Introduction
Stratford Ellis ("S&E", "we", or "us") is committed to protecting your personal data and respecting your privacy in all our dealings. We are a UK-based consultancy, and we handle personal information in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This Privacy Policy explains how we collect, use, store, and share your personal data when you interact with us – for example, by visiting our website or using our consulting services – and outlines your rights under data protection law. We adhere to the core data protection principles, ensuring that personal data is used lawfully, fairly and transparently, is collected for specific legitimate purposes, is limited to what is necessary, is kept accurate and up-to-date, is not retained longer than needed, and is secured against unauthorised use.
By engaging with Stratford Ellis (e.g. submitting your information via our website or signing a contract with us), you acknowledge this Privacy Policy. We may provide additional notices highlighting certain uses of your data when you sign up for particular services, but this document contains the comprehensive policy. Please note: our services are intended for adults and businesses; we do not knowingly collect personal data from children under 16, and if you are under 16 you should seek consent from a parent or guardian before providing any personal information.
Personal Data We Collect
We collect different types of personal data about you depending on how you interact with us. This includes information you provide directly, information collected automatically (e.g. via cookies), and information obtained through transactions or third-party services. The types of personal data we process include:
Information You Provide Directly
When you fill out forms on our website (such as our contact or enquiry forms, newsletter sign-up forms, or event registration forms) or communicate with us by email, phone, or in person, you may give us personal data. This includes identifiers and contact details such as your name, email address, telephone number, postal address, job title, and company/organisation name. It also includes the content of any messages or inquiries you send us and other information you choose to provide.
Information We Collect Automatically
When you visit our website, we automatically collect certain technical and usage information about your device and browsing actions by using cookies and similar technologies. This may include your IP address, browser type and version, device identifiers, pages you visit, the date/time of your visit, and referring URLs. For example, our site uses Google Analytics (a web analytics service provided by Google) to gather data about how users interact with our website.
Information from Transactions and Services
If you engage our consulting services or make a purchase/payment, we will collect information needed to process that transaction and maintain our business records. This includes financial and transaction data such as your billing address, the services or products you purchased, dates of transactions, and payment details.
Information from Third Parties
We may receive personal data about you from third-party sources in certain situations. For example, if you are working for one of our client companies, your employer or colleague might provide us with your contact details as a point of contact. We might also collect personal data from publicly available sources – for instance, we might obtain your business contact information from your company's website or a professional networking site like LinkedIn.
How We Use Personal Data (Purposes and Legal Bases)
We only use your personal information for specific, explicit, and legitimate purposes, and we ensure we have a valid legal basis for each use. Under the UK GDPR, the main legal grounds we rely on are: (a) your consent, (b) necessity for performing a contract with you, (c) compliance with a legal obligation, and (f) our legitimate interests (balanced with your rights).
- To provide our consulting services and fulfil contracts: we process personal data to deliver the services you have requested from us. Legal basis: necessary for the performance of a contract with you (UK GDPR Article 6(1)(b)).
- To respond to enquiries and provide information: if you contact us with a question, request a quote, or seek information about our services, we will use your provided information to respond to you. Legal basis: legitimate interest in responding to prospective clients or inquiries (Article 6(1)(f)).
- For marketing and newsletters (with consent): with your permission, we may use your contact information to send you marketing communications. Legal basis: consent (Article 6(1)(a)). We will only send you email marketing if you have actively opted in.
- To improve our website and services (analytics): we may process data about how users interact with our website or services to identify trends, troubleshoot issues, and make enhancements. Legal basis: we will only use non-essential analytical data with your consent (Article 6(1)(a)).
Cookies and Similar Technologies
Cookies are small text files placed on your device when you visit websites, and similar technologies include scripts, beacons, and local storage. Our website uses cookies and similar technologies to ensure the site functions correctly and to help us understand how you use our site.
Essential Cookies
These cookies are necessary for the basic operation of our website. For example, they may remember your preferences (like language or cookie consent choices) or keep you logged in to a secure area of the site. Consent is not required for essential cookies, as they are needed to provide the service you requested.
Analytics and Performance Cookies
We would like to use analytics cookies (such as those from Google Analytics) to collect information about how visitors use our website. We do not set analytics or other non-essential cookies without your prior consent. When you first visit our site, you will see a cookie consent banner explaining the types of cookies we use.
Managing Cookies
Most web browsers allow you to control cookies through their settings. You can set your browser to refuse all or some cookies, or to alert you when websites set or access cookies. However, please be aware that if you disable or delete cookies, some parts of our site might not function properly.
Data Sharing and Third-Party Service Providers
We treat your personal data with care and do not sell it to third parties for their own marketing or other independent use. However, in the course of running our business, we share personal data with certain trusted third parties. These third parties perform services on our behalf or in collaboration with us, and they only process your data for the purposes described in this Privacy Policy.
- Analytics providers: we use Google Analytics, provided by Google LLC (headquartered in the United States). When you consent to analytics cookies, usage data (like your IP address and website activities) is collected by Google Analytics and shared with Google.
- Customer Relationship Management (CRM) platforms: we may use a CRM system to manage our contacts, client relationships, and communications. For example, we might use a cloud-based CRM like HubSpot or Salesforce to store your name, contact details, company info, and a log of our interactions.
- Cloud storage and IT infrastructure: we use reliable cloud-based services for data storage, email, and IT infrastructure. For instance, we may use Microsoft 365 (OneDrive/SharePoint/Exchange) or Google Workspace for business email and document management.
- Payment processors: if you make a payment to us by credit card or online payment, that payment will be processed by third-party payment processors such as Stripe, PayPal, or our banking institutions. We do not see or store your full financial account numbers.
