Cohanim Limited trading as Cohanim Architecture (“Cohanim Architecture”, “we”, “us”, the "company" or “our”) is committed to protecting your privacy and handling personal information responsibly and transparently. For the purposes of UK data protection law, including the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018, the data controller is:
Cohanim Limited t/a Cohanim ArchitectureCompany No. 09826097
Registered in England and Wales
The Old Brewery House
86 New Street
Henley-on-Thames
Oxfordshire
RG9 2BT
United Kingdom
Privacy enquiries may be sent to
office.ops@cohanimarchitecture.com with "Privacy Enquiry" written in the subject line.
1. Information we collect
We may collect and process personal information when you contact us, use our website, enquire about a project, become a client, supplier or professional contact, apply to work with us, attend a meeting or communicate with our studio.
This may include:your name, address, email address, telephone number, job title and organisation;
the address or location of a property or proposed project;
information you provide about a property, development, planning application, listed building, landholding or other project;correspondence, enquiries and records of our communications with you;
CCTV images and footage captured at our office premises via standard security systems, together with access-control information such as key issue, return and entry records relating to staff, visitors and other authorised persons where applicable;
architectural drawings, plans, photographs, decision notices, reports and other files uploaded through our website or otherwise provided to us;information relating to existing or prospective clients, consultants, contractors and other project participants;
CVs, portfolios, employment history, qualifications and other information submitted in connection with recruitment, employment, internships or placements;information recorded in our client relationship management systems;
meeting and telephone-call information, including recordings, transcripts, summaries or voice notes where recording or transcription is used;
technical information relating to your use of our website, including IP address, browser and device information, pages visited, referring websites and analytics information; and
information obtained from publicly accessible sources where relevant to our professional or business activities.
Where you provide information about another person, you should ensure that you are entitled to provide that information to us.
The UK GDPR requires organisations to provide individuals with clear information about the categories of information collected, the purposes for which it is processed, the relevant lawful bases, recipients and retention periods.
2. How and why we use your informationWe may process personal information for the following purposes:
Enquiries and prospective projects.We use information submitted through our website, by email, telephone or otherwise to understand your enquiry, assess a site or project, respond to you, arrange meetings and determine whether we are able to provide professional services.Our lawful basis will normally be taking steps at your request before entering into a contract and/or our legitimate interests in operating our architectural and consultancy practice.
Providing architectural and consultancy services.Where you appoint us, we process personal information to administer the appointment, provide architectural, planning, heritage, design and related professional services, coordinate consultants and contractors, maintain project records, invoice for services and manage the professional relationship.The lawful basis will normally be performance of a contract, compliance with legal obligations and our legitimate interests in managing and documenting our professional services.
Client and contact relationship management.We maintain contact and project information within our CRM and related business systems so that we can manage current and prospective client relationships, professional contacts, enquiries and business development.We generally rely on our legitimate interests in managing our practice and maintaining appropriate business records.
Premises security, CCTV and access control We operate CCTV at our office premises and may maintain key and access-control records relating to persons entering or using the premises. CCTV and access-control systems are used for the security of our staff, visitors, premises, property, equipment and confidential or client information held at the premises; to prevent, detect and investigate theft, unauthorised access, damage or other security incidents; and to maintain an appropriate record ofphysical access to the premises.
We generally rely on our legitimate interests in maintaining the physical and information security of our business, protecting staff, visitors, property and confidential information, and preventing and investigating security incidents. CCTV and access-control information will not ordinarily be used for unrelated purposes.
CCTV footage or access records may be reviewed where reasonably necessary in connection with a security incident, accident, suspected unlawful activity, insurance matter, legal claim or other legitimate investigation, and may where appropriate be disclosed to law-enforcement authorities, insurers, professional advisers or other persons where disclosure is necessary or permitted by law.
Marketing and business development.We may use contact details to provide news, project updates, invitations, publications or information about services which we reasonably believe may be relevant to you.Where consent is legally required, we will obtain it. Where permitted, we may rely upon our legitimate interests in promoting our professional services. You may object to direct marketing or unsubscribe at any time.Electronic marketing is also subject to the Privacy and Electronic Communications Regulations (“PECR”). In particular, the rules differ between corporate subscribers and individuals, sole traders and certain partnerships.
Calls, meetings, recording and transcription.Some telephone calls, online meetings or other business communications may be recorded, transcribed or summarised using Zoom or other communication and productivity systems.
We may use these records to:maintain an accurate record of project discussions and instructions;prepare meeting or telephone notes;improve continuity and quality of service;resolve discrepancies concerning instructions or discussions; andprovide appropriate internal training and quality control.Where a call or meeting is being recorded, participants will be informed that recording is taking place and the purpose of that recording.
We generally rely on our legitimate interests in maintaining accurate business records, quality assurance and training, subject to those interests being balanced against the rights and expectations of participants.ICO guidance recognises that business calls may in appropriate circumstances be recorded for evidence, training or quality-control purposes, but requires callers to be told that recording is taking place and why, should the call be too brief to facilitate this (e.g. the person phoning the company is talking with speed and does not appear to have the time to facilitate a typical conversation by virtue of time constraints on their side) the prospective enquirier/contact should contact us directly to request delivery or confirmation of any data held emanating from that call.
