Privacy Policy
How Wesbridge Associates collects, uses, discloses and safeguards your personal information when you visit our website or use our immigration services.
Last updated June 2026
Client care and casework procedures
How we meet the IAA Code of Standards (F1.1 – F6.1).
F1 — Recording client information
- F1.1 Basic information. At first contact we record the client's identity, contact details, immigration history and the matter they need help with, and offer written confirmation of those basic details before any substantive work begins.
- F1.2 Further information and confirmation in writing. Detailed facts, instructions, advice and the scope of work are captured in our client care letter and follow-up correspondence, and agreed in writing with the client before action is taken.
F2 — Case management
- F2.1 Complex case plans. Complex matters are supported by a written case plan covering objectives, key steps, evidence required, risks and decision points, signed off by the Principal and shared with the client.
- F2.2 Updating issues and progress. Clients receive timely updates on case progress, new developments and any change in legal position or strategy, with all updates logged against the client file.
- F2.3 Updating costs information. If costs or disbursements are likely to change from the original quote, the client is told in writing and asked to agree before further chargeable work is carried out.
- F2.4 Responsibility for the case. Every matter has a named adviser responsible day-to-day and is supervised by the Principal, Danish Farooq. The client is told who their adviser and supervisor are at the outset.
F3 — Case closure
- F3.1 Confirming information at the end of the case. At the close of every matter we issue a written closing letter confirming the outcome, any next steps the client must take (including deadlines), what is being returned to them, and how their file will be stored.
F4 — Confidentiality and privacy
- F4.1 Confidentiality procedure. All staff are bound by a written confidentiality obligation. Client information is only accessed by those who need it for the matter, and is never disclosed to third parties without informed client consent or a clear legal basis.
- F4.2 Privacy. Personal data is handled in line with UK GDPR and the Data Protection Act 2018. Full detail on lawful basis, retention and your rights is set out in the sections below.
F5 — Instructing other legal service providers
- F5.1 Non-discrimination. When we instruct other legal service providers on a client's behalf, selection is based solely on competence, suitability and value — never on protected characteristics or any unlawful basis.
- F5.2 Selection of providers. Providers are selected against documented criteria including regulatory standing (SRA / Bar Council), relevant expertise, capacity, conflict checks, cost transparency and professional indemnity cover.
- F5.3 Evaluation of providers. We keep a record of providers we instruct and review their performance on each matter — quality of work, communication, timeliness and outcomes — to inform future selection.
- F5.4 Client information and consultation. Before instructing another provider we tell the client who they are, why they have been chosen, the likely cost, and any referral arrangement, and we obtain the client's agreement.
- F5.5 Content of instructions. Instructions to other providers are issued in writing and set out the scope of work, agreed fees, deadlines, relevant facts and documents, and the limits of their authority on the matter.
F6 — Information handling
- F6.1 Secure information handling. Client information is stored on access-controlled, encrypted systems with role-based permissions. Documents are transmitted over secure channels, retained only for as long as legally required, and securely destroyed at the end of the retention period.
These procedures are owned by the Compliance Officer (Fahad Zohaib Asghar) and reviewed annually by the Director (Nayab Sarosh Khalid). The data-protection detail required by UK GDPR follows below.
File and case management
Independent review of files and feedback to caseworkers (E1.1 – E2.6).
E1 — File management
- E1.1 File list. We maintain a single, up-to-date master list of all open and closed client matters within our case management system, with a unique reference number for each file.
- E1.2 File management procedures. Written procedures govern how files are opened, named, stored, supervised, closed and archived, so every adviser handles client matters in the same way.
- E1.3 Logical and orderly files. Every case file follows a standard structure (client care, ID/CDD, instructions, evidence, advice, correspondence, Home Office submissions, decisions) so anyone picking it up can find what they need quickly.
E2 — File review
- E2.1 Review processes and procedures. A documented file-review procedure sets out how files are sampled, what is checked (advice quality, compliance, supervision, costs, deadlines) and how findings are recorded and actioned.
- E2.2 Process management. The Compliance Officer schedules reviews, tracks completion, and ensures every adviser has a representative sample of their open and closed files reviewed each cycle.
- E2.3 File reviewers. Reviews are carried out by the Principal (Danish Farooq) or the Compliance Officer (Fahad Zohaib Asghar) — never by the adviser whose file is under review — to ensure independence.
