Privacy policy · Last reviewed 11 August 2026

How we use personal information

Design Review Ltd is the controller for personal information collected through enquiries and delivery of the Design Review Governance service.

Who we are

Design Review Ltd is registered in England and Wales under company number 06512522. Our registered office is 5 Barnfield Crescent, Exeter, Devon, United Kingdom, EX1 1QT. Privacy questions and rights requests can be sent to governance@designreviewpanel.co.uk. You may also call 01395 265768.

Information we collect

We may collect your name, role, organisation, contact details, correspondence, enquiry and appointment information, invoice and billing details, purchase-order references, meeting records, and personal information contained in evidence supplied for a review, and information entered into a Governance Health Check workspace. The booking form records the selected package, authority and terms confirmations, preferred timing and information needed for conflicts checks. The callback form records your service interest, preferred contact method and timing. A Health Check records the arrangement profile, evidence-register metadata, safeguard answers, assessment commentary, action owners and target dates. It does not accept evidence document uploads. Users should avoid entering unnecessary personal, confidential, legally privileged or special-category information.

Why we use it

  • To respond to enquiries and take steps towards a contract.
  • To deliver, administer and quality-assure an agreed service.
  • To manage conflicts, security, billing and business records.
  • To meet legal, regulatory and professional obligations.
  • To make limited, relevant business contact where our legitimate interests support it and your rights do not override them.

Our usual lawful bases are contract or steps requested before a contract, legitimate interests in running and protecting the service, and legal obligation. We will identify another lawful basis where the circumstances require it.

Sharing and international processing

We do not sell personal information. We share it only where needed with authorised reviewers, business-system and hosting providers, professional advisers, or public authorities where law requires it. Where a provider processes information outside the UK, we use arrangements intended to provide the safeguards required by UK data protection law.

Website data and cookies

The short public self-check on the main website works only in your browser and is not submitted to us. The paid Governance Health Check is different: its progress and entered assessment data are saved to the private workspace so authorised users can return to it. We do not currently use marketing cookies or website analytics. Our hosting and security providers may process technical request information, such as IP address, browser details and timestamps, to deliver and protect the website.

Private workspace access

Each Health Check workspace uses a long, non-sequential access link. It is excluded from search indexing but works like a password: the purchaser must share it only with authorised colleagues, the external provider and professional advisers permitted by the licence. We use assessment data to provide and secure the service; we do not treat a self-assessment as independent evidence or publish its result.

Retention and security

We keep information only for as long as needed for the relevant purpose and any legal, contractual, insurance or professional record-keeping requirement. Review evidence is handled under the access, transfer and retention arrangements agreed for the assignment. Please do not send sensitive evidence by ordinary email; we will agree a suitable route.

Your rights

Depending on the circumstances, you may have rights to be informed, access, correction, erasure, restriction, portability and objection, and rights concerning automated decisions. You may complain to the Information Commissioner's Office. We would welcome the opportunity to address your concern first.