stop-watch mail angle-double-down angle-double-up angle-double-right angle-double-left chevron-thin-down chevron-thin-up twitter-with-circle linkedin-with-circle facebook-with-circle

Privacy policy

PUBLIC-FACING WEBSITE POLICY

At Gideon Franklin the privacy of the people with whom we engage in our business is of paramount importance to us and we are committed to safeguarding their privacy by handling personal data in accordance with data protection laws.

This privacy policy explains how and why we use personal data, and what we do to ensure that your information is kept safe and secure in accordance with applicable data protection and privacy laws including the UK Data Protection Act 2018, the UK GDPR (being the EU General Data Protection Regulation 2016/679 in the form retained in UK law after Brexit) and any other applicable data protection and privacy laws (Data Protection Laws).

 

This policy explains:

  1. Who we are and how to contact us
  2. How we collect and process personal data:
  3. Clients (and other persons)
  4. Business and professional contacts
  5. Recruitment
  6. Cookies and website visitors
  7. CCTV
  8. Recipients of personal data
  9. How long we store personal data for
  10. How we keep personal data safe
  11. International transfers
  12. Your rights as a data subject
  13. Updates to this policy

 

  1. WHO WE ARE AND HOW TO CONTACT US

We are Gideon Franklin Limited (we, us or our), a limited liability company with registered number 05880357, having our registered office and main place of business at The Lambourn Wyndyke Furlong Abingdon Oxfordshire OX14 1UJ. You can contact us by writing to us at our office address, telephoning us on +44 1235 617235 or emailing info@gideonfranklin.com.

We are regulated as a controller under Data Protection Laws in relation to the personal data we collect and process. This means that we are responsible for deciding how and why we use personal data, and for keeping it safe. We are registered as a data controller with the Information Commissioner’s Office (ICO) with registration number ZA429328.

 

  1. HOW WE COLLECT AND PROCESS PERSONAL DATA

 

  1. CLIENTS (AND OTHER PERSONS)

HOW WE COLLECT PERSONAL DATA

We collect and process personal data (meaning information which relates to an identified or identifiable individual) relating to our clients and matters we advise on. This will include other individuals involved, such as representatives, employees and officers of corporate clients, other parties and professional advisers. This information is typically:

THE TYPES OF PERSONAL DATA WE COLLECT

The categories of personal data we collect will vary, depending on the matter in question, but may include some or all of the following:

We may process other types of personal data in the course of providing corporate finance advisory services, receiving goods and services from our suppliers and promoting our business. If we do, then it will be protected to the same high standards explained in this policy.

OUR LAWFUL BASIS AND PURPOSES FOR PROCESSING PERSONAL DATA

We use personal data because we need to for one or more of the following reasons:

If you do not provide the personal data which we need in order to enter into or to perform a contract with you, then we may not be able to contract with you or to provide the corporate finance advisory services which you have requested.

In limited circumstances, we may use personal data on the basis of your consent. If so, we will always clearly ask for your specific and informed agreement to this. You are, of course, free to refuse this and we will inform you as to what (if any) consequences your refusal might have.

 

  1. BUSINESS AND PROFESSIONAL CONTACTS

HOW WE COLLECT PERSONAL DATA

We process personal data about individual business and professional contacts. These people include individual (or representatives from corporate) intermediaries, service providers, other professional advisors, organisations that have attended our events, and potential clients.

THE TYPES OF PERSONAL DATA WE COLLECT

The types of personal data we hold about these individuals typically relate to that person’s profession and consist of basic personal details and contact information, such as position title, name, work email, address, telephone and the person’s employer. Depending on the circumstances, and the nature of our relationship with the people involved, we may use this information to:

OUR LAWFUL BASIS AND PURPOSES FOR PROCESSING PERSONAL DATA

We use this personal data because it is in our legitimate interests to promote our services and build business relationships.

If you receive news or marketing communications from us, it is because we think you might be interested in our firm or its services (usually on the basis of previous dealings with you or a recommendation from a third party).

