Privacy Policy
Effective date: 1 April 2026
Last updated: 9 September 2026
1. Who we are
Better Future Group, referred to in this policy as “BFG”, is the trading and group identity of Better Future Group Ltd. BFG is a UK-rooted multidisciplinary enterprise supporting organisations across strategy, transformation, technology, delivery, governance, research, sustainability, energy, health, communication, international growth and other specialist requirements. This website presents BFG’s business lines, capability families, professional practices, market routes, insights and enquiry pathways.
Better Future Group Ltd is responsible for this website and decides how personal data obtained through it is processed. For data protection purposes, Better Future Group Ltd is the website controller.
- Legal entity: Better Future Group Ltd
- Trading or group identity: Better Future Group
- Company number: 11529349
- Registered office: 25 Honeycomb Way, Birmingham, England, B31 1RA
- Privacy contact: info@betterfutureg.com
- Data protection responsibility: BFG has designated a responsible person to handle data protection matters through info@betterfutureg.com. BFG will appoint a formal data protection officer if and when required by law.
ICO data protection fee: At the date of this policy, BFG is not currently registered with the Information Commissioner’s Office (ICO), and no public website personal data collection has started. BFG will assess its obligation to pay the ICO data protection fee and will complete any registration required by applicable law before the public website begins processing personal data. Where BFG is exempt, it will retain evidence of that exemption and review its position periodically. BFG will add its ICO registration reference to this policy once issued.
2. Scope of this policy
This policy explains how BFG collects, uses, stores, shares and protects personal data obtained through this website. It covers information submitted through enquiry, consultation or review routes, information exchanged by email, information generated through website use, and professional contact information received from lawful sources.
It applies to visitors, prospective clients, client representatives, suppliers, professional contacts, reviewers and other individuals who interact with the website. It should be read with the Cookie Policy and Website Terms.
Where a specific BFG business line, group company, delivery partner or client engagement has its own privacy notice or contractual arrangement, that notice or arrangement may provide additional information. This policy does not replace a specific notice that applies to a separate processing activity.
3. The legal framework
BFG processes personal data in accordance with applicable UK data protection and privacy law, including the UK General Data Protection Regulation, the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003, as amended, the Data (Use and Access) Act 2025 where applicable, and other legislation and regulatory guidance in force at the relevant time.
BFG applies the data protection principles of lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability. This policy describes BFG’s intended website practices. The precise processing arrangement may depend on the service requested, the relevant engagement, the supplier configuration and the law that applies to the circumstances.
4. Personal data we may collect
Depending on how you interact with BFG, we may collect:
- identity and contact details, such as your name, role, organisation, email address and telephone number;
- enquiry information, including the capability, market, requirement, challenge summary, timing, constraints and correspondence you provide;
- consultation and relationship information, including meeting records, requests, preferences and follow up communications;
- professional and organisational information relevant to a business enquiry or potential engagement;
- review or testimonial information, where you submit a review or give permission for publication;
- technical information, such as IP address, browser and device information, operating system, referring page, pages viewed, approximate location derived from technical information, timestamps and security events;
- consent, cookie and preference information;
- information needed to manage complaints, legal claims, fraud prevention, security incidents and regulatory obligations; and
- information you choose to provide through correspondence, attachments or other communications.
5. Special category and confidential information
BFG does not intentionally request special category data through general website forms. Special category data includes information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used to uniquely identify a person, health data, or information concerning a person’s sex life or sexual orientation.
Please do not send confidential, sensitive, regulated or special category information through a general website form unless BFG has expressly requested it through a secure and appropriate channel.
If special category data is submitted accidentally, BFG will restrict access to the information, avoid using it for unrelated purposes, record the incident where appropriate, and securely delete or return the information as soon as practicable. BFG will target deletion within seven days after triage. If continued processing is necessary for safeguarding, legal, regulatory, insurance, dispute or other legitimate purposes, BFG will first identify an applicable condition under Article 9 of the UK GDPR, establish an appropriate lawful basis, apply additional safeguards and retain only what is necessary.
If you have sent special category data accidentally, please contact info@betterfutureg.com promptly and identify the relevant communication if possible. Do not resend the sensitive information.
6. How we collect information
BFG may collect information directly from you through forms, email, telephone or other correspondence. It may collect technical information automatically through the website. It may also receive professional contact information from your organisation, service providers, public registers, professional networks or other lawful sources.
Where BFG receives personal data from a source other than you, it will provide the information required by applicable law unless a lawful exception applies. BFG will not knowingly obtain personal data through unlawful or unfair means.
