Privacy & Data Protection
Privacy Notice
This notice explains how IG-Smart collects, uses, shares and protects personal information, and the rights you have. It describes what our website and services actually do.
Who we are
IG-SMART LTD ("IG-Smart", "we", "us") is a governance, risk and assurance consultancy. We are a company registered in England and Wales (company number 06873438) and registered with the Information Commissioner's Office (registration reference ZA397651).
Registered office: 1 Park Road, Hampton Wick, Kingston Upon Thames, United Kingdom, KT1 4AS.
IG-Smart is based in the UK and works with organisations that operate internationally. For the personal information described in this notice, IG-Smart is the controller, unless we tell you otherwise. Where we process personal information on behalf of a client under a contract, the client is usually the controller and its own privacy notice applies.
Questions about privacy, data protection or your rights: dpo@ig-smart.com. General and commercial enquiries: info@ig-smart.com.
The law we follow
Our core framework is UK data protection law: the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as amended, including by the Data (Use and Access) Act 2025 where relevant. The Privacy and Electronic Communications Regulations (PECR) apply to cookies, similar technologies and electronic marketing.
Because we serve clients and contacts in other countries, other laws may also apply to a particular individual or activity. Where they do, you may have additional rights and we may have additional obligations. We don't assume that every foreign privacy law applies to every activity.
Whose information we process
This notice covers personal information about:
- website visitors;
- people who request a Discovery Call or a Proposal, and other prospective clients;
- people who request evidence or procurement assurance information through our Trust Centre;
- personnel of our clients, where we work with them during an engagement;
- suppliers, partners and other professional contacts;
- event and training participants, where we run events or training;
- job and contractor candidates, where we recruit;
- users of our Assurance Pathfinder who choose to give us their contact details, once that tool is available;
- authorised IG-Smart staff who sign in to our restricted review area.
We don't currently operate a newsletter or regulatory-update mailing list. If we introduce one, subscription will be optional and we will update this notice first.
What we collect and where it comes from
Mostly, you give it to us directly. Depending on how you interact with us, this may include:
- Enquiry forms (Talk to a Senior Practitioner and Submit a Requirement): name, business email, organisation, optional telephone number, the service you are interested in, your message and any scope details you add.
- Trust Centre requests: name, business email, organisation, optional role, the documents or procurement-assurance areas requested, and any reason or context you give. We also record the status of your request and which IG-Smart reviewer handled it.
- Engagements, supplier relationships, events and recruitment: business contact details, role, correspondence, and the information needed for the engagement, contract, event or application.
- Reviewer sign-in: email address and sign-in records of authorised IG-Smart staff.
We also collect some information automatically:
- Security and anti-abuse: when you submit a form we create a one-way scrambled (hashed) version of your internet (IP) address and a fingerprint of the submission, to stop spam, duplicate submissions and misuse. We don't store your IP address itself.
- Service delivery: our hosting provider processes technical information such as your IP address and browser details to deliver the website and protect it from attack.
- Enquiry attribution — only if you accept Analytics: the page you arrived on, the referring website, and the page or button that led you to a form. These are kept in your browser for the session and are sent to us only if you submit an enquiry.
Occasionally we receive information from other sources, for example a colleague who introduces you, your organisation during an engagement, or publicly available professional sources such as Companies House or your organisation's website.
How we use it and our lawful bases
- Responding to enquiries and preparing proposals — to take steps at your request before entering a contract, or our legitimate interests in responding to business enquiries.
- Reviewing and fulfilling Trust Centre requests — our legitimate interests in supporting procurement and due diligence while controlling who receives non-public material.
- Delivering services and managing client and supplier relationships — performance of a contract, or our legitimate interests where the contract is with your organisation.
- Protecting our website, forms and systems — our legitimate interests in security and preventing misuse.
- Measuring which pages and services generate enquiries — your consent, given through our cookie choices; you can withdraw it at any time.
- Running events or training, and recruitment — performance of a contract or steps before one, or our legitimate interests.
- Meeting legal, regulatory, accounting and insurance obligations, and establishing or defending legal claims — legal obligation, or our legitimate interests.
Where we rely on legitimate interests, we have balanced them against your interests and rights. You can ask us for more detail.
We don't sell personal information. We don't send you marketing unless you have asked for it, and we don't make decisions about you based solely on automated processing, including profiling, that have legal or similarly significant effects.
International data transfers
Because we work internationally and use service providers with global infrastructure, personal information may be processed in countries outside the UK, where our suppliers, systems, clients or professional advisers operate.
When we, or our providers, transfer personal information outside the UK, we make sure a lawful transfer mechanism is in place where one is required. This may be a UK adequacy decision ("data bridge"), the UK International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses, or another safeguard recognised by UK law, supported by appropriate security measures. Contact us for more information about the safeguards for a particular transfer.
How long we keep it
We keep personal information only for as long as necessary for:
- the purpose for which it was collected;
- delivering and managing client services;
- responding to enquiries and proposals;
- legal, regulatory, contractual and professional obligations;
- establishing, exercising or defending legal claims;
- security, fraud prevention and audit requirements;
- applicable limitation periods;
- legitimate record-keeping requirements.
In particular:
- Enquiries that don't lead to an engagement: kept for as long as needed to respond and follow up, then deleted or anonymised.
- Trust Centre requests: kept as a record of what was requested, what was decided and by whom; approved access to controlled material expires after the period set by our reviewers (currently 30 days).
- Client and supplier records: kept for the duration of the relationship and afterwards for as long as legal, contractual, tax, insurance or limitation-period requirements apply.
- Analytics attribution stored in your browser: deleted when you close the browser tab, and cleared straight away if you withdraw consent.
If we adopt a defined retention schedule, we will update this notice to reflect it.
How we protect it
IG-Smart operates an information security management system certified to ISO/IEC 27001:2022 (certificate number 487582026). Our controls include access restricted to authorised personnel, encrypted connections, least-privilege database access rules, and restricted, audited access to our request-review area. No method of transmission or storage is completely secure, but we take appropriate measures proportionate to the risk.
Your rights
Under UK data protection law you have the right to:
- access your personal information;
- have inaccurate information corrected;
- have information erased, in certain circumstances;
- restrict or object to our processing, including processing based on legitimate interests;
- data portability, in certain circumstances;
- withdraw consent at any time, where we rely on consent. For analytics, use "Cookie Settings" in the footer of any page.
To use any of these rights, email dpo@ig-smart.com. We may need to confirm your identity. We will respond within the time the law requires. If another jurisdiction's law applies to you, you may have additional rights; tell us and we will take them into account.
Complaints
If you are unhappy with how we have handled your personal information, please contact us first at dpo@ig-smart.com so we can try to resolve it. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint, or to a supervisory authority in the country where you live or work.
Changes to this notice
We review this notice regularly and update it when our processing changes. The date it was last reviewed is shown on this page. This version was last reviewed on 30 September 2026.