Reward Heads Privacy Policy
Effective date: 7 September 2026
Reward Heads Limited respects your privacy. This policy explains what personal data we collect, why we use it, who we share it with, how long we keep it and the rights available to you.
1. Who we are
Reward Heads Limited ("Reward Heads", "we", "us" or "our") is a company incorporated in England and Wales under company number 08410651. Our registered address is 4 Westland Close, Leavesden, Watford, WD25 7GH. Our website is www.rewardheads.co.uk.
Reward Heads Limited is the controller of personal data used for its own business purposes, including operating its website, managing enquiries and client relationships, organising events and carrying out marketing and business administration.
For some client assignments, we process personal data about a client's employees or other individuals only on that client's documented instructions. In those circumstances, the client is normally the controller and Reward Heads is its processor. The client's privacy notice explains how the client uses that information.
We are not required to appoint a statutory Data Protection Officer. We have appointed a privacy contact who coordinates data protection matters:
Jamie MilfordEmail: jamie@rewardheads.co.uk
Address: 4 Westland Close, Leavesden, Watford, WD25 7GH
2. Scope of this policy
This policy applies to personal data we process as a controller about website visitors, prospective and current clients, suppliers, professional contacts, event or forum participants, newsletter recipients and other people who interact with Reward Heads. It does not replace a client's own privacy notice where we act solely as that client's processor.
We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Data (Use and Access) Act 2025 and the Privacy and Electronic Communications Regulations 2003 (PECR), where applicable. The EU GDPR may also apply in limited circumstances where our activities fall within its territorial scope.
3. Personal data we collect
Depending on how you interact with us, we may collect and use:
- Identity and business information, such as your name, job title, employer and professional role.
- Contact information, such as your business email address, telephone number and postal address.
- Enquiry, correspondence and relationship information, including meeting notes, requirements, proposals, contracts and records of our communications.
- Event, forum and marketing information, including registrations, attendance, interests, communication preferences and unsubscribe requests.
- Financial and transaction information connected with services we provide or purchase.
- Website and technical information, which may include IP address, device and browser information, security logs, referral information and interactions with our website.
- Project data where Reward Heads is a controller, which may include job, pay, bonus, benefits, performance or workforce information supplied for reward analysis.
- Any other information you choose to provide to us.
Where possible, client project datasets are anonymised or pseudonymised before we receive them. Pseudonymised information remains personal data where an individual can still be identified using additional information.
4. Special-category data
Some reward, equal pay and pay-gap work may involve information revealing or concerning race or ethnicity, health or disability, religion or belief, sexual orientation or other special-category information. We will process such information only where it is necessary, proportionate and appropriately protected.
Where Reward Heads acts as a processor, the client is responsible for identifying the relevant UK GDPR Article 6 lawful basis and Article 9 condition, and we act only on the client's documented instructions. Where Reward Heads acts as a controller, we identify and document both an Article 6 lawful basis and an applicable Article 9 condition before processing. Depending on the circumstances, this may include explicit consent or substantial public interest in equality of opportunity or treatment under the Data Protection Act 2018. We maintain an appropriate policy document where the law requires one.
5. Where we obtain personal data
We may obtain personal data:
- directly from you, including through enquiries, meetings, events, forms and correspondence;
- from your employer, colleague or another person who introduces or involves you;
- from a client where information is needed for an assignment;
- from publicly accessible professional sources, such as corporate websites, Companies House or LinkedIn; and
- from service providers that support our website, communications, events or business administration.