Recruitment.We process CVs, portfolios and other application information to assess candidates, communicate about vacancies, internships or placements and administer recruitment.We generally rely on taking steps before entering into a contract, our legitimate interests in recruitment and, where applicable, our legal obligations.
Legal, regulatory and professional obligations.We may retain and use information where necessary for accounting, taxation, insurance, professional indemnity, contractual, regulatory, dispute-resolution or legal purposes.
3. Information submitted through our website
Our website enquiry form may collect your:enquiry type;name;email address;site address or postcode;telephone number;project description; andplans, photographs, drawings, decision notices and other uploaded documents.
We use this information primarily to assess and respond to your enquiry.Information submitted through an enquiry form will not automatically be treated as consent to receive unrelated electronic marketing where consent is required by law.You should avoid including unnecessary confidential, sensitive or special-category personal information in an enquiry or uploaded document.
4. Who we may share information with
Where reasonably necessary, we may disclose personal information to organisations assisting us in operating our practice or providing professional services, including:
architects, planning consultants, engineers, quantity surveyors, surveyors such as topographical, valuation or other measured surveyors, party wall professionals and other professional consultants including but not limited to;
contractors and suppliers engaged in connection with a project;
local planning authorities,
building control bodies and private inspectors,
statutory consultees and other public authorities where relevant;
professional advisers, insurers, accountants and legal advisers;
website hosting and technology providers;
artificial intelligence platforms in pursuing general preparatory assistance,;
email,
document-management,
cloud-storage and CRM providers;
Google, including Google Analytics and Google Maps;
Meta / Instagram, where Instagram services or content are incorporated into our website;
Zoom and Teams, where it/they is/are used for meetings, calls, recording, transcription or meeting notes;
website and IT support providers; andregulators, courts, law-enforcement authorities or other bodies where disclosure is required or permitted by law.
Third parties processing personal information on our behalf are required to process it appropriately and in accordance with applicable data-protection requirements.
5. International transfers
Some technology and cloud-service providers we use may store or process personal information outside the United Kingdom.Where personal information is transferred internationally, we take reasonable steps to ensure that an appropriate lawful transfer mechanism is in place, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved Standard Contractual Clauses or another mechanism permitted under UK data-protection law.
6. How long we keep information
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected and to satisfy professional, legal, accounting, insurance and regulatory requirements.Retention periods will depend upon the nature of the information.
In general: unsuccessful recruitment information will normally be retained for up to eighteen months after completion of the relevant recruitment exercise unless there is a legitimate reason, or permission, to retain it longer;
enquiry and prospective-client information may be retained while an enquiry remains active and for a reasonable period afterwards;
client and project records may be retained for the periods necessary to meet contractual, professional-indemnity, limitation and regulatory requirements;
CRM information may be retained while there is an ongoing business or professional relationship, subject to periodic review;marketing information will be retained until you unsubscribe, object, or the information is no longer reasonably required. We may retain limited suppression information after an opt-out to ensure that your preference continues to be respected; andrecordings and transcripts should be retained only for so long as required for the purposes for which they were made.
CCTV footage is retained only for the period reasonably necessary for the security purposes for which it was collected and is then securely deleted, unless particular footage needs to be retained for longer in connection with an identified incident, investigation, insurance matter or legal claim. Access-control and key records are similarly retained only for so long as reasonably necessary for security, operational, legal or evidential purposes.
7. Cookies, Google Analytics and third-party content
Our website uses cookies and similar technologies.
Some cookies are necessary for the website to function. Other technologies may be used for analytics or to provide third-party functionality.
We use
Google Analytics to understand how visitors use our website, such as which pages are visited and how visitors arrive at the site.Analytics cookies are not regarded as strictly necessary under current PECR guidance and therefore should not be placed until the visitor has provided the required consent. Our website may also include or link to services provided by third parties, including:
Google Maps; and
Instagram / Meta.
These services may collect information about your device or interaction with their content and may place their own cookies or similar technologies. Where consent is required, these services should remain disabled until the relevant consent has been given.You can change or withdraw your cookie preferences through the cookie controls available on our website.
8. Your rightsDepending upon the circumstances, UK data-protection law gives you rights including the right to:
request access to personal information we hold about you;
request correction of inaccurate or incomplete information;
request deletion of your information in certain circumstances;
request restriction of processing;object to processing based upon legitimate interests;
object at any time to processing for direct-marketing purposes;
request transfer of certain information in a portable format;withdraw consent at any time where processing is based upon consent; and complain to the Information Commissioner’s Office. These rights are subject to applicable statutory qualifications and exemptions.
To exercise a data-protection right, contact
office.ops@cohanimarchitecture.com.
9. Security
We take reasonable organisational and technical measuresdesigned to protect personal information against unauthorised access,alteration, disclosure, loss or destruction. These measures may includephysical access controls, key-management systems and CCTV at our office premises, together with appropriate electronic and organisational safeguards. Access to personal information and security records is limited to members ofstaff, consultants and service providers who reasonably require access fortheir duties or the provision of services.
10. ComplaintsIf you have a concern about how we process your personal information, please contact us in the first instance at:
office.ops@cohanimarchitecture.comYou also have the right to complain to the
Information Commissioner’s Office (ICO), the UK supervisory authority for data protection.
11. Changes to this noticeWe may update this Privacy & Data Protection Notice periodically to reflect changes to our services, systems or legal obligations.The current version will be published on this website with the date of its most recent revision.