Privacy Policy



Last updated: 28/07/2026

1. About this policy

This Privacy Policy explains how The Arch Initiative collects, uses, stores and protects personal information when you visit our website, contact us or enquire about our services.

For the purposes of UK data protection law, the data controller is:

TAI (NW) Ltd, trading as The Arch Initiative
Company number:
12534994
Registered address:
Queens Drive, Liverpool, L13 5TY
Email:
enquiries@thearchinitiative.com

2. Information we may collect

We may collect and process:

  • your name;
  • your organisation and job title;
  • your email address and telephone number;
  • information included in an enquiry, message or correspondence;
  • information provided when discussing, commissioning or receiving our services;
  • billing, contractual and transaction information;
  • records of communications with you;
  • technical information relating to your use of the website, such as your IP address, browser, device and cookie preferences; and
  • information that you choose to provide when subscribing to updates or responding to communications.

Please do not submit confidential tender information, special-category personal data or commercially sensitive documents through the general website contact form.

3. How we collect information

We may collect personal information:

  • directly from you when you complete a form, email us, telephone us or engage our services;
  • through correspondence, meetings and project delivery;
  • through website hosting, security, analytics and cookie technologies;
  • from publicly available professional or business sources; and
  • through an authorised representative of your organisation.

4. How we use personal information

We may use personal information to:

  • respond to enquiries;
  • understand your requirements;
  • arrange meetings and provide proposals or quotations;
  • enter into and administer contracts;
  • provide bid, tendering, market-development and consultancy services;
  • manage client and supplier relationships;
  • process invoices and maintain financial records;
  • operate, secure and improve the website;
  • maintain appropriate business, quality and audit records;
  • comply with legal, regulatory and professional obligations;
  • establish, exercise or defend legal rights; and
  • send relevant business communications where permitted by law.

We do not sell personal information.

5. Our lawful bases

Depending on the circumstances, we rely on one or more of the following lawful bases:

Contract: where processing is necessary to take steps at your request before entering into a contract or to perform a contract.

Legitimate interests: where processing is necessary for our legitimate business interests, including responding to business enquiries, managing client relationships, developing our services, maintaining records and protecting our website and business.

Legal obligation: where we must process information to comply with applicable legal, tax, accounting or regulatory requirements.

Consent: where you have given clear consent for a specific purpose, such as certain optional cookies or marketing communications. You may withdraw consent at any time.

6. Marketing communications

We may send relevant business-to-business communications where this is permitted by law and consistent with your reasonable expectations.

You may ask us to stop sending marketing communications at any time by:

We may retain limited information on a suppression list so that we can respect your request.

7. Sharing personal information

We may share personal information with carefully selected service providers where this is necessary to operate our business. These may include:

  • website hosting and maintenance providers;
  • email, cloud-storage and collaboration providers;
  • accounting, payment and professional advisers;
  • IT support and cybersecurity providers;
  • subcontractors or specialist consultants involved in an agreed assignment; and
  • regulators, public authorities, courts or law-enforcement bodies where required by law.

Service providers may only process information for authorised purposes and must apply appropriate security and confidentiality protections.

We will not share confidential client or tender information with subcontractors without an appropriate contractual basis and, where required, client authorisation.

8. International transfers

Some technology, professional-service providers and members of our team may process or store information outside the United Kingdom. Where personal information is transferred internationally, we will take reasonable steps to ensure that an appropriate transfer mechanism and safeguards are in place, as required by applicable data protection law.

9. How long we retain information

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, contractual, accounting and dispute-resolution requirements.

Typical retention periods are:

  • general enquiries that do not proceed: up to 24 months;
  • client, contract and project records: normally seven years after the relevant engagement ends;
  • financial and tax records: for the period required by applicable law;
  • marketing records: until you unsubscribe or the information is no longer required; and
  • cookie information: for the period stated in our Cookie Policy or cookie-preference tool.

We may retain information for longer where necessary in connection with a complaint, dispute, legal claim or regulatory requirement.

10. Security

We use proportionate organisational and technical safeguards designed to protect personal information against unauthorised access, loss, misuse, alteration or disclosure.

Access to personal information is restricted to people and service providers who reasonably require it for authorised business purposes.

No internet-based system is completely secure. You should avoid using the website contact form to send confidential tender documents, passwords or highly sensitive personal information.

11. Your rights

Depending on the circumstances, you may have the right to:

  • request access to your personal information;
  • request correction of inaccurate or incomplete information;
  • request deletion of your information;
  • request restriction of processing;
  • object to certain processing;
  • request transfer of information you have provided;
  • withdraw consent where processing relies on consent; and
  • complain about how your information has been handled.

These rights are not absolute and may be subject to legal exemptions.

To exercise a right, email enquiries@thearchinitiative.com. We may need to verify your identity before responding.

12. Complaints

Please contact us first if you have concerns about how we use your personal information:

Email: enquiries@thearchinitiative.com

You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority for data protection.

13. Third-party websites

Our website may contain links to third-party websites. We are not responsible for the privacy practices, security or content of external websites. You should review their privacy information before providing personal information.

14. Changes to this policy

We may update this Privacy Policy to reflect changes to our services, website, suppliers or legal obligations. The current version will be published on this page with its latest revision date.