PRIVACY POLICY
1 BACKGROUND
Last updated: 7 March 2025
1.1 This notice (Privacy Notice) tells you how we look after your personal data when you visit our
website at https://illumifiadvisory.co.uk/ (Website) or when you purchase our Data Consultancy
Services, where you are a prospective customer of our business, or where you are another type of
business contact, such as a supplier or service provider to our business.
1.2 This notice sets out what information we collect about you, what we use it for and whom we share
it with. It also explains your rights under data protection laws and what to do if you have any concerns
about your personal data.
1.3 We may sometimes need to update this Privacy Notice, to reflect any changes to the way our
services are provided or to comply with new business practices or legal requirements. You should
check this Privacy Notice regularly to see whether any changes have occurred.
2 WHO WE ARE AND OTHER IMPORTANT INFORMATION
2.1 We are ILLUMIFI ADVISORY LTD, registered in England and Wales with company number
16118269 with our registered address at 167-169 Great Portland Street, London, W1W 5PF (we, us or
our).
2.2 For all visitors to our Website and for users who purchase our services through an organisation,
we are the controller of your information (which means we decide what information we collect and
how it is used).
3 CONTACT DETAILS
3.1 If you have any questions about this Privacy Notice or the way that we use information, please get
in touch using the following details:
Data protection officer
- Name: Nader Hosni
- Email address: dataprotectionofficer@illumifiadvisory.co.uk
4 THE INFORMATION WE COLLECT ABOUT YOU
4.1 Personal data means any information which does (or could be used to) identify a living person.
We have grouped together the types of personal data that we collect, and where we receive it from,
below.
4.2 Type of personal data:
Identity Data: your first and last name or title.
Contact Data: your email address, telephone numbers, home address.
Feedback: information and responses you provide when completing surveys and questionnaires.
Profile Data: email address, password, username, chat logs, audit trail of systems used and
documents accessed and downloaded.
Marketing and Communication Data: includes your preferences in receiving marketing from us
and our third parties and your communication preferences.
Project Data: Any business data provided to us to perform our consultancy services (subject to
confidentiality agreements)
5 HOW WE USE YOUR INFORMATION
5.1 We are required to identify a legal justification (also known as a lawful basis) for collecting and
using your personal data. There are six legal justifications which organisations can rely on. The most
relevant of these to us are where we use your personal data to:
- fulfil our contract with you;
- comply with a legal obligation that we have;
- do something for which you have given your consent.
5.2 Below is set out the lawful basis we rely on when we use your personal data. If we intend to use
your personal data for a new reason that is not listed below, we will update our Privacy Notice.
5.2.1 Contract
- To administrate or perform our contract with you.
- To process your payment information in connection with any contract we have with you.
- To send you updates about the services you have bought (e.g. confirmation of order, arrival time).-
5.2.2 Legal Obligation
- Recording your preferences (e.g. marketing) to ensure that we comply with data protection laws.
- Where we send you information to comply with a legal obligation (e.g. where we send you
information about your legal rights).
- Where we retain information to enable us to bring or defend legal claims.-
5.2.3 Consent
- Where you have provided your consent to providing us with information or allowing us to use or
share your information.
- Where you have consented to receive marketing material from us.
5.3 Where we need to collect your personal data (for example, in order to fulfil a contract we have
with you), failure to provide us with your personal data may mean that we are not able to provide you
with the services. Where we do not have the information required about you to fulfil an order, we may
have to cancel the service ordered.
6 WHO WE SHARE YOUR INFORMATION WITH
6.1 We share (or may share) your personal data with:
- Our personnel: our employees (or other types of workers) who have contracts containing
confidentiality and data protection obligations.
- Our supply chain: other organisations that help us provide our goods. We ensure these
organisations only have access to the information required to provide the support we use them and
have a contract with them that contains confidentiality and data protection obligations.
- Our professional advisers: such as our accountants or legal advisors where we require specialist
advice to help us conduct our business.
- Any actual or potential buyer of our business.
6.2 If we were asked to provide personal data in response to a court order or legal request (e.g. from
the police), we would seek legal advice before disclosing any information and carefully consider the
impact on your rights when providing a response.
7 WHERE YOUR INFORMATION IS LOCATED OR TRANSFERRED TO
7.1 We use third-party service providers to support the operation of our business and services. This
means that your data may be stored, processed, or transferred to servers operated by these providers,
which may be located in the UK, the European Economic Area (EEA), or other jurisdictions with
appropriate data protection safeguards.
Specifically, we use:
- GoDaddy – for domain registration, website hosting, and related services. Your data may be
stored on GoDaddy’s servers, which are subject to their security and privacy policies.
- Microsoft – for cloud storage, email, and productivity tools (e.g., Microsoft 365). Data processed
through these services is stored on Microsoft’s secure servers, which may be located in multiple
jurisdictions.
7.2 These providers are responsible for maintaining the security of their systems and complying with
applicable data protection laws.
8 HOW WE KEEP YOUR INFORMATION SAFE
8.1 We take appropriate technical and organisational measures to protect your personal data from
unauthorised access, loss, misuse, or disclosure. This includes encryption, secure servers, and access
controls.
8.2 We use third party service providers, who implement industry-standard security measures to
protect the data stored on their servers. While we take reasonable steps to ensure your data is
protected, no method of transmission over the internet is entirely secure. Therefore, we cannot
guarantee absolute security.
