Strategy&Consult

Client Privacy Notice

Client contacts, engagement personnel and client-supplied data

Effective: 4 August 2026 | Version: 1.0

1. Scope and roles

This notice explains how STRATEGY&CONSULT PROFESSIONAL SERVICES LTD uses personal data in developing, entering into and managing client engagements. For relationship administration, conflicts, billing, security, quality, legal compliance and our own professional records, we normally act as controller. When a client supplies personal data for us to process only on documented instructions as part of a service, the client may be controller and we may be processor; the engagement agreement/data-processing terms govern that processing.

2. Data

  • Client/contact information: names, roles, employer, professional contact details, signatures and communications.
  • Engagement information: requirements, proposals, contracts, deliverables, meeting records, access permissions and project activity.
  • Financial/compliance information: billing, bank/payment references, tax, due diligence, conflicts, sanctions and fraud-prevention information where required.
  • Client-supplied data: workforce, customer, supplier, transaction, risk, audit, financial or operational data defined in the engagement. Clients must minimise and lawfully disclose it.
  • Technology/security records: accounts, authentication, device/log, access, incident and collaboration metadata.

3. Uses and legal bases

We use data to evaluate and contract for work; deliver, manage and quality-review services; communicate and collaborate; manage conflicts, independence and risk; invoice and collect; secure systems; keep professional records; improve methods using anonymised/aggregated information where feasible; and meet legal, regulatory, insurance and claims duties. UK/EU bases are contract/steps at request, legitimate interests and legal obligation, with consent or additional conditions where needed. Saudi processing uses a basis permitted by PDPL and additional controls for sensitive/credit/health data.

4. Client instructions and responsibility

  • A client must have authority and a lawful basis to disclose personal data, provide required notices, respect rights and limit data to what is necessary.
  • Do not send special-category, criminal, health, biometric, credit, national-ID or children’s data until the engagement team approves a secure channel and documents necessity, roles and safeguards.
  • Processor work is governed by documented instructions, confidentiality, security, subprocessor, breach-assistance, rights-assistance, deletion/return and audit provisions.
  • We may refuse or quarantine data that is outside scope, excessive, unsafe or unlawfully supplied.

5. Recipients and transfers

Data may be accessed by the engagement team, authorised contractors and approved IT, collaboration, security, storage, finance, insurance and professional-adviser providers; and disclosed to authorities or transaction parties where lawful. We maintain need-to-know access and contractual controls. Restricted transfers use UK, EU and Saudi mechanisms as applicable, supported by risk assessment and data minimisation.

6. Retention

Engagement records are normally retained for seven years after completion/termination, subject to contract, professional requirements, local law, claims and legal hold. Client-supplied processor data is returned or securely deleted at the end of services as instructed, unless law requires retention. Backups expire through controlled rotation.

7. AI-enabled processing

We do not place client confidential or personal data into public consumer AI services for engagement delivery. Any approved AI-enabled tool must undergo provider, contract, privacy, security, transfer and human-review assessment; use must be consistent with client instructions and the engagement agreement. Material AI use will be disclosed where contract or law requires.

8. Rights, security and contact

Controller-related rights may be exercised directly with us. If we are processor, we promptly route the request to the client and assist under contract. Security and complaint information is in our Privacy Policy and Information Security Statement. Contact the engagement lead and copy the privacy contact at info@strategyandconsult.com.