Strategy&Consult

Privacy Policy

UK GDPR, EU GDPR and Saudi PDPL privacy notice

Effective: 4 August 2026 | Version: 1.0

STRATEGY&CONSULT PROFESSIONAL SERVICES LTD (company 15974941) is responsible for the personal data described in this notice unless another entity is identified at collection. We use personal data to operate the website, respond to enquiries, develop and deliver services, protect our systems, meet legal duties and send permitted business communications. We do not sell personal data.

1. Who we are and scope

Strategy&Consult is the trading name of STRATEGY&CONSULT PROFESSIONAL SERVICES LTD, a company registered in England and Wales under number 15974941, with registered office at 1 Glen Iris Close, Canterbury, Kent, England, CT2 8HR. Contact: info@strategyandconsult.com; +44 793 817 6394. This notice applies to https://strategyandconsult.com, enquiries, business-development contacts, event/insight interactions and related communications. Separate notices apply to candidates and client engagements.

UK data-protection law applies to our UK processing. EU GDPR applies where its territorial tests are met. Saudi PDPL applies where we process personal data within its scope, including relevant data about individuals residing in the Kingdom. If another Strategy&Consult entity or a client is the controller, we will identify it in the relevant notice or contract.

2. Personal data we collect

  • Identity and business details: name, role, employer, industry, location and professional profile.
  • Contact details: business/personal email, telephone, postal address and communication preferences.
  • Enquiry and engagement data: service interests, subject, message, proposal information, meeting notes and correspondence.
  • Website/device data: IP address, browser/device characteristics, referring page, pages/actions, timestamps, security events, consent preferences and similar technical data.
  • Marketing and relationship data: event attendance, downloads, campaign interactions, preferences and suppression records.
  • Public or third-party data: information from company websites, professional networks, referrals, public registers and service providers, where lawful.
  • Sensitive data: not requested through general website forms. Please do not submit health, biometric, criminal-offence, national-ID, financial-account or other sensitive data unless we specifically request it through an approved secure channel.

3. Purposes and legal bases

Purpose Data UK/EU basis Saudi PDPL basis / control
Respond to enquiries and prepare proposals Identity, contact, enquiry, correspondence Steps at your request before contract; legitimate interests in responding to business enquiries Request/contract where applicable; consent or documented legitimate interest where permitted
Manage business relationships and deliver services Identity, contact, engagement data Contract; legitimate interests; legal obligation Contract, legal obligation, consent or another basis permitted by PDPL
Website operation, fraud prevention and security Device, log and security data Legitimate interests in secure, reliable services; legal obligation where applicable Documented legitimate interest where permitted; legal obligation
Optional analytics, preferences and similar technologies Device, usage and consent data Consent where PECR/ePrivacy requires it; otherwise legitimate interests only where lawful Consent where required; data minimisation and purpose limitation
Business-to-business marketing Business contact, relationship and preference data Consent where required; legitimate interests for permitted corporate communications; PECR applies Consent for direct marketing where required by PDPL; clear opt-out
Legal, regulatory, claims and governance Relevant records Legal obligation; legitimate interests in establishing/exercising/defending claims Legal obligation and other bases permitted by PDPL

Where we rely on legitimate interests, we assess necessity, proportionality and impact on individuals. Saudi sensitive data is not processed on legitimate-interest grounds. You may request information about an applicable assessment.

4. Sources and whether provision is required

We usually collect data from you. We may also receive it from your employer, a colleague/referrer, a client, public professional sources, Companies House or equivalent registers, social platforms, event partners and IT/security providers. Required form fields are marked. Without contact and enquiry information we may be unable to respond or provide requested services. Phone number should be optional on general forms unless a documented need makes it necessary.

5. Sharing

We disclose personal data only as reasonably necessary to: hosting, content-delivery, form, email, collaboration, CRM, analytics, security, backup and professional-service providers; Strategy&Consult personnel and approved contractors with a need to know; clients or partners where disclosed and lawful; banks, insurers, auditors and advisers; regulators, courts, law enforcement and public authorities; and a buyer/reorganised entity in a controlled transaction. Providers must be bound by appropriate confidentiality, security and data-processing terms. We do not publish a provider as a recipient merely because a link leads to its independent website.

6. International transfers

Our work may involve the United Kingdom, Saudi Arabia, Pakistan and other locations. Before a restricted transfer we identify the exporter, importer, destination, purpose, data and onward transfers; minimise the data; and select a lawful mechanism.