- E2.4 Review and corrective action on file. The completed review form, any issues identified and the corrective action taken are saved on the client file itself, so it is evident the file has been reviewed and acted on.
- E2.5 Review records. A central review register records every file reviewed, the reviewer, date, outcomes, training needs identified and feedback given to the responsible caseworker.
- E2.6 Monitoring file review. The Director monitors the review programme: completion rates, trends in findings, repeat issues and the effectiveness of corrective actions feed into our annual quality review.
File reviews are independent of the responsible adviser, fed back to caseworkers individually, and rolled up into the annual quality review by the Director (Nayab Sarosh Khalid).
Introduction
Wesbridge Associates ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our immigration services.
Information we collect
Personal information
We may collect personal information that you provide directly to us, including:
- Name, email address, phone number, and postal address
- Passport details and immigration documentation
- Employment and educational history
- Financial information relevant to visa applications
- Any other information you choose to provide
Automatically collected information
When you visit our website, we may automatically collect:
- IP address and browser type
- Device information and operating system
- Pages viewed and links clicked
- Time and date of visits
How we use your information
We use the information we collect to:
- Provide immigration advisory and application services
- Communicate with you about your case
- Process payments and maintain records
- Improve our website and services
- Comply with legal obligations
- Send you updates and marketing communications (with your consent)
Communications via WhatsApp
We use the WhatsApp Business Platform, provided by Meta Platforms, Inc., to communicate with prospective and existing clients about their enquiries and cases.
If you contact us via WhatsApp or consent to us contacting you on WhatsApp, we will process your WhatsApp phone number and the content of the messages you exchange with us in order to respond to your enquiry, provide our services, and maintain a record of our communications.
Messages sent and received via WhatsApp are also processed by Meta in accordance with Meta's own privacy policy and terms; we do not control Meta's processing of your data, and your use of WhatsApp to communicate with us is subject to WhatsApp's and Meta's terms and privacy policy.
We process this data on the basis of our legitimate interest in responding to enquiries and providing our services, and/or your consent where you have initiated or agreed to WhatsApp communication.
You can ask us to stop contacting you via WhatsApp at any time by replying STOP or by contacting us using the details below.
Legal basis for processing (GDPR)
Under GDPR, we process your personal data under the following legal bases:
| Legal basis | Why we rely on it |
|---|---|
| Contract | To fulfil our contractual obligations to you |
| Legal obligation | To comply with UK immigration and legal requirements |
| Legitimate interest | To operate our business and improve our services |
| Consent | For marketing communications and non-essential cookies |
Data sharing and disclosure
We may share your information with:
- UK Home Office and immigration authorities — as required for visa applications
- Service providers — third parties who assist in our operations
- Legal and professional advisers — when necessary for legal advice
We will never sell your personal information to third parties.
Data security and retention
Security measures
We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. However, no internet transmission is completely secure, and we cannot guarantee absolute security.
Retention period
We retain your personal information for as long as necessary to provide our services and comply with legal obligations. Immigration case files are typically retained for 7 years after case closure in accordance with professional regulations.
Your rights under UK GDPR
You have the following rights:
| Right | What it means |
|---|---|
| Access | Request copies of your personal data |
| Rectification | Request correction of inaccurate data |
| Erasure | Request deletion of your data |
| Restriction | Request limitation of processing |
| Portability | Receive your data in structured format |
| Object | Object to processing |
How to request deletion of your data
You can ask us to delete the personal data we hold about you at any time. To make a data deletion request, please follow the steps below.
- Step 1 — Email us. Send an email to admin@wesbridgeassociates.co.uk with the subject line "Data Deletion Request".
- Step 2 — Help us locate your records. Include the full name, email address and phone number associated with your enquiry so we can locate your records.
- Step 3 — Verification and response. We will verify your identity and confirm the outcome of your request within 30 days.
We will delete the personal data we hold about you, including any WhatsApp message history we hold, except where we are legally required to retain certain records (for example for regulatory, tax or anti-money-laundering obligations). Where this applies, we will explain it in our response.
Complaints to the ICO
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at www.ico.org.uk.
Questions about this policy?
Write to Wesbridge Associates Limited, Level 30, The Leadenhall Building, 122 Leadenhall Street, London EC3V 4AB, or email admin@wesbridgeassociates.co.uk.
Wesbridge Associates Limited · Company No. 16029047 · IAA No. F202537300