You can unsubscribe from marketing at any time by clicking the “unsubscribe” link on any of our emails, or by emailing info@gideonfranklin.com with the subject line “unsubscribe.”

 

  1. RECRUITMENT

HOW WE COLLECT PERSONAL DATA
We collect, store and use personal data about individuals who apply to join us.

THE TYPES OF PERSONAL DATA WE COLLECT

The information we collect about applicants may include information:

The information we collect might include sensitive personal data, such as information about your health and sickness records. If we need to process sensitive personal data then we will ask for your explicit consent before doing so.

If you apply for a position with us, we may carry out a check for criminal convictions in order to satisfy ourselves that there is nothing in your history which makes you unsuitable for the role. We do this because working with us involves a high degree of trust (as you may be dealing with price sensitive transactions and will have access to confidential information).

We only carry out criminal records checks and ask for references at the last stage of the application process, when making an offer of employment, and always act in accordance with the specific requirements of Data Protection Laws and other applicable national laws when doing so.

OUR LAWFUL BASIS AND PURPOSES FOR PROCESSING PERSONAL DATA
We use the personal data we collect about you to:

We do all of this because either it is a necessary part of entering into a contract of employment with you or because we have a legitimate interest in ensuring that you are suitable for a particular role.

If you fail to provide personal data when requested, which is necessary for us to consider your application (such as evidence of qualifications or work history), we will not be able to process your application successfully.

If we need to process sensitive personal data about a job applicant, for example disability information in order to consider whether we need to provide appropriate adjustments during the recruitment process, we will ask for explicit consent to do this at the time at which we request the personal data or ensure that we satisfy another condition under Data Protection Laws for lawfully processing such personal data.

RETENTION OF APPLICANT INFORMATION

We normally retain personal data about unsuccessful candidates for no more than 6 months from the time we inform them of our hiring decision. We retain personal data for this period so that we can demonstrate, in the event of a legal claim, we have not discriminated against an applicant and that the recruitment process was fair and transparent. After this period, we will securely destroy the applicant’s personal data. If we wish to retain personal data on file, in case future opportunities arise, we will contact the applicant and ask for his or her consent to do so.

If you are successful, the personal data you provided in the application process will be stored as part of your personnel file.

 

  1. COOKIES AND WEBSITE VISITORS

We do not normally collect personal data about visitors to our website unless they choose to provide such information (such as by filling in a website form or contacting us directly).

We collect anonymous information about visitors to our website in order to optimise and improve the website. This might include IP addresses, browser or device details and the connection type (for example, the Internet service provider used). However, none of this information will by itself directly identify any particular user.

COOKIES
We use Google Analytics to analyse the use of our website and create reports about such usage. Google Analytics gathers information about website use by means of cookies. Such usage data may include your IP address, geographical location, browser type and version, operating system, referral source, length of visit, page views and website navigation paths, as well as information about the timing, frequency and pattern of your service use.

A cookie is a file containing an identifier (a string of letters and numbers) that is sent by a web server to a web browser and is stored by the browser. The identifier is then sent back to the server each time the browser requests a page from the server. You can find more information about the individual cookies we use and the purposes for which we use them in the table below:

 

Cookie Provider Purpose Lifespan
_gid Google Analytics Used to transmit data to Google Analytics regarding the visitor’s device and actions. It tracks the visitor across various devices and marketing channels. 1 day
_ga_2H2HV29N04 Google Analytics Assists in collecting data that allows website owners to understand how visitors interact with their website content. 24 months
_ga Google Analytics Assigns a unique ID that generates statistical data on the visitor’s interaction with the website. 25 months and 4 days
_gat_gtag_UA Google Analytics Used to store a unique user ID. 1 minute
moove_gdpr_popup https://www.gideonfranklin.com/ Used to save the visitor’s cookie setting preferences. 3 months

 

Further information on the cookies and how they work can be found here: https://policies.google.com/technologies/cookies?hl=en-US

You can prevent these cookies by installing the Google Analytics opt-out browser extension by visiting https://support.google.com/analytics/answer/181881?hl=en or by adjusting your browser settings.

