Privacy Policy
Last updated: August 13, 2026
1. Introduction
PDL Solutions (Europe) Ltd (we, us, our) is committed to protecting your personal data. This policy explains what personal data we collect when you visit this website or get in touch with us, how we use it, who we share it with, and the rights you have over it.
We are the controller of the personal data described in this policy. We are a company registered in England and Wales under company number 04213928, with its registered office at 1 Tanners Yard, Hexham, NE46 3NL, and we are registered with the Information Commissioner’s Office under registration number [ICO NUMBER].
This policy should be read alongside our Terms and Conditions of Use.
2. How to contact us
If you have any questions about this policy or about how we handle personal data, please contact us:
- Email: solutions@pdl-group.com
- Post: Data Protection, PDL Solutions (Europe) Ltd, 1 Tanners Yard, Hexham, Northumberland, NE46 3NL, United Kingdom
- Telephone: +44 (0)1434 609 473
3. Personal data we collect
3.1 Information you give us
When you complete an enquiry form on this website, we collect your name, company, email address, the subject and type of your enquiry, and the content of your message. Enquiry forms are delivered to us by email and are not stored in this website’s database.
We also collect the information you give us when you correspond with us by email, telephone, post or through LinkedIn, when you meet us at an event, or when you transfer files to us through our file transfer (FTP) facility.
3.2 Information we collect automatically
When you visit the site, our hosting provider automatically records technical information in server logs, including your IP address, browser type and version, operating system, the pages you visited and the date and time of your visit. This is used to keep the site secure and running correctly.
We also collect information about how the site is used through cookies and similar technologies — see section 6.
3.3 Information from other sources
We may receive your business contact details from your employer, from a colleague who refers you to us, or from publicly available sources such as LinkedIn, company websites or industry directories, where we are researching or responding to a potential project.
3.4 Personal data in project material
Client project material sent to us — drawings, reports, specifications, data sets and correspondence — sometimes contains personal data, such as the names and contact details of engineers, reviewers and approvers. Where we process personal data contained in material supplied by a client for the purposes of delivering that client’s project, we act as a processor on the client’s instructions, and the terms of our contract with that client govern that processing rather than this policy.
4. How we use your personal data and our lawful basis
Under UK data protection law we must have a lawful basis for using your personal data. The table below sets out what we use it for and the basis we rely on.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Responding to your enquiry and discussing a possible project | Name, company, email, enquiry details | Legitimate interests (responding to a request made to us and pursuing business opportunities); steps taken at your request before entering a contract |
| Providing engineering, analysis and consultancy services, and managing our contract with you or your employer | Contact and correspondence details, project records | Performance of a contract; legitimate interests (managing our client relationships) |
| Sending occasional updates about our services, projects and technical publications to business contacts | Name, company, email | Consent, or legitimate interests in marketing to existing business contacts |
| Understanding how the site is used and improving it | Usage and device data from analytics cookies | Consent |
| Keeping the site and our systems secure, and preventing spam and misuse | IP address, server log data | Legitimate interests (network and information security) |
| Meeting our legal, regulatory, quality management and accounting obligations | Relevant records | Legal obligation; legitimate interests (maintaining our certifications and quality records) |
Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights, and we have concluded that they are not. You can ask us for more information about that assessment at any time. Where we rely on consent, you can withdraw it at any time — see section 12.
5. Third parties who process data for us
We share personal data with a small number of service providers who process it on our behalf, under contracts that require them to keep it secure and use it only on our instructions. These currently include:
- [HOSTING PROVIDER] — hosting for this website and its server logs.
- Our email and IT providers — delivery and storage of enquiries and correspondence.
- Google — [ANALYTICS] website analytics and search performance reporting via Google Analytics and Google Search Console, and the interactive map on our contact page.
We may also disclose personal data:
- to our professional advisers, such as lawyers, auditors and insurers, where necessary;
- to regulators, law enforcement or other authorities where we are required to do so by law;
- to a buyer or prospective buyer in connection with a sale or restructuring of our business.
We do not sell your personal data, and we do not share it with third parties for their own marketing purposes.
6. Cookies, analytics and the contact page map
Cookies are small text files placed on your device when you visit a website. We use:
- Strictly necessary cookies, which are required for the site to function securely — for example to protect forms against cross-site request forgery, and to keep you signed in if you have an account with us. These do not require your consent.
- Analytics cookies, which help us understand how visitors use the site so we can improve it. These are only set where you have consented to them.
Our enquiry forms use a hidden field to detect automated submissions rather than a third-party spam-filtering service, so completing a form does not pass your data to a CAPTCHA provider.
