Blue Brook Ltd ("we", "our", "us") is committed to protecting and respecting your privacy. This policy explains how we collect, use, store, and protect personal information when you use our website or engage our services.
We are registered with the Information Commissioner's Office (ICO) under registration number ZA789456. For data protection purposes, our Data Protection Officer can be contacted at [email protected].
Information We Collect
We collect and process the following categories of personal information:
Information you provide directly
- Contact details including your name, email address, and postal address
- Financial information relevant to benefits eligibility assessments
- Employment status and income details
- Health information where relevant to disability or health-related benefits
- Household composition and family circumstances
- National Insurance number and other identifying information
- Correspondence and communication records
Information collected automatically
- IP address and browser type
- Pages visited and time spent on our website
- Referring website addresses
- Device information and operating system
How We Use Your Information
We use your personal information for the following purposes:
- To assess your eligibility for benefits and social payments
- To prepare and submit benefit applications on your behalf
- To communicate with government departments and local authorities regarding your claims
- To prepare appeals and mandatory reconsiderations
- To respond to your enquiries and provide customer support
- To send you updates about your case progress
- To improve our services and website functionality
- To comply with legal and regulatory obligations
Legal Basis for Processing
We process your personal data on the following legal bases:
- Contract: Processing necessary to perform our services under our agreement with you
- Consent: Where you have given explicit consent for specific processing activities
- Legal obligation: Where processing is necessary to comply with laws and regulations
- Legitimate interests: Where processing is necessary for our legitimate business interests, balanced against your rights
For special category data such as health information, we rely on your explicit consent and the processing being necessary for reasons of substantial public interest in relation to social security and social protection.
Sharing Your Information
We may share your personal information with:
- Government departments: Department for Work and Pensions, HM Revenue & Customs, local authorities, and other relevant bodies as necessary to process your benefits applications
- Healthcare providers: Where medical evidence is needed to support your claim
- Tribunals and courts: If you are appealing a decision
- Service providers: Who assist us with IT, administration, and professional services, bound by confidentiality agreements
- Legal advisors: If we need professional advice regarding your case
We will never sell your personal information to third parties or use it for marketing purposes without your explicit consent.
Data Security
We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit and at rest
- Secure access controls and authentication
- Regular security assessments and updates
- Staff training on data protection and confidentiality
- Secure physical storage of paper records
- Incident response procedures
Data Retention
We retain your personal information for as long as necessary to fulfil the purposes for which it was collected and to comply with legal obligations. Specific retention periods include:
- Active client records: Duration of our engagement plus 7 years
- Completed cases: 7 years from case closure
- Appeal records: 7 years from final decision
- Financial records: 7 years as required by HMRC
- Website analytics: 26 months
After these periods, we securely delete or anonymise your data.
Your Rights
Under data protection law, you have the following rights:
- Access: Request a copy of the personal information we hold about you
- Rectification: Request correction of inaccurate or incomplete information
- Erasure: Request deletion of your information in certain circumstances
- Restriction: Request that we limit how we use your information
- Portability: Receive your data in a structured, commonly used format
- Objection: Object to processing based on legitimate interests
- Withdraw consent: Where processing is based on consent, withdraw it at any time
To exercise any of these rights, contact us at [email protected]. We will respond within one month of receiving your request.
International Transfers
Your personal information is primarily stored and processed within the United Kingdom. We do not routinely transfer personal data outside the UK. Where any transfer to a third country is necessary, we ensure appropriate safeguards are in place in accordance with UK data protection law.
Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices or legal requirements. Significant changes will be notified to you via email or through a prominent notice on our website. We encourage you to review this policy periodically.
Complaints
If you are unhappy with how we have handled your personal information, please contact us first at [email protected] so we can try to resolve your concern.
You also have the right to lodge a complaint with the Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
blue-brook.com
Contact Us
For any questions about this privacy policy or our data practices, please contact:
Data Protection Officer
Blue Brook Ltd
47 Whitmore Street
Bristol, BS1 3QH
[email protected]