HYPERLINKS TO OTHER SITES

Our website contains hyperlinks to third-party websites. We are not responsible for the content or functionality of any of those external websites.  If an external website requests personal information from you, the information you provide will not be covered by this policy. We suggest you read the privacy policy of any website before providing any personal information.

 

  1. CCTV

Any CCTV used in our Abingdon office is operated by the building landlord and not by us. We do not have access to CCTV footage and are not a controller in respect of any personal data included on such footage. CCTV inquiries should be directed to privacy@mantle.co.uk or by writing to Data Protection Officer, Mantle Space Ltd, The Priory, Thremhall Park, Start Hill, Bishop’s Stortford, Hertfordshire CM22 7WE.

 

  1. RECIPIENTS OF PERSONAL DATA

Personal data you provide to us will be kept private and confidential in accordance with our obligations under Data Protection Laws. We will only disclose or share personal data with other data controllers where this is required:

We also share personal data with some of the third parties who provide services to our firm. This includes software providers (such as Microsoft), cloud service providers and IT support services. However, these third parties will only process personal data (which may include your information) on our behalf for specified purposes and in accordance with our strict instructions.

We only use third party service providers who have provided sufficient guarantees, as required by Data Protection Laws, that your personal data will be kept safe. We always ensure there is a written contract in place which protects your personal data and prevents it from being used for any purpose other than providing services to our firm, in accordance with Data Protection Laws.

 

  1. HOW LONG WE STORE PERSONAL DATA FOR

We only retain personal data for as long as is necessary for the specific purpose(s) it was collected for (or for related compatible purposes such as complying with applicable legal, accounting, or record-keeping requirements).

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from its unauthorised use or disclosure, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

 

  1. HOW WE KEEP PERSONAL DATA SAFE

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, damaged or destroyed, altered or disclosed. This includes both physical security measures (such as keeping paper files in secure, access-controlled premises, and adhering to strict password policies) and electronic security technologies (such as device encryption, multi-factor authentication, digital back-ups and sophisticated anti-virus protection).

We limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to legal and contractual confidentiality obligations.

We have put in place reporting procedures to deal with any suspected personal data breach and will notify you and any applicable supervisory authority of a breach when we are legally required to do so.

 

  1. INTERNATIONAL TRANSFERS

We normally only store personal data within the UK or European Economic Area. However, some of the technology and support services we use are provided by international organisations and/or companies which are based in other countries. Before using such service providers, we take steps to make sure that any personal data they process is adequately protected and transferred in accordance with Data Protection Laws, usually by one or more of the following methods:

If you would like more detailed information on the measures and safeguards which we implement for such data transfers, then please contact us using the details set out in section 1 above.

 

  1. YOUR RIGHTS AS A DATA SUBJECT

Data Protection Laws provide you with certain rights in relation to your personal data. These are as follows:

 

RESPONDING
We try to respond to all personal data requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. Please also bear in mind that there are exceptions to the rights above and some situations where they do not apply.

We may need to request additional information from you to help us confirm your identity. This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you to clarify your request.

 

FEES FOR MAKING A REQUEST

You will not normally have to pay a fee to access your personal data (or to exercise any of your other rights). However, we may charge a reasonable fee if your request is manifestly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.

 

HOW TO MAKE A REQUEST

If you want to exercise any of the rights described above, please email info@gideonfranklin.com or write to Data Protection Requests, Gideon Franklin Limited The Lambourn Wyndyke Furlong Abingdon Oxfordshire OX14 1UJ.

 

YOUR RIGHT TO COMPLAIN TO A SUPERVISORY AUTHORITY

You have the right to complain to the Information Commissioner’s Office if you are not satisfied with our response to a data protection request or if you think your personal data has been mishandled. For further information on how to make a complaint, please visit https://ico.org.uk.

 

  1. UPDATES TO THIS POLICY

We will update this policy from time to time. The current version will always be posted on our website. This policy was last updated on 13 March 2025.