Privacy Policy
Data Controller
AMSM Consulting Ltd
Registered in England and Wales
Company No. 14109825
Registered Office: 66 Paul Street, London, EC2A 4NA
Email: info@AMSMConsulting.com
Privacy Notice
Last updated: October 2026
AMSM Consulting Ltd respects your privacy and is committed to handling personal information lawfully, fairly and securely.
This Privacy Notice explains how we collect, use, share and protect personal information when you visit our website, contact us or engage our services.
1. Who we are
AMSM Consulting Ltd is a company registered in England and Wales.
Company number: 14109825
Registered office: 66 Paul Street, London, EC2A 4NA
Email: info@AMSMConsulting.com
For the personal information described in this notice, AMSM Consulting Ltd is the data controller where we determine how and why that information is processed.
2. Information we may collect
Depending on our relationship with you, we may collect and process:
Your name and contact details
Your organisation and professional role
Information provided through our website, email or telephone
Information relating to enquiries, proposals and client engagements
Financial, invoicing and administrative information
Travel, itinerary or location information where relevant to an engagement
Information relating to protective security, threats, vulnerabilities or incidents
Technical information generated when you use our website, such as IP address, browser type and device information
Because of the nature of our work, we may sometimes process sensitive information, including health information or other special category personal data.
Where this is necessary, we will only process such information where an appropriate lawful basis and any additional legal condition required by UK data protection law applies.
3. Information obtained from other sources
Our work may require us to receive information about an individual from another person or organisation.
This may include information provided by:
Clients or their representatives
Employers or family offices
Security or medical professionals
Trusted specialist associates
Public authorities or emergency services
Publicly available sources
Other parties relevant to a legitimate security or operational requirement
Where required by law, we will provide appropriate information about the categories and sources of personal data we receive.
4. How we use personal information
We may use personal information to:
Respond to enquiries
Assess client requirements
Prepare proposals and enter into contracts
Deliver security, travel, medical coordination and related services
Plan and manage protective arrangements
Assess threats, vulnerabilities and operational risks
Coordinate trusted specialist associates and service providers
Communicate with clients and professional contacts
Manage invoicing and business administration
Protect clients, personnel and our legitimate business interests
Comply with legal, regulatory, insurance and professional obligations
Maintain the security and operation of our website and systems
We do not sell personal information.
5. Lawful bases for processing
Depending on the circumstances, we may rely on one or more of the following lawful bases:
Contract
Where processing is necessary to enter into or perform a contract.
Legal obligation
Where processing is necessary to comply with a legal requirement.
Legitimate interests
Where processing is necessary for our legitimate interests, or those of another party, and those interests are not overridden by an individual's rights and freedoms.
Our legitimate interests may include:
Providing and administering professional services
Protecting clients and personnel
Maintaining effective security arrangements
Preventing or responding to security incidents
Protecting our business, systems and confidential information
Establishing, exercising or defending legal rights
Consent
Where we have specifically requested and received consent.
Vital interests
In limited circumstances, where processing is necessary to protect someone's life or physical safety.
6. Sensitive and health information
Health information and certain other categories of personal information receive additional protection under UK data protection law.
Where AMSM processes special category personal data, including in connection with medical support, emergency response or repatriation, we will only do so where:
The processing is necessary for the relevant purpose
An appropriate lawful basis applies
Any additional legal condition required for special category data is satisfied
We seek to collect and use only the information that is necessary and proportionate for the relevant purpose.
7. Sharing personal information
We only share personal information where there is a legitimate and lawful reason to do so.
Depending on the engagement, this may include:
Trusted security and specialist associates
Emergency, medical and repatriation professionals
Transport and logistics providers
Professional advisers, including accountants, insurers and legal advisers
IT, communications and website service providers
Public authorities, emergency services or law-enforcement bodies where disclosure is required or permitted by law
Other organisations where disclosure is necessary to provide an agreed service
Where another organisation processes personal information on our behalf, we require appropriate contractual and security arrangements.
Where an independent specialist determines its own purposes and methods of processing, it may act as a separate data controller and will be responsible for its own data protection obligations.
8. Our global network
AMSM works with a trusted global network of specialist associates developed through decades of operational experience.
Where an assignment requires international security, medical, logistical or other specialist capability, limited personal information may need to be shared with relevant associates or service providers.
We apply the principle of data minimisation and seek to share only the information reasonably necessary for the purpose.
9. International transfers
Some assignments may require personal information to be transferred or made accessible outside the United Kingdom.
Where UK data protection rules governing international transfers apply, we will use an appropriate legal mechanism and, where necessary, additional safeguards to protect the information.
10. How long we keep information
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected and for any applicable legal, contractual, regulatory, insurance or accounting requirements.
Retention periods may depend on:
The nature and sensitivity of the information
The purpose for which it was collected
The duration of the client relationship
Relevant legal limitation periods
Tax, accounting, insurance or regulatory requirements
The need to establish, exercise or defend legal claims
Information that is no longer required will be securely deleted, destroyed or anonymised where appropriate.
11. Protecting your information
Confidentiality and discretion are fundamental to the way AMSM operates.
We use proportionate technical and organisational measures designed to protect personal information against:
Unauthorised access
Accidental loss
Misuse
Alteration
Unauthorised disclosure
Access to sensitive client or operational information is restricted to those with a legitimate need to receive it.
12. Your rights
Depending on the circumstances, UK data protection law may give you the right to:
Request access to personal information we hold about you
Request correction of inaccurate or incomplete information
Request deletion of your personal information
Request restriction of processing
Object to certain types of processing
Request transfer of your information in certain circumstances
Withdraw consent where processing is based on consent
These rights are not absolute and legal exemptions may apply.
Your right to object
Where we process your information on the basis of legitimate interests, you may have the right to object to that processing.
To exercise any of your rights, contact:
