Privacy Policy

360 Forensic Limited 3 Archway, Manchester, England, M15 5QJ Company Number: 09754624

Last updated: 10 March 2026

1. Introduction

1.1 360 Forensic Limited (“we”, “us”, “our”) is committed to protecting and respecting your privacy. This
Privacy Policy explains how we collect, use, store and share personal data in connection with our
business, and sets out your rights in relation to that personal data.

1.2 We provide royalty audit services to our clients. In doing so, we handle personal data in two distinct
capacities:

  • as a controller in respect of the personal data of our own contacts and clients (including client representatives and other individuals who contact or engage with us directly); and
  • as a processor in respect of personal data that our clients provide to us in connection with the royalty audit services we perform on their behalf.

1.3 This policy should be read alongside any engagement letter, terms of business or other contractual
documentation we have entered into with you, which may contain further information about how we
handle personal data in the context of a specific engagement.

1.4 We may update this policy from time to time. Any changes will be posted on our website and, where appropriate, notified to you directly.

2. Who We Are

2.1 For the purposes of applicable data protection legislation (including the UK General Data Protection
Regulation (“UK GDPR”) and the Data Protection Act 2018), the controller in respect of personal data
processed by us in our controller capacity is:

  • 360 Forensic Limited Registered in England and Wales Company Number: 09754624 Registered
  • Office: 3 Archway, Manchester, England, M15 5QJ

2.2 If you have any questions about this policy or about how we handle your personal data, please
contact us at:

3. Personal Data We Collect and Process as a Controller

This section applies to personal data in respect of which we act as a controller — that is, where we determine the purposes and means of processing. This primarily covers personal data relating to:

  • individuals who contact us directly (for example, by email, telephone or through our website);
  • client contacts and representatives; and
  • prospective clients and other business contacts.

3.1 Categories of Personal Data We Collect

We may collect and process the following categories of personal data about you:

  • Identity data: your name, job title and the organisation you represent;
  • Contact data: your email address, telephone number and postal address;
  • Communications data: the content of any correspondence or communications you send to us or that we send to you;
  • Business relationship data: records of our interactions with you, notes of meetings and calls, and information about the services we have provided or discussed with you;
  • Financial data: invoicing and payment information where relevant to our business relationship; and
  • Technical data: where you access our systems or communications (including any online portal or dashboard), information such as your IP address, login credentials and usage data.

3.2 How We Collect Your Personal Data

We collect personal data in a number of ways, including:

  • directly from you, when you contact us, enter into a contract with us or otherwise correspond with us;
  • from your organisation, when it engages us to provide services;
  • through the course of our ongoing business relationship with you; and
  • from publicly available sources, such as Companies House or professional directories, in the context of business development.

3.3 Purposes and Legal Bases for Processing

We process personal data in our controller capacity for the following purposes and on the following legal bases:

PurposeLegal Basis
Responding to enquiries and communicating with contacts and prospective clientsLegitimate interests (Article 6(1)(f) UK GDPR) — it is in our legitimate interests to respond to enquiries and develop our business
Entering into and performing contracts with clientsLegitimate interests (Article 6(1)(f) UK GDPR) — it is in our legitimate interests to contract with our clients and perform those contracts
Managing our ongoing client relationships, including invoicing and administrationLegitimate interests (Article 6(1)(f) UK GDPR) — it is in our legitimate interests to manage our business relationships
Complying with our legal and regulatory obligationsCompliance with a legal obligation (Article 6(1)(c) UK GDPR)
Protecting our legitimate business interests, including enforcing our contractual rightsLegitimate interests (Article 6(1)(f) UK GDPR)
Marketing and business development communications (where applicable)Legitimate interests (Article 6(1)(f) UK GDPR) or consent (Article 6(1)(a) UK GDPR) where required

4. Personal Data We Process as a Processor

4.1 In connection with the royalty audit services we provide, our clients may provide us with personal data relating to third parties (for example, artists, songwriters, licensees, royalty recipients or other individuals whose data is relevant to the audit). In respect of such personal data, we act as a processor on behalf of our clients, who are the controllers.

4.2 Where we act as a processor:

  • we process personal data only on the documented instructions of our clients;
  • we do not use that personal data for our own purposes;
  • we implement appropriate technical and organisational measures to keep the data secure; and
  • we assist our clients in fulfilling their own obligations as controllers under applicable data protection legislation.

4.3 If you are an individual whose personal data has been provided to us by one of our clients in connection with a royalty audit, you should contact that client directly to exercise your data subject rights, as they are the controller in respect of your personal data. We will, however, assist our clients in responding to any such requests as required under applicable law.

4.4 Our processing activities as a processor are governed by the terms of the data processing
agreement or equivalent provisions in the relevant contractual documentation with the applicable client.

