Legal & Compliance

Privacy Notice

How we collect, use, and protect your personal data — and what your rights are.

Version: 3.0.0

Published: August 2026

Last reviewed: August 2026

Next review: November 2026

Controller: Vulnerability Managers Limited

Introduction

We are Vulnerability Managers, a UK consultancy run by Matt Radford. We provide training, coaching, consultancy, and advisory services on how to work with people in vulnerable circumstances.

We collect personal data to deliver our services and to meet our legal obligations. We never sell your data. We do not share it with third parties except where we have a legal duty to do so — for example, in a safeguarding situation.

You have rights over your data, including the right to see what we hold, to ask us to correct it, and in some cases to ask us to delete it.

To use those rights, or to ask us any questions, contact matt@vulnerabilitymanagers.com.

If you are not satisfied with how we handle your data, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.

Who we are

We are Vulnerability Managers Limited, a company registered in England and Wales (Company No. 17145853). We trade as Vulnerability Managers.

Our founder and director is Matt Radford. He is the data controller for all personal data Vulnerability Managers processes.

Registered address: Vulnerability Managers Limited, Chingford, London, United Kingdom.

Contact:matt@vulnerabilitymanagers.com

What personal data we collect

We only collect what we need. The type of data we collect depends on how you work with us.

If you enquire about or book our services

  • Name, job title, organisation

  • Email address and phone number

  • Information about the service you are enquiring about

  • Accessibility and adjustment requirements you choose to share

If you attend training, coaching, or a consultancy engagement

  • Attendance records

  • Session notes (where relevant to the engagement)

  • Accessibility requirements and reasonable adjustments

  • Any information about your circumstances you choose to share with us

If you are an associate or subcontractor

  • Identity and contact information

  • Right-to-work documentation

  • Qualifications and professional memberships

  • DBS check information where regulated activity applies

  • Contractual and financial records

If you are a third-party partner or supplier

  • Organisation and contact details

  • Information gathered as part of our due diligence process

  • Contractual records and monitoring notes

If you visit our website

  • Cookies and analytics data (see our separate Cookie Policy)

  • Any information you submit via a contact or enquiry form

Why we collect it — our lawful bases

Under UK GDPR Article 6, we must have a lawful basis for processing personal data. Below sets out the bases we rely on and when each applies.

Performance of a contract - 6(1)(b)

Delivering services you have engaged us to provide — training, coaching, consultancy, advisory work

Legal obligation - 6(1)(c)

Meeting our duties under safeguarding law, modern slavery legislation, HMRC requirements, and other legal requirements

Vital interests - 6(1)(d)

In safeguarding situations where we believe someone's life or safety is at risk and we cannot obtain consent in time

Legitimate interests - 6(1)(f)

Responding to enquiries; running due diligence on partners; maintaining records needed for the safe delivery of services; communication with clients and associates about existing engagements

Consent - 6(1)(a)

Where we use specific tools — for example, transcription software — and ask for your agreement before using them. Consent is always specific, informed, and freely given, and you can withdraw it at any time

Special category data

Some of the data we may handle is classified under UK GDPR Article 9 as special category data. This includes information about health, disability, mental health, and other protected characteristics.

We come into contact with this type of data through:

  • Requests for reasonable adjustments from delegates or coachees

  • Voluntary disclosures of vulnerability or personal circumstances during an engagement

  • Safeguarding disclosures that require us to act

  • Equality, diversity and inclusion considerations in our work

Our Article 9 conditions

For special category data, we must also meet a condition under UK GDPR Article 9. The conditions we rely on are:

  • Explicit consent — where you have actively chosen to share information with us for a specific purpose (Article 9(2)(a))

  • Vital interests — in a safeguarding situation where processing is necessary to protect life and consent cannot be obtained (Article 9(2)(c))

  • Safeguarding condition — under Schedule 1 Part 2 of the Data Protection Act 2018, for processing necessary for safeguarding purposes

How we handle it

We collect the minimum we need for the purpose. We use it only for that purpose. We store it securely and do not share it with clients, other delegates, or third parties without your consent — except in the narrow circumstances described in Section 6 below.

