Policies
Privacy Policy
Last updated: 26 August 2026
1. About this Privacy Policy
This Privacy Policy explains how FRGN LTD, trading as BPRG, collects, uses, stores, shares and protects personal information in connection with the BPRG website, our enquiry and contact forms, our online business assessment, our diagnostic sprints, prospective client discussions, and other interactions that refer or link to this policy. "Personal information" (also "personal data") means information relating to an identified or identifiable individual. This policy does not govern personal information processed under a separate client contract, data-processing agreement, recruitment notice or other service-specific notice where that document expressly applies.
2. Who we are
The controller responsible for the personal information described here is FRGN LTD, trading as BPRG ("BPRG", "we", "us", "our"), company number 14044289, registered office Unit 1, Willow Park, Upton Lane, Stoke Golding, Nuneaton, Warwickshire, England, CV13 6EU. For privacy enquiries, requests or complaints: email benjamin@bprg.uk or write to the registered office. We are the controller where we determine why and how personal information is processed. In some client engagements we may instead process personal information on a client's documented instructions; where that occurs, the client will ordinarily be the controller and its privacy information will apply.
3. The personal information we collect
The information we collect depends on how you interact with us.
3.1 Enquiries and prospective client discussions. When you submit an enquiry or discuss a potential engagement, we may collect your name, business email address, telephone number, employer or organisation, job title or role, country or business location, the subject and contents of your enquiry, information about your organisation, operations, objectives or challenges, records of correspondence, calls and meetings, your communication preferences and any other information you choose to provide.
3.2 The assessment and other diagnostic tools. When you complete our online assessment, we may collect your name, work email address, employer or organisation, job title or role, country, assessment answers, band or score and calculated results, report-generation information, completion status, timestamps and related technical records, comments or free-text responses, and requests for follow-up. Assessment answers may include information about an organisation's systems, practices, governance, processes, performance or capabilities; although information about a company is not necessarily personal information, it may become personal information where it identifies or relates to an individual. Please do not use assessment fields to provide trade secrets, patient information, employee records, confidential manufacturing data, protected health information, special-category personal information or other information not necessary to receive the result.
3.3 Resources and updates. BPRG does not currently operate a newsletter or a gated content library, and the website has no subscription form. If we introduce one, we may collect your email address, your name and organisation or role where provided, the content requested, subscription date and source, communication preferences, delivery, opening and click information where enabled, and unsubscribe and suppression records. Registering to read or download a resource would not place you in a sales pipeline unless that is made clear at the point of collection or you separately request contact about our services.
3.4 Events and webinars. BPRG does not currently run public events or webinars. If you register for or attend one in future, we may collect your registration details, organisation and job title, attendance records, questions and comments, event preferences, recordings or transcripts where the event is recorded and appropriate notice is given, and follow-up communications.
3.5 Technical, device and usage information. When you use the website, we or our service providers may collect your internet protocol (IP) address (including hashed, truncated or pseudonymised versions), device, operating system and browser information, language and time-zone settings, approximate geographic region derived from network information, referring website or campaign source, pages and links viewed, dates, times and duration of visits, navigation and interaction events, session, cookie and local-storage identifiers, consent preferences, error, diagnostic and security logs, and information used to identify automated traffic, misuse or attempted unauthorised access. Where we describe information as hashed, pseudonymised or de-identified, it may still be personal information unless it has been rendered genuinely anonymous. The BPRG website currently sets no analytics, advertising or other non-essential cookies, so no consent banner is shown; if that changes we will ask for consent before setting them and publish a cookie notice.
3.6 Information received from other sources. We may receive professional contact information from your employer or colleagues, business partners and professional advisers, event organisers, publicly available professional sources, professional networking services, referrals and introductions, and our CRM and business-development or business-contact providers, where their collection and disclosure is lawful. Where we obtain your personal information from another source, we will provide the information required by applicable data-protection law unless an exemption applies.
3.7 Special-category and highly sensitive information. We do not intentionally request or seek to collect information about health, genetic or biometric identifiers, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade-union membership, sex life or sexual orientation, or criminal convictions or offences. Please do not submit such information through our website, assessments or free-text fields. Where you provide sensitive information without being asked, we may delete it, restrict access to it or contact you to determine how it should be handled.