The contact page displays an interactive map provided by Google. When that page loads, your IP address and browser information are sent to Google in order to serve the map, and Google may set its own cookies. If you would prefer not to share that data, do not visit the contact page, or block third-party content in your browser. Google’s own privacy policy explains how it uses that information.
Some assets on the site — the carousel stylesheet and the icon library — are loaded from third-party content delivery networks, which means your IP address is visible to those providers. Our typefaces are hosted by us and are not loaded from a third party.
Most browsers let you block or delete cookies through their settings. Blocking strictly necessary cookies may stop parts of the site working. For more detail, see our Cookie Policy.
7. International transfers
We are based in the United Kingdom and store personal data in the UK or the European Economic Area wherever we can. Some of our service providers — including Google — process data outside the UK.
Where personal data is transferred outside the UK, we make sure it is protected by an appropriate safeguard recognised under UK data protection law, which will usually be UK adequacy regulations covering the destination country, or the International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses. You can ask us for a copy of the safeguards we rely on using the contact details in section 2.
8. How long we keep personal data
We keep personal data only for as long as we need it for the purposes set out in this policy, and then delete it or securely destroy it.
- Enquiries that do not lead to work: [RETENTION — ENQUIRIES].
- Client and project records: [RETENTION — CLIENT RECORDS], reflecting the limitation periods that apply to engineering work and the record-keeping our quality management certification requires.
- Accounting records: six years from the end of the financial year they relate to, as required by law.
- Marketing contacts: until you ask us to stop contacting you, after which we keep a minimal record so we can honour that request.
- Server logs and analytics: in line with our hosting and analytics providers’ standard retention settings.
Where a client’s contract sets a different retention period for project material, that contract takes precedence.
9. Recruitment
If you apply for a role with us, or send us a speculative CV, we use the information you provide to assess your application, to contact you about it, and to keep a record of our recruitment decisions. Our lawful bases are steps taken at your request before entering a contract, our legitimate interests in recruiting suitable staff, and our legal obligations.
We keep unsuccessful applicants’ details for [RETENTION — RECRUITMENT] in case a suitable role arises, unless you ask us to delete them sooner.
10. Security screening
Some of our work in the nuclear and defence sectors requires personnel to hold particular clearances, or to pass identity, right-to-work and background checks before being granted access to a client’s site, systems or information. Where this applies to you, we will tell you separately what information is needed, who it will be shared with, and on what basis, before any screening takes place.
11. Security
We maintain appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration and disclosure. These include access controls, encryption of data in transit, staff training, and the controls required by our Cyber Essentials Plus and ISO 9001 certifications.
Please do not send confidential, commercially sensitive, export-controlled or security-classified information through the website’s enquiry forms. If you need to share sensitive project information with us, contact us first so we can agree confidentiality arrangements and a secure transfer method.
12. Your rights
Under UK data protection law you have the right to:
- Access the personal data we hold about you, and receive a copy of it;
- Rectification of personal data that is inaccurate or incomplete;
- Erasure of your personal data, where there is no good reason for us to continue holding it;
- Restrict processing of your personal data in certain circumstances;
- Object to processing based on our legitimate interests, and to object at any time to the use of your data for direct marketing;
- Data portability — to receive the data you gave us in a structured, commonly used, machine-readable format;
- Withdraw consent at any time, where we rely on consent. Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew it.
To exercise any of these rights, contact us using the details in section 2. We will respond within one month; if your request is complex we may extend that by up to two further months and will tell you if we do. You will not usually have to pay a fee. We may need to ask you for information to confirm your identity before we act on a request.
Where a request concerns personal data we hold as a processor on a client’s behalf (see section 3.4), we will refer you to that client, who is the controller.
13. Marketing
If we send you updates about our services and you no longer want to receive them, you can opt out at any time by using the unsubscribe link in any message we send, or by emailing us at [PRIVACY CONTACT EMAIL]. We will stop sending marketing messages, but we will still contact you where necessary about a project or contract.
14. Complaints
If you are unhappy with how we have handled your personal data, please tell us first so we can try to put it right. You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority for data protection:
Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF — telephone 0303 123 1113 — ico.org.uk/make-a-complaint.
15. Third party links
This website contains links to other websites, including those of our clients, partners and certification bodies, and to our LinkedIn page. We are not responsible for the privacy practices of those websites. We encourage you to read the privacy policy of every website you visit.
16. Children
This website is aimed at businesses and professionals. We do not knowingly collect personal data from children.
17. Changes to this policy
We may update this policy from time to time. Any changes will be posted on this page with a revised “last updated” date. If we make a significant change to how we use your personal data, we will take reasonable steps to tell you.