HomeWhy usOur expertise
Digital report
2026 EditionFirst Edition
Your teamCareers
contact

Privacy Policy

Introduction

Greenbrook Communications Limited (“Greenbrook”, “we”, “our”) is a London-based financial communications firm. We are committed to safeguarding the privacy of the personal information that is provided to us or collected by us during the course of our business, as well as the personal information we receive from visitors to our website at www.greenbrookadvisory.com (our “Website”). 

Greenbrook is the data controller in respect of the personal information covered by this Privacy Policy, except where we process personal information solely on behalf of a client or other third party, in which case we may act as a data processor.

This Privacy Policy explains how we may collect and use any personal information that we obtain about you, and your rights in relation to that information. It also sets out how to contact us if you have any questions about this Privacy Policy or want to make a complaint to us about how we handle your personal information.

We may provide you with additional privacy notices where we think that it is appropriate to do so. Those additional notices supplement and should be read together with this Privacy Policy.

The UK General Data Protection Regulation (UK GDPR), the UK Data Protection Act 2018 and other applicable data protection and privacy legislation (together the “Data Protection Laws”) give you various rights regarding the way in which we collect, store and use your information. These are set out below in the section “Your rights under the Data Protection Laws”. You can also obtain further information about data protection and privacy laws by visiting the Information Commissioner’s Office website at: https://ico.org.uk/.

If you have any questions about this Privacy Policy, our practices, or your dealings with Greenbrook, please contact our Privacy Officer at privacy@greenbrookadvisory.com.

Scope of this Privacy Policy

This Privacy Policy applies in the following circumstances:

  • when we carry out due diligence searches on you in connection with our business development or business acceptance processes; when we agree to provide financial communications services to you or the organisation you work for;
  •  
  • when you or the organisation you work for have business dealings with our clients;
  • when you request information from us or provide information to us;
  •  
  • when you apply for a role or work experience opportunity;
  • when you work for, provide services to, or otherwise have an employment or working relationship with Greenbrook
  • when you visit our Website;
  • when you attend our seminars or other hosted events; and
  •  
  • when you are included in our mailing lists to receive our newsletter and other marketing communications.

What information do we collect from you?

What information do we collect from you?

Business development

We collect personal information about prospective clients and/or directors as part of business development activities and our business acceptance processes. The types of personal information we may collect include name, address, nationality, business interests and employment history. We obtain this information from publicly available sources, either directly or through a third party.

‍Providing financial communications services, our newsletter and other marketing

‍The type of personal information that we may collect includes current and historical information including your name and contact details (such as your address, email address and telephone numbers) and identifiers such as your organisation, employment history and positions held.  

We will also collect personal information you choose to provide to us and information about your other dealings with us and our clients, including contact we have with you in person, by telephone, letter, email or online. We obtain personal information from your IP address and the operating system and web browser that you use to access our Website, which we may use to compile statistical data on the use of our Website for the purpose of improving visitors’ experiences.

We collect personal information directly from you, or from our clients and their authorised representatives. We may also collect personal information from third parties such as your employer, regulators, government agencies, publicly available records, information or service providers and other financial communications firms or professional advisers.  

We may store your personal information in our contact database, and use your information to send you emails about our services and to invite you to Greenbrook events.  If you no longer wish to receive marketing communications from us by email or post, you can unsubscribe at any time by using the “Unsubscribe” option in the email footer or by contacting privacy@greenbrookadvisory.com.

In the course of our business, personal information may also be stored, accessed and processed using the technology and communications systems that we use to operate our business. These include email, document storage and collaboration platforms, customer relationship management (CRM) and contact management systems, video conferencing and webinar platforms, and other business administration systems.

We may use CRM and contact management systems to manage and maintain our client, prospective client and other business relationships, including maintaining appropriate records of communications, interactions and business contacts.

We also use information security, device management, identity management, backup and cyber-security systems to protect our systems and the information held within them.

Employment and Recruitment

‍If you work for or provide services to Greenbrook, we may collect and process personal information relating to your employment or working relationship with us. This may include identification and contact details, employment records, remuneration and benefits information, performance and training records, absence information and other information reasonably required to manage that relationship and comply with our legal obligations. Where appropriate, this may include special category personal information.

If you apply for a position or work experience opportunity with us you may need to provide personal information, which may include special categories of personal information. We will use this information for the purposes of managing the recruitment process, considering your suitability for the role and, where appropriate, taking steps before entering into a contract with you.

We may also use the information to carry out checks to verify the information provided by you (including reference, background, identity, credit, suitability and, where lawful and appropriate, criminal record checks).

We may use third party service providers to store or otherwise process employment and recruitment information.  We may also disclose relevant information to recruiters, occupational health or other medical professionals, your referees, pension and benefits providers, professional advisers and, where appropriate, your current and previous employers.

Who we share your personal information with

We may share your personal information with, or permit access to it, third parties who provide services on our behalf. These may include providers of IT infrastructure and support, cloud hosting and data storage, email and communications, customer relationship management (CRM) and contact management systems, marketing and mailing services, website hosting and analytics, video conferencing and webinar services, cyber-security, identity and access management, device management, data backup and recovery, recruitment and other professional or business support services.

These service providers may process personal information on our behalf where this is necessary to provide their services to us and are required to handle that information appropriately and securely.

If Greenbrook sells or buys any business or assets, we may disclose your personal information to any prospective seller or buyer of such business or assets.  If Greenbrook or substantially all of its assets are acquired by a third party, your personal information may be transferred to that third party.  We may also have to share your personal information with regulators, government agencies, courts and other third parties where required or permitted by law.

