Privacy Policy
Last updated: 22 April 2026
This Privacy Policy explains how FACG Consultants Ltd (“FACG”, “we”, “us”, “our”) collects, uses, shares and protects personal data when you visit facg.co.uk, contact us, attend a meeting with us or engage us as a service provider. We are committed to processing personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR).
1. Who we are
FACG Consultants Ltd is a company registered in England and Wales. We are the controller for personal data collected through this website and through our direct client engagements unless a written agreement states otherwise. You can contact our data protection lead at privacy@facg.co.uk.
2. Personal data we collect
2.1 Information you give us
- Identity and contact data: name, job title, employer, business email, business phone number.
- Enquiry data: the content of any message you send us via the contact form, email or phone.
- Engagement data: information you share during scoping, delivery and support of an engagement.
- Marketing preferences: your consent for receiving emails from us and your subsequent preferences.
2.2 Information we collect automatically
- Technical data: IP address, browser type and version, device type, operating system, referrer URL, pages visited, dwell time.
- Cookies and similar technologies: see our Cookie Policy for details.
2.3 Information we receive from third parties
- Information you make publicly available on professional networks (for example LinkedIn) where you initiate contact through them.
- Sub-processors and platform providers as listed below in section 6.
3. How we use personal data and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Responding to your enquiry and follow-up correspondence | Legitimate interests; pre-contract steps |
| Performing a contract for services with you or your employer | Performance of a contract |
| Sending you marketing emails you have opted in to | Consent |
| Improving our website and service quality (analytics, fraud prevention) | Legitimate interests |
| Meeting our legal, accounting and regulatory obligations | Legal obligation |
| Protecting our information assets and detecting security incidents | Legitimate interests; legal obligation |
4. Sharing personal data
We do not sell personal data. We share personal data only as necessary with:
- Sub-processors and service providers (see section 6) bound by written agreements meeting UK GDPR Article 28 requirements.
- Professional advisers (lawyers, accountants, auditors) bound by confidentiality.
- Regulators, law enforcement and other authorities where required by law or to protect our rights.
- Acquirers in the event of a corporate transaction (sale, merger, financing) under appropriate confidentiality.
5. International transfers
Some of our sub-processors are located outside the UK. Where personal data is transferred outside the UK we rely on appropriate safeguards including the UK International Data Transfer Agreement (IDTA), the EU Standard Contractual Clauses with the UK Addendum, or transfers to countries covered by UK adequacy regulations.
6. Sub-processors and tooling
The principal sub-processors that may process personal data on our behalf as part of operating this website and our business are:
- Netlify (Netlify, Inc., USA) — static website hosting and form delivery.
- Microsoft 365 (Microsoft Corporation, EU/UK data residency) — corporate email, calendaring, document storage.
- Google Workspace — backup productivity tooling (project-specific basis only).
- Xero (Xero Limited, New Zealand) — invoicing and bookkeeping.
An up-to-date list is available on request from privacy@facg.co.uk.
7. Retention
- Enquiry data: up to 24 months from last contact unless we enter into a contract.
- Contract data: for the duration of the contract plus 7 years to satisfy UK statutory accounting and limitation periods.
- Marketing data: until you withdraw consent, or 24 months of inactivity, whichever is sooner.
- Website logs: 90 days, then aggregated for security trend analysis.
8. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate or incomplete personal data.
- Request erasure where the data is no longer necessary.
- Restrict processing in certain circumstances.
- Object to processing based on legitimate interests, including for direct marketing.
- Receive your personal data in a structured, machine-readable format (data portability).
- Withdraw consent at any time where processing is based on consent.
To exercise any of these rights please email privacy@facg.co.uk. We will respond within one calendar month.
9. Security
We operate an Information Security Management System aligned to ISO 27001:2022. Technical and organisational measures include encryption in transit and at rest, multi-factor authentication for all access to personal data, role-based access control, audit logging, scheduled vulnerability management, supplier due diligence, documented incident response and regular staff awareness training.
10. Children
This website and our services are directed at businesses. We do not knowingly collect personal data from children under 16.
11. Complaints
If you are unhappy with how we have handled your personal data you can complain to the UK Information Commissioner’s Office: ico.org.uk, +44 (0)303 123 1113. We would prefer to address your concern first if you are willing to contact us.
12. Changes to this policy
We will update this policy from time to time. The date at the top will reflect the most recent material change. Material changes will be highlighted on the homepage for 30 days.