This privacy policy explains how Meet Your Past collects, uses, and protects your personal information when you use this website or engage our services.
We take data privacy seriously. The personal information you share with us, including any sensitive family history details, is handled with care and used only for the purposes set out in this policy.
This policy applies to information collected via meetyourpast.co.uk and through direct correspondence by phone, email, or in person. It is governed by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Who we are
Meet Your Past is a professional family history investigation service operated by Gary Skerritt, based in Nottingham, England.
For the purposes of UK data protection law, Gary Skerritt trading as Meet Your Past is the data controller responsible for your personal data.
Data controller details
If you have any questions about how we handle your personal data, please contact us using the details below.
Data we collect
We collect only the information we need to provide our services and respond to your enquiries. The categories of personal data we may collect are set out below.
Information you give us directly
- Contact details. Your name, email address, postal address, and telephone number when you make an enquiry, book a consultation, or instruct us.
- Family information. Names, dates, locations, and other details about your family members that you provide to enable us to carry out research on your behalf.
- Correspondence. The content of any emails, letters, or messages you send us, and notes from telephone calls or home visits.
- Payment information. Billing details when you pay for our services. We do not store full card numbers. Payments are processed by secure third-party providers.
- DNA and biological data. If your investigation involves DNA analysis, we may discuss test results or match data that you share with us. We do not administer DNA tests directly or hold raw DNA data on our systems.
Information collected automatically
- Website usage data. Pages visited, time spent on the site, referring pages, and browser type, collected via standard web analytics tools.
- Device and technical data. IP address, browser type and version, operating system, and screen resolution.
- Cookie data. See Section 9 for full details on cookies.
We do not knowingly collect data from children under the age of 16. If you are under 16 and wish to use our services, please ask a parent or guardian to contact us on your behalf.
How we use your data
We use the personal information you provide for the following purposes.
| Purpose | What this involves | Lawful basis |
|---|---|---|
| Enquiry handling | Responding to your contact form submissions, emails, or calls | Legitimate interests |
| Service delivery | Carrying out family history research on your behalf | Contract performance |
| Client communication | Keeping you informed about research progress and findings | Contract performance |
| Payment processing | Invoicing and processing payments for services | Contract performance |
| Legal compliance | Keeping records as required by law, including financial records | Legal obligation |
| Website improvement | Understanding how the website is used to improve content and functionality | Legitimate interests |
| Marketing | Sending information about services, only where you have given consent | Consent |
We will never sell your personal data or share it with third parties for their own marketing purposes.
Lawful basis for processing
Under UK GDPR, we must have a lawful basis to process your personal data. Depending on the context, we rely on one or more of the following.
- Contract performance. When we carry out research on your behalf or provide any other services you have instructed us to deliver, processing your data is necessary to fulfil that contract.
- Legitimate interests. For handling initial enquiries, improving our website, and maintaining the security of our systems, we rely on legitimate interests, provided those interests are not overridden by your rights.
- Legal obligation. We may be required to process certain data in order to comply with financial record-keeping requirements or other legal obligations.
- Consent. For any optional marketing communications, we will ask for your explicit consent before sending them. You may withdraw consent at any time by contacting us or using the unsubscribe link in any communication we send.
Sharing your data
We do not share your personal data with third parties except in the following limited circumstances.
- Service providers. We use a small number of trusted third-party services to operate the business, including email hosting, website hosting, and payment processing. These providers act as data processors and are bound by contractual obligations to handle your data securely and only as instructed.
- Archives and record offices. When making research enquiries on your behalf, we may share limited information, such as a name and approximate date, with archives, record offices, or genealogical databases. Only the minimum information needed for the enquiry is shared.
- Legal requirements. We may disclose personal data where required to do so by law, a court order, or a regulatory authority.
- Business transfer. In the unlikely event that the business is transferred or sold, client data may be transferred to a new operator, who would be bound by the same obligations under this policy.
We do not transfer your personal data outside the United Kingdom without ensuring appropriate safeguards are in place. Where third-party services are based outside the UK, we confirm those services meet adequate protection standards before using them.
Research data and third-party individuals
Family history research by its nature involves information about people other than the client, including deceased individuals, living relatives, and in some cases sensitive personal details such as adoption, paternity, or criminal records.
