Privacy Notice

Last Updated: 4 August 2026

1. About This Privacy Notice

CATALA Consulting Ltd respects your privacy and is committed to protecting your personal information.

This Privacy Notice explains how we collect, use, store and share personal information when you:

  • visit our website;
  • contact us;
  • submit an enquiry;
  • book a meeting;
  • subscribe to communications;
  • become or represent a client, prospective client, supplier or business partner; or
  • otherwise interact with CATALA Consulting.

This notice also explains your rights and how you can contact us about the way we handle your personal information.

We process personal information in accordance with applicable data-protection legislation, including the UK General Data Protection Regulation, the Data Protection Act 2018, the Data (Use and Access) Act 2025 and, where applicable, the Privacy and Electronic Communications Regulations 2003.

Where the EU General Data Protection Regulation applies to particular processing activities, we will also comply with its requirements.

UK privacy information should identify the controller, purposes, lawful bases, recipients, international transfers, retention periods, individual rights and complaint rights.

2. Who We Are

The controller responsible for the personal information described in this notice is:

CATALA CONSULTING LTD
Company Number: 11373928
Registered Office: 71–75 Shelton Street, London, WC2H 9JQ, United
Correspondence Address: 71–75 Shelton Street, London, WC2H 9JQ, United Kingdom
Email: contact@catalaconsulting.co.uk
Website: catalaconsulting.co.uk

In this notice, “CATALA Consulting”, “we”, “us” and “our” refer to CATALA CONSULTING LTD.

Our privacy contact is responsible for coordinating questions, requests and complaints relating to personal information.

We have not appointed a formal Data Protection Officer. Questions concerning this notice or our use of personal information should be sent to:

Privacy Contact
Email: contact@catalaconsulting.co.uk

If another legal entity is identified as the contracting party in an agreement with you, that entity may be a separate controller for the processing described in that agreement.

3. Personal Information We Collect

Depending on how you interact with us, we may collect the following categories of personal information.

Identity and Contact Information

This may include:

  • name;
  • job title;
  • employer or company;
  • business address;
  • email address;
  • telephone number;
  • professional profile information; and
  • communication preferences.

Enquiry and Meeting Information

This may include:

  • hotel or company name;
  • hotel location;
  • number of rooms;
  • service interests;
  • commercial priorities;
  • challenges or objectives described in an enquiry;
  • meeting availability;
  • Calendly booking information;
  • meeting notes; and
  • correspondence before and after a meeting.

Client and Contract Information

This may include:

  • client contact details;
  • contractual information;
  • service requirements;
  • authorised users and system contacts;
  • invoices and payment records;
  • records of services delivered;
  • correspondence;
  • client feedback; and
  • information necessary to manage our professional relationship.

Hotel and Commercial Information

During a consulting engagement, clients may provide information such as:

  • hotel performance data;
  • occupancy, ADR and RevPAR information;
  • forecasts and budgets;
  • segment and channel information;
  • pricing and distribution data;
  • financial and profitability information;
  • operating reports;
  • technology and systems information; and
  • other commercial information required to provide our services.

Much of this information relates to a business rather than an individual. However, it may constitute personal information where it identifies or can be associated with an individual.

Website and Technical Information

This may include:

  • IP address;
  • device type;
  • operating system;
  • browser type;
  • approximate location;
  • pages visited;
  • dates and times of visits;
  • referring website;
  • interaction with website content;
  • cookie identifiers; and
  • security and diagnostic information.

Marketing Information

This may include:

  • newsletter subscriptions;
  • marketing preferences;
  • events or content in which you have shown an interest;
  • previous communications;
  • campaign engagement information; and
  • records of consent, objection or unsubscribe requests.

Information from Public and Third-Party Sources

We may obtain professional contact information from:

  • company websites;
  • professional directories;
  • LinkedIn and other professional platforms;
  • event organisers;
  • business partners;
  • referrals;
  • publicly available industry sources; and
  • existing clients or professional contacts.

We do not intentionally collect special-category information, such as information about health, religion, ethnicity, political opinions or sexual orientation, through our website.

Please do not submit sensitive personal information unless it is necessary and we have specifically requested it.

