Legal

Privacy Policy.

This policy explains how Beers Consultancy collects and uses personal data when you use our website or contact us, and your rights over it. It does not cover personal data inside instruction and project material, which is handled under the contract for that work.

Last updated: 27 September 2026.

1.0

Who we are

Beers Consultancy is a trading name of Beers Building & Fire Safety Ltd, a company registered in England and Wales under company number 15020311, with its registered office at 167-169 Great Portland Street, Fifth Floor, London W1W 5PF.

Beers Building & Fire Safety Ltd is the controller of the personal data described in this policy. We are registered with the Information Commissioner's Office under reference ZC259294.

For any question about this policy or your personal data, contact us at admin@beersconsultancy.co.uk or write to us at the address above, marked for the attention of the Director. We have not appointed a data protection officer because we are not required to, but the Director is responsible for data protection within the practice.

What this policy covers

Personal data you give us through this site, by email or by telephone, and the data our website host records when you visit. Personal data inside instruction and project material is handled under the contract for that work, which sets out the role, the lawful basis, retention and the arrangements for special category data.

2.0

The personal data we collect

Depending on how you deal with us, we may collect:

  • Contact and identity details: name, job title, organisation, email address, telephone number and postal address.
  • Enquiry content: what you tell us through the contact form, by email or by telephone.
  • Website data: technical information such as IP address and browser type, recorded in the server logs kept by our website host, from which we receive aggregate statistics. We set no cookies, as described below.

We do not ask for special category data, such as health information, through this website, and you should not send it to us through the enquiry form. Where it arises in instruction material it is governed by the contract for that work.

3.0

How we use personal data, and our lawful basis

We only use personal data where the law allows. The table below sets out what we do with the data this website and our general correspondence bring us, the lawful basis we rely on under Article 6 of the UK GDPR and how long we keep it. Personal data in instruction and project material is covered by the contract for that work.

  • Responding to website, email and telephone enquiries

    Contact details, enquiry content

    Legitimate interests: responding to people who contact us. Where you are enquiring as an individual about engaging us, steps taken at your request before entering into a contract.

    24 months from last contact if no instruction follows

  • Operating the website, and understanding which pages are read

    Website data

    Legitimate interests: keeping the site secure and available, and knowing which pages are read so that the site can be made more useful. The statistics we see are aggregate and identify nobody. Cookies and site storage are covered in the section below.

    Server logs held by our host under its own retention policy. We set no cookies.

  • Recruitment, where you send us a CV

    CV and application details

    Legitimate interests in assessing applicants. Steps before a contract.

    6 months after the recruitment decision, unless you agree to a longer period

  • Responding to data protection requests and complaints

    Details of the request or complaint and our response

    Legal obligation.

    3 years from closure

Where we rely on legitimate interests, we have considered whether those interests are outweighed by your rights and freedoms. You can ask us for more information about that assessment.

We do not use personal data to make decisions about you by solely automated means, and we do not sell personal data.

4.0

Who we share personal data with

We share the personal data covered by this policy only where it is needed for the purposes above, and only with:

  • Service providers who support our business: website hosting, the enquiry form and aggregate website statistics (Netlify), and email and document storage (Microsoft 365). Our records are kept in a system we built and run ourselves, and we use no external IT support provider. They act on our instructions and are bound to keep the data secure.
  • Our professional advisers and insurers, where needed to obtain advice, maintain cover or deal with a claim.
  • The Royal Institution of Chartered Surveyors, where required by professional regulation or to handle a complaint.
  • Law enforcement, courts or other parties where the law requires it, or where needed to establish, exercise or defend legal claims.

We do not share personal data with other businesses for their own marketing.

5.0

International transfers, and security

Some of our service providers store or access data outside the United Kingdom. Where they do, we make sure the transfer is protected, either because the destination benefits from UK adequacy regulations, or because appropriate safeguards are in place, such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or certification under the UK Extension to the EU-US Data Privacy Framework. You can ask us for details of the safeguard that applies.

We use technical and organisational measures appropriate to the data we hold, including access controls, multi-factor authentication on business systems, encrypted storage and restricted access to project files. If a personal data breach occurs that is likely to result in a risk to you, we will notify the Information Commissioner's Office and, where required, you.

6.0

Cookies, site storage and measurement

Our website sets no cookies. It loads no analytics script, no advertising tag, no social tracking pixel, no embedded video and no web font from a third party, and it carries no cookie banner, because there is nothing stored on your device to consent to.

We do see how the site is used. Our host produces aggregate statistics from the server logs it already keeps: how many times a page was requested, roughly where the request came from and which site it came from. Nothing is stored on your device and nothing is read from it, no cookie is set, and no identifier follows you between visits or between websites. We cannot identify you from any of it, and we use it for one purpose, to know which pages are read and which are not.

The site stores one item in your browser's session storage: whether you have paused the moving list of organisations on the home page. It is cleared when you close the tab, it is not a cookie, it is not sent to us and it identifies nobody. You can clear it at any time in your browser settings.

If any tool that sets a cookie or stores information on your device is added later, this section will be updated before it goes live and a consent control will be provided.

Our site links to third-party websites, such as LinkedIn. Those sites have their own privacy and cookie policies, and we are not responsible for them.

As the site is built today

The build loads one thing from another host: one client logo served from the practice's own media library, which means that logo is requested from that host when the home page loads. Nothing else on any page is fetched from a third party. If any tool is added before launch, this section changes with it.

7.0

Your rights

Under data protection law you have the right to:

  • ask for a copy of the personal data we hold about you;
  • ask us to correct personal data that is inaccurate or incomplete;
  • ask us to delete personal data in certain circumstances;
  • ask us to restrict how we use personal data in certain circumstances;
  • object to our use of personal data where we rely on legitimate interests, and object at any time to direct marketing;
  • ask for personal data you gave us to be transferred to you or another organisation, where we rely on consent or contract and process it by automated means;
  • withdraw consent at any time where we rely on it, without affecting what we did before you withdrew it.

Some rights are subject to exemptions. For example, we may need to keep project records to meet professional obligations or to defend a claim, and we may need to withhold information that would identify another person or that is legally privileged. If we cannot meet a request in full, we will explain why.

To make a request, contact us at admin@beersconsultancy.co.uk. We may need to confirm your identity. There is normally no charge, and we will respond within one month, which can be extended by up to two further months for complex requests, in which case we will tell you.

8.0

Complaints, and changes to this policy

If you are unhappy with how we have handled your personal data, please contact us first at admin@beersconsultancy.co.uk. We will acknowledge your complaint within 30 days, investigate it without undue delay, keep you informed of progress and tell you the outcome.

You also have the right to complain to the Information Commissioner's Office at any time: ico.org.uk/make-a-complaint, telephone 0303 123 1113.

We review this policy periodically and will post any changes on this page with a new date above. Where a change materially affects how we use personal data you have already given us, we will tell you directly where we can.

Need a clear position from complex building safety evidence?

Send us the reports, the issue and the decision you need to make. We will tell you whether the evidence supports the position, what remains uncertain and what a proportionate next step looks like.

Discuss an instruction