Skip to main content
Privacy by Design • UK GDPR Compliant

Privacy Policy & Data Protection Commitment

At WEEEvolution Ltd, we are committed to protecting and respecting your privacy. We operate on a strict Privacy-by-Design architecture with zero non-essential tracking cookies and zero third-party profiling.

Our Zero-Tracking Guarantee (PECR & UK GDPR):

  • 0 Non-Essential Cookies: We do not set any marketing, tracking, profiling, or behavioral analytics cookies.
  • No Cookie Banners Required: Because we do not store tracking cookies, no disruptive cookie consent pop-up is required under UK GDPR or PECR regulations.
  • Self-Hosted Typography: All fonts are served locally from our static bundle. Your IP address is never transmitted to Google Fonts or third-party font networks.
  • Client-Side File Processing: Compliance files uploaded via our Notice Uploader tool are processed locally in your browser and never transmitted to our servers without your explicit email or WhatsApp dispatch.

1. Who We Are (Data Controller)

WEEEvolution Ltd is a UK-based environmental consultancy providing independent advice, operational audits, and representation in relation to the Waste Electrical and Electronic Equipment (WEEE) Regulations 2013, Waste Batteries Regulations 2009, and Packaging EPR.

Entity: WEEEvolution Ltd
Company Registration (England & Wales): 16209170
Registered Office: Chandos Business Centre, 87 Warwick Street, Leamington Spa, Warwickshire, CV32 4RJ
Data Protection Officer / Lead Consultant: Dan Cronin (info@weeevolution.co.uk | 07349 717 600)

2. What Information We Collect

We only collect personal information that you voluntarily provide to us when contacting us or engaging our professional services:

  • Contact Details: Full name, corporate email address, telephone numbers.
  • Business Information: Company name, registered address, Companies House number, job title, and VAT / EORI numbers.
  • Regulatory Notice Information: Environment Agency letters, Information Notices (Section 108), Warning Letters, Producer Compliance Scheme (PCS) memberships, EEE product catalogues, and sales tonnage datasets.
  • Technical Data: Anonymised server access logs (IP addresses are masked and not stored in identifiable form) and browser protocol metadata essential for secure HTTPS communication.
  • Communications: Email correspondence, meeting notes, call records, and client enquiry submissions.

3. How We Use Your Information

We process personal and corporate data strictly for the following purposes:

  • To respond to your direct compliance enquiries and regulatory emergencies.
  • To deliver contracted environmental consultancy, AATF audits, AR mandates, and compliance scheme negotiations.
  • To represent producers and recyclers before the Environment Agency, SEPA, NRW, and NIEA where formal power of attorney or Authorised Representative mandates are in place.
  • To manage ongoing client relationships, invoicing, and statutory accounting.
  • To fulfil mandatory statutory reporting and legal obligations under UK legislation.

4. Lawful Basis for Processing (UK GDPR Article 6)

Under Article 6 of the UK General Data Protection Regulation (UK GDPR), we rely on the following lawful bases to process your personal data:

  • Contractual Necessity (Article 6(1)(b)): Processing is necessary for the performance of a contract to which you are a party (e.g. consultancy engagement, Authorised Representative services) or to take steps at your request prior to entering into a contract.
  • Legal Obligation (Article 6(1)(c)): Processing is necessary to comply with common law and statutory obligations, including environmental compliance records, tax retention (HMRC), and Companies Act requirements.
  • Legitimate Interests (Article 6(1)(f)): Processing is necessary for our legitimate commercial interests in operating an advisory practice, preventing fraud, maintaining cybersecurity, and responding to initial B2B business enquiries, provided such interests are not overridden by your fundamental rights.
  • Consent (Article 6(1)(a)): Where you provide explicit consent for specific communications or voluntary feedback. You may withdraw consent at any time.

5. Commercial Confidentiality, Non-Disclosure & Data Sharing

All corporate records, Environment Agency correspondence, tonnage files, and operational assessments are treated under strict director-level confidentiality and commercial non-disclosure. Where formal Legal Professional Privilege is required in contentious enforcement matters or PACE interviews, Dan Cronin coordinates technical input alongside your appointed solicitors or counsel.

  • No Commercial Sale: We never sell, rent, lease, or trade your personal or business data to any marketing agency, compliance scheme, or commercial broker.
  • Strict Data Processors: We may share necessary data with trusted IT infrastructure providers (such as encrypted email hosting and secure server hosting) operating under rigorous Data Processing Agreements (DPAs) compliant with UK GDPR.
  • Statutory Disclosures: Data is disclosed to regulators (Environment Agency, SEPA, NRW, NIEA) solely when formally instructed and authorized by you under an Authorised Representative mandate or client defence protocol.

6. Data Retention Schedules

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, regulatory, tax, and auditing requirements:

  • Client Engagement & Compliance Audits: Retained for 6 years following the conclusion of the contractual relationship, in accordance with the UK Limitation Act 1980 and HMRC statutory accounting regulations.
  • General Business Enquiries: Retained for up to 12 months from the date of last contact if no formal advisory engagement is established, after which data is permanently deleted.
  • Server Access Logs: Anonymised and purged on a rolling 30-day schedule.

7. Your Statutory Rights & ICO Contact

Under UK GDPR, you have enforceable legal rights regarding your personal data:

  • Right of Access: Request a copy of the personal data we hold about you (Subject Access Request).
  • Right to Rectification: Request correction of inaccurate or incomplete personal information.
  • Right to Erasure ('Right to be Forgotten'): Request deletion of your personal data where retention is no longer legally justified.
  • Right to Restrict or Object: Restrict processing or object to processing based on legitimate interests.
  • Right to Data Portability: Request transmission of your data in a structured, commonly used machine-readable format.
  • Right to Withdraw Consent: Where processing is based on consent, withdraw that consent at any time without affecting past lawful processing.

To exercise any of these rights, please email Dan Cronin at info@weeevolution.co.uk. We respond to all verified requests within one calendar month.

Right to Complain: If you are dissatisfied with our response, you have the right to lodge a formal complaint with the UK supervisory authority:
Information Commissioner's Office (ICO)
Website: www.ico.org.uk | Helpline: 0303 123 1113

8. Cookies & Local Storage

Our website does not use cookies for tracking, analytics, or behavioral profiling. The only client-side storage utilized is essential browser memory for interactive tools (such as temporary form fields while you complete the Notice Uploader), which remains strictly on your local device.

9. Third-Party Websites & Services

Our website may contain hyperlinks to statutory bodies (such as legislation.gov.uk, gov.uk, or the Environment Agency). We do not control and are not responsible for the privacy practices, content, or policies of third-party external websites.

10. Policy Updates & Governance

This policy was originally published in June 2025 and was comprehensively reviewed and updated in 2026 to ensure full compliance with the latest UK GDPR guidelines and static privacy standards.

For any data protection inquiries, contact Dan Cronin directly at info@weeevolution.co.uk or call 07349 717 600.