Website and Client Privacy Notice

Advice Bureau Plus Limited, trading as AB Plus

At a glance:

We use personal information to respond to enquiries, provide HR, health and safety and training services, manage client relationships, run our website and meet our legal obligations. We do not sell personal information.

Last updated: 25 August 2026

1. Who we are

Advice Bureau Plus Limited (company number 06994879), trading as AB Plus, is the controller of the personal information described in this notice. Our registered office is PGD Accountants, 26 Spinney Close, Roundswell, Barnstaple, Devon, England, EX31 3RT.

For privacy questions, rights requests or data protection complaints, contact Duncan Peel by email at duncan@ab-plus.co.uk, by telephone on 07973 951401, or by post at the registered office above.

This notice applies to website visitors, prospective clients, client contacts, course delegates, suppliers and other business contacts. It does not replace a client organisation's own privacy notice. When a client gives us personal information about its workers or other individuals so that we can provide advice or support on its behalf, the client will normally be the controller and AB Plus will process that information under the client's instructions and our contract.

2. The information we collect

Depending on how you interact with us, we may collect:

·   identity and business contact details, such as your name, job title, organisation, address, email address and telephone number;

·   enquiry, correspondence and service information, including the content of emails, calls, meeting notes, instructions, feedback and records of advice or work provided;

·   contract, billing and transaction information, such as services purchased, invoices, payment status and limited payment details;

·   training information, such as booking details, attendance, assessment results and certificates;

·   website and device information, such as IP address, browser type, device information, referring pages, pages visited and cookie preferences; and

·   marketing preferences and records of whether you have opened or interacted with our communications, where the relevant service provides this information.

Our consultancy work may occasionally involve special category information, particularly health information, or information about alleged misconduct or criminal offences. We only use this where necessary, with suitable safeguards and an additional legal condition. In many cases this information is supplied by a client acting as controller. Please avoid sending sensitive personal information through a general website enquiry form unless it is necessary.

3. How we obtain information

We obtain personal information:

·   directly from you when you contact us, use a website form, become a client, book or attend training, respond to a survey or communicate with us;

·   from your employer, colleague or another client contact where this is necessary to arrange or deliver our services;

·   from client organisations where they ask us to advise or assist them;

·   automatically through essential website technologies, server logs and, where you have agreed, analytics or other non-essential cookies; and

·   from public sources such as Companies House, professional websites and business social-media profiles when reasonably necessary for business administration or to verify contact details.

4. How and why we use personal information

We use your personal information for the following purposes:

Responding to enquiries and preparing proposals. We use identity, contact and enquiry information to take the steps you request before entering into a contract, and because we have a legitimate interest in responding to enquiries and developing our business.

Setting up and delivering consultancy, support and training services. We use identity, contact, service, correspondence, training and transaction information under the contract with you, in pursuit of our legitimate interests, and to meet our legal obligations.

Managing the client relationship, accounts, invoices and debt recovery. We use identity, contact, contract, billing and transaction information under the contract, to meet legal obligations, and in pursuit of our legitimate interests in business administration and recovering sums due.

Maintaining service quality, records and security, and defending legal claims. We use correspondence, service, website and transaction information in pursuit of our legitimate interests in quality, security and protecting our legal rights, and to meet legal obligations.

Sending relevant service updates or marketing. We use identity, business contact details, preferences and engagement information with your consent where required, or otherwise in pursuit of our legitimate interests and in line with electronic-marketing rules. You may opt out at any time.

Operating, securing and improving our website. We use technical, usage and cookie information in pursuit of our legitimate interests in security and essential operation, and with your consent or under a statutory exception for non-essential storage or access technologies, as applicable.

Complying with law, regulators and official requests. We use relevant identity, contact, service and transaction information to meet our legal obligations, and on other recognised lawful grounds where applicable.

Where we use special category information, this will usually relate to employment and social protection law, establishing or defending legal claims, substantial public interest, or your explicit consent where appropriate. Criminal-offence information is only handled where authorised by law and subject to appropriate safeguards.

We do not use solely automated decision-making that produces legal or similarly significant effects on individuals.

5. Marketing

We may send relevant service information to business contacts where the law permits and our interests are not overridden by your rights. Where consent is required, we will ask for it. You can stop marketing at any time by using an unsubscribe link or contacting us. We may retain a minimal suppression record so that we respect your choice. Service messages about work you have asked us to provide are not marketing. We do not sell personal information or share it with third parties for their own marketing.

