INDIGO – PRIVACY NOTICE
As part of the company secretarial and corporate governance services provided by Indigo (‘Indigo’, ‘we’, ‘us’ or ‘our’), we store and process personal data. We generally do this as a data processor for our clients rather than as a data controller. Generally our clients are the data controller of data collected and processed by us in providing our services.
What information do we collect?
We collect personal data of the directors, shareholders, employees, members and associates of our clients (including where we are acting on the instruction of a client in respect of another third party entity, the directors, shareholders, employees, members and associates of that third party). We:
- collect personal data from job applicants as part of our recruitment processes;
collect personal data when we are instructed or as part of an on-going contract to provide services, for example when a director is appointed or a company’s share ownership changes, - personal data collected may include name (including past names), home address, date of birth, nationality, identity number (e.g. passport number), contact details including email addresses, telephone numbers and service address, job title, statutory appointments, share ownership and entity membership information,
- we may collect personal data direct from the data subject but more generally collect personal data from the companies or their advisers on whose behalf we act. We do not generally collect sensitive personal data or financial information.
How do we use personal information?
We process personal data for the following purposes:
- providing company secretarial ad corporate governance services
- account set up and administration
- legal obligations (eg anti-money laundering)
- meeting internal audit requirements.
What legal basis do we have for processing your personal data?
When collecting and processing personal data we do so on the grounds of:
- contract – either individual contract with a client or providing services under our Standard Terms of Business,
- legitimate interests – we are unable to provide our services and to help our clients to meet their obligations under the Companies Act 2006 and other legislation and regulations without collecting and processing personal data on their behalf,
- legal obligation – we are required to collect certain personal data in order to satisfy our obligations under anti-money laundering regulations, for example.
When do we share personal data?
We share personal data from time to time with, for example, our clients’ other advisers:
- personal data may be shared electronically (e.g. via email) or in paper copy. Where personal data is shared electronically, we use password protection,
- before sharing personal data, we seek to ensure that the party (named individual) with whom we are sharing the data has a legitimate basis for collecting the relevant data. We may obtain that assurance via instruction from our clients.
Where do we store and process personal data?
All personal data is stored in the UK. Appropriate steps and notifications will be made in the event that any personal data is to be transferred outside of the EEA.
How do we secure personal data?
Paper documents which contain personal data are kept in locked cabinets within a locked office. Personal data which is stored electronically is protected by password and other security arrangements (e.g. secure server). Our staff only have access to the personal data they require in order to perform their role. Back up measures are in place to ensure business continuity and disaster recovery.
How long do we keep your personal data for?
We retain personal data as follows:
- personal data contained within board and general meeting minutes will be retained for a period of ten years from the date of the relevant meeting as required by the Companies Act 2006,
- other personal data will generally be retained for a period of six years.
Your rights in relation to personal data and how to contact us
Data subjects who wish to exercise their rights under the GDPR, for example to access personal information, request correction or deletion, restrict or object to data processing, should contact Bernadette Young, Director, Indigo, Vincent Court, Ground Floor, 853-855 London Road, Westcliff On Sea, Essex SS0 9SZ. Exemptions to these rights will apply where personal data has been collected and/or processed in order to meet legal obligations under the Companies Act 2006 or other regulatory requirements, including anti-money laundering regulations.
Data Protection Complaints Procedure
Data subjects have a right to raise a complaint directly with us if they are concerned about how their personal data has been collected, used, stored, shared or protected. Any data subject who is concerned about how we have collected, used, stored, shared or protected personal data, or about the way we have handled a data protection request, may make a data protection complaint.
Data subjects who wish to make a data protection complaint should contact Bernadette Young, Director, Indigo, Vincent Court, Ground Floor, 853-855 London Road, Westcliff On Sea, Essex SS0 9SZ.
We may need to ask a data subject for proof of ID before we acknowledge a complaint. If someone makes a complaint on a data subject’s behalf we will need to check they are authorised to act before acknowledging the complaint. If we do not receive sufficient evidence that a third party is authorised to act on a data subject’s behalf we will not investigate the complaint until we receive the appropriate authority.
We will acknowledge a complaint within 30 days of receipt. The 30 days start the day after we receive a complaint, including non-working days. If the last day to acknowledge a complaint falls on a weekend or public holiday, we will respond by the next working day.
We will make appropriate enquiries, investigate the complaint without undue delay and keep the data subject (or a person acting on their behalf) informed where necessary. This may include asking for further information to be provided and speaking with any witnesses in order for us to investigate a complaint fully.
Once a complaint has been fully investigated, we will inform the data subject (or person acting on their behalf) of the outcome of the complaint without undue delay, and in writing.
Making a complaint to us does not prevent a data subject (or a person acting on their behalf) from complaining to the Information Commissioner’s Office (ICO) at any time.
We will keep a secure record of data protection complaints, including the date received, the date acknowledged, relevant communications and documents, the outcome, any action taken and any ICO correspondence. Access to complaint records will be limited to those who need to know and records will be retained in accordance with our Data Retention Policy.
Last amended July 2026