Data Protection.
Data protection sits at the centre of how we run the business — not least because data governance has been part of our background for years. This policy sets out the principles and practical controls we apply to keep client and business data safe.
01Scope
This policy applies to all personal data processed by Straxa Advisory, in any format, whether for clients, prospects, suppliers, or our own employees and contractors. It sits alongside our Privacy Policy, which is the client-facing explanation of how we use personal data.
02Our principles
We hold ourselves to the seven principles of UK GDPR:
- Lawfulness, fairness, transparency — we tell people what we do and why.
- Purpose limitation — data is used only for the purposes it was collected for.
- Data minimisation — we collect what we need, and nothing more.
- Accuracy — we keep records up to date and correct errors promptly.
- Storage limitation — we retain data only as long as needed or required by law.
- Integrity and confidentiality — we protect data with appropriate technical and organisational measures.
- Accountability — we document our decisions and can demonstrate compliance.
03Roles & responsibilities
Straxa Advisory acts as a data controller for personal data we collect about clients, prospects, and our own staff. Where we process data on a client's behalf as part of a delivery engagement — for example in data analysis, reporting, or systems work — we may also act as a data processor, with our obligations set out in the engagement letter.
Day-to-day responsibility for data protection compliance sits with the founder. Given the size of the business we are not required to appoint a Data Protection Officer, but we operate to DPO-equivalent standards in our processes and decisions.
04How we keep data safe
Access controls
- Access to client systems and records is granted on a least-privilege basis.
- Multi-factor authentication is enforced on email, business systems, and document storage.
- Devices are encrypted at rest with full-disk encryption, with strong screen-lock policies.
Storage and transmission
- Client records are stored in reputable, UK/EEA-hosted cloud platforms with appropriate certifications (e.g. ISO 27001, SOC 2).
- Documents containing personal or sensitive business data are exchanged through secure channels — not unencrypted email — wherever possible.
- Paper records are kept to a minimum and stored under lock and key when held.
Suppliers and processors
- We carry out due diligence on every processor before engaging them, and review periodically.
- Each processor is bound by a written data processing agreement covering security, sub-processors, and breach notification.
- We maintain a register of processors and the categories of data shared with each.
Training and culture
- All people working in or for the business receive data protection and information-security guidance, refreshed annually.
- Phishing and social-engineering risks are flagged and rehearsed — professional services is a high-target sector and we treat it accordingly.
05International transfers
Where a processor stores data outside the UK or EEA, we rely only on transfer mechanisms recognised by the UK government — typically UK adequacy regulations or the UK International Data Transfer Agreement (or its addendum to the EU Standard Contractual Clauses). We assess each transfer for additional risk and apply supplementary measures where needed.
06Retention
We hold personal data for the shortest period needed for the purpose — guided by legal and professional retention periods. As a general rule:
- Client and engagement records — six years from the end of the engagement, reflecting the Scottish prescription period for contractual claims.
- Marketing data — until consent is withdrawn, with regular review.
At the end of the retention period, data is securely deleted or anonymised.
07Subject rights
We respond to subject access requests, rectification requests, and other GDPR rights requests within one calendar month of receipt. We never charge for these unless a request is manifestly unfounded or excessive, in which case we explain our reasoning.
To exercise any right, email [email protected].
08Breach notification
A data breach is any incident leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. We log every incident, contain it, and assess the risk to those affected.
- If a breach is likely to result in a risk to people's rights and freedoms we notify the ICO within 72 hours of becoming aware.
- If the risk is high we also notify affected individuals directly, in plain language, and explain what they can do.
- Where Straxa Advisory acts as a processor, we notify the controller without undue delay.
09Use of AI and automation
Where we use AI or automation in our work — for example to draft, analyse, check, or transcribe meeting notes — we apply careful guardrails. Our full approach is set out in our AI Use Policy. In summary:
- We do not input identifiable client data into AI tools without appropriate privacy and data protection commitments.
- Where a tool processes personal or sensitive data, we review its data processing terms and enter a data processing agreement where required.
- A qualified human reviews all AI output before it is used, sent, or filed on a client's behalf.
- Clients are always notified before meetings are recorded or transcribed, and may opt out.
- The use of AI is recorded as part of our risk assessment for each engagement.
Use this form to submit a data subject rights request or a data-protection query — including subject access requests, erasure, rectification, or any other question about how we handle your personal data. We will respond within one calendar month, as required under UK GDPR.
You also have the right to complain to the Information Commissioner's Office at any time: ico.org.uk.