Legal & Compliance
Privacy Notice
How we collect, use, and protect your personal data — and what your rights are.
Version: 3.0.0
Published: August 2026
Last reviewed: August 2026
Next review: November 2026
Controller: Vulnerability Managers Limited
Introduction
We are Vulnerability Managers, a UK consultancy run by Matt Radford. We provide training, coaching, consultancy, and advisory services on how to work with people in vulnerable circumstances.
We collect personal data to deliver our services and to meet our legal obligations. We never sell your data. We do not share it with third parties except where we have a legal duty to do so — for example, in a safeguarding situation.
You have rights over your data, including the right to see what we hold, to ask us to correct it, and in some cases to ask us to delete it.
To use those rights, or to ask us any questions, contact matt@vulnerabilitymanagers.com.
If you are not satisfied with how we handle your data, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
Who we are
We are Vulnerability Managers Limited, a company registered in England and Wales (Company No. 17145853). We trade as Vulnerability Managers.
Our founder and director is Matt Radford. He is the data controller for all personal data Vulnerability Managers processes.
Registered address: Vulnerability Managers Limited, Chingford, London, United Kingdom.
Contact:matt@vulnerabilitymanagers.com
What personal data we collect
We only collect what we need. The type of data we collect depends on how you work with us.
If you enquire about or book our services
Name, job title, organisation
Email address and phone number
Information about the service you are enquiring about
Accessibility and adjustment requirements you choose to share
If you attend training, coaching, or a consultancy engagement
Attendance records
Session notes (where relevant to the engagement)
Accessibility requirements and reasonable adjustments
Any information about your circumstances you choose to share with us
If you are an associate or subcontractor
Identity and contact information
Right-to-work documentation
Qualifications and professional memberships
DBS check information where regulated activity applies
Contractual and financial records
If you are a third-party partner or supplier
Organisation and contact details
Information gathered as part of our due diligence process
Contractual records and monitoring notes
If you visit our website
Cookies and analytics data (see our separate Cookie Policy)
Any information you submit via a contact or enquiry form
Why we collect it — our lawful bases
Under UK GDPR Article 6, we must have a lawful basis for processing personal data. Below sets out the bases we rely on and when each applies.
Performance of a contract - 6(1)(b)
Delivering services you have engaged us to provide — training, coaching, consultancy, advisory work
Legal obligation - 6(1)(c)
Meeting our duties under safeguarding law, modern slavery legislation, HMRC requirements, and other legal requirements
Vital interests - 6(1)(d)
In safeguarding situations where we believe someone's life or safety is at risk and we cannot obtain consent in time
Legitimate interests - 6(1)(f)
Responding to enquiries; running due diligence on partners; maintaining records needed for the safe delivery of services; communication with clients and associates about existing engagements
Consent - 6(1)(a)
Where we use specific tools — for example, transcription software — and ask for your agreement before using them. Consent is always specific, informed, and freely given, and you can withdraw it at any time
Special category data
Some of the data we may handle is classified under UK GDPR Article 9 as special category data. This includes information about health, disability, mental health, and other protected characteristics.
We come into contact with this type of data through:
Requests for reasonable adjustments from delegates or coachees
Voluntary disclosures of vulnerability or personal circumstances during an engagement
Safeguarding disclosures that require us to act
Equality, diversity and inclusion considerations in our work
Our Article 9 conditions
For special category data, we must also meet a condition under UK GDPR Article 9. The conditions we rely on are:
Explicit consent — where you have actively chosen to share information with us for a specific purpose (Article 9(2)(a))
Vital interests — in a safeguarding situation where processing is necessary to protect life and consent cannot be obtained (Article 9(2)(c))
Safeguarding condition — under Schedule 1 Part 2 of the Data Protection Act 2018, for processing necessary for safeguarding purposes
How we handle it
We collect the minimum we need for the purpose. We use it only for that purpose. We store it securely and do not share it with clients, other delegates, or third parties without your consent — except in the narrow circumstances described in Section 6 below.
