Privacy Policy
Last updated: July 2026
Brown Hound Group Limited respects your privacy and is committed to protecting your personal information.
This notice explains how we collect and use personal information when you:
-
visit our website;
-
contact us about our services;
-
work with us as a client, prospective client, supplier or partner;
-
receive relevant business-development communications from us; or
-
take part in research or consultancy activity managed by Brown Hound.
1. Who we are
Brown Hound Group Limited is a healthcare insight and experience consultancy registered in England and Wales.
Registered company number: 15856265
Registered address:
Brown Hound Group Limited, Suite A - 82 James Carter Road, Mildenhall, IP28 7DE, United Kingdom
For the purposes of UK data-protection law, Brown Hound Group Limited may act as either:
-
a data controller, where we decide why and how personal information is used; or
-
a data processor, where we process information on the documented instructions of a client.
Questions about this notice or our use of personal information can be sent to:
Email: hello@wearebrownhound.com
Website: www.wearebrownhound.com
2. The information we collect
The personal information we collect depends on how you interact with us.Website and enquiry information
Website and enquiry information
This may include:
-
your name;
-
job title and organisation;
-
email address and telephone number;
-
information included in an enquiry or contact form;
-
communication preferences;
-
technical information such as IP address, browser type, device information and website usage data.
Client and business-contact information
This may include:
-
professional contact details;
-
employer, job title and business responsibilities;
-
correspondence, meeting notes and project communications;
-
proposal, contract, invoicing and payment information;
-
information required for onboarding, due diligence or procurement;
-
records relating to services we provide or may provide.
Supplier, associate and partner information
This may include:
-
contact and professional information;
-
CV, skills and work-history details;
-
contractual and payment information;
-
bank details and tax information;
-
insurance, compliance or due-diligence documentation.
Research-participant information
Where we conduct or support research, we may collect:
-
contact and recruitment information;
-
demographic or professional information;
-
interview, survey, workshop or usability-testing responses;
-
audio, video or written recordings, where agreed;
-
information about experiences, preferences, needs and behaviours;
-
health information or other sensitive information where necessary for the research.
Health information and certain other sensitive information are classed as special-category personal data and receive additional legal protection.
Where we process this information, we will identify both a lawful basis and an appropriate special-category condition before processing begins. Participants will normally receive additional project-specific privacy information explaining how their data will be used.
Please do not send identifiable patient information or sensitive health information through our general website contact form unless we have specifically asked you to use an agreed secure method.
3. How we obtain personal information
We may collect information:
-
directly from you;
-
from your employer or colleagues;
-
from a client commissioning or supporting a project;
-
from recruitment partners or research-fieldwork suppliers;
-
from publicly available professional sources, such as company websites or LinkedIn;
-
through referrals and professional networks;
-
through our website, email, meetings, surveys, interviews or workshops;
-
from service providers supporting our website, communications or business operations.
Where a client provides participant or stakeholder information to us, responsibilities for that information will be set out in the relevant contract or data-processing agreement.
4. How and why we use personal information
Responding to enquiries and developing business relationships
We may use personal information to:
-
respond to questions;
-
arrange calls or meetings;
-
prepare proposals;
-
understand potential client needs;
-
maintain records of prospective opportunities.
Our lawful basis is usually our legitimate interests in operating and developing our consultancy, or taking steps at your request before entering into a contract.
Delivering and managing client services
We may use personal information to:
-
establish and manage projects;
-
communicate with client teams;
-
conduct research, analysis, workshops and consultancy;
-
prepare and deliver outputs;
-
manage contracts, invoices and payments;
-
maintain project and decision records.
Our lawful basis is usually performance of a contract, taking steps before entering into a contract, or our legitimate interests in delivering
professional services.
Conducting research
We may use personal information to:
-
recruit and communicate with participants;
-
conduct interviews, surveys, workshops or testing;
-
analyse responses;
-
produce aggregated or anonymised findings;
-
improve products, services, communications and experiences.
The lawful basis and, where relevant, special-category condition will depend on the individual project. These will be assessed before the research begins and explained in the participant information for that project.
Working with suppliers, associates and specialist partners
We may use personal information to:
-
commission and manage services;
-
assess expertise and suitability;
-
provide access to information necessary for a project;
-
manage contracts and payments;
-
meet client procurement and compliance requirements.
Our lawful basis is usually contract, legal obligation or our legitimate interests in managing our business and delivering client work.
Managing our business and meeting legal obligations
We may use personal information for:
-
accounting, tax and financial administration;
-
maintaining insurance and legal records;
-
preventing fraud or misuse;
-
protecting our systems, information and legal rights;
-
responding to regulatory or legal requests;
-
handling complaints and resolving disputes.
Our lawful basis may be a legal obligation, performance of a contract or our legitimate interests in protecting and administering the business.
Relevant business-development communications
We may occasionally contact professional contacts about:
-
Brown Hound services;
-
relevant articles, insights or events;
-
updates we reasonably believe may be of professional interest.
We do not currently operate a regular newsletter, although we may introduce one in future.
Where required, we will ask for consent. In other cases, we may rely on our legitimate interests in developing professional relationships and promoting relevant business services.
When sending business-to-business marketing, we will identify ourselves clearly and provide a straightforward way to opt out. Different rules apply depending on whether the recipient is a corporate organisation, sole trader or certain type of partnership.
