1. Who we are
Rappid BSR is a trading name of Napkin Group Limited. Napkin Group Limited is the data controller for the personal information described in this policy.
Company number 10338310
Park Mill, Burydell Lane
Park Street, St Albans
England, AL2 2EZ
Email: ready@rappidbsr.com
2. Scope of this policy
This policy applies to personal information collected through:
- rappidbsr.com and its contact form;
- emails, calls, meetings and other business communications with us;
- our marketing and service-update communications; and
- our administration of prospective and current client relationships.
Where we process project or personnel information solely on a client’s documented instructions, the relevant client may be the controller and we may act as its processor. That processing should be covered by the applicable service agreement and, where required, a separate data-processing agreement.
3. Information we collect
Depending on how you interact with us, we may collect:
- your name, job title, company and professional contact details;
- project names, enquiry details, messages and correspondence;
- your preference about receiving ongoing Rappid BSR emails;
- contract, billing and service-administration information;
- technical and security information such as IP address, browser, device, request time and hosting logs; and
- other information you choose to provide to us.
Please do not send special-category information, criminal-offence information or personal information that is not necessary for your enquiry through the public contact form.
4. How and why we use personal information
| Purpose | Typical information | Lawful basis |
|---|---|---|
| Respond to enquiries and discuss potential services | Identity, company, contact and enquiry details | Steps requested before a contract and our legitimate interests in developing our business |
| Set up, deliver and administer agreed services | Business contacts, project, contract and billing information | Contract, legitimate interests and legal obligations |
| Protect the website, systems and communications | Technical, security and request information | Our legitimate interests in security, preventing misuse and maintaining availability |
| Send relevant service updates and occasional marketing email | Name, company, email and marketing preference | Your consent, which you may withdraw at any time |
| Meet legal duties and establish, exercise or defend legal claims | Relevant contact, contract, project and correspondence records | Legal obligations and legitimate interests |
We do not use the website contact form to make decisions about you based solely on automated processing that produce legal or similarly significant effects.
5. Information you must provide
Fields marked as required on our contact form are needed so that we can understand and respond to your enquiry. Telephone number, project name and ongoing-email consent are optional. If required information is not provided, we may be unable to respond properly.
7. International transfers
Some service providers may process information outside the United Kingdom. Where this happens, we use a lawful transfer mechanism and appropriate safeguards, such as UK adequacy regulations or approved contractual protections. You may contact us for more information about the safeguards relevant to your information.
8. How long we keep information
- General enquiries and related correspondence: normally up to 24 months after the last contact.
- Client, contract, billing and material service records: normally six years after the relationship ends.
- Marketing contact details: while your consent remains current and the communication remains relevant; we review inactive records at least every 24 months.
- Opt-out records: the minimum information needed to respect your preference may be retained for as long as necessary to prevent further marketing.
- Security and technical records: normally no longer than 12 months, unless needed to investigate an incident.
We may retain information for longer where law, an active dispute, a legal hold or an agreed client instruction requires it. Project data processed for clients is retained under the applicable service terms and documented instructions.
9. Security
We use proportionate technical and organisational measures designed to protect personal information from unauthorised access, alteration, disclosure or loss. No internet service is completely secure, so you should avoid sending unnecessary or highly sensitive information through the public form.
11. Your data-protection rights
Depending on the circumstances, you may have the right to:
- ask for access to your personal information;
- ask us to correct inaccurate or incomplete information;
- ask us to erase information or restrict how it is used;
- object to processing based on legitimate interests or to direct marketing;
- receive certain information in a portable format; and
- withdraw consent at any time, without affecting earlier lawful processing.
To exercise a right, email ready@rappidbsr.com. We may need to verify your identity before acting on a request.
12. Marketing preferences
If you opted into ongoing email, you can withdraw that consent at any time by replying to an email or emailing ready@rappidbsr.com. We will stop marketing to that email address, although we may retain a minimal suppression record to respect your choice.
13. Questions and complaints
Please contact us first at ready@rappidbsr.com so that we can try to resolve your concern. You also have the right to complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaintor by calling 0303 123 1113.
14. Changes to this policy
We may update this policy to reflect changes to our services, suppliers or legal obligations. The current version will be published on this page with its effective date. We will draw attention to material changes where appropriate.