6. Cookies and similar technologies

Our website may use cookies, tags, pixels, local storage or similar technologies. Technologies that are strictly necessary, or that fall within another applicable statutory exception, may operate without consent. Where consent is required, non-essential technologies—such as certain analytics, embedded media or advertising tools—must remain off until you choose to allow them. You can change your choices using the website's cookie preference tool. The website's Cookie Notice should identify the technologies actually used, their providers, purposes and durations.

7. Who we share information with

Where necessary, we may share personal information with:

·   website, hosting, cloud storage, email, IT support, accounting, payment, document-management, video-conferencing and training-platform providers;

·   professional advisers, insurers, auditors and debt-recovery providers;

·   the relevant client organisation, where information relates to services provided for that client;

·   regulators, courts, law-enforcement bodies, HM Revenue & Customs and other authorities where required or permitted by law; and

·   a purchaser, investor or adviser involved in a genuine business sale, restructuring or transfer, subject to appropriate confidentiality and data-protection safeguards.

Service providers that act as processors may use personal information only for agreed purposes, under contract and with appropriate security. Some recipients may act as independent controllers for their own legal or professional responsibilities.

8. International transfers

Some technology providers may store or access information outside the UK. Where this involves a restricted transfer, we use a lawful transfer mechanism, such as UK adequacy regulations (including the UK Extension to the EU-US Data Privacy Framework where applicable), the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another permitted safeguard. We also carry out any required risk assessment and apply supplementary measures where appropriate. Contact us if you would like information about the safeguard relevant to your data.

9. Security and retention

We use proportionate technical and organisational measures designed to protect personal information against accidental loss, misuse, alteration, unauthorised access or disclosure. Access is limited to people and providers who need it and who are subject to confidentiality or contractual duties. No internet or email system is completely secure, so please use an agreed secure method when sending particularly sensitive information.

We keep information only for as long as reasonably necessary. Our usual guide is:

·   general enquiries that do not become client work: normally up to 12 months after the last meaningful contact;

·   client contracts, advice records and related correspondence: normally six years after the relationship or relevant matter ends, and longer where reasonably required for a continuing claim, insurance or legal obligation;

·   financial and tax records: normally six years after the end of the relevant accounting period, or longer if required by law;

·   training records and certificates: for the period reasonably needed to evidence attendance, qualification or renewal;

·   marketing information: until you opt out or it is no longer relevant, with a minimal suppression record retained to respect an opt-out; and

·   website security logs and cookie information: according to the operational need and the durations stated in the Cookie Notice.

We may keep information longer where law, litigation, insurance or regulatory requirements justify this, or anonymise it so that it no longer identifies anyone.

10. Your rights

Depending on the circumstances and lawful basis, you may have the right to:

·   ask for access to your personal information;

·   ask us to correct inaccurate or incomplete information;

·   ask us to erase information or restrict how we use it;

·   object to processing based on legitimate interests and object at any time to direct marketing;

·   receive certain information in a portable, machine-readable format; and

·   withdraw consent at any time, without affecting earlier lawful processing.

Your right to object: You may object at any time to direct marketing. You may also object to processing based on legitimate interests because of your particular situation. We will stop unless we have compelling legitimate grounds to continue or the processing is needed for legal claims.

Rights are not absolute and exemptions may apply. We will normally respond within one month. We may pause the response period if we reasonably need clarification or information to verify identity, and we may extend the period for a complex request as permitted by law. Requests are normally free, although we may charge a reasonable fee or refuse a request where the law allows.

11. Complaints

If you believe we have not handled personal information properly, please contact us using the details in section 1. We will provide a clear route for your complaint, acknowledge it within 30 days, investigate appropriately, keep you informed where necessary and tell you the outcome without undue delay.

You may also complain to the Information Commissioner's Office (ICO), although the ICO will normally expect you to have raised the matter with us first. Visit ico.org.uk/make-a-complaint or telephone 0303 123 1113.

12. Changes to this notice

We may update this notice when our services, website technologies, suppliers or the law change. The latest version will be published on our website with its revision date. Please tell us if your contact details change so that the information we hold remains accurate.