Further Forward

Privacy Policy

Effective Date: 1stNovember 2024
Last Updated: 10th June 2025

Scope of this Notice. This Privacy Policy explains how we handle personal data collected via (a) our website and (b) our consultancy engagements. It does not apply to data processed within the individual software products or applications we create or maintain for clients or end users. Each product we own, operate or build for clients will display its own privacy notice.

Further Forward Innovation Ltd ("Further Forward", "we", "us", "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose and safeguard personal data when you visit our website (www.furtherforward.co.uk), engage with our marketing, or contract with us for consultancy or software‑development services. It also sets out your rights under the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations ("PECR").

1. Who We Are

  • Legal entity: Further Forward Innovation Ltd, a company registered in England and Wales (Company No. 14146615).
  • Registered office: 28 Maple Way, Dunmow, Essex, United Kingdom, CM6 1WZ.
  • Data Controller: For data collected via our website, sales enquiries and marketing lists, we act as Data Controller.
  • Data Processor: When our clients provide us with personal data (e.g. end‑user data) for project delivery, we act as Data Processor under their instructions, governed by a separate Data Processing Agreement ("DPA").

2. Personal Data We Collect

CategoryExamplesSource
Identity DataFirst name, last name, job titleProvided by you (forms, contracts)
Contact DataEmail address, telephone number, billing addressProvided by you
Technical DataIP address, browser type, operating system, device identifiersCollected automatically via cookies and similar technologies
Usage DataPage views, time spent, clicks, referring URLsAnalytics cookies, tracking pixels
Marketing DataMarketing preferences, newsletters openedProvided by you / collected via email pixels
Project DataRepositories, application logs, end‑user information supplied by clientsProvided by clients (processor role)

We do not intentionally collect special ‑ category data unless explicitly required for a project and agreed in writing.

PurposeData TypesLegal Basis
Responding to enquiries, preparing proposalsIdentity, ContactContractual necessity (Art. 6(1)(b))
Performing consultancy or development servicesIdentity, Contact, ProjectContractual necessity (Art. 6(1)(b))
Invoicing and accountingIdentity, ContactLegal obligation (Art. 6(1)(c))
Improving our website and servicesTechnical, UsageLegitimate interests (Art. 6(1)(f)) – to keep services functional and secure
Sending newsletters or event invitesIdentity, Contact, MarketingConsent (Art. 6(1)(a)) or soft opt‑in under PECR
Security monitoring and fraud preventionTechnicalLegitimate interests (Art. 6(1)(f))

Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms.

4. Cookies and Similar Technologies

We use first‑party and third‑party cookies, pixels and local storage to:

  1. Operate the site (essential cookies).
  2. Analyse traffic & performance (analytic cookies, e.g. Google Analytics set to IP‑anonymisation).
  3. Remember preferences (functional cookies).
  4. Deliver targeted marketing (only if you have consented).

When you first visit, you will see a cookie banner allowing you to accept or reject non‑essential cookies. You can update preferences at any time via the “Cookie Settings” link in the footer. Browser settings can also delete or block cookies.

Detailed information about each cookie category, name, provider, purpose and retention period is contained in our separate Cookie Notice, accessible at /cookies.

5. Data Retention

Data CategoryTypical Retention
Enquiry emails24 months after last contact
Client project dataDuration of the contract + 12 months (unless otherwise agreed)
Invoices & tax records7 years (legal obligation)
Marketing listsUntil you unsubscribe or 24 months after inactivity
Analytics logs26 months (Google default)

We securely erase or anonymise data once retention periods lapse, unless legal obligations require longer storage.

6. Sharing and International Transfers

We disclose personal data only when necessary:

  • Service Providers/Sub‑Processors (e.g. cloud hosting, CRM, email delivery, analytics). These providers are bound by confidentiality and data‑processing terms equivalent to ours.
  • Professional Advisers (lawyers, accountants) under confidential duties.
  • Authorities if required to comply with law or protect rights, property or safety.

Some providers operate outside the UK or European Economic Area. Where transfers occur, we rely on:

  1. UK Adequacy Regulations (if the destination country is deemed adequate), or
  2. UK International Data Transfer Agreement (IDTA) or UK‑approved Standard Contractual Clauses (SCCs), plus supplementary measures where necessary.

A list of current sub‑processors and transfer safeguards is available on request.

7. Security Measures

We follow industry best practice, including but not limited to:

  • Encryption in transit (TLS 1.2+) and at rest for cloud storage.
  • Principle of least privilege and role‑based access controls.
  • Multi‑factor authentication for privileged accounts.

In the unlikely event of a personal‑data breach, we will notify the Information Commissioner’s Office ("ICO") and affected individuals where required, within 72 hours of becoming aware.

8. Your Data‑Subject Rights

You have rights under UK GDPR to:

  1. Access – request a copy of data we hold about you.
  2. Rectification – correct inaccurate or incomplete data.
  3. Erasure – request deletion where data is no longer needed ("right to be forgotten").
  4. Restriction – pause processing in certain circumstances.
  5. Portability – obtain data in a structured, machine‑readable format.
  6. Objection – object to processing based on legitimate interests or direct marketing.
  7. Withdraw consent at any time (without affecting prior processing).
  8. Not be subject to automated decision‑making producing legal effects (we do not conduct such profiling).

Requests are free of charge (unless manifestly unfounded or excessive). We respond within one month. To exercise your rights, see Section 9.

9. Contact Details

  • Data Protection Contact: info@furtherforward.co.uk
  • Postal Address: Further Forward Innovation Ltd, Office One, 1 Coldbath Square, London, EC1R 5HL.
    We do not currently fall within the mandatory criteria to appoint a DPO, but privacy queries are handled by our senior leadership.

10. Complaints

If you are unhappy with how we have handled your data, please contact us first so we can resolve your concerns. You also have the right to lodge a complaint with the Information Commissioner’s Office:

  • Website: https://ico.org.uk
  • Helpline: +44 (0)303 123 1113
  • Address: ICO, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom.

11. Changes to This Policy

We review this Privacy Policy periodically and will post any updates on this page. Significant changes will be signposted via the website or email. Please review this page regularly. Continued use of our services after changes are posted constitutes your acceptance.

Version History

VersionDateNotes
1.010/06/2025Initial issue

Email info@furtherforward.co.uk or use the contact form on our website. We are happy to clarify any part of this notice.