0
Skip to Content
The Outside Look
Home
Five ways to work with us
Customer problems
People Problems
How we investigate
Questions people ask us
Book now
The Outside Look
Home
Five ways to work with us
Customer problems
People Problems
How we investigate
Questions people ask us
Book now
Home
Five ways to work with us
Customer problems
People Problems
How we investigate
Questions people ask us
Book now

Privacy Policy

We need some information to answer enquiries, manage bookings and do our work properly.

We keep that information proportionate to what we actually need. Our starting point is simple: record the pattern rather than the person wherever we can.

Who we are

The Outside Look Ltd is responsible for the personal information described in this policy.

Company number: SC901167
Registered office: 48 West George Street, Glasgow, G2 1BP
Contact: hello@theoutsidelook.scot

What information we may use

Depending on how you work with us, this may include:

your name and contact details;
booking and service information;
payment and transaction references — we do not routinely receive or store full card details;
communications between you and us;
information provided during a Private Lab or MOT;
structured diagnostic notes and limited supporting evidence;
accessibility requirements where you choose to tell us about them;
marketing preferences;
complaints, corrections and dispute information;
website and cookie information; and
photographs where you have specifically agreed to identifiable marketing photography.

During diagnostic work we may also see limited information about staff, customers, applicants, suppliers or other people connected with the business we are looking at.

We normally need the pattern or process, not those people’s identities, so we avoid copying identifiers where we can.

Why we use information

We use personal information to:

answer enquiries;
manage bookings and payments;
provide Masterclasses, Clinics and private work;
carry out independent diagnostic work;
prepare and deliver reports;
make reasonable accessibility adjustments;
manage complaints and corrections;
keep appropriate accounting, tax and legal records;
protect our systems and investigate incidents; and
send marketing emails where somebody has separately asked us to.

Our lawful bases

Depending on what we are doing, we rely on:

Contract — where information is needed to provide a service to an individual customer.

Legitimate interests — for proportionate business administration, independent diagnostic work, responding to complaints and maintaining a limited defence record.

Legal obligation — where we need information for tax, accounting or another legal requirement.

Consent — for things such as future marketing emails, identifiable marketing photography and, where genuinely necessary, retaining health or disability information for an accessibility adjustment.

Consent can be withdrawn where consent is the basis we rely on.

Staff and other participants

If we speak directly to somebody as part of a diagnostic, we give them short privacy information at or before collecting information from them.

Participation is optional where our methodology uses staff input.

We normally use written notes rather than recording audio or video, and we report staff evidence thematically rather than attributing comments to named individuals.

In very small teams, we cannot promise that nobody could ever infer who contributed a particular theme.

Information we see indirectly

We may sometimes see personal information in a client’s systems, documents or processes.

Our default is to observe what matters and record a de-identified pattern rather than copy the person’s identity.

If we deliberately retain identifiable information obtained indirectly, we will deal with the relevant transparency requirements rather than simply assume the client has done that for us.

Sensitive information

Our normal diagnostic method is designed not to collect special-category or criminal-offence information.

If sensitive information is volunteered incidentally, we do not probe unnecessarily and we minimise, redact or delete it where practical.

For accessibility, tell us what adjustment would help, rather than giving us a medical history.

If we genuinely need to retain health or disability information to provide an adjustment, we will keep only what is necessary and obtain the appropriate permission.

AI-supported work

We may use an approved ChatGPT Business workspace to support activities such as structuring evidence, finding patterns, challenging analysis and drafting.

We use minimum necessary information, keep client work separated, do not use AI as the diagnostic decision-maker and do not routinely put special-category information or raw lists of customers/applicants into AI.

The Outside Look remains responsible for all professional findings and recommendations.

Material records are kept in Microsoft 365 rather than ChatGPT, and client AI projects are deleted when the engagement closes.

Who we share information with

Where necessary, information may be processed through suppliers that help us operate the business, such as:

Squarespace and Acuity for our website and bookings;
Stripe for card payments;
Microsoft 365 for business records and communications;
Xero for accounting; and
OpenAI/ChatGPT Business for approved AI-supported work.

We may also share information where reasonably necessary with insurers, professional advisers, regulators, law enforcement or other bodies where required or permitted by law.

We do not sell personal information.

International processing

Some of our technology providers may process information outside the UK.

Where this happens, we rely on the contractual and legal transfer safeguards used by the relevant supplier rather than promising that all processing happens only in the UK.

How long we keep information

Private-work core defence file: normally 6 years from closure.

Working evidence, unnecessary screenshots, drafts and transient notes: normally deleted at the 30-day engagement closure point unless genuinely required in the core file.

Client ChatGPT project: deleted at closure after material outputs are preserved in Microsoft 365.

Masterclass and Clinic operational attendee information: normally 90 days, except information needed for accounting/payment records or separately consented marketing.

Accounting and company records: kept for the applicable statutory period, normally around 6 years.

Complaint, claim or legal hold: relevant information may be kept until the matter is concluded.

We review retention by purpose rather than keeping everything indefinitely.

Your rights

Depending on the circumstances, you may have rights to:

access your personal information;
correct inaccurate information;
ask us to erase information;
restrict how information is used;
receive certain information in a portable form;
object to certain processing; and
withdraw consent where we rely on consent.

You also have the right to complain to the Information Commissioner’s Office.

Current ICO guidance requires privacy information to be concise, accessible and to explain purposes, retention and sharing. ICO

To exercise a privacy right, contact admin@theoutsidelook.scot

Marketing

Marketing is optional.

Booking or buying from us does not automatically subscribe you to marketing.

Where we offer an email marketing option it is separate and unticked by default. You can unsubscribe at any time.

Changes to this policy

We will review this policy when our services, technology or legal obligations materially change.

Last updated: 4 September 2026

The Outside Look Ltd
Company number SC901167
Registered in Scotland
Registered office: 48 West George Street, Glasgow, G2 1BP
hello@theoutsidelook.scot
© 2026 The Outside Look Ltd

Accessibility Statement
Cancellations & Refunds
Cookie Policy
Privacy Policy
Terms of Service