You can ask us to stop sending marketing communications at any time by emailing hello@wearebrownhound.com.
5. Our lawful bases
Depending on the circumstances, we may rely on:
-
Consent: you have given clear permission for a specific use.
-
Contract: processing is necessary to enter into or perform a contract.
-
Legal obligation: processing is required by law.
-
Legitimate interests: processing is necessary for our legitimate business interests or those of another organisation, provided those interests are not overridden by your rights.
-
Vital interests or public task: only in limited circumstances where the relevant requirements are met.
Where we process special-category information, we also identify an appropriate additional condition under data-protection law.
6. Who we share personal information with
We may share personal information where necessary with:
-
clients commissioning or supporting a project;
-
Brown Hound directors, employees, associates and approved subcontractors;
-
research recruitment, fieldwork, transcription or analysis partners;
-
website, hosting, email, cloud-storage and IT providers;
-
accountants, insurers, lawyers and other professional advisers;
-
payment and banking providers;
-
regulators, courts, government bodies or law-enforcement authorities where legally required;
-
a potential purchaser or successor if the business is reorganised, sold or transferred.
We only provide the information reasonably required for the relevant purpose.
Where suppliers or associates process personal information on our behalf, we require appropriate confidentiality, security and data-protection obligations.
We do not sell personal information.
7. International transfers
Some service providers or project partners may process information outside the United Kingdom.
Where a restricted international transfer occurs, we will use an appropriate legal safeguard, such as:
-
UK adequacy regulations;
-
the UK International Data Transfer Agreement;
-
the UK Addendum to approved contractual clauses; or
-
another legally permitted transfer mechanism.
We will assess transfers and apply additional safeguards where required.
8. How long we keep personal information
We keep personal information only for as long as reasonably required for the purpose for which it was collected, including legal, regulatory, contractual, insurance and accounting requirements.
Indicative retention periods are:
-
Website enquiries and unsuccessful proposals: normally up to two years after the last meaningful contact.
-
Client and project records: normally six years after the end of the relevant contract.
-
Financial and tax records: normally six years after the end of the relevant financial period.
-
Supplier and associate records: normally six years after the relationship ends.
-
Research recruitment and contact information: deleted or anonymised in line with the project-specific retention plan.
-
Research recordings and identifiable responses: retained only for the period explained to participants or agreed with the client.
-
Anonymised research findings: may be retained for longer because they no longer identify an individual.
-
Business-development information: retained until you opt out, object or the information is no longer relevant.
We may retain information for longer where necessary to establish, exercise or defend legal claims or comply with a legal requirement.
9. How we protect personal information
We use proportionate technical and organisational measures designed to protect personal information against loss, misuse, unauthorised access, alteration or disclosure.
These may include:
-
access controls and multifactor authentication;
-
password-management requirements;
-
encrypted devices and secure cloud services;
-
secure transfer methods;
-
confidentiality obligations;
-
supplier and subcontractor checks;
-
data minimisation, anonymisation and pseudonymisation;
-
secure-retention and deletion procedures;
-
incident identification and response processes.
Access is limited to people who require the information for an authorised purpose.
10. Cookies and website analytics
Our website is built using Wix and may use cookies and similar technologies to:
-
operate essential website functions;
-
maintain security;
-
remember visitor preferences;
-
understand website usage and performance;
-
support forms, embedded content and other enabled features;
-
support analytics or marketing tools where these are activated.
The cookies used may change as website features, Wix services and third-party integrations are added or updated.
We use a cookie-consent banner to allow visitors to accept or reject non-essential cookies. Essential cookies may operate because they are required for the website to function. Non-essential analytics, functional or marketing cookies will only be used where the appropriate consent has been obtained.
Wix provides tools to scan the website and identify the cookies currently in use. The cookie banner and preferences centre should be treated as the current source of detailed cookie information.
Visitors can review or change their cookie choices through the cookie-preferences tool available on the website.
11. Your data-protection rights
Depending on the circumstances, you may have the right to:
-
ask for access to your personal information;
-
ask us to correct inaccurate or incomplete information;
-
ask us to delete information;
-
ask us to restrict how information is used;
-
object to certain processing, including direct marketing;
-
receive certain information in a portable format;
-
withdraw consent where processing is based on consent;
-
challenge certain decisions made solely by automated means.
These rights are not absolute and may not apply in every situation.
To exercise a right, email hello@wearebrownhound.com. We may need to verify your identity before responding.
You will not normally be charged for exercising your rights.
12. Automated decision-making
Brown Hound does not currently use personal information to make solely automated decisions that produce legal or similarly significant effects.
Should this change, we will provide appropriate information about the logic involved, the likely consequences and the rights available.
13. Links to other websites
Our website may contain links to websites operated by other organisations.
We are not responsible for how those organisations collect or use personal information. Please review the privacy information provided on the relevant website.
14. Complaints
Please contact us first if you have concerns about how we have used your personal information.
You can contact us at: hello@wearebrownhound.com
You also have the right to complain to the Information Commissioner’s Office.
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Current complaint and contact information is available through the ICO.
15. Changes to this notice
We may update this privacy notice to reflect changes to our services, technology, suppliers or legal obligations.
The latest version will be published on our website with the date it was last updated.