Privacy Policy
This privacy notice explains how Serve First CX Limited looks after your personal data and tells you about your privacy rights.
Last updated: 29 July 2026
Serve First CX respects your privacy and is committed to protecting your personal data. This privacy notice explains how we look after your personal data when you visit our website and how the law protects you.
Contact the Data Privacy Manager at dpm@servefirst.co.uk if you have questions about this policy or wish to exercise your legal rights.
This privacy notice explains how Serve First CX collects and processes your personal data through this website, including data provided when you sign up to our newsletter, purchase a product or service, or use a contact form.
This website is not intended for children and we do not knowingly collect data relating to children.
Serve First CX Limited is the controller responsible for your personal data. Our Data Privacy Manager oversees questions about this notice and requests to exercise your legal rights.
You may complain to the Information Commissioner's Office at www.ico.org.uk. We would appreciate the chance to address your concerns first.
This version was last updated on 29 July 2026. Please keep us informed if your personal data changes.
This website may include third-party links. We do not control those websites and encourage you to read their privacy notices.
Personal data means information about an individual from which that person can be identified. It does not include anonymous data.
We may collect, use, store, and transfer the following kinds of personal data:
We do not collect Special Categories of Personal Data or information about criminal convictions and offences.
If you fail to provide personal data required by law or contract, we may be unable to perform the relevant contract or service and will notify you if this occurs.
We collect data through direct interactions when you fill in forms or correspond with us, including when you apply for services, make an enquiry, subscribe, request marketing, enter a promotion or survey, or provide feedback.
We automatically collect Technical Data through cookies, server logs, and similar technologies. The website uses Next.js, is deployed on Vercel, and uses Sanity as a headless CMS. Sanity does not collect personal data directly from your browser. See our Cookies Policy for details.
We may also receive personal data from third parties and public sources.
We only use your personal data when the law allows us to.
We generally do not rely on consent except for direct marketing by email, post, or text. You may withdraw marketing consent at any time by using an unsubscribe link or contacting us.
We may share personal data with the External Third Parties described in the Glossary and with third parties involved in a sale, transfer, merger, acquisition, or reorganisation of our business or assets.
We require all third parties to respect the security of your personal data and process it in accordance with the law. Service providers may only process it for specified purposes and on our instructions.
Some external third parties are based outside the European Economic Area, so their processing may involve an international transfer.
When personal data is transferred outside the EEA, we use appropriate safeguards.
Contact us for more information about the specific transfer mechanism we use.
We use appropriate security measures to prevent personal data from being accidentally lost, used, accessed, altered, or disclosed without authorisation.
Access is limited to employees, agents, contractors, and third parties with a business need to know. They process data on our instructions and are subject to confidentiality duties.
We have procedures for suspected personal data breaches and will notify you and the relevant regulator where legally required.
We retain personal data only as long as necessary for the purposes for which it was collected, including legal, accounting, and reporting requirements.
We consider the amount, nature, and sensitivity of the data, the risk of harm, the processing purposes, available alternatives, and legal requirements.
We keep basic customer Contact, Identity, Financial, and Transaction Data for six years after the customer relationship ends for tax purposes.
You may ask us to delete your data in some circumstances. We may use anonymised data indefinitely for research or statistics.
Under data protection law, you may have the following rights:
Contact us to exercise these rights. There is usually no fee, but we may charge a reasonable fee for requests that are clearly unfounded, repetitive, or excessive.
We may request information to confirm your identity. We aim to respond to legitimate requests within one month.
Legitimate Interest means our interest in conducting and managing the business to provide the best and most secure experience.
Performance of Contract means processing necessary to perform a contract with you or take steps at your request before entering into one.
Comply with a legal or regulatory obligation means processing necessary to meet an obligation that applies to us.
External Third Parties include IT and administration service providers, professional advisers, HM Revenue & Customs, regulators, and analytics or tracking providers.