Privacy Notice
General
We respect individuals’ rights to privacy and to the protection of personal information. This Privacy Notice sets up why we collect your personal information, what information is collected, how it is processed and provides you with your rights in relation to that data.
‘Personal information’ (also referred to as ‘personal data’) means information about a living individual who can be identified from that information (either by itself or when it is combined with other information).
Throughout this Privacy Notice, we use the term “processing” to cover all activities involving your personal information, including collecting, handling, storing, sharing, accessing, using, transferring, securing and disposing of information.
Graham + Sibbald is committed to ensuring that your privacy is protected. Any personal data provided to us by you or by a 3rd party, shall only be used by us in accordance with this notice or as otherwise authorised by law. Your personal data will be processed securely and in compliance with data protection law.
We may update this notice from time to time by updating the terms on our website (www.g-s.co.uk). We would encourage you to visit our website for any amendments. This policy is effective from May 2026.
Topics:
- Who we are
- Data Controller
- To whom does this privacy notice apply?
- What personal information might we process?
- How we obtain information?
- What we do with your Personal Data?
- Who do we share your Personal Data with?
- Security
- Marketing
- Our Website
- How long we keep your Personal Data?
- Your rights
- Exercising your rights
- How to contact us
Who we are
Graham + Sibbald (collectively ‘Graham + Sibbald’, ‘the Company’ or ‘we’), are Graham + Sibbald Property Consultants Limited. Company No.SC837809.
Data Controller
The Firm’s Data Protection Officer is: Alison Rae, Group Operations Director
Contact details:
Email – datacontroller@g-s.co.uk
Address – 40 Torphichen Street, Edinburgh, EH3 8JB
Telephone – 0131 225 1559
We have appointed a Data Protection Officer (“DPO”) – Group Operations Director – datacontroller@g-s.co.uk, 0131 225 1559.
To whom does this privacy notice apply?
- All individuals who visit our website or who contact us by post, telephone, e-mail, social media or other means (including other electronic means); or
- All individuals who are or have been our clients; or
- All individuals who are our client contacts where you or your organisation are or have been our customer;
- All individuals who are related to our clients (client-related individuals) such as tenants or leaseholders where our client is the landlord; or
- All individuals who are our business contacts where you or your organisation supply goods or services to us, provide professional services, have expressed an interest in us or have any other business relationship with us (including where your organisation is a public authority, an industry body or regulatory authority or similar).
Your duty to inform us of changes
It is important that the personal data that we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.
What information might we process?
We collect and process various categories of personal information at the start of and for the duration of your relationship with us. We will limit the collection and processing of information to information necessary to achieve one or more legitimate purposes as identified in this notice. Personal Information may include:
Relevant to ALL
- Basic personal information, including name and address and contact details such as telephone number + email address (for example you have registered an interest in a property/ have requested particularly or to be provided with a quote to undertake a valuation on your property);
Customer + Suppliers
- Financial information, including bank account details, account + transactional information and borrowing details;
- Card payment details;
Customer(s)
- Access details to ‘named’ property(ies);
- Customer Due Diligence (CDD) ID documentation (for example on purchaser/ buyers/ leaseholders of Commercial Properties. Documents include Passport, Driving Licence, Utility Bill/ Mortgage/ Bank statement, etc.);
- Lease information;
- Planning consents;
- General valuation data;
- Full business accounts;
- Services provided;
Website Users
- Online profile
How we obtain information?
Your information is made up of all the personal information we collect and hold about you. It includes:
- Information you give us directly
- Information that we learn about you through our relationship
- Information that we receive from 3rd parties (for example from mortgage lenders)
- Information that we gather from the technology that you use to access our services (for example website usage such as demographic or statistical information such as IP geographic location and web client details)
- Information that we gather from publicly available sources, such as company registers
What we do with your Personal Data?
We will only use and share your information where it is necessary for us to lawfully carry out our business activities. The personal data we hold about you is processed by us to enable us to:
- Operate our business;
- Promote our business;
- Understand your needs or the needs of your organisation;
- Provide you with the services you or your organisation have engaged us to provide;
- Improve our services;
- Managing relationships with business contacts;
- Collect payment for those services provided;
- If you agree, email you about other services we think may be of interest to you;
- Sometimes we need to process it to enforce our legal rights or defend a legal claim against us;
- In the event of a sale or restructure of our business, we may need to share some personal information with a purchaser or other relevant party, but we will keep it to a minimum and follow ICO guidance; or
- share your data as set out in the next paragraph.
