Last updated: 07/07/2026

This Privacy Policy explains how Scott Risk Management Ltd collects and uses personal data when you visit this website, contact us, request a demo, use our website chatbot or interact with our website content.

This policy applies to the public website only. It does not replace any separate privacy information, data processing terms or client agreement that may apply when you become a client, use SRM Genie, receive consultancy services, attend training or enter into a formal agreement with us.

1. Who we are

Scott Risk Management Ltd is the organisation responsible for this website.

Trading names may include Scott Risk Management, SRM, SRM Genie, SRM Consulting, and SRM Training.

Registered office: 167-169 Great Portland Street, 5th Floor, London, W1W 5PF Company number: 11908951 VAT number: GB322782310 Email: enquiries@scottrm.co.uk Telephone: 01952 794 796

For the purposes of UK data protection law, Scott Risk Management Ltd will usually be the data controller for personal data collected through this website.

2. Personal data we may collect

We may collect personal data when you use this website, including:

Information you provide directly

This may include:

  • your name;
  • job title;
  • company name;
  • email address;
  • telephone number;
  • location or region;
  • information about your organisation;
  • information submitted through contact forms, demo request forms or enquiry forms;
  • information provided through the website chatbot;
  • marketing preferences;
  • any other information you choose to provide.

Technical and website usage information

Depending on the tools used on the website, we may collect:

  • IP address;
  • browser type and version;
  • device type;
  • operating system;
  • pages visited;
  • time and date of visits;
  • referring website;
  • interactions with website pages, forms or links;
  • cookie and analytics information, where applicable.

Chatbot information

If you use the website chatbot, we may collect:

  • your questions or messages;
  • contact details you provide;
  • business information you choose to share;
  • date and time of the conversation;
  • conversation history needed to respond to your enquiry.

You should not submit confidential, sensitive, special category, commercially sensitive or highly detailed operational information through the website chatbot unless we have specifically asked you to do so through an appropriate agreed process.

3. How we use personal data

We may use personal data to:

  • respond to enquiries;
  • arrange demonstrations;
  • provide information about SRM Genie or our services;
  • understand whether our services may be suitable for your organisation;
  • send requested resources, information or follow-up communications;
  • manage sales and business development activity;
  • operate and improve the website;
  • monitor website performance and security;
  • manage chatbot interactions;
  • maintain records of enquiries and communications;
  • comply with legal, regulatory and accounting requirements;
  • protect our business, website, systems and legal rights.

4. Lawful basis for using personal data

We will only use personal data where we have a lawful basis to do so.

The lawful bases we may rely on include:

Legitimate interests

We may use personal data where it is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms.

This may include responding to business enquiries, managing potential customer relationships, improving our website, protecting our systems, maintaining business records and promoting relevant business services.

Consent

We may rely on consent where you have actively agreed to something, such as receiving certain marketing communications or accepting non-essential cookies.

Where we rely on consent, you can withdraw it at any time.

Contract or steps before entering into a contract

We may use personal data where necessary to take steps at your request before entering into a contract, such as preparing a proposal or arranging a demonstration.

Legal obligation

We may use personal data where necessary to comply with a legal obligation, such as tax, accounting, regulatory or legal record-keeping requirements.

5. Marketing communications

If you submit an enquiry, request a demo or engage with us as a business contact, we may contact you about relevant SRM Genie or Scott Risk Management services.

Where required, we will ask for your consent before sending marketing communications.

You can opt out of marketing communications at any time by using the unsubscribe option in an email, where available, or by contacting us directly.

We will not sell your personal data to third parties.

6. Cookies and similar technologies

This website may use cookies or similar technologies to make the website work, improve performance, understand website use and support marketing activity.

Some cookies are essential for the website to function. Others, such as functional, analytics, marketing or social-proof cookies, are only used where the appropriate consent has been provided. This includes the Zoho live-chat service and ProveSource social-proof services where enabled.

