Legal
Privacy Policy
Last updated: 24 June 2026
How we collect, use, protect and retain your personal data under UK GDPR and the Data Protection Act 2018.
1. Who We Are
Patterdale Recovery Limited ("we", "us", "our") is a company registered in England and Wales (Company No. 11933192), incorporated on 8 April 2019. Our registered office is at Manor House, 35 St Thomas's Road, Chorley, Lancashire, England, PR7 1HP.
We are registered with the Information Commissioner's Office (ICO) as a data controller under registration number ZA789012. For any data protection queries, please contact our Data Protection Officer at privacy@patterdalerecovery.co.uk.
This privacy policy applies to all personal data we collect and process through our website, client portal, consultation forms, email communications, and telephone interactions.
2. Data We Collect
Personal data you provide directly: full name, email address, telephone number (including country code), country of residence, details of the fraud you have experienced (including scam type, platforms used, amounts involved), financial information relevant to your case (bank statements, transaction records, cryptocurrency wallet addresses), and any documents or evidence you upload through our secure portal.
Data collected automatically: IP address, browser type and version, operating system, device type, pages visited and time spent on each page, referring website, and approximate geographic location (country/city level).
Data from third parties: information shared by law enforcement agencies, financial institutions, or legal partners acting on your behalf, with your explicit consent.
Special category data: in rare cases, we may process health-related information if relevant to your case (e.g., evidence of emotional distress caused by the fraud). This is processed only with your explicit consent.
3. Legal Basis for Processing
Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we process your personal data on the following legal bases:
Consent - when you submit your information through our contact or consultation forms, you provide explicit consent for us to process your data for the purpose of assessing and managing your case.
Contract performance - when you engage our services, we process your data as necessary for the performance of the contract between you and Patterdale Recovery Limited.
Legitimate interests - we process data for our legitimate business interests including service improvement, fraud prevention, internal analytics, and maintaining client relationships, provided these interests do not override your fundamental rights.
Legal obligations - we may process data where required to comply with legal obligations, including anti-money laundering regulations, financial reporting requirements, and cooperation with law enforcement.
4. How We Use Your Information
We use your personal data for the following purposes: assessing the viability of your case and providing an initial consultation; conducting forensic investigations including blockchain analysis, asset tracing, and evidence gathering; communicating with you about your case progress via your preferred contact method; coordinating with our legal partners, law enforcement agencies, and international investigators; processing recovered funds and managing fee payments; complying with regulatory obligations and responding to lawful requests; improving our website, services, and client experience; sending relevant updates and communications (with your consent where required).
5. Third-Party Recipients
We share your data only when necessary and with appropriate safeguards in place:
Legal partners - solicitors and barristers who provide legal services for your case, under their own professional confidentiality obligations and regulatory frameworks.
Investigation partners - specialist forensic analysts and investigators working under non-disclosure agreements and our data processing instructions.
Financial institutions - banks, cryptocurrency exchanges, and payment processors where necessary to trace, freeze, or recover funds.
Law enforcement - Action Fraud, the National Crime Agency, and international equivalents, where you have consented or where legally required.
Technology providers - secure hosting, encrypted communication, and case management platforms, all operating under data processing agreements compliant with UK GDPR.
We never sell your personal data to third parties. All data sharing is documented and subject to appropriate contractual safeguards.
6. International Data Transfers
Given the international nature of fraud investigation, some of your data may be transferred to countries outside the UK and European Economic Area (EEA). This occurs when: the fraud involves overseas entities, we engage international legal or investigation partners, or we need to interact with foreign financial institutions or exchanges.
We ensure adequate protection for all international transfers through: UK-approved Standard Contractual Clauses (SCCs), data processing agreements with all international partners, assessment of the receiving country's data protection adequacy, and additional safeguards where required by the Information Commissioner's Office.
We only transfer data to countries and organisations that provide an adequate level of protection as determined by UK law, or where appropriate safeguards are in place.
7. Data Retention Periods
Case data - retained for 7 years after case closure, as required by financial regulations and anti-money laundering obligations.
Contact information - retained for 3 years after last contact, or until you request deletion.
Financial records - retained for 7 years as required by HMRC and financial regulatory requirements.
Marketing and communications data - retained until you withdraw consent or opt out.
Website analytics data - anonymised after 26 months.
Evidence and documents - retained for the duration of your case plus 7 years, then securely destroyed.
You may request deletion of your data at any time (subject to legal retention obligations) by contacting our Data Protection Officer.
8. Your Data Subject Rights
Under UK GDPR and the Data Protection Act 2018, you have the following rights:
Right of access - you can request a copy of all personal data we hold about you.
Right to rectification - you can request correction of inaccurate or incomplete data.
Right to erasure - you can request deletion of your data (subject to legal retention obligations).
Right to restrict processing - you can request that we limit how we use your data.
Right to data portability - you can request your data in a structured, machine-readable format.
Right to object - you can object to processing based on legitimate interests.
Right to withdraw consent - where processing is based on consent, you can withdraw it at any time.
To exercise any of these rights, please contact our Data Protection Officer at privacy@patterdalerecovery.co.uk. We will respond within 30 days. If you are dissatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office at ico.org.uk.
9. Security Measures
We implement comprehensive technical and organisational security measures to protect your personal data:
Encryption - all data in transit is protected by TLS 1.3 encryption. Stored documents and sensitive data are encrypted using AES-256 encryption.
Access controls - role-based access with two-factor authentication for all systems containing personal data. Staff access is limited to the minimum necessary for their role.
Infrastructure - our servers are hosted in UK-based, ISO 27001 certified data centres with physical security, fire suppression, and redundant power supplies.
Monitoring - continuous security monitoring, intrusion detection, and regular penetration testing conducted by independent security firms.
Staff training - all staff undergo regular data protection and security awareness training. Investigators handling sensitive evidence receive additional specialist training.
Incident response - we maintain a documented data breach response procedure and will notify affected individuals and the ICO within 72 hours of any qualifying breach.
11. Children's Privacy
Our services are not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately and we will take steps to delete such information.
12. Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices or applicable law. Any material changes will be notified via a prominent notice on our website and, where appropriate, by email. The "Last updated" date at the top of this page indicates when this policy was last revised. We encourage you to review this policy periodically.
13. Contact Information
For any privacy-related queries, data subject requests, or complaints:
Data Protection Officer, Patterdale Recovery Limited, Manor House, 35 St Thomas's Road, Chorley, Lancashire, England, PR7 1HP.
Email: privacy@patterdalerecovery.co.uk | Phone: +44 7886 080951.
You also have the right to lodge a complaint with the Information Commissioner's Office: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Website: ico.org.uk | Helpline: 0303 123 1113.
Last updated: 24 June 2026