We have described the purposes for which your information may be used in detail in Schedule 1 – Purposes of processing.
Who do we share your Personal Data with?
We will not share your information with anyone outside the Firm except:
– Where we have your permission;
– Where you are a client-related individual (for example, where we are acting on behalf of a client and you are the tenant/leaseholder and require to assess the affordability of leaseholders on behalf of a client);
– Where you are a client or client contact, as required for the purposes of providing a service to our client (for example to a planning committee for planning application submissions);
– Where we are required by law to share your personal information with law enforcement agencies, judicial bodies, government entities or regulatory bodies;
– With 3rd parties providing services to us such as agents and sub-contractors acting on our behalf, such as the companies we use to put up marketing boards, utility brokers, site contractors, professional providers. We also need to share data with suppliers that provide us with technology systems or platforms that we use to operate our business e.g. email provider, Anti – Money Laundering ID Check and verification service;
– With debt collection agencies, and legal and other professional advisors;
– In the event of a sale or restructure of our business; and
- If it is for a Recognised Legitimate Interest (as defined under UK GDPR), which interests are set out in Annex 1 to UK GDPR and are fairly limited in scope. They mainly refer to processing for safeguarding vulnerable individuals, sharing with the Police for the purposes of detection or prevention of crime or apprehension of offenders; national security, public security and defence, emergency situations, for public tasks (requested by public authority). In such cases we would always consider if it is actually necessary.
Graham + Sibbald will not share your information for marketing purposes outside the Company.
Where we use any contractor/sub-processor to process your personal data, we ensure that they have entered into a binding legal contract with us ensuring that they will only process your data on our written instruction and in accordance with appropriate security provisions.
If you ask us to, we will share your personal information with any 3rd party on the basis you provide us with permission to do so. Please note, we’re not responsible for any such 3rd party’s use of your personal information, which will be governed by their agreement with you and any privacy statement they provide to you.
The personal information held by us will in the main be stored and processed within the United Kingdom. In the event that we transfer information to countries out with the UK, we will only do so where:
- The Information Commissioner’s Office (ICO) has decided that the country or the organisation we are sharing your information with will protect your information adequately;
- We have entered into a contract with the organisation with which we are sharing your information (on terms approved by the ICO) to ensure your information is adequately protected; or
- You have given us explicit consent to transfer information to a country out with the UK or another derogation under Chap V of UK GDPR applies.
If you fail to provide personal data
Where we need to collect personal data by law, or under the terms of a contract we have with you, and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with services). In this case, we may have to cancel a service you have with us, but we will notify you if this is the case at the time.
Security
We are committed to ensuring that your information is secure with us and the 3rd parties who act on our behalf. In order to prevent unauthorised access or disclosure, we have put in place suitable physical, electronic and managerial procedures to safeguard and secure the information we process. Periodic checks are undertaken to ensure that our security measures remain appropriate and up to date.
Marketing
If you are a consumer, we will only provide you with direct electronic marketing communications e.g. email where you have consented to receive such communications or you have contacted us directly to request specific information about our products or services. You can subscribe to receive our regular marketing communications, and you can adjust your marketing preferences at any time by contacting our Marketing department, details below. We may make marketing telephone calls and rely on legitimate interest.
If you represent another business, we may provide you with direct marketing communications where we feel that this may be relevant to your business (provided that you have not opted out of such communications). When we use your personal data for such purposes, we do so on the basis that it is in our legitimate interest to pursue direct marketing, provided that it constitutes fair processing of your personal data to do so.
You can also opt-out or unsubscribe from all or some of these marketing communications at any time by contacting us, details below, or by clicking “unsubscribe” at the bottom of any marketing email.
Where you opt out of receiving these marketing communications, this opt-out will not apply to personal data provided to us for any other purpose.
We will still use your contact details to contact you in relation to the service that we are providing you.
Email: enquiries@g-s.co.uk
Address: Graham + Sibbald, Marketing Department, 40 Torphichen Street, Edinburgh, EH3 8JB
Telephone: 0131 225 1559
Our website
Cookies
Find out about how we use Cookies - Schedule 17 - Cookie Policy
Card payments made via our website
We do not store debit or credit card details, nor do we share customer details with any third parties.
Other websites
Our website may contain links to other websites of interest. This privacy notice only applies to our website, so when you link to other websites, you should exercise caution and read the privacy statement to the website in question.
How long we keep your Personal Data?
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.
In the absence of specific legal, regulatory or contractual requirements, our standard retention period for personal data is seven years after conclusion of any relationship between you and us.
