UK GDPR. That agreement covers: processing only on documented instructions; a confidentiality obligation on every member of our personnel with access; engagement of sub-processors only with the client's authorisation; assistance with data subject requests and with security, breach notification and impact assessments; notification of personal data breaches without undue delay; and return or deletion of the data at the end of the contract, at the client's choice.
3. Data we collect
As controller, we collect and hold:
- Contact and business details needed to enter into and perform a contract: name, job title, business email address, telephone number, company name, business address and VAT number where one exists.
- Enquiry content: the message you send us and any information you choose to include in it, including details of the administrative work you want handled.
- Contract and engagement records: signed agreements, agreed scopes of work, access lists, task logs and the reports we issue to you.
- Billing records: invoices we raise, amounts, payment dates and related correspondence.
- Correspondence: emails and call notes relating to the engagement.
This website has no server-side forms. Our contact buttons open your own email client, so nothing you type on the page is transmitted to us until you send that email yourself.
4. Data inside client systems
To deliver the service we are given access to client mailboxes, calendars, CRM systems, document stores and accounting platforms. Those systems contain personal data about people who are not our clients — the client's employees, suppliers, contractors and customers.
In respect of that data:
- We process it only to carry out the tasks the client has instructed, and never for our own purposes.
- Access is granted at the minimum level the agreed tasks require, and is reviewed when the scope changes.
- We keep a log of the operations carried out on the client's behalf.
- We do not disclose it to third parties except where the contract or the law requires it.
- At the end of the engagement we return it or delete it, as the client directs.
If you are an employee, supplier or customer of one of our clients and you want to exercise your rights over data held in that client's systems, please contact the client directly — they are the controller. We will support them in responding.
5. Purposes and legal bases
- Responding to enquiries and preparing quotes — legitimate interests (replying to a business approach and assessing whether we can help) and, where you are contracting as an individual, steps taken at your request prior to entering a contract.
- Providing the contracted services and administering the engagement — performance of a contract.
- Invoicing, credit control and keeping accounting records — performance of a contract and legal obligation.
- Keeping records of access granted and work performed, and maintaining the security of our systems — legitimate interests (accountability, dispute resolution and information security).
- Occasional service updates by email to existing business contacts — legitimate interests, or consent where consent is required. You can opt out at any time.
- Meeting statutory obligations and responding to lawful requests — legal obligation.
Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights and freedoms, and we will explain that assessment on request.
6. Special category data
We do not ask for and do not seek special category data as defined in Article 9 UK GDPR (such as data revealing health, racial or ethnic origin, religious beliefs or trade union membership), nor data about criminal convictions.
Such data may nonetheless appear inside material we handle for a client — for example in HR correspondence sitting in a mailbox we administer. Where it does, it is processed under the same processor arrangement described above, with heightened protection: tighter access limits, a requirement to handle it only where the instructed task cannot be completed otherwise, and no copying outside the client's own systems.
7. Sharing with third parties
We do not sell personal data and we do not share it for anyone else's marketing. We share it only with the following categories of recipient:
- IT and communications providers that host our email, file storage and security tooling, acting as our sub-processors under contract.
- Our own professional advisers — accountants, auditors, insurers and lawyers — where they need the information to advise us.
- The client's own advisers, where the client has instructed us to pass prepared documents to them, for example the client's accountant or tax adviser.
- Payment and banking providers used to issue invoices and receive payment.
- Regulators, courts and law enforcement, where we are legally required to disclose.
- A purchaser or successor if our business or its assets are transferred, subject to the same protections.
Sub-processors used in work carried out for a client are engaged only with that client's authorisation, and are bound by data protection terms no less protective than those in our agreement with the client.
8. International transfers
We aim to keep personal data within the United Kingdom and the European Economic Area. Some of our service providers may process data outside the UK.
Where that happens, we rely on UK adequacy regulations covering the destination country, or on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment and any additional safeguards it identifies. For client data processed on instruction, transfers outside the UK take place only where the client has authorised them. You can ask us for details of the safeguards applied.
9. Retention
- Enquiries that do not become engagements — up to 12 months from the last contact.
- Contracts, scopes of work and access records — for the term of the engagement and 6 years afterwards, matching the limitation period for contractual claims.
- Invoices and accounting records — 6 years from the end of the accounting period, as required by UK law.
- General correspondence — up to 3 years from the end of the engagement, unless it forms part of a contract or accounting record.
- Client data processed on instruction — returned or deleted at the end of the engagement as the client directs, other than copies we must retain by law.
When a retention period ends, data is deleted or securely destroyed.
10. Security
We apply technical and organisational measures appropriate to the risk, including: multi-factor authentication on accounts used for client work; encryption of data in transit and of devices at rest; access granted on a least-privilege basis and revoked promptly when it is no longer needed; separation of client environments; logging of operations performed on a client's behalf; written confidentiality obligations for everyone with access; and a documented process for assessing and reporting personal data breaches.
No method of transmission or storage is completely secure. If a personal data breach affects data we hold as controller and is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of it, and notify you where the risk is high. Where we act as processor, we notify the client without undue delay.
11. Cookies
This website does not set cookies, does not use analytics or advertising tools, and does not build visitor profiles. No tracking scripts run on these pages, and nothing is written to local or session storage.
The site loads a web font from Google Fonts. When it does, your browser makes a request to Google's servers, which necessarily discloses your IP address to them. If you would rather avoid that, most browsers allow you to block remote fonts; the site remains fully readable in a system font.
12. Your rights
Where we act as controller, you have the right to:
- Access — obtain confirmation of whether we process your data and a copy of it.
- Rectification — have inaccurate data corrected and incomplete data completed.
- Erasure — have your data deleted where there is no continuing lawful basis to keep it.
- Restriction — have processing limited while a dispute about accuracy or legitimate interests is resolved.
- Portability — receive data you provided to us in a structured, commonly used, machine-readable format where processing rests on consent or contract and is automated.
- Objection — object to processing based on legitimate interests, and to direct marketing at any time, without needing to give a reason in the marketing case.
- Not to be subject to automated decision-making — we do not carry out automated decision-making or profiling that produces legal or similarly significant effects.
To exercise a right, email [email protected]. We respond within one month and may extend that by up to two further months for complex requests, telling you if we do. We may ask for information to confirm your identity. Exercising these rights is free of charge unless a request is manifestly unfounded or excessive.
13. Withdrawing consent
Where we rely on your consent, you may withdraw it at any time by emailing [email protected] or using the unsubscribe link in any message we send. Withdrawal does not affect the lawfulness of processing carried out before you withdrew, and it does not affect processing that rests on another lawful basis, such as the performance of a contract.
14. Complaints
If you are unhappy with how we have handled your data, please raise it with us first — we would rather fix it directly. You also have the right to complain to the UK supervisory authority:
Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Helpline: 0303 123 1113. Website: ico.org.uk.
15. Age restriction
Our services are offered to businesses and are not directed at children. We do not knowingly collect personal data from anyone under 18 as controller. If you believe a child has provided us with personal data, contact us and we will delete it.
16. Changes to this policy
We may update this policy to reflect changes in our services, our systems or the law. The current version is always published on this page with the "Last updated" date at the top. Where a change materially affects how we use your data, we will tell active clients by email before it takes effect.
17. Contact us
PNM CONSULTANTS LIMITED
17 Wiley House Mill Road, Gillingham, Kent, United Kingdom, ME7 1HZ
Company number 17207074
Email: [email protected]
Telephone: +44 7481 226905