How we use your data
We use the data we collect only for the purpose it was collected for. Specifically:
To deliver the service you have engaged us to provide
To make reasonable adjustments so you can participate fully
To respond to a disclosure of vulnerability in a way that is appropriate and proportionate
To meet our safeguarding obligations — identifying risk, responding, recording, and referring when needed
To carry out due diligence before we work with a third-party partner or supplier
To comply with our legal obligations (safeguarding law, modern slavery legislation, HMRC, and others)
To communicate with you about an existing engagement
We do not use your personal data for unsolicited marketing. We do not use automated decision-making that would have a significant effect on you.
Purpose limitation
Data collected for one purpose is not used for another purpose without a fresh lawful basis. For example, information you share with us to request a reasonable adjustment is used to make that adjustment — it is not passed to your employer or shared with other participants.
Who we share your data with
We share personal data with third parties only when we have to or when we have your consent.
When we may share data without your consent
Safeguarding referrals — if we have a duty to act to protect someone from harm, we may share information with the relevant local authority, police, Disclosure and Barring Service (DBS), Charity Commission, or regulator. We share only what is necessary.
Legal obligations — where a court order, regulatory duty, or other legal requirement means we must disclose information
HMRC — financial and tax records where required by law
When we share data with your knowledge
Associates and subcontractors — where a colleague is involved in delivering a service to you, they will have access to what they need to do that work. All associates sign a data processing agreement and must follow this Privacy Notice.
Technology providers — for example, secure file storage or video conferencing tools we use in service delivery. These providers are assessed before use and must meet our data protection requirements.
What we do not do
We do not sell your personal data
We do not share vulnerability or adjustment disclosures with clients, employers, or other participants without your consent
We do not transfer personal data outside the UK unless we have a lawful transfer mechanism in place (such as an International Data Transfer Agreement — IDTA)
AI and your data
We use AI tools to support our work — for drafting, summarising, and administrative tasks. Our AI Use Policy sets firm limits on how your data is involved.
AI is a drafting tool here, not a decision tool. A person is accountable for everything we produce with it.
What we use AI for
We use AI tools to help us:
develop written copy, including web pages, emails, proposals and training materials
structure and draft reports and other documents
produce images and illustrations for general, non-personal use
prepare marketing and communications material
summarise published research, guidance and other open-source material
structure and organise ideas
produce code, data analysis and templates
transcribe and take notes, where everyone present has agreed first
These are examples and not a full list. The tools available change quickly, and so does what we use them for.
Human oversight
Nothing AI-assisted reaches a client, a regulator or the public without human review. A named person at Vulnerability Managers carries out that review.
That person is accountable for the accuracy, fairness and tone of what we publish. "The tool said so" is not an answer we accept, from ourselves or from the associates who work with us.
In practice this means:
every AI-assisted draft is read, checked and edited by a person before it is used
factual claims are confirmed against the original source, not against the tool
content is checked for bias — in particular bias relating to disability, mental health, ethnicity, age, sex, gender identity and socio-economic status
images are checked so that they do not rely on stereotyped depictions of people in vulnerable circumstances
serious subject matter is checked so that it is not trivialised
Your data and AI
We do not use AI to make automated decisions about you that would have a significant effect
Where we use transcription tools, we ask for your consent first, tell you which tool we use, and confirm how long the recording is kept
What we do not use AI for
We do not:
use AI in place of human judgement on safeguarding, vulnerability response, or other ethically sensitive decisions
generate content that impersonates a real, named person, or that attributes words to them that they did not say
allow an AI provider to keep your data for training or other secondary purposes without your explicit, informed consent
Before we adopt a tool
We check each tool before we use it. We look at:
the provider's data processing terms
whether our inputs are used to train the provider's models, and whether that can be switched off
where processing and storage take place
whether the tool is appropriate for the sensitivity of the information involved
Telling you when AI has been used
Where AI has been used in producing a deliverable for you, we tell you — for example, noting that a report includes AI-assisted drafting reviewed and signed off by Matt Radford.
Where your own organisation has a policy restricting AI use, we follow your policy rather than ours.