7. Why we use personal data and our lawful bases
The following table sets out the principal purposes for which BFG may process personal data and the typical lawful basis. The applicable basis depends on the circumstances.
| Purpose | Typical lawful basis |
|---|---|
| Responding to an enquiry, consultation request or request for information | Legitimate interests in managing business enquiries and, where relevant, taking steps at your request before entering into a contract |
| Assessing a potential engagement and preparing an appropriate BFG response | Legitimate interests and pre contractual steps, where applicable |
| Delivering services under an agreed engagement | Performance of a contract, legitimate interests and compliance with legal obligations, as applicable |
| Managing client, supplier and professional relationships | Performance of a contract, legitimate interests and legal obligations, as applicable |
| Operating, securing, maintaining and improving the website | Legitimate interests and legal obligations, with consent where consent is required for storage or access technologies |
| Using optional analytics or similar measurement technologies | Consent where required by law |
| Sending email or text marketing to individuals, sole traders and partnerships | Prior consent, or the soft opt in where all applicable legal conditions are met, together with an applicable UK GDPR lawful basis |
| Sending business to business email or text marketing to corporate subscribers | Legitimate interests may be used where the Privacy and Electronic Communications Regulations permit marketing without prior consent. BFG will identify itself, provide a simple opt out and respect objections |
| Reviewing and publishing client stories or testimonials | Permission or consent for publication, together with legitimate interests in maintaining an evidence led website |
| Preventing misuse, fraud and security incidents, and establishing or defending legal claims | Legitimate interests and legal obligations |
Where BFG relies on legitimate interests, it considers the purpose, necessity, impact on individuals and reasonable expectations, and applies safeguards where appropriate. BFG does not use consent as a substitute for another lawful basis where processing is necessary to provide a service.
8. Cookies and similar technologies
BFG uses cookies, local storage and similar technologies to operate, secure and improve the website, remember preferences, manage consent and, where enabled, understand how visitors use the website.
Strictly necessary technologies may be used where they are required to provide a service you request, operate the website, maintain security or remember your privacy choices. Optional analytics, advertising and other non essential technologies will be used only where the required consent has been obtained. BFG will not deliberately activate optional technologies in a way that bypasses applicable consent requirements.
The Cookie Policy explains the categories of technology used, their purposes, retention periods and how to change your preferences. BFG will update the Cookie Policy and consent configuration when it introduces or removes a material technology.
9. Direct marketing
BFG will send direct marketing only when the relevant legal, consent, preference and suppression controls are in place.
For individuals, sole traders and partnerships, BFG will send marketing by email or text only with prior consent or under the soft opt in where all applicable conditions are met. A work email address or work mobile number may still be personal data, and the UK GDPR continues to apply where an individual can be identified.
For corporate subscribers, including contacts at companies and other corporate bodies, BFG may send business to business email or text marketing without prior consent where permitted by the Privacy and Electronic Communications Regulations. BFG will identify itself, explain why the recipient is being contacted and provide a clear way to object. BFG will not treat a sole trader or partnership as a corporate subscriber merely because the address is used for business.
Every marketing message will identify BFG and provide a clear, free and simple unsubscribe or opt out method appropriate to the channel. BFG will action unsubscribe requests promptly and maintain a suppression record containing only the minimum information needed to ensure that the objection is respected. You may also object by contacting info@betterfutureg.com.
10. Sharing personal data
BFG may share personal data where necessary, proportionate and lawful with:
- relevant BFG personnel, business lines, group companies or delivery partners who need the information for the stated purpose;
- hosting, website, form, email, security, backup, consent management, analytics and other technology providers acting on BFG’s documented instructions where they are processors;
- professional advisers, insurers, auditors and other service providers subject to appropriate confidentiality and data protection arrangements;
- public authorities, courts, regulators, law enforcement bodies or other recipients where required or permitted by law; and
- a successor, purchaser or adviser in connection with a corporate transaction, subject to appropriate safeguards.
BFG currently uses Hostinger for website hosting and Hostinger email services. Website enquiry submissions are collected through Contact Form 7 and, where enabled, stored in the WordPress installation through Flamingo. Complianz manages the website’s consent preferences. For staging continuity, BFG stores staging backups in Amazon S3, Europe (London), region eu-west-2, in a restricted bucket with a rolling maximum retention of 90 days. This staging backup arrangement is separate from the live website and is not used for live personal-data processing unless the production arrangement is approved and recorded.
BFG will not treat optional marketing, analytics, advertising or external backup services as active processing arrangements until they have been approved, configured and recorded. BFG does not sell personal data and does not disclose enquiry information to third parties for their own unrelated marketing purposes.
11. International transfers
Personal data may be accessed or processed outside the United Kingdom where this is necessary for a service used by BFG or for another lawful purpose. BFG will assess the relevant transfer before it takes place.
For a restricted transfer, BFG will use an applicable lawful mechanism, such as an adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to standard contractual clauses, or another permitted safeguard. BFG will assess supplementary measures where required and will make information about relevant safeguards available through the privacy contact where the law requires or permits this.