6. How and why we use personal data
We use personal data only where we have a lawful basis. The principal purposes and bases are set out below. More than one basis may apply depending on the circumstances.
| Purpose | Typical lawful basis |
|---|---|
| Responding to enquiries and discussing potential work | Steps requested before entering a contract, or our legitimate interests in responding to enquiries and developing our business |
| Providing reward consultancy and managing client relationships | Performance of a contract, or our legitimate interests in delivering services and managing relationships with client representatives |
| Pay, benefits, reward and workforce analysis where we act as controller | Our or a client's legitimate interests in making informed, fair and effective reward decisions, subject to an assessment of individuals' rights and interests |
| Operating, securing and improving our website and systems | Our legitimate interests in providing a functional service, preventing fraud or misuse and maintaining information security |
| Events, forums, newsletters and relevant business communications | Consent where required, or our legitimate interests in communicating with professional contacts, together with compliance with PECR |
| Contracts, invoicing, tax, regulatory compliance and legal claims | Performance of a contract, compliance with legal obligations, or our legitimate interests in administering our business and protecting legal rights |
| Using approved AI-assisted tools | The same lawful basis that applies to the underlying activity for which the tool is used |
Where we rely on legitimate interests, we consider the necessity of the processing, the benefits sought and the potential impact on individuals. You may ask us for further information about a relevant assessment.
7. Marketing communications
We may send professional contacts information about Reward Heads services, insights, newsletters, forums and events where the law permits. Depending on the recipient and communication channel, we rely on consent or legitimate interests and comply with PECR.
You can unsubscribe at any time by using the link in a marketing email or contacting charis@rewardheads.co.uk. We may retain a minimal suppression record so that we continue to respect your request. Objecting to direct marketing does not affect service or administrative communications that are not marketing.
8. Use of artificial intelligence
We may use approved artificial intelligence-assisted tools to support activities such as research, analysis, drafting, summarisation and quality assurance. Where an activity involves personal data, we apply the same purpose and lawful basis as the underlying activity and use appropriate data-minimisation, confidentiality and security controls.
We assess relevant suppliers and contractual terms, restrict access to authorised personnel and seek to avoid entering identifiable or special-category personal data into general-purpose AI tools unless the use has been specifically authorised and appropriate safeguards are in place. AI-generated outputs are subject to proportionate human review.
Reward Heads does not use AI to make decisions based solely on automated processing that produce legal or similarly significant effects on individuals. If this changes, we will update this policy and provide meaningful information about the processing and the safeguards available.
9. Who we share personal data with
We do not sell personal data. Where necessary for the purposes described above, we may share it with:
- Reward Heads employees and authorised contractors who need the information for their work;
- clients, where this is necessary for an assignment or relationship;
- IT, cloud hosting, website, email, CRM, file-sharing, videoconferencing, event-management and cybersecurity providers;
- approved AI service providers, where personal data is processed through an authorised AI-assisted tool;
- accountants, insurers, auditors, legal advisers and other professional advisers;
- regulators, law-enforcement bodies, courts or other parties where disclosure is required by law or necessary to establish, exercise or defend legal rights; and
- a purchaser, investor or adviser in connection with a proposed sale, reorganisation or transfer of all or part of our business, subject to appropriate confidentiality protections.
We require processors acting on our behalf to process personal data only on our instructions, maintain appropriate security and assist us in meeting applicable data protection obligations.
10. International transfers
Some service providers may store or access personal data outside the United Kingdom. We only store our data in the Microsoft Cloud. If we had to make a restricted transfer, we would use a lawful transfer mechanism where required. This may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses or another mechanism permitted by UK data protection law. We also carry out any required transfer risk assessment and apply supplementary safeguards where appropriate. You may contact us for further information about the safeguards relevant to your data.
11. How long we keep personal data
We retain personal data only for as long as reasonably necessary for the relevant purpose, including legal, accounting and reporting requirements. Our usual periods are:
| Record | Usual retention approach |
|---|---|
| Unsuccessful enquiries and proposals | Normally up to two years after the last meaningful contact |
| Client relationship, contract and core project records | Normally six years after the end of the relevant engagement, where needed for contractual, tax or legal purposes |
| Identifiable client project datasets | Deleted (or returned in accordance with the client agreement), normally within 3 months after the purpose has been completed unless a different period is agreed or legally required |
| Accounting and tax records | Normally six years after the end of the relevant financial year, or longer if legally required |
| Marketing contact information | For as long as the relationship remains relevant, subject to periodic review and any objection or withdrawal of consent |
| Marketing suppression records | A minimal record may be retained for as long as necessary to respect the opt-out |
| Website and security logs | Normally no longer than 12 months unless needed to investigate an incident or legal claim |
We may retain information for longer where required by law, where a dispute or investigation is reasonably anticipated or active, or where records have been securely anonymised so that they are no longer personal data.
