GDPR

Website: splinnovation.co.uk

Last updated: 4 September 2026


1. Our commitment

SPL Innovation Limited is committed to protecting the privacy and personal data of everyone we work with — prospective clients, clients, referral partners, and website visitors. As a newly established consultancy handling sensitive commercial and financial information as part of R&D tax credit claims, data protection is built into how we operate from day one, not added afterwards.

This statement sits alongside our Privacy Policy and sets out the principles and processes that underpin our approach to compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. The principles we follow

We handle personal data in line with the core UK GDPR principles. Data is:

  • Processed lawfully, fairly and transparently

  • Collected for specified, explicit and legitimate purposes only

  • Adequate, relevant and limited to what's necessary

  • Kept accurate and up to date

  • Retained only for as long as necessary

  • Processed with appropriate security, integrity and confidentiality

3. Our responsibilities as a data controller

For most of the personal data we collect — enquiries, calculator submissions, and client records — SPL Innovation Limited acts as the data controller, meaning we determine how and why that data is processed.

Data protection contact: paul@splinnovation.co.uk

4. How we assess data protection risk

Before introducing any new tool or process that involves personal data — such as our website contact form, calculator, or a future CRM system — we consider what data is involved, why it's needed, how long it will be kept, and who it will be shared with. Where a new process involves higher-risk processing, we'll carry out a data protection impact assessment before going live.

5. Working with third parties

Where we use third-party suppliers to help deliver our services — website hosting, email, analytics, or CRM tools — we choose providers who can demonstrate their own GDPR compliance, and we put data processing agreements in place where required.

6. Data security

We use appropriate technical and organisational measures to keep personal data secure, including restricted access to client records, secure handling of information submitted through our website, and secure storage of any documents relating to R&D tax credit claims.

7. Data breaches

In the unlikely event of a personal data breach that poses a risk to individuals' rights and freedoms, we'll assess the risk without undue delay and, where required, report it to the ICO within 72 hours and notify affected individuals in line with our legal obligations.

8. Your rights

Anyone whose data we hold has the right to access, correct, or request erasure of their personal data, to object to or restrict certain processing, and to complain to the ICO. Full details are set out in our Privacy Policy.

9. Reviewing this statement

We'll review this statement periodically, and as our business and the tools we use develop, to make sure it continues to reflect how we actually handle personal data.

10. Contact us

If you have any questions about our approach to data protection, contact us at paul@splinnovation.co.uk.