Privacy Policy

1. Who we are

KRE Corporate Recovery Limited (“KRE”, “we”, “us”, “our”) is a firm of licensed insolvency practitioners registered in England and Wales (Company Number 12645353). Our registered office is Unit 8, The Aquarium, 1-7 King Street, Reading, Berkshire, RG1 2AN.

KRE Corporate Recovery Limited is registered as a Data Controller with the Information Commissioner’s Office (“ICO”) under registration number ZA074505.
Our licensed insolvency practitioners hold authorisation granted by the Institute of Chartered Accountants in England and Wales (“ICAEW”) as the Recognised Professional Body (“RPB”) under the Insolvency Act 1986.

In the course of our business as insolvency practitioners, we act in a variety of capacities — including as joint administrators, liquidators, administrative receivers and LPA receivers — and in doing so process the personal data of a wide range of individuals. This policy explains how we collect, use, store and protect that data and the rights available to you.

2. Legal Framework

This policy has been prepared in accordance with the following legislative and regulatory framework:

  • UK General Data Protection Regulation (UK GDPR)
  • Data Protection Act 2018 (DPA 2018)
  • Data (Use and Access) Act 2025 (DUAA 2025) — which amends the UK GDPR and DPA 2018 in a number of material respects, including in relation to legitimate interests, Data Subject Access Requests (DSARs), and automated decision-making. Key provisions came into force on 5 February 2026.
  • Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)
  • Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017
  • Insolvency Act 1986 and subordinate legislation made thereunder
  • Statements of Insolvency Practice (SIPs) issued by the Joint Insolvency Committee and adopted by ICAEW
  • Company Directors Disqualification Act 1986
  • Employment Rights Act 1996 and associated employment legislation

3. Scope of This Policy

This policy applies to personal data processed by KRE Corporate Recovery Limited in the following capacities:

  • As a professional services firm carrying on the business of insolvency practice;
  • As licensed office holders appointed over insolvent entities and individuals (including as administrator, liquidator, administrative receiver, LPA receiver, nominee or supervisor of a voluntary arrangement); and
  • As an employer and prospective employer.

This policy covers personal data collected from clients, directors and shareholders of insolvent entities, creditors, employees and former employees of insolvent entities, vendors, suppliers, business contacts, job applicants, and visitors to our website (krecr.co.uk).

4. Our Dual Role as Data Controller and Data Processor

Depending on the context in which we process personal data, KRE Corporate Recovery Limited may act as:

4.1 Data Controller for the Firm’s Own Processing

In relation to our own business operations — including client engagement, marketing, HR, and website operation — KRE Corporate Recovery Limited is the data controller, determining the purposes and means of processing.

4.2  Office Holder Processing During Formal Insolvency Appointments

Upon appointment as administrator or liquidator, an insolvency practitioner becomes responsible for the affairs of the insolvent entity. The personal data held by that entity does not automatically transfer to the insolvency practitioner as controller. The position is nuanced:

  • Where we take active decisions about the purposes and means of processing personal data held by the insolvent entity (for example, in the course of trading the business, marketing assets for sale, or conducting investigations), we may act as a joint controller or, in some circumstances, as an independent controller.
  • Where we process data purely in our capacity as agent of the insolvent entity — for example, maintaining records to facilitate a dividend distribution — we are likely to be acting as a processor in respect of that data.

This distinction is consistent with the High Court’s analysis in the Southern Pacific Personal Loans and Cambridge Analytica litigation. In practice, we maintain a record of processing activities (ROPA) covering both capacities and keep the two data sets distinct so far as practicable.

Important Note for Data Subjects in Formal Insolvency Proceedings

If you are a director, employee, creditor or other stakeholder of a company or individual over which one of our practitioners has been appointed, your rights in relation to the personal data held by that entity will depend upon the lawful basis on which it is held and the stage of the insolvency proceedings. Please refer to Section 10 (Individual Rights) and contact us using the details in Section 14 for further guidance.

