Privacy Notice

CRO Nest Ltd.

This privacy notice tells you what to expect us to do with your personal information.

Contact details

Email us at enquiries@cro-nest.co.uk

What information we collect, use, and why

We collect or use the following information to provide and improve products and services for clients:

  • Names and contact details

  • Addresses

  • Client Employee Data: This includes the names, business email addresses, and telephone numbers of our clients' employees and representatives, necessary for managing our contractual relationship.

  • Customer Personal Data: This includes personal data belonging to our clients' customers. The scope is determined by our client and may include names, email addresses, and behavioural data such as website metrics, IP addresses, and user interaction data derived from analytics and testing tools.

  • When you interact with our website (www.cro-nest.co.uk), or engage with us for sales or marketing, we act as a Data Controller. We may collect:

    • Identity and Contact Data: Name, email address, telephone number, and job title.

    • Technical Data: Internet Protocol (IP) address, browser type and version, and other technology on the devices you use to access our website.

    • Usage Data: Information about how you use our website and services.

How we use your information

  • To Provide Services to Clients: To deliver our CRO and IT consultancy services as defined in our client agreements.

  • To Manage Our Business: To manage client relationships, send administrative information, issue invoices, and keep our records up to date.

  • For Security: To protect our services, prevent fraud, and ensure the security of our own and our clients' data.

  • For Marketing: To communicate with you about our services, if this is in accordance with your marketing preferences.

Lawful bases and data protection rights

Under UK data protection law, we must have a “lawful basis” for collecting and using your personal information. There is a list of possible lawful bases in the UK GDPR. You can find out more about lawful bases on the ICO’s website.

Which lawful basis we rely on may affect your data protection rights which are set out in brief below. You can find out more about your data protection rights and the exemptions which may apply on the ICO’s website:

·       Your right of access - You have the right to ask us for copies of your personal information. You can request other information such as details about where we get personal information from and who we share personal information with. There are some exemptions which means you may not receive all the information you ask for. Read more about the right of access.

·       Your right to rectification - You have the right to ask us to correct or delete personal information you think is inaccurate or incomplete. Read more about the right to rectification.

·       Your right to erasure - You have the right to ask us to delete your personal information. Read more about the right to erasure.

·       Your right to restriction of processing - You have the right to ask us to limit how we can use your personal information. Read more about the right to restriction of processing.

·       Your right to object to processing - You have the right to object to the processing of your personal data. Read more about the right to object to processing.

·       Your right to data portability - You have the right to ask that we transfer the personal information you gave us to another organisation, or to you. Read more about the right to data portability.

·       Your right to withdraw consent – When we use consent as our lawful basis you have the right to withdraw your consent at any time. Read more about the right to withdraw consent.

If you make a request, we must respond to you without undue delay and in any event within one month.

To make a data protection rights request, please contact us using the contact details at the top of this privacy notice.

Our lawful bases for the collection and use of your data

Our lawful bases for collecting or using personal information to provide and improve products and services for clients are:

  • Performance of a Contract: We process data when it is necessary to fulfil our contractual obligations to our clients, or to take steps before entering into a contract. we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.

  • Legitimate Interests: We process data for our legitimate interests, such as marketing our services to other businesses or for the internal administration of our company, provided these interests are not overridden by your rights. When acting as a Processor, we do so to enable the legitimate interests of our clients (the Controllers) to improve their website and services.

  • Legal Obligation: We may process data where necessary to comply with a legal or regulatory obligation.

  • Consent: For our own direct marketing communications, we will rely on your consent.

Where we get personal information from

  • Directly from you

We do not sell personal data. We may share personal data with:

  • Third-Party Service Providers: Such as analytics platforms (e.g. Google Analytics), and cloud hosting services

  • Professional Advisers: Including lawyers, bankers, auditors, and insurers who provide consultancy, banking, legal, insurance, and accounting services.

  • Legal Authorities: Where required by law or to protect our legal rights.

How long we keep information

We will only retain personal data for as long as is necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

·       Client records are stored for up to seven years

·       Details from enquiries that do not lead to contract will be stored for up to one year.

How to complain

If you have any concerns about our use of your personal data, you can make a complaint to us using the contact details at the top of this privacy notice.

If you remain unhappy with how we’ve used your data after raising a complaint with us, you can also complain to the ICO.

The ICO’s address:           

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Helpline number: 0303 123 1113

Website: https://www.ico.org.uk/make-a-complaint

Last updated 24 October 2025