This page is a drafting framework, not legal advice. Have your own counsel review and adapt it before publication — data protection, consumer and financial-services obligations vary by jurisdiction and by what you actually do.
Who we are
What we collect
Why we use it
We only process personal data where we have a lawful basis to do so.
Who we share it with
- Service providers who host our website, email and CRM, under contract and only as instructed.
- Professional advisers such as lawyers and accountants where necessary.
- Authorities where we are legally required to disclose.
- A buyer or successor if the business is sold, subject to the same obligations.
We do not sell personal information. Where a provider is located outside your jurisdiction, transfers rely on the transfer mechanism your counsel identifies, e.g. standard contractual clauses.
How long we keep it
Your rights
- Access a copy of the personal data we hold about you.
- Correct data that is inaccurate or incomplete.
- Request deletion where we have no continuing lawful basis to hold it.
- Object to processing based on legitimate interest.
- Restrict processing while a dispute about accuracy or basis is resolved.
- Receive your data in a portable format where processing is based on consent or contract.
- Withdraw consent at any time where consent is the basis.
- Complain to your supervisory authority.
To exercise any of these, contact [email protected]. We respond within statutory period for your jurisdiction.
Security
We apply encryption in transit and at rest, role-based access control, least-privilege access to client systems and logging of administrative actions. No system is perfectly secure, and we will notify you and any regulator as required if a breach affecting your data occurs.
Our vulnerability disclosure process is on the Security & Disclosure page. Please report security issues there rather than through the general contact form.