top of page

Privacy Policy

Data Protection & Privacy Policy

Poppy and Thistle Group Ltd, Poppy & Thistle Property Ltd

Effective Date: 21/06/2026

Review Date: 19th December 2026

1. Policy Overview

This policy outlines how Poppy and Thistle Group Ltd ("the Company") collects, uses, and protects personal data. As a small family-run business, we take a "privacy by design" approach to ensure that data protection is integrated into our daily operations using password protected personal devices and Google Drive.

Poppy and Thistle Group Ltd shares these services with our sister company Poppy and Thistle Property Ltd.

2. Lawful Basis for Processing

We identify the following legal bases for processing data:

  • Legitimate Interests: For B2B marketing (contacting employees at their business addresses), general operations, AML

  • Consent: For B2C marketing (contacting individuals or sole traders) where we rely on "opt-in" permissions provided via purchased lists or direct sign-ups.

  • Legal Obligation: For maintaining financial records and tax compliance, satisfying the AML requirements of own solicitors and commercial lenders

  • Performance of a Contract: JV agreement or loan agreement

 

3. Data Collection and Sources

We process names, company addresses, and email addresses. This data is sourced via:

  • Purchased Lists: We only use lists from reputable providers who guarantee GDPR-compliant "opt-in" consent for marketing.

  • Public Records: Information sourced from Companies House and official business websites.

  • Direct Contact: Information provided to us via email or our website, Names, IDs, proof of address, bank statements (for Source of Funds), and corporate entity details for JV partners or private lenders.

  • Social Media: Information publicly available on social medial (LinkedIn, Facebook).

 

4. Storage and Security (BYOD Policy)

As we operate using personal laptops and Google Drive, the following security protocols are mandatory:

4.1 Digital Security

  • Google Workspace: All data is stored in Google Drive. Two-Factor Authentication (2FA) is enabled for both directors.

  • Encryption: Personal laptops must use full-disk encryption (FileVault for Mac / BitLocker for Windows).

  • No Local Storage: Sensitive files must not be saved to the laptop’s local "Downloads" or "Desktop" folders permanently; they must be uploaded to the secure Drive and deleted locally.

4.2 Physical Security

  • Laptops must be password-protected with complex passwords.

  • Devices must never be left unattended in public spaces.

  • Operating systems must be set to "Auto-Update" to ensure security patches are applied.

 

5. Marketing Procedures

To remain compliant with PECR (Privacy and Electronic Communications Regulations) alongside GDPR:

  • Transparency: Every marketing email will identify "Poppy and Thistle Group Ltd" as the sender.

  • The Right to Object: Every email will contain a clear "Unsubscribe" link or instructions to opt-out.

  • Suppression List: We maintain a "Do Not Contact" list. If a person opts out, their data is moved to this list to ensure they are never contacted again (rather than simply deleting them, which might lead to re-importing them later).

 

6. Retention and Disposal

  • Marketing Data: Reviewed every 12 months. Any lead that has not engaged with us in 24 months will be deleted.

  • Purchased Data: We adhere to the specific "usage life" defined by the list provider (e.g., if a list is licensed for 12 months, it is deleted after that period).

  • JV Partners, Lenders, and Investors: 6 years after the JV agreement or loan is fully paid off and concluded (this aligns with standard UK limitation periods for breach of contract claims and HMRC corporate tax record-keeping).

 

7. Data Breach Procedure

In the event of a lost laptop or a compromised Google account:

  1. Assessment: We will immediately assess if the breach poses a risk to individuals (e.g., if the laptop was encrypted, the risk is "Low").

  2. Reporting: If there is a high risk to individuals' rights (e.g., a large unencrypted list is stolen), we will notify the affected individuals without undue delay.

  3. Action: Passwords will be changed immediately, and "Remote Wipe" will be triggered via Google Workspace if possible.

 

8. Your Rights

Individuals may contact us to exercise their rights of access, rectification, or erasure at:

Email: hello@poppyandthistlegroup.co.uk

bottom of page