4. How We Collect Personal Information

We may collect personal information directly from you when you:

  • submit a website form;
  • contact us by email, telephone, WhatsApp or social media;
  • book a meeting through Calendly;
  • subscribe to a newsletter or mailing list;
  • respond to a survey;
  • attend an event, lecture, webinar or meeting;
  • enter into an agreement with us;
  • provide information during a consulting engagement;
  • communicate with members of our team; or
  • apply to work with or for us.

We may also collect information automatically when you use our website, subject to your cookie choices.

We may receive information from third parties, including referrals, business partners, client organisations, professional platforms and publicly available business sources.

5. How and Why We Use Personal Information

We must have a valid lawful basis for each purpose for which we process personal information. The appropriate basis depends on the purpose, necessity of the processing and our relationship with the person concerned.

Responding to Enquiries

We use identity, contact, company and enquiry information to:

  • respond to questions;
  • assess the nature of an enquiry;
  • understand a hotel’s requirements;
  • recommend an appropriate next step; and
  • arrange an introductory conversation.

Our lawful basis is normally:

  • taking steps at your request before entering into a contract; or
  • our legitimate interest in responding to genuine business enquiries and developing our business.

Scheduling and Conducting Meetings

We use contact, company, availability and meeting information to:

  • schedule meetings;
  • issue invitations and reminders;
  • provide video-conferencing details;
  • prepare for meetings;
  • maintain meeting notes; and
  • follow up after discussions.

Our lawful basis is normally:

  • taking steps at your request before entering into a contract;
  • performance of a contract; or
  • our legitimate interest in managing professional meetings efficiently.

Providing Consulting and Professional Services

We use client, contractual, commercial, financial and operational information to:

  • deliver agreed services;
  • provide analysis and recommendations;
  • manage projects;
  • access authorised hotel systems;
  • communicate with client teams;
  • issue reports and deliverables;
  • monitor performance;
  • administer the client relationship; and
  • manage changes, renewals or termination.

Our lawful basis is normally:

  • performance of a contract;
  • taking steps before entering into a contract;
  • compliance with a legal obligation; or
  • our legitimate interest in delivering and managing professional services.

Managing Our Business

We use personal information to:

  • administer our operations;
  • manage suppliers and professional advisers;
  • maintain business records;
  • manage payments and invoices;
  • prepare accounts and tax records;
  • enforce agreements;
  • establish or defend legal claims;
  • manage commercial risk; and
  • support a possible business restructuring, investment, acquisition or sale.

Our lawful basis is normally:

  • performance of a contract;
  • compliance with legal obligations; or
  • our legitimate interests in operating, protecting and developing our business.

Website Operation and Security

We use technical information to:

  • operate and maintain the website;
  • protect forms and systems from spam, fraud and misuse;
  • diagnose technical issues;
  • protect our network and information;
  • monitor website performance; and
  • maintain security logs.

Our lawful basis is normally:

  • our legitimate interest in maintaining a functional and secure website;
  • compliance with legal obligations; or
  • consent where required for a particular cookie or technology.

Website Analytics and Improvement

Where enabled, we may use website analytics to:

  • understand how visitors use the website;
  • measure website and campaign performance;
  • identify popular content;
  • improve navigation and usability; and
  • make informed marketing decisions.

Our lawful basis is consent where required by applicable cookie and electronic-communications rules.

Certain limited statistical or website-improvement technologies may qualify for an exception from consent under current UK rules. Where we rely on an exception, we will still provide appropriate information and an accessible way to object where required. The current UK rules permit limited exceptions for some low-risk statistical and functionality technologies, but advertising and intrusive tracking generally require consent.

Marketing Communications

We may use professional contact details to send:

  • newsletters;
  • industry insights;
  • invitations;
  • service updates;
  • event information;
  • podcast or content announcements; and
  • other relevant business communications.

Depending on the recipient and method of communication, our lawful basis may be:

  • consent;
  • our legitimate interests in promoting relevant professional services to business contacts; or
  • the existing-customer or business-to-business provisions permitted by applicable law.

Where electronic marketing consent is legally required, we will obtain it before sending the communication. Individuals, including sole traders and some partnerships, generally receive stronger protection under PECR than corporate subscribers. Every recipient may opt out at any time.

We will not add someone to a general marketing list merely because they submitted a service enquiry unless we have an appropriate basis to do so.

