Privacy Policy
Last Updated: 2026
Startup Consultant London (operated by StartupConsultantLondon Ltd, Company No. 11372923) is committed to protecting and respecting your personal privacy in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Data Controller Identification
The data controller responsible for the processing of your personal data is:
- Entity: StartupConsultantLondon Ltd
- Company Registration Number: 11372923 (Incorporated in England and Wales)
- Registered Office: Floor 8, One Canada Square, Canary Wharf, London, E14 5AA, United Kingdom
- Direct Privacy Contact: Jose Antonio Somalo (josesomalo@startup-consultant.uk)
2. Categories of Data Collected
We may collect and process the following personal data categories:
- Technical Browsing Data: IP address, operating system, browser user agent, referral source, and technical session identifiers.
- Contact & Inquiry Data: Full name, telephone number, business email address, company name, and project descriptions submitted via consultation forms.
- Client Due Diligence Data: Corporate documentation, shareholding structures, and identification records strictly required to execute consulting agreements and comply with statutory Anti-Money Laundering (AML) regulations.
3. Legal Bases for Data Processing
In accordance with GDPR Article 6, we process your personal data under the following lawful bases:
- Consent: Given freely by you when submitting general inquiry forms or subscribing to communications. You maintain the right to withdraw consent at any time.
- Contractual Performance: Processing necessary to execute a consulting engagement, prepare business plans, build financial models, or deliver executive coaching.
- Legal & Statutory Compliance: Processing mandatory under UK company law, HMRC tax regulations, and statutory record-retention requirements.
4. Data Security Architecture
We implement robust technical and organizational security measures to protect your information:
- Hardware Encryption: All corporate computers and workstations are protected using Windows BitLocker full-disk encryption.
- Communications Security: Email communications are transmitted via TLS (Transport Layer Security) encryption.
- Confidential Deliverables: Sensitive financial models and strategic plans are distributed in secure PDF or password-protected archives transmitted via secondary verified communication channels.
- Automated Decision-Making: We do not conduct automated profiling or algorithmic decision-making.
5. Your GDPR Statutory Rights
Under UK data protection legislation, you possess the following rights:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete records.
- Right to Erasure ('Right to be Forgotten'): Request deletion of your personal data where retention is not required by statutory or contractual obligations.
- Right to Data Portability: Obtain and reuse your personal data in a structured, machine-readable format.
- Right to Object & Restrict Processing: Object to direct marketing or request limitation of processing activities.
To exercise any of these rights, contact us at info@startup-consultant.uk. You also hold the statutory right to lodge a complaint with the UK supervisory authority: Information Commissioner’s Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF (ico.org.uk).