Some of our service providers may process personal information outside the UK. Where personal information is transferred internationally, we will ensure that the transfer is made in accordance with applicable Data Protection Laws, including, when required, by relying on applicable adequacy regulations or implementing appropriate contractual or other safeguards.  

In addition, some of your personal information may be stored in a private cloud located within or outside of the United Kingdom and managed by a third party hosting provider. If we transfer your personal information outside the United Kingdom, we will implement and maintain, and ensure that our service providers implement and maintain, appropriate technical and organisational measures to ensure that your personal information is treated securely and in accordance with this Privacy Policy.

We may share your personal information with third parties where:

  • you have consented to us doing so or, where appropriate, the organisation that you work for has lawfully provided the information to us;; or
  • we are under a legal, regulatory or professional obligation to do so, for example to comply with applicable legal and regulatory requirements); or
  • it is necessary for the purpose of, or in connection with, legal proceedings or in order to exercise or defend legal rights; or
  • it is otherwise lawful and reasonably necessary in connection with the operation of our business or provision of our services.

How we use your information, and how long we keep it for

We will only use your personal information if, and to the extent that, we are permitted to under Data Protection Laws. Depending on the circumstances, we will therefore only process your personal information where:

  • it is necessary for the performance of a contract with you or the organisation you work for steps at your request before entering into a contract; or
  • it is necessary in connection with a legal obligation; or
  • where required, you have given your consent to such use or the organisation you work for has obtained your consent to share your information with us; or
  • it is necessary for the purposes of our legitimate interests, or those of a third party, where those interests are not overridden by your interests or fundamental rights and freedoms; or another lawful basis permitted under Data Protection Laws applies.

Where we process special category personal information, we will only do so where an additional lawful condition for processing that information applies.

We may use your personal information:

  • to carry out verification and other background checks;
  • to provide financial communications and other services to you and/or the organisation you work for;
  • to carry out day-to-day administrative or operational processes, including invoicing, employment and recruitment;
  • to operate, administer, secure and improve our business, systems and services, including maintaining the security and integrity of our IT systems, preventing and detecting fraud or misuse and maintaining appropriate business records;
  • to manage our employment and working relationships, including payroll, benefits, performance, training and compliance matters;
  • to manage and maintain our client, prospective client and other business relationships, including maintaining appropriate records of communications and interactions; and
  • to develop our business relationship with you, including sending you newsletters and other marketing communications where permitted by law.

We will only retain your personal information for as long as is necessary for the purpose for which it was collected, including for the purposes of complying with any legal, regulatory, accounting or reporting requirements.  

The appropriate retention period will depend on the nature of the information, the purposes for which it is processed and any applicable legal, regulatory or contractual requirements.

Security

We implement and maintain appropriate technical and organisational security measures designed to protect your personal information from unauthorised access, improper use or disclosure, unauthorised modification or unlawful destruction, or accidental loss. These measures include, where appropriate, access controls, identity and device management, encryption, email and endpoint security, threat detection, data backup and recovery and other cyber-security measures.

Specifically:

  • for data stored on the Greenbrook network, 256-bit Advanced Encryption Standard (AES) encryption; and
  • for data in transit, 128-bit (or higher) AES encryption using Secure Sockets Layer (SSL)/Transport Layer Security (TLS).

Our staff and third party service providers who have access to personal information are subject to appropriate confidentiality obligations.

Your rights under the Data Protection Laws

Depending on the circumstances and the applicable lawful basis for processing, you may have certain rights under Data Protection Laws, including:

  1. The right to be informed about how we collect and use your personal data.  
  2. The right to request access to the personal information that we hold about you. Unless you make repeated or manifestly unfounded or excessive requests, we will not charge a fee for providing you with a copy of this data.
  3. The right to request that we correct any inaccurate or incomplete personal information that we hold about you.
  4. The right, in certain circumstances, to request that we irretrievably delete all personal information that we hold about you (the so-called “right to be forgotten”).  
  5. The right, in certain circumstances, to request that we restrict the processing of your personal information.
  6. The right to object to certain processing of your personal information, including processing based on legitimate interests and processing for direct marketing purposes.
  7. Where we rely on your consent to process your personal information, the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of processing carried out before consent was withdrawn.
  8. The right to request that we transmit all the personal information that we hold about you (in a structured, commonly used and machine-readable form) to another organisation’s IT environment. Note that we are only legally obliged to comply with this request if it is technically feasible for us to do so.
  9. Rights relating to certain decisions made solely by automated means which produce legal or similarly significant effects, where applicable.

These rights are subject to certain limitations and exemptions under Data Protection Laws and may not apply in every circumstance.

Should you wish to exercise any of the above rights, please contact us by post at:

Privacy Officer

Greenbrook Communications Limited
1 Vere Street
London
W1G 0DF

or by email at privacy@greenbrookadvisory.com.

We will respond to requests in accordance with the timescales required by applicable Data Protection Laws.

We are confident that our Privacy Officer can resolve any query or concern you have about our use of your personal information, however if you feel that we have not handled your query or concern to your satisfaction you have the right to complain to the Information Commissioner’s Office (ICO), the United Kingdom’s supervisory authority for data protection issues and further information is available at https://ico.org.uk/concerns or telephone 0303 123 1113.

why us
our expertise
your team
contact us
ⒸGREENBROOK 2026
privacy & LEGALGreenbRook is a carbon neutral organisationlOW CARBON VERSION OF OUR SITE