Legal, Regulatory and Security Purposes

We may use personal information to:

  • comply with applicable laws;
  • respond to lawful requests from regulators or authorities;
  • prevent and investigate fraud;
  • protect our rights, systems and personnel;
  • manage disputes;
  • establish, exercise or defend legal claims; and
  • report or investigate security incidents.

Our lawful basis is normally:

  • compliance with a legal obligation;
  • recognised legitimate interests where applicable; or
  • our legitimate interests in protecting our business and others.

6. When We Act for Hotel Clients

During some consulting engagements, a hotel or hotel group may give CATALA Consulting access to systems or information containing personal information about guests, employees, travel agents or other individuals.

In these circumstances, the hotel or hotel group will normally determine why and how the information is processed and will normally act as the controller.

CATALA Consulting will normally act as a processor and will:

  • process the information only on documented client instructions;
  • use it only to provide the contracted services;
  • apply appropriate confidentiality and security measures;
  • limit access to authorised personnel;
  • assist the client with relevant compliance obligations where contractually required; and
  • delete or return the information in accordance with the contract.

Questions about the hotel’s use of guest or employee information should normally be directed to the relevant hotel or hotel group.

Our agreements with clients and technology providers should include the required terms governing controller-to-processor relationships. Article 28 processor contracts must define matters including the processing subject, duration, nature, purpose, data types and controller rights.

7. Contact Forms, Calendly and Communications

Website Forms

When you submit a website form, we use the information provided to:

  • respond to your enquiry;
  • assess the requested support;
  • route the enquiry to the appropriate team member;
  • keep a record of the communication; and
  • follow up where appropriate.

Submitting a service enquiry does not automatically subscribe you to marketing communications.

Calendly

We use Calendly to provide online meeting scheduling.

Calendly may process information such as your:

  • name;
  • email address;
  • telephone number, if provided;
  • company or hotel name;
  • meeting answers;
  • selected time;
  • time zone; and
  • booking or cancellation information.

Calendly processes information under its own privacy terms and as a service provider to us, depending on the activity concerned.

Email and Video Conferencing

We may use email, calendar, file-storage and video-conferencing providers to communicate, organise meetings and deliver services.

These providers may process names, email addresses, meeting information, messages, attachments and technical information.

WhatsApp

Our website may include links enabling visitors to contact us through WhatsApp.

When you use WhatsApp, Meta and WhatsApp process information under their own terms and privacy notices. Information sent through WhatsApp may include your telephone number, profile information, message content and communication metadata.

Do not send confidential hotel data, payment information, passwords or sensitive personal information through WhatsApp.

Google reCAPTCHA

We use Google reCAPTCHA on certain forms to distinguish genuine users from automated activity and reduce spam or abuse.

reCAPTCHA may collect technical and interaction information such as IP address, device and browser information, cookies and page interaction data. Google processes this information under its own privacy terms.

Our lawful basis for using essential form-security technology is our legitimate interest in securing the website and preventing abuse.

8. Cookies and Similar Technologies

Our website may use cookies, pixels, local storage, scripts and similar technologies.

These technologies may be used for:

  • essential website functions;
  • security and fraud prevention;
  • remembering privacy choices;
  • website analytics;
  • embedded video or social content;
  • measuring advertising performance; and
  • personalising or evaluating campaigns.

Where consent is required, non-essential technologies will not be activated until you make a choice through our cookie banner or consent-management tool.

You can change or withdraw your cookie choices through the cookie settings available on the website.

Some cookies are necessary for the website to operate and cannot be disabled through the consent tool.

Further information about individual cookies, providers, purposes and durations should be provided in our separate Cookie Policy.

UK rules generally require organisations to tell users what storage and access technologies do and obtain consent unless an applicable exception applies.

9. Who We Share Personal Information With

We may share personal information with the following categories of recipient where necessary:

  • members of the CATALA Consulting team;
  • contractors and consultants supporting the delivery of our services;
  • website hosting, maintenance and security providers;
  • email, calendar, file-storage and productivity providers;
  • form, anti-spam and security providers;
  • meeting-booking and video-conferencing providers;
  • analytics and advertising providers, subject to your choices;
  • customer-relationship and communication platforms;
  • accounting, payment and financial-service providers;
  • insurers;
  • legal, accounting, tax and other professional advisers;
  • client organisations where this is necessary to deliver services;
  • regulators, courts, law-enforcement bodies or public authorities where legally required; and
  • prospective purchasers, investors, lenders or advisers involved in a legitimate business transaction.