If something goes wrong
AI tools make mistakes. They can state something confidently that is not true, and they can invent sources that look real. Our review process exists to catch that before it reaches you.
If something is missed or incorrect, tell us at matt@vulnerabilitymanagers.com to help us correct it and avoid similar errors in the future.
Where an error involves your personal data, we also run our breach process. That includes reporting to the Information Commissioner's Office within 72 hours where the legal threshold is met.
Review
We review this section, and the AI Use Policy behind it, every six months. AI tools and AI regulation both move quickly, and an annual review would be too slow. This is the cadence set out in Section 11.
Your rights over your personal data are not changed by our use of AI. They are set out in full in the ‘your rights’ section.
How long we keep your data
We keep personal data only as long as we need it. The length of time depends on the type of data and the purpose it was collected for. This includes, the type of record, how long we keep it and the reason.
Client contracts and financial records
7 years from end of engagement (Legal and tax obligation)
Safeguarding records
As required by relevant safeguarding guidance — typically until the youngest person involved reaches 25, or longer where a serious incident occurred (Legal duty; guidance from statutory safeguarding bodies)
Reasonable adjustment records
Duration of the engagement; deleted promptly when no longer needed (Purpose limitation — collected for the adjustment only)
Vulnerability disclosures (non-safeguarding)
Duration of the engagement; deleted promptly when no longer needed (Data minimisation — minimum necessary, minimum duration)
Associate and subcontractor records
Duration of the engagement plus 7 years (Legal and contractual obligations)
Enquiries not leading to an engagement
12 months from last contact (Legitimate interests; deleted when purpose is exhausted)
When data is no longer needed, it is deleted securely.
Paper records are shredded.
Digital records are permanently deleted from all storage locations including backups within a reasonable time.
Your rights
Under UK GDPR, you have a number of rights over your personal data. Your rights depend on the lawful basis we use to process your data and the specific circumstances.
Access
Ask us to confirm whether we hold data about you and to receive a copy. This is called a Subject Access Request (SAR). We respond within one month.
Rectification
Ask us to correct data that is inaccurate or incomplete.
Erasure
Ask us to delete your data in certain circumstances — for example, where the data is no longer needed or you withdraw consent.
Restriction
Ask us to limit how we use your data while a query is resolved.
Portability
Receive your data in a structured, machine-readable format where we process it by automated means on the basis of consent or contract.
Object
Object to processing based on legitimate interests. We will stop unless we can show a compelling reason that overrides your interests.
Withdraw consent
Where we process your data on the basis of consent, you can withdraw it at any time. Withdrawal does not affect processing that took place before you withdrew.
Automated decisions
Not to be subject to a solely automated decision that has a significant effect on you. We do not make such decisions.
To exercise any of these rights, contact us at the details in Section 10.
We do not charge a fee for standard requests. We may ask you to confirm your identity before responding.
Contact and complaints
If you have a question about this notice, want to exercise a right, or have a concern about how we have handled your data, contact us directly in the first instance.
We aim to acknowledge all data-related requests within five working days and to respond fully within one month of receiving your request.
If you are not satisfied with our response, or if you believe we are processing your data unlawfully, you have the right to complain to the Information Commissioner's Office (ICO) — the UK supervisory authority for data protection.
Information Commissioner's Office (ICO)
Website: ico.org.uk
Helpline: 0303 123 1113
You can also make a complaint using the ICO's online form at ico.org.uk/make-a-complaint
Changes to this notice
We review this Privacy Notice in line with our data protection obligations and any changes to the law or our services. The review schedule follows our AI Use Policy cadence — every six months until the regulatory landscape stabilises — and in any case when a material change occurs.
Material changes include: a new service or way of processing data; a change to the lawful bases we rely on; a new technology provider; or a relevant change in UK data protection law.
When we make a significant change, we update the version number and the "last reviewed" date at the top of this page. We do not notify individuals of minor updates.
The current version of this notice is always available at vulnerabilitymanagers.com/privacy.
Version history
Version: 2.0.0
Date: May 2026

