Skip to content
Dharma Risk
What we do
Services
Fractional CROTargeted Risk ReviewsAffordability
Building Society Benchmarking‹
Portfolio BenchmarkingRisk Function Benchmarking
AboutContactTalk to us
What we doFractional CROTargeted Risk ReviewsAffordabilityBuilding Society Benchmarking
Portfolio BenchmarkingRisk Function Benchmarking
AboutContact
Privacy

Privacy notice.

How Dharma Risk Ltd uses personal data when you visit our website, contact us, arrange a meeting or work with us.

Last updated: 7 September 2026

Data controller

Dharma Risk Ltd
Company no. 16937051
Registered in Wales

26 Plymouth Road
Penarth
CF64 3DH

hello@dharmarisk.com

1. What this notice covers

Dharma Risk Ltd ("Dharma Risk", "we", "us") is the controller of personal data described in this notice. This notice explains what information we collect, why we use it, who we may share it with, how long we keep it and the rights available to you under UK data protection law.

Where we process personal data solely on a client's documented instructions as a data processor, the client remains the controller and its privacy information applies to that processing.

2. Personal data we collect

Depending on how you interact with us, we may collect:

  • Contact and professional information, such as your name, work email address, organisation, job title and business contact details.
  • Enquiry and meeting information, including messages, meeting dates, correspondence and information you choose to provide when you email us or use Microsoft Bookings.
  • Client and engagement information, such as project correspondence, contractual records, invoices and information needed to deliver consultancy services.
  • Technical information generated when the website is delivered, such as IP address, browser/device information and server or security logs processed by our hosting provider.
  • Business contact information from other sources, for example where someone introduces us or where professional contact details are publicly available.

3. How and why we use personal data

PurposeTypical lawful basis
Responding to enquiries, arranging meetings and discussing possible workOur legitimate interests in operating and developing the business; and, where you are personally party to a proposed contract, taking steps at your request before entering into that contract
Delivering consultancy services and managing client relationshipsWhere you are personally party to the contract, performance of that contract; otherwise our legitimate interests in delivering the engagement and managing professional relationships
Maintaining financial, tax and business recordsCompliance with legal obligations and our legitimate interests in proper business administration
Operating, protecting and troubleshooting the website and business systemsOur legitimate interests in providing secure and reliable services
Keeping in touch with relevant professional contacts about Dharma Risk's servicesOur legitimate interests in business development, subject to applicable direct-marketing rules and your right to object

Where we rely on legitimate interests, we consider whether those interests are proportionate and whether your rights and interests override them.

4. Who we share information with

We do not sell personal data. We may share information where necessary with service providers that support our business, including:

  • Microsoft 365 and Microsoft Bookings for email, calendar and meeting administration;
  • Hostinger and related hosting/infrastructure providers for website delivery and security;
  • professional advisers, accountants, insurers or other suppliers where required for the operation of the business; and
  • regulators, courts, law-enforcement bodies or other authorities where disclosure is required by law or is necessary to establish, exercise or defend legal rights.

Where a service provider processes personal data for us, we expect it to do so under appropriate contractual and security arrangements.

5. International transfers

Some technology providers may process information outside the United Kingdom. Where UK data protection law requires safeguards for an international transfer, we rely on an applicable adequacy decision or appropriate contractual safeguards and supplementary measures as required.

6. How long we keep information

We keep personal data only for as long as it is reasonably needed for the purpose for which it was collected, taking account of legal, tax, insurance and professional record-keeping requirements.

  • Enquiries that do not lead to an engagement are generally retained for up to 24 months after the last meaningful contact.
  • Client, contractual and project records are generally retained for up to six years after the engagement or relationship ends, unless a longer or shorter period is required for a particular record.
  • Financial and accounting records are retained for the period required by applicable law.
  • Technical and security logs are retained according to operational and hosting-provider requirements and are deleted or overwritten when no longer needed.

7. Cookies and analytics

Dharma Risk does not currently deploy analytics, advertising pixels or non-essential cookies in the main website code. If you follow a link to an external service such as Microsoft Bookings or LinkedIn, that service may process information and use cookies under its own privacy and cookie terms.

8. Your rights

Depending on the circumstances, you may have rights to request access to your personal data, correct inaccurate data, ask for deletion or restriction, object to certain processing, and receive certain information in a portable format. You can object at any time to processing for direct marketing. Where processing is based on consent, you may withdraw that consent at any time.

To exercise a right or raise a privacy question, email hello@dharmarisk.com. We may need to verify your identity before acting on a request.

9. Data protection complaints

If you believe we have not handled your personal data properly, you can make a data protection complaint directly to us. Email hello@dharmarisk.com with the subject Data protection complaint and briefly explain your concern, the information involved and what you would like us to do.

We will acknowledge a data protection complaint within 30 days of receiving it. We will take appropriate steps to investigate it without undue delay, keep you informed as appropriate and tell you the outcome.

You also have the right to complain to the UK Information Commissioner's Office (ICO). You do not have to wait for our process if you wish to contact the ICO.

Visit the ICO complaints service →

10. Automated decision-making and changes to this notice

We do not use personal data collected through this website for solely automated decision-making or profiling that produces legal or similarly significant effects.

We may update this notice if our services, suppliers or legal obligations change. The current version will always be published on this page with its latest update date.

Dharma Risk
Principled. Proportionate. Pragmatic.
© 2026 Dharma Risk Ltd · Registered in Wales, company no. 16937051 · Registered office: 26 Plymouth Road, Penarth, CF64 3DH
Fractional CRO Targeted Risk Reviews Benchmarking Affordability About Contact Privacy