We require service providers processing personal information on our behalf to protect it, use it only for authorised purposes and comply with applicable contractual and legal requirements.

We do not sell personal information to third parties.

We do not disclose personal information to third parties for their unrelated direct marketing without an appropriate lawful basis.

10. International Transfers

Some providers or team members may access or process personal information outside the United Kingdom.

This may include processing within the European Economic Area, Switzerland, the United States or other countries in which our approved service providers operate.

Where a transfer is subject to UK international-transfer restrictions, we will use an appropriate legal mechanism, such as:

  • UK adequacy regulations;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to approved contractual clauses;
  • another approved safeguard; or
  • a legally permitted exception.

Where required, we will assess whether the transfer provides an appropriate level of protection.

Restricted transfers must be covered by UK adequacy regulations, appropriate safeguards or a permitted exception.

You may contact us for further information about safeguards relevant to your personal information.

11. How Long We Keep Personal Information

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, regulatory, operational and dispute-management requirements.

Our proposed standard retention periods are:

Unsuccessful Enquiries and Prospective Clients

We normally retain enquiry and correspondence records for up to 24 months after the last meaningful interaction.

We may retain limited information for longer where necessary to record an objection, prevent duplicate contact or establish the history of a commercial relationship.

Calendly and Introductory Meeting Records

We normally retain booking information and meeting notes for up to 24 months after the meeting or last interaction, unless the person becomes a client or a longer period is justified.

Client and Contract Records

We normally retain client, contractual, project and commercial records for the duration of the relationship and for up to six years after the end of the relevant financial year or client relationship.

Some records may be retained longer where necessary for legal claims, contractual obligations, tax investigations or regulatory requirements.

UK limited companies are generally required to retain relevant accounting records for six years from the end of the financial year to which they relate, subject to limited circumstances requiring longer retention.

Financial and Accounting Records

We normally retain invoices, payment records, contracts and relevant accounting correspondence for at least six years from the end of the relevant financial year, or longer where legally required.

Marketing Records

We retain active marketing information until you unsubscribe, withdraw consent or successfully object.

We may retain a minimal suppression record after an opt-out so that we can respect your preference and avoid contacting you again for the same marketing purpose.

Website and Security Records

Technical logs are normally retained for up to 12 months, unless a longer period is necessary to investigate a security incident, fraud or misuse.

Cookie Information

Cookie and consent records are retained for the periods described in our Cookie Policy and consent-management tool.

We periodically review retained information and securely delete or anonymise information that is no longer required.

A privacy notice should state specific retention periods or explain the criteria used to determine them.

12. Data Security

We use appropriate technical and organisational measures designed to protect personal information against:

  • unauthorised access;
  • loss;
  • alteration;
  • misuse;
  • accidental disclosure;
  • destruction; and
  • unlawful processing.

Measures may include:

  • access controls;
  • password protection;
  • multifactor authentication;
  • encryption where appropriate;
  • secure cloud services;
  • staff and contractor confidentiality obligations;
  • restricted system permissions;
  • backups;
  • security monitoring; and
  • procedures for responding to suspected incidents.

Access to personal information is limited to people who have a legitimate business need to use it.

No internet transmission or storage system can be guaranteed to be completely secure. However, we take reasonable steps to reduce risk and respond appropriately to suspected incidents.

Where legally required, we will notify the relevant regulator and affected individuals of a personal-data breach.

13. Your Data-Protection Rights

Depending on the circumstances and applicable law, you may have the right to:

Be Informed

You have the right to receive clear information about how your personal information is used.

Request Access

You may request confirmation that we process your personal information and obtain a copy of that information.

Request Correction

You may ask us to correct inaccurate information or complete information that is incomplete.

Request Erasure

You may ask us to delete personal information where the relevant legal conditions apply.

This right is not absolute. We may need to retain information for contractual, legal, regulatory or legal-claims purposes.

Request Restriction

You may ask us to restrict the way we use personal information in certain circumstances.

Request Portability

Where processing is based on consent or a contract and carried out by automated means, you may have the right to receive information you provided in a structured, commonly used and machine-readable format.

Object to Processing

You may object to processing based on legitimate interests.