International Data Transfers
Stratford Ellis is based in the United Kingdom. However, some of the third-party service providers we use and some internal operations may involve transferring your personal data across national borders. In particular, data may be transferred to or accessed in countries outside the UK (and potentially outside the European Economic Area – EEA).
When we transfer personal data internationally, we ensure that an appropriate level of protection is applied to your information, as required by the UK GDPR. The safeguards we rely on may include:
- Adequacy decisions: in some cases, data may be sent to countries that have been officially designated by the UK government as providing an "adequate" level of data protection.
- Standard Contractual Clauses (SCCs) / International Data Transfer Agreements: for transfers to countries without an adequacy decision – such as the United States – we implement standard data protection clauses approved by the UK.
- Additional technical and organisational measures: we may use measures like encryption and pseudonymisation for data in transit and at rest, to mitigate the risk when data is stored overseas.
Data Retention and Storage
We will not keep your personal data for longer than necessary for the purposes for which it was collected, unless a longer retention period is required or permitted by law. Below are some typical retention practices:
- Client and contract data: we generally retain relevant data for up to six (6) years from the end of the contract or last interaction.
- Enquiry and prospective client data: we may retain your contact information and communications for no more than 12 to 18 months after our last interaction.
- Marketing data: we will retain your contact details on our mailing list until you unsubscribe or opt out.
- Website analytics data: data collected via Google Analytics is retained for 14 months from your last visit.
Data Security
We have implemented a range of technical and organisational security measures to ensure that your personal data is kept secure and confidential. Protecting your information is a top priority for Stratford Ellis, and we take into account industry best practices and legal requirements.
- Access control: personal data is only accessible to those in our team who need access to perform their job duties.
- Encryption: we use encryption to protect personal data in transit and at rest wherever feasible. Our website is secured via HTTPS (SSL/TLS encryption).
- Secure infrastructure: our website and IT systems are protected by firewalls, anti-malware defences, and network security monitoring.
- Physical security: for any physical records or on-site servers, we maintain appropriate physical controls.
- Monitoring and testing: we monitor our systems for potential breaches or attacks and periodically review our security measures.
Your Rights under GDPR
As an individual ("data subject") whose personal data we hold, you have certain rights under the UK GDPR and other data protection laws. We respect these rights and have processes to enable you to exercise them. Below is a summary of your key rights:
- Right to be informed: you have the right to be informed about the collection and use of your personal data. This Privacy Policy is part of fulfilling that right.
- Right of access: you have the right to access the personal data we hold about you and request a copy of that data (commonly known as a "Data Subject Access Request").
- Right to rectification: you have the right to have inaccurate personal data corrected or completed if it is incomplete. We will rectify the data promptly once you let us know.
- Right to erasure ('right to be forgotten'): you have the right to request deletion of your personal data in certain circumstances, for example where it is no longer necessary, you have withdrawn consent, you have objected, or it was processed unlawfully. The right is not absolute and certain legal exceptions may apply.
- Right to restrict processing: you have the right to ask us to limit or "freeze" the processing of your personal data in certain situations – for example, while we verify the accuracy of contested data, or where you prefer restriction to erasure.
- Right to data portability: in certain circumstances, you have the right to receive your personal data in a structured, commonly used, machine-readable format and to have that data transmitted to another controller. This right applies where processing is based on consent or contract and is carried out by automated means.
- Right to object: you have the right to object to our processing of your personal data in certain circumstances – including an absolute right to object to direct marketing, and the right to object to processing based on legitimate interests on grounds relating to your particular situation.
- Right to withdraw consent: where we rely on consent, you may withdraw it at any time. This will not affect the lawfulness of processing carried out before withdrawal.
- Rights related to automated decision-making: you have the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal or similarly significant effects on you, save for limited exceptions. We do not currently make such automated decisions.
- Right to lodge a complaint: you have the right to file a complaint with the UK Information Commissioner's Office (ICO) at www.ico.org.uk or on +44 303 123 1113. We would always encourage you to contact us first so we can try to resolve any concern.
How to exercise your rights
You can exercise any of your rights by contacting us using the details below. Typically, we will need to verify your identity before acting on a request. We will respond as soon as we can, generally within one month. If your request is complex or you have made multiple requests, we may extend the response time by a further two months, and will let you know why. There is no fee for exercising your rights, save for the narrow exception for manifestly unfounded or excessive requests.
Changes to this Privacy Policy
We may update or revise this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational reasons. If we make any significant changes, we will notify you by appropriate means – for example, by posting a prominent notice on our website or, where appropriate, sending you an email. We will also update the "Last updated" date at the top of this Policy.
Any changes will become effective when the revised Policy is posted on our website, unless stated otherwise. Your continued relationship with us – for example, use of our website or services – after any updates to this Policy will constitute acknowledgment of the changes.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of your personal data, please do not hesitate to contact us.
- Email: info@stratfordellis.com (please include "Privacy Inquiry" in the subject line for quicker routing).
- Phone: 020 8720 7490 (available during normal business hours, UK time).
- Postal address: Mansion House, Manchester Road, Broadheath, Cheshire, Altrincham WA14 4RW.
The data controller for the purposes of UK data protection law is Ahonsi Consulting, trading as Stratford Ellis. If you contact us about your rights or any privacy matter, we may ask to verify your identity (to protect your data from unauthorised access) and will then promptly assist you.
Data Protection Officer: at this time we have not appointed a formal Data Protection Officer, as we are not legally required to do so given the nature and scale of our data processing. However, we have a dedicated privacy team (led by our managing director) that oversees data protection compliance. Please use the contact details above for any privacy-related queries.
Alternatively, for general enquiries, you can reach us through the contact form, and your message will be directed to the appropriate person.
Stratford Ellis is the trading name for Ahonsi Consulting. Registered in England and Wales under company number 13494736.