8.3 If you have any concerns about data security, please contact us at dataprotectionofficer@illumifiadvisory.co.uk .
9 HOW LONG WE KEEP YOUR INFORMATION
9.1 Where we act as the controller, we will only retain your personal data for as long as necessary to
fulfil the purposes we collected it for.
9.2 To decide how long to keep personal data (also known as its retention period), we consider the
volume, nature, and sensitivity of the personal data, the potential risk of harm to you if an incident
were to happen, whether we require the personal data to achieve the purposes we have identified or
whether we can achieve those purposes through other means (e.g. by using aggregated data instead),
and any applicable legal requirements (e.g. minimum accounting records for HM Revenue & Customs).
9.3 We may keep Identity Data, Contact Data and certain other data (specifically, any exchanges
between us by email or any other means) for up to seven years after the end of our contractual
relationship with you.
9.4 If you browse our Website, we keep personal data collected through our analytics tools for only as
long as necessary to fulfil the purposes we collected it for.
9.5 If you have asked for information from us or you have subscribed to our mailing list, we keep
your details until you ask us to stop contacting you.
10 YOUR LEGAL RIGHTS
10.1 You have specific legal rights in relation to your personal data.
10.2 We can decide not to take any action in relation to a request where we have been unable to
confirm your identity (this is one of our security processes to make sure we keep information safe) or
if we feel the request is unfounded or excessive. Usually there is no cost for exercising your data
protection rights, but we may charge a fee where we decide to proceed with a request that we believe
is unfounded or excessive. If this happens we will always inform you in writing.
10.3 We will respond to your legal rights request without undue delay, but within one month of us
receiving your request or confirming your identity (whichever is later). We may extend this deadline
by two months if your request is complex or we have received multiple requests at once. If we need to
extend the deadline, we will let you know and explain why we need the extension.
10.4 We do not respond directly to requests which relate to personal data for which we act as the
processor. In this situation, we forward your request to the relevant controller and await their
instruction before we take any action.
10.5 If you wish to make any of the right requests listed below, you can reach us at
dataprotectionofficer@illumifiadvisory.co.uk.
10.6 Your rights include:
- Access: You must be told if your personal data is being used and you can ask for a copy of your
personal data as well as information about how we are using it to make sure we are abiding by the
law.
- Correction: You can ask us to correct your personal data if it is inaccurate or incomplete. We
might need to verify the new information before we make any changes.
- Deletion: You can ask us to delete or remove your personal data if there is no good reason for us
to continue holding it or if you have asked us to stop using it (see below). If we think there is a
good reason to keep the information you have asked us to delete (e.g. to comply with regulatory
requirements), we will let you know and explain our decision.
- Restriction: You can ask us to restrict how we use your personal data and temporarily limit the
way we use it.
- Objection: You can object to us using your personal data if you want us to stop using it. If we
think there is a good reason for us to keep using the information, we will let you know and explain
our decision.
- Portability: You can ask us to send you or another organisation an electronic copy of your
personal data.
- Complaints: If you are unhappy with the way we collect and use your personal data, you can
complain to the ICO or another relevant supervisory body, but we hope that we can respond to your concerns before it reaches that stage. Please contact us at dataprotectionofficer@illumifiadvisory.co.uk.
11 WHEN WE SEND YOU MARKETING MESSAGES
11.1 We market our services to prospective and existing business customers, this is known as
Business-to-Business Marketing (B2B Marketing). We may send marketing communications to their
staff via work contact details. If you are a member of staff and do not wish to receive B2B Marketing,
please let us know at privacy@illumifiadvisory.co.uk.
11.2 Opting out of marketing will not affect our processing of your personal data in relation to any
order you have with us and where we are required to use your personal data to fulfil that order or
provide you with certain information
COOKIE NOTICE
1 INTRODUCTION
1.1 Our Website (www.illumifiadvisory.co.uk) uses cookies and similar technologies. This helps us to
provide you with a good experience when you browse our Website and also allows us to improve our
Website.
1.2 Cookies are small text files that are downloaded to your device (e.g. your computer or
smartphone). Cookies contain uniquely generated references which are used to distinguish you from
other users. They allow information gathered on one webpage to be stored until it is needed for use on
another, allowing our Website to provide you with a personalised experience (like remembering your
favourites) and provide us with statistics about how you interact with our (and sometimes third party)
Website.
1.3 Cookies are not harmful to your devices (like a virus or malicious code) but some individuals
prefer not to share their information (for example, to avoid targeted advertising).
2 DIFFERENT TYPES OF COOKIES
2.1 Session vs. persistent cookies: cookies have a limited lifespan. Cookies which only last a short
time or end when you close your browser are called session cookies. Cookies which remain on your
device for longer are called persistent cookies (these are the type of cookies that allow websites to
remember your details when you log back onto them).
2.2 First party vs. third party cookies: cookies placed on your device by the website owner are
called first party cookies. When the website owner uses other businesses’ technology to help them
manage and monitor their website, the cookies added by the other business are called third party
cookies.
2.3 Categories of cookies: cookies can be grouped by what they help the website or website owner
do:
- Necessary cookies are cookies which help the website to run properly (when they are strictly
necessary cookies it means their only function is to help the website work);
- Performance / functionality cookies help a website owner understand and analyse how a user
uses a website, in order to personalise content and remember user preferences;
- Analytical cookies are used to understand how visitors interact with the website. These cookies
help provide information on metrics the number of visitors, bounce rate, etc.
3 WHAT DO WE USE COOKIES FOR?
3.1 We use cookies to track how visitors use our Website.