top of page

Eliza Kozman Consulting customer privacy notice

This privacy notice tells you what to expect us to do with your personal information.

  • Contact details

  • What information we collect, use, and why

  • Lawful bases and data protection rights

  • Where we get personal information from

  • How long we keep information

  • Who we share information with

  • Sharing information outside the UK

  • How to complain

Contact details

Post:19 Manor Gardens, Godalming, Surrey, GU7 3LL

Email: eliza@elizakozman.com

What information we collect, use, and why

We collect or use the following information to provide and improve products and services for clients:

  • Names and contact details

  • Occupation and employer

  • Transaction data (including details about payments to and from you and details of products and services you have purchased)

  • Information relating to compliments or complaints

  • Records of meetings and decisions

  • Purchase or service history

We collect or use the following personal information for information updates or marketing purposes:

  • Names and contact details

  • Profile information

  • Marketing preferences

  • Purchase or account history

We collect or use the following personal information for research or archiving purposes:

  • Names and contact details

  • Opinions, views or feedback, collected via meetings, workshops interviews or other data gathering exercises

 

We may change this privacy notice from time to time. If we make any significant changes in the way we treat your personal information we will make this clear in this privacy notice or by contacting you directly.

 

Lawful bases and data protection rights

Under UK data protection law, we must have a “lawful basis” for collecting and using your personal information. There is a list of possible lawful bases in the UK GDPR. You can find out more about lawful bases on the ICO’s website.

Which lawful basis we rely on may affect your data protection rights which are set out in brief below. You can find out more about your data protection rights and the exemptions which may apply on the ICO’s website:

If you make a request, we must respond to you without undue delay and in any event within one month.

To make a data protection rights request, please contact us using the contact details at the top of this privacy notice.

Our lawful bases for the collection and use of your data

Our lawful bases for collecting or using personal information to provide and improve products and services for clients are:

  • Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.

  • Legitimate interests – we’re collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are to manage client relationships, deliver services effectively, and maintain business records. For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.

Our lawful bases for collecting or using personal information for information updates or marketing purposes are:

  • Consent - we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.

Our lawful bases for collecting or using personal information for research or archiving purposes:

  • Consent - we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.

Where we get personal information from

  • Directly from you

  • Publicly available sources

How long we keep information

Data is only kept as long as it is needed to fulfil the purpose for which it was collected (typically for 1 year after the end of a contract).

Where we are processing data to provide and improve products and services for clients, data will be retained for as long as it is needed to fulfil the contractual obligation. If data is no longer relevant, a person has changed role, or has requested to be forgotten, we will update or delete the personal information as required (unless there is a legal reason to retain it). All data is reviewed on at least an annual basis.

Personal data may be moved into the list used for information updates or marketing purposes and therefore retained beyond the contract period. This approach is in-line with our legitimate interests to process data for this purpose. Our legitimate interests are to manage client relationships, deliver services effectively, and maintain business records. More typically, people will be added to this list when they consent to be contacted for this pupose, and we will retain the information until this consent is withdrawn. All individuals have the ability to opt-out of such further communications at any time. If data is no longer relevant, a person has changed role, or has requested to be forgotten, we will update or delete the personal information as required (unless there is a legal reason to retain it). All data is reviewed on at least an annual basis.

Where we process data for research or archiving purposes, the length of time we plan to keep information will be outlined on a privacy notice for each individual project. Wherever possible, personal data will be anonymised or pseudonymised. When data is no longer needed it will be securely destroyed, as specified in the privacy notice for the project (unless there is a legal reason for retention).

For more information on how long we store your personal information or the criteria we use to determine this please contact us using the details provided above.

Who we share information with

We use Google Workspace & Google Cloud Platform for the secure processing of personal information. Security and compliance information can be found in the Google Compliance Resource CentrePrivacy Resource Centre and the Google Cloud & the GDPR pages.

We may also sometimes share data with other third parties where this is necessary to perform the activities outlined in this privacy notice. Third parties will be subject to review to ensure that their processing activities are aligned with the level of security we expect from ourselves.

We may share data with:

  • Cloud services

  • Banking services

  • Organisations we’re legally obliged to share personal information with

Sharing information outside the UK

Where necessary, we may transfer personal information outside of the UK. When doing so, we comply with the UK GDPR, making sure appropriate safeguards are in place.

For further information or to obtain a copy of the appropriate safeguard for any of the transfers below, please contact us using the contact information provided above.

Organisation name: Google LLC

Category of recipient: Cloud-based productivity and collaboration suite

Country the personal information is sent to: Global storage centres (not limited to UK/EU) -as we use Google Workspace Business Starter, we do not control the specific geographic location where data is stored.

How the transfer complies with UK data protection law: Google has confirmation of compliance from European Data Protection Authorities for their standard contract clauses, affirming that the contractual commitments for Google Workspace and Google Cloud meet the requirements to legally frame transfers of personal data from the EU to the third countries that do not provide adequate protection. This is achieved via Standard Contractual Clauses (SCCs) and a UK Addendum to SCCs. Google also implements additional technical and organisational security measures, including encryption and access controls. For more information Safeguards for International Data Transfers with Google Workspace and Workspace for Education

 

Organisation name: Starling Bank

Category of recipient: Banking services

Country the personal information is sent to: UK and European Economic Area (EEA)

How the transfer complies with UK data protection law: UK adequacy regulations apply

 

How to complain

If you have any concerns about our use of your personal data, you can make a complaint to us using the contact details at the top of this privacy notice.

If you remain unhappy with how we’ve used your data after raising a complaint with us, you can also complain to the ICO.

The ICO’s address:           

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Helpline number: 0303 123 1113

Website: https://www.ico.org.uk/make-a-complaint

Last updated:

This privacy notice was last updated in April 2026.

bottom of page