4. How we use personal information and our lawful bases
We process personal information only where we have an appropriate lawful basis. Across the purposes below, we rely on one or more of the following: taking steps at your request before entering into a contract; performance of a contract; compliance with legal obligations; our legitimate interests; establishing, exercising or defending legal claims; and, where required (for example for electronic marketing or non-essential cookies), your consent.
4.1 Responding to enquiries and managing business relationships. To receive and respond to enquiries, understand the matter, arrange calls or meetings, assess whether our services may be suitable, prepare proposals, maintain contact and relationship records, manage proposals, contracts, billing and administration, and provide client support. Bases: pre-contract steps; performance of a contract; legal obligations; and our legitimate interests in responding to enquiries, managing professional relationships and operating our consultancy.
4.2 Providing assessments and requested resources. To administer assessments, calculate scores and maturity levels, produce and deliver reports and commentary, provide access to requested resources, prevent repeated access prompts where appropriate and respond to questions about a result. Bases: pre-contract steps where applicable; performance of a contract where the assessment or resource forms part of an agreed service; and our legitimate interests in providing requested business resources and operating our assessment tools. We do not ordinarily rely on consent merely to generate or deliver a report you have requested, though consent may be required for separate marketing or certain cookies.
4.3 Updates and marketing. BPRG does not currently send marketing email, and completing the assessment or booking a call does not add you to a marketing list. Where we do send electronic marketing, we send it only with your consent, to provide invitations, insights and reports, information about the assessment and relevant services, and other professional updates. You may withdraw consent or unsubscribe at any time using the unsubscribe link in an email or by contacting benjamin@bprg.uk; withdrawal does not affect earlier lawful processing. In limited B2B circumstances, applicable law may permit us to send communications to corporate subscribers or existing business contacts on the basis of legitimate interests, in which case we provide a clear opt-out and consider the nature of the recipient, the relationship, reasonable expectations and potential impact. We do not sell personal information or provide mailing lists to third parties for their independent marketing.
4.4 Transactional and service communications. We may send non-marketing messages where necessary to deliver a report or resource, confirm an enquiry or registration, provide information about a meeting or service, notify you of material operational, security or legal matters, respond to a request or administer an existing relationship. These are not treated as marketing merely because they use email, and unsubscribing from marketing will not prevent messages reasonably necessary to provide a requested service or administer a contract. Bases: performance of a contract; pre-contract steps; legal obligations; and our legitimate interests in administering requested services and relationships.
4.5 Website operation, analytics and improvement. No analytics product is currently installed on the BPRG website. Where we operate and maintain the website, understand how content and features are used, measure performance, diagnose technical problems, improve navigation, accessibility and user experience, test new features and produce aggregated statistics. Where the processing involves non-essential cookies or similar technologies, we rely on consent unless a statutory exception applies; for associated personal-information processing, our bases are consent (where appropriate) and our legitimate interests in understanding and improving our website and services. Where possible, we configure analytics to minimise the personal information collected and reduce retention.
4.6 Security, fraud prevention and misuse. To protect the website, accounts and systems, detect and prevent fraud, malicious activity and abuse, enforce rate limits, identify automated or unauthorised access, investigate incidents and preserve evidence. Bases: our legitimate interests in protecting our business, users, systems and information; legal obligations; and establishing, exercising or defending legal claims.
4.7 Legal, regulatory and corporate purposes. To comply with applicable laws, court orders and regulatory requirements, respond to lawful requests from authorities, maintain corporate, tax and accounting records, obtain professional advice, manage disputes and complaints, protect our legal rights and support a corporate transaction, restructuring, financing, sale or acquisition. Bases: legal obligations; our legitimate interests in managing and protecting our business; and establishing, exercising or defending legal claims.
5. Our legitimate interests
Where we rely on legitimate interests, those interests may include responding to business enquiries, providing requested professional content and assessments, developing and maintaining business relationships, improving our website, resources and services, measuring the effectiveness of our communications, ensuring network and information security, preventing fraud and misuse, maintaining appropriate business records, protecting our intellectual property and legal rights, and operating and developing our consultancy. Before relying on legitimate interests, we consider whether the processing is necessary and whether our interests are overridden by your rights, freedoms and reasonable expectations. You may object to processing based on legitimate interests (see section 12).