5. Our Processing Activities

5.1 Clients (Including Individuals Associated with Client Businesses)

Categories of Personal Data Collected

In connection with our professional engagements, we process a range of personal data, including:

  • Names, addresses, and contact details;
  • Identity verification documents (e.g. passports, photocard driving licences);
  • Financial information, including details of assets, liabilities, and transactions;
  • Business activities, directorships, shareholdings, and beneficial ownership information;
  • Information about management, employees, and associated persons;
  • Payroll data, national insurance numbers, and wage arrears details;
  • Bank account details for the purpose of dividend distributions;
  • Credit reference and anti-money laundering (AML) search results;
  • Information about alleged or proven criminal offences and regulatory matters (including matters arising under the Company Directors Disqualification Act 1986), processed in accordance with Article 10 UK GDPR and Schedule 1 DPA 2018; and
  • Correspondence and meeting records.
Lawful Basis for Processing

We rely on one or more of the following lawful bases when processing client personal data:

  • Legal obligation (Article 6(1)(c) UK GDPR) — the majority of our processing in formal insolvency appointments is underpinned by statutory obligations arising under the Insolvency Act 1986, the Companies Act 2006, the Money Laundering Regulations 2017, and other applicable legislation.
  • Legitimate interests (Article 6(1)(f) UK GDPR and, as supplemented by the DUAA 2025, including recognised legitimate interests for fraud prevention and information security purposes) — we rely on this basis for processing that is necessary to carry out our professional functions but not expressly required by statute, including client relationship management, internal risk management, and quality monitoring.
  • Contract (Article 6(1)(b) UK GDPR) — where we are engaged under a contract for services.
  • Consent (Article 6(1)(a) UK GDPR) — for marketing communications and, where applicable, processing that falls outside the above bases.

Where we process special category data (Article 9 UK GDPR) or criminal offence data (Article 10 UK GDPR), we rely upon one or more of the conditions at Schedule 1 DPA 2018, including the substantial public interest condition (paragraph 6) and the administration of justice condition.

Pre-Appointment Activities

When we are engaged to provide pre-appointment advisory services, we collect and process the personal data of directors, shareholders, creditors, and other stakeholders as necessary to advise on restructuring options, insolvency strategy, and creditor engagement. At this stage, our primary lawful basis is legitimate interests (or contract where a formal engagement letter is in place).

Anti-Money Laundering Searches

KRE Corporate Recovery Limited uses TransUnion CallValidate to conduct anti-money laundering and identity verification searches as required by the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017. TransUnion’s privacy notice, explaining how it processes and holds data, is available at: www.transunion.co.uk/legal/privacy-centre

Sale of Business and Data as an Asset

Where an insolvency appointment involves the sale of a business that includes personal data (such as customer lists, employee records, or debtor information), we will ensure that the sale agreement imposes appropriate data protection obligations on the purchaser consistent with the UK GDPR. Where required by law or good practice, we will notify relevant data subjects of the transfer. We will not transfer personal data to a purchaser whose data protection standards we consider inadequate.

5.2 Creditors

We collect and process the personal data of creditors — including individual creditors, trade creditors, and persons associated with corporate creditors — for the following purposes:

  • Processing and adjudicating proofs of debt;
  • Communicating updates on the progress of the insolvency case;
  • Processing dividend distributions;
  • Complying with statutory reporting obligations (e.g. progress reports under the Insolvency (England and Wales) Rules 2016); and
  • Responding to creditor enquiries and Data Subject Access Requests.

Our lawful basis for this processing is primarily legal obligation. Creditor personal data forms part of the statutory insolvency record and must be retained for the period set out in Section 7.

5.3 Employees of Insolvent Entities

Where we are appointed over an entity with employees (or former employees), we process the following categories of personal data:

  • Names, addresses, national insurance numbers, and dates of birth;
  • Payroll records, salary details, and pension information;
  • Details of accrued holiday pay, notice pay, and redundancy entitlements;
  • Information required to process claims through the Redundancy Payments Service (RPS) operated by the Insolvency Service; and
  • Employment contracts and HR records relevant to the insolvency.

Processing is carried out under legal obligation (Insolvency Act 1986; Employment Rights Act 1996) and, where applicable, to fulfil contractual obligations to former employees.

5.4 Vendors and Suppliers

Where we engage vendors, suppliers, and professional agents in connection with our business or an insolvency appointment, we collect and process:

  • Contact details (names, email addresses, telephone numbers);
  • Business and billing addresses;
  • Details of accrued holiday pay, notice pay, and redundancy entitlements;
  • Bank account details for payment processing.

Processing is carried out under contract and legitimate interests.

5.5 Business Contacts and Marketing

If you have consented to receive marketing communications from us, or if we have a legitimate interest in contacting you in a business context (for example, because you are a professional contact in the restructuring and insolvency market), we may hold your contact details and use them to:

  • Send information about insolvency and restructuring developments, market commentary, and relevant updates;
  • Invite you to events and seminars; and
  • Make you aware of other services that may be of interest.

