Privacy & GDPR Policy
Protecting people’s personal information supports our goal of building stronger communities. That’s why we take your privacy seriously.
We are committed to protecting your personal information and using it in ways that are fair, transparent, and duty bound under legal obligations. We will never sell your data or personal information and will only use in ways you would reasonably expect, in line with current data protection law.
If you have any questions at all about how we use or store data please contact our data controller via [email protected].
We are required to provide you with the information in this Privacy Notice under applicable law which includes:
We are a private limited company registered in England and Wales under company number 10038348
Our registered office address is: Huckletree Ancoats, The Express Building, 9 Great Ancoats St, Manchester M4 5AD
How you can contact us:
(Updated: October 2025)
When you directly give us information
We collect personal data when you provide it to our team directly, such as when you contact High-Rise via email, phone, in-person, or our website.
For example, this could be when you:
When you indirectly give us information
When you interact with us on social media platforms such as Facebook, Twitter or LinkedIn we may also obtain some personal information about you. The information we receive will depend on the privacy preferences you have set on each platform and the privacy policies of each platform. To change your settings on these platforms, please refer to their privacy notices.
We may obtain information from cookies to understand how visitors interact with our website and to improve the user experience. You can manage your cookies via your browser settings. For more information, please email our data controller: [email protected]
When you engage with us by phone, mail, in person or online, we may collect information about you (referred to in this privacy policy as ‘personal information’). This may include your name, address, email address, telephone number, date of birth, job title and details of your education and career, and other information relating to you personally which you may choose to provide to us.
Data protection law recognises that certain types of personal information are more sensitive. This is known as ‘sensitive’ or ‘special category’ personal information and covers information revealing racial or ethnic origin, religious or philosophical beliefs and political opinions, trade union membership, genetic or biometric data, information concerning health or data concerning a person’s sex life or sexual orientation.
Sensitive information will only be collected where necessary, for example, for a case study collected with your permission and used for advocacy or media relations purposes.
In line with data protection law and GDPR regulation, our legal bases for processing personal data may include:
Our legitimate interests include:
If you’re aged under 16, you must get your parent/guardian’s permission before you provide any personal information to us.
We may use your personal information for the following purposes:
We will only use your information for the purposes for which it was obtained. We will not sell your personal information with any third party and will not share your sensitive details without your consent.
We cannot confirm all the data we process remains in the UK. As a part of the legitimate functioning of our commercial interests, data can be transferred to international media outlets and journalists, alongside those that reside in Great Britain and Northern Ireland and its overseas territories.
However, at High-Rise our ways of working limit the amount, and type, of personal data and information sharing that takes place.
High-Rise will never share information that falls under the ‘special information’ category of data without your verbal, or written, consent.
We retain personal data for as long as necessary to fulfil and cover the purposes of which we collated it for. This includes meeting any legal, accounting, or reporting requirements reasonably expected of a UK limited company by HM Government and Companies House.
Information types and the legal bases under which data was originally collate determines the period we retain data. See examples of these data types below.
We work hard to make sure your personal information is secure. We undertake regular reviews of who has access to information that we hold. We cannot 100% guarantee the security of data (including personal information) disclosed or transmitted over public networks.
At High-Rise, we take the security and confidentiality of all organisational data seriously, including any personal data we process as part of our operations. While we have robust and clear guidelines on how to handle and process data, it is important we are prepared for and equipped to deal with data breaches.
In the event of a data breach, we’re committed to dealing with the situation quickly and in an organised way. Within the first 72 hours after discovery, we will notify the Information Commissioner’s Office (ICO), in line with our legal obligations. Regardless of the severity of a data breach, whether it meets the threshold for ICO reporting or not, High-Rise is committed to investigating the origins of the incident, establishing a timeline, and documenting the event to prevent it from happening again.
Some data breaches may be a simple mix-up with little to no risk, while some can present lasting impact. In cases where breaches may pose a high risk to individuals’ rights and freedoms, we will notify those affected. Our Data Protection Officer, Helen Furnivall, will contact individuals personally as needed on a case-by-case basis, referring to the ICO Accountability Framework throughout.
Through our ‘Privacy by Design’ ways of working, we minimise the risk of data breaches through strict controls on data access, limiting it to authorised employees and vetted third-party partners. Embedding this into our work processes means we ensure data protection is front of mind in all our business activities. We also regularly review and assess third-party relationships to ensure their GDPR compliance holds up to the highest levels of data protection and they are helping us keep our IT secure.
As a part of our ongoing commitment to ensure high levels of data protection, staff at High-Rise are required to have a strong awareness of the topic as a part of their good working practices. For example, this includes awareness of UK GDPR law, how to securely handle information, and recognising high-risk areas for potential breaches. This ongoing work helps reduce human error, which is by far the most common source of data breaches.
On an organisational level, High-Rise undertakes an annual risk assessment to evaluate the severity and likelihood of potential data breaches through our ways of working. Assessing where we store our data, process it, and the types we control, helps us take the most appropriate response in the event of a breach. If the High-Rise team feels any systems can be strengthened to mitigate further risk, this is fed back through our one to one and team meetings.
At High-Rise we will never use your personal data for automated decision-making or profiling. Neither will we provide your personal data to a third party to execute such processes.
You have rights under UK data protection law, as specified by the aforementioned pieces of legislation and regulation, including the right to:
If you wish to exercise these rights, please email our data controller: [email protected]
You also have the right to raise objections to the way we handle your data with the Information Commissioner’s Office (ICO) if you’re unhappy with our processes.
To exercise this right, please see the ICO’s complaints page here.
Our Privacy Policy may change from time to time, so please check this page occasionally to see if we have included any updates or changes, and that you are happy with them.
(Last updated: October 22nd 2025)