top of page
Nikki-Gibson-logo

Tiki Group Privacy Policy

Last updated: September 2026

Why we have a privacy policy and how to get in touch about your data is all explained here on this page.

Tiki Group is committed to complying with the UK's Data Protection law and the UK GDPR for the protection of personal data, as well as the principles of data security in the configuration of our services. If you have any questions about this privacy notice or how we use your personal data, please contact us:

In Writing:
Tiki Group
Edinburgh, EH6 6AT
By Email: privacy@tikigroup.uk

Overview: What data is being collected and processed?

Like all companies, we collect and hold data provided to us in exchange for services. "Services" means paid for services, sending requested information such as a quote or proposal, or responding to contact form submissions. You can opt out and withdraw consent, or ask to be forgotten, at any time.

In order to enter into an agreement with Tiki Group, we will collect, store and use elements of your personal data. Processing this data is a contractual requirement, necessary for us to administer your account and provide the consultancy services you've requested.

When you approach Tiki Group to engage our services, we will ask your consent to collect and process your personal data. Failure to provide this consent may mean we're unable to execute the contract and will result in termination of our services.

When engaging Tiki Group, you will usually need to disclose to us some or all of the following:

Name. Email address. Place of work or company name. Location. Reasonable contextual information to help us provide relevant advice.

We may also monitor, record, store and use any telephone, email or other electronic communications with you for training purposes, so we can check any instructions given to us and improve the quality of our service.

Our website is hosted by Wix.com Ltd, which may mean personal data is transferred outside the UK or EEA. Where this happens, appropriate safeguards, such as Standard Contractual Clauses or the UK International Data Transfer Agreement, are in place to protect your data.

Website Cookies

These help improve your experience on our website and help us share communications with you that are more relevant. Our website holds cookies to ensure the best browsing experience and to help make sure any marketing information we share is relevant.

Direct Marketing Communications

We aim to send only interesting and relevant marketing communications, and you can opt out at any time.

If you've chosen to opt in to our direct marketing communications, we'll use your information to tell you about consultancy services from Tiki Group that may be of interest to you. To help make our emails more relevant, we may receive a confirmation when you open an email from us, if your device supports this.

You have the right to opt out of our direct marketing communications at any time, either by following the unsubscribe instructions at the bottom of the communication, or by emailing insert contact email.

Legal basis for processing personal information

Our legal basis for collecting and using your personal information depends on the context. We will normally only collect it where we have your consent, where we need it to perform a contract with you, or where processing is in our legitimate interests and doesn't override your data protection rights. In some cases, we may also have a legal obligation to collect it.

Where we rely on legitimate interests, it's for reasons such as:

Keeping existing clients up to date with our services and advice. Keeping people who've requested a quote or proposal up to date on that process. Keeping people who've shown genuine interest in our services, for example by getting in touch directly, informed about relevant updates.

You may withdraw your consent at any time by using the unsubscribe link on any communication, or by emailing insert contact email.

Links to other websites

We don't control websites that aren't our own, but we may link out to them, so please check their privacy policies before giving them any information. This policy only applies to Tiki Group, and we're not responsible for information submitted to or collected by third-party sites.

How long will data be stored for?

We only hold your data for as long as we think is fair, and you can ask us to delete it at any time. Where possible, we'll erase personal data that's no longer necessary for the purpose it was collected for, or if you've withdrawn consent.

As a general rule, if you enter into or take steps to enter into a contract with Tiki Group, we'll store your data for seven years, to meet our general legal obligations and for the exercise or defence of any legal claims.

Under the GDPR, you have the right to request the deletion or removal of personal data, also known as "the right to be forgotten," including where it's no longer necessary, where you withdraw consent, where you object and there's no overriding legitimate interest, or where it was unlawfully processed. If deletion isn't possible due to legal or contractual retention periods, we'll block the data instead.

Sharing of data with other data controllers and processors

In short, we don't, unless we legally have to, for example to prevent fraud. We'll only disclose your information outside Tiki Group when you've given consent, it's necessary to perform a contract, we need professional advice, we or others need to investigate or prevent crime, the law requires it, or a regulatory body requests it.

Other data processors we may share information with include Companies House, for submitting tax returns and confirming details, and any third-party software we use to process invoicing, payroll or accounts.

Fraud Prevention

If you give us false or inaccurate information and fraud in any form is identified, details will be passed to fraud prevention agencies, who may access and use this information to prevent fraud and money laundering.


We take reasonable technical and organisational steps to protect the personal data we hold from accidental or deliberate loss, misuse or unauthorised access. Any access to data stored by us only takes place through a secure connection, and our website uses SSL/TLS encryption, an industry standard used by millions of websites to protect online transactions with customers.

While we try to keep our website secure and reliable, your use of the internet is at your own risk, and we have no responsibility for the security of information transmitted via the internet.

Breaches

If we become aware that your data has been compromised, or that a breach affecting the security of your data has occurred, we will notify the Information Commissioner's Office and you, without undue delay.

Subject Access Requests

You can request a copy of the data we hold on you at any time, and we'll provide it within one month of receiving your request in writing, if not sooner. This is provided free of charge, though we can charge a reasonable fee or refuse requests that are manifestly unfounded, excessive or repetitive.

To submit a request, contact us in writing at:

Tiki Group, Edinburgh, EH6 6AT
Email: privacy@tikigroup.uk

Rectifying or updating personal data

If you believe the personal data we hold about you is inaccurate or incomplete, you have the right to ask us to correct it. We'll typically respond within one month, extended by up to two months for complex requests.

Withdrawing consent

If we're processing your data based on consent, you have the right to withdraw that consent at any time. To do so, please confirm this in writing to:

Tiki Group, Edinburgh, EH6 6AT
Email: privacy@tikigroup.uk

Please note that withdrawing consent may mean we're unable to execute a contract you've entered into with us, and may result in termination of our services. Withdrawing consent doesn't affect the lawfulness of processing carried out before it was withdrawn.

bottom of page