You may withdraw your consent or object to this processing at any time by contacting us using the details in Section 14. We will process any such request promptly.

5.6 Recruitment and Employees

We process the personal data of job applicants and employees for the following purposes:

  • Conducting pre-employment checks (including, where appropriate, DBS checks and professional reference verification);
  • Administering employment contracts, payroll, and benefits;
  • Managing performance, conduct, and grievance processes; and
  • Complying with employment law obligations.

We rely on legitimate interests (for recruitment), contract (for employment), and legal obligation as our lawful bases. Personal data of unsuccessful job applicants will be retained for six months and then securely deleted, unless you have consented to a longer retention period.
If your personal data is available on publicly accessible sources (such as LinkedIn or Companies House), we may collect it in connection with recruitment or case-related work on which we are formally engaged.

6. Who We Share Your Personal Data With

We do not sell personal data. We share personal data only in the circumstances described below, and only to the extent necessary for the relevant purpose:

  • Statutory authorities and regulators — including HMRC, the Insolvency Service, Companies House, the Pension Protection Fund, and the Redundancy Payments Service, where we are under a legal obligation or duty to disclose;
  • ICAEW — as our RPB, ICAEW may inspect our files and records in connection with regulatory monitoring and complaints handling;
  • maintaining and using IT systems;
  • The Official Receiver — in connection with compulsory liquidations and related investigations;
  • Courts and tribunals — where disclosure is required in the course of insolvency proceedings or related litigation;
  • Secured creditors and their advisers — where required in the administration of a formal insolvency;
  • Professional agents and service providers — including solicitors, barristers, surveyors, valuers, auctioneers, debt collection agents, IT service providers, and tracing agents, engaged by us in connection with a formal insolvency appointment or our own business. All such third parties are subject to appropriate data processing agreements and are required to maintain the confidentiality and security of personal data;
  • TransUnion CallValidate — for AML and identity verification searches, as described in Section 5.1;
  • Purchasers of insolvent businesses — where personal data (such as employee lists or customer data) transfers as part of a business sale, subject to appropriate contractual protections as described in Section 5.1; and
  • Other parties — where we are required to disclose by law, or where you have consented to the disclosure.

All personal data processed by third parties on our behalf is subject to written data processing agreements consistent with Article 28 UK GDPR.

7. Data Retention

We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, and to comply with applicable legal, regulatory, and professional obligations. The following retention schedule applies:

 

Category of Personal DataRetention PeriodBasis
Directors and shareholders of insolvent entities6 years from case closureLegal obligation / SIP compliance
Creditors (including proof of debt records)6 years from case closureLegal obligation / Insolvency Act 1986
Employee data (payroll, NI, wage arrears claims)6 years from case closureLegal obligation / Employment legislation
Debtor records and book debt information6 years from case closureLegal obligation / legitimate interest
AML / KYC search records5 years from end of business relationshipLegal obligation (Money Laundering Regulations 2017)
Client engagement and onboarding records6 years from end of engagementLegal obligation / contractual
General business contact and correspondence6 years from end of business relationship6 years from end of business relationship
Marketing and contact databaseUntil consent withdrawn or opt-out receivedConsent
Recruitment applications (unsuccessful)6 months from decisionLegitimate interest
Employee / personnel files (current and former)6 years from termination of employmentLegal obligation
Website visitor data (cookies and analytics)Up to 13 monthsConsent (PECR)

In formal insolvency cases, data forming part of the statutory insolvency record must be retained for a minimum of six years from the date of case closure (dissolution, vacation of office, or other completion of the appointment), consistent with the Insolvency Act 1986, the Insolvency (England and Wales) Rules 2016, and applicable SIPs. In compulsory liquidation cases, records may be destroyed earlier with the consent of the Official Receiver.

Where we consider it appropriate to retain data beyond the periods above (for example, in connection with ongoing litigation, regulatory investigation, or the exercise of legal claims), we will document the reasons for extended retention.

At the end of the applicable retention period, personal data is securely deleted or anonymised in accordance with our data disposal procedure.

8. Where We Store Your Personal Data

All personal data processed by KRE Corporate Recovery Limited is stored on secure servers and systems located within the United Kingdom. We do not transfer personal data to, or store it at, destinations outside the United Kingdom.