6. Automated processing and artificial intelligence
Our assessment tools may automatically calculate a score, maturity level or standardised commentary based on the answers submitted, and we may use software or AI-assisted tools to support activities such as structuring results, producing preliminary summaries, improving drafting, classifying enquiries and detecting technical errors or abuse. Unless we tell you otherwise, we do not use solely automated processing to make decisions about you that produce legal or similarly significant effects. Assessment outputs are indicative and should not be treated as a professional audit, regulatory determination, employment or credit decision or other significant decision about an individual. Where AI tools are used, we seek to apply appropriate controls concerning access, confidentiality, verification and human oversight, and you should not submit personal, confidential or regulated information that is unnecessary for the relevant purpose.
7. When we share personal information
We may share personal information with the following categories of recipient where reasonably necessary.
7.1 Website and technology providers — including providers of website hosting and content delivery, cloud databases and storage, website development and maintenance, email delivery, analytics, security, monitoring and error reporting, CRM, scheduling and video conferencing, document generation, workflow automation and IT support. Providers currently used for relevant website functions are Supabase (database and storage, hosted in the EU) and Vercel (hosting, deployment and content delivery). We do not currently use a third-party analytics or email-delivery provider on this website. The specific providers and configurations may change as our systems develop. We require service providers to process personal information only for authorised purposes and subject to appropriate contractual and security obligations.
7.2 Professional advisers and insurers — lawyers, accountants, auditors, tax advisers, insurers and other professional advisers where reasonably necessary.
7.3 Business partners, consultants and subcontractors — where relevant to an enquiry or engagement, authorised personnel, consultants, subject-matter experts or subcontractors who support us. We will not disclose confidential operational details to an external expert merely because you have completed a public website assessment; additional disclosure will be subject to an appropriate business purpose and, where required, confidentiality arrangements or your instructions.
7.4 Authorities and legal recipients — where required by law, in response to a binding court order or lawful regulatory request, to report or investigate suspected unlawful conduct, to protect rights, property or safety, or to establish, exercise or defend legal claims.
7.5 Corporate transactions — prospective purchasers, investors, lenders, professional advisers or counterparties in connection with a proposed merger, acquisition, financing, restructuring or sale of all or part of our business. Any recipient will be required to use the information only for the relevant transaction and subject to appropriate confidentiality restrictions.
8. International transfers
Our current service providers process personal information within the United Kingdom and the European Economic Area, which benefits from UK "adequacy" (so no additional transfer safeguard is required for those transfers). Where we later transfer personal information to a country not covered by UK adequacy regulations, we will use an appropriate transfer mechanism where required — such as the UK International Data Transfer Agreement, the UK Addendum to the European Commission's Standard Contractual Clauses, binding corporate rules, an applicable statutory exception or another lawful safeguard recognised under UK data-protection law — and consider whether supplementary protections are required. Information may be delivered through or cached within global content-delivery networks; we configure our services to minimise unnecessary international processing where reasonably practicable but do not promise that every technical operation will occur solely within the UK or EEA. Contact us for further information about the safeguards relevant to a particular transfer.
9. Data security
We use reasonable and proportionate technical and organisational measures designed to protect personal information from unauthorised access, accidental or unlawful destruction, loss, alteration, disclosure and other unlawful processing. These may include encrypted transmission using HTTPS, access controls and role-based permissions, multi-factor authentication where supported and appropriate, secure hosting and database services, monitoring and logging, backups and recovery, supplier due diligence, confidentiality obligations, data-minimisation controls and incident-management procedures. No website, transmission or storage system can be guaranteed to be completely secure; you are responsible for taking reasonable care in deciding what to send through the website and for keeping any credentials confidential. If we become aware of a personal-data breach, we will investigate it and make any notifications required by law.
10. Data retention
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, security and reporting requirements. Our normal periods are:
- Enquiries and prospective client records — normally up to 24 months after the last meaningful interaction, unless discussions remain active, a longer period is reasonably necessary given the opportunity, you ask us to retain the information, it becomes part of a client relationship, or a legal or regulatory reason requires a different period.
- Assessment records — identifiable assessment responses and reports normally up to 24 months after completion or the last related interaction; aggregated or anonymised statistics may be kept longer where individuals cannot reasonably be identified. Where an assessment leads to an engagement, relevant records may be retained with the client file.