After this time, it will be securely destroyed if it is no longer required for the purpose it was obtained.
Retention periods may be changed from time to time based on business or legal and regulatory requirements.
We may on exception retain your information for longer periods, particularly where we need to withhold destruction or disposal based on an order from the courts, an investigation by law enforcement agencies, our regulators or to enforce our legal rights or defend ourselves in a legal claim. This is intended to make sure that the Company will be able to produce records as evidence if they are needed.
Your rights
We want to make sure you are aware of your rights in relation to the personal information we process about you. We have described those rights and the circumstances in which they apply below.
Right of Access - You have the right to access your personal information that we hold
Commonly known as a “subject access request”, you have the right to request access to the personal information we hold about you and to check that we are lawfully processing it. Please contact our DPO via datacontroller@g-s.co.uk if you wish to request such access.
Right of Erasure – You have the right to request that we delete your personal information
You may request that we delete your personal information if you believe that:
- we no longer need to process your information for the purposes for which it was provided;
- we have requested your permission to process your personal information, and you wish to withdraw your consent; or
- we are not using your information in a lawful manner.
Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be explained to you, if applicable, following your request. The right of erasure does not apply to personal data which is processed because it is necessary for the performance of a contract with individual(s).
Please note that if you request us to delete your information, we may have to suspend the service(s) we provide to you.
Right of Rectification – You have the right to request us to amend any inaccurate data
You have the right to rectification and for any inaccurate data to be amended. Requests should be made verbally or in writing to our Data Protection Officer.
Right of Restriction – You have the right to request us to restrict the processing of your personal information
You may request us to restrict processing your personal information if you believe that:
- you want us to establish the accuracy of your personal data;
- where our use of the data is unlawful, but you do not want us to erase it;
- where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or
- you have objected to our use of your data, but we need to verify whether we have overriding legitimate grounds to use it.
Please note if you request us to restrict processing your information, we may have to suspend the service(s) we provide to you.
Right of Data Portability – You have a right to data portability
Where we have requested your permission to process your personal information or you have provided us with information for the purposes of entering into a contract with us, you have a right to receive the personal information you provided us in a portable format. If you would like to request the personal information you provided to us in a portable format, please contact our Data Protection Officer.
Right of Objection – You have a right to object to the processing of your personal information
Where we rely on our legitimate interests (or those of a 3rd party) as the basis for processing your personal information, you have a right to object to us processing your personal information (and to request us to restrict processing) based on your particular situation unless we can demonstrate compelling and legitimate or legal grounds for the processing, which may override your own interests or where we need to process your information to investigate and protect us or others from legal claims.
Depending on the circumstances, we may need to cease processing your personal information altogether, or where requested, delete your information. Please note that if you object to us processing your information, we may have to suspend the service(s) we provide to you.
Marketing – You have the right to object to direct marketing
You have the right to object at any time to processing of your personal information for direct marketing purposes. For more information, please refer to section on ‘Marketing’ above.
Withdraw consent – You have a right to withdraw your consent
Where we rely on your permission to process your personal information, you have a right to withdraw your consent at any time. We will always make it clear where we need your permission to undertake specific processing activities.
Please note the above rights are not absolute and there may be some circumstances where we cannot fulfil your request. We will explain where that happens.
Exercising your rights
If you wish to exercise any of these rights outlined above, please contact our Data Protection Officer.
We may need to clarify your request or request specific information from you to help us confirm your identity and ensure your right to access your personal information (or to exercise any of your other rights). This is a security measure to ensure that personal information is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
You will not have to pay a fee to access your personal information (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.
We try to respond to all legitimate requests within one month. Occasionally, it may take us longer than a month if your request is particularly complex in which case we can extend the deadline by a further two months. In this case, we will notify you and keep you updated.
Complaints
You have the right to make a complaint about how we handle your personal data. Please direct any complaints to datacontroller@g-s.co.uk in the first instance. We will acknowledge your complaint within 30 days. We will thereafter respond to your complaint without undue delay.
How to contact us
We are committed to ensuring that your personal information is processed lawfully, fairly and securely. If you have any questions about our privacy notice, the information we hold about you or concerns about our notice or the way in which we process your personal information please contact us:
- By email controller@g-s.co.uk
- Or write to Data Protection Officer, Graham + Sibbald, 40 Torphichen Street, Edinburgh, EH3 8JB
You also have the right to complain to the Information Commissioner’s Office about how we are processing your personal information. If you remain unsatisfied with our response, you can contact the Information Commissioner’s Office at: -
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Tel: 0303 123 1113
www.ico.org.uk