We limit access to personal data to those employees, agents, contractors, and professional advisers who have a legitimate need to access it in connection with the relevant engagement or business function. All persons with access to personal data are subject to appropriate confidentiality obligations.

We maintain a range of technical and organisational security measures to protect personal data against unauthorised access, loss, destruction, or disclosure. These include:

  • Encryption of data in transit and at rest;
  • Access controls and user authentication;
  • Regular security monitoring and vulnerability management;
  • Staff training on data protection and information security; and
  • Physical security measures at our office premises.

Notwithstanding these measures, no method of electronic transmission or storage is completely secure. We cannot guarantee the absolute security of data transmitted via the internet; any transmission is at your own risk. Once we have received your personal data, we will use appropriate procedures to seek to prevent unauthorised access.

9. Website, Navigation Information and Cookie Policy

 

9.1 Website Navigation Information

When you visit our website at krecr.co.uk, our web servers automatically collect certain technical and navigational information about your visit. This information is collected regardless of whether you interact with any page or form on the site. The information collected includes:

  • Internet Protocol (IP) address — a numerical identifier assigned to your device or network when you connect to the internet. IP addresses are used to route data to and from your device and are collected by our server logs automatically. We use IP address data to monitor site security, diagnose technical issues, and compile aggregate statistical information about site traffic. We do not use IP addresses to identify individual users.
  • Browser type and version — the name and version of the internet browser you are using (e.g. Google Chrome, Mozilla Firefox, Microsoft Edge, Safari).
  • Device and operating system — the type of device you are using (desktop, laptop, tablet, smartphone) and the operating system it runs.
  • Referring URL — the web address of the page or search result that directed you to our site, if applicable.
  • Pages visited — the specific pages on our website that you access during your visit, together with the date and time of each access.
  • Time spent on pages — how long you spend viewing individual pages.
  • Clickstream data — the sequence of pages you visit, links you click, and the path through which you navigate our site and exit it.
  • Search terms — where you arrive at our site through an internet search, the search terms used may be visible to us through the referring URL.
  • Download errors and page response times — technical performance data used to identify and resolve issues affecting the website.

This navigational data is collected and processed on the basis of our legitimate interests in understanding how our website is used and in maintaining its security and performance. It is aggregated and analysed in a manner that does not identify individual users, except where required to investigate a security incident.

Our website may contain hyperlinks to third-party websites. If you follow such a link, please note that those websites operate their own privacy policies and we are not responsible for how they process your personal data. You should review the relevant third-party privacy policy before submitting any personal data to those websites.

9.2 Cookie Policy

What are Cookies?

Cookies are small text files placed on your device (computer, tablet, or smartphone) when you visit a website. They enable the website to recognise your device on subsequent visits and to store limited information about your preferences and browsing activity. Cookies are widely used by website operators to make websites work more efficiently, to provide functionality, and to collect information about how visitors use sites.

Cookies set by the website operator (in this case, KRE Corporate Recovery Limited) are called “first-party cookies”. Cookies set by parties other than the website operator are called “third-party cookies”. Third-party cookies may be set by analytics providers or other service providers whose functionality has been embedded in the website.

What Cookies Do We Use?

We use the following categories of cookies on krecr.co.uk:

 

Cookie TypePurposeDurationConsent Required?
Strictly NecessaryEssential for the website to function (e.g. session management, security, contact form operation). Cannot be disabled.Session / persistentNo
Performance / AnalyticsCollect anonymised data on how visitors use the site (e.g. pages visited, time spent). Helps us improve the website experience.Up to 13 monthsYes
FunctionalityRemember preferences you have set (e.g. language, region). Enhances your experience but not essential.Up to 12 monthsYes
Targeting / AdvertisingWe do not currently use targeting or advertising cookies.N/AN/A

 

Your Consent and How to Manage Cookies

In accordance with the Privacy and Electronic Communications Regulations 2003 (PECR) and UK GDPR, we will not place non-essential cookies on your device without your prior informed consent.

When you first visit our website, a cookie consent banner will be displayed. This banner will:

  • Provide you with a clear explanation of the cookies we use;
  • Ask for your explicit consent before any non-essential cookies are placed on your device;
  • Allow you to accept all cookies, reject non-essential cookies, or manage your preferences by category; and
  • Record your choice securely.

Your consent, once given, will be valid for a period of up to 12 months, after which you will be asked to confirm your preferences again. You may withdraw or change your consent at any time by clearing your browser cookies and revisiting the site, or by using your browser’s privacy settings.

