Effective: 4 August 2026 | Version: 1.0
This notice explains how STRATEGY&CONSULT PROFESSIONAL SERVICES LTD uses personal data in developing, entering into and managing client engagements. For relationship administration, conflicts, billing, security, quality, legal compliance and our own professional records, we normally act as controller. When a client supplies personal data for us to process only on documented instructions as part of a service, the client may be controller and we may be processor; the engagement agreement/data-processing terms govern that processing.
We use data to evaluate and contract for work; deliver, manage and quality-review services; communicate and collaborate; manage conflicts, independence and risk; invoice and collect; secure systems; keep professional records; improve methods using anonymised/aggregated information where feasible; and meet legal, regulatory, insurance and claims duties. UK/EU bases are contract/steps at request, legitimate interests and legal obligation, with consent or additional conditions where needed. Saudi processing uses a basis permitted by PDPL and additional controls for sensitive/credit/health data.
Data may be accessed by the engagement team, authorised contractors and approved IT, collaboration, security, storage, finance, insurance and professional-adviser providers; and disclosed to authorities or transaction parties where lawful. We maintain need-to-know access and contractual controls. Restricted transfers use UK, EU and Saudi mechanisms as applicable, supported by risk assessment and data minimisation.
Engagement records are normally retained for seven years after completion/termination, subject to contract, professional requirements, local law, claims and legal hold. Client-supplied processor data is returned or securely deleted at the end of services as instructed, unless law requires retention. Backups expire through controlled rotation.
We do not place client confidential or personal data into public consumer AI services for engagement delivery. Any approved AI-enabled tool must undergo provider, contract, privacy, security, transfer and human-review assessment; use must be consistent with client instructions and the engagement agreement. Material AI use will be disclosed where contract or law requires.
Controller-related rights may be exercised directly with us. If we are processor, we promptly route the request to the client and assist under contract. Security and complaint information is in our Privacy Policy and Information Security Statement. Contact the engagement lead and copy the privacy contact at info@strategyandconsult.com.