Version 1.2
Last Updated: 11/09/2026
Who is responsible for your personal information?
Talia Decent, a sole trader trading as Pretty Decent Admin, is the controller of personal information processed for Pretty Decent Admin’s own business purposes.
Contact details
Email: talia@prettydecentadmin.co.uk
What information I collect, use, and why
I collect or use the listed information for the following purposes:
To provide and improve products and services for clients
Names and contact details
Addresses
Occupation
Payment details (including card or bank information for transfers)
Transaction data (including details about payments to and from you and details of products and services you have purchased)
Information relating to compliments or complaints
Records of meetings and decisions
Account access information
For the operation of client or customer accounts
Names and contact details
Addresses
Purchase or service history
Account information, including registration details
Information used for security purposes
For information updates and direct marketing
Names and business contact details
Organisation name, business role, publicly available business contact details, marketing preferences, objections and opt-out records
For website analytics purposes
Consented page views and scrolls
Client/session identifiers
Browser/device/language information
Page URL/title
Referrer
Session data
Approximate location derived from network information
To comply with legal requirements
Name
Contact information
Client account information
Any other personal information required to comply with legal obligations
For supplier, adviser and associate administration
Names and business contact details
Organisation and business role
Contracts and correspondence
Due-diligence, insurance and compliance information
Invoice, payment and other relevant financial records
For security, access logs, rights requests and incidents
Account, device and access metadata
IP and security-log information
Information about data-protection requests, complaints or security incidents
Relevant correspondence
Investigation evidence, decisions and disclosure records
For dealing with queries, complaints or claims
Names and contact details
Payment details
Account information
Purchase or service history
Relevant information from previous investigations
Customer or client accounts and records
Financial transaction information
Correspondence
I do not intentionally collect special category or criminal offence data for Pretty Decent Admin's own routine business administration. Where I process this type of information solely on a client's instructions as part of the Services, the client remains the controller and the processing is governed by the applicable Client Services Agreement and Data Processing Schedule.
My Lawful bases for the collection and use of your data
My lawful bases for collecting or using personal information for the following purposes:
To provide and improve products and services for clients
Contract - I have to collect or use the information so I can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
Legitimate interests - I am collecting or using your information because it benefits you, my organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. My legitimate interests are:
I have a legitimate interest in managing and improving the administrative services I provide to clients, maintaining effective business processes and ensuring my services are delivered securely and efficiently. I only use personal information where it is necessary for these purposes and where the use would reasonably be expected as part of my working relationship with clients. I limit the information I use to what is relevant and proportionate, and I do not use it in ways that would have an unjustified impact on an individual’s privacy, rights or freedoms.
For more information on my use of legitimate interests as a lawful basis you can contact me using the contact details set out above.
For the operation of client or customer accounts
Contract - I have to collect or use the information so I can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
Legitimate interests - I am collecting or using your information because it benefits you, my organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. My legitimate interests are:
I have a legitimate interest in managing client accounts efficiently and securely, including maintaining accurate account records, administering client portal access, managing bookings and service history, and protecting client accounts from unauthorised access or misuse. I only use personal information where it is necessary and proportionate for these purposes, and in ways that clients would reasonably expect as part of their relationship with me. I limit the information used to what is relevant and do not use it in ways that would have an unjustified impact on individuals’ privacy, rights or freedoms.
For more information on my use of legitimate interests as a lawful basis you can contact me using the contact details set out above.
For information updates and direct marketing
Consent - I have permission from you after I gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.
Legitimate interests - I am collecting or using your information because it benefits you, my organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. My legitimate interests are:
I have a legitimate interest in promoting Pretty Decent Admin's services to existing and prospective business contacts where this is lawful, relevant and proportionate. This may include direct marketing to corporate business contacts and screened live business calls. I only send electronic direct marketing, including email and professional-networking direct messages, where permitted by law. I use consent where it is required by law, including for electronic marketing to sole traders and other individual subscribers unless a lawful exception applies. I do not use personal information for marketing where an individual has objected or opted out. I limit the information used to what is necessary, use public business sources responsibly, and provide a clear and easy way to object to or opt out of marketing communications.