To manage or delete cookies through your browser, please refer to your browser’s help function or support pages. The following links provide guidance for the most commonly used browsers:

  • Google Chrome: Settings > Privacy and Security > Cookies and other site data
  • Mozilla Firefox: Options > Privacy & Security > Cookies and Site Data
  • Mozilla Firefox: Options > Privacy & Security > Cookies and Site Data
  • Apple Safari: Preferences > Privacy > Manage Website Data

Please be aware that disabling certain cookies may affect the functionality of our website. In particular, disabling strictly necessary cookies may prevent some features from operating correctly.

For further general information about cookies, including guidance on how to manage them across all websites, please visit:

ICO Cookie Guidance — ico.org.uk/cookies
www.aboutcookies.org

 

Analytics

Where we use analytics tools (such as Google Analytics or equivalent) to collect performance data about how visitors use our website, such tools may set their own cookies. Analytics data is collected in aggregated, anonymised form and is not used to identify individual visitors. We will only activate analytics cookies with your consent.

If you consent to analytics cookies, data collected through those tools (including pages visited, time on site, and general geographic region based on anonymised IP) will be shared with the relevant analytics provider in accordance with their privacy policy. We configure analytics tools to anonymise IP addresses before any data is transmitted.

10. Security

We take the security of all personal data we hold very seriously. We maintain a framework of policies, procedures, and training covering data protection, confidentiality, and information security. This framework is regularly reviewed to ensure that the measures in place remain appropriate.

In the event that we become aware of a personal data breach — whether affecting data processed by us in our own capacity or in our capacity as office holder — we will:

  • Take prompt steps to contain the breach and mitigate its effects;
  • Assess the risk to the rights and freedoms of affected individuals;
  • Where required, notify the ICO within 72 hours of becoming aware of the breach (in accordance with Article 33 UK GDPR); and
  • Where required, notify affected individuals without undue delay (in accordance with Article 34 UK GDPR).

A full procedure for handling data breach complaints raised by individuals is set out in Section 13 of this policy.

11. Your Individual Rights

Subject to the caveats noted below in relation to formal insolvency proceedings, you have the following rights under UK data protection law as supplemented by the DUAA 2025:

RightDescriptionInsolvency Caveat
Access (DSAR)Receive a copy of personal data held about you. Searches will be reasonable and proportionate per Article 15(1A) UK GDPR as amended by DUAA 2025.May be limited where compliance would be disproportionate to the interests of the creditor body (Southern Pacific Personal Loans; Cambridge Analytica).
RectificationCorrection of inaccurate or incomplete data.We will correct factual errors but cannot alter the formal record of an insolvency case.
ErasureRequest deletion of data where there is no lawful basis to retain it.Cannot apply to data forming part of the statutory insolvency record during the currency of a case or within the mandatory retention period.
RestrictionAsk us to suspend processing in certain circumstances.Limited application during active insolvency proceedings.
PortabilityReceive your data in a machine-readable format.Applies only where processing is based on consent or contract. Does not apply where our lawful basis is legal obligation.
ObjectObject to processing based on legitimate interests.We may demonstrate compelling legitimate grounds that override this right, including duties to the general body of creditors.
Withdraw ConsentWithdraw consent at any time where consent is the lawful basis.Withdrawal does not affect the lawfulness of prior processing.
Automated DecisionsNot be subject solely to automated decision-making with significant effects, subject to safeguards introduced by the DUAA 2025.We do not currently carry out automated decision-making of this nature.

To exercise any of your rights, please contact us using the details provided in Section 14. We will respond within one calendar month of receiving your request. This period may be extended by a further two months where the request is complex or we have received a number of requests at the same time, in which case we will notify you of the extension within the initial one-month period.
There is no charge for exercising your rights, unless a request is manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable fee or, in some circumstances, decline to act upon it.

Important Note Regarding Rights in Formal Insolvency Proceedings

Where personal data forms part of the formal statutory record of an insolvency case, certain individual rights — in particular the rights to erasure and restriction — will be limited or excluded during the currency of the appointment and the mandatory retention period. This is because compliance with such requests would conflict with our statutory duties as office holder or our legal obligations as a firm. Any such limitation will be communicated to you in writing, together with the reasons for it, when we respond to your request.

