Privacy Policy
Privacy Notice
Last updated: August 2026
1. Who I am
ASM Quality Consulting is operated by Arwen Sarah May, a sole trader providing business management, ISO management system and general consultancy services.
For the purposes of UK data protection law, I am the data controller responsible for the personal information described in this notice.
Contact details
Trading name: ASM Quality Consulting
Name: Arwen Sarah May
Business address: Apex Office Space, Watervole Way, Doncaster, DN4 5JP
Email: arwen.may@asmqualityconsulting.com
Telephone: 07540 952343
Website: www.asmqualityconsulting.com
2. Scope of this notice
This Privacy Notice explains how I collect, use, store and protect personal information when you:
visit or use this website; contact me about my services; request a quotation or proposal; become a client; supply goods or services to my business; subscribe to communications; or otherwise interact with my consultancy.
3. Personal information I may collect
Depending on how you interact with me, I may collect:
your name and job title; your employer or business name; your postal address, email address and telephone number; information included in enquiries, correspondence and meeting notes; information necessary to prepare quotations, proposals and contracts; information required to provide consultancy services; billing, payment and transaction information; feedback, complaints and other communications; technical information relating to your use of this website, such as your IP address, browser type and cookie information; and marketing and communication preferences.
Please do not provide special category information, such as information about health, ethnicity, religion, political opinions or trade union membership, unless it is necessary for the consultancy service and has been specifically requested.
4. How I collect personal information
I may collect personal information: directly from you through the website, email, telephone, online meetings or face-to-face contact; through contracts, questionnaires, project documents and other records you provide; from another person within your organisation; from publicly available business sources, such as company websites, Companies House or professional networking platforms; from professional advisers, suppliers or referral partners; and automatically through cookies or similar website technologies.
Where you provide personal information about another person, you should ensure that you are authorised to provide it and that the person has been given appropriate information about how it will be used.
5. How and why I use personal information
I may use personal information for the following purposes.
Responding to enquiries, I use contact details and enquiry information to respond to questions, discuss potential work and prepare quotations or proposals. My lawful basis will normally be taking steps at your request before entering into a contract or, where you are acting for an organisation, my legitimate interest in responding to business enquiries.
Providing consultancy services, I use client and project information to enter into and perform consultancy contracts, communicate with clients, deliver agreed services and manage projects. My lawful basis will normally be performance of a contract or taking steps before entering into a contract.
Where the contract is with an organisation rather than directly with you, I may rely on my legitimate interest in communicating with the organisation’s employees, representatives and professional advisers.
Managing the business, I use personal information to maintain business records, issue invoices, receive payments, manage suppliers, administer contracts and obtain professional advice. My lawful basis may be performance of a contract, compliance with a legal obligation or my legitimate interest in operating and protecting my business.
Meeting legal and regulatory obligations, I may process and retain personal information where necessary to comply with tax, accounting, insurance, legal or regulatory requirements. My lawful basis is compliance with a legal obligation.
Protecting legal rights, I may use relevant records to establish, exercise or defend legal claims, resolve complaints, prevent fraud or protect the security of my business and website. My lawful basis is normally my legitimate interest in protecting my business and legal rights.
Marketing, I may send information about my consultancy services where you have consented to receive it or where another lawful basis permits the communication. You may unsubscribe or object to direct marketing at any time by contacting me at arwen.may@asmqualityconsulting.com or by using any unsubscribe option included in the communication.
I will not sell your personal information to third parties for marketing purposes.
Operating and improving the website, I may use limited technical information to operate the website, maintain security, understand website performance and improve its content. The lawful basis may be my legitimate interest in maintaining an effective and secure website. Where cookies or similar technologies require consent, they will only be used after appropriate consent has been obtained.
6. Legitimate interests
Where I rely on legitimate interests, I consider whether the processing is necessary and whether my interests are overridden by your rights and freedoms.