How we use your data

We use the data we collect only for the purpose it was collected for. Specifically:

  • To deliver the service you have engaged us to provide

  • To make reasonable adjustments so you can participate fully

  • To respond to a disclosure of vulnerability in a way that is appropriate and proportionate

  • To meet our safeguarding obligations — identifying risk, responding, recording, and referring when needed

  • To carry out due diligence before we work with a third-party partner or supplier

  • To comply with our legal obligations (safeguarding law, modern slavery legislation, HMRC, and others)

  • To communicate with you about an existing engagement

We do not use your personal data for unsolicited marketing. We do not use automated decision-making that would have a significant effect on you.

Purpose limitation

Data collected for one purpose is not used for another purpose without a fresh lawful basis. For example, information you share with us to request a reasonable adjustment is used to make that adjustment — it is not passed to your employer or shared with other participants.

Who we share your data with

We share personal data with third parties only when we have to or when we have your consent.

When we may share data without your consent

  • Safeguarding referrals — if we have a duty to act to protect someone from harm, we may share information with the relevant local authority, police, Disclosure and Barring Service (DBS), Charity Commission, or regulator. We share only what is necessary.

  • Legal obligations — where a court order, regulatory duty, or other legal requirement means we must disclose information

  • HMRC — financial and tax records where required by law

When we share data with your knowledge

  • Associates and subcontractors — where a colleague is involved in delivering a service to you, they will have access to what they need to do that work. All associates sign a data processing agreement and must follow this Privacy Notice.

  • Technology providers — for example, secure file storage or video conferencing tools we use in service delivery. These providers are assessed before use and must meet our data protection requirements.

What we do not do

  • We do not sell your personal data

  • We do not share vulnerability or adjustment disclosures with clients, employers, or other participants without your consent

  • We do not transfer personal data outside the UK unless we have a lawful transfer mechanism in place (such as an International Data Transfer Agreement — IDTA)

AI and your data

We use AI tools to support our work — for drafting, summarising, and administrative tasks. Our AI Use Policy sets firm limits on how your data is involved.

AI is a drafting tool here, not a decision tool. A person is accountable for everything we produce with it.

What we use AI for

We use AI tools to help us:

  • develop written copy, including web pages, emails, proposals and training materials

  • structure and draft reports and other documents

  • produce images and illustrations for general, non-personal use

  • prepare marketing and communications material

  • summarise published research, guidance and other open-source material

  • structure and organise ideas

  • produce code, data analysis and templates

  • transcribe and take notes, where everyone present has agreed first

These are examples and not a full list. The tools available change quickly, and so does what we use them for.

Human oversight

Nothing AI-assisted reaches a client, a regulator or the public without human review. A named person at Vulnerability Managers carries out that review.

That person is accountable for the accuracy, fairness and tone of what we publish. "The tool said so" is not an answer we accept, from ourselves or from the associates who work with us.

In practice this means:

  • every AI-assisted draft is read, checked and edited by a person before it is used

  • factual claims are confirmed against the original source, not against the tool

  • content is checked for bias — in particular bias relating to disability, mental health, ethnicity, age, sex, gender identity and socio-economic status

  • images are checked so that they do not rely on stereotyped depictions of people in vulnerable circumstances

  • serious subject matter is checked so that it is not trivialised

Your data and AI

  • We do not use AI to make automated decisions about you that would have a significant effect

  • Where we use transcription tools, we ask for your consent first, tell you which tool we use, and confirm how long the recording is kept

What we do not use AI for

We do not:

  • use AI in place of human judgement on safeguarding, vulnerability response, or other ethically sensitive decisions

  • generate content that impersonates a real, named person, or that attributes words to them that they did not say

  • allow an AI provider to keep your data for training or other secondary purposes without your explicit, informed consent

Before we adopt a tool

We check each tool before we use it. We look at:

  • the provider's data processing terms

  • whether our inputs are used to train the provider's models, and whether that can be switched off

  • where processing and storage take place

  • whether the tool is appropriate for the sensitivity of the information involved

Telling you when AI has been used

Where AI has been used in producing a deliverable for you, we tell you — for example, noting that a report includes AI-assisted drafting reviewed and signed off by Matt Radford.

Where your own organisation has a policy restricting AI use, we follow your policy rather than ours.