We will stop unless we have compelling legitimate grounds to continue or the information is required for legal claims.

Object to Direct Marketing

You have an absolute right to object to the use of your personal information for direct marketing.

You may unsubscribe using the link in a marketing email or contact us directly.

Withdraw Consent

Where processing relies on consent, you may withdraw that consent at any time.

Withdrawal does not affect processing that was lawful before consent was withdrawn.

Rights Relating to Automated Decisions

You may have rights relating to decisions made solely through automated processing that produce legal or similarly significant effects.

The UK GDPR provides rights concerning access, correction, erasure, restriction, portability, objection and certain automated decisions. The applicability of a particular right depends on the circumstances and lawful basis.

CATALA Consulting does not currently make decisions about individuals based solely on automated processing where the decision produces legal or similarly significant effects.

14. Exercising Your Rights

To exercise a right, contact:

Privacy Contact
CATALA Consulting Ltd
Email: contact@catalaconsulting.co.uk
Correspondence Address: 71–75 Shelton Street, London, WC2H 9JQ, United Kingdom

Please describe:

  • the right you wish to exercise;
  • the information or processing concerned;
  • your preferred contact method; and
  • any information that may help us identify the relevant records.

We may request proportionate proof of identity before acting on a request.

We will normally respond without undue delay and within the period required by applicable law.

In most cases, no fee will be charged. We may charge a reasonable fee or refuse a request where legally permitted, including where it is manifestly unfounded or excessive.

15. Data-Protection Complaints

You may make a complaint to us if you believe that we have processed your personal information in a way that infringes data-protection law.

Send the complaint to:

Privacy Contact
Email: contact@catalaconsulting.co.uk
Subject: Data Protection Complaint

Please include:

  • your name and contact details;
  • a description of the issue;
  • relevant dates;
  • copies of relevant communications or documents; and
  • the outcome you are seeking.

We will:

  • provide an accessible way to make a complaint;
  • acknowledge receipt within 30 days;
  • make appropriate enquiries;
  • keep you reasonably informed about progress; and
  • communicate the outcome without undue delay.

These complaint-handling requirements have applied to organisations handling personal information since June 2026.

We encourage you to raise the matter with us first so that we have an opportunity to investigate and resolve it.

You also have the right to complain to the Information Commissioner’s Office, the United Kingdom’s data-protection regulator.

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
United Kingdom

You may contact the ICO through its official website.

If you are located in the European Economic Area and the EU GDPR applies to the processing, you may also have the right to complain to the supervisory authority in the country where you live, work or believe an infringement occurred.

16. Direct Marketing Preferences

You can stop receiving marketing communications by:

We may still send non-marketing communications relating to:

  • an enquiry;
  • a booking;
  • a contract;
  • an active service;
  • an invoice;
  • changes to service terms;
  • security; or
  • another administrative matter.

Opting out of marketing does not prevent us from communicating with you where necessary for a contractual, legal or legitimate administrative purpose.

17. Third-Party Websites and Services

Our website may contain links to third-party websites, social-media platforms, booking tools, learning platforms, podcast platforms and other services.

We do not control the way independent third parties process personal information.

When you follow an external link or use a third-party service, the relevant third party’s privacy notice and terms apply.

We encourage you to review those notices before submitting personal information.

18. Children’s Information

Our website and services are intended for business and professional users and are not directed at children.

We do not knowingly collect personal information from children through the website.

If you believe that a child has provided personal information to us without appropriate authority, contact us so that we can investigate and take appropriate action.

19. Changes to This Privacy Notice

We may update this Privacy Notice to reflect:

  • changes to our services;
  • new technology;
  • operational changes;
  • changes to our providers; or
  • legal and regulatory developments.

The latest version will be published on this page with an updated date.

Where a change materially affects how we use information already collected, we will take reasonable steps to bring the change to the attention of affected individuals where appropriate.

20. Contact Us

For questions, requests or complaints concerning this Privacy Notice or our use of personal information, contact:

CATALA Consulting Ltd
Privacy Contact
Email: contact@catalaconsulting.co.uk
Registered Office: 71–75 Shelton Street, London, WC2H 9JQ, United
Correspondence Address: 71–75 Shelton Street, London, WC2H 9JQ, United Kingdom
Company Number: 11373928

Scroll to Top