For more information on my use of legitimate interests as a lawful basis you can contact me using the contact details set out above.
For website analytics purposes
Consent - I use Google Analytics only after you select “I agree” on the website cookie banner. You can refuse Analytics by selecting “Only essentials” and can withdraw your consent at any time using “Update My Cookie Preferences”.
To comply with legal requirements
- Legal obligation - I have to collect or use your information so I can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object and the right to data portability.
For supplier, adviser and associate administration
Contract - Where the supplier, adviser or associate is an individual or sole trader, I may need to use their information to enter into or carry out a contract with them.
Legitimate interests - I have a legitimate interest in selecting, engaging, managing and paying appropriate business suppliers, advisers and associates, maintaining accurate business records and monitoring the services they provide. I limit the information used to what is necessary and proportionate for those purposes.
Legal obligation - I may need to keep invoice, payment, tax, insurance or compliance information to meet my legal and regulatory obligations.
For security, access management and data-protection compliance
- Legitimate interests - I have a legitimate interest in protecting my systems and business information, preventing and investigating unauthorised access or misuse, resolving security concerns and establishing, exercising or defending legal claims. I use only the information reasonably necessary for those purposes.
- Legal obligation - I may need to use and retain information to respond to data-protection rights requests, investigate and document personal-data incidents, make legally required notifications and demonstrate compliance with data-protection law.
For dealing with queries, complaints or claims
Legitimate interests - I am collecting or using your information because it benefits you, my organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. My legitimate interests are:
I have a legitimate interest in responding to enquiries, investigating and resolving complaints or disputes, and establishing, exercising or defending legal claims where necessary. I only use personal information that is relevant and necessary for these purposes and would reasonably be expected in the context of the enquiry, complaint or dispute. I balance my need to resolve matters fairly and protect my business against the rights and privacy of the individuals involved, and I do not use the information in ways that would have an unjustified impact on them.
For more information on my use of legitimate interests as a lawful basis you can contact me using the contact details set out above.
Your data protection rights
Depending on the circumstances and the lawful basis I rely on, you may have rights to:
- ask for access to your personal information;
ask for inaccurate information to be corrected;
ask for personal information to be erased;
ask for processing to be restricted;
object to certain processing;
request transfer of information in certain circumstances; and
- withdraw consent where processing relies on consent.
You can refuse Google Analytics by selecting “Only essentials” on the cookie banner. If you previously selected “I agree”, you can withdraw your consent at any time using “Update My Cookie Preferences”.
These rights are not absolute and do not all apply in every circumstance. However, you have an absolute right to object to the use of your personal information for direct marketing. To exercise a right or opt out of marketing, contact me using the details above.
Where I get personal information from
Directly from you
Analytics information is received automatically from your browser or device, but only after you select “I agree”.
Third parties:
I may receive personal information from existing clients, professional contacts, referral partners or other organisations where they introduce or refer an individual to me, or provide contact details so that I can communicate with that individual in connection with my services. I may also collect limited business contact information from public business sources, such as company websites, Companies House, public professional profiles and directories, where it is relevant to offering my services. If I use information collected from a public source to contact you directly, I will provide privacy information no later than my first communication with you.