12. How we protect personal data
We use appropriate technical and organisational measures designed to protect personal data against unauthorised or unlawful access, alteration, disclosure, loss or destruction. Measures include proportionate access controls and authentication, staff training, secure systems, backup and recovery arrangements, supplier due diligence and incident-response procedures.
Reward Heads maintains Cyber Essentials certification as part of its information-security framework. We review our security measures in light of the nature of the information, how it is used and the risks to individuals. No electronic transmission or storage system can be guaranteed to be completely secure.
We maintain procedures for identifying, investigating and responding to personal-data breaches. Where required by law, we notify the Information Commissioner's Office and affected individuals.
13. Your rights
Depending on the circumstances and the lawful basis used, you may have the right to:
- be informed about how we use your personal data;
- request access to your personal data and receive a copy;
- ask us to correct inaccurate or incomplete information;
- ask us to erase personal data in certain circumstances;
- ask us to restrict processing in certain circumstances;
- receive certain information in a portable format or have it transferred to another controller;
- object to processing based on legitimate interests;
- object at any time to the use of your personal data for direct marketing;
- withdraw consent at any time where we rely on consent, without affecting earlier lawful processing; and
- request safeguards in relation to a significant decision based solely on automated processing, where applicable.
Your right to object to direct marketing is absolute. Other rights may be subject to legal conditions or exemptions. We may need to verify your identity before acting on a request. We normally respond within one month, although the law allows an extension in certain circumstances.
To exercise a right, contact Jamie Milford at jamie@rewardheads.co.uk. You will not usually have to pay a fee.
14. Children
Our website and services are intended for organisations and professional audiences and are not directed at children. We do not knowingly collect personal data directly from children through our website. If we learn that this has occurred, we will take appropriate steps to delete the information, unless the law requires us to retain it.
15. Cookies and similar technologies
Our website does not intentionally use optional analytics or advertising cookies. It may use strictly necessary cookies or similar technologies needed for security, network management, accessibility or core website functions. These do not require consent under PECR, but we provide information about them where they are used.
Third-party links or embedded content may be governed by the third party's own privacy and cookie information. We are not responsible for external websites. We periodically review the technologies used by our website and will update this policy and introduce an appropriate consent mechanism before using non-essential cookies or similar technologies.
16. Data protection complaints
You may make a data protection complaint by contacting Jamie Milford at jamie@rewardheads.co.uk. We will:
- acknowledge receipt of the complaint within 30 days;
- take appropriate steps to investigate and respond without undue delay;
- keep you informed about progress where appropriate; and
- tell you the outcome without undue delay once our investigation is complete.
You also have the right to complain to the Information Commissioner's Office (ICO). We would appreciate the opportunity to address your concern first, but you may contact the ICO directly at any time:
Information Commissioner's OfficeWycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
Website: www.ico.org.uk
17. Changes to this policy
We review this policy periodically and update it when our processing activities, suppliers or legal obligations change. The effective date at the beginning of the policy shows when it was last updated. Where a change materially affects individuals, we may provide an additional notice by email or another appropriate method.
18. Contact us
Questions about this policy or the way we use personal data should be sent to:
Jamie Milford, Privacy ContactReward Heads Limited, 4 Westland Close, Leavesden, Watford, WD25 7GH
Email: jamie@rewardheads.co.uk
Website: www.rewardheads.co.uk