5. Sharing Your Personal Data

5.1 General

We may share your personal data with the following categories of recipients:

  • Our staff and personnel: employees and contractors who need access to your personal data in order to provide our services or manage our business relationship with you;
  • Professional advisers: lawyers, accountants and other professional advisers where necessary in connection with our business;
  • IT and systems providers: third-party service providers who provide us with IT infrastructure, software and support services, acting as processors on our behalf;
  • Regulatory and law enforcement authorities: where we are required to do so by law or by a competent authority; and 360 Spectra Limited: as further described in Section 5.2 below.

5.2 Sharing with 360 Spectra Limited

5.2.1 Where a client has elected to use the online audit and reporting dashboard service (the “Dashboard”), we will share relevant personal data and other information with 360 Spectra Limited, a company incorporated in England and Wales with company number 16282783 (“Spectra”), in order to enable Spectra to provide and operate the Dashboard and associated reporting services.

5.2.2 The categories of information that may be shared with Spectra include personal data relating to the relevant engagement that is necessary for the operation of the Dashboard.

5.2.3 Where we share personal data with Spectra in our capacity as a processor (i.e., personal data provided to us by a client in connection with a royalty audit), we will only do so where the relevant client has provided their consent or instruction to such sharing, and we will ensure that appropriate contractual arrangements are in place with Spectra governing its use of that personal data.

5.2.4 Where we share personal data with Spectra in our capacity as a controller (i.e., client contact information), the legal basis for such sharing is your consent or, where applicable, our legitimate interests in providing the Dashboard service to you.

5.2.5 Use of the Dashboard is subject to Spectra’s own terms of use and privacy practices. We recommend that you review Spectra’s privacy policy for further information about how Spectra processes your personal data.

5.3 International Transfers

We will not transfer your personal data outside of the United Kingdom or the European Economic Area unless appropriate safeguards are in place in accordance with applicable data protection legislation. If any such transfer becomes necessary, we will notify you and ensure that the transfer is carried out in compliance with the UK GDPR and any applicable guidance from the Information Commissioner’s Office (“ICO”).

6. Data Retention

6.1 We retain personal data only for as long as is necessary for the purposes for which it was collected,
or as required by law or regulation.

6.2 The key retention periods we apply are as follows:

  • Client contact and engagement data: retained for the duration of our business relationship and for a period of 6 years thereafter, in accordance with the Limitation Act 1980;
  • Enquiry and correspondence data: retained for 2 years from the date of last contact, unless the enquiry leads to an engagement;
  • Financial and invoicing records: retained for 6 years from the end of the relevant financial year, in accordance with our obligations under applicable tax and company law; and
  • Processor data (third-party personal data provided by clients): retained only for the duration of the relevant engagement and deleted or returned to the client promptly upon termination, in accordance with the terms of the applicable agreement with such client.

6.3 Where personal data is no longer required, we will delete or anonymise it securely.

7. Security

7.1 We take the security of personal data seriously and implement appropriate technical and organisational measures to protect personal data against accidental loss, destruction, alteration, unauthorised disclosure or access.

7.2 Where we share personal data with third parties (including Spectra), we take steps to ensure that
those parties have appropriate security measures in place.

7.3 In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO and, where required, affected individuals, in accordance with our obligations under the UK GDPR.

8. Your Rights

8.1 Where we process your personal data as a controller, you have the following rights under the UK
GDPR, subject to applicable exemptions:

  • Right of access: the right to request a copy of the personal data we hold about you;
  • Right to rectification: the right to ask us to correct inaccurate or incomplete personal data;
  • Right to erasure: the right to ask us to delete your personal data in certain circumstances;
  • Right to restriction: the right to ask us to restrict our processing of your personal data in certain circumstances;
  • Right to data portability: the right to receive your personal data in a structured, commonly used and machine-readable format in certain circumstances;
  • Right to object: the right to object to our processing of your personal data where we rely on legitimate interests as our legal basis; and
  • Rights in relation to automated decision-making: the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, where applicable.

8.2 If you wish to exercise any of these rights, please contact us using the contact details set out in Section 2.2. We will respond to your request within one month of receipt, in accordance with the UK GDPR. We may ask you to verify your identity before responding to your request.

8.3 Please note that if you are an individual whose personal data was provided to us by one of our clients in connection with a royalty audit, your rights should be exercised directly against that client as controller. We will, however, cooperate with our clients in responding to your requests.

9. Complaints

9.1 If you have any concerns about how we handle your personal data, we encourage you to contact us in the first instance using the details in Section 2.2 so that we can seek to resolve your concern.

9.2 You also have the right to lodge a complaint with the Information Commissioner’s Office (“ICO”), the
UK supervisory authority for data protection matters, at any time:

  • Website: www.ico.org.uk
  • Telephone: 0303 123 1113
  • Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

10. Changes to This Policy

10.1 We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. The date at the top of this policy indicates when it was last updated.

10.2 Where changes are material, we will take reasonable steps to bring the updated policy to your attention.