Privacy Policy

Khan & Brown Commercial Services

Last updated: 13 March 2026

Khan & Brown Commercial Services (“we”, “us”, “our”) is committed to protecting your privacy and handling your personal data in a transparent, secure, and lawful manner. This Privacy Policy explains how we collect, use, store, and protect personal information when you visit our website https://khanandbrown.co.uk/ (the “Website”), contact us, request a free bill review, book a clarity call, or engage our commercial utility cost optimisation services.

For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Khan & Brown Commercial Services is the data controller.

1. Information We Collect

We may collect the following types of personal data:

  • Identity and contact data: name, business name, job title, email address, telephone number, postal address.
  • Business and utility-related data: details of your current energy, water, or connectivity contracts, utility bills, meter readings or numbers, consumption data, supplier information, and payment history (where provided for review or audit purposes).
  • Technical data: IP address, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access the Website (collected automatically via cookies and similar technologies).
  • Usage data: information about how you use our Website, services, and interactions (e.g. pages visited, time spent, referral sources).
  • Marketing and communications data: your preferences for receiving marketing from us and your communication history with us.

We do not knowingly collect special category data (e.g. health, racial or ethnic origin) or data relating to criminal convictions, nor do we collect information about children.

2. How We Collect Your Information

We collect data:

  • Directly from you when you fill in forms on our Website (e.g. contact form, free bill review request), correspond with us by phone, email, or otherwise, or provide documents for a cost health check or contract review.
  • Automatically through your use of the Website (via cookies, server logs, and similar technologies).
  • From third parties, such as utility suppliers (with your consent or where lawful), business directories (where publicly available), or our trusted partners (e.g. Dojo for payment solutions, where relevant and disclosed).

3. How We Use Your Information

We process your personal data for the following purposes and lawful bases:

  • To provide our services (e.g. bill reviews, cost health checks, meter installation support, contract negotiations) — performance of a contract or steps prior to entering a contract.
  • To respond to enquiries, provide quotations, or arrange clarity calls — performance of a contract or legitimate interests (running our business effectively).
  • To comply with legal obligations (e.g. record-keeping, anti-money laundering where applicable) — legal obligation.
  • To send you service-related communications or updates about your bill review or contract — performance of a contract or legitimate interests.
  • Where you have given consent, to send marketing communications about similar services that may interest your business — consent (you can withdraw this at any time).
  • To improve our Website and services, for analytics, and to detect fraud/security issues — legitimate interests.

4. Sharing Your Information

We may share your personal data with:

  • Utility suppliers, network operators, or meter installation providers (only as necessary to deliver our services and with your knowledge/consent where required).
  • Our business partners (e.g. Dojo for payment solutions).
  • Professional advisers (e.g. accountants, lawyers, insurers).
  • Regulators, authorities, or law enforcement where legally required.
  • Third-party service providers (e.g. IT/hosting providers, email platforms) acting as processors under strict contractual terms.

We do not sell your personal data.

5. International Transfers

We do not routinely transfer personal data outside the UK. Where any transfer occurs (e.g. to cloud providers), we ensure appropriate safeguards are in place (e.g. UK International Data Transfer Agreement or adequacy decision).

6. Data Security

We implement appropriate technical and organisational measures to protect your data against unauthorised access, loss, or destruction. Unfortunately, no transmission over the internet is 100% secure.

7. Data Retention

We keep personal data only for as long as necessary for the purposes set out in this policy, or to meet legal, accounting, or reporting obligations. Data relating to bill reviews or contracts is typically retained for 6–7 years after the end of the relevant engagement (for tax and legal purposes). Marketing data is kept until you unsubscribe or object.

8. Your Rights

Under UK data protection law you have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Erase data (in certain circumstances)
  • Restrict processing
  • Object to processing (including for direct marketing)
  • Data portability
  • Withdraw consent (where processing is based on consent)

To exercise these rights, contact us using the details below. You also have the right to complain to the Information Commissioner’s Office (ico.org.uk).

9. Cookies

Our Website uses cookies and similar technologies. View our full Cookie Policy.

10. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact:

Khan & Brown Commercial Services
Email: zig@khanandbrown.co.uk or ste@khanandbrown.co.uk
Telephone: Zig: 07983 041 015 or Ste: 07900 018 552
Postal address: 31 Hazel Grove, Bacup, Rossendale, Lancashire, OL13 9XT

We may update this Privacy Policy from time to time.

Changes will be posted on this page with an updated revision date.