Legal
Privacy Notice
Effective date: 11 October 2026
Version: 1.5
© What If HR Ltd 2026. All rights reserved.
1. Who we are and how this notice works
What If HR Ltd ("we", "us", "our") respects your privacy and is committed to protecting personal data. This Privacy Notice explains what personal data we collect, how and why we use it, our lawful bases for doing so, who we share it with, how long we keep it and the rights you have.
This Privacy Notice applies to:
- visitors to www.whatifhr.co.uk and people who contact us about our services (we act as Data Controller); and
- personal data we handle on behalf of our clients while delivering HR consultancy services (we act as Data Processor, and the client's privacy notice governs that processing, although for some work, such as an independent investigation, we may act as a separate Data Controller, and the client's Specification says so); and
- the record of advice we keep after our work for a client ends, which can include information about the client's staff (we act as Data Controller for that record only).
This Notice sits alongside:
- our Website Terms of Use;
- our Cookies and Tracking Policy (covering cookies, pixels and similar tech under PECR); and
- our Master Terms of Business, which contain our data processing agreement with clients.
We update this Notice when the law or the way we work changes. We follow UK data protection law, including the UK GDPR, the Data Protection Act 2018, the Data (Use and Access) Act 2025 and the Privacy and Electronic Communications Regulations (PECR).
2. Our roles and contact details
Controller (for website, enquiries, marketing, supplier/contact records and our record of advice):
What If HR Ltd, 21 Dunedin Drive, Caterham, CR3 6BA.
Registered with the Information Commissioner's Office, registration number ZB980360.
Data Protection Lead: Elena Suhova, Director
Contact: hello@whatifhr.co.uk | +44 7557 982 407
Processor (for client HR files):
When providing HR consultancy to a client, we process personal data under the client's written instructions as their Processor. In that case, the client's privacy notice applies to their staff data. For some work, such as an independent investigation, we may act as a separate Data Controller because we decide how the information is used. If so, the client's Specification says so. Our data processing terms are in our Master Terms of Business.
You can contact us using the details above about any privacy questions. You also have the right to complain to the Information Commissioner's Office (ICO) (www.ico.org.uk) if you're unhappy with how we handle personal data.
3. Children
Our website and services are aimed at businesses. We do not knowingly collect data about children through our website, and we ask that children do not submit personal data via our website or contact channels.
Some of our clients work with children, for example children's homes, nurseries and schools. Their staff records, such as conduct or safeguarding cases, can include information about the children in their care. We handle that information only as the client's Processor, on the client's instructions, keep it to what the work needs and do not put it into AI tools.
4. What data we collect and how we obtain it
We collect, use and store personal data in a number of ways depending on how you interact with us.
4.1 Data you provide directly
You may give us personal data when you:
- complete forms or contact us via our website or email;
- subscribe to updates, book consultations, purchase a service or package or download materials;
- correspond with us about services, invoices or HR matters; or
- participate in surveys, webinars or feedback requests.
This may include:
- name, job title and business contact details;
- company name and registration information;
- correspondence and enquiry details;
- billing, transaction and payment details (processed securely via third-party providers; What If HR does not store card information);
- marketing and communication preferences.
4.2 Data we receive from clients
When acting as a Data Processor for a client, we may receive employee or applicant information (such as names, job titles, contact details, employment records, absence and health information, conduct and grievance records, performance data or, where the work needs it, criminal record (DBS) check results) to deliver HR consultancy services. Where a client works with children, those records can also include information about the children in their care.
We handle this information only under the client's written instructions and in accordance with our Master Terms of Business and data-processing obligations. Where a client gives us access to its own systems, we work in them and do not keep copies, apart from a working copy a task needs.
4.3 Data we collect automatically
When you visit our website, our hosting provider, Netlify, automatically processes limited technical data needed to deliver the site and keep it secure, such as:
- IP address, browser type, device type and operating system;
- the pages requested and the referring website;
- the date and time of the request.
We also use Plausible Analytics to count visits. Plausible does not use cookies, does not store anything on your device and does not collect personal data. It counts visits using a code that changes every day and cannot be used to identify you or to follow you across other websites.
If you send us a message or sign up to our emails through a form on our website, the details you enter are processed by Netlify and sent to us by email.
This helps us keep the site secure, understand which pages are useful and reply to you. For details, see our separate Cookies and Tracking Policy.
