Effective: 4 August 2026 | Version: 1.0
STRATEGY&CONSULT PROFESSIONAL SERVICES LTD (company 15974941) is responsible for the personal data described in this notice unless another entity is identified at collection. We use personal data to operate the website, respond to enquiries, develop and deliver services, protect our systems, meet legal duties and send permitted business communications. We do not sell personal data.
Strategy&Consult is the trading name of STRATEGY&CONSULT PROFESSIONAL SERVICES LTD, a company registered in England and Wales under number 15974941, with registered office at 1 Glen Iris Close, Canterbury, Kent, England, CT2 8HR. Contact: info@strategyandconsult.com; +44 793 817 6394. This notice applies to https://strategyandconsult.com, enquiries, business-development contacts, event/insight interactions and related communications. Separate notices apply to candidates and client engagements.
UK data-protection law applies to our UK processing. EU GDPR applies where its territorial tests are met. Saudi PDPL applies where we process personal data within its scope, including relevant data about individuals residing in the Kingdom. If another Strategy&Consult entity or a client is the controller, we will identify it in the relevant notice or contract.
| Purpose | Data | UK/EU basis | Saudi PDPL basis / control |
|---|---|---|---|
| Respond to enquiries and prepare proposals | Identity, contact, enquiry, correspondence | Steps at your request before contract; legitimate interests in responding to business enquiries | Request/contract where applicable; consent or documented legitimate interest where permitted |
| Manage business relationships and deliver services | Identity, contact, engagement data | Contract; legitimate interests; legal obligation | Contract, legal obligation, consent or another basis permitted by PDPL |
| Website operation, fraud prevention and security | Device, log and security data | Legitimate interests in secure, reliable services; legal obligation where applicable | Documented legitimate interest where permitted; legal obligation |
| Optional analytics, preferences and similar technologies | Device, usage and consent data | Consent where PECR/ePrivacy requires it; otherwise legitimate interests only where lawful | Consent where required; data minimisation and purpose limitation |
| Business-to-business marketing | Business contact, relationship and preference data | Consent where required; legitimate interests for permitted corporate communications; PECR applies | Consent for direct marketing where required by PDPL; clear opt-out |
| Legal, regulatory, claims and governance | Relevant records | Legal obligation; legitimate interests in establishing/exercising/defending claims | Legal obligation and other bases permitted by PDPL |
Where we rely on legitimate interests, we assess necessity, proportionality and impact on individuals. Saudi sensitive data is not processed on legitimate-interest grounds. You may request information about an applicable assessment.
We usually collect data from you. We may also receive it from your employer, a colleague/referrer, a client, public professional sources, Companies House or equivalent registers, social platforms, event partners and IT/security providers. Required form fields are marked. Without contact and enquiry information we may be unable to respond or provide requested services. Phone number should be optional on general forms unless a documented need makes it necessary.
We disclose personal data only as reasonably necessary to: hosting, content-delivery, form, email, collaboration, CRM, analytics, security, backup and professional-service providers; Strategy&Consult personnel and approved contractors with a need to know; clients or partners where disclosed and lawful; banks, insurers, auditors and advisers; regulators, courts, law enforcement and public authorities; and a buyer/reorganised entity in a controlled transaction. Providers must be bound by appropriate confidentiality, security and data-processing terms. We do not publish a provider as a recipient merely because a link leads to its independent website.
Our work may involve the United Kingdom, Saudi Arabia, Pakistan and other locations. Before a restricted transfer we identify the exporter, importer, destination, purpose, data and onward transfers; minimise the data; and select a lawful mechanism.
To request more information or a copy of relevant safeguards (subject to lawful redactions), contact us.
We keep personal data only while needed for the stated purpose, legal/accounting duties, security, complaints and claims. Typical periods are in our Data Retention Notice. We consider relationship status, data sensitivity, risk, statutory/contractual requirements and limitation periods. At expiry we securely delete, anonymise or place data under a documented legal hold.
Depending on the law and circumstances, rights may include being informed; access and a copy; correction/completion; deletion/destruction; restriction; objection (including an absolute objection to direct marketing); portability; withdrawal of consent; and safeguards concerning solely automated decisions. Saudi rights include information, access, obtaining a readable copy, correction/completion/update and destruction, subject to the PDPL.
Send a request using the contact details below. We verify identity proportionately and do not request more data than necessary. UK/EU requests are normally answered within one month, subject to lawful extension. Saudi requests are handled without delay and within 30 days, subject to a permitted additional 30-day extension with advance reasons. Rights are not absolute; if an exemption applies, we explain it where lawful.
Marketing messages identify us and include an easy opt-out. We maintain suppression records so an opt-out is respected. Cookies and similar technologies are explained in our Cookie Policy. Non-essential technologies are not to be activated until valid consent where required, and consent can be withdrawn through ‘Consent Preferences’.
We do not currently make decisions about website visitors solely by automated means that produce legal or similarly significant effects. If that changes, we will provide specific information about the logic, significance, consequences and applicable rights before the processing. Our use of AI-enabled tools is subject to human review, confidentiality, data-minimisation and contract controls; see the AI Services Disclaimer.
We use risk-based organisational and technical measures designed to protect confidentiality, integrity, availability and resilience. Access is limited by role and need; providers are assessed; systems are maintained; and incidents are escalated. No internet service is completely secure. Where a personal-data breach triggers notification duties, we notify the relevant authority and affected individuals within applicable legal thresholds and timeframes.
Our website and services are directed to organisations and professionals, not children. We do not knowingly solicit personal data from anyone under 18 through the website. If we learn that a child submitted data, we will assess and delete or otherwise handle it lawfully, including through a guardian where required.
If EU GDPR Article 27 requires an EU representative for relevant processing, we will appoint one and publish its contact details before that processing. Social networks and linked websites may act as independent controllers under their own notices. A client may be controller for personal data we process solely on its documented instructions; the Client Privacy Notice explains this distinction.
Questions, rights requests and privacy complaints may be sent to info@strategyandconsult.com, with the subject line ‘Privacy Request’ or ‘Data Protection Complaint’, or by post to STRATEGY&CONSULT PROFESSIONAL SERVICES LTD, 1 Glen Iris Close, Canterbury, Kent, England, CT2 8HR. Telephone: +44 793 817 6394.
We acknowledge a UK data-protection complaint within 30 days, investigate it appropriately, provide proportionate progress information, and communicate the outcome. This internal route does not remove the right to contact a regulator or seek a judicial remedy.
We review this notice at least annually and when processing, law, vendors or transfers materially change. Material changes will be highlighted appropriately. Version and effective date appear at the top; archived versions are retained internally.