  • UK-restricted transfers: UK adequacy regulations or, where appropriate, the UK International Data Transfer Agreement or UK Addendum, plus a transfer risk assessment and supplementary measures.
  • EEA-restricted transfers: an EU adequacy decision or approved EU Standard Contractual Clauses, with transfer impact assessment and supplementary measures where required.
  • Saudi transfers: the PDPL and Transfer Regulation conditions, including minimum-necessary transfer, Saudi adequacy where available or SDAIA-approved appropriate safeguards such as Saudi standard contractual clauses, and a transfer risk assessment where required.
  • Limited legal derogations are used only when their conditions are satisfied, not as a routine solution.

To request more information or a copy of relevant safeguards (subject to lawful redactions), contact us.

7. Retention

We keep personal data only while needed for the stated purpose, legal/accounting duties, security, complaints and claims. Typical periods are in our Data Retention Notice. We consider relationship status, data sensitivity, risk, statutory/contractual requirements and limitation periods. At expiry we securely delete, anonymise or place data under a documented legal hold.

8. Your rights

Depending on the law and circumstances, rights may include being informed; access and a copy; correction/completion; deletion/destruction; restriction; objection (including an absolute objection to direct marketing); portability; withdrawal of consent; and safeguards concerning solely automated decisions. Saudi rights include information, access, obtaining a readable copy, correction/completion/update and destruction, subject to the PDPL.

Send a request using the contact details below. We verify identity proportionately and do not request more data than necessary. UK/EU requests are normally answered within one month, subject to lawful extension. Saudi requests are handled without delay and within 30 days, subject to a permitted additional 30-day extension with advance reasons. Rights are not absolute; if an exemption applies, we explain it where lawful.

9. Marketing and cookies

Marketing messages identify us and include an easy opt-out. We maintain suppression records so an opt-out is respected. Cookies and similar technologies are explained in our Cookie Policy. Non-essential technologies are not to be activated until valid consent where required, and consent can be withdrawn through ‘Consent Preferences’.

10. Automated decisions and AI

We do not currently make decisions about website visitors solely by automated means that produce legal or similarly significant effects. If that changes, we will provide specific information about the logic, significance, consequences and applicable rights before the processing. Our use of AI-enabled tools is subject to human review, confidentiality, data-minimisation and contract controls; see the AI Services Disclaimer.

11. Security and breaches

We use risk-based organisational and technical measures designed to protect confidentiality, integrity, availability and resilience. Access is limited by role and need; providers are assessed; systems are maintained; and incidents are escalated. No internet service is completely secure. Where a personal-data breach triggers notification duties, we notify the relevant authority and affected individuals within applicable legal thresholds and timeframes.

12. Children

Our website and services are directed to organisations and professionals, not children. We do not knowingly solicit personal data from anyone under 18 through the website. If we learn that a child submitted data, we will assess and delete or otherwise handle it lawfully, including through a guardian where required.

13. Representatives and other controllers

If EU GDPR Article 27 requires an EU representative for relevant processing, we will appoint one and publish its contact details before that processing. Social networks and linked websites may act as independent controllers under their own notices. A client may be controller for personal data we process solely on its documented instructions; the Client Privacy Notice explains this distinction.

14. Contact and complaints

Questions, rights requests and privacy complaints may be sent to info@strategyandconsult.com, with the subject line ‘Privacy Request’ or ‘Data Protection Complaint’, or by post to STRATEGY&CONSULT PROFESSIONAL SERVICES LTD, 1 Glen Iris Close, Canterbury, Kent, England, CT2 8HR. Telephone: +44 793 817 6394.

We acknowledge a UK data-protection complaint within 30 days, investigate it appropriately, provide proportionate progress information, and communicate the outcome. This internal route does not remove the right to contact a regulator or seek a judicial remedy.

  • United Kingdom: Information Commissioner’s Office (ICO), https://ico.org.uk/make-a-complaint/.
  • European Economic Area: the supervisory authority in the country where the individual lives or works, or where the alleged infringement occurred.
  • Saudi Arabia: the Saudi Data & AI Authority (SDAIA) or the competent authority through the official Personal Data Protection channels at https://dgp.sdaia.gov.sa/.
15. Changes

We review this notice at least annually and when processing, law, vendors or transfers materially change. Material changes will be highlighted appropriately. Version and effective date appear at the top; archived versions are retained internally.