Privacy policy — Trauma-Informed Content Consulting
Last updated: 29 July 2026
This policy covers the Trauma-Informed Content Consulting website at traumainformedcontent.com, enquiries you send us, our mailing list, events, and our consultancy engagements.
Rembrandt Editor has its own policy. If you’re using the review tool at rembrandteditor.com, see that policy instead.
Who we are
Trauma-Informed Content Consulting is a trading name of Bankside Communications Limited, a limited company registered in England and Wales, company number 14193570, registered office Pearce & Co, Ground Floor, 11 Pierrepont Street, Bath, England, BA1 1LA.
For UK GDPR and the Data Protection Act 2018, Bankside Communications Limited is the data controller for everything described in this policy — except client material, where we act as processor. See “Client material” below.
Contact: privacy@traumainformedcontent.com
What we collect
When you browse this website. Our hosting provider records standard server logs — IP address, browser type, pages requested, timestamps — for security and diagnosing faults. The site is built on WordPress and uses functional cookies for session handling and, where you’re an administrator, for logging in.
When you contact us. Through the contact form, by email, by phone or on social media: your name, email address, telephone number if you give one, organisation, and whatever you tell us. We keep a record of the correspondence.
When you subscribe to the mailing list. Your email address and name, and whether you’ve opened or clicked our emails.
When you register for an event or workshop. Your name, email address, organisation and role, plus any accessibility or dietary requirements you tell us. Requirements relating to disability or health are special category data, held only for the event and deleted afterwards.
When you engage us as a client. Contact details for the people we work with, correspondence, contract and invoicing details, and records of the work.
Client material. Engagements often involve material containing other people’s personal data — customer letters, claimant correspondence, research transcripts, case notes. See below.
When you make a payment to us. Bank details for invoice payment, or card details processed by our payment provider. We don’t store card details.
Client material: we are your processor
When you give us material containing personal data as part of an engagement, you are the controller and we are your processor. We process it only on your instructions and only for the engagement.
This is governed by our consultancy data processing agreement, which sets out sub-processors, security measures, retention, breach notification and audit rights.
Two things worth saying plainly. First, we ask clients to redact identifying details from real correspondence wherever the work doesn’t depend on them — a letter reviews just as well with “[Customer]” and “[Ref]” in place of a name and account number. Second, we use AI tools including Rembrandt Editor as part of our practice, and where an engagement involves putting your material through one, we’ll tell you which and you can decline.
Our lawful bases
- Legitimate interests — responding to enquiries, running the website securely, managing client relationships, and marketing our services to organisations, balanced against your interests
- Contract — delivering engagements and taking payment
- Consent — the mailing list, and any special category data you give us for an event
- Legal obligation — accounting and tax records, responding to lawful requests
Who processes your data
Our website host — hosts traumainformedcontent.com and holds server logs.
Google Workspace (Google Ireland Limited) — email, calendar and document storage. Data held in the EU and United States under Standard Contractual Clauses.
Our mailing list provider — holds subscriber names, email addresses and engagement data.
Our accountants and payment providers — invoicing, bookkeeping and payment records.
Anthropic, PBC (United States) — where an engagement involves AI-assisted analysis. Content is not used to train models. Transfers under the UK Addendum to the EU Standard Contractual Clauses.
Rembrandt Editor — our own service, operated by the same company. Where we use it on client material, the Rembrandt Editor privacy policy describes the infrastructure involved.
We’ll update this list as providers change. Clients receive notice of sub-processor changes under the consultancy DPA.
How long we keep it
| What | How long |
|---|---|
| Website server logs | Per the host’s standard retention, typically under 30 days |
| Enquiries that don’t become engagements | 24 months |
| Mailing list subscription | Until you unsubscribe, then a suppression record so we don’t re-add you |
| Event registrations | 12 months. Accessibility and dietary requirements are deleted immediately after the event |
| Client contact and engagement records | 6 years from the end of the engagement, to meet contractual and tax requirements |
| Client material containing personal data | Per the engagement and the consultancy DPA; deleted or returned within 30 days of the engagement ending unless you ask us to keep it |
| Invoices and accounting records | 6 years, to meet HMRC requirements |
Your rights
Under UK GDPR you can ask us to give you a copy of what we hold, correct anything inaccurate, delete your data, restrict or object to processing, provide it in a portable format, or withdraw consent you’ve given. You can also complain to the ICO at https://ico.org.uk/concerns/.
If your data reached us in client material, we’ll direct you to the client who is the controller and tell them you’ve been in touch — we can’t act on your request without their instruction, and telling you who they are is usually the fastest route to a resolution.
Email privacy@traumainformedcontent.com. We aim to respond within 14 days and will always respond within the statutory month.
Marketing
We may email organisations about our services where we have a legitimate interest — typically because you’ve enquired, attended an event, or work in a role our practice is relevant to. Every email carries an unsubscribe link, and we’ll stop when you ask.
We don’t sell or rent your details, and we don’t share them with other organisations for their marketing.
Cookies
The website uses functional cookies for session handling and, for administrators, logging in. Where we use embedded content — video, maps, social media — that third party may set its own cookies.
We keep third-party embeds and analytics to a minimum. If we add anything requiring consent under PECR, we’ll add a consent mechanism and update this policy first.
Security
Data is held in Google Workspace and on the website host, both with encryption in transit and at rest. Access is limited to Adrie van der Luijt, Director, Bankside Communications. Devices are encrypted and password-protected. Client material is stored separately from general business records and deleted at the end of the engagement unless the client asks otherwise.
We’re a single-practitioner practice. We hold no ISO 27001 or SOC 2 certification, and we’d rather say so than imply otherwise.
If a breach affects your personal data we’ll notify the ICO within 72 hours of becoming aware, and notify you without undue delay where the risk to you is high. Where the breach affects client material, we’ll notify the client within 48 hours.
Children
This website and our services are aimed at professionals. We don’t knowingly collect data from anyone under 18.
Some of our work concerns content read by young people. Where an engagement involves material about or from children, that is client material processed under the consultancy DPA, with additional care.
Changes
We’ll update this policy when our processing changes, when providers change, or when the law does, and update the date at the top.
Contact
Email: privacy@traumainformedcontent.com
Post: Bankside Communications Limited, Pearce & Co, Ground Floor, 11 Pierrepont Street, Bath, England, BA1 1LA London: 107 Bankside Lofts, 65 Hopton Street, London SE1 9JL.
Complaints about our handling of personal data can also go to the Information Commissioner’s Office: https://ico.org.uk/concerns/