Privacy notice.
How Yasmin Khan’s office handles personal data, in plain language and in accordance with the UK General Data Protection Regulation and the Data Protection Act 2018.
Who we are.
This privacy notice applies to the website at yasminkhan.co and to correspondence handled by Yasmin Khan’s office. Yasmin Khan, acting as a sole trader, is the data controller for personal data collected through the website and through correspondence channels listed on it.
If you have questions about how we handle your data, please write to privacy@yasminkhan.co.
What we collect.
We collect only the personal data necessary to respond to your correspondence and to operate the website.
Information you give us
- Name, organisation, and role, when you submit an enquiry form.
- Email address and telephone number, when you provide them.
- The content of your enquiry, including any context you choose to include.
- Email correspondence sent directly to one of our published addresses.
- Email address, when you subscribe to occasional updates.
Information collected automatically
- Standard server logs, including IP address, browser type, and the pages requested. These are kept briefly for security and diagnostic purposes.
- Anonymised analytics, where enabled. See the cookie notice for full detail.
How we use it.
Personal data is used only for the purposes for which you gave it to us.
- To respond to enquiries about advisory work, speaking engagements, media requests, commissions, and general correspondence.
- To send the occasional update list, where you have subscribed.
- To operate and protect the website.
We do not use your personal data for advertising, profiling, or automated decision-making.
Lawful basis.
Under UK GDPR, the lawful bases on which we process personal data are:
- Consent, where you have actively chosen to share data with us, such as by subscribing to updates.
- Legitimate interests, where we respond to enquiries you have initiated. Our interest is in conducting the work of Yasmin’s office; the interest is balanced against your reasonable expectations as the person making contact.
- Legal obligation, where we are required to retain or disclose information under UK law.
How long we keep it.
We keep personal data only as long as needed for the purpose it was given.
- Enquiry correspondence: retained for up to two years after the enquiry concludes, in case of follow-up. Deleted thereafter.
- Subscriber list: retained while you remain subscribed. Removed promptly when you unsubscribe.
- Server logs: retained for up to 30 days for security and diagnostic purposes.
Your rights.
Under UK GDPR you have the following rights in relation to your personal data. To exercise any of them, please write to privacy@yasminkhan.co.
- The right to be informed about how your data is used.
- The right of access to your data.
- The right to rectification of inaccurate data.
- The right to erasure, in certain circumstances.
- The right to restrict processing, in certain circumstances.
- The right to data portability.
- The right to object to processing based on legitimate interests.
- Rights in relation to automated decision-making and profiling. We do not undertake such processing.
We will respond to requests within one month, in line with the statutory timeframe.
International transfers.
Most processing takes place within the United Kingdom or the European Economic Area. Where a processor operates outside these regions, transfers take place under adequacy regulations or under standard contractual clauses approved by the Information Commissioner’s Office.
Changes to this notice.
We may update this privacy notice from time to time. Material changes will be noted on this page with a revised effective date. The current version is the one above the table of contents.
Complaints.
If you are unhappy with how we have handled your personal data, please write to us first at privacy@yasminkhan.co so that we can address the matter.
You also have the right to complain to the Information Commissioner’s Office, the UK’s independent regulator for data protection, at ico.org.uk or by writing to: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.