4.4 Data from other sources
We may receive information from:
- business partners or suppliers assisting in service delivery (for example, IT support, accountants or marketing platforms);
- publicly available sources such as Companies House or LinkedIn, to verify business identity or contact details.
We take reasonable steps to ensure that any third party providing data to us has obtained it lawfully and provided the necessary privacy information to affected individuals.
4.5 Our record of advice
When our work for a client ends, we keep a record of the advice, reports, letters and other documents we gave that client. This record can include information about the client's staff, job applicants or contractors, such as names, job details and information about absence, health, conduct or grievances. It comes from our client.
We keep it so we can answer questions about our advice and deal with any legal claim. We keep only what is needed, keep it securely, use it for nothing else and delete it no later than seven years after the work ends.
4.6 Meeting recordings
With the client's agreement, and only after everyone in the meeting has been told, we may record and transcribe a meeting or interview using Plaud. We use the recording only to produce accurate notes. We delete the recording once the notes have been checked, and the notes become part of the client's work file.
4.7 If you do not give us information
You do not have to give us personal data. If you do not give us the information we need to reply to you, agree a contract or invoice you, we may not be able to provide our services. We need some information to meet legal duties, such as keeping tax and accounting records.
5. How we use personal data and our lawful bases
We use personal data only where we have a clear and lawful basis for doing so.
Depending on the context, that basis may be contract, legitimate interests, consent or legal obligation.
5.1 When acting as Data Controller (website, marketing and business contacts)
We may use your personal data to:
- respond to enquiries, schedule consultations and deliver requested information;
- provide, manage and improve our services, website and user experience;
- maintain our client records, invoicing and accounting systems;
- send you service updates, policy changes or legal notices;
- send optional marketing communications (see "Marketing" below);
- protect the security of our website, IT systems and business operations;
- comply with our legal and regulatory obligations (for example, tax or record-keeping duties); and
- prevent or detect fraud, misuse or other unlawful activity.
Our lawful bases for this processing are:
Contract: to perform or take steps at your request before entering a contract with you, for example replying to enquiries, booking calls, delivering our services and invoicing;
Legitimate interests: for efficient business administration, network security and service development, keeping client records, sending relevant updates to business contacts, and keeping our record of advice to answer questions and deal with legal claims, provided your rights do not override those interests;
Consent: where you opt-in to receive marketing (such as our newsletter) or where the law requires consent (for example, non-essential cookies); and
Legal obligation: where we must retain or disclose data under UK law, for example tax and accounting records.
Marketing. We send our newsletter only to people who have signed up. We may also send occasional updates about our services to business contacts at the companies we work with or talk to. Every email has an unsubscribe link, and you can opt out at any time by emailing hello@whatifhr.co.uk.
5.2 When acting as Data Processor (client HR data)
When delivering HR consultancy services to a client, we process staff and related personal data solely:
- on the client's written instructions,
- for the purposes set out in the Specification or contract, and
- in accordance with our Data Processing obligations in the Master Terms of Business.
We do not use client HR data for our own purposes, apart from keeping our record of advice.
5.3 Special-category data
HR records can include special-category (sensitive) data, such as health information, and information about criminal offences, such as the results of criminal record checks.
- When we act as a Processor, our client decides the lawful basis and the condition for using this information.
- For our record of advice, we rely on the condition for establishing, exercising or defending legal claims (UK GDPR Article 9(2)(f)) and, for any information about criminal offences, the matching condition in Schedule 1 of the Data Protection Act 2018 (paragraph 33).
5.4 Automated decision-making and AI tools
We do not make decisions that produce legal or similarly significant effects using solely automated means.
We use AI-assisted tools, including Claude from Anthropic on a business account, for drafting, research and analysis. They are used only to support human judgement and never make decisions about anyone.
No personal or confidential data is input into such systems without appropriate safeguards, and we only use tools that do not use your information to train their models (see Section 7, How we protect personal data).
6. Who we share personal data with and international transfers
We treat all personal data as confidential. We share it only where necessary and lawful.
6.1 Service providers and professional advisers
We may share limited personal data with trusted third parties who help us operate our business, including:
- the tools we use to run the business: Google Workspace (email and documents), Netlify (this website and its forms), Stripe (card payments), Xero (invoices and accounts), Calendly or Google Calendar (booking calls), Claude from Anthropic (drafting, research and analysis, on a business account), Toggl Track (recording the time we spend for each client, under the client's business name and without the names of the client's staff) and Plaud (recording and transcribing meetings, only with agreement);
- professional advisers (such as accountants, insurers or solicitors);
- payment processors and banking providers;
- marketing, website-analytics and communications platforms (where consent or another lawful basis exists); and
- consultants or associates engaged to deliver parts of our services, under written confidentiality and data-processing terms.