Deceased individuals
UK GDPR does not apply to the personal data of deceased individuals. Historical records relating to people who have died are processed under our standard research methodology and may be included in the research report delivered to you.
Living individuals
Where research uncovers information about living people, we take care to consider the privacy implications before including that information in a report. We will discuss any sensitive findings with you before finalising research outputs. We do not provide the personal addresses or contact details of living individuals.
Sensitive findings
Some investigations, particularly those involving DNA matching or unknown parentage, may produce unexpected or emotionally significant discoveries. We handle such findings with discretion. Our research methodology page sets out how we approach sensitive discoveries.
You are responsible for ensuring that your own use of information we provide complies with applicable data protection laws, including how you handle or share details about living relatives.
How long we keep your data
We keep your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law.
| Data category | Retention period | Reason |
|---|---|---|
| Client contact details and correspondence | 7 years from end of instruction | Legal and financial record-keeping requirements |
| Research notes and findings | 7 years from delivery of report | Ability to verify research and respond to queries |
| Financial records and invoices | 7 years | HMRC requirements |
| Enquiry data (not converted to instruction) | 12 months | Follow-up purposes, then deleted |
| Website analytics data | Up to 26 months | Standard analytics retention period |
| Marketing consent records | Until consent is withdrawn, then deleted within 30 days | Consent management |
When data is no longer required, it is securely deleted or anonymised.
Your rights
Under UK GDPR, you have a number of rights in relation to your personal data. These are summarised below. To exercise any of them, please contact us at gary@meetyourpast.co.uk.
Right of access
You may request a copy of the personal data we hold about you. We will respond within one month.
Right to rectification
If any information we hold about you is inaccurate or incomplete, you may ask us to correct it.
Right to erasure
You may ask us to delete your personal data in certain circumstances, for example if we no longer need it for the purpose it was collected.
Right to restrict processing
You may ask us to pause the processing of your personal data in certain circumstances while a dispute is resolved.
Right to data portability
Where we process your data by automated means and on the basis of consent or contract, you may request a copy in a commonly used format.
Right to object
You may object to processing based on legitimate interests, including direct marketing. We will comply unless we can demonstrate a compelling reason to continue.
We will not charge a fee for exercising your rights in most circumstances. We may ask you to verify your identity before responding to a request. If you are not satisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
Cookies
Cookies are small text files placed on your device when you visit a website. They help us understand how the site is used and improve your experience.
Cookies we use
| Cookie type | Purpose | Duration |
|---|---|---|
| Essential | Necessary for the website to function. Cannot be disabled. | Session or up to 12 months |
| Analytics | Help us understand how visitors use the site, which pages are most visited, and where visitors come from. No personally identifiable information is collected. | Up to 26 months |
| Preference | Remember choices you make, such as language preferences or cookie consent settings. | Up to 12 months |
We use strictly necessary cookies to operate the site and, with your consent, marketing cookies to understand how visitors find us and to deliver relevant advertising via Meta (Facebook) Pixel. You can manage your cookie preferences at any time. For full details of every cookie we use, their purposes, and their durations, please see our Cookie Policy.
Security
We take reasonable steps to protect your personal data from unauthorised access, loss, or disclosure. These steps include:
- Secure encrypted connections (HTTPS) across the entire website.
- Password-protected systems and devices used in the research process.
- Using reputable, secure third-party services for email, payments, and file storage.
- Limiting access to personal data to only those who need it to carry out their work.
No method of digital transmission or storage is completely secure. While we work hard to protect your information, we cannot guarantee absolute security. If you have concerns about sharing sensitive information, please contact us to discuss the most appropriate way to do so.
If we become aware of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and inform you as soon as practicable.
Changes to this policy
We may update this privacy policy from time to time, for example to reflect changes in the law, our services, or the way we operate. The date at the top of this page indicates when the policy was last revised.
If we make material changes, we will take reasonable steps to notify you, which may include placing a notice on the website or contacting you directly if you are a current client.
We encourage you to review this page periodically. Continued use of our services following any changes constitutes acceptance of the updated policy.
Contact us
If you have any questions about this privacy policy, wish to exercise any of your rights, or have a concern about how we handle your personal data, please get in touch.
Get in touch about your data
We aim to respond to all privacy-related enquiries within 5 working days. For formal subject access requests, we will respond within one month as required by law.