12. Retention
BFG keeps personal data only for as long as necessary for the purpose for which it was collected, to manage an ongoing relationship, to comply with legal, regulatory, accounting or reporting duties, or to establish, exercise or defend legal claims. BFG applies the following starting retention schedule to website and related enquiry records.
| Data category | Starting retention period | Trigger and action |
|---|---|---|
| Unconverted website enquiries | 12 months | From closure or last meaningful contact, then securely delete from website, email, CRM and exports. |
| Quotes, proposals and unsuccessful opportunities | 24 months | From the decision or opportunity closure, then securely delete unless a complaint, dispute, legal claim or legal hold applies. |
| Active client engagement records | Engagement period plus 6 years | From the end of the engagement, retain only records necessary for delivery, insurance, accounting, regulatory or legal purposes. |
| Accounting, invoices and payment records | 6 years from the end of the relevant financial year, or longer where required | Retain in the appropriate accounting system where needed for tax, accounting or other legal obligations. |
| Active marketing contacts | Review every 12 months; remove after 12 months of inactivity unless a documented reason justifies retention | Remove from active marketing lists when no longer necessary and respect all consent withdrawals and objections. |
| Marketing suppression records | As long as necessary to honour the objection | Retain only the minimum identifier needed to prevent future marketing. Do not use the record for marketing. |
| Consent and marketing permission records | While relied upon, plus 3 years after withdrawal or last use | Retain evidence of what was agreed, when, how and for which purpose. |
| Cookie consent and preference records | 12 months from the last recorded choice, or the period configured in the consent platform | Refresh consent when required and delete expired records when no longer needed. |
| Routine security and access logs | 90 days | Extend only where necessary for an incident, investigation, complaint or legal claim, normally for no more than 12 months after closure. |
| Data protection requests and complaints | 6 years after closure | Retain the case record needed to demonstrate compliance, while deleting unnecessary underlying personal data under its ordinary schedule. |
| Testimonials and publication permissions | While published, plus 3 years after removal or withdrawal | Retain evidence of permission and editorial approval, subject to any longer contractual or legal requirement. |
| Accidentally submitted special category data | As soon as practicable after triage, with a target of 7 days | Restrict access and securely delete or return the information unless continued retention is necessary for safeguarding, legal or dispute purposes. |
| Backups containing personal data | Rolling maximum of 90 days | Delete from live systems at the relevant trigger and allow backup copies to expire through the approved rotation. |
These are starting periods, not automatic permissions to retain personal data. A longer period may apply where necessary for a statutory, accounting, contractual, insurance, regulatory, complaint, dispute or legal claim requirement. BFG will document the reason, restrict access and apply a legal hold where appropriate.
BFG reviews this schedule at least annually and whenever it introduces a new system, processor, processing purpose or material change. At the end of the applicable period, BFG securely deletes the information, anonymises it effectively or restricts it from further use where deletion is not immediately practicable.
13. Your rights
Subject to legal conditions and exemptions, you may have the right to:
- request access to your personal data;
- request correction of inaccurate or incomplete data;
- request erasure of data;
- request restriction of processing;
- object to processing based on legitimate interests;
- object at any time to direct marketing;
- request data portability where the right applies; and
- withdraw consent where processing relies on consent.
To exercise a right, contact info@betterfutureg.com. BFG may request information reasonably necessary to verify identity and protect personal data. BFG will normally respond within one calendar month, subject to lawful extensions or other applicable rules.
You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority, through the ICO’s complaint service. BFG would welcome the opportunity to address your concern first.
14. Security and data incidents
BFG applies proportionate technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, loss and destruction. Measures may include access controls, authentication, encryption where appropriate, secure configuration, updates, backups, monitoring, staff awareness and incident management procedures.
BFG will assess suspected personal data incidents, take steps to contain and remediate them, keep appropriate records and notify individuals or the Information Commissioner’s Office where required by law. No internet transmission or storage system can be guaranteed to be completely secure.
15. Children
This website is directed primarily to organisations and professional audiences. BFG does not knowingly seek personal data from children through its general enquiry routes. If a child’s information has been provided without appropriate authority, contact BFG so that it can assess and address the matter.
16. Automated decision making and AI
BFG does not intend to make decisions through this website that produce legal or similarly significant effects on individuals solely by automated means. Any use of artificial intelligence, analytics or other automated tools in BFG’s operations remains subject to appropriate governance, human oversight, security, data protection assessment and contractual controls.
17. Third party websites
This website may contain links to third party websites or services. BFG does not control their content, security or privacy practices. Review the relevant third party’s terms and privacy information before providing personal data.
18. Changes to this policy
BFG may update this policy to reflect changes in law, guidance, services, technology or processing arrangements. The latest version will be published on this page with its updated date. Where a change is materially relevant, BFG will provide additional information where required.
19. Contact
For privacy questions, data subject requests or complaints, contact info@betterfutureg.com.
Corporate details: Better Future Group Ltd, company number 11529349, registered office 25 Honeycomb Way, Birmingham, England, B31 1RA.