My legitimate interests may include: responding to business enquiries; managing client and supplier relationships;
operating and developing my consultancy; maintaining appropriate business records; securing my website and information systems; preventing fraud and misuse; and establishing or defending legal claims.
You may object to processing based on legitimate interests by contacting me.
7. Sharing personal information
I may share personal information where reasonably necessary with: website hosting, email, cloud storage and IT service providers; accounting, payment processing and bookkeeping providers; insurers, solicitors, accountants and other professional advisers; subcontractors or specialist consultants supporting the delivery of services; government departments, regulators, courts, law-enforcement bodies or other authorities where required by law; and another party in connection with the proposed sale, transfer or restructuring of the business.
Service providers are only given the information reasonably necessary to perform their services. Where required, I use appropriate contractual and security safeguards. I do not sell or rent personal information.
8. International transfers
Some technology or cloud service providers may store or access personal information outside the United Kingdom. Where personal information is transferred internationally, I will take reasonable steps to ensure that an appropriate lawful transfer mechanism and suitable safeguards are in place, as required by UK data protection law. Further information about relevant safeguards is available on request.
9. How long I keep personal information
I keep personal information only for as long as reasonably necessary for the purpose for which it was collected and to meet legal, tax, insurance and contractual requirements.
Typical retention periods are: unsuccessful enquiries and quotations: normally up to 12 after the last meaningful contact; client contracts, project correspondence and deliverables: normally up to six years after the end of the engagement; invoices, payment records and tax information: for the applicable statutory tax-record retention period; supplier records: normally up to six years after the relationship ends; complaint and dispute records: for as long as reasonably necessary to resolve the matter and protect legal rights; marketing records: until you withdraw consent, object or the information is no longer required; and website security records: for a limited period appropriate to their security purpose.
Information may be retained for longer where there is an ongoing dispute, legal claim, regulatory requirement or another lawful reason.
10. Information security
I take proportionate technical and organisational measures to protect personal information against unauthorised access, accidental loss, destruction, alteration or disclosure.
These measures may include: password protection and access controls; multi-factor authentication where available; secure and supported devices and software; reputable cloud and email service providers; secure backups; appropriate confidentiality arrangements; and limiting access to those who genuinely require the information.
No internet or email system is completely secure. You should avoid sending particularly sensitive or confidential information through unsecured email unless suitable safeguards have been agreed.
11. Your data protection rights
Depending on the circumstances, you may have the right to: be informed about how your personal information is used; request access to your personal information; ask for inaccurate or incomplete information to be corrected; ask for personal information to be erased; ask for processing to be restricted; object to processing based on legitimate interests; object at any time to direct marketing; receive certain information in a portable format; withdraw consent where processing is based on consent; and raise concerns about automated decision-making.
These rights are not absolute and may be subject to legal conditions or exemptions.
To exercise a right, contact me using the details in section 1. I may need to ask for information to confirm your identity. I will not normally charge a fee, although the law permits a reasonable fee or refusal in certain limited circumstances.
12. Automated decision-making
I do not currently use personal information to make solely automated decisions that produce legal or similarly significant effects. This notice will be updated if that changes.
13. Cookies
This website may use cookies or similar technologies.
Strictly necessary cookies may be used where required for the website to function or remain secure. Analytics, advertising or other non-essential cookies will not be used unless an appropriate legal basis, including consent where required, is in place.
14. Links to other websites
This website may contain links to third-party websites. I am not responsible for the privacy practices or content of those websites. You should review the privacy notice of any external website you visit.
15. Complaints
Please contact me first if you have concerns about how I use your personal information. I will take your concerns seriously and try to resolve them.
You also have the right to complain to the Information Commissioner’s Office, the UK regulator for data protection.
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
Website: www.ico.org.uk
16. Changes to this notice
I may update this Privacy Notice to reflect changes to my services, website, suppliers or legal obligations.
The latest version will be published on this website with its revision date. Where a change materially affects how personal information is used, I will take reasonable steps to bring it to the attention of affected individuals.