Sourcechange Limited · Website Privacy Policy · Last updated: June 2026
Welcome to Sourcechange Limited’s Privacy and Data Protection Policy (“Privacy Policy”). At Sourcechange Limited (“we”, “us”, or “our”) we are committed to protecting and respecting your privacy and Personal Data in compliance with the United Kingdom General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018, each as amended by the Data (Use and Access) Act 2025, and all other mandatory data protection laws and regulations of the United Kingdom. This Privacy Policy explains how we collect, process, and keep your data safe. It also outlines your privacy rights, how the law protects you, and informs our employees and staff members of their obligations when processing data.
This Privacy Policy applies to all our employees, staff members, and all Personal Data processed at any time by us.
Sourcechange Limited is your Data Controller and responsible for your Personal Data. For any GDPR-related queries and requests please email our GDPR Lead at ops@sourcechange.com.
You have the right to complain to us directly about how we handle your Personal Data. Complaints can be sent to ops@sourcechange.com and are handled in line with our Complaints Policy. We will acknowledge your complaint within 30 days and respond without undue delay.
You also have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO, so please contact us in the first instance.
In discharging our responsibilities as a Data Controller we may use employees or third parties to process your data on our behalf (“Processors”).
The Data Controller and our Processors have the following responsibilities:
“Personal Data” means any information about an individual from which that person can be identified. It does not include anonymous data.
We do not collect any Special Categories of Personal Data (such as ethnicity, religion, health, biometric, or criminal data).
We rely on the following justifications under the GDPR:
We apply the GDPR principles of data minimisation and storage limitation, ensuring data is adequate, relevant, and not kept longer than necessary.
We will only use your Personal Data when the law allows us to. If we need to use it for another reason compatible with the original purpose, we will notify you. We may process your data without your knowledge or consent where required by law.
Under data protection laws you have the following rights: right to be informed, right of access, right to rectification, right to erasure, right to object, right to restrict processing, and right to data portability.
If you exercise your right to erasure, we will delete your Personal Data unless we are required by law or have overriding legitimate grounds to continue holding it (such as compliance or legal defence).
Your data is accessible only by authorised staff and subcontractors under strict confidentiality. We apply technical and organisational measures to protect against loss or unauthorised access. While we strive to protect your data, internet transmission cannot be guaranteed fully secure.
You may submit a data subject access request. We will respond within one month of receiving your request, although this period may be extended for complex requests or paused where we need additional information from you to progress it. When responding, we are required to carry out searches that are reasonable and proportionate. We may request additional information to verify your identity. Requests that are manifestly unfounded may be refused.
We may share your Personal Data:
We will only retain your Personal Data for as long as necessary to fulfil the purposes for which it was collected. By default, we retain most Personal Data for no longer than 2 years from the date of your last interaction with us. After this period, your data will be securely deleted or anonymised.
Some categories of data must be kept longer to comply with legal requirements:
We review retention practices annually to ensure compliance.
Your information may be stored and processed in the US or other countries where Sourcechange Limited has facilities. Where we transfer your Personal Data outside the United Kingdom, we do so only where the destination ensures an appropriate standard of protection for your data. This means the transfer is covered by UK adequacy regulations or by appropriate safeguards, such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
We keep this Privacy Policy under review and will post any updates on our website. Continued use of our services after changes means you accept the updated Privacy Policy.