Where non-essential cookies are used, the website provides a cookie banner or consent tool explaining what cookies are used and allowing you to manage your choices.

You can also control cookies through your browser settings.

7. Analytics and tracking

We may use Google Analytics to understand how visitors use the website, which pages are visited and how the website can be improved.

Where analytics cookies or similar tracking technologies are used, we will handle them in line with applicable cookie and privacy requirements.

8. Third-party services

We may use trusted third-party providers to operate this website and manage enquiries.

These may include providers for:

  • website hosting;
  • form handling;
  • CRM systems;
  • email systems;
  • chatbot services;
  • analytics;
  • website security;
  • business administration.

For example, the website may use Zoho tools for forms, chatbot, CRM or customer communication, and ProveSource for social-proof notifications. Where third-party providers process personal data on our behalf, they are expected to handle it securely and only in line with appropriate instructions and legal requirements.

9. Data location and international transfers

Personal data collected through this website is intended to be stored and processed within the United Kingdom and/or European Economic Area.

Where we use third-party systems to support website forms, chatbot functionality, CRM, email communication, analytics, hosting or website administration, we will take reasonable steps to ensure that personal data is retained within the UK and/or EEA wherever this is available and within our control.

We do not intentionally transfer personal data collected through this website outside the UK or EEA for routine website enquiry, chatbot, CRM or marketing purposes.

If a transfer outside the UK or EEA becomes necessary, we will only do this where appropriate safeguards are in place in line with applicable data protection law. This may include an adequacy decision, appropriate contractual safeguards or another lawful transfer mechanism

10. How long we keep personal data

We will only keep personal data for as long as reasonably necessary for the purpose it was collected.

As a general guide:

  • enquiry records may be kept while the enquiry is active and for a reasonable period afterwards;
  • proposal and business communication records may be kept for business administration and legal purposes;
  • marketing records may be kept until you unsubscribe or ask us to stop contacting you;
  • website analytics data may be kept in line with the settings of the relevant analytics tool;
  • legal, tax and accounting records may be kept for the period required by law.

11. How we protect personal data

We take reasonable steps to protect personal data against unauthorised access, loss, misuse, alteration or disclosure.

These steps may include access controls, secure systems, password protection, supplier controls, staff awareness and appropriate technical and organisational measures.

No website, email system or online service can be guaranteed to be completely secure. You should take care when deciding what information to send through forms, email or chatbot tools.

12. Sharing personal data

We may share personal data with:

  • employees, consultants or contractors who need it to respond to enquiries or provide services;
  • IT, hosting, CRM, email, chatbot or website service providers;
  • professional advisers, such as accountants, insurers or legal advisers;
  • regulators, public authorities or law enforcement where required;
  • other parties where necessary to protect our rights, safety, property or legal position.

We do not sell personal data.

13. Your data protection rights

Depending on the circumstances, you may have rights under data protection law, including the right to:

  • be informed about how your personal data is used;
  • access your personal data;
  • ask for inaccurate personal data to be corrected;
  • ask for personal data to be erased;
  • ask for processing to be restricted;
  • object to certain processing;
  • request data portability, where applicable;
  • withdraw consent, where processing is based on consent;
  • complain to the Information Commissioner’s Office.

Some rights only apply in certain circumstances.

14. How to contact us about privacy

To ask a question about this Privacy Policy or how we use personal data, please contact:

Scott Risk Management Ltd Email: enquiries@scottrm.co.uk Telephone: 01952 794 796 Address: 167-169 Great Portland Street, 5th Floor, London, W1W 5PF

15. Complaints

If you are unhappy with how we handle your personal data, please contact us first so we can try to resolve the issue.

You also have the right to complain to the Information Commissioner’s Office, which is the UK supervisory authority for data protection.

Website: www.ico.org.uk

16. Changes to this Privacy Policy

We may update this Privacy Policy from time to time.

The latest version will be published on this page. Where changes are significant, we may take additional steps to bring them to your attention.