Policies

    Privacy Policy

    EffectiveAugust 2026Version1.4ControllerStraxa Advisory

    This policy explains what personal data Straxa Advisory collects, why we collect it, how we use and protect it, and the rights you have over it. We aim for plain, honest language — if anything is unclear, please ask.

    01Who we are

    Straxa Advisory Limited is a business advisory and consulting firm based in Glasgow, Scotland, registered in Scotland under company number SC878109. We work with owner-managed businesses on growth strategy, operational efficiency, data and reporting systems, and process improvement — using modern tools including automation and AI where they earn their place.

    For the purposes of UK GDPR and the Data Protection Act 2018, we are the data controller for personal data we hold about our clients, prospects, and website visitors. Contact: [email protected] · 07897 774240.

    02What we collect

    We only collect what we need to deliver our services and run the business responsibly. Typically:

    • Identity and contact data — name, business name, email, phone, address.
    • Engagement data — the services you've engaged us for, correspondence, meeting notes, instructions you give us, and any documents you choose to share in the course of an engagement.
    • Technical and analytics data — IP address, browser type, approximate location, referral source, pages visited, and website actions such as form submissions — where you consent to analytics cookies (kept to a minimum).
    • Business health check data — if you use our online scorecard and choose to have your results sent to you, we collect the answers you give, your resulting score, and the name, email, and optional business name you enter. We use these to send your results (a service you've asked for) and, only if you tick the box, to send occasional relevant advice. You can unsubscribe at any time.
    • Resource download data — if you download a free sample or template from our site (for example the Data Portal), we collect your name, business name, and email so we can send you the file and, occasionally, follow up once to ask whether it was useful. We do not use this for unrelated marketing unless you have separately opted in.

    03How we collect it

    • Directly from you — when you contact us, engage us, or send us documents.
    • From your authorised representatives, with your consent.
    • From our website forms and email correspondence.
    • From meeting notes and transcripts, where you have consented to a meeting being recorded or transcribed — as set out in our AI Use Policy.

    04Why we use it (lawful basis)

    We process your personal data on one or more of the following lawful bases:

    • Contract — to deliver the services in your engagement letter.
    • Legal obligation — to comply with applicable laws and regulatory requirements.
    • Legitimate interest — to manage and improve our business, communicate with clients, and protect our operations — balanced carefully against your rights.
    • Consent — for optional analytics cookies and any marketing communications (which you can withdraw at any time).

    05Who we share it with

    We do not sell your data. We share it only where necessary, and only with parties bound to confidentiality:

    • Regulators or public authorities where law requires.
    • Software providers we use to run the business (CRM, secure document storage, email, project and collaboration tools) — under data processing agreements.
    • Analytics providers where you consent to analytics cookies — currently Google Analytics 4 via Google Tag Manager.
    • Professional advisers (legal, IT, insurance) when needed for the business.

    06How long we keep it

    We keep records for as long as we have a working relationship with you, and afterwards for as long as we are required by law. As a general rule, we retain client and engagement records for six years from the end of the engagement, reflecting the Scottish prescription period for contractual claims. Enquiry and business health check data from people who do not become clients is kept only as long as it is useful for follow-up, and is deleted on request.

    07How we protect it

    We apply appropriate technical and organisational measures to protect your data — encrypted storage, multi-factor authentication, access controls, and regular review of our processors and systems. If a breach were to occur that risks your rights and freedoms, we would notify you and the ICO within the timeframes required by law.

    08Your rights

    Under UK GDPR you have the right to:

    • Access the personal data we hold about you.
    • Have inaccurate data corrected.
    • Request erasure where there is no overriding legal reason to retain it.
    • Restrict or object to certain processing.
    • Data portability — receive your data in a usable format.
    • Withdraw consent for any processing based on consent, at any time.
    • Complain to the Information Commissioner's Office (ico.org.uk).

    To exercise any of these rights, email [email protected].

    A note on cookies

    Our website uses essential cookies required for the site to function. If you accept analytics cookies, we use Google Analytics 4 via Google Tag Manager to understand website usage, referral sources, and lead actions such as successful form submissions. We do not send names, email addresses, phone numbers, business names, or message text to Google Analytics. You can reject analytics cookies in the cookie banner or reset your preferences below, and Google also provides a browser add-on for opting out of Google Analytics.

    09Changes to this policy

    We may update this policy from time to time. The current version, with its effective date, will always be available on this page.