Legal

Privacy Policy

Last updated: June 2026

1. Introduction and Data Controller

Renmaker is a trading name of 650B Ltd ("we", "our", "us"). We are committed to protecting your privacy and handling your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

This Privacy Policy explains how we collect, use, store, and protect your personal information when you visit our website at renmaker.co.uk, make enquiries, or engage our consultancy services.

1.1 Data Controller Details

650B Ltd (trading as Renmaker) is the data controller responsible for your personal data.

650B Ltd (trading as Renmaker)

Registered in England and Wales

Company number: 09743643

VAT number: GB446756753

Registered office: 73 Mackie Avenue, Brighton, East Sussex, BN1 8RD

1.2 Contact for Data Protection Enquiries

If you have any questions about this Privacy Policy or our data protection practices, please contact us:

Email: enquiries@renmaker.co.uk

Post: 650B Ltd (trading as Renmaker), 73 Mackie Avenue, Brighton, East Sussex, BN1 8RD


2. Information We Collect

We collect and process personal data through various means depending on how you interact with us.

2.1 Information You Provide Directly

2.2 Information Collected Automatically

For detailed information about cookies and tracking technologies, please see our Cookie Policy.

2.3 Information from Third Parties

We may receive personal data about you from third parties, including:


3. How We Use Your Information and Lawful Basis

UK GDPR requires us to have a lawful basis for processing your personal data. The table below sets out the purposes for which we use your data and the legal basis we rely on in each case.

PurposeData UsedLawful Basis
Responding to enquiries and providing proposalsContact details, business informationLegitimate interests (responding to business enquiries)
Delivering consultancy services under contractContact details, business information, project data, communicationsPerformance of contract
Delivering access to and support for Ecosystem platformContact details, business information, project and asset dataPerformance of contract
Invoicing and payment processingContact details, financial informationPerformance of contract
Sending service updates and project communicationsContact detailsPerformance of contract / Legitimate interests
Sending marketing communications about our servicesContact details, business informationConsent (where required) / Legitimate interests (B2B soft opt-in)
Improving our website and servicesUsage data, technical dataLegitimate interests
Website analytics and performance monitoringTechnical data, usage dataLegitimate interests / Consent (for non-essential cookies)
Maintaining business records and accountsContact details, financial information, communicationsLegal obligation
Complying with legal and regulatory requirementsAs required by the specific obligationLegal obligation
Establishing, exercising, or defending legal claimsAll relevant personal dataLegitimate interests

3.1 Legitimate Interests

Where we rely on legitimate interests as the lawful basis for processing, we have assessed that the processing is necessary for our legitimate business interests and that these interests are not overridden by your rights and freedoms. Our legitimate interests include: operating and growing our business, understanding how clients and prospective clients use our website, improving our services, and maintaining relationships with clients and contacts.

You have the right to object to processing based on legitimate interests. See Section 9 for details on how to exercise this right.


4. Marketing Communications

We may send you marketing communications about our consultancy services, Ecosystem platform, insights articles, industry updates, and events that we believe may be of interest to you.

4.1 When We Send Marketing

For business contacts, we rely on the "soft opt-in" under the Privacy and Electronic Communications Regulations (PECR). This means we may send you marketing if you have previously enquired about or used our services, and we gave you the opportunity to opt out at that time and in every subsequent communication.

Where we do not have an existing business relationship, we will only send marketing communications with your express consent.

4.2 Opting Out

You can opt out of marketing communications at any time by:

Opting out of marketing will not affect service-related communications necessary for the performance of any contract with you.


5. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to distinguish you from other users, improve your browsing experience, and analyse website usage. For detailed information about the cookies we use, the purposes for which we use them, and how to manage your cookie preferences, please see our Cookie Policy.


6. Who We Share Your Data With

We do not sell your personal data to third parties. We may share your personal data with the following categories of recipients where necessary for the purposes described in this Privacy Policy.

6.1 Service Providers

We use third-party service providers to support our business operations, including:

These service providers are contractually bound to use your data only for the purposes of providing services to us and to implement appropriate security measures.

6.2 Professional Advisers

We may share data with our professional advisers, including lawyers, accountants, and insurers, where necessary for the provision of professional services.

6.3 Legal and Regulatory Disclosures

We may disclose your personal data where required by law, regulation, or court order, or to protect our legal rights or the rights, property, or safety of others.

6.4 Business Transfers

In the event of a merger, acquisition, or sale of all or part of our business, your personal data may be transferred to the acquiring entity as part of the transaction. We will notify you of any such transfer and any choices you may have regarding your data.


7. International Data Transfers

Some of the third-party service providers we use are based outside the United Kingdom, including in the United States. This means that your personal data may be transferred to, stored in, and processed in countries outside the UK. The services we use that may involve international transfers include Google (Google Analytics, Google Workspace) and Microsoft (Azure, Microsoft 365).

7.1 Safeguards for International Transfers

Where we transfer personal data outside the UK, we ensure appropriate safeguards are in place, including transfers to countries with UK adequacy decisions, use of the UK International Data Transfer Agreement (UK IDTA), or EU Standard Contractual Clauses with the UK Addendum. You may request further information about the safeguards in place by contacting us using the details in Section 1.


8. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements.

Data CategoryRetention PeriodReason
Enquiries that do not proceed to engagement2 yearsBusiness development and follow-up
Client project files and deliverables7 years from project completionContractual reference, professional indemnity, limitation periods
Contracts and engagement letters7 years from contract endLegal and contractual requirements, limitation periods
Financial and accounting records7 yearsHMRC requirements, Companies Act
Invoices and payment records7 yearsTax and VAT compliance
Marketing consent recordsDuration of consent plus 2 yearsEvidence of consent for regulatory compliance
Website analytics data26 months (aggregated)Website performance analysis
Correspondence and communications7 years from last contactBusiness records, dispute resolution
Ecosystem platform project and asset dataDuration of subscription plus 2 yearsContractual obligations and dispute resolution

9. Your Rights Under UK GDPR

Under UK data protection law, you have the following rights regarding your personal data:

To exercise any of your rights, please contact us using the details in Section 1. We will respond within one month of receipt. We will not charge a fee for most requests.


10. Right to Complain to the ICO

If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection. We would appreciate the opportunity to address your concerns before you approach the ICO, so please contact us in the first instance.

Information Commissioner's Office

Website: ico.org.uk

Telephone: 0303 123 1113

Address: Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF


11. Automated Decision-Making and Profiling

We do not use automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you. Where we use AI-assisted tools to support document drafting, analysis, and research, all significant decisions regarding our services and client relationships are made by our team with human oversight.


12. Children's Data

Our website and services are intended for businesses and business professionals. We do not knowingly collect personal data from individuals under 18 years of age. If you believe we have inadvertently collected data from a child, please contact us immediately and we will take steps to delete such data.


13. Third-Party Links

Our website may contain links to third-party websites, including industry resources, government information, and service providers. These websites have their own privacy policies, and we do not accept any responsibility or liability for their policies or practices. We encourage you to read the privacy policy of every website you visit.


14. Data Security

We have implemented appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Our security measures include encryption of data in transit and at rest, access controls limiting data access to authorised personnel, secure password policies and multi-factor authentication, and regular review of security practices and service provider security.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO and, where required, notify you without undue delay.


15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. The date at the top of this page indicates when this Privacy Policy was last updated. We encourage you to review this Privacy Policy periodically.


16. Contact Us

650B Ltd (trading as Renmaker)

Email: enquiries@renmaker.co.uk

Post: 73 Mackie Avenue, Brighton, East Sussex, BN1 8RD