Privacy Policy
We need some information to answer enquiries, manage bookings and do our work properly.
We keep that information proportionate to what we actually need. Our starting point is simple: record the pattern rather than the person wherever we can.
Who we are
The Outside Look Ltd is responsible for the personal information described in this policy.
Company number: SC901167
Registered office: 48 West George Street, Glasgow, G2 1BP
Contact: hello@theoutsidelook.scot
What information we may use
Depending on how you work with us, this may include:
your name and contact details;
booking and service information;
payment and transaction references — we do not routinely receive or store full card details;
communications between you and us;
information provided during a Private Lab or MOT;
structured diagnostic notes and limited supporting evidence;
accessibility requirements where you choose to tell us about them;
marketing preferences;
complaints, corrections and dispute information;
website and cookie information; and
photographs where you have specifically agreed to identifiable marketing photography.
During diagnostic work we may also see limited information about staff, customers, applicants, suppliers or other people connected with the business we are looking at.
We normally need the pattern or process, not those people’s identities, so we avoid copying identifiers where we can.
Why we use information
We use personal information to:
answer enquiries;
manage bookings and payments;
provide Masterclasses, Clinics and private work;
carry out independent diagnostic work;
prepare and deliver reports;
make reasonable accessibility adjustments;
manage complaints and corrections;
keep appropriate accounting, tax and legal records;
protect our systems and investigate incidents; and
send marketing emails where somebody has separately asked us to.
Our lawful bases
Depending on what we are doing, we rely on:
Contract — where information is needed to provide a service to an individual customer.
Legitimate interests — for proportionate business administration, independent diagnostic work, responding to complaints and maintaining a limited defence record.
Legal obligation — where we need information for tax, accounting or another legal requirement.
Consent — for things such as future marketing emails, identifiable marketing photography and, where genuinely necessary, retaining health or disability information for an accessibility adjustment.
Consent can be withdrawn where consent is the basis we rely on.
Staff and other participants
If we speak directly to somebody as part of a diagnostic, we give them short privacy information at or before collecting information from them.
Participation is optional where our methodology uses staff input.
We normally use written notes rather than recording audio or video, and we report staff evidence thematically rather than attributing comments to named individuals.
In very small teams, we cannot promise that nobody could ever infer who contributed a particular theme.
Information we see indirectly
We may sometimes see personal information in a client’s systems, documents or processes.
Our default is to observe what matters and record a de-identified pattern rather than copy the person’s identity.
If we deliberately retain identifiable information obtained indirectly, we will deal with the relevant transparency requirements rather than simply assume the client has done that for us.
Sensitive information
Our normal diagnostic method is designed not to collect special-category or criminal-offence information.
If sensitive information is volunteered incidentally, we do not probe unnecessarily and we minimise, redact or delete it where practical.
For accessibility, tell us what adjustment would help, rather than giving us a medical history.
If we genuinely need to retain health or disability information to provide an adjustment, we will keep only what is necessary and obtain the appropriate permission.
AI-supported work
We may use an approved ChatGPT Business workspace to support activities such as structuring evidence, finding patterns, challenging analysis and drafting.
We use minimum necessary information, keep client work separated, do not use AI as the diagnostic decision-maker and do not routinely put special-category information or raw lists of customers/applicants into AI.
The Outside Look remains responsible for all professional findings and recommendations.
Material records are kept in Microsoft 365 rather than ChatGPT, and client AI projects are deleted when the engagement closes.
Who we share information with
Where necessary, information may be processed through suppliers that help us operate the business, such as:
Squarespace and Acuity for our website and bookings;
Stripe for card payments;
Microsoft 365 for business records and communications;
Xero for accounting; and
OpenAI/ChatGPT Business for approved AI-supported work.
We may also share information where reasonably necessary with insurers, professional advisers, regulators, law enforcement or other bodies where required or permitted by law.
We do not sell personal information.
International processing
Some of our technology providers may process information outside the UK.
Where this happens, we rely on the contractual and legal transfer safeguards used by the relevant supplier rather than promising that all processing happens only in the UK.
How long we keep information
Private-work core defence file: normally 6 years from closure.
Working evidence, unnecessary screenshots, drafts and transient notes: normally deleted at the 30-day engagement closure point unless genuinely required in the core file.
Client ChatGPT project: deleted at closure after material outputs are preserved in Microsoft 365.
Masterclass and Clinic operational attendee information: normally 90 days, except information needed for accounting/payment records or separately consented marketing.
Accounting and company records: kept for the applicable statutory period, normally around 6 years.
Complaint, claim or legal hold: relevant information may be kept until the matter is concluded.
We review retention by purpose rather than keeping everything indefinitely.
Your rights
Depending on the circumstances, you may have rights to:
access your personal information;
correct inaccurate information;
ask us to erase information;
restrict how information is used;
receive certain information in a portable form;
object to certain processing; and
withdraw consent where we rely on consent.
You also have the right to complain to the Information Commissioner’s Office.
Current ICO guidance requires privacy information to be concise, accessible and to explain purposes, retention and sharing. ICO
To exercise a privacy right, contact admin@theoutsidelook.scot
Marketing
Marketing is optional.
Booking or buying from us does not automatically subscribe you to marketing.
Where we offer an email marketing option it is separate and unticked by default. You can unsubscribe at any time.
Changes to this policy
We will review this policy when our services, technology or legal obligations materially change.
Last updated: 4 September 2026