All suppliers who process personal data for us act under written contracts that require them to keep data secure, act only on our instructions and comply with the UK GDPR and Data Protection Act 2018.
6.2 Business transfers or restructuring
If we reorganise or transfer our business, merge, sell or otherwise restructure, personal data may be transferred to a successor entity that agrees in writing to maintain equivalent privacy protections.
6.3 Legal and regulatory disclosures
We may disclose personal data where required to do so by law, regulation, court order or competent authority, or to enforce our contractual rights, protect our property or defend legal claims.
6.4 Within client projects
When we act as a Data Processor for client HR data, we share data only with the client's authorised representatives and the providers and associates named in our Master Terms or the client's Specification (for example, HR or payroll platforms). We do not share client staff data for our own purposes.
6.5 International transfers (including Google Workspace services)
Most of the information we hold stays in the UK. Some of our providers, such as Google, Anthropic, Toggl and Plaud, may store it in other countries, including the European Union and the United States. Where that happens, it is protected by UK adequacy regulations or by agreements or safeguards approved under UK law, such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. Ask us at hello@whatifhr.co.uk if you would like the details.
7. How we protect personal data
We take the security of all personal data seriously. We apply appropriate technical and organisational measures to protect it against unauthorised or unlawful processing, accidental loss, destruction or damage.
7.1 Our security measures
Our measures include:
- encryption of data in transit and at rest, where practicable;
- secure cloud storage and password-protected systems;
- multi-factor authentication for administrator accounts;
- role-based access control so data is visible only to those who need it;
- confidentiality undertakings for employees, associates and contractors;
- regular staff training on data protection and information security;
- up-to-date antivirus, malware protection and system patching; and
- routine back-ups and business-continuity planning.
We expect the same standards from all service providers who handle personal data for us.
7.2 Data-breach response
If we become aware of a personal-data breach, we will:
- investigate promptly and assess the risk to individuals;
- contain and mitigate the incident;
- where acting as a Processor, notify the affected client without undue delay and, in any event, within 48 hours of becoming aware; and
- where acting as a Controller, notify the Information Commissioner's Office (ICO) within 72 hours and affected individuals where legally required.
We record all security incidents and review lessons learned to prevent recurrence.
7.3 Use of technology and AI tools
Where we use digital or artificial-intelligence tools to assist with drafting, data analysis or administration, we do so only to support human judgement.
Today, our main AI tool for drafting, research and analysis is Claude, from Anthropic, on a business account. We may enter a client's business name, information about the client's business and details of the matter we are working on. We keep information about a client's staff to what the task needs, and leave out names and other identifying details where we can. We do not put information about the children in a client's care into AI tools.
No confidential or personal data is entered into any system unless:
- the provider offers contractual data-protection assurances;
- the data is encrypted or pseudonymised where appropriate;
- the provider does not use the data to train its AI models, and we do not use features, such as feedback ratings, that would let it do so; and
- human review is carried out before any advice or output is relied upon.
7.4 Transmission of information
While we use appropriate safeguards once information reaches our systems, transmission of data over the internet (including by email) can never be guaranteed as completely secure. For sensitive information, please use the secure sharing method we agree with you, such as a shared folder with restricted access, rather than ordinary email attachments. We do not use WhatsApp or other personal messaging apps for client work.
8. Data retention
We keep personal data only for as long as it is needed for the purpose for which it was collected, or to meet legal, regulatory, accounting or reporting requirements.
8.1 General retention principles
We apply the following principles to determine how long we retain personal data:
- we retain it only for as long as necessary to fulfil the purpose for which it was collected;
- where processing is based on consent, we delete the data promptly after consent is withdrawn;
- where processing is required for a contract, we keep relevant data for the duration of the contract and a reasonable period afterwards (normally up to seven years) to handle potential queries or legal claims;
- where required by law (for example, HMRC records), we retain data for the statutory minimum period; and
- we securely delete or anonymise data when it is no longer required.
8.2 Typical retention periods
As a guide:
- Client staff data we handle as Processor: returned to the client or securely deleted within 30 days of our work ending (for an ongoing plan, within 30 days of the plan ending, or sooner for a closed matter if the client asks).