- Client and contractual records — retained for the duration of the relationship and afterwards for a period consistent with contractual, tax, insurance and legal limitation requirements, commonly up to seven years after the end of the relevant engagement, though a different period may apply where reasonably necessary.
- Newsletter and marketing records — active subscription information until you unsubscribe or we determine it is no longer required. After an unsubscribe request, we may retain limited information on a suppression list to respect the request and avoid further marketing; a suppression record is not used to continue marketing.
- Technical and security records — routine server, security and diagnostic logs normally up to 12 months, though some may be kept for a shorter period and records connected with a security incident, dispute or suspected misuse may be retained longer.
- Analytics information — retained in accordance with our configured analytics settings and normally deleted or aggregated within 12 months, unless a shorter period is technically available and appropriate.
- Legal claims and compliance records — information relevant to an actual or reasonably anticipated dispute, complaint, investigation or legal obligation may be retained until the matter and any applicable limitation or appeal period have ended.
At the end of the applicable period, information will be deleted, anonymised or securely archived with access restricted where immediate deletion is not reasonably practicable.
11. Marketing choices
You may stop receiving marketing communications at any time by selecting the unsubscribe link, changing any available communication preferences or emailing benjamin@bprg.uk, and we will action valid opt-out requests as soon as reasonably practicable. An opt-out does not require us to delete all information about you; we may retain a minimal suppression record and continue sending communications necessary to administer a request, contract, event or existing professional relationship. You may also object to the use of your personal information for direct marketing at any time, and where you do so we will stop using it for that purpose.
12. Your data-protection rights
Depending on the circumstances and subject to applicable conditions and exemptions, you may have the right to: access your personal information and receive a copy with certain supplementary information; rectification of inaccurate or incomplete information; erasure in certain circumstances (this right is not absolute; we may retain information where processing remains necessary for legal compliance, legal claims, freedom of expression or another lawful reason); restriction of processing in certain circumstances, including while accuracy or an objection is being considered; objection to processing based on legitimate interests (with an absolute right to object to direct marketing; other objections require us to assess whether we have compelling legitimate grounds to continue); data portability, where the legal conditions apply; withdrawal of consent at any time where processing is based on consent (without affecting earlier lawful processing); safeguards concerning solely automated decisions that produce significant effects, including human intervention where the legal conditions apply; and to complain to us and to the Information Commissioner's Office.
13. How to exercise your rights or make a complaint
To exercise a right or raise a data-protection complaint, email benjamin@bprg.uk or write to FRGN LTD trading as BPRG, Unit 1, Willow Park, Upton Lane, Stoke Golding, Nuneaton, Warwickshire, England, CV13 6EU, providing enough information for us to understand and investigate the request. We may ask for proportionate evidence of identity where necessary to protect personal information from unauthorised disclosure. We will normally respond to a valid rights request within one month; where the request is complex or multiple requests have been made, the period may be extended where permitted by law, and we will explain any extension. For a data-protection complaint, we will provide an accessible means of submitting it, and will acknowledge, investigate and respond to it without undue delay, explaining the outcome and any action taken. You may complain to the Information Commissioner's Office whether or not you have first complained to us, though the ICO may recommend that you give us an opportunity to address the issue first. Information about the ICO is available at ico.org.uk.
14. Children
Our website and services are intended for business and professional users and are not directed at children. We do not knowingly seek to collect personal information from anyone under 18 through the website. If you believe a child has provided personal information to us, contact benjamin@bprg.uk so that we can review and, where appropriate, delete it.
15. Third-party websites and services
Our website may contain links to, or embedded content from, third-party websites and services. Those organisations may collect personal information independently and will have their own privacy notices; we do not control and are not responsible for their processing merely because the website contains a link or integration. You should review the privacy information provided by the relevant third party before submitting personal information to it.
16. Changes to this Privacy Policy
We may update this policy where our processing changes or to reflect legal, regulatory, technical or operational developments. The date at the top identifies the latest version. Where a change materially affects how we use personal information, we will take reasonable steps to provide additional notice where required by law.
17. Contact details
For questions, requests or complaints concerning this policy or our use of personal information, contact FRGN LTD trading as BPRG, Unit 1, Willow Park, Upton Lane, Stoke Golding, Nuneaton, Warwickshire, England, CV13 6EU; email benjamin@bprg.uk.