In addition, under the DUAA 2025, our obligation to conduct searches in response to DSARs is qualified by a ‘reasonable and proportionate’ standard (Article 15(1A) UK GDPR as amended). This is consistent with the High Court’s approach in the Southern Pacific Personal Loans and Cambridge Analytica cases. We will notify you of the scope of any search carried out in response to a DSAR and, where we decline to conduct a particular search, we will explain our reasons.

12. Automated Decision-Making

We do not carry out automated decision-making (including profiling) that produces legal or similarly significant effects on individuals within the meaning of Article 22 UK GDPR (as amended by the DUAA 2025). All significant decisions affecting individuals are made with meaningful human involvement.
If we introduce automated decision-making processes in the future that are subject to the safeguards introduced by the DUAA 2025, we will update this policy and ensure that appropriate information, representation, and human review mechanisms are in place.

13. Data Breach Complaints Procedure

This section sets out KRE Corporate Recovery Limited’s procedure for handling complaints from individuals who believe their personal data has been subject to a breach, misuse, or unauthorised disclosure — whether in connection with our firm’s own processing activities or an insolvency appointment held by one of our licensed practitioners.

13.1 What Constitutes a Data Breach Complaint?

A data breach complaint may arise where you believe that:

  • Your personal data has been disclosed to a person who was not authorised to receive it;
  • Your personal data has been lost, stolen, or accessed without authorisation;
  • Your personal data has been used for a purpose inconsistent with the purpose for which it was collected and without a lawful basis;
  • Your personal data has been inaccurately processed or retained for longer than necessary; or
  • Your rights as a data subject have not been respected.

13.2 How to Raise a Complaint

If you believe that your personal data has been mishandled, you may raise a complaint with us by any of the following means:

MethodContact Details
Email[email protected]
Telephone01189 479090
PostCompany Secretary, KRE Corporate Recovery Limited, Unit 8, The Aquarium, 1-7 King Street, Reading, RG1 2AN
Websitekrecr.co.uk

To assist us in handling your complaint promptly, please provide as much of the following information as possible:

  • Your full name and contact details;
  • The nature of the complaint and the personal data you believe has been affected;
  • The date(s) on which the relevant events occurred, if known;
  • The name of any KRE practitioner or member of staff involved, if known; and
  • Any reference number associated with your matter (e.g. case name or company number).

13.3 How We Will Handle Your Complaint

Upon receipt of your complaint, we will:

  • Acknowledge your complaint in writing within five working days of receipt;
  • Assign your complaint to a senior member of our team for investigation;
  • Investigate the matter thoroughly and impartially, including reviewing relevant files and systems;
  • Take any immediate steps necessary to contain the alleged breach and protect further data; and
  • Provide you with a full written response within 28 calendar days of acknowledgement, setting out the findings of our investigation and any remedial action taken or proposed.

Where the matter is complex and a full response within 28 days is not reasonably practicable, we will notify you of this within the initial period and provide an estimated timeframe for resolution.

We maintain a log of all data breach complaints received, which is reviewed periodically to identify systemic issues and inform improvements to our data protection framework.

13.4 Escalation — Information Commissioner’s Office

If you are not satisfied with the outcome of our internal complaints procedure, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO), which is the UK’s independent supervisory authority for data protection matters.

ICO Contact MethodDetails
Websitewww.ico.org.uk/concerns
Telephone0303 123 1113
PostInformation Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

You may also have the right to seek a judicial remedy. The ICO can advise you on the options available.
Please note that the ICO is in the process of transitional change following the DUAA 2025, which establishes a replacement body called the Information Commission. Until the relevant provisions of the DUAA 2025 are fully brought into force, the ICO remains the relevant supervisory authority.

14. Contact Us

If you have any questions about this privacy policy, wish to exercise any of your data protection rights, or have any other data protection enquiry, please contact us using the following details:

Contact MethodDetails
Firm NameKRE Corporate Recovery Limited
Websitekrecr.co.uk
Email[email protected]
Telephone01189 479090
PostCompany Secretary, KRE Corporate Recovery Limited, Unit 8, The Aquarium, 1-7 King Street, Reading, RG1 2AN
Data Controller RegistrationICO Registration No. ZA074505

15. Changes to This Privacy Policy

We review this privacy policy on an annual basis and following any material change to applicable law, regulatory guidance, or our processing activities. Where we make significant changes, we will notify relevant data subjects by reference to our website or, where appropriate, by direct communication.

KRE Corporate Recovery
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.