How Hills & Associates collects, uses, shares and protects your personal information.
Hills & Associates UK ("we", "us", "our") respects your privacy and is committed to protecting your personal information. This policy explains what we collect, why we collect it, how we use and share it, and the rights you have under the UK GDPR and the Data Protection Act 2018.
Hills & Associates UK is the data controller for the personal information described in this policy. You can contact us at:
We only collect the information we need to respond to you and to operate our website securely.
When you submit our contact form, or contact us by email or telephone, we may collect:
When you visit our website, our web server and our content delivery and security provider record standard technical information. This may include your IP address, the date and time of your visit, the pages you request, your browser and operating system type, and a referring address. This information is used for security, to diagnose faults, and to understand aggregate, anonymised usage of the site.
We use your personal information to:
We do not sell your personal information, and we do not use it for automated decision-making or profiling.
Under the UK GDPR we must have a lawful basis for using your personal information. We rely on:
Our website does not use advertising, analytics or other non-essential cookies, and we do not require a cookie consent banner. We do set, and our security provider may set, a small number of strictly necessary cookies that are essential to keep the site and its forms working and secure. Full details are set out in our Cookie Policy.
We share personal information only where necessary, and only with organisations that help us run our website and business. These include:
We may also disclose information where we are required to do so by law, or to establish, exercise or defend legal claims. We never sell your personal information.
Some of our service providers, including Cloudflare, are based outside the United Kingdom and may process your information in other countries, including the United States. Where we transfer personal information outside the UK, we rely on appropriate safeguards recognised by UK law, such as the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses.
We keep personal information only for as long as we need it for the purposes described above. As a guide:
When information is no longer needed, we securely delete or anonymise it.
Under the UK GDPR you have the right to:
To exercise any of these rights, please contact us at [email protected]. We will respond within one month. You will not normally be charged a fee.
If you are unhappy with how we have handled your information, you have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection. You can contact the ICO at ico.org.uk or on 0303 123 1113. We would appreciate the opportunity to address your concerns first.
We take appropriate technical and organisational measures to protect your personal information against unauthorised access, loss or misuse. These include encrypted connections (HTTPS/TLS) across the site, security filtering and protection provided by Cloudflare, and restricted access to systems that hold personal data.
We may update this policy from time to time to reflect changes in our practices or the law. The date at the top of this page shows when it was last revised. Any significant changes will be made clear on this page.
If you have any questions about this policy or about how we handle your personal information, please contact us at [email protected] or +44 20 3807 8443.