If something goes wrong

AI tools make mistakes. They can state something confidently that is not true, and they can invent sources that look real. Our review process exists to catch that before it reaches you.

If something is missed or incorrect, tell us at matt@vulnerabilitymanagers.com to help us correct it and avoid similar errors in the future.

Where an error involves your personal data, we also run our breach process. That includes reporting to the Information Commissioner's Office within 72 hours where the legal threshold is met.

Review

We review this section, and the AI Use Policy behind it, every six months. AI tools and AI regulation both move quickly, and an annual review would be too slow. This is the cadence set out in Section 11.

Your rights over your personal data are not changed by our use of AI. They are set out in full in the ‘your rights’ section.

How long we keep your data

We keep personal data only as long as we need it. The length of time depends on the type of data and the purpose it was collected for. This includes, the type of record, how long we keep it and the reason.

Client contracts and financial records

  • 7 years from end of engagement (Legal and tax obligation)

Safeguarding records

  • As required by relevant safeguarding guidance — typically until the youngest person involved reaches 25, or longer where a serious incident occurred (Legal duty; guidance from statutory safeguarding bodies)

Reasonable adjustment records

  • Duration of the engagement; deleted promptly when no longer needed (Purpose limitation — collected for the adjustment only)

Vulnerability disclosures (non-safeguarding)

  • Duration of the engagement; deleted promptly when no longer needed (Data minimisation — minimum necessary, minimum duration)

Associate and subcontractor records

  • Duration of the engagement plus 7 years (Legal and contractual obligations)

Enquiries not leading to an engagement

  • 12 months from last contact (Legitimate interests; deleted when purpose is exhausted)

When data is no longer needed, it is deleted securely.

Paper records are shredded.

Digital records are permanently deleted from all storage locations including backups within a reasonable time.

Your rights

Under UK GDPR, you have a number of rights over your personal data. Your rights depend on the lawful basis we use to process your data and the specific circumstances.

Access

  • Ask us to confirm whether we hold data about you and to receive a copy. This is called a Subject Access Request (SAR). We respond within one month.

Rectification

  • Ask us to correct data that is inaccurate or incomplete.

Erasure

  • Ask us to delete your data in certain circumstances — for example, where the data is no longer needed or you withdraw consent.

Restriction

  • Ask us to limit how we use your data while a query is resolved.

Portability

  • Receive your data in a structured, machine-readable format where we process it by automated means on the basis of consent or contract.

Object

  • Object to processing based on legitimate interests. We will stop unless we can show a compelling reason that overrides your interests.

Withdraw consent

  • Where we process your data on the basis of consent, you can withdraw it at any time. Withdrawal does not affect processing that took place before you withdrew.

Automated decisions

  • Not to be subject to a solely automated decision that has a significant effect on you. We do not make such decisions.

To exercise any of these rights, contact us at the details in Section 10.

We do not charge a fee for standard requests. We may ask you to confirm your identity before responding.

Contact and complaints

If you have a question about this notice, want to exercise a right, or have a concern about how we have handled your data, contact us directly in the first instance.

Data controller contact

Matt Radford, Director

Email: matt@vulnerabilitymanagers.com

We aim to acknowledge all data-related requests within five working days and to respond fully within one month of receiving your request.

If you are not satisfied with our response, or if you believe we are processing your data unlawfully, you have the right to complain to the Information Commissioner's Office (ICO) — the UK supervisory authority for data protection.

Information Commissioner's Office (ICO)

Website: ico.org.uk

Helpline: 0303 123 1113

You can also make a complaint using the ICO's online form at ico.org.uk/make-a-complaint

Changes to this notice

We review this Privacy Notice in line with our data protection obligations and any changes to the law or our services. The review schedule follows our AI Use Policy cadence — every six months until the regulatory landscape stabilises — and in any case when a material change occurs.

Material changes include: a new service or way of processing data; a change to the lawful bases we rely on; a new technology provider; or a relevant change in UK data protection law.

When we make a significant change, we update the version number and the "last reviewed" date at the top of this page. We do not notify individuals of minor updates.

The current version of this notice is always available at vulnerabilitymanagers.com/privacy.

Version history

Version: 2.0.0

Date: May 2026