Privacy notice
How THOTH GRP LTD collects and uses personal data, how long it keeps it, and your rights under UK data protection law. Last updated 25 September 2026.
Who we are
THOTH GRP LTD (“THOTH”, “we”) is the controller of the personal data described in this notice. We are registered in England and Wales under company number 12913479, with our registered office at 124 City Road, London, England, EC1V 2NX. We are registered with the Information Commissioner's Office (ICO) under reference ZC256322.
Our Data Protection Officer can be contacted at privacy@thoth.group about this notice, your data or your rights.
What we collect
- When you book a call on this website: your name, email address and organisation, the time you choose, anything you write in the message field, and the time zone your browser reports, so that we can show you times in your local time.
- When you contact us or ask for a proposal: your name, email address, organisation and role, and what you tell us about your situation.
- When you visit this website: the technical data your browser sends, such as your IP address, browser type and the pages requested, which our web server records in its logs. This website sets no cookies, uses no analytics or advertising trackers, and loads nothing from third-party servers: its fonts are served from our own server.
- When we act for your organisation: the data needed to deliver the engagement, including information about directors, shareholders, employees and other individuals contained in your records.
- For anti-money-laundering checks: identity documents, proof of address, information about beneficial owners, and the results of sanctions and politically-exposed-person checks, as required by the Money Laundering Regulations 2017.
- For Companies House identity verification, when we act as an Authorised Corporate Service Provider: the identity information and documents needed to verify the individual concerned to the Companies House identity verification standard.
Where it comes from
Mostly from you. When we act for your organisation, we also receive personal data from the organisation itself, and we consult public registers such as the Companies House register.
How we use it, and on what basis
- To arrange the call you book, send you the confirmation and the meeting link, and hold the call: steps you ask us to take before entering into a contract, or our legitimate interest in responding to you.
- To answer your enquiry and prepare a proposal: the same bases.
- To deliver our services: performance of our contract with you or your organisation.
- To carry out customer due diligence, identity verification and record keeping required by law, including under the Money Laundering Regulations 2017, the Companies Act 2006 and tax legislation: legal obligation.
- To keep this website and our booking service secure and working: our legitimate interest in operating a reliable service.
Where anti-money-laundering checks involve information about criminal convictions or offences, we process it only where the Data Protection Act 2018 permits it, in particular to meet a legal or regulatory requirement.
We do not sell personal data, and we do not send marketing emails without your consent.
How a booking works
When you book a call, your details pass through our booking service, which runs on our own server, to our Microsoft Bookings calendar. Microsoft records the appointment, creates the Microsoft Teams meeting and sends you the confirmation email. Our booking service does not keep a copy of your details. To protect it against abuse, it counts requests from each IP address, in memory only, for up to one hour.
Who we share it with
- Service providers who process data on our behalf under contract: Microsoft, for email, Teams video calls and Bookings scheduling; and OVHcloud, which provides the server that hosts this website and our booking service. The server is located in London, United Kingdom.
- Authorities where the law requires it, including HMRC, Companies House and the National Crime Agency.
- Other parties on your instruction, such as your auditors, administrators or advisers.
- Our professional advisers and insurers, where needed to establish or defend our legal position.
International transfers
Some of our service providers may process data outside the United Kingdom, including in the European Economic Area and, for Microsoft, in the United States. Where they do, we rely on UK adequacy regulations, including the UK Extension to the EU-US Data Privacy Framework where the recipient is certified, or on appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses.
How long we keep it
- Bookings and enquiries that do not lead to an engagement: up to two years after our last contact.
- Customer due-diligence records: five years after the end of the business relationship, as required by the Money Laundering Regulations 2017. We then delete the personal data they contain, unless the law requires us to keep it or it is needed for legal proceedings.
- Companies House identity verification records: seven years from the verification, as Companies House requires of Authorised Corporate Service Providers.
- Engagement records: generally six years after the end of the engagement, reflecting limitation periods and tax record-keeping requirements, and longer where an HMRC enquiry, a claim or legal proceedings are open or reasonably expected.
- Web server logs: up to 14 days, for security and troubleshooting, after which they are deleted.
How we protect it
This website and our booking service use encrypted connections only. Administrative access to our servers requires a hardware security key, and access to personal data is limited to those who need it to do their work.
Your rights
You have the right to access your personal data, to have it corrected or erased, to restrict or object to its use, and to receive it in a portable format. Where we rely on consent, you may withdraw it at any time. Some rights are limited where the law requires us to keep data. To exercise a right, write to privacy@thoth.group. We will reply within one month, or tell you within that month if a complex request needs up to two more months.
Complaints
If you are unhappy with how we handle your personal data, you can complain to us at privacy@thoth.group. We will acknowledge your complaint within 30 days, look into it without undue delay, keep you informed of progress and tell you the outcome.
You also have the right to complain to the Information Commissioner's Office, at ico.org.uk or on 0303 123 1113.
Automated decisions and changes
We do not make decisions about you based solely on automated processing. We will update this notice when our practices change; the date at the top shows the current version.