- Our record of advice: kept for up to seven years after the work ends, to answer questions and deal with legal claims.
- Meeting recordings: deleted once the notes from them have been checked.
- Business contact data (suppliers, prospects, newsletter subscribers): kept until consent is withdrawn or the relationship ends, and reviewed annually.
- Financial and accounting records: kept for seven years from the transaction date to meet HMRC and Companies Act obligations.
- Time records (Toggl): the client's business name and the time we spent, without the names of the client's staff, kept for seven years with our financial records.
- Website enquiry forms and support emails: kept for up to twenty-four months from the last contact to maintain an audit trail and customer-service record.
- Recruitment data (people who apply to work with What If HR, job applicants): kept for up to twelve months after the recruitment process ends for legitimate-interest and equality-monitoring purposes.
- Security logs and system backups: normally retained for up to ninety days (logs) or on a rolling twelve-month basis (backups) for system integrity and incident response.
These periods may be adjusted if law requires a longer period or if necessary to defend legal claims.
8.3 Secure deletion and archiving
When retention periods expire, we either:
- securely delete the data from active systems and backups; or
- archive it in a restricted area if a continuing legal or regulatory need exists.
8.4 Review and updates
We review our retention schedule annually and update it when business or legal requirements change. A summary of our current retention policy is available on request at hello@whatifhr.co.uk.
9. Your rights and how to exercise them
You have a number of rights under the UK GDPR and Data Protection Act 2018 in relation to your personal data. These rights are not absolute and may depend on the purpose or legal basis for processing, but we will always respond openly and fairly to any request.
9.1 Your data-protection rights
You have the right to:
- Access your data: request a copy of the personal data we hold about you.
- Correct your data: ask us to update or correct any inaccurate or incomplete information.
- Delete your data: request that we delete your personal data where there is no legal reason for us to keep it.
- Restrict processing: ask us to suspend or limit the way we use your data in certain circumstances.
- Object to processing: object to our processing of your personal data when we rely on legitimate interests or use it for direct marketing.
- Data portability: request that we provide your data in a structured, commonly used and machine-readable format, and that we transfer it to another controller where technically possible.
- Withdraw consent: where we rely on your consent (for example, for marketing), you may withdraw it at any time by using the unsubscribe link in our emails or by contacting us.
We do not carry out automated decision-making that produces legal or similarly significant effects on individuals.
If your request is about information we hold for one of our clients, for example as your employer's HR adviser, we will pass it to that client, who decides how to respond, and help them do so. Requests about our record of advice are dealt with by us.
9.2 Making a request
To exercise any of your rights, please email hello@whatifhr.co.uk with your name, contact details and a clear description of your request.
We will respond within one month of receiving your request and may ask for proof of identity before releasing any personal information. If a request is complex, or you make several, we may extend this by up to two further months and will tell you why. When we ask for proof of identity or for clarification, the time limit starts once we receive it. We make reasonable and proportionate searches for the information you ask for.
There is no fee for most requests, although we may charge a reasonable administrative fee if a request is manifestly unfounded or excessive.
9.3 Right to complain
If you are unhappy with how we have handled your personal data, please contact us first so we can try to resolve your concern. We will reply within 30 days to confirm we have your complaint, look into it, and tell you what we have done about it as soon as we can.
You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection.
Further information is available at www.ico.org.uk, or you can write to:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
10. Cookies and tracking technologies
Our website does not use cookies for analytics, advertising or tracking, which is why there is no cookie banner. We count visits with Plausible Analytics, which does not use cookies or collect personal data. The only thing the website keeps on your device is your answers to our HR compliance self-check, in your own browser, until you clear them.
When you follow a link to another service, such as our booking calendars, social media or our payment pages, that service's own cookie and privacy policies apply. Our Cookies and Tracking Policy has the details.
11. Changes to this notice and contact information
We may update this Privacy Notice from time to time to reflect changes in the law, regulatory guidance or our business practices. When we do, we will update the effective date at the top of this page and publish the revised version on our website. We encourage you to review this page periodically to stay informed about how we protect your information.
If there are any significant changes to how we collect or use personal data, we will take reasonable steps to notify you in advance, for example by email (where appropriate) or by a prominent notice on our website.
If you have any questions, comments or requests about this Privacy Notice or how we handle your personal data, please contact us:
What If HR Ltd
Registered in England and Wales
Email: hello@whatifhr.co.uk
Website: www.whatifhr.co.uk
End of Privacy Notice.