1. Who we are

NM Risk Consulting Ltd is a UK-based international consultancy providing corporate security, risk management, HSE consulting and related operational and management support to organisations, international projects and private clients. Our work may include advisory services, in-country management and the delivery or coordination of security and HSE services in the UK and internationally.

NM Risk Consulting Ltd is the controller of personal information processed for its own business purposes.

Company No. 17379972. Registered office: Swan Building, 20 Swan Street, Manchester, England, M4 5JW.

Data protection enquiries can be sent to info@nmriskconsulting.com.

This notice applies to website visitors, people who contact us, prospective and existing clients, suppliers, contractors, consultants, professional contacts and other individuals whose personal information we process for our own business purposes. Where NM Risk Consulting processes personal information on behalf of a client during an assignment, the relevant contract, client instructions or a separate privacy notice may also apply.

2. Information we collect

Depending on how you deal with us, we may process:

  • Identity and professional information, such as your name, job title, organisation, business role and your relationship to a client, supplier, contractor, consultant or project.
  • Contact information, such as your email address, telephone number and business address where you provide them.
  • Enquiry, business relationship and assignment information, including the content of emails, requests for proposals, meeting notes, project or assignment requirements, records of discussions and other business communications.
  • Technical website information that may be recorded by hosting infrastructure, such as IP address, browser or device information, timestamps and requested pages.

We do not ask visitors to submit special category information or criminal offence information through this website. Please do not send such information in an initial enquiry unless it is genuinely necessary and has been agreed with us in advance.

3. How and why we use personal information

We use personal information only where we have a lawful reason to do so. Our principal purposes and lawful bases are:

  • Responding to enquiries and managing business relationships — our legitimate interests in operating our consultancy, communicating with prospective and existing clients, suppliers, contractors, consultants and professional contacts, and considering potential assignments.
  • Taking steps before entering into an agreement and delivering agreed services — where processing is necessary in connection with a contract with you, or steps you ask us to take before entering one.
  • Planning, managing and supporting assignments — our legitimate interests in administering security, risk, HSE, operational and management engagements, coordinating with relevant client personnel and professional contacts, and delivering services effectively.
  • Operating and protecting the website and business systems — our legitimate interests in maintaining security, preventing misuse and administering our systems.
  • Meeting legal and regulatory requirements — where processing is necessary to comply with a legal obligation.
  • Establishing, exercising or defending legal claims — our legitimate interests in protecting the company and its legal position.

Where we rely on legitimate interests, we consider the purpose of the processing, whether it is necessary and the impact on the individual before deciding to use that basis.

4. Website data, cookies and tracking

This is a static corporate website. The website code does not include analytics services, advertising pixels, behavioural tracking tools, embedded social-media widgets or non-essential cookie scripts.

Our web-hosting and network providers may automatically process limited technical logs needed to deliver and secure the website. Those logs can include an IP address, access time, requested URL, browser or device details and diagnostic information. We use or permit this processing for website availability, security, troubleshooting and abuse prevention.

If the website is later changed to add analytics, marketing cookies or similar technologies, this notice and any required cookie controls should be updated before those technologies are enabled.

5. Sharing information and international transfers

We do not sell personal information. We may disclose personal information where reasonably necessary to:

  • hosting, IT, email and other service providers that support our business;
  • professional advisers, insurers, auditors or consultants who require the information for a legitimate professional purpose;
  • clients, project counterparties or approved subcontractors where disclosure is necessary for an enquiry or agreed assignment and is subject to appropriate confidentiality arrangements; or
  • courts, regulators, law-enforcement bodies or other authorities where disclosure is required by law or is necessary to protect legal rights.

NM Risk Consulting operates internationally. This means that some business communications or assignment-related information may need to be accessed from, or shared with recipients in, countries outside the United Kingdom. Where UK data protection law treats a transfer as restricted, we take appropriate steps to use an applicable adequacy arrangement, approved contractual safeguard or other lawful transfer mechanism.

6. How long we keep information

We retain personal information only for as long as it is reasonably needed for the purpose for which it was collected, including responding to an enquiry, maintaining an appropriate business record, managing client, supplier, contractor, consultant or professional relationships, administering assignments, meeting legal or contractual requirements and establishing or defending legal claims.

Retention periods therefore vary according to the type of record and the circumstances. When information is no longer required, we delete it, securely dispose of it or anonymise it where appropriate.

7. Your data protection rights

Depending on the circumstances and the lawful basis being used, you may have rights to request access to your personal information, correction of inaccurate information, erasure, restriction of processing, data portability, and to object to certain processing.

Your right to object: where we rely on legitimate interests, you have the right to object to processing based on your particular situation. We will consider the objection and stop the processing unless there are compelling legitimate grounds to continue or the information is needed for legal claims.

We do not use this website to make solely automated decisions about individuals or to profile visitors for advertising.

To exercise a right, email info@nmriskconsulting.com. We may need to confirm your identity before acting on a request.

8. Questions, complaints and changes to this notice

If you have a question or concern about how we use your information, contact us first at info@nmriskconsulting.com.

You also have the right to complain to the UK supervisory authority, the Information Commissioner's Office (ICO).

We may update this notice when our website, services, suppliers or legal obligations change. The date shown at the top of this notice identifies the current version.

Return to website