How long I keep information
Please find my retention schedule below:
Record Type | Purpose | Retention Period |
|---|---|---|
Enquiries that do not become clients (including website/contact form enquiries) | Responding to enquiries, assessing likely fit and arranging prospective-client discussions. | 3 months after last contact. If the person becomes a client, move relevant records into the applicable client, contract, communication and financial categories. |
General former-client record | Maintaining client relationship and service history. | 1 year after last contact or end of service. |
Contracts and key contractual records | Evidence of the contractual relationship and protection in the event of a claim. | 6 years after the contract ends or the relevant matter closes, whichever is later. |
Financial and tax records | Accounting, tax and legal obligations. | At least 5 years after the 31 January Self Assessment submission deadline for the relevant tax year. Keep them longer where required for a late return or an HMRC enquiry. |
Client login credentials and access tokens | Providing authorised access to client systems. | Delete immediately when access is no longer required. Revoke access where possible as well as deleting saved credentials. |
Routine business emails, messages and meeting notes | Managing client, supplier and other business relationships and providing services. | 1 year after last contact or the end of the relevant relationship. |
Important correspondence supporting a contract, dispute, payment or legal position | Maintaining evidence of significant contractual, payment or service matters and establishing, exercising or defending potential claims. | 6 years after the contract ends or the relevant matter closes, whichever is later. |
Complaints, disputes and claims | Investigating and resolving disputes and defending potential claims. | 6 years after closure. |
Data protection rights requests, security incidents and related evidence | Responding to data protection requests, investigating incidents and demonstrating compliance. | Keep while the matter is active. After closure, retain only the evidence needed to demonstrate compliance or support a legal position. Where it is important as evidence of a complaint, claim or legal matter, retain it for 6 years after closure; otherwise delete it sooner when no longer needed. |
Provider security and access logs | Protecting systems, identifying issues and investigating access or security events. | For the provider-configured period and operational need, reviewed at least annually. Export or retain a separate copy only where needed for an incident, rights request, complaint or claim. |
Marketing contact information | Sending relevant service updates and maintaining appropriate business relationships where consent or another lawful basis applies. | Keep while consent or another lawful basis remains valid and the contact remains relevant. Review at least annually. Remove from active direct marketing immediately following an unsubscribe or objection. |
Marketing suppression record | Recording opt-outs and objections so that people who have asked not to receive marketing are not contacted again. | Keep only the minimum contact identifier, the channel restricted, and the date and source of the opt-out or objection, for as long as needed to ensure the preference is respected. |
Prospect research and direct business outreach records | Identifying potentially relevant UK businesses and contacts, assessing likely service fit, making limited personalised contact, and recording sources, responses and outreach status. | Review before reuse and at least annually. Delete or anonymise information that is irrelevant, inaccurate or no longer needed. If the contact becomes an enquiry, apply the enquiry period. Following an objection or opt-out, stop marketing and retain only the applicable suppression record. |
Minimal organisation exclusion record | Avoiding repeated research or contact where Pretty Decent Admin has decided not to pursue an organisation. | Keep only the organisation or domain, a neutral reason, the decision date and review date, with no named-contact information. Review at least annually and delete when no longer needed. |
Website cookies, browser storage and cookie-choice records | Operating the website, maintaining sessions, remembering relevant preferences and recording visitors' cookie choices. | For the configured lifetime of each cookie or browser-storage item. Review at least annually and whenever the website or cookie configuration materially changes. Current durations are listed in the Cookie Policy. |
Google Analytics user and event data | Measuring consented page views and scroll activity to understand website use and improve content and usability. | 2 months. Retention does not reset following new user activity. Standard aggregated reports may remain available beyond this period; keep them only while useful for website improvement and review them at least annually. |
Trustpilot reviews, replies and website testimonials | Managing public reviews and publishing separately approved testimonials. | Trustpilot controls retention of reviews on its platform. Do not retain a separate copy unless needed for a complaint, claim or publication-approval record. Remove a website testimonial if permission is withdrawn or it is no longer used. Review published material at least annually and keep only the minimum approval or withdrawal evidence still needed. |
Personal data processed on behalf of clients | Providing contracted administrative services on a client's behalf and processing personal information only in accordance with the client's instructions. | As specified in the client's instructions or Data Processing Schedule. Return or delete it when no longer required or at the end of the engagement, unless the client instructs otherwise or the law requires continued retention. |
For more information on how long I store your personal information or the criteria I use to determine this please contact me using the details provided above. I review prospect contact information periodically and remove it when it is no longer relevant. If you opt out or object to direct marketing, I stop using your information for that purpose and retain only the minimum information needed to make sure I do not contact you again by that channel.
Who I share information with
Data processors
Odoo
This data processor does the following activities for me:
- Provides business management CRM, invoicing, client portal, website hosting and related administrative services.
Odoo stores and processes client contact details, account information, service records, correspondence and other information entered into the platform on my behalf.
Google LLC – Google Workspace and related Google services
This data processor does the following activities for me:
- Provides business email, cloud storage, document management and productivity services through Google Workspace.
Google stores and processes personal information contained in emails, contacts, documents, files and business records through the Google Workspace services I use.
Google LLC - Google Analytics
Google processes consented information about visits to my website, including:
Pseudonymous client and session identifiers
Browser and device information
Page and referral information
Approximate location
Page-view and scroll events.
This helps me understand website use and improve content and usability. Analytics information is collected only after the visitor selects “I agree”. I do not send contact-form contents to Google Analytics.
Others I share personal information with
Insurance companies, brokers or other intermediaries
Professional or legal advisors
Organisations I am legally obliged to share personal information with
Trustpilot A/S (online review platform) - I use Trustpilot to collect and respond to reviews about Pretty Decent Admin. If you choose to leave a review, you provide your information directly to Trustpilot, which processes its platform, account and review information under its own privacy policy. Your username, review, rating, date of experience and any reply may be publicly visible. I do not upload client contact details to Trustpilot under my current direct-link process.
Use of Artificial Intelligence
I may use ChatGPT, provided by OpenAI, to assist with drafting, editing, reviewing and developing written content, templates and administrative materials.
I do not input identifiable personal data, special category data, criminal offence data or confidential client information into my own AI tools. Information used with ChatGPT is generic, anonymised or otherwise non-identifiable, and AI-generated outputs are reviewed by me before use.
I do not use AI to make solely automated decisions about individuals that have legal or similarly significant effects.
Clients may request that AI tools are not used in connection with their Services.
Sharing information outside the UK
Where necessary, my data processors will share personal information outside of the UK. When doing so, they comply with the UK GDPR, making sure appropriate safeguards are in place.
For further information or to obtain a copy of the appropriate safeguard for any of the transfers below, please contact me using the contact information provided above.
Google Workspace | |
Organisation name | Google LLC and its authorised subprocessors. |
Category of recipient | Cloud and productivity service provider |
Country the personal information is sent to | Countries where Google and its authorised subprocessors operate |
Safeguards | Depending on the transfer, an adequacy arrangement, including the UK Extension to the EU–US Data Privacy Framework where applicable, or applicable contractual clauses under Google’s Cloud Data Processing Addendum. |
Google Analytics | |
Organisation name | Google LLC and its authorised subprocessors |
Category of recipient | Website analytics service provider. |
Country the personal information is sent to | United States and other countries where Google and its authorised subprocessors operate |
Safeguards | Depending on the transfer, the UK Extension to the EU-US Data Privacy Framework and/or applicable contractual clauses |
Odoo | |
Organisation name | Odoo S.A. and its authorised hosting subprocessors, including Google Cloud EMEA Ltd and OVH S.A.S. |
Category of recipient | Cloud infrastructure and hosting providers used by Odoo |
Country the personal information is sent to | European hosting region: production in France or Belgium; backups in France, the Netherlands and Sweden. |
Safeguards | The country or sector has been assessed as providing adequate protection to data subjects (also known as Adequacy Regulations or UK data bridge) |
How to complain
If you have any concerns about my use of your personal information, you can make a data protection complaint to me:
Email: talia@prettydecentadmin.co.uk
You can view my data complaints procedure at this link: www.prettydecentadmin.co.uk\/data-protection-complaints
If you remain unhappy with how I’ve used your data after raising a complaint with me, you can also complain to the ICO